Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

3h ago · bleeping-computer

The Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, warning that they are actively exploited in attacks. These include a critical authentication bypass flaw (CVE-2026-5430) in WSO2 products, an incorrect authorization vulnerability (CVE-2026-71362) in Adobe Commerce and Magento, a high-severity code injection flaw (CVE-2026-65660) in Microsoft SharePoint, and a medium-severity SSH state-machine bypass (CVE-2026-67279) in Mikrotik RouterOS. Security firm watchTowr observed exploitation attempts against WSO2 using forged JWT tokens, and Sansec reported active exploitation of the Adobe Commerce flaw in the wild. Federal agencies are required to patch these flaws by September 27–28, 2026.
1 IoCs 1 CVEs
Elementor WordPress flaw lets attackers create admin accounts

3h ago · bleeping-computer

A cross-site request forgery (CSRF) vulnerability in Elementor plugin versions 4.3.0 and 4.3.1 for WordPress allows unauthenticated attackers to create administrator accounts by tricking a logged-in administrator into opening a malicious link. The flaw exists in the Editor Events module, which bypasses WordPress REST nonce validation when the request URI contains the 'elementor/v1/events/' path, enabling attackers to append this path via query parameters to trigger unauthorized REST API actions. The vulnerability was reported by security firm Patchstack and patched in version 4.3.2, with no CVE assigned at the time of reporting.
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

10h ago · hacker-news

Cryptocurrency exchange Bitget suffered a $351.6 million theft from its hot and warm wallets, attributed to suspected North Korean threat actors. The attackers compromised a critical backend system, spoofed transaction data, and triggered unauthorized fund transfers. While customer balances remain intact and cold wallets were unaffected, withdrawals have been suspended during a security review. Bitget has engaged Mandiant and SlowMist for investigation and is collaborating with blockchain foundations to freeze hacker-controlled wallet addresses. The attack pattern aligns with known North Korean hacking groups based on IP behavior and on-chain analysis.
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

8h ago · hacker-news

A new variant of the PamStealer macOS malware has been identified, featuring live command-and-control (C2) payload decryption and multi-layer persistence mechanisms. The malware is distributed via a fake cryptocurrency wallet website (wavel[.]app), which delivers a malicious disk image containing a compiled AppleScript that executes a JXA dropper. The dropper initiates a key exchange with the C2 server using X25519 to decrypt the payload, preventing static analysis. The malware employs four persistence methods, including LaunchAgent, shell hooks, and Git hooks, and ultimately deploys a Swift-based stealer to harvest credentials, browser data, keychain items, and system metadata.
5 IoCs
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

6h ago · hacker-news

Two compromised GitHub Actions, 'actions-cool/issues-helper' and 'actions-cool/maintain-one-comment', were reactivated on September 16, 2026, after being previously disabled due to their involvement in the Mini Shai-Hulud supply chain attack campaign. The repositories resumed serving malicious code that had been introduced on May 18, 2026, allowing credential harvesting from CI/CD pipelines without any new attacker action. The malicious payloads were re-downloaded and executed by workflows referencing the affected version tags, highlighting the risk of mutable version tags in supply chain security. The incident is linked to the Mini Shai-Hulud activity cluster, which also targeted npm packages under the @antv ecosystem.
4 IoCs
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud

10h ago · socket-dev

The compromised GitHub Actions repositories 'actions-cool/issues-helper' and 'actions-cool/maintain-one-comment' were re-enabled on September 16, 2026, while still hosting malicious code from the May 2026 Mini Shai-Hulud campaign. This reactivation allowed the malicious payload to execute in downstream workflows that referenced the actions by mutable tags, affecting an estimated 15,000+ repositories. The attack resumed without any new exploit or infrastructure, as the malicious tags were never cleaned. Workflows referencing these actions by tag instead of pinned commit SHA began executing the obfuscated payload, which installs the Bun runtime and runs a malicious script, potentially exfiltrating secrets and gaining unauthorized access.
4 IoCs
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

16h ago · hacker-news

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. CVE-2026-5430 is a path traversal flaw in WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway that enables unrestricted file upload and remote code execution. CVE-2026-71362 is an incorrect authorization vulnerability in Adobe Commerce and Magento that allows attackers to escalate privileges and access sensitive customer data without user interaction. Exploitation of both vulnerabilities has been observed in the wild, with attacks detected as early as September 10, 2026.
1 CVEs
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

16h ago · hacker-news

Cloudflare patched a vulnerability in its Containers and Sandboxes services that allowed a customer's container to read leftover disk data from previously deleted containers on the same server. The issue stemmed from thin-provisioned disks that were not properly wiped before reallocation, enabling data remnants—including SQLite databases, .env files, and browser profiles—to be recovered. The flaw was reported by researcher Oren Yomtov via Cloudflare's bug bounty program and was fixed by re-enabling block wiping and retiring all running container disks and caches. Cloudflare found no evidence of exploitation beyond authorized testing.
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

11h ago · hacker-news

A pre-authentication SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is being actively exploited in the wild. The flaw exists in the virtuser_query plugin of versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, allowing unauthenticated attackers to inject arbitrary SQL and potentially access mail account credentials and stored messages. The Canadian Centre for Cyber Security and SentinelOne have confirmed active exploitation, though specific threat actor details remain limited. Patches were released in May 2026, but over 500,000 Roundcube instances remain internet-exposed, with at least 10 identified as vulnerable as of late September 2026.
1 Malware 3 CVEs
Hackers steal $351.6 million in Bitget crypto exchange hack

12h ago · bleeping-computer

Cryptocurrency exchange Bitget suffered a breach in which $351.6 million was stolen from its hot and warm wallets. The attack is attributed to suspected North Korean hackers who compromised a critical backend system within Bitget's wallet infrastructure, enabling them to forge transaction data and trigger fund transfers. The breach affected multiple blockchain networks including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base, with XRP suffering the largest single-chain loss. Bitget has suspended withdrawals pending investigation and confirmed that its cold wallets and self-custodial Bitget Wallet were unaffected. The losses will be covered by the User Protection Fund.