Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
6h ago · hacker-news
Two trojanized npm packages, 'bianira-ui' and 'fluid-type-ui', have been identified as part of a malicious campaign leveraging a novel blockchain-based command-and-control (C2) technique dubbed NullReceiver. This method, attributed to North Korean threat actors, encodes the C2 server IP address within the recipient address of zero-value Ethereum transactions, eliminating the need for smart contracts or calldata payloads. The malware decodes the IP address from the first four bytes of the transaction's destination address and connects to it, with the decoded IP being 166.88.134[.]62. The technique improves stealth and resilience by using throwaway addresses and minimizing on-chain footprint.
8 IoCs
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
4h ago · hacker-news
Two critical vulnerabilities in Paperclip, an open-source AI agent control plane, allow remote code execution on server or developer machines via malicious agent imports. CVE-2026-41679 enables unauthenticated attackers to register and import a malicious agent configuration that executes commands with server privileges due to insufficient access controls during company creation. A second path exploits DNS rebinding in local_trusted mode, where a malicious website can trigger command execution on localhost by rebinding a hostname to 127.0.0.1 and invoking the import API. A third vulnerability, GHSA-xfqj-r5qw-8g4j, exposes sensitive API routes without proper authentication, potentially leaking control-plane details and allowing unauthorized access to heartbeat data and system health information.
1 CVEs
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
1h ago · hacker-news
A macOS-focused threat operation leveraging over 250 front-end domains employs browser fingerprinting to selectively serve malware lures to genuine Mac users while evading crawlers and sandbox environments. The fingerprinting script collects navigator properties, screen dimensions, WebGL signals, timezone, iframe detection, touch support, developer console activity, and codec capability checks to determine if the visitor is a real Mac user. Qualified users are presented with a fake GitHub-themed 'Download for macOS' page that delivers the Atomic Stealer (AMOS) infostealer via an obfuscated Terminal command. The command retrieves additional scripts from a /curl/<id> endpoint and executes payloads that target credentials, browser data, authentication stores, cryptocurrency wallets, and sensitive files.
4 IoCs 1 Malware
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
4h ago · bleeping-computer
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies of active exploitation of three critical vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat. The Langflow flaw (CVE-2026-9198) allows unauthenticated remote code execution by chaining API endpoints, with proof-of-concept exploits publicly available. A second Langflow vulnerability (CVE-2026-0770) is also being exploited for root-level remote code execution. The N-central vulnerability (CVE-2026-18576) enables attackers to hijack administrative accounts without authentication, despite prior patching attempts. The Apache Tomcat flaw (CVE-2026-34486), stemming from an incomplete fix for a prior encryption issue, is being exploited by a Chinese-speaking threat actor to deploy reverse shells. CISA has added all three CVEs to its Known Exploited Vulnerabilities catalog and mandated mitigation within three days.
4 CVEs
COLDCARD security audit phishing attack installs remote access tool
2h ago · bleeping-computer
A phishing campaign impersonating COLDCARD is distributing a malicious batch file named Coldcard_Diagnostic_Tool.bat, which installs ScreenConnect remote access software to gain persistent control over victims' systems. The attack leverages fears around a recent COLDCARD wallet vulnerability and a $88.6 million Bitcoin theft, using spoofed emails and a fake website (coldcardcompliance.com) to trick users into downloading the payload. The batch file drops and executes a signed ScreenConnect installer disguised as a legitimate diagnostic tool, connecting to a command-and-control server at activeretirementrelocation[.]com, enabling remote access, data theft, and potential ransomware deployment.
6 IoCs
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
5h ago · hacker-news
Veeam, HashiCorp, and Django have released patches for critical vulnerabilities in their software. Veeam's Service Provider Console has two critical flaws: CVE-2026-58073 allows unauthenticated attackers to impersonate managed agents and steal credentials (CVSS 9.5), and CVE-2026-58072 enables arbitrary file write leading to remote code execution with low-privilege access (CVSS 9.0). HashiCorp's Terraform MCP Server has a CVSS 10.0 cross-tenant vulnerability (CVE-2026-16498) due to improper session isolation in stateless HTTP mode, allowing token reuse across users. Django patched a high-severity flaw in GeoDjango (CVE-2026-15307) that could allow file writes and potentially remote code execution via spatial lookups accessible to staff users.
3 CVEs
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
9h ago · hacker-news
GitGuardian researchers identified 321 exposed and still-valid n8n API tokens in public GitHub commits, enabling unauthorized access to sensitive automation workflows, execution data, and stored credentials. Attackers can exploit these tokens to enumerate users, read or exfiltrate data, use or extract stored credentials (e.g., OpenAI API keys), and map high-risk configurations via the audit endpoint—all without exploiting a software vulnerability. The tokens remain valid due to missing expiration dates and poor credential hygiene, with some instances hosted on managed services like n8n.cloud. Responsible disclosure efforts met limited success, highlighting ongoing exposure risks.
2 IoCs 1 CVEs
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
8h ago · hacker-news
A critical vulnerability in Gitea, tracked as CVE-2026-59774, allows unauthenticated attackers to read arbitrary files accessible by the Gitea service account by exploiting the Org-mode markup renderer. The flaw exists in versions 1.22.1 through 1.27.0 and is triggered via a crafted Org-mode #+INCLUDE directive processed by the /{owner}/{repo}/markup endpoint. Although not direct remote code execution, attackers can chain the file-read capability with reading app.ini to extract the INTERNAL_TOKEN and subsequently inject Git hooks to achieve command execution. The vulnerability was discovered by XBOW Security and independently reported by Shai Rod, with no known in-the-wild exploitation observed at the time of disclosure.
2 CVEs
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
8h ago · hacker-news
A memory corruption vulnerability in the Linux kernel's Open vSwitch (OVS) datapath, tracked as CVE-2026-64531 and dubbed OVSwrap, allows local users to escalate privileges to root. The flaw stems from a 16-bit length field wraparound when processing Netlink attributes in OVS flow installation, which can be triggered without requiring existing OVS bridges or daemons. A public proof-of-concept exploit achieves reliable local privilege escalation by chaining kernel pointer leaks, arbitrary reads, and targeted decrements to modify credentials and gain root access. The exploit supports around 800 kernel builds and leaves behind modified sudoers files and persistent root shells. Default installations of numerous Linux distributions are vulnerable if Open vSwitch is enabled and unprivileged user namespaces are allowed.
1 CVEs
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
14h ago · hacker-news
A long-standing supply chain attack has affected QuickFox, a VPN and network acceleration tool, since at least August 2025. The malicious Windows installer, starting from version 3.0.51.0, delivers a backdoor called FDMTP via a trojanized Electron-based application. The attack uses a JavaScript loader that fingerprints the victim endpoint and downloads the payload from a malicious domain, cdns3.51quickfox[.]cn, which mimics the legitimate domain. The malware employs DLL side-loading to execute FDMTP, which communicates with a C2 server to exfiltrate system information and download additional plugins, targeting users such as Chinese expatriates and professionals interacting with Chinese speakers.
5 IoCs 1 Actors 1 Malware