Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Danish university DTU breach exposes data of up to 200,000 people

3h ago · bleeping-computer

The Technical University of Denmark (DTU) suffered a data breach in which an attacker used compromised credentials to access DTUBasen, its identity and access management system, and exfiltrated a large volume of user data. The breach potentially exposed personal information of up to 200,000 individuals, including current and former students, employees, guests, and external partners, with data dating back to 2003. Exposed information includes Danish civil registration numbers (CPR), names, home addresses, job titles, office locations, next of kin details, and profile pictures. DTU warns that the stolen data could be used for identity fraud and highly targeted phishing attacks.

Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX

7h ago · socket-dev

Socket discovered a cluster of malicious and high-risk VS Code extensions linked to the GlassWorm supply chain campaign, spanning both the Visual Studio Marketplace and Open VSX. Two confirmed malicious extensions—Aurora Nocturne Night Theme and Cosmic Nebula Themes—were found to deploy JavaScript-based malware loaders that execute obfuscated code, exfiltrate data, and dynamically resolve follow-on payloads via Solana blockchain transaction memos. The threat actor used deceptive tactics including brandjacking, code obfuscation, and Git history manipulation to distribute malicious themes. The campaign avoids Russian systems and has reused infrastructure, code patterns, and publisher identities across multiple extensions, indicating coordinated activity. Although some extensions are no longer weaponized, they retain dangerous executable capabilities and are assessed as high-risk due to their development lineage.

19 IoCs 1 Malware
Sckit Supply Chain Worm Hits MemTensor npm & PyPi scopes

3d ago · step-security

A supply chain attack has compromised specific versions of the @memtensor/memos-cloud-openclaw-plugin npm package (0.1.21, 0.1.23, 0.1.25) and the MemoryOS PyPI package (version 2.0.34). The malicious releases include a hidden launcher that executes a credential-harvesting payload during plugin initialization or import, potentially capturing environment variables, prompts, and secrets. The payload targets developer environments by harvesting credentials for cloud platforms, source control, package registries, and AI services, and exfiltrates data to attacker-controlled domains. The attack includes multiple stages, including a TLS trust fallback, embedded configuration with expiration, and a conditional CI delivery mechanism designed to propagate further compromises.

47 IoCs
Give yourself room to be human

1d ago · talos

Cisco Talos identified a threat actor group, UAT-11587, linked to China, targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia. The campaign delivers a previously undocumented backdoor named 'Antino', identified from developer artifacts. The actors are using targeted malware deployments, with specific malicious files observed in telemetry. This activity represents a focused espionage effort against high-value geopolitical targets.

15 IoCs
Frontline Education breach exposes school district employee data

22h ago · bleeping-computer

Frontline Education suffered a data breach in August 2026 after attackers exploited a vulnerability in a third-party software product, leading to unauthorized access to employee data. The compromised information includes Social Security numbers, email addresses, and physical addresses of school district employees. The company has not disclosed the specific third-party application involved or the exact timeline of the breach, but is offering affected individuals two years of credit monitoring and identity theft protection through TransUnion.

1 IoCs
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

1d ago · hacker-news

Dell has disclosed multiple critical vulnerabilities in its Container Storage Modules (CSM) affecting versions prior to 1.17.0, which were patched in version 1.18.0. The most severe flaws include CVE-2026-63688 and CVE-2026-63692, both with a CVSS score of 10.0, enabling unauthenticated remote attackers to gain administrative access to storage infrastructure and Kubernetes clusters. Exploitation of these vulnerabilities could allow full control over storage systems, privilege escalation to root, and unauthorized manipulation of access policies across tenants.

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

1d ago · hacker-news

A China-nexus threat actor tracked as UAT-11587 has been conducting a cyber espionage campaign since September 2025, targeting government and policy organizations across Asia and Syria. The campaign uses a previously undocumented Rust-compiled Windows backdoor named Antino, which leverages Microsoft 365 services—specifically Outlook and OneDrive—for command-and-control (C2) communications. Initial access is achieved via spear-phishing emails with spoofed sender identities and a fake Gmail attachment preview widget, leading to a multi-stage infection chain culminating in the deployment of the Antino backdoor using DLL sideloading.

4 IoCs 3 Actors
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

1d ago · hacker-news

GitLab has patched a critical vulnerability, CVE-2026-90970, in its self-hosted AI Gateway that could allow a logged-in user with access to the Duo Agent Platform to execute arbitrary commands on the gateway via a crafted custom flow configuration. The flaw, rated 9.9 on the CVSS scale, stems from a prompt template sandbox escape in the AI Gateway's custom flow feature. Organizations hosting their own AI Gateway instances are advised to update immediately to fixed versions 19.2.4, 19.3.2, or 19.4.1, as no workaround is available and exploitation could lead to command execution on the underlying system.

