Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

4w ago · hacker-news

A Go-based botnet named NadMesh, discovered in early July 2026, actively targets exposed AI and cloud services to harvest cloud credentials, Kubernetes tokens, and model access. The malware prioritizes exploitation of MCP (Model Context Protocol) services, Docker APIs, Jenkins consoles, and Redis instances, with a focus on credential theft rather than host compromise. The operator uses self-propagating scanning infrastructure, persistence mechanisms, and obfuscation to evade detection, while targeting specific ports associated with AI tools like ComfyUI, Ollama, Gradio, and n8n. Researchers observed real-time exploitation traffic, though success rates for MCP exploitation remain low compared to other vectors.

3 IoCs 4 CVEs
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

4w ago · hacker-news

North Korean threat actors linked to the Contagious Interview campaign are targeting software developers through fake job postings and coding challenges. They distribute malicious repositories that include SVG images with steganographically hidden payloads, which deploy the OtterCookie malware. This multi-stage malware steals browser credentials, cryptocurrency wallets, files, and clipboard data, while also enabling remote access via a Socket.IO-based backdoor.

2 IoCs 1 Malware
Inside the Search for "Clean" Residential Proxies for Carding

4w ago · bleeping-computer

Cybercriminals involved in carding are increasingly relying on 'clean' residential proxies to bypass fraud detection systems, but these proxies alone are no longer sufficient. They are now part of a broader identity-simulation strategy that includes matching geographic data, device fingerprints, and browser profiles to stolen identity information. As financial services improve detection, carders face challenges with proxy reputation degradation and provider restrictions, leading to a growing demand for finance-compatible proxy services.

2 IoCs
Ernst & Young discloses data breach after support system hack

4w ago · bleeping-computer

Ernst & Young disclosed a data breach resulting from the compromise of a third-party support ticket system used by its IT personnel. The breach occurred between March 28 and April 12, during which an unauthorized party accessed and downloaded documents containing personal and financial data related to tax filings. The company detected anomalous activity on April 23, launched an investigation with external cybersecurity experts, and has since secured its systems. No threat actor has claimed responsibility, and there is no evidence of data misuse to date.

M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions

4w ago · wiz

In July 2026, an attacker exploited a misconfigured GitHub Actions workflow in the AsyncAPI generator repository using a 'pwn request' technique to steal a privileged Personal Access Token. The attacker published five malicious npm packages under the @asyncapi namespace, which download and execute a multi-stage payload establishing persistence and connecting to C2 infrastructure. The payload targets developer credentials, including browser data, SSH keys, and cloud tokens, and communicates via HTTP, Nostr relays, Ethereum smart contracts, and IPFS. The attack leverages infrastructure and obfuscation techniques linked to the Miasma framework but shows distinct characteristics from prior campaigns.

16 IoCs
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

4w ago · unit42

Palo Alto Networks and Siemens collaborated to identify a chained exploit involving three zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949) in Siemens ROX II OT switches. The attack chain begins with arbitrary file disclosure, enables privilege escalation via command injection, and establishes persistent root-level access through the task scheduler. These vulnerabilities allow an unauthenticated attacker to gain full control of critical OT switches, potentially disrupting industrial operations. Siemens has released firmware updates, and virtual patching is available via Palo Alto Networks.

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

4w ago · hacker-news

A previously undocumented malware named GoSerpent has been used in cyber espionage campaigns targeting government and diplomatic entities in Southeast Asia since late 2025. The malware enables long-term access, credential dumping, and data exfiltration through a suite of tools including Mimikatz, QuarksDumpLocalHash, and a custom file collection tool called ThumbcacheService. In May 2026, attackers returned to compromised environments to deploy evolved tools such as Stowaway and TmcLoader/TmcPayload for further data exfiltration. The activity shows operational overlaps with the TetrisPhantom threat actor, though definitive attribution remains unconfirmed.

2 Actors 2 Malware
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

4w ago · hacker-news

ACR Stealer, an infostealer active since 2024, is being distributed through social engineering lures such as fake Claude AI assistant pages and malvertising. The malware uses fileless techniques and WebDAV shares to steal browser credentials, session tokens, and sensitive files from Microsoft 365, OneDrive, and SharePoint. It relies on user execution via pasted commands and does not exploit software vulnerabilities, making detection dependent on behavioral analysis and proactive controls.

