Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
Exploits and vulnerabilities in Q2 2026

6d ago · securelist

In Q2 2026, a significant increase in registered vulnerabilities was observed, driven by AI-assisted discovery tools. Multiple critical vulnerabilities were exploited in both Windows and Linux systems, including local privilege escalation flaws in the Linux kernel's caching subsystem (e.g., Dirty Frag family) and newly disclosed Windows Defender and BitLocker bypass vulnerabilities. Exploitation of AI/LLM platforms such as OpenClaw, Dify, and Open WebUI surged, with vulnerabilities enabling session compromise, unauthorized access, and message manipulation. APT groups increasingly targeted newly published and zero-day vulnerabilities, using C2 frameworks like Sliver and Metasploit for post-exploitation. The report highlights growing risks from insecure AI tooling and the need for enhanced access controls and real-time monitoring.
3 Malware 15 CVEs
ValleyRAT masquerading as adware

1d ago · securelist

The ValleyRAT backdoor is being distributed under the guise of adware, specifically a modified version of the QN Wallpaper application. The malware uses DLL sideloading via a malicious libcef.dll to execute its payload, which includes stealing keystrokes, clipboard data, screenshots, and system information. It establishes persistence and communicates with C2 servers, with configurations allowing for process protection and module downloads. The campaign primarily targets users in China and India and is attributed to the threat actor group Silver Fox.
5 IoCs 1 Actors 1 Malware
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

21h ago · securelist

Mirage Kitten, an APT group, is conducting cyberespionage campaigns targeting the aviation and FinTech sectors in the Middle East and Africa. The group uses spear-phishing via fake recruiter accounts on LinkedIn to deliver trojanized coding challenge archives, leading to the deployment of two newly identified cross-platform malware families: NodeRabbit and PollCat. NodeRabbit is a Node.js-based remote access trojan (RAT) with three variants, each exhibiting increasing sophistication in persistence and evasion techniques. PollCat is a JavaScript-based RAT distributed through a separate coding challenge, using similar infrastructure and TTPs. Both malware families communicate with C2 servers hosted on Azure and Cloudflare domains, leveraging legitimate cloud services to blend in with normal traffic.
48 IoCs
Password spraying campaign targets AWS root user accounts across 150+ organizations

2d ago · datadog-security-labs

Datadog Security Research observed a password spraying campaign from July 24 to August 23, 2026, targeting AWS root user accounts across more than 150 organizations. The attackers used specific Chrome and Firefox user agents and routed traffic through proxy infrastructure with IP addresses flagged as malicious or residential. A key indicator of this campaign is the use of valid root user email addresses, suggesting the attackers either had prior access to such lists or performed brute-force enumeration. No successful authentications were observed, and the motive remains unclear due to the lack of post-compromise activity.
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack

2h ago · socket-dev

The npm package @7nohe/openapi-react-query-codegen was compromised in a supply chain attack dubbed 'Mini Shai-Hulud', where ten malicious versions were published using a comment-triggered GitHub Actions workflow vulnerability. The malicious code executes during installation via an obfuscated JavaScript loader (3FWCvzduYZg.js), which decrypts and runs a second-stage payload designed to steal cloud credentials, package registry tokens, GitHub Actions secrets, and AI agent configurations. The payload includes self-propagation capabilities, including SSH-based lateral movement, GitHub Actions workflow tampering, and package poisoning across npm, JFrog, RubyGems, and PyPI. All malicious versions carry valid npm provenance attestations, making them appear legitimate despite containing attacker-controlled code.
21 IoCs
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

15h ago · hacker-news

The Iranian threat actor Nimbus Manticore, also known as Iranian Dream Job, is using fake job recruitment lures on platforms like LinkedIn to deliver two newly identified cross-platform remote access trojans (RATs): NodeRabbit and PollCat. These malware families are distributed via trojanized coding challenge archives that contain malicious npm packages or JavaScript code, targeting developers on Windows, Linux, and macOS. The attacks enable command execution, file manipulation, persistence, and reconnaissance, with C2 infrastructure hosted on Azure and communication through specific API endpoints. The group's shift to Node.js-based cross-platform tools expands its reach while maintaining its historical social engineering tactics for cyber espionage in the Middle East and Africa.
11 IoCs 1 Actors
Hackers abuse Faronics Deploy admin tool to install ScreenConnect

7h ago · bleeping-computer

Hackers are exploiting the legitimate Faronics Deploy endpoint management tool to gain remote administrative access to victim systems by tricking users into installing a maliciously repurposed, signed installer disguised as an Adobe-related executable. The installer enrolls the victim's machine into an attacker-controlled Faronics deployment, enabling the execution of PowerShell scripts that deploy additional payloads, including ConnectWise ScreenConnect, a remote access tool used for persistent and interactive control. The attack uses phishing emails with business-themed lures, such as fake invoices, and includes anti-analysis techniques to evade detection in sandboxed environments. Activity declined after Faronics implemented anti-abuse measures in response to disclosure by Huntress.
1 IoCs
How to Spot and Stop Rogue Device Joins

8h ago · wiz

Attackers are abusing Entra ID device registration functionality to establish persistent access by registering rogue devices using stolen credentials, often obtained via device code phishing. Traditionally, these attacks used predictable indicators like 'DESKTOP-XXXXXXXX' device names and specific User-Agent strings, but attackers are now adopting AI-generated, benign-looking identifiers such as 'Work PC' to evade static detection. The article highlights a shift toward behavioral detection methods, including identifying anomalies in device naming conventions and correlating device code phishing with subsequent device registration events to detect these stealthier attacks.
2 IoCs
Inside 90 days of attacks on AI infrastructure

8h ago · wiz

Wiz Threat Research observed 90 days of sustained attacks against AI infrastructure through honeypots deployed across services like LiteLLM, Flowise, and LangChain. Attackers exploited vulnerabilities in MCP servers, including authentication bypass and command injection (CVE-2026-59822, CVE-2026-42271), to achieve remote code execution and deploy cryptominers. A second pattern involved blind prompt injection against AI agent frameworks, where attackers used out-of-band DNS callbacks to confirm execution and later fetch payloads from Pastebin. Post-exploitation activity was tailored to AI environments, including in-memory extraction of LiteLLM master keys, model enumeration, and use of environment-specific camouflage to hide malicious binaries.
10 IoCs 2 Malware 3 CVEs
@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow

4d ago · step-security

On August 28, 2026, the npm package @7nohe/openapi-react-query-codegen was compromised via an exposed GitHub Actions workflow that allowed unauthorized publishing. An external attacker exploited a permissive release workflow triggered by a comment from any pull request participant, leading to the publication of ten malicious versions. These versions included obfuscated payloads and malicious preinstall hooks that executed during installation, downloading and running the Bun executable, probing for GitHub credentials, and exfiltrating sensitive data. The attack leveraged npm Trusted Publishing with GitHub Actions OIDC, allowing code execution without needing the maintainer's npm token.
18 IoCs