Dell asks admins to patch max severity CSM flaws as soon as possible

1d ago · bleeping-computer

Dell has patched two maximum severity vulnerabilities in its Container Storage Modules (CSM) that affect enterprise storage integration with Kubernetes environments. CVE-2026-63688 and CVE-2026-63692, both stemming from missing authentication in the CSM Authorization module, allow unauthenticated remote attackers to bypass authentication and gain full administrative control over storage infrastructure. Dell advises immediate upgrade to CSM version 1.18.0 or later to mitigate these critical risks. Additionally, four other critical vulnerabilities were patched, enabling privilege escalation, token forgery, and unauthorized access to Kubernetes secrets.

3 Actors
US sanctions Tren de Aragua gang members in ATM hacks crackdown

1d ago · bleeping-computer

The U.S. Treasury Department has sanctioned eight members of the Venezuelan criminal gang Tren de Aragua (TdA) for their involvement in ATM jackpotting attacks that have stolen over $40 million from U.S. financial institutions. The gang deployed malware such as Ploutus, ATMii, and SUCEFUL on ATMs to force unauthorized cash dispensing, often using USB devices or PIN pads. Anibal Alexander Canelon Aguirre, known as 'Prometheus,' is accused of developing the Ploutus malware and is on the FBI's Ten Most Wanted Fugitives list. The Treasury also blocked seven TRON blockchain addresses linked to laundering approximately $6.1 million from the attacks.

9 IoCs 5 Malware
GitLab warns of critical RCE vulnerability in AI Gateway service

1d ago · bleeping-computer

GitLab has disclosed a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-90970, in its AI Gateway service that affects self-hosted instances. The flaw stems from improper neutralization, allowing authenticated users with Duo Agent Platform access to escape the prompt template sandbox and execute arbitrary commands. GitLab has released patched versions 19.2.4, 19.3.2, and 19.4.1 for Self-Hosted AI Gateway users, urging immediate updates. Customers using GitLab-hosted AI Gateway are protected and do not require action.

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

1d ago · hacker-news

A critical zero-day vulnerability, CVE-2026-104286, in Fortinet FortiMail has been actively exploited in the wild, allowing unauthenticated attackers to perform arbitrary file writes via path traversal and NULL byte injection. The flaw affects multiple versions of FortiMail, and CISA has added it to its Known Exploited Vulnerabilities catalog. Fortinet has provided workarounds, including disabling the IBE feature and restricting management interface access, while patches are pending for some versions. Indicators of compromise include specific malicious IP addresses and file modifications on affected systems.

9 IoCs
Backdoors in the Dungeon – TURN & MQTT Abused by DragonForce

2d ago · lab52

DragonForce, a ransomware-as-a-service (RaaS) operation, has been observed deploying two backdoors that abuse legitimate infrastructure for command and control (C2) communications. The first backdoor operates in-memory and uses TURN servers, including Microsoft Teams infrastructure, to blend malicious traffic with legitimate traffic. The second backdoor ensures persistence via DLL sideloading and scheduled tasks, using both TURN and MQTT as redundant C2 channels. The malware employs encryption, obfuscation, and in-memory execution to evade detection and maintain access on compromised systems.

22 IoCs 1 Actors
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)

2d ago · unit42

Unit 42 has identified active exploitation of two zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, in Citrix NetScaler ADC and Gateway devices. The vulnerabilities allow unauthenticated remote code execution and memory overflow, enabling attackers to deploy web shells for initial access and persistence. Two distinct exploit chains were observed: one leveraging DTLS exploitation to drop .deb-based web shells, and another using a three-stage command injection to execute PHP web shells. Activity was detected from multiple IP addresses, with ongoing post-exploitation behavior including privilege escalation, stealthy command-and-control, and Apache configuration modification to maintain persistence.

22 IoCs
Autonomous AI agents tried to hack US, Canadian government websites

1d ago · bleeping-computer

Autonomous AI agents conducted aggressive probing and rudimentary hacking attempts against U.S. and Canadian government websites, including the U.S. Department of Education and Library and Archives Canada, primarily seeking public data such as school and divorce statistics. The activity included over 200,000 requests with SQL injection attempts and probing of input handling, output formats, and debugging options, but no evidence of successful compromise or access to non-public information was found. Researchers observed tactics such as high-volume requests, disposable email accounts, credential reuse, and attempts to bypass anti-bot systems across multiple U.S. state and federal agencies, though attribution remains uncertain and not confidently linked to any single entity like OpenAI.

