Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

13h ago · hacker-news

A previously undocumented Linux backdoor named 'ted' has been discovered embedded within trojanized HAProxy binaries deployed at two South Korean organizations in the automotive and media sectors. The implant intercepts web traffic, enables command-and-control (C2) communication by mimicking legitimate HTTP responses, and allows attackers to execute shell commands, upload/download files, and modify configurations. Rapid7 Labs attributes the activity with medium confidence to North Korean state-sponsored actors, potentially linked to APT37, Lazarus, and Kimsuky clusters, based on infrastructure overlaps and operational patterns. The backdoor evades logging by manipulating HAProxy's internal connection counters and uses trojanized system binaries such as crond, sshd, agetty, atd, and polkitd to maintain persistence and exfiltrate credentials.
12 IoCs 2 Actors
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

12h ago · hacker-news

A high-volume phishing campaign has been leveraging invisible Unicode tag characters, specifically from the Unicode Tags block (U+E0000 to U+E007F), to obfuscate financial lure words such as 'funding' and evade email security filters. The technique, known as ASCII Smuggling, splits keywords with non-rendering characters (e.g., 'fun⟨U+E0020⟩ding') to bypass literal string detection while appearing normal to human recipients. The campaign has sent millions of emails daily, primarily targeting Small Business Administration (SBA) loan applicants, using the ActiveCampaign platform to distribute AI-generated phishing emails and dynamically generated, convincing phishing websites. The operation uses disposable finance-themed domains and leverages ActiveCampaign's infrastructure for link tracking, complicating reputation-based filtering.
12 IoCs
Critical Citrix NetScaler auth bypass now leveraged in attacks

13h ago · bleeping-computer

Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler appliances, tracked as CVE-2026-19490, which allows unprivileged remote actors to bypass authentication when the appliance is configured as an AAA virtual server or Gateway. Exploitation attempts have been observed from multiple IP addresses geolocated to Australia, the United States, and Germany, following the release of a public proof-of-concept. The Centre for Cybersecurity Belgium and vulnerability intelligence firm Previdian have issued warnings urging administrators to patch affected systems immediately.
3 IoCs
Google warns of new Chrome zero-day flaw exploited in attacks

16h ago · bleeping-computer

Google has patched a high-severity zero-day vulnerability in Chrome's V8 JavaScript and WebAssembly engine, identified as CVE-2026-85046, which is being actively exploited in the wild. The flaw is a type confusion issue that could allow remote code execution if a user visits a specially crafted webpage containing malicious JavaScript. Google has not disclosed specific exploitation details to allow time for users to update. Chrome users are urged to update to version 152.0.7977.82 or later to mitigate the risk. This is the sixth actively exploited Chrome zero-day fixed by Google in 2026.
3 CVEs
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges

15h ago · bleeping-computer

An anonymous security researcher known as Nightmare Eclipse disclosed a zero-day privilege escalation vulnerability in CrowdStrike Falcon, dubbed 'FalconFlank,' which allows attackers to achieve SYSTEM-level privileges on fully updated Windows 11 25H2 and Windows Server 2025 systems. The exploit abuses the 'File Suspicious Macro Removal' feature in CrowdStrike Falcon Sensor by loading a malicious DLL. CrowdStrike has not yet assigned a CVE ID but advises customers to disable the related Microsoft Office policy setting while investigations continue. The researcher has also released other zero-day exploits targeting Kaspersky, Avast, Nvidia, and multiple Microsoft products.
1 IoCs
Angry Birds: Toy Ghouls’ new toys

18h ago · securelist

Toy Ghouls, a financially motivated threat actor active since 2025, has developed two custom backdoor variants named mqtt-bird-agent and matrix-bird-agent, both version 0.1.0. These backdoors are deployed using Windows Remote Management (WinRM) and establish persistence via Windows services. The HiveMQ version communicates through the public broker.hivemq.com MQTT broker, while the Element version uses a malicious Element server at meet.element[.]tw for C2 communications, leveraging Matrix protocol rooms for command exchange. The backdoors collect system telemetry, execute commands via PowerShell or cmd, and use machine-bound encryption for configuration files, indicating increased sophistication in the group's tooling and operational security.
11 IoCs
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

1d ago · hacker-news

BraZetsu is a sophisticated Python-based Windows malware framework used by the threat actor Exilware to compromise systems and monetize access via the 'Infected Marketplace' (aka 'Banco de Infects'). The malware conducts deep reconnaissance, steals financial data including CNAB-format remittance files, captures screenshots, and enables remote command execution. It leverages generative AI for target triage and prioritization, and maintains persistent communication via WebSocket. BraZetsu shares infrastructure and code with AgenteV2, indicating they are part of the same malware framework. The campaign primarily targets Iberian and Latin American organizations in e-commerce, finance, and critical infrastructure sectors.
4 IoCs 1 Malware
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

1d ago · hacker-news

Cisco disclosed a critical vulnerability, CVE-2026-20212, in 10 Silicon One-based Nexus 9000 switches that allows unauthenticated remote attackers to execute code with root privileges by exploiting exposed TCP ports 43210 and 43211. The flaw stems from binding to an unrestricted IP address, enabling direct access to a privileged service. Cisco has released patches and recommends immediate upgrades, while also providing temporary mitigations such as infrastructure ACLs and a Live Protect shield. Separately, a hardening release for IOS XR addresses 7 CVEs, including two rated 9.8, and ongoing exploitation of similar infrastructure is linked to the China-nexus threat actor Fire Ant, which has deployed stealthy implants on IOS XR routers to manipulate traffic and exfiltrate data.
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

1d ago · hacker-news

Multiple threat campaigns are leveraging social engineering, phishing-as-a-service (PhaaS), and abuse of trusted software to gain unauthorized access to corporate and personal accounts. Microsoft Teams is being abused in vishing attacks to trick users into granting remote access via RMM tools, while PhaaS platforms like Outsider and BlueKit enable credential theft through browser-in-the-middle attacks. Malicious actors are also exploiting misconfigurations in AI instruction files (llms.txt) to deliver malicious packages, and trojanized Electron apps are distributing the RevStealer information stealer. Additionally, attackers are abusing legitimate tools like Faronics Deploy and ScreenConnect to establish persistent remote access, and ransomware operations such as The Gentlemen and CRPx0 continue to target organizations with sophisticated, multi-stage attack chains.
6 IoCs 1 Actors 1 Malware
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

21h ago · hacker-news

Google has released a security update for Chrome to address CVE-2026-85046, a high-severity type confusion vulnerability in the V8 JavaScript and WebAssembly engine that is actively exploited in the wild. The flaw allows a remote attacker to execute arbitrary code within the sandbox by using a crafted HTML page. Security researcher Salvatore Gulizia discovered and reported the vulnerability, which stems from incorrect handling of JavaScript array maps leading to arbitrary read/write capabilities on the JavaScript heap. Users are urged to update to Chrome version 152.0.7977.82 or later to mitigate the risk.