Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
9h ago · hacker-news
UNC6671, a financially motivated threat actor group, is conducting vishing attacks to steal credentials and multi-factor authentication tokens by impersonating IT help desk personnel and contacting employees on their personal mobile devices. The attackers use adversary-in-the-middle (AitM) infrastructure to capture credentials and session tokens, enabling access to SaaS platforms such as Microsoft 365 and Okta. The group operates under multiple extortion brands including Redact, Pink, Helix, and Falcon, and has exfiltrated data from organizations in North America, Australia, and the U.K., collecting over $10.6 million in Bitcoin between January and May 2026. Google and CrowdStrike assess that the group leverages social engineering rather than technical vulnerabilities, highlighting the need for phishing-resistant MFA and improved session controls.
3 IoCs 2 Actors
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
9h ago · hacker-news
A large-scale npm supply chain campaign has distributed nearly 800 malicious packages designed to deliver a cross-platform RAT and infostealer. The packages bypass typical lifecycle hook detection by instructing developers to load them via require(), triggering a downloader named WEL1DROPPER that fetches payloads from Cloudflare Workers or fallback domains using DNS TXT record exfiltration. The payloads target Windows, Mac, and Linux systems, establishing persistence, evading detection, and deploying secondary malware such as Sliver C2. The campaign, tracked as Flooding Dropper, may target Russian financial institutions and appears to evolve from the earlier Moika campaign.
12 IoCs 1 Malware
North Carolina Ports confirms cyberattack disrupting operations
14h ago · bleeping-computer
The North Carolina Ports Authority confirmed a cyberattack that disrupted IT systems and port operations at the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. The incident was detected on August 4, 2026, leading to a systems-wide outage and operational delays starting August 5. The authority activated its cybersecurity contingency plan and began recovery efforts, but did not attribute the attack to a specific threat actor or confirm data exfiltration. Operations were gradually returning to normal by August 7, though delays were still expected.
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
9h ago · hacker-news
ClickFix-style attacks are delivering a Go-based macOS stealer that profiles the system, escalates privileges via a fake system error prompt, and steals sensitive data including browser passwords, Apple iCloud Keychain, and cryptocurrency wallet contents. The malware includes a 'DRAIN' routine that siphons partial or full balances from wallets supporting Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP into attacker-controlled accounts. The infrastructure used in the attack is linked to Aeza Group, a Russian bulletproof hosting provider under international sanctions.
Metabase SQLi zero-day exploited in customer data-theft attacks
7h ago · bleeping-computer
A critical unauthenticated SQL injection vulnerability in Metabase versions 1.58 and above was exploited in zero-day attacks to compromise customer instances, leading to data theft at organizations including Framework, Tally, and a third-party vendor used by LexisNexis. The vulnerability allowed attackers to gain administrator access to Metabase instances, enabling them to steal stored credentials, read accessible data, and export customer information. Metabase confirmed active exploitation and issued patches across multiple affected branches, urging self-hosted users to update immediately and rotate credentials.
2 IoCs
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
15h ago · hacker-news
A pre-authentication reflected cross-site scripting (XSS) vulnerability in WordPress, tracked as CVE-2026-64638, affects all versions and can be exploited without authentication. The XSS flaw exists in the login screen, where a malicious username can bypass sanitization and execute JavaScript on the failed-login error page. This XSS can be chained with the SOME technique to achieve PHP code execution on the server when an administrator interacts with an attacker-controlled page, enabling actions such as plugin installation or arbitrary ZIP upload without requiring the plugin to be activated.
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
16h ago · hacker-news
A critical use-after-free vulnerability in Linux's SCTP implementation, tracked as CVE-2026-64564 and named SCTPhantom, has existed since 2008 and could allow local attackers to gain root privileges and escape containers. The flaw arises from improper handling of SCTP dynamic address reconfiguration, where a delete request is validated against one address but applied to another, leading to a use-after-free condition. Tencent's Zhuque Lab demonstrated successful exploitation on multiple Linux distributions, achieving host-level root access without requiring CAP_NET_ADMIN or CAP_SYS_ADMIN under specific conditions. The vulnerability was patched in Linux kernel versions 7.1.6, 6.18.42, 6.12.101, and 6.6.148, released on August 3, 2026.
1 CVEs
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
21h ago · hacker-news
TeamPCP, a threat actor active since at least 2020, has evolved from exploiting exposed Redis, Docker, Ray, and React infrastructure to conducting large-scale supply chain attacks. The group has used overlapping infrastructure and tradecraft across campaigns, including ShadowRay 2.0 (aka IronErn) and TA-NATALSTATUS, which targeted Redis servers to deploy cryptocurrency miners. More recently, TeamPCP has poisoned open-source libraries via GitHub Actions abuse and token theft, while also deploying destructive malware such as 'kube.py' that includes wiper functionality targeting Kubernetes clusters, particularly those in Iran.
2 IoCs 1 Actors
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
19h ago · hacker-news
Researchers at Novee Security identified critical vulnerabilities in Anthropic's Claude Code and Google's Gemini CLI that could allow unprivileged attackers to access CI workflow secrets or execute code on CI runners. CVE-2026-12537 in Gemini CLI enables OS command injection via a malicious .gemini/.env file, allowing pre-sandbox code execution on CI hosts. CVE-2026-54316 in Claude Code allows exfiltration of API keys one character at a time through Hugging Face's public download counter. Both vulnerabilities have been patched, with no evidence of active exploitation in the wild. The root cause across both systems was flawed 'harness' code that failed to properly validate or sandbox model-generated commands.
2 IoCs 2 CVEs
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
19h ago · hacker-news
Researcher Dirk-jan Mollema demonstrated a technique where malware running in a signed-in Windows session can abuse Windows Hello for Business keys to silently authenticate to Microsoft Entra ID, enabling persistent cloud access without extracting private keys or requiring administrator privileges. By leveraging WebAuthn, the attacker can request a signed assertion from the compromised endpoint and use it to obtain a Primary Refresh Token (PRT), register a new device, and bypass phishing-resistant authentication requirements. The technique exploits legitimate Windows ticketing behavior and does not require device-specific access, allowing attackers to establish long-term access to cloud resources under certain tenant policies.
3 IoCs