Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

18h ago · hacker-news

PostgreSQL has patched a 12-year-old vulnerability, CVE-2026-6471, affecting versions prior to 18.6, 17.11, 16.15, 15.19, and 14.24. The flaw allows an authenticated replication user to execute arbitrary code as the database OS user by exploiting unvalidated plugin paths in logical decoding. Attackers can leverage path traversal in the CREATE_REPLICATION_SLOT command to load malicious libraries from remote SMB or NFS shares, or local disk, achieving privilege escalation and persistence. The fix introduces a whitelist parameter, output_plugin_libraries, to restrict allowed decoding plugins, but gaps remain, such as in pg_createsubscriber behavior.
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

2h ago · hacker-news

Threat actors are actively exploiting two vulnerabilities in PaperCut software, identified as CVE-2026-81578 and CVE-2026-82078, to conduct unauthorized access and credential theft targeting educational institutions in the U.S. and Europe. The attackers chain an authentication bypass with remote code execution to create privileged accounts, execute commands, and deploy credential-harvesting tools such as lsa_collect.exe and save_hives.exe. Post-exploitation activities include collecting Windows registry hives, searching configuration files for secrets, and exfiltrating data to attacker-controlled IP addresses.
5 IoCs
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

18h ago · hacker-news

A previously undocumented Linux backdoor named 'ted' has been discovered embedded within trojanized HAProxy binaries deployed at two South Korean organizations in the automotive and media sectors. The implant intercepts web traffic, enables command-and-control (C2) communication by mimicking legitimate HTTP responses, and allows attackers to execute shell commands, upload/download files, and modify configurations. Rapid7 Labs attributes the activity with medium confidence to North Korean state-sponsored actors, potentially linked to APT37, Lazarus, and Kimsuky clusters, based on infrastructure overlaps and operational patterns. The backdoor evades logging by manipulating HAProxy's internal connection counters and uses trojanized system binaries such as crond, sshd, agetty, atd, and polkitd to maintain persistence and exfiltrate credentials.
12 IoCs 2 Actors
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

17h ago · hacker-news

A high-volume phishing campaign has been leveraging invisible Unicode tag characters, specifically from the Unicode Tags block (U+E0000 to U+E007F), to obfuscate financial lure words such as 'funding' and evade email security filters. The technique, known as ASCII Smuggling, splits keywords with non-rendering characters (e.g., 'fun⟨U+E0020⟩ding') to bypass literal string detection while appearing normal to human recipients. The campaign has sent millions of emails daily, primarily targeting Small Business Administration (SBA) loan applicants, using the ActiveCampaign platform to distribute AI-generated phishing emails and dynamically generated, convincing phishing websites. The operation uses disposable finance-themed domains and leverages ActiveCampaign's infrastructure for link tracking, complicating reputation-based filtering.
12 IoCs
Critical Citrix NetScaler auth bypass now leveraged in attacks

18h ago · bleeping-computer

Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler appliances, tracked as CVE-2026-19490, which allows unprivileged remote actors to bypass authentication when the appliance is configured as an AAA virtual server or Gateway. Exploitation attempts have been observed from multiple IP addresses geolocated to Australia, the United States, and Germany, following the release of a public proof-of-concept. The Centre for Cybersecurity Belgium and vulnerability intelligence firm Previdian have issued warnings urging administrators to patch affected systems immediately.
3 IoCs
Google warns of new Chrome zero-day flaw exploited in attacks

21h ago · bleeping-computer

Google has patched a high-severity zero-day vulnerability in Chrome's V8 JavaScript and WebAssembly engine, identified as CVE-2026-85046, which is being actively exploited in the wild. The flaw is a type confusion issue that could allow remote code execution if a user visits a specially crafted webpage containing malicious JavaScript. Google has not disclosed specific exploitation details to allow time for users to update. Chrome users are urged to update to version 152.0.7977.82 or later to mitigate the risk. This is the sixth actively exploited Chrome zero-day fixed by Google in 2026.
3 CVEs
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges

20h ago · bleeping-computer

An anonymous security researcher known as Nightmare Eclipse disclosed a zero-day privilege escalation vulnerability in CrowdStrike Falcon, dubbed 'FalconFlank,' which allows attackers to achieve SYSTEM-level privileges on fully updated Windows 11 25H2 and Windows Server 2025 systems. The exploit abuses the 'File Suspicious Macro Removal' feature in CrowdStrike Falcon Sensor by loading a malicious DLL. CrowdStrike has not yet assigned a CVE ID but advises customers to disable the related Microsoft Office policy setting while investigations continue. The researcher has also released other zero-day exploits targeting Kaspersky, Avast, Nvidia, and multiple Microsoft products.
1 IoCs
Angry Birds: Toy Ghouls’ new toys

23h ago · securelist

Toy Ghouls, a financially motivated threat actor active since 2025, has developed two custom backdoor variants named mqtt-bird-agent and matrix-bird-agent, both version 0.1.0. These backdoors are deployed using Windows Remote Management (WinRM) and establish persistence via Windows services. The HiveMQ version communicates through the public broker.hivemq.com MQTT broker, while the Element version uses a malicious Element server at meet.element[.]tw for C2 communications, leveraging Matrix protocol rooms for command exchange. The backdoors collect system telemetry, execute commands via PowerShell or cmd, and use machine-bound encryption for configuration files, indicating increased sophistication in the group's tooling and operational security.
11 IoCs
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

1d ago · hacker-news

BraZetsu is a sophisticated Python-based Windows malware framework used by the threat actor Exilware to compromise systems and monetize access via the 'Infected Marketplace' (aka 'Banco de Infects'). The malware conducts deep reconnaissance, steals financial data including CNAB-format remittance files, captures screenshots, and enables remote command execution. It leverages generative AI for target triage and prioritization, and maintains persistent communication via WebSocket. BraZetsu shares infrastructure and code with AgenteV2, indicating they are part of the same malware framework. The campaign primarily targets Iberian and Latin American organizations in e-commerce, finance, and critical infrastructure sectors.
4 IoCs 1 Malware
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

1d ago · hacker-news

Cisco disclosed a critical vulnerability, CVE-2026-20212, in 10 Silicon One-based Nexus 9000 switches that allows unauthenticated remote attackers to execute code with root privileges by exploiting exposed TCP ports 43210 and 43211. The flaw stems from binding to an unrestricted IP address, enabling direct access to a privileged service. Cisco has released patches and recommends immediate upgrades, while also providing temporary mitigations such as infrastructure ACLs and a Live Protect shield. Separately, a hardening release for IOS XR addresses 7 CVEs, including two rated 9.8, and ongoing exploitation of similar infrastructure is linked to the China-nexus threat actor Fire Ant, which has deployed stealthy implants on IOS XR routers to manipulate traffic and exfiltrate data.