Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
Max severity SAP Commerce Cloud flaw now targeted in attacks

2h ago · bleeping-computer

A critical remote code execution vulnerability, CVE-2026-58231, in SAP Commerce Cloud is being actively exploited in the wild just three days after the patch was released. The flaw, which has a CVSS score of 10.0, stems from improper authorization in the Data Hub Adapter extension, allowing unauthenticated attackers to execute arbitrary code by exploiting a default authentication client. Threat intelligence firm Defused confirmed exploitation attempts are already occurring, as observed through honeypot traffic, despite the absence of a public proof-of-concept. The vulnerability affects internet-exposed SAP Commerce Cloud instances, with over 4,200 such systems identified globally, primarily in Europe and North America.
1 CVEs
Shell investigates 'potential incident' after Clop data theft claims

4h ago · bleeping-computer

The Clop ransomware gang claimed responsibility for stealing 89GB of data from energy giant Shell, allegedly exploiting a critical vulnerability, CVE-2026-12569, in Internet-exposed PTC Windchill and FlexPLM instances. The same vulnerability was actively exploited to target other major companies, including General Electric and Philips, with attackers deploying JSP webshells to exfiltrate sensitive data such as engineering drawings, project plans, and facility reports. U.S. CISA and German BSI issued urgent advisories urging immediate patching, and the flaw has been added to CISA's Known Exploited Vulnerabilities catalog.
RingCentral data breach exposed info of 1.6 million accounts

5h ago · bleeping-computer

In July 2026, the ShinyHunters extortion group breached RingCentral through a sophisticated social engineering campaign, exfiltrating personal information from 1.6 million customer accounts. The stolen data included names, email addresses, phone numbers, and physical addresses. After RingCentral refused to pay a ransom, ShinyHunters leaked a 280GB compressed archive of the stolen data on their dark web leak site. The breach did not impact RingCentral's core platform, and no further unauthorized activity has been observed since remediation efforts were implemented.
1 Actors
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

7h ago · securelist

The HoneyMyte APT group, also known as Mustang Panda, has upgraded its CoolClient backdoor with a kernel-mode Windows rootkit to enhance stealth and persistence. The new variant uses a signed kernel driver, msagent.sys, deployed as a Windows service to hide malicious processes, files, registry keys, and network connections. The malware chain begins with DLL sideloading via a renamed Sangfor executable (defender.exe), establishes persistence through scheduled tasks and registry entries, performs UAC bypass using RPC techniques, and injects into synchost.exe before deploying the driver. The driver communicates with user-mode components via IOCTLs and employs minifilter and registry callbacks to protect its artifacts.
22 IoCs 1 Actors 1 Malware
Armored Likho expands its cyber-espionage toolkit

1d ago · securelist

In May 2026, the Armored Likho (aka Eagle Werewolf) threat actor group expanded its cyber-espionage operations targeting individuals and organizations in Russia through a fake donation app dropper written in Rust using the Tauri framework. The campaign delivers a new Rust-based toolkit called Still Toolkit, consisting of two components: Still Sync, which steals Telegram session data and exfiltrates chat logs and media via the Telegram API, and Still Audio, an audio surveillance implant that records microphone input when voice activity is detected. The malware uses gRPC and FlatBuffers for C2 communication, leverages the SeBackupPrivilege for file access, and employs a Dead Drop Resolver via a GitHub repository to retrieve updated C2 addresses.
27 IoCs
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

19h ago · bleeping-computer

An Akira ransomware affiliate gained initial access via an exposed SonicWall VPN without MFA, then used RDP to move laterally and exfiltrate data. The attacker rebooted the compromised host into Safe Mode with Networking to disable EDR and AV solutions, including the Huntress agent and Microsoft Defender. Data was stolen using s5cmd and uploaded to an attacker-controlled S3 bucket, while AnyDesk was installed and configured to persist in Safe Mode. The ransomware payload (akira.exe) failed to execute due to low virtual memory, preventing encryption. Despite the failure, the actor exfiltrated sensitive data within five hours.
1 IoCs 1 Actors
Curiouser and Curiouser

22h ago · talos

Cisco Talos discovered 'JWR', a previously undocumented real-time phishing framework and likely variant of the 'The Outsider' phishing-as-a-service platform. JWR uses open WebSocket connections to enable attackers to monitor victim keystrokes in real time and dynamically guide them through fake login and checkout flows. The campaign is currently distributed via SMS lures impersonating regional toll and postal authorities, allowing threat actors to steal payment data, two-factor authentication (2FA) codes, identity documents, and device fingerprints.
15 IoCs
Microsoft patches LegacyHive Windows zero-day vulnerability

22h ago · bleeping-computer

Microsoft has patched a Windows zero-day vulnerability known as 'LegacyHive' (CVE-2026-62832), which affects the Windows User Profile Service and allows authenticated local attackers to gain administrator privileges by exploiting improper link resolution during registry hive loading. The vulnerability was publicly disclosed and demonstrated by security researcher Nightmare Eclipse, who criticized Microsoft's disclosure practices. Exploitation does not require user interaction and enables privilege escalation by modifying another user's registry hive when they log in.
Hackers breach govt webmail while running parallel crypto fraud

22h ago · bleeping-computer

The China-based threat actor Jewelbug (also known as Earth Alux and REF7707) has been conducting espionage operations against government and military organizations in the Middle East, Southeast Asia, and South Asia, while simultaneously running a large-scale cryptocurrency fraud operation. The group compromised a shared webmail platform used by multiple government tenants, injecting a malicious script into login and mailbox pages to steal cookies and credentials. Successful compromises led to the deployment of the Antino backdoor via fake Adobe Flash installers, enabling further payload delivery, including a malicious browser extension called 'PDF Viewer' that steals credentials and injects JavaScript. Symantec uncovered the group's infrastructure, revealing over one million implant check-ins, more than 580,000 stolen browser cookies, and extensive cryptocurrency fraud operations using AI-generated content and lookalike domains impersonating Binance and OKX.
2 IoCs 2 Actors
Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List.

23h ago · step-security

Team PCP, a threat actor active in 2026, executed a widespread software supply chain attack by compromising trusted open source projects such as Trivy, KICS, telnyx, and LiteLLM. The group injected credential stealers into CI/CD pipelines, exfiltrating 78,330 secrets from 2,186 organizations between March 19 and 24, 2026. These stolen credentials included cloud access keys, API tokens, and private keys, enabling further pivoting across organizations. The attack targeted CI/CD environments due to their weak security posture despite handling highly privileged credentials.
6 IoCs