Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

16h ago · hacker-news

Cryptocurrency exchange Bitget suffered a $387.5 million theft after attackers exploited a zero-day vulnerability in a third-party security product, gaining access to internal credentials and deploying malicious tools to bypass risk controls. The attackers compromised multiple nodes by running hidden scripts to extract database credentials and laterally moved into Bitget's wallet environment using compromised security appliances. Forensic analysis by SlowMist and Mandiant linked the attack to North Korean threat actors, who used a custom tool to execute unauthorized withdrawals across 11 blockchains. The breach began as early as August 31, 2026, with command-and-control established via a web shell on security appliance B.
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

6h ago · hacker-news

A sophisticated WordPress backdoor named SC has been identified, utilizing a self-healing mesh of persistence mechanisms across files, database entries, and shared memory segments to resist removal. The malware, which hides using obfuscated code and a substitution cipher decoder, is capable of rebuilding itself from any surviving component, including hidden files, mu-plugins, themes, and System V shared memory. It can communicate with a C2 server via the Ethereum blockchain, create hidden admin accounts, inject malicious JavaScript, and execute arbitrary PHP code. The backdoor spreads identical payloads across multiple locations, ensuring reinfection even after partial cleanup.
8 IoCs
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

4h ago · hacker-news

KillSec, a ransomware group active since at least 2021, transitioned to ransomware operations in October 2023 and began offering its tools as a ransomware-as-a-service in June 2024. The group extorted victims by stealing sensitive data, threatening to publish it unless ransoms were paid, and leveraging AI for infrastructure and victim identification. In September 2026, law enforcement in Spain, Germany, the UK, Romania, and Puerto Rico arrested three suspects, including a 16-year-old suspected administrator, and seized the group's leak site, servers, domains, and over 110 TB of data. The investigation uncovered approximately 500 confirmed successful attacks out of around 1,000 suspected incidents globally, with evidence of ransom payments in cryptocurrency.
1 IoCs
Kiteworks patches max severity code injection vulnerability

7h ago · bleeping-computer

Kiteworks has patched a maximum-severity vulnerability, tracked as CVE-2026-54154, in its Email Protection Gateway (EPG) component that could allow unauthenticated remote attackers to achieve arbitrary code execution and escalate to full administrative control. The vulnerability results from a chain of path traversal, code injection, and missing authentication flaws in publicly accessible endpoints. It affects all EPG releases prior to version 9.4.1, and successful exploitation does not require user interaction. Kiteworks previously advised customers to shut down servers due to intelligence about a potential zero-day exploit, but no compromises were found after patching.
Police dismantle KillSec ransomware gang allegedly led by 16-year-old

6h ago · bleeping-computer

Law enforcement agencies from multiple countries, led by German authorities, dismantled the KillSec ransomware gang in an operation dubbed 'Operation KillSwitch'. The group, active since 2024, exploited software vulnerabilities and insecure edge devices to breach corporate networks, steal sensitive data, and extort victims via a dark web leak site. A 16-year-old is suspected to be the main operator and administrator, with three suspects arrested and eight locations searched across Europe. Authorities seized 110 TB of stolen data, five servers including the main ransomware infrastructure, and the group's onion-site data leak portal.
1 IoCs
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

1d ago · hacker-news

Threat actors are conducting phishing campaigns using socially engineered lures to distribute a maliciously repackaged, digitally signed MSP360 RMM installer. Once executed, the installer establishes initial access and persistence, then deploys ConnectWise ScreenConnect to create a redundant remote access channel. This dual-RMM approach allows attackers to blend malicious activity with legitimate remote administration traffic, enabling post-compromise tool deployment and credential access. The same attack pattern has also been observed using Faronics Deploy Agent instead of MSP360, indicating a broader tactic of abusing legitimate remote management tools.
4 IoCs
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

1d ago · hacker-news

Threat actors are exploiting a patched command injection vulnerability, CVE-2026-73570, in Zimbra Collaboration Suite (ZCS) to achieve remote code execution without authentication. The flaw is triggered via a crafted SMTP request when SNMP notifications are enabled and the zimbra-snmp package is installed. Upon exploitation, attackers deploy JSP web shells, establish reverse shells, escalate privileges, and harvest authentication secrets including LDAP credentials and service account data. They also perform lateral movement using Zimbra's SSH identity and exfiltrate mailbox data, sometimes using cloud tools like AzCopy targeting Azure Blob storage.
6 IoCs 1 CVEs
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

16h ago · hacker-news

Threat actors are actively exploiting CVE-2026-88771, a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and Gateway, to execute arbitrary commands and deploy post-exploitation payloads. The attackers use malicious authentication attempts with usernames containing 'pitboss' and 'NSPPE' strings to trigger the vulnerability and drop web shells. Second-stage payloads include a Perl script that creates a privileged account, exfiltrates configuration data, and deploys a PHP web shell mapped to CSS-like URLs, as well as a Python script that establishes a reverse shell and kills specific processes. These actions enable persistent access, remote command execution, and data theft, with infrastructure tied to multiple malicious IPs.
6 IoCs
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

15h ago · hacker-news

Security researchers from Calif have published a proof-of-concept for CVE-2026-86950, a vulnerability in Apple's CoreGraphics framework that can be triggered by a malicious PDF containing a crafted embedded font, leading to a crash due to an out-of-bounds write. The flaw affects unpatched versions of iOS and macOS and was patched by Apple on September 28, 2026, after being reported by Meta Product Security. While no active exploit has been demonstrated, the vulnerability could serve as part of a zero-click attack chain, with circumstantial evidence suggesting WhatsApp as a potential delivery vector due to changes in its attachment scanning logic.
1 IoCs
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

10h ago · hacker-news

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-76504, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager, to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation observed in the wild. The flaw, which carries a CVSS score of 9.8, allows unauthenticated remote attackers to bypass authentication by sending a crafted HTTP request to the API, gaining admin-level access. Organizations are urged to apply patches immediately and review specific log files for signs of compromise, including suspicious POST requests to URL-encoded variants of '/j_security_check' and activity involving user accounts starting with 'viptela-reserved-'.
2 IoCs