Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
21h ago · hacker-news
Researchers at Calif demonstrated a zero-click worm exploiting a vulnerability in WeChat that allows full takeover of a user's account via an incoming call, without requiring any interaction from the target. The exploit spreads laterally by leveraging compromised accounts to call other contacts, enabling rapid propagation across devices. The attack works even if the call is not answered, though declining the call stops that particular attempt. Tencent mitigated the exploit server-side and released client updates (Android 8.0.77, iOS 8.0.76) in August 2026, but has not issued a formal advisory or CVE. No real-world attacks have been observed, and technical details have been withheld pending a future conference presentation.
ShinyHunters hackers claim breach of Florida "DAVID" DMV database
17h ago · bleeping-computer
The ShinyHunters extortion gang claims to have breached the Florida Department of Motor Vehicles' 'DAVID' (Driver and Vehicle Information Database) system via a password-reset vulnerability, stealing over 200,000 driver records. As proof, they published a screenshot of Jeffrey Epstein's DMV record containing sensitive personal information. The attackers claim they accessed the system using compromised accounts belonging to DMV employees and an FBI agent, then exfiltrated data by iterating through driver IDs. They state they have since lost access and that the vulnerability is being patched, while also indicating plans to disclose breaches of other state DMVs in the near future.
1 Actors
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
15h ago · bleeping-computer
Microsoft's September 2026 Patch Tuesday addresses 966 security vulnerabilities, including two actively exploited zero-day flaws. The first, CVE-2026-81963, is an elevation of privilege vulnerability in the Windows Update Stack that allows attackers to gain SYSTEM privileges through improper link resolution. The second, CVE-2026-85880, is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC) that enables local privilege escalation to SYSTEM. Both vulnerabilities were actively exploited in the wild before patches were released, though technical details on exploitation are not disclosed. The update marks Microsoft's largest Patch Tuesday to date, attributed to the use of AI-powered vulnerability discovery.
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
19h ago · hacker-news
A financially motivated threat actor known as TeamPCP (aka Altered Spider, UNC6780) has conducted large-scale software supply chain attacks targeting PyPI, npm, and Docker Hub, deploying credential stealers SANDCLOCK and DUSTMAKER. SANDCLOCK, used in March and April 2026, is a Python-based tool targeting Linux and Kubernetes environments with container escape capabilities, while DUSTMAKER is a cross-platform JavaScript payload focused on credential theft in CI/CD pipelines and includes AI-targeting techniques like prompt injection. The group exfiltrates API credentials and targets AI coding assistants, monetizing access through ransomware and data theft extortion networks.
2 IoCs 1 Actors
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
17h ago · hacker-news
Slim Spider is a financially motivated threat actor targeting Brazilian financial institutions since at least March 2026. The group conducts multi-stage intrusions into cloud environments to steal cryptocurrency custody secrets and access instant payment systems like Pix. They use custom Bash scripts to extract cloud credentials, implement cloud-native cryptographic signing via OpenSSL, and deploy backdoors such as MikeDor. Slim Spider also leverages malicious DevOps pipelines and maintains web-based panels for automating attacks, including endpoint scanning, email reconnaissance, and unauthorized Pix transactions.
1 IoCs
Adobe fixes critical Magento zero-day exploited to backdoor servers
20h ago · bleeping-computer
Adobe has patched a critical zero-day vulnerability, CVE-2026-75650 (StyleSmuggler), actively exploited in the wild to backdoor Magento and Adobe Commerce servers. The flaw allows arbitrary code execution, and attackers have deployed PHP web shells to exfiltrate server data. A second threat actor using different tooling has also been observed exploiting the same vulnerability. Sansec discovered the attacks, which began at least on September 4, 2026, and recommend immediate application of Adobe's hotfix and credential rotation.
1 IoCs
ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
19h ago · hacker-news
Check Point Research discovered a vulnerability in ChatGPT that allowed a maliciously crafted prompt to enable covert data exfiltration from a user's session. By exploiting a shared internal JFrog Artifactory service used for package caching, an attacker could establish a hidden communication channel between isolated ChatGPT containers across different accounts. This allowed the silent reading of Gmail data, chat history, and files from a victim's session and transmitting them to an attacker-controlled account without user consent or awareness. The vulnerability stemmed from improper isolation in the internal service and excessive container permissions, which allowed write access to shared metadata properties. OpenAI confirmed the issue and took the internal service offline, but no user-facing patch was required or released.
1 IoCs
Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
18h ago · hacker-news
On September 6, 2026, approximately 4,000 bitcoin (worth ~$320M) were withdrawn from the Liquid Network's federation wallet due to a bug in the Elements software underlying the sidechain. The attackers, who claim to be white hats, returned 3,400 bitcoin after confirming that Blockstream had patched its systems, but are still holding 598.5 bitcoin (~$47M). The exploit leveraged the SideSwap Peg-out Authorization Key to initiate a peg-out without compromising any private keys, suggesting a flaw in logic or validation within the Elements codebase. Communications occurred on-chain, including a PGP-encrypted message sent via a microtransaction, and the incident remains unresolved as the network stays offline.
1 IoCs
220 million traveler records exposed in Vietnam-linked APIS leak
1d ago · bleeping-computer
An Elasticsearch cluster named 'pax-info', linked to a Vietnamese organization and hosted in Viettel-assigned IP space, was found exposed online due to chained security misconfigurations. The database contained over 220 million traveler and crew records spanning from January 2017 to April 2026, including personally identifiable information such as names, passport details, flight data, and nationalities. The system was accessible via default credentials after initial HTTP 401 authentication was bypassed through a cloud-based path, and it was secured on June 8 following disclosure by Kinryū Labs. It remains unknown whether the data was accessed or exfiltrated by malicious actors prior to remediation.
1 IoCs
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
23h ago · talos
Cisco Talos identified a cryptocurrency theft campaign dubbed ClickFix that abuses legitimate services, particularly the Google Visualization API, for command and control (C2). The attackers use social engineering to trick victims into pasting malicious JavaScript into their browser or installing it via the Tampermonkey browser extension, enabling persistent access. The malicious script acts as a web skimmer, intercepting and altering cryptocurrency deposit addresses in real time, hijacking clipboard content, and injecting fake UI elements to deceive users into believing they are receiving transaction bonuses. The campaign primarily targets cryptocurrency traders through lures distributed on Telegram, DarkForums, and paste sites, using Google Sheets to host obfuscated payloads and evade detection.
5 IoCs