Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
17h ago · hacker-news
Threat actors are leveraging the legitimate Node.js runtime (node.exe) to deliver malware in targeted attacks against government departments, technology firms, and hotels since February 2026. By using signed, trusted binaries and executing malicious JavaScript scripts, attackers evade signature-based detection. The attacks involve tools such as AdaptixC2, Cobalt Strike, ModeloRAT, Mistic (MLTBackdoor), GateKeeper, and C2Looper, with initial access often gained via the ClickFix social engineering technique. Attackers also abuse EtherHiding and blockchain-based C2 infrastructure for resilience, making blocking efforts difficult.
1 IoCs 4 Malware
Coder's registry infrastructure compromised to push malicious modules
8h ago · bleeping-computer
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers to distribute malicious Terraform modules. These modules contained credential-stealing code that targeted environment variables, API keys, CI/CD credentials, SSH keys, and other sensitive data from development environments. The malicious activity occurred between 07:35 UTC and 21:45 UTC on August 31, 2026, with stolen data exfiltrated to the domain coder-infra[.]com. Coder recommends rotating secrets, inspecting logs for connections to the suspicious domain, and purging potentially compromised cached modules.
1 IoCs
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
14h ago · hacker-news
Thomson Reuters disclosed a data breach affecting its C-Track court case management platform, which exposed sensitive personal information including Social Security numbers, driver's license numbers, and sealed or redacted court data. The unauthorized access occurred from March 1 to June 29, 2026, impacting court systems in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. The breach originated within Thomson Reuters' cloud environment, with backup data accessed without evidence of fraud or misuse to date. Investigations are ongoing, and affected individuals are being offered identity monitoring services.
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
22h ago · hacker-news
Security researcher Chaotic Eclipse (aka INFINITE NIGHTMARE) disclosed a zero-day privilege escalation vulnerability in CrowdStrike Falcon Sensor dubbed FalconFlank, which exploits the product's handling of malicious Office macros. A proof-of-concept (PoC) has been released and reportedly works on fully updated Windows 11 25H2 and Windows Server 2025 systems with Falcon installed. The researcher also previously disclosed similar zero-days in Kaspersky's endpoint product (HardBreacher) and Microsoft Defender (ShieldBreak, CVE-2026-69414), the latter of which remains unpatched. The researcher claims Microsoft has not responded to their reports, prompting public disclosure.
2 IoCs
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
16h ago · hacker-news
A widespread RMM phishing campaign has targeted 46 countries, with the United States now the top target, accounting for 45% of observed activity. Attackers use social engineering lures tailored to specific regions, including tax forms, shipping notices, and Adobe PDFs, to trick victims into installing legitimate remote monitoring and management (RMM) software for malicious purposes. The campaign leverages rapidly rotating infrastructure hosted on Vercel, GitHub Pages, Netlify, and other platforms, with 94% of domains active for only one day, complicating detection. Persistent artifacts such as shared resources (e.g., font1.woff2, icons8-microsoft-word-94.png) and a consistent delivery pattern (secure.html → project/*.zip) link disparate infrastructure to the same operation, indicating a coordinated and adaptive threat.
4 IoCs
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
18h ago · unit42
Unit 42 identified two ongoing attack campaigns—CL-CRI-1131 and CL-CRI-1163—targeting organizations in Latin America, leveraging AI tools to enhance operational efficiency. The Mexican transportation campaign (CL-CRI-1131) targeted government and transportation entities, using living-off-the-land techniques, volume shadow copy manipulation, and a self-hosted NextChat instance on IP 178.128.87.160 for AI-assisted scripting. The Brazilian financial campaign (CL-CRI-1163) involved phishing via resume-themed emails, deployment of a custom Go-based SOCKS5 proxy (SockTz), and use of AI-generated script names hosted on exposed infrastructure at 167.148.195.53. Both campaigns exhibited operational security failures, including exposed certificates and open directories, enabling threat researchers to track and analyze their infrastructure.
17 IoCs
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
23h ago · hacker-news
CISA has added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including critical flaws in SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and Berri LiteLLM. Threat actors are exploiting these vulnerabilities to deploy reverse shells, execute arbitrary code, steal credentials, and deploy cryptocurrency miners. Exploitation of CVE-2026-83548 and CVE-2026-83549 in SonicWall devices has been confirmed, while CVE-2026-9586 and CVE-2026-82329 are being used to gain administrative access and conduct post-exploitation activities. Microsoft and Wiz report active exploitation of CVE-2026-42271 and CVE-2026-48710 in LiteLLM deployments, with attackers achieving remote code execution and stealing API keys, and CVE-2026-49869 in Kestra being used to establish reverse shells and deploy miners.
3 Malware 4 CVEs
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
19h ago · hacker-news
A member of Serbia's student protest movement had their iPhone infected with NSO Group's Pegasus spyware via an iMessage zero-click exploit between December 2025 and January 2026. The exploit has since been patched in iOS 18.4.1. At least 14 individuals in Serbia, including activists and opposition figures, have been targeted with advanced spyware in 2026, coinciding with local elections. A new variant of NoviSpy Android spyware was also identified, suggesting ongoing surveillance operations by Serbian authorities or affiliated actors.
1 Malware
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
1d ago · bleeping-computer
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform, to achieve remote code execution. The flaw exists in the /pa HTTP endpoint, which processes XML messages and improperly concatenates user-controlled input into SQL queries. Exploitation has been observed in the wild, with attackers attempting to deploy reverse shells and exfiltrate system information. Horizon3 observed multiple exploit attempts originating from a single IP address, indicating widespread targeting of internet-exposed Switchvox systems.
1 IoCs
The invisible passenger in your car
1w ago · securelist
A new multi-stage Android malware has been discovered targeting automotive head units via compromised firmware update mechanisms. The malware, distributed through the legitimate TWCore app's update function, operates in three stages: an initial dropper (JarService), a loader, and a final stage that performs ad fraud and establishes a reverse proxy botnet. The infection chain leverages MQTT-based commands and downloads malicious payloads from attacker-controlled servers. This campaign is attributed to the MoYu Group, a threat actor associated with the BADBOX botnet, based on code similarities, infrastructure overlap, and naming patterns observed in other compromised devices such as TV set-top boxes.
35 IoCs 1 Malware