Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
9h ago · hacker-news
Threat actor UNC6240, linked to ShinyHunters, is exploiting CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft, to deploy web shells and establish persistent access. The attackers bypass web application firewall (WAF) protections by URL-encoding the 'P' character as '%50' in requests to the vulnerable PSEMHUB endpoint. Exploitation leads to fileless command execution, deployment of JSP web shells, and installation of the SIDEEYE backdoor and Neo-reGeorg tunneling toolkit for data exfiltration and lateral movement. Targets span multiple sectors including education, healthcare, government, and technology, with the threat actor demonstrating root- and SYSTEM-level access on compromised systems.
6 IoCs 1 Actors
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
2h ago · hacker-news
Lunex Stealer, also known as Psychedelic Stealer, is a malware-as-a-service platform distributing information-stealing malware through compromised Ukrainian websites using fake CAPTCHA pages via ClickFix. The attack chain uses a malicious AMD driver (PDFWKRNL.sys) exploiting CVE-2023-20598 to bypass security monitoring via the BYOVD technique, enabling privilege escalation and evasion of EDR solutions. The malware steals credentials from multiple Chromium-based browsers, exfiltrates cryptocurrency wallet data, and establishes persistent remote access through a PowerShell-based Chrome Native Messaging Host. Command-and-control infrastructure includes multiple panels across 13 countries, with phishing domains linked to at least one Turkish-hosted panel.
6 IoCs
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
2h ago · bleeping-computer
The ShinyHunters threat actor, tracked as UNC6240, is exploiting CVE-2026-35273 in Oracle PeopleSoft systems using a WAF bypass technique involving URL-encoded paths (e.g., '/%50SEMHUB/') to evade detection. This allows continued exploitation of unpatched servers where WAF rules were expected to block access. The attackers deploy JSP web shells (x.jsp, u.jsp, u2.jsp, tunnel.jsp, tunnel.jspx), execute in-memory commands, and deploy the SIDEEYE backdoor via 'Ple64.exe' on Windows systems. They also use Neo-reGeorg for tunneling and MeshAgent for persistence on Linux systems, targeting sectors including education, government, healthcare, and technology.
7 IoCs 1 Actors
A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity
1w ago · unit42
Unit 42 researchers identified a security issue in AWS AgentCore Harness where default configurations allow attackers to exfiltrate plaintext credentials from AgentCore Identity via prompt injection. The built-in shell tool, enabled by default and running as root, can access the memory space of the harness process (PID 1), where credentials are temporarily stored in plaintext during runtime. By injecting malicious commands through a support ticket, an attacker can execute reconnaissance and exfiltrate a JSON Web Token (JWT) used for downstream MCP server authentication. This stolen credential, belonging to the operator's service account (mcp-service), enables unauthorized access to sensitive data such as personally identifiable information (PII). AWS acknowledged the finding but classified it under customer responsibility, emphasizing proper scoping of allowedTools and egress filtering.
1 IoCs
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
7h ago · bleeping-computer
Two previously compromised GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, were re-enabled by their maintainer on September 16, 2026, without removing the malicious payload from May's Mini Shai-Hulud supply-chain attack. The actions continued to serve an obfuscated malicious payload in 'index.js', causing dependent workflows to execute malware that targets developer tokens, credentials, and CI/CD secrets. The repositories were re-disabled on September 25 after researchers at Socket raised the alarm. Developers are advised to remove or pin these actions and rotate potentially exposed secrets.
2 IoCs
Trust and the enticing consultancy offer
2d ago · talos
The article is a commentary on social engineering tactics targeting cybersecurity professionals through fake consultancy offers and job scams, emphasizing the importance of trust in the industry. It does not describe a specific malware, vulnerability, or attack campaign with technical indicators. The piece also promotes a new open-source toolkit, CAIRN, and includes general security news summaries without detailed technical analysis or IoCs tied to a single threat event.
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
12h ago · hacker-news
CISA has added two vulnerabilities to its Known Exploited Vulnerabilities catalog due to active in-the-wild exploitation. CVE-2026-65660 is a code injection flaw in Microsoft Office SharePoint that allows authenticated attackers to achieve remote code execution, which Microsoft initially classified as a spoofing issue. The second vulnerability, CVE-2026-67279, affects MikroTik RouterOS and enables unauthenticated attackers to open a session channel, which when combined with CVE-2026-86060 (an argument injection flaw), forms the 'MikroTrick' exploit chain allowing full administrative takeover of vulnerable routers without credentials.
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
11h ago · hacker-news
A high-severity CSRF vulnerability in Elementor Website Builder WordPress plugin versions 4.3.0 and 4.3.1 allows unauthenticated attackers to take over WordPress sites by tricking an authenticated administrator into clicking a crafted link. The flaw bypasses CSRF protection for cookie-authenticated REST API requests when the string 'elementor/v1/events/' appears in the request URI, enabling actions like creating rogue administrator accounts. The vulnerability affects over 2 million sites and has been patched in version 4.3.2.
1 IoCs
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
23h ago · bleeping-computer
Kiteworks has issued a precautionary advisory urging customers to shut down their servers for a six-hour window due to credible threat intelligence from federal authorities indicating a potential imminent cyberattack. While no confirmed breach or exploitation has been identified, the company suspects possible zero-day attacks targeting its secure file-sharing systems. The warning is preventative, with all known vulnerabilities already patched in the latest version (9.5.1). The Clop extortion gang is mentioned as a potential threat actor due to its history of targeting similar platforms.
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
1d ago · bleeping-computer
The Clop ransomware gang's data leak site was compromised by the ShinyHunters extortion group through an unpatched path traversal vulnerability in Grav CMS version 1.7.43. ShinyHunters exploited the flaw to upload malicious files, deface the site, and claim theft of source code, plugins, server logs, and Tor private keys, subsequently issuing a ransom demand. Grav CMS confirmed the vulnerability, tracked as CVE-2026-42608, resides in the core of Grav and was fixed in Grav 2.0 but not backported to the 1.7 branch until version 1.7.53.4 was released following disclosure.
1 Actors 1 CVEs