Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
ARTEX AI, Claude agents used in cyberattacks on South Korean banks

7h ago · bleeping-computer

A Chinese-speaking threat actor used the ARTEX AI penetration testing framework and Anthropic's Claude AI agents to conduct cyberattacks against major South Korean banks, including Shinhan Bank, KB Kookmin Bank, and Hana Bank. The attacks led to exposure of customers' personal and financial data, as well as system outages. Infrastructure analysis revealed open directories containing ARTEX configuration files, Claude session histories, and memory files, which exposed the attacker's methods and partial identity. The actor used multiple LLMs, including DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6, accessed via the API proxy xcai[.]pro, and showed interest in monetizing stolen data through Telegram.
1 IoCs
TP-Link Sued by Four More U.S. States Over Router Security and China Ties

1d ago · hacker-news

Multiple U.S. states have filed lawsuits against TP-Link Systems over claims of misleading consumers about router security and ties to China. The complaints highlight real-world attacks involving TP-Link routers, including exploitation by state-backed hackers from China and Russia. Specific vulnerabilities in TP-Link devices, particularly those supplied by ISPs under the Aginet brand, were disclosed and technically detailed by SEC Consult, allowing unauthenticated attackers to gain full control of affected devices. These flaws, including CVE-2025-30237 through CVE-2025-30241, enable privilege escalation, command execution, and credential decryption, with fixes distributed via ISPs but not always accessible to end users.
1 Malware
Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto

1d ago · bleeping-computer

Threat actors are actively exploiting two unpatched vulnerabilities in the AhsayCBS backup management platform to gain unauthorized access, deploy webshells, and mine cryptocurrency. The attack chain begins with CVE-2026-105133, an authentication bypass, followed by CVE-2026-105134, which enables OS command injection. Attackers deploy JSP webshells, install the XMRig miner disguised as edge.exe, and use a PowerShell script to hide mining activity from Task Manager. The malware persists via a malicious service named 'MicrosoftEdgeUpdateSvc' and may leverage the WinRing0x64.sys driver to enhance mining performance.
4 IoCs 1 Malware
New GhostAction Wave Hits Hundreds of Repos, Expanding Beyond CI/CD Secrets to Cloud Credentials

23h ago · socket-dev

A new wave of the GhostAction campaign has compromised maintainer accounts on GitHub, injecting a malicious workflow named security-audit.yml into 346 repositories, including high-profile projects like uber/athenadriver and kitao/pyxel. The workflow exfiltrates both GitHub Actions secrets and cloud/AI service credentials from the working tree and full Git history, sending them to a hardcoded C2 server. This variant expands on prior GhostAction activity by combining stolen publishing credentials with the harvesting of committed cloud credentials, including AWS, OpenAI, and GitHub API keys. The malicious workflow runs on every push and remains active on affected repositories, posing ongoing supply chain and cloud security risks.
3 IoCs
GhostAction Returns: Malicious “Security Audit” Workflows Now Mine Credentials from Entire Git Histories

1d ago · step-security

The GhostAction campaign has resurged with a new wave of malicious GitHub Actions workflows injected into compromised open-source repositories. Attackers compromised maintainer accounts (kitao, henrywoo) to push malicious 'security audit' workflows directly to default branches, bypassing review. These workflows exfiltrate GitHub Actions secrets and mine the entire git history for credentials, including AWS, AI provider, and SaaS tokens. The exfiltration endpoint has shifted to the IP address 193.32.204.199, using plain HTTP to evade domain-based detection. Successful exfiltration was confirmed in multiple repositories, including Uber's athenadriver.
9 IoCs
Evolution of Web3 in Cloud Supply Chain Attacks

2d ago · unit42

Threat actors, including North Korea-affiliated groups like Alluring Pisces (aka Sapphire Sleet or Midnight Neptune), are leveraging Web3-based command-and-control (C2) infrastructure in software supply chain attacks to dynamically update botnets and evade detection. Two major campaigns, ChainDrop and PolinRider, have infected hundreds of npm packages and expanded across multiple package registries, harvesting cloud IAM keys, CI/CD tokens, and environment secrets from developer workflows. These threats use blockchain-based C2 techniques such as EtherHiding, TxDataHiding, and NullReceiver to bypass traditional network monitoring and maintain persistence.
3 IoCs 1 Actors
Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

1d ago · hacker-news

The China-linked threat actor Flax Typhoon has exploited five vulnerabilities in ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND to gain initial access to organizations and exfiltrate sensitive data. These vulnerabilities were added to CISA's Known Exploited Vulnerabilities (KEV) catalog, and federal agencies are mandated to patch or discontinue use by October 11, 2026. The attacks involve scanning tools, cross-site scripting, password spraying on Microsoft Exchange servers, persistence via VPN software, and data exfiltration using scripts.
1 Actors 7 CVEs
Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

1d ago · hacker-news

Threat actors are exploiting two vulnerabilities, CVE-2026-105133 and CVE-2026-105134, in the AhsayCBS backup utility to gain remote code execution on affected systems. The attackers chain the flaws to bypass authentication and execute arbitrary commands, leading to the deployment of web shells and XMRig cryptocurrency miners disguised as Microsoft Edge. Post-exploitation activities include reconnaissance, cryptomining, and the use of an AI-assisted PowerShell script that interferes with Windows Task Manager to avoid detection.
3 IoCs 1 Malware
Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

1d ago · hacker-news

Security researchers have published a working exploit called AnyPwn for a pre-authentication remote code execution vulnerability in AnyDesk Linux versions prior to 8.0.3. The flaw is a heap buffer overflow in the session protocol that allows attackers to achieve root access via direct TCP connections on port 7070. The exploit relies on a 32-bit integer overflow when calculating buffer size, leading to a heap-based buffer overflow that corrupts adjacent memory and enables arbitrary code execution using a ROP chain. Although AnyDesk patched the issue in June 2026, no CVE has been assigned and no formal advisory was issued.
3 IoCs
P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

1d ago · hacker-news

P7 DarkSword is a new variant of the DarkSword iOS exploit kit that enhances stealth and data theft capabilities, including exfiltration of iCloud Keychain, cryptocurrency wallet data, and remote command execution on compromised iPhones. The kit leverages previously undocumented iOS vulnerabilities CVE-2025-24201 and CVE-2025-31200 to escape browser sandbox and achieve kernel-level privileges. It has been used in attacks targeting Saudi Arabia, Turkey, Malaysia, and Ukraine by multiple threat actors, including PARS Defense and Star Blizzard. Researchers also identified active C2 infrastructure and open directories linked to Chinese-speaking operators running exploitation-as-a-service with a focus on cryptocurrency theft.
6 IoCs 1 Actors 1 Malware 1 CVEs