Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
2h ago · hacker-news
A large-scale campaign involving 737 malicious Chrome VPN and proxy extensions has been uncovered, primarily targeting Russian-speaking users. These extensions impersonate 66 legitimate VPN brands and route users' entire browser traffic through SOCKS5 proxies controlled by a single threat actor, enabling adversary-in-the-middle (AitM) monitoring of destinations, IP addresses, SNI values, and unencrypted HTTP traffic. The extensions bypass Chrome Web Store policies by submitting false claims, using code obfuscation, and performing post-approval code substitution to hide malicious behavior, including non-existent premium tiers and affiliate monetization schemes.
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
10h ago · hacker-news
A high-severity vulnerability, CVE-2026-20349, in Cisco Secure Firewall ASA and FTD software is being actively exploited in the wild to trigger remote denial-of-service (DoS) conditions. The flaw stems from insufficient error checking when processing crafted HTTP requests sent to the Remote Access SSL VPN service, allowing unauthenticated attackers to cause affected devices to reload. Cisco confirms the vulnerability was discovered internally and has been exploited, with no workarounds available. The U.S. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by August 14, 2026.
33 IoCs
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
7h ago · hacker-news
Threat actors are actively exploiting CVE-2026-59310, a critical directory traversal vulnerability in VMware vCenter, to achieve remote code execution and establish persistence via malicious cron jobs. The attackers deploy reverse_ssh, an open-source tool, to create reverse SSH connections to their infrastructure, enabling them to bypass inbound security controls. Forensic evidence from QUIRSO confirms successful compromises beginning August 3, with 361 victim IPs across 47 countries. While the specific actor is not identified, the campaign exhibits characteristics consistent with an advanced persistent threat, and exploitation closely follows public disclosure of the vulnerability.
2 IoCs 1 Actors 1 Malware
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
5h ago · hacker-news
Adobe has released security updates to address multiple critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. The most severe flaws include three with a CVSS score of 10.0, which could allow arbitrary code execution or privilege escalation if exploited. These vulnerabilities affect on-premise and hybrid deployments of Campaign Classic, while Adobe-hosted instances have already been patched. Although no active exploitation has been observed, Adobe assigns a Priority 1 rating to these updates due to their high risk, urging administrators to apply patches within 72 hours.
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
5h ago · hacker-news
A vulnerability in reasoning APIs used by OpenAI, Anthropic, and Google allowed attackers to recover hidden internal reasoning and sensitive data such as API keys, passwords, and private keys from encrypted reasoning blocks. The flaw enabled cross-session and cross-model replay attacks, where encrypted reasoning objects from one session could be replayed in another, even using weaker models as 'fuzzy decoders' to extract secrets. Researchers analyzed 6,708 public agent trajectories and recovered 704 distinct privacy artifacts, including 62 API keys and 33 passwords, primarily from unsanitized published logs. While vendors have implemented mitigations, the research highlights ongoing risks from already-published reasoning blocks and the potential for invisible prompt injection attacks.
Hackers leverage new Microsoft SharePoint exploit in attacks
4h ago · bleeping-computer
Attackers are actively exploiting CVE-2026-55040, a critical authentication bypass vulnerability in Microsoft SharePoint's JWT token validation pipeline, to perform unauthorized actions as SharePoint users or administrators. A proof-of-concept exploit was published by Rapid7 and has already been weaponized, with attacks observed targeting SharePoint honeypots. Microsoft patched the vulnerability in its July 2026 updates, but over 8,500 SharePoint servers remain exposed online. CISA has issued warnings urging organizations to secure internet-facing SharePoint servers and apply security hardening measures.
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
8h ago · hacker-news
Malicious versions 1.82.7 and 1.82.8 of the open-source LiteLLM package were uploaded to PyPI on March 24, 2026, and remained available for approximately 40 minutes before being quarantined. These compromised releases contained a credential-stealing payload that collected environment variables, SSH keys, cloud credentials, Kubernetes tokens, and database passwords, exfiltrating them to the domain models.litellm[.]cloud. The incident is part of the broader TeamPCP supply-chain campaign, linked to the earlier compromise of Aqua Security's Trivy scanner, which allowed attackers to gain access to PyPI publishing tokens. The attack potentially exposed over 2,100 organizations, with stolen data including sensitive CI/CD secrets that remain exploitable if not rotated.
6 IoCs 1 CVEs
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
6h ago · bleeping-computer
A new zero-day vulnerability dubbed 'ShieldBreak' has been disclosed by security researcher Nightmare Eclipse, exploiting a bypass in Microsoft Defender that allows privilege escalation to SYSTEM level on fully patched Windows 10, 11, and Server systems. The flaw effectively circumvents the patch for CVE-2026-50656 (RoguePlanet), which Microsoft had previously addressed. The exploit has been successfully tested on Windows 11 25H2 (Canary) and Windows Server 2025 with a 100% success rate. Microsoft Defender must be enabled for the exploit to work, and the vulnerability remains unpatched at the time of publication.
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
10h ago · hacker-news
Security researcher Chaotic Eclipse has released a proof-of-concept (PoC) exploit called ShieldBreak, which demonstrates a full patch bypass for CVE-2026-50656 (RoguePlanet), a previously patched Microsoft Defender for Windows vulnerability. The original flaw was a race condition in the Microsoft Malware Protection Engine (mpengine.dll) that could allow privilege escalation to SYSTEM-level access. ShieldBreak allegedly achieves 100% success in bypassing the fix on Windows 11 25H2 and Windows Server 2025, indicating the patch was incomplete. Microsoft is investigating follow-up reports of data leakage during file operations, and the vulnerability remains exploitable despite prior remediation efforts.
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
9h ago · hacker-news
SAP has patched a critical vulnerability, CVE-2026-58231, in SAP Commerce Cloud (Data Hub Adapter) that allows unauthenticated attackers to execute arbitrary code due to insufficient authorization checks and input validation. The flaw enables exploitation by abusing a default authentication client and submitting crafted input, leading to compromise of internal components with high impact on confidentiality, integrity, and availability. SAP recommends applying the patch and re-deploying the updated version, or implementing an IP Filter Set as a temporary mitigation. Three additional critical vulnerabilities were also addressed in the same update, including code injection and memory corruption flaws in other SAP products.