Live threat intelligence — updated continuously
Open Cyber Threat Intelligence
Structured, AI-extracted threat intel. Free with no login required.
Latest Intelligence
View all → Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
11h ago · bleeping-computer
A threat actor compromised the maintainer's website for the Admin Menu Editor Pro WordPress plugin and distributed malicious updates (versions 2.35 and 2.36), which backdoored approximately 1,500 sites. The backdoor created a hidden user account and installed a web shell via a malicious file named wp-user-consent.php. The attacker had likely gained root-level access to the server, prompting the developer to take the site offline and issue cleanup guidance. Customers are advised to check for specific indicators of compromise and restore from clean backups.
2 IoCs
Acronis warns of actively exploited flaw in its cPanel backup plugin
10h ago · bleeping-computer
Acronis has disclosed a high-severity local privilege escalation vulnerability, CVE-2026-87886, in its backup plugins for cPanel & WHM and Plesk, which is being actively exploited in limited, targeted attacks. The vulnerability allows low-privileged attackers to escalate privileges on affected Linux servers, potentially enabling unauthorized access to sensitive data and system disruption. Exploitation has been detected in the wild, though no specific indicators of compromise have been identified. Acronis recommends immediate updates to patched versions to mitigate the risk.
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
13h ago · hacker-news
KREMLIN is a Brazilian banking malware operation active since May 2025 that targets Chromium-based browsers to steal credentials, session tokens, and sensitive data. It uses multi-stage JavaScript loaders, C++ installers, and malicious browser extensions, evading sandbox detection by checking hardware properties and process names. The malware leverages Ethereum smart contracts as dead drop resolvers to dynamically update C2 infrastructure and employs DLL sideloading via a legitimate SentinelOne binary. It installs a malicious extension named 'AVSync System Inc.' that exfiltrates browser data through WebSocket and HTTP-based polling mechanisms.
8 IoCs 1 Actors 1 Malware
Hackers target WordPress sites via third-party WooCommerce plugin
17h ago · bleeping-computer
Hackers are actively exploiting a critical unauthenticated arbitrary file-upload vulnerability, CVE-2026-27540, in the WooCommerce Wholesale Lead Capture plugin for WordPress. The flaw allows attackers to upload PHP webshells by manipulating the wwlc_file_upload_handler AJAX action and bypassing file extension checks via a user-controlled parameter. Exploitation attempts have been observed in multiple waves, with over 100,000 attacks blocked by Wordfence. The uploaded webshell, named shell.php, enables host reconnaissance and facilitates deployment of additional malicious payloads.
6 IoCs
CenterPoint Energy confirms customer data stolen in cyberattack
15h ago · bleeping-computer
CenterPoint Energy confirmed a data breach in which an unauthorized actor exfiltrated personal information of a portion of its customers through an external-facing system. A threat actor using the alias '4d722e4d656f77' claimed responsibility, stating they extracted 7.49 million records containing names, phone numbers, addresses, account numbers, billing amounts, and partial Social Security numbers by exploiting inadequate security controls on the company's public API, including lack of rate limiting and WAF protection. The company has launched an investigation, engaged third-party experts, and reported the incident to authorities, while confirming that utility services were unaffected.
1 IoCs
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
21h ago · hacker-news
A mass-scanning campaign has been exploiting CVE-2026-39364, a high-severity vulnerability in Vite, to extract sensitive data from internet-exposed development servers. The flaw allows unauthenticated attackers to bypass file access restrictions by manipulating query parameters, enabling them to retrieve cloud credentials, environment configurations, and infrastructure state files from AWS and Azure environments. Attackers use spoofed User-Agent headers and forged X-Forwarded-For headers to evade detection, with significant malicious traffic originating from Google Cloud Platform IP ranges in the U.S., Belgium, the Netherlands, Singapore, and Taiwan.
2 IoCs 1 CVEs
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
20h ago · hacker-news
A skilled human threat actor exploited CVE-2026-39987, a pre-authenticated remote code execution vulnerability in Marimo, to gain initial access and pivot to an SSH bastion host within eight seconds. The attacker used a custom, hand-rolled Python toolkit to extract AWS credentials from the compromised instance, retrieve a private SSH key from AWS Secrets Manager, and establish SSH access to a bastion host. Over a nine-hour session, the operator executed more than 850 interactive commands without using known offensive tools, demonstrating high tradecraft and evasion capabilities. The activity highlights the speed and precision achievable by skilled human attackers, even without AI assistance.
5 IoCs 1 CVEs
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
16h ago · hacker-news
BambooToken is a multi-platform malware family active since at least February 2023, targeting organizations in Asia and South America. It uses the MQTT protocol for command-and-control (C2) communications, leveraging DLL sideloading of Tendyron's OnKeyToken software to execute on Windows and Linux systems. The malware collects extensive host information, including antivirus details via WMI, and communicates with C2 servers hosted behind Cloudflare, indicating large-scale data collection operations. Recent activity was observed as of July 2026, with infrastructure linked to IP addresses in Singapore, Cambodia, and Vietnam.
3 IoCs
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
20h ago · bleeping-computer
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that the critical VMware vCenter vulnerability CVE-2026-59310, a directory traversal flaw allowing unauthenticated remote code execution, is now actively exploited by ransomware gangs. The vulnerability was patched by Broadcom in July 2026, but attackers have been observed exploiting unpatched systems to deploy reverse SSH tools for persistence and remote access. CISA added the flaw to its Known Exploited Vulnerabilities catalog and mandated federal agencies to remediate within three days. The broader threat landscape shows a pattern of ransomware groups targeting VMware infrastructure due to its strategic access to enterprise networks and data.
BambooToken malware controls Windows and Linux systems via MQTT
17h ago · bleeping-computer
BambooToken is a previously unknown malware framework active since at least 2023 that uses the MQTT protocol for command-and-control communications on both Windows and Linux systems. It has been observed compromising enterprise servers in Asia and South America, including those supporting mobile apps, legal and financial services, and software development. The malware is capable of keylogging, clipboard theft, audio and webcam capture, and file manipulation, with a Linux variant (version 2.1) observed in December 2025. While no specific threat actor is attributed, targeting patterns suggest alignment with China-aligned operations.