Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List.

14m ago · step-security

Team PCP, a threat actor active in 2026, executed a widespread software supply chain attack by compromising trusted open source projects such as Trivy, KICS, telnyx, and LiteLLM. The group injected credential stealers into CI/CD pipelines, exfiltrating 78,330 secrets from 2,186 organizations between March 19 and 24, 2026. These stolen credentials included cloud access keys, API tokens, and private keys, enabling further pivoting across organizations. The attack targeted CI/CD environments due to their weak security posture despite handling highly privileged credentials.
6 IoCs
Trezor discloses data breach affecting nearly 14,000 customers

1h ago · bleeping-computer

Trezor disclosed a data breach affecting nearly 14,000 customers due to a compromise of its shipping provider, ShipMonk, which was breached via a zero-day SQL injection vulnerability in the analytics platform Metabase. The attackers accessed customer order data including names, email addresses, phone numbers, and shipping addresses. ShipMonk confirmed the breach stemmed from exploitation of a critical vulnerability in Metabase, which was also used to attack other companies like Framework and Tally. Trezor emphasized that its own systems were not compromised and device security remains intact, but warned affected users of increased phishing risks. The ShinyHunters extortion group has claimed responsibility, sending extortion emails to ShipMonk.
1 Actors
Critical VMware vCenter RCE flaw exploited for reverse SSH access

30m ago · bleeping-computer

A critical directory traversal vulnerability in VMware vCenter Syslog Server (CVE-2026-59310) is being actively exploited to gain remote code execution. Attackers are deploying the open-source reverse_ssh framework to establish reverse SSH connections for persistence and remote access. Compromised systems have been observed connecting to attacker infrastructure starting August 3, with 361 victim IPs identified across 47 countries by August 7. The campaign is suspected to be conducted by an advanced persistent threat (APT) actor, though attribution remains unconfirmed.
Dissecting the JWR phishing framework

7h ago · talos

Cisco Talos identified a new phishing framework named JWR, likely a variant of the 'Outsider' PhaaS platform, used in active smishing campaigns targeting users in Southeast Asia and the Middle East. The framework enables real-time, operator-driven session manipulation via AES-CTR encrypted WebSocket connections, allowing threat actors to harvest payment data, login credentials, 2FA codes, identity documents, and full device fingerprints. The client engine uses Vue.js to render 44 phishing pages and supports live keystroke streaming, enabling actors to monitor victim input as it is typed. The campaign delivers the phishing kit via SMS lures impersonating toll, postal, and courier services, with operator interfaces in Simplified Chinese, indicating a Chinese-speaking actor.
7 IoCs
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

11h ago · hacker-news

Threat actors are actively exploiting a critical authentication bypass vulnerability in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS score: 9.1), following the public release of a proof-of-concept (PoC) exploit by Rapid7. The flaw allows unauthenticated attackers to forge JWT tokens and impersonate SharePoint users by exploiting weaknesses in the JWT validation pipeline, specifically within SPJsonWebSecurityTokenHandlerV2 and SPJsonWebSecurityBaseTokenHandlerV2 classes. Exploitation enables unauthorized access to files and data modification on vulnerable servers. Telemetry shows a spike in exploitation attempts originating from multiple countries, with 12 observed attempts as of mid-August 2026, eight of which occurred immediately after the PoC release.
8 IoCs
Android malware combo takes out loans and relays victims' credit cards

18h ago · bleeping-computer

A new Android malware campaign combines WindRelay, an NFC relay tool, with the SpyNote remote administration trojan to enable real-time financial fraud. Attackers socially engineer victims by impersonating bank employees, tricking them into sideloading a malicious APK that grants Accessibility Services, enabling remote device control. The attackers then install WindRelay to capture NFC payment card data and PINs during live phone calls, allowing them to conduct fraudulent transactions or take out loans in the victim's name. The attack chain was executed entirely over a 13-minute call, highlighting a shift toward real-time, voice-mediated social engineering without requiring persistent malware access.
6 IoCs 2 Malware
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

18h ago · bleeping-computer

The City-Forum data theft campaign targets misconfigured Salesforce Experience Cloud and ServiceNow portals by exploiting overly permissive guest user access. Attackers use a single server at IP 158.220.87.79 to enumerate and steal data exposed to unauthenticated users via custom techniques on both legacy Aura and newer Lightning Web Runtime (LWR) frameworks in Salesforce, as well as the ServiceNow Service Portal search API. The campaign has been active since at least March 2025, with increasing activity across multiple sectors including finance, telecom, and public-sector organizations. No vulnerability is exploited; instead, the theft relies on misconfigurations that allow public access to sensitive records.
2 IoCs 1 Actors
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

20h ago · bleeping-computer

Hackers are actively exploiting a critical vulnerability, CVE-2026-71362, in Adobe Commerce and Magento platforms to hijack customer accounts without authentication or user interaction. The flaw stems from improper handling of customer identity in account sessions, allowing attackers to switch between customer accounts. Security firm Sansec has observed exploitation attempts in the wild and confirms that the vulnerability enables unauthorized access to private customer data. Adobe released patches as isolated updates, urging administrators to apply them immediately to mitigate risk.
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

23h ago · hacker-news

The North Korean threat actor Lazarus Group has exploited a Windows zero-day vulnerability, CVE-2026-68820, in the AFD.sys driver to escalate privileges to SYSTEM and deploy a new in-memory backdoor named Troy. The attack is part of Operation Dream Job, a long-running cyber espionage campaign using fake job offers on LinkedIn to lure victims into downloading trojanized software or opening malicious PDFs. Two infection chains were observed: one using DLL side-loading with the malicious libmupdf.dll and another via a trojanized SecurityPDF viewer that triggers payload execution upon detecting a specific marker in a PDF. The attackers also use compromised legitimate infrastructure, including WordPress, SharePoint, and vulnerable Roundcube servers (CVE-2025-49113), to host C2 communications and distribute the ForestTiger (ScoringMathTea) backdoor.
7 IoCs 1 Actors 4 Malware 1 CVEs
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

1d ago · bleeping-computer

Researchers Alejandro Hernando and Borja Martínez disclosed 'Plug and Pwn' attack techniques that exploit Windows Plug and Play to gain SYSTEM privileges by emulating malicious USB devices. The attacks abuse signed vendor software installed automatically by Windows during device enumeration, leveraging vulnerabilities in co-installers, services, or insecure update mechanisms. One variant, 'NoPlug & Pwn', abuses RDP USB redirection to perform the attack remotely without physical access. A demonstrated chain uses emulated Sierra Wireless and Sony FeliCa devices to manipulate DNS and hijack unencrypted downloads, ultimately achieving code execution as SYSTEM. Another RDP-based variant emulates an Intel RealSense camera to exploit DLL hijacking in a co-installer for privilege escalation.
1 IoCs