67 IoCs 1 Malware
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

4w ago · hacker-news

Armenia has detained a Russian national, Aleksandr Ermakov, based on a U.S. extradition request related to alleged involvement in REvil (Sodinokibi) ransomware attacks. However, his legal team claims authorities have mistaken him for another individual with the same name—Aleksandr Gennadievich Ermakov—who was sanctioned in 2024 for cybercriminal activity including the Medibank data breach. The accused individual in custody, Aleksandr Yuryevich Ermakov, is a former prison-service lawyer with no known English proficiency, and lawyers argue insufficient identification was used for the arrest. The confusion stems from identical names and lack of patronymic or biometric verification in the extradition process.

5 IoCs 1 Malware
The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?

4w ago · hacker-news

The article discusses the growing emphasis on military autonomy and the need for trusted information infrastructure to support interconnected autonomous systems across defense forces. It highlights strategic investments by the U.S., UK, and NATO in autonomous technologies and underscores the importance of secure, cross-domain data sharing for mission effectiveness. The focus is shifting from deploying individual autonomous platforms to enabling secure, trusted, and interoperable information exchange across systems and coalition partners. The article promotes Everfox’s hardware-enforced separation solution as a means to achieve secure, high-assurance connectivity for autonomous military operations.

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

4w ago · hacker-news

The European Commission has mandated Google to open access to Android's microphone, camera, screen, and other core features for rival AI assistants under the Digital Markets Act. This decision requires Google to implement a certification program allowing third-party AI assistants to access sensitive device functions, while also enforcing strict security and privacy safeguards. The move aims to promote competition but raises concerns about potential abuse of powerful device permissions by untrusted applications. Google must comply by August 2027, with certain features deferred to 2028.

New Windows LegacyHive zero-day gives hackers admin privileges

4w ago · bleeping-computer

A security researcher known as Nightmare Eclipse has released a Windows zero-day exploit named LegacyHive, which enables privilege escalation on fully patched systems by exploiting a flaw in the Windows User Profile Service. The proof-of-concept requires additional user credentials to limit weaponization, but successful exploitation allows non-admin users to manipulate registry hives and achieve automatic code execution upon administrator login. Microsoft has not yet assigned a CVE to this vulnerability, and the company has issued warnings against malicious use of such disclosures.

1 IoCs
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

4w ago · hacker-news

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the actively exploited SharePoint Server remote code execution vulnerability CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) catalog. This critical zero-day flaw allows authenticated attackers with Site Owner privileges to execute arbitrary code remotely on vulnerable SharePoint servers. CISA warns of ongoing exploitation and mandates federal agencies to apply patches by July 19, 2026. Additional SharePoint-related vulnerabilities are also being actively exploited, enabling remote code execution and post-exploitation activities such as theft of IIS machine keys.

CISA urges immediate action on actively exploited Fortinet flaws

4w ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to urgently patch two actively exploited critical vulnerabilities in Fortinet's FortiSandbox platform, identified as CVE-2026-39808 and CVE-2026-25089. These flaws allow unauthenticated remote code execution via command injection with no user interaction required. Exploitation in the wild has been confirmed by threat intelligence firm Defused, prompting CISA to add the vulnerabilities to its known exploited catalog. Agencies must remediate by July 19, 2026, per Binding Operational Directive 26-04.

US charges two over laundering $43 million from investment fraud

4w ago · bleeping-computer

U.S. authorities charged Zhuoying Chen and Haojie Zhang for allegedly managing a money laundering network that processed at least $43 million from cyber-enabled investment fraud scams. The funds originated from 'pig butchering' or romance baiting schemes, where victims were lured into fraudulent investment opportunities via social media and messaging platforms. The defendants used 140 bank accounts under 45 shell companies to transfer stolen funds to China. This case highlights the growing scale of investment fraud, which accounted for 49% of scam incidents in the FBI's 2025 Internet Crime Report.

