Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

4w ago · hacker-news

Researchers have identified a new class of attack called Agent Data Injection (ADI), which exploits how AI agents parse structured data by injecting malicious input disguised as trusted data elements like sender names or button IDs. Unlike traditional prompt injection, ADI corrupts underlying facts the agent trusts, enabling actions such as unintended clicks or execution of attacker-controlled commands. The attack affects multiple AI models including GPT-5, Claude, and Gemini, with success rates up to 50% despite existing defenses. No real-world exploitation has been reported, but proof-of-concept demonstrations show high effectiveness across web and coding agents.

20+ Hijacked Government Websites Became
an Attack Channel

4w ago · hacker-news

The PhantomEnigma campaign has hijacked over 20 Brazilian government websites, leveraging compromised .gov.br domains and authenticated email accounts to distribute malware. The attack uses fake police-themed documents to lure victims, redirecting them through trusted government infrastructure to deliver a modular Inno/Node.js backdoor. This backdoor enables credential theft, remote access, and delivery of additional payloads, posing significant risks to banks and public agencies.

4 IoCs
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

4w ago · hacker-news

A new modular malware named TELEPUZ has been spreading since April 2026 via ClickFix social engineering lures, which use clipboard hijacking (pastejacking) to trick users into executing malicious PowerShell commands. The malware, written in C, performs anti-analysis checks, disables security monitoring, and establishes persistent command-and-control (C2) communication using multiple fallback methods. It is capable of data theft, command execution, and browser manipulation via Chrome DevTools Protocol, and is likely offered as malware-as-a-service (MaaS) based on active development and distribution patterns.

3 IoCs
Russian hackers trojanize WebEx, Zoom apps to push Starland malware

4w ago · bleeping-computer

A Russian financially motivated threat actor, UAT-11795, has been conducting attacks since at least June 2025 by distributing trojanized installers of legitimate software such as WebEx, Zoom, and MobaXterm to deploy the Starland RAT. The malware establishes persistence, performs reconnaissance, steals credentials and cryptocurrency, and can deploy additional payloads like CastleStealer and Remcos RAT. The campaign targets users in the U.S., Germany, Romania, and Venezuela, using sophisticated techniques including registry manipulation, sandbox detection, and encrypted C2 communications via a PowerShell framework called WLDR.

1 IoCs
CISA orders feds to patch actively exploited Oracle flaw by Saturday

4w ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to patch a critical vulnerability, CVE-2026-46817, in Oracle E-Business Suite (EBS) by July 18, 2026, due to active exploitation in the wild. The flaw resides in the File Transmission component of Oracle Payments and allows unauthenticated attackers to take over systems via HTTP. Threat intelligence firm Defused confirmed exploitation after observing attacks on honeypots, despite the absence of public proof-of-concept code. CISA emphasizes prompt patching to prevent compromise of federal systems.

Windows 11 24H2 Home and Pro reach end of support in 90 days

4w ago · bleeping-computer

Microsoft has announced that Windows 11 24H2 Home and Pro editions will reach end of support on October 13, 2026, after which they will no longer receive security or non-security updates. This increases the risk of unpatched vulnerabilities being exploited on unupdated systems. Users are advised to upgrade to Windows 11 25H2 to remain protected against emerging threats.

Scattered Spider members behind TfL hack get five years in prison

4w ago · bleeping-computer

Two key members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, were sentenced to five years and six months in prison for their involvement in the August 2024 breach of Transport for London (TfL). The attack disrupted critical internal systems, forced 27,000 employees to reset passwords, and led to the theft of customer data. The group is also linked to over 120 network intrusions globally, including attacks on U.S. healthcare providers and critical infrastructure, resulting in over $115 million in extortions.

1 Actors
23andMe to pay $18 million in new genetics data breach settlement

4w ago · bleeping-computer

23andMe suffered a significant data breach in 2023 due to credential-stuffing attacks that went undetected for five months, resulting in the theft of genetic and personal data from 6.9 million customers. The breach was attributed to inadequate security controls, including lack of password blocklisting, multifactor authentication, and intrusion detection. The company faced multiple lawsuits, regulatory fines, and ultimately a bankruptcy filing, culminating in a $18 million settlement with a coalition of 43 attorneys general to resolve claims over its failure to protect user data.

AI Agents Broke the Security Playbook. Here's What Replaces It.

4w ago · bleeping-computer

AI agents are transforming enterprise environments by operating autonomously, accessing systems, and evolving faster than traditional security tools can track. This shift invalidates the old security model based on static, knowable environments, as agents can inherit human credentials and bypass conventional monitoring. The article argues that security teams must move beyond fixed workflows and vendor dashboards, instead building on a live identity foundation to maintain control over dynamic agent behaviors and access patterns.

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

4w ago · talos

UAT-11795 is a financially motivated, Russian-speaking threat actor active since June 2025, targeting users in the U.S. and Europe. The group deploys a novel Python-based remote access tool (RAT) named Starland RAT and a bespoke PowerShell-based C2 implant, WLDR, using trojanized installers of legitimate software. The campaign focuses on stealing credentials and cryptocurrency wallets, utilizing a multi-stage infection chain involving HTA downloaders, Telegram beacons, and resilient C2 infrastructure, including a fallback mechanism via a Polygon smart contract.

13 IoCs
The Hunter's Paradox: Is it time to embrace automated threat hunting?

4w ago · talos

The article discusses the 'Hunter's Paradox' in cybersecurity, where human analysts can no longer keep up with the volume, velocity, and complexity of modern threats, necessitating the use of AI-driven threat hunting. However, AI systems are vulnerable to deception by attackers who operate through lies and obfuscation, making full trust in AI problematic. The author argues for redefining threat hunting as a reasoning-driven process rather than a human-only activity, advocating for a balanced approach where AI executes hunts under human-defined strategies and constraints. The path forward involves careful implementation of AI with guardrails, graduated autonomy, and continued human oversight in creative and strategic aspects.

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover

4w ago · hacker-news

Zoom has patched a critical vulnerability, CVE-2026-53412, in its Windows clients that could allow unauthenticated remote attackers to perform account takeover via improper input validation. Additionally, three high-severity vulnerabilities related to privilege escalation were addressed in various Zoom products for Windows. There is no evidence of active exploitation in the wild. Users are advised to update to the latest versions to mitigate these risks.

OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol

4w ago · hacker-news

OpenAI has developed GPT-Red, an internal automated red-teaming model designed to identify and mitigate prompt injection vulnerabilities in its GPT series of models. GPT-Red simulates adversarial attacks by iterating through prompts to achieve malicious goals such as exfiltrating sensitive data or injecting malicious scripts, thereby improving the robustness of GPT-5.6 Sol. The model is used in adversarial training to harden production models against both direct and indirect prompt injections, significantly reducing failure rates compared to previous versions.

New Spirals ransomware encrypts victim network in under 24 hours

4w ago · bleeping-computer

A new ransomware actor named Spirals successfully breached an IT services firm in South Asia, achieving full network encryption within 24 hours of initial access. The attackers exploited a publicly exposed IIS server, deployed an ASP.NET web shell, and used tools like PsExec, revsocks, and Chisel for lateral movement and persistence. The Spirals ransomware, written in Rust, uses AES-128 encryption protected by ECDH P-256 and employs intermittent encryption to speed up the process, threatening victims with data exposure unless a ransom is paid.

2 IoCs
Next.js moves to scheduled security releases

4w ago · socket-dev

Next.js is transitioning to a scheduled security release model to address vulnerabilities in a predictable and coordinated manner, replacing ad-hoc patching. This change follows high-severity incidents like React2Shell (CVE-2025-55182), a critical remote code execution flaw in React Server Components that was widely exploited. The new program enables advance notice of patches, allowing organizations time to plan upgrades and implement mitigations. Vercel cites increasing vulnerability discovery rates due to AI-assisted tools as a driver for more frequent and structured releases.

1 Actors 5 CVEs
Harden-Runner Block Mode Now Available for macOS and Windows GitHub-Hosted Runners

1mo ago · step-security

Harden-Runner v2.20.0 now extends egress block mode to macOS and Windows GitHub-hosted runners, enabling organizations to prevent secret exfiltration across all operating systems used in CI/CD pipelines. This update addresses critical attack vectors seen in campaigns like Megalodon and GhostAction, where compromised workflows or dependencies exfiltrated secrets via outbound calls. Previously limited to audit mode on non-Linux runners, teams can now enforce network policies to block unauthorized egress traffic, strengthening supply chain security.

Runtime Security for Third-Party GitHub Actions Runners: Bitrise, Blacksmith, Depot, Namespace, and Warp

1mo ago · step-security

Supply chain attacks targeting GitHub Actions workflows pose consistent risks regardless of the runner infrastructure used. Third-party runner providers like Bitrise, Blacksmith, Depot, Namespace, and Warp are increasingly adopted for performance and specialized hardware, but they inherit the same threat model as GitHub-hosted runners. Malicious dependencies or compromised actions can still access sensitive secrets and execute harmful payloads. Harden-Runner v2.20.0 now supports these third-party runners, providing runtime security through egress monitoring, policy enforcement, and threat detection.

The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)

1mo ago · unit42

The npm ecosystem has faced escalating supply chain attacks since the emergence of the Shai-Hulud worm in September 2025. These attacks have evolved into sophisticated, wormable campaigns that steal credentials, propagate across packages, and establish persistent access in CI/CD pipelines. Recent operations, including Mini Shai-Hulud and Miasma variants, have targeted major organizations like Red Hat and AsyncAPI, using novel initial access techniques and resilient C2 infrastructure. The public release of Mini Shai-Hulud tooling has increased the risk of copycat campaigns.

56 IoCs 1 Actors
Introducing Device Policy: Enforce Approved VS Code Extensions Across Your Fleet

1mo ago · step-security

The article discusses the introduction of Device Policy by StepSecurity to help security teams enforce approved VS Code extensions across developer fleets. It highlights recent threats involving malicious IDE extensions, such as the IoliteLabs campaign and compromised Nx Console extension, which have led to backdoors and API key theft. The solution enables allow-listing of extensions using native IDE policies enforced via MDM or a standalone agent, ensuring tamper-resistant governance without requiring a proprietary enforcement layer.

Dutch police bust investment fraud ring stealing over €100 million

1mo ago · bleeping-computer

Dutch police dismantled an international investment fraud ring responsible for stealing over €100 million monthly, with tens of thousands of victims worldwide. The criminal organization operated through 20 call centers across multiple countries, using social engineering to lure victims into fake investment platforms. Victims were manipulated into sending cryptocurrency, while the group used technical obfuscation to hide their identities and infrastructure. The main suspect, an Israeli-Polish national with prior hacking charges, was arrested in Poland and extradited to the Netherlands.

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

1mo ago · hacker-news

TuxBot v3 Evolution is a newly identified IoT botnet framework showing signs of large language model (LLM)-assisted development, though with functional flaws due to incomplete code. The malware targets IoT devices using brute-force attacks and known vulnerabilities, featuring a modular architecture with multiple C2 mechanisms including encrypted TCP, DGA, IRC, DNS, and P2P. It is attributed to the Keksec ecosystem based on shared infrastructure with Kaitori v3.9 and AISURU, indicating it is part of a broader portfolio of IoT botnets.

4 IoCs 1 Actors 1 Malware
Zoom warns of critical account takeover vulnerability

1mo ago · bleeping-computer

Zoom has disclosed a critical vulnerability, CVE-2026-53412, in its Windows desktop client and SDK that could allow unauthenticated attackers to perform account takeover via network access. The flaw is described as an improper input validation issue and affects multiple versions of Zoom Workplace, VDI Client, and Meeting SDK for Windows. Zoom recommends updating to the latest patched versions to mitigate the risk, as no active exploitation has been observed at the time of disclosure.

Google Gemini CLI abused as a hacking agent, malware botnet operator

1mo ago · bleeping-computer

A Russian-speaking threat actor named 'bandcampro' abused Google's open-source Gemini CLI AI tool to operate a small-scale botnet and conduct hacking activities. The actor used the AI as an automated hacking agent to migrate command-and-control (C2) infrastructure, manage botnet operations via natural language, and attempt password guessing and data analysis. The botnet targeted systems in a dental clinic, accessing the OpenDental database, with operations sustained through simple but effective techniques including PowerShell agents and scheduled tasks. The malware lacked advanced evasion capabilities but was managed efficiently through AI-driven automation.

1 IoCs
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

1mo ago · hacker-news

OkoBot is a malware framework targeting Windows users, active since April 2025, that injects phishing pages into legitimate cryptocurrency wallet applications like Ledger Live and Trezor Suite to steal recovery phrases. One of its modules, SeedHunter, hooks into Electron-based apps and waits for hardware wallet connections before displaying a malicious recovery page. The framework uses trojanized software and phishing lures to gain access, establishes persistent remote access via SSH and RDP, and deploys multiple surveillance and data-stealing plugins. Kaspersky attributes the campaign to an unknown actor but notes Russian-language artifacts and targeting patterns.

9 IoCs 2 Malware
We built a vulnerability vending machine: AI tokens in, zero-days out

1mo ago · bleeping-computer

Intruder's AI-powered vulnerability research pipeline, combining code scanning with large language models, discovered a high-impact blind SQL injection vulnerability (CVE-2026-3985) in the Creative Mail WordPress plugin. The vulnerability allows unauthenticated attackers to extract sensitive database information, including admin password hashes and secret tokens, when WooCommerce is also installed. The exploit chain requires multiple requests and was automatically discovered and validated using AI, demonstrating the growing capability of AI in both offensive and defensive security research.

​ ​AsyncAPI npm packages infected with credential-stealing malware

1mo ago · bleeping-computer

Five malicious versions of AsyncAPI npm packages were published in a supply-chain attack that delivered a credential-stealing remote access trojan. The attacker compromised GitHub repositories via a misconfigured CI/CD pipeline, leveraging legitimate workflows to publish trojanized packages with valid SLSA attestations. The malware, which resembles the Miasma backdoor, steals credentials, tokens, browser data, and other sensitive information, and communicates via HTTP, Nostr, Ethereum smart contracts, and libp2p. The exposure window lasted about four hours on July 14, 2026, and although the packages have been removed, existing installations may still be compromised.

1 IoCs 1 Malware
The Red Agent POV: The One Boolean That Broke a B2B Platform’s Credit System

1mo ago · wiz

A business-logic flaw in a B2B platform's data API allowed unauthorized access to premium contact data without spending credits. The vulnerability stemmed from the backend trusting a client-controlled boolean flag 'unmaskContactData' without validating user entitlements. This enabled free-tier users to bypass paywall restrictions and extract unmasked business emails, phone numbers, and personal information at scale. The flaw highlights a critical gap in server-side authorization enforcement, which traditional security tools failed to detect.

1 IoCs
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

1mo ago · hacker-news

A critical vulnerability in the Cursor IDE on Windows allows malicious cloned repositories to trigger arbitrary code execution by placing a file named git.exe in the project root. When the repository is opened, Cursor automatically executes this binary without user consent, enabling attackers to run code with the user's privileges, including access to SSH keys and cloud tokens. Despite being reported in December 2025, no patch has been released, and the issue remains unaddressed in the latest version. Similar behavior has been observed in other AI-powered development tools, indicating a broader trend in untrusted search path vulnerabilities.

1 IoCs 1 CVEs
New Webinar: Closing the Approval Gap in AI-Era Ad Tech

1mo ago · hacker-news

The article discusses the 'Approval Gap' in AI-era ad tech, where approved marketing tags can dynamically load unvetted fourth-party scripts, creating client-side security risks. These scripts operate with the same privileges as first-party code, potentially exposing sensitive customer data. The threat is exacerbated by AI-driven ad tech that rapidly evolves, making point-in-time security reviews insufficient. The piece emphasizes the need for continuous monitoring of digital supply chains to prevent unauthorized data access.

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

1mo ago · hacker-news

Security researcher Chaotic Eclipse has released a proof-of-concept (PoC) exploit named LegacyHive, which exploits a Windows User Profile Service vulnerability to load arbitrary hives and achieve privilege escalation. The exploit works on all supported Windows versions, including those updated with the July 2026 Patch Tuesday. The researcher claims the original version did not require additional credentials and could target any registry hive, raising concerns about potential misuse. This disclosure follows an ongoing dispute between the researcher and Microsoft over responsible vulnerability disclosure.

← Previous Next →