Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

The Replicant in Your Directory: AI Agents and the Identity Security Gap

1mo ago · bleeping-computer

The article discusses how AI agents and machine identities are outpacing traditional identity governance, creating a growing security gap. These non-human identities, such as service accounts and OAuth applications, often inherit excessive permissions and persist long after their original purpose, increasing the attack surface. A notable incident involved threat actor UNC6395 exploiting a trusted OAuth token from Salesloft's Drift integration to pivot across Salesforce, AWS, and Snowflake environments. The core issue is not new vulnerabilities, but the lack of ownership, visibility, and lifecycle management for machine identities.

1 Actors
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks

1mo ago · hacker-news

Angelo Martino, a former ransomware negotiator, was sentenced to 70 months in prison for conspiring with BlackCat ransomware operators to extort victims by leaking confidential negotiation details. He collaborated with two cybersecurity professionals, Ryan Goldberg and Kevin Martin, to deploy BlackCat ransomware against multiple U.S. victims between April and November 2023. Martino betrayed clients by sharing their insurance limits and negotiation strategies, enabling higher ransom demands. The case highlights insider threats in cybersecurity and resulted in $10 million in seized assets.

Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets

1mo ago · hacker-news

Attackers have exploited a vulnerability dubbed 'Ill Bloom' in cryptocurrency wallet software that used weak randomness when generating recovery phrases, enabling them to predict and steal funds from vulnerable wallets. A coordinated attack on May 27 drained approximately $3.1 million from 431 wallets, primarily affecting older or lesser-known mobile wallets created as far back as 2018. The flaw does not impact hardware wallets or most mainstream software wallets, but users are urged to check their addresses on illbloom.org and migrate funds if their wallet is flagged as exposed.

1 IoCs 2 CVEs
Former ransomware negotiator gets 4 years for BlackCat attacks

1mo ago · bleeping-computer

A former ransomware negotiator, Angelo Martino, was sentenced to 70 months in prison for participating in BlackCat (ALPHV) ransomware attacks between April 2023 and April 2025. Alongside accomplices Kevin Tyler Martin and Ryan Clifford Goldberg, Martino targeted at least five U.S. organizations, leveraging insider knowledge of victims' insurance limits to maximize ransom demands. The attackers operated as BlackCat affiliates, paying 20% of ransom proceeds to the core group while extorting tens of millions from victims in financial services, healthcare, and education sectors.

1 Malware
OpenMandriva Linux says contributor tried to sabotage the project

1mo ago · bleeping-computer

The OpenMandriva Linux project faced an internal sabotage attempt allegedly carried out by Davide Beatrici, a developer associated with the Mumble project, following a dispute over project direction and contributor behavior. Beatrici deleted repositories and pushed an empty package to the Cooker repository, targeting the Gnome and Cosmic desktop environments. Although he denied malicious intent, claiming his actions were in response to disagreements over project governance, the OpenMandriva team is restoring affected systems and conducting a security audit. Legal action has been waived by the project despite the severity of the incident.

Fake Braintree NuGet Package Skims Credit Cards and Harvests Merchant Credentials

1mo ago · socket-dev

A malicious NuGet package named 'Braintree.Net' has been identified as a typosquatting campaign targeting developers using the legitimate Braintree payment SDK. The package intercepts live credit card data, steals merchant API credentials, and harvests environment secrets through a multi-stage .NET implant. It exfiltrates sensitive data to attacker-controlled domains and uses obfuscated C2 communications, particularly in companion dependencies like DependencyInjector.Core. The threat relies on production-only gating to avoid detection during development and testing.

27 IoCs
WolfSSL, GeoVision, VTK vulnerabilities

1mo ago · talos

Cisco Talos identified multiple vulnerabilities in WolfSSL, GeoVision, and VTK-DICOM software. The vulnerabilities include improper input validation, integer underflow, memory corruption, OS command injection, buffer overflows, privilege escalation, XSS, and encryption weaknesses. These issues have been patched by the vendors, and Snort rules are available to detect potential exploitation attempts.

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

1mo ago · hacker-news

Microsoft has analyzed a destructive Windows backdoor named GigaWiper, which combines disk-wiping, fake ransomware, and spyware capabilities. The malware, written in Go, allows operators to choose from multiple destructive payloads, including full disk wiping, overwriting the Windows drive, and fake encryption with no decryption key. It also includes surveillance features such as screen recording, VNC streaming, and system reconnaissance. The same malware was independently identified as BLUERABBIT by Binary Defense and is linked to an Iran-nexus group targeting Israeli organizations, with ties to prior threats like Crucio and FlockWiper.

2 IoCs 1 Actors
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

1mo ago · hacker-news

Multiple overlapping campaigns are actively enumerating corporate GitHub organizations, repositories, and user accounts using automated scraping tools and compromised or dormant GitHub accounts. Attackers leverage old 'ghost' accounts and exposed personal access tokens (PATs) to blend in with legitimate traffic and avoid detection while conducting reconnaissance. The activity includes querying public endpoints to map organizational structures and, in some cases, cloning private repositories. This behavior enables threat actors to gather intelligence for potential supply chain attacks.