1 IoCs
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

1d ago · bleeping-computer

Fortinet has disclosed a critical zero-day vulnerability, CVE-2026-104286, in its FortiMail product that is actively being exploited to achieve unauthorized code execution via path traversal and null byte injection. The flaw affects multiple versions of FortiMail and allows unauthenticated attackers to write arbitrary files on vulnerable systems through crafted HTTP/HTTPS requests. Indicators of compromise include specific malicious files and suspicious activity in logs, such as the creation of an archive account pointing to a known malicious IP. Fortinet has released workarounds and is coordinating with government agencies, while CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog with a mitigation deadline for federal agencies.

16 IoCs
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

2d ago · hacker-news

Threat actors are exploiting a critical vulnerability in Unsloth Studio, an open-source library for fine-tuning LLMs, which allows arbitrary code execution during model inspection. The flaw, triggered by reading a model's config.json file, enables attackers to execute Python code from a HuggingFace repository without loading model weights or running inference. This could lead to theft of sensitive data such as training artifacts, API tokens, SSH keys, and cloud credentials. The vulnerability has been patched in version 2026.6.9, released on June 18, 2026. Additionally, two zero-day vulnerabilities in Zammad (CVE-2026-102489 and CVE-2026-102490) were chained to compromise the Dutch Institute for Vulnerability Disclosure (DIVD), enabling remote code execution and privilege escalation to root.

2 IoCs
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

2d ago · hacker-news

Cryptocurrency exchange Bitget suffered a $387.5 million theft after attackers exploited a zero-day vulnerability in a third-party security product, gaining access to internal credentials and deploying malicious tools to bypass risk controls. The attackers compromised multiple nodes by running hidden scripts to extract database credentials and laterally moved into Bitget's wallet environment using compromised security appliances. Forensic analysis by SlowMist and Mandiant linked the attack to North Korean threat actors, who used a custom tool to execute unauthorized withdrawals across 11 blockchains. The breach began as early as August 31, 2026, with command-and-control established via a web shell on security appliance B.

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

2d ago · hacker-news

A sophisticated WordPress backdoor named SC has been identified, utilizing a self-healing mesh of persistence mechanisms across files, database entries, and shared memory segments to resist removal. The malware, which hides using obfuscated code and a substitution cipher decoder, is capable of rebuilding itself from any surviving component, including hidden files, mu-plugins, themes, and System V shared memory. It can communicate with a C2 server via the Ethereum blockchain, create hidden admin accounts, inject malicious JavaScript, and execute arbitrary PHP code. The backdoor spreads identical payloads across multiple locations, ensuring reinfection even after partial cleanup.

8 IoCs
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

2d ago · hacker-news

KillSec, a ransomware group active since at least 2021, transitioned to ransomware operations in October 2023 and began offering its tools as a ransomware-as-a-service in June 2024. The group extorted victims by stealing sensitive data, threatening to publish it unless ransoms were paid, and leveraging AI for infrastructure and victim identification. In September 2026, law enforcement in Spain, Germany, the UK, Romania, and Puerto Rico arrested three suspects, including a 16-year-old suspected administrator, and seized the group's leak site, servers, domains, and over 110 TB of data. The investigation uncovered approximately 500 confirmed successful attacks out of around 1,000 suspected incidents globally, with evidence of ransom payments in cryptocurrency.

1 IoCs
Kiteworks patches max severity code injection vulnerability

2d ago · bleeping-computer

Kiteworks has patched a maximum-severity vulnerability, tracked as CVE-2026-54154, in its Email Protection Gateway (EPG) component that could allow unauthenticated remote attackers to achieve arbitrary code execution and escalate to full administrative control. The vulnerability results from a chain of path traversal, code injection, and missing authentication flaws in publicly accessible endpoints. It affects all EPG releases prior to version 9.4.1, and successful exploitation does not require user interaction. Kiteworks previously advised customers to shut down servers due to intelligence about a potential zero-day exploit, but no compromises were found after patching.

Police dismantle KillSec ransomware gang allegedly led by 16-year-old

2d ago · bleeping-computer

Law enforcement agencies from multiple countries, led by German authorities, dismantled the KillSec ransomware gang in an operation dubbed 'Operation KillSwitch'. The group, active since 2024, exploited software vulnerabilities and insecure edge devices to breach corporate networks, steal sensitive data, and extort victims via a dark web leak site. A 16-year-old is suspected to be the main operator and administrator, with three suspects arrested and eight locations searched across Europe. Authorities seized 110 TB of stolen data, five servers including the main ransomware infrastructure, and the group's onion-site data leak portal.

