Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service
1h ago · socket-dev
A malicious browser extension named 'Twitch Enhanced Viewer | JeetBot' available on Chrome and Firefox has been exfiltrating users' live Twitch OAuth session tokens to proxy servers controlled by a Russian commercial bot service. The extension, marketed as a quality-of-life tool for Twitch users, forwards the tokens via URL query parameters during video playlist proxying, exposing approximately 30,000 Chrome and 552 Firefox users to potential account compromise. Earlier versions actively collected and POSTed tokens to dedicated endpoints, while current versions silently leak tokens through inline forwarding, except for a hardcoded allowlist of ten Russian streamer channels.
20 IoCs
Hackers abused Claude to extract secrets from 1.8M Android apps
7h ago · bleeping-computer
Between December 2025 and August 2026, multiple threat groups abused Anthropic's Claude AI for malicious purposes, including credential harvesting, malware development, and reconnaissance. A suspected ShinyHunters affiliate named 'frkoo' automated the download and analysis of 1.8 million Android APKs to extract hardcoded secrets using TruffleHog, with findings sent to a Telegram group. The same actor harvested GitHub email addresses to obtain Personal Access Tokens, enabling breaches of corporate systems. Russian group Midnight Blizzard and Chinese-speaking GTG-10007 used Claude for AI-driven attack automation across multiple stages, including phishing, malware development, and exploit delivery, targeting government and private-sector organizations globally.
2 IoCs 2 Actors
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
13h ago · bleeping-computer
Threat actors are exploiting trusted AI platforms such as Claude, ChatGPT, and Grok by weaponizing shareable content features to distribute malware. Attackers created malicious Claude Artifacts and shared conversations that mimic legitimate software install guides or troubleshooting advice, hosted on the official domains of these platforms, to bypass user skepticism. These lures trick users into downloading SectopRAT, MacSync stealer, or AMOS stealer via malicious commands or redirects, leveraging the inherent trust in well-known domains. The campaigns are short-lived but effective, relying on SEO poisoning and sponsored search results to increase visibility.
3 IoCs 2 Malware
Florida confirms DMV database breached via stolen police account
8h ago · bleeping-computer
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a data breach of its DAVID driver database, which was accessed using compromised credentials from a Plant City Police Department employee's personal device. The ShinyHunters extortion group claimed responsibility, stating they exploited a password reset vulnerability to gain access to multiple accounts, including those of DMV employees and an FBI agent, then scraped driver records by iterating through record IDs. ShinyHunters provided a screenshot of a Jeffrey Epstein DAVID record as proof of compromise and later claimed they had lost access, likely due to patching. The breach impacted at least 200,000 driver records, though FLHSMV has not confirmed the exact number.
1 IoCs 1 Actors
Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
19h ago · hacker-news
Attackers exploited a chain of two vulnerabilities in self-hosted JFrog Artifactory instances—CVE-2026-42018 and CVE-2026-42016—to escalate privileges from unauthenticated access to full administrator control. By exploiting the first flaw to obtain an internal anonymous user token and then abusing the second to elevate it to admin scope, attackers created backdoored administrator accounts and deployed malicious Groovy plugins for code execution. In parallel, a separate critical vulnerability, CVE-2026-82329, allowed unauthenticated attackers to gain admin privileges directly, leading to theft of cluster join keys and deployment of custom Rust-based backdoors on compromised servers.
AI-powered attack exploited PaperCut flaws to hack 395 organizations
1d ago · bleeping-computer
A Russian-speaking threat actor leveraged AI-powered agents to rapidly develop and deploy exploits for CVE-2026-81578 and CVE-2026-82078, targeting vulnerable PaperCut NG/MF servers. The campaign, active since August 31, 2026, compromised at least 440 servers across 395 organizations in 48 countries, with a focus on the education sector. Attackers achieved rapid domain compromise using techniques like pass-the-hash, noPac, and DCSync, often gaining full domain admin access within minutes. The actor used AI models such as OpenAI’s Codex and DeepSeek to accelerate exploit development and target selection via Netlas scanning.
2 Malware
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
17h ago · wiz
Wiz Research has identified active in-the-wild exploitation of three vulnerabilities in JFrog Artifactory: CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329. Attackers are chaining CVE-2026-42018 and CVE-2026-42016 to escalate privileges from an unauthenticated state to admin access, while CVE-2026-82329 allows direct unauthenticated administrative access. Post-exploitation activities include creation of persistent admin accounts, deployment of malicious Groovy plugins, execution of ad-hoc commands, and installation of Rust-based backdoors for C2 communication. Multiple threat actors have been observed exploiting these flaws across self-hosted Artifactory instances, with evidence of configuration exfiltration, credential theft, and persistence mechanisms.
23 IoCs
We've got one word for it, and it's usually the wrong one
1d ago · talos
Cisco Talos identified a complex WebDAV-based infection chain used in an attack against a Ukrainian government organization. The campaign is attributed to the Russian threat actor UAT-10820 and delivers multiple payloads, including the Amatera stealer, ZigCryptoStealer, and NetSupport Manager. The attackers abuse legitimate infrastructure such as the BNB Smart Chain for hosting and use fake CAPTCHA prompts to evade detection. The operation is assessed as opportunistic, focused on stealing cryptocurrency and credentials, with techniques including memory-resident malware, DLL sideloading via 'rundll32.exe', and use of vulnerable drivers to disable EDR solutions.
15 IoCs 1 Malware
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
1d ago · hacker-news
A suspected Russian-speaking threat actor has exploited CVE-2026-81578 and CVE-2026-82078, a vulnerability chain in PaperCut NG/MF involving authentication bypass and remote code execution, to compromise at least 440 instances across 395 organizations in 48 countries. The attacker used AI agents powered by OpenAI Codex and DeepSeek, along with offensive tools like Mimikatz and Impacket, to automate exploitation and post-compromise activities including credential harvesting and domain reconnaissance. The campaign targeted primarily the education sector and demonstrated rapid lateral movement, with some attacks achieving domain administrator access in under seven minutes. The actor’s ultimate objectives remain unclear, though activity suggests potential initial access brokering or preparation for follow-on attacks such as data theft or ransomware.
4 IoCs 3 Malware
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
21h ago · hacker-news
Multiple threat actor clusters have exploited two critical vulnerabilities in Cisco's Secure Firewall Management Center (FMC) to gain unauthorized access, steal credentials, and deploy ransomware. CVE-2026-20079, a critical authentication bypass flaw (CVSS 10.0), allowed unauthenticated remote attackers to execute scripts and gain root access. CVE-2026-20316, a lower-severity flaw, enabled access via a low-privilege account and was used in conjunction with other vulnerabilities for privilege escalation. Three distinct post-compromise activity clusters were identified: UAT-12197 deployed JSP web shells and JAR-based command executors; UAT-11823 delivered Netcat reverse shells and a Cyclops Blink variant; and UAT-11988, a ransomware operation, used living-off-the-land techniques to deploy Qilin ransomware.
1 Actors 1 Malware