Windows Server 2022 reach end of mainstream support in 90 days

4w ago · bleeping-computer

Microsoft has announced that Windows Server 2022 will reach the end of mainstream support on October 13, 2026, transitioning to extended support with continued security updates until 2031. Organizations are advised to upgrade to Windows Server 2025, the latest Long-Term Servicing Channel release, to remain protected and supported. The article highlights Microsoft's lifecycle policy and recent extensions to hotpatching and extended security updates for certain editions.

AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report

4w ago · unit42

The Unit 42 2026 Global Incident Response Report highlights how AI is acting as a force multiplier for cyber attackers, accelerating existing attack methods rather than introducing new ones. Threat actors are leveraging AI to streamline malware development, automate phishing content, and enhance reconnaissance, reducing attack timelines significantly. Despite these efficiency gains, core tactics such as credential theft, phishing, and exploitation of known vulnerabilities remain unchanged. Defenders are advised to strengthen prevention controls and combine AI proficiency with human judgment to counter AI-enhanced threats.

New ClickLock macOS malware traps users into revealing login password

4w ago · bleeping-computer

A new macOS malware named ClickLock targets users through social engineering to steal login credentials, cryptocurrency assets, browser data, and password manager information. The malware forces victims into entering their system password by displaying fake authentication dialogs and terminating critical system processes. It establishes persistence via LaunchAgents, exfiltrates data through Telegram, and deploys a persistent backdoor using GSocket for remote access. The malware leverages compromised legitimate domains and evades detection by self-deleting modules and clean reputations of host infrastructure.

2 IoCs
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack

4w ago · hacker-news

Owen Flowers and Thalha Jubair, alleged members of the Scattered Spider threat actor group, were sentenced to five and a half years each for their roles in a 2024 cyberattack on Transport for London (TfL) that disrupted 148 systems and affected 27,000 employees. The attack, which exfiltrated personal and financial data and nearly led to a network shutdown, caused £29 million in losses and recovery costs. The hackers also targeted US healthcare organizations, with threats to disrupt critical systems, and are linked to a broader campaign of social engineering, SIM swapping, and data extortion spanning hundreds of attacks from 2022 to 2025.

1 Actors
Claude Chrome extension flaw lets malicious extensions trigger AI actions

4w ago · bleeping-computer

A vulnerability in Anthropic's Claude for Chrome extension allows malicious browser extensions to trigger predefined AI workflows by simulating untrusted click events. The flaw arises because the extension fails to validate the Event.isTrusted property, enabling unauthorized execution of actions in connected services like Gmail, Google Docs, Calendar, and Salesforce. Although the issue requires a malicious extension already installed by the user, it can abuse Claude's authenticated access to sensitive platforms without additional user consent.

Coca-Cola says Fairlife ransomware attack halts US dairy production

4w ago · bleeping-computer

The Coca-Cola Company disclosed that its Fairlife dairy subsidiary suffered a ransomware attack, leading to the temporary suspension of production across U.S. facilities. The attack impacted production-related systems, though product safety remains unaffected. Investigation is ongoing, with outside cybersecurity experts and law enforcement involved. No ransomware group has claimed responsibility, and details on data exfiltration or extortion remain undisclosed.

Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Music Scraping

4w ago · socket-dev

AI music generator Suno suffered a breach stemming from the Shai-Hulud worm, which compromised a developer's machine and exfiltrated GitHub and cloud credentials. The attacker, using the handle ellie.191, accessed Suno's source code, customer data, and payment information without the company's public notification. The breach highlights the ongoing impact of the Shai-Hulud campaign, which spreads via trojanized npm, PyPI, and Packagist packages and exfiltrates credentials to public GitHub repositories.

3 IoCs 1 Malware
Begun, the Patch Wars have

4w ago · talos

Cisco Talos has identified a new campaign by UAT-11795, a financially motivated Russian-speaking threat actor, targeting users in the U.S. and Europe since at least June 2025. The group uses trojanized installers of legitimate software such as Webex, Zoom, and MobaXterm to deliver a custom Python-based remote access tool called 'Starland RAT'. This tool enables deployment of additional payloads, including the in-memory PowerShell-based 'WLDR agent', CastleStealer, and Remcos RAT, to steal credentials and cryptocurrency.

12 IoCs
New OkoBot framework deploys 20 payloads to steal data, crypto

4w ago · bleeping-computer

A new malicious framework named OkoBot has been active since January 2026, delivering over 20 payloads to steal cryptocurrency wallet seed phrases, credentials, and sensitive data. It spreads via ClickFix attacks and malicious GitHub repositories hosting trojanized software. The infection chain begins with the TookPS PowerShell script, which installs an SSH bot to deploy further modules. Victims are primarily in Brazil, with secondary targets in Vietnam, Canada, Mexico, and Turkey, and evidence suggests the threat actor may be Russian-speaking due to geoblocking and code comments.

7 IoCs
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

4w ago · hacker-news

ClickLock is a new macOS infostealer that uses social engineering via a fake Cloudflare CAPTCHA to trick users into pasting a malicious command into Terminal. Upon refusal to enter credentials, it initiates aggressive app-killing loops every 210ms to coerce compliance. It steals login passwords, browser credentials, crypto wallets, and Keychain data, exfiltrating via Telegram bots. The malware uses compromised websites for payload delivery and a modified open-source backdoor, with persistence via LaunchAgents.

11 IoCs 1 Malware
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

4w ago · hacker-news

A vulnerability in n8n's Enterprise token exchange feature, tracked as CVE-2026-59208, allowed attackers to log in as users from another issuer due to improper validation of JWT tokens. The flaw occurred when n8n matched incoming tokens solely on the 'sub' claim without verifying the 'iss' (issuer), enabling account takeover if two trusted issuers used overlapping subject identifiers. The issue affects n8n versions prior to 2.27.4 and 2.28.1, and while the feature is limited to Enterprise deployments in preview, it poses a high-severity risk for misconfigured systems.

1 CVEs
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

4w ago · hacker-news

Multiple cyber threat campaigns were observed in mid-2026, including malicious NuGet packages distributing spyware disguised as game cheats, fake installers delivering the Starland RAT and WLDR C2 implant, and a new ransomware family named Spirals that encrypted a South Asian IT firm's network within 24 hours. Threat actors exploited known vulnerabilities such as CVE-2026-46817 and CVE-2023-4346, while also leveraging social engineering via phishing eCards and OAuth device code attacks. Additional threats include large-scale infostealer distribution through fake GitHub repositories, Chrome Sync abuse for stalking, and dual monetization campaigns deploying Vidar stealer and XMRig miner.

3 IoCs 2 Actors 1 Malware
Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide

4w ago · hacker-news

A critical unpatched vulnerability in Shark robot vacuums allows attackers with access to a device's certificate to execute arbitrary commands on other vacuums within the same AWS region. The flaw stems from overly permissive AWS IoT policies that permit wildcard subscription and publishing to device shadows, enabling remote code execution, camera access, and Wi-Fi password theft. The issue affects older Shark vacuum models whose certificates were issued with unrestricted policies, and the fix requires server-side policy updates from SharkNinja, as no firmware update is needed. Despite being reported in March 2026, no patch or CVE has been issued as of July.

1 IoCs
AI Can Find Bugs, But Human Knowledge Still Proves Them

4w ago · hacker-news

The article discusses the growing reliance on AI in offensive security and highlights the risks of treating AI-generated findings as validated vulnerabilities without proper human verification. It emphasizes that while AI can accelerate vulnerability discovery, it cannot replace human judgment in proving exploitability, impact, and real-world risk. The core message is that validation through technical knowledge and reproducible evidence remains essential to distinguish noise from genuine threats.

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

4w ago · hacker-news

A China-linked threat actor has resurfaced with the Daxin kernel-mode rootkit, detected in 2026 within a Taiwan-based subsidiary of a multinational high-tech manufacturer. The compromised system was also infected with a previously undocumented backdoor, Stupig, which enables pre-login SYSTEM-level command execution by masquerading as a legitimate keyboard DLL. Both malware samples were compiled in 2013, suggesting long-term stealthy persistence, with Daxin using covert C2 via hijacked TCP connections and Stupig enabling credential theft before user login. The attack highlights sophisticated, sustained cyber espionage activity targeting critical infrastructure.

4 IoCs 1 Malware
← Previous Next →