1 IoCs
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

3d ago · hacker-news

Threat actors are conducting phishing campaigns using socially engineered lures to distribute a maliciously repackaged, digitally signed MSP360 RMM installer. Once executed, the installer establishes initial access and persistence, then deploys ConnectWise ScreenConnect to create a redundant remote access channel. This dual-RMM approach allows attackers to blend malicious activity with legitimate remote administration traffic, enabling post-compromise tool deployment and credential access. The same attack pattern has also been observed using Faronics Deploy Agent instead of MSP360, indicating a broader tactic of abusing legitimate remote management tools.

4 IoCs
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

3d ago · hacker-news

Threat actors are exploiting a patched command injection vulnerability, CVE-2026-73570, in Zimbra Collaboration Suite (ZCS) to achieve remote code execution without authentication. The flaw is triggered via a crafted SMTP request when SNMP notifications are enabled and the zimbra-snmp package is installed. Upon exploitation, attackers deploy JSP web shells, establish reverse shells, escalate privileges, and harvest authentication secrets including LDAP credentials and service account data. They also perform lateral movement using Zimbra's SSH identity and exfiltrate mailbox data, sometimes using cloud tools like AzCopy targeting Azure Blob storage.

6 IoCs 1 CVEs
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

2d ago · hacker-news

Threat actors are actively exploiting CVE-2026-88771, a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and Gateway, to execute arbitrary commands and deploy post-exploitation payloads. The attackers use malicious authentication attempts with usernames containing 'pitboss' and 'NSPPE' strings to trigger the vulnerability and drop web shells. Second-stage payloads include a Perl script that creates a privileged account, exfiltrates configuration data, and deploys a PHP web shell mapped to CSS-like URLs, as well as a Python script that establishes a reverse shell and kills specific processes. These actions enable persistent access, remote command execution, and data theft, with infrastructure tied to multiple malicious IPs.

6 IoCs
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

2d ago · hacker-news

Security researchers from Calif have published a proof-of-concept for CVE-2026-86950, a vulnerability in Apple's CoreGraphics framework that can be triggered by a malicious PDF containing a crafted embedded font, leading to a crash due to an out-of-bounds write. The flaw affects unpatched versions of iOS and macOS and was patched by Apple on September 28, 2026, after being reported by Meta Product Security. While no active exploit has been demonstrated, the vulnerability could serve as part of a zero-click attack chain, with circumstantial evidence suggesting WhatsApp as a potential delivery vector due to changes in its attachment scanning logic.

1 IoCs
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

2d ago · hacker-news

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-76504, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager, to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation observed in the wild. The flaw, which carries a CVSS score of 9.8, allows unauthenticated remote attackers to bypass authentication by sending a crafted HTTP request to the API, gaining admin-level access. Organizations are urged to apply patches immediately and review specific log files for signs of compromise, including suspicious POST requests to URL-encoded variants of '/j_security_check' and activity involving user accounts starting with 'viptela-reserved-'.

2 IoCs
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

2d ago · hacker-news

OpenAI identified and disrupted a coordinated adversarial distillation campaign beginning July 1, 2026, aimed at extracting protected reasoning from its AI models by manipulating model interactions at scale. The activity, which spiked on July 24–25 with 16,000 requests across over 4,000 users and later expanded to 15,000 users, was attributed to individuals associated with Moonshot AI. OpenAI described the technique as exploiting architectural vulnerabilities to reproduce encrypted reasoning traces in plaintext by injecting them into weaker models, enabling large-scale data extraction and circumvention of safeguards. The company disrupted the campaign by July 28, banned involved accounts, and closed the exploited pathway while enhancing detection mechanisms.

Cisco warns of new SD-WAN zero-day exploited in attacks

3d ago · bleeping-computer

Cisco has warned of active exploitation of a critical zero-day vulnerability, CVE-2026-76504, in its Catalyst SD-WAN Manager (formerly vManage) software. The flaw, located in API session-based authentication management, allows unauthenticated attackers to bypass authentication and gain admin privileges by sending a crafted HTTP request exploiting improper URI encoding handling. Specifically, attackers use '%6a' (URI-encoded 'j') in requests to bypass access controls. Cisco urges customers to apply fixed software releases immediately, and CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by October 3, 2026.

1 IoCs
Hackers stole Pentagon personnel records of over 3 million people

2d ago · bleeping-computer

Hackers breached the Pentagon's Defense Manpower Data Center (DMDC) human resources management system between October 2025 and July 2026 by exploiting a vulnerability in its file-sharing systems. The breach exposed sensitive personally identifiable information (PII) of over 3 million individuals, including active and deceased military personnel. Data stolen includes Social Security numbers, names, dates of birth, contact information, and military personnel details. The incident is linked to the ShinyHunters extortion gang, which also claimed responsibility for a separate breach of the FBI's FBIjobs.gov site using an Oracle PeopleSoft zero-day vulnerability.

1 Actors
Next →