Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
2h ago · hacker-news
Threat actors are actively exploiting a critical authentication bypass vulnerability in Microsoft SharePoint, tracked as CVE-2026-55040 (CVSS score: 9.1), following the public release of a proof-of-concept (PoC) exploit by Rapid7. The flaw allows unauthenticated attackers to forge JWT tokens and impersonate SharePoint users by exploiting weaknesses in the JWT validation pipeline, specifically within SPJsonWebSecurityTokenHandlerV2 and SPJsonWebSecurityBaseTokenHandlerV2 classes. Exploitation enables unauthorized access to files and data modification on vulnerable servers. Telemetry shows a spike in exploitation attempts originating from multiple countries, with 12 observed attempts as of mid-August 2026, eight of which occurred immediately after the PoC release.
8 IoCs
Android malware combo takes out loans and relays victims' credit cards
10h ago · bleeping-computer
A new Android malware campaign combines WindRelay, an NFC relay tool, with the SpyNote remote administration trojan to enable real-time financial fraud. Attackers socially engineer victims by impersonating bank employees, tricking them into sideloading a malicious APK that grants Accessibility Services, enabling remote device control. The attackers then install WindRelay to capture NFC payment card data and PINs during live phone calls, allowing them to conduct fraudulent transactions or take out loans in the victim's name. The attack chain was executed entirely over a 13-minute call, highlighting a shift toward real-time, voice-mediated social engineering without requiring persistent malware access.
6 IoCs 2 Malware
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
9h ago · bleeping-computer
The City-Forum data theft campaign targets misconfigured Salesforce Experience Cloud and ServiceNow portals by exploiting overly permissive guest user access. Attackers use a single server at IP 158.220.87.79 to enumerate and steal data exposed to unauthenticated users via custom techniques on both legacy Aura and newer Lightning Web Runtime (LWR) frameworks in Salesforce, as well as the ServiceNow Service Portal search API. The campaign has been active since at least March 2025, with increasing activity across multiple sectors including finance, telecom, and public-sector organizations. No vulnerability is exploited; instead, the theft relies on misconfigurations that allow public access to sensitive records.
2 IoCs 1 Actors
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
11h ago · bleeping-computer
Hackers are actively exploiting a critical vulnerability, CVE-2026-71362, in Adobe Commerce and Magento platforms to hijack customer accounts without authentication or user interaction. The flaw stems from improper handling of customer identity in account sessions, allowing attackers to switch between customer accounts. Security firm Sansec has observed exploitation attempts in the wild and confirms that the vulnerability enables unauthorized access to private customer data. Adobe released patches as isolated updates, urging administrators to apply them immediately to mitigate risk.
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
14h ago · hacker-news
The North Korean threat actor Lazarus Group has exploited a Windows zero-day vulnerability, CVE-2026-68820, in the AFD.sys driver to escalate privileges to SYSTEM and deploy a new in-memory backdoor named Troy. The attack is part of Operation Dream Job, a long-running cyber espionage campaign using fake job offers on LinkedIn to lure victims into downloading trojanized software or opening malicious PDFs. Two infection chains were observed: one using DLL side-loading with the malicious libmupdf.dll and another via a trojanized SecurityPDF viewer that triggers payload execution upon detecting a specific marker in a PDF. The attackers also use compromised legitimate infrastructure, including WordPress, SharePoint, and vulnerable Roundcube servers (CVE-2025-49113), to host C2 communications and distribute the ForestTiger (ScoringMathTea) backdoor.
7 IoCs 1 Actors 4 Malware 1 CVEs
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
16h ago · bleeping-computer
Researchers Alejandro Hernando and Borja Martínez disclosed 'Plug and Pwn' attack techniques that exploit Windows Plug and Play to gain SYSTEM privileges by emulating malicious USB devices. The attacks abuse signed vendor software installed automatically by Windows during device enumeration, leveraging vulnerabilities in co-installers, services, or insecure update mechanisms. One variant, 'NoPlug & Pwn', abuses RDP USB redirection to perform the attack remotely without physical access. A demonstrated chain uses emulated Sierra Wireless and Sony FeliCa devices to manipulate DNS and hijack unencrypted downloads, ultimately achieving code execution as SYSTEM. Another RDP-based variant emulates an Intel RealSense camera to exploit DLL hijacking in a co-installer for privilege escalation.
1 IoCs
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
18h ago · hacker-news
A large-scale campaign involving 737 malicious Chrome VPN and proxy extensions has been uncovered, primarily targeting Russian-speaking users. These extensions impersonate 66 legitimate VPN brands and route users' entire browser traffic through SOCKS5 proxies controlled by a single threat actor, enabling adversary-in-the-middle (AitM) monitoring of destinations, IP addresses, SNI values, and unencrypted HTTP traffic. The extensions bypass Chrome Web Store policies by submitting false claims, using code obfuscation, and performing post-approval code substitution to hide malicious behavior, including non-existent premium tiers and affiliate monetization schemes.
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
1d ago · hacker-news
A high-severity vulnerability, CVE-2026-20349, in Cisco Secure Firewall ASA and FTD software is being actively exploited in the wild to trigger remote denial-of-service (DoS) conditions. The flaw stems from insufficient error checking when processing crafted HTTP requests sent to the Remote Access SSL VPN service, allowing unauthenticated attackers to cause affected devices to reload. Cisco confirms the vulnerability was discovered internally and has been exploited, with no workarounds available. The U.S. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by August 14, 2026.
33 IoCs
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
23h ago · hacker-news
Threat actors are actively exploiting CVE-2026-59310, a critical directory traversal vulnerability in VMware vCenter, to achieve remote code execution and establish persistence via malicious cron jobs. The attackers deploy reverse_ssh, an open-source tool, to create reverse SSH connections to their infrastructure, enabling them to bypass inbound security controls. Forensic evidence from QUIRSO confirms successful compromises beginning August 3, with 361 victim IPs across 47 countries. While the specific actor is not identified, the campaign exhibits characteristics consistent with an advanced persistent threat, and exploitation closely follows public disclosure of the vulnerability.
2 IoCs 1 Actors 1 Malware
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
21h ago · hacker-news
Adobe has released security updates to address multiple critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. The most severe flaws include three with a CVSS score of 10.0, which could allow arbitrary code execution or privilege escalation if exploited. These vulnerabilities affect on-premise and hybrid deployments of Campaign Classic, while Adobe-hosted instances have already been patched. Although no active exploitation has been observed, Adobe assigns a Priority 1 rating to these updates due to their high risk, urging administrators to apply patches within 72 hours.