1 IoCs
Injective SDK on npm infected with cryptocurrency wallet stealer

1mo ago · bleeping-computer

Hackers compromised a contributor's GitHub account for the Injective Labs SDK project and published a malicious version (1.20.21) of the @injectivelabs/sdk-ts npm package. This supply-chain attack targeted developers building cryptocurrency-related applications, stealing wallet private keys and mnemonic seed phrases when SDK functions were used. The stolen data was exfiltrated via HTTP POST to a legitimate Injective Labs endpoint to blend in with normal traffic. The malicious package was downloaded 310 times before being deprecated, and 17 associated packages were also compromised.

2 IoCs
Wiz in the Verizon DBIR: How AI Acceleration and Cloud Sprawl Impact Modern Defense

1mo ago · wiz

The 2026 Verizon DBIR highlights that attackers are exploiting known vulnerabilities and trusted relationships at increasing speed and scale, with vulnerability exploitation now the leading initial access vector in 31% of breaches. Cloud environments are particularly at risk, as 40% of cloud intrusions begin with weaponized vulnerabilities. Attackers are leveraging AI to accelerate reconnaissance, exploit development, and post-compromise automation, while supply chain compromises and identity abuse further expand the attack surface.

How ProdSec uses Wiz

1mo ago · wiz

The article describes how Wiz's Product Security (ProdSec) team leverages the Wiz platform to secure cloud environments through integrated threat detection, CI/CD security controls, and proactive threat modeling. The team employs Wiz CLI scanning, custom Cloud Configuration Rules (CCRs), and automated threat detection using the Wiz Blue Agent to identify and respond to risks in real time. Emphasis is placed on shifting security left into development workflows, contextualizing alerts for specialized infrastructure, and pressure-testing security tooling using AI-powered attack simulations like Red Agent.

Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys

1mo ago · step-security

On July 8, 2026, attackers compromised a trusted developer's account to inject a backdoor into the @injectivelabs/sdk-ts npm package, a core SDK for the Injective blockchain. The malicious code captured cryptocurrency wallet recovery phrases and private keys during wallet creation or loading and exfiltrated them to an attacker-controlled server disguised as legitimate infrastructure. The backdoor was distributed across 18 related npm packages for less than an hour before being detected and reverted, posing a significant risk to any application that installed the tainted versions during that window.

5 IoCs
Winning 54% of the time

1mo ago · talos

Cisco Talos has identified activity from the China-nexus threat actor UAT-7810, which is expanding its Operational Relay Box (ORB) networks using custom malware to exploit vulnerabilities in unpatched Ruckus and ASUS routers. The group has deployed updated backdoors, including LONGLEASH and DOGLEASH, to create covert proxy infrastructure used by other APT groups. This infrastructure enables threat actors to mask their origins and bypass traditional defenses by routing traffic through compromised edge devices.

12 IoCs
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

1mo ago · hacker-news

This week's threat landscape highlights a range of cyber activities, from cloud bucket hijacking and ransomware tooling overlaps to social engineering campaigns and supply chain attacks. Notable incidents include a global fraud operation resulting in nearly 6,000 arrests, typosquatting of payment SDKs on npm and PyPI, and the abuse of Microsoft Teams for delivering EtherRAT. Additionally, new techniques like Process Parameter Poisoning and ADFS token forgery underscore evolving evasion and privilege escalation methods.

2 IoCs 1 Actors 2 Malware
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

1mo ago · hacker-news

GitHub has released npm version 12, disabling install scripts by default to reduce supply chain risks. The update requires explicit user approval for lifecycle scripts, Git dependencies, and remote URL resolutions. Additionally, granular access tokens (GATs) that bypass 2FA are being restricted from performing sensitive account and package management actions, with full publishing capabilities removed in a future update. These changes aim to harden npm's security posture against automated attacks and token misuse.

Microsoft expects more Windows security updates from AI-discovered flaws

1mo ago · bleeping-computer

Microsoft anticipates an increase in Windows security updates due to the use of artificial intelligence in identifying vulnerabilities within its codebase. The company is leveraging its AI-powered system, MDASH, to scan and validate potential security flaws in critical Windows binaries, leading to faster discovery and remediation. While AI accelerates defensive efforts, Microsoft also acknowledges its use by threat actors to exploit zero-day vulnerabilities. As a result, Microsoft is updating its Secure Development Lifecycle to integrate AI earlier in development and counter emerging AI-enabled attack techniques.

New Helix vishing group emerges in SharePoint data theft attacks

1mo ago · bleeping-computer

A new data-extortion group named Helix has emerged, conducting SharePoint data theft attacks using vishing, device code phishing, and MFA abuse. The group targets organizations by impersonating employees or managers to gain account access, then exfiltrates data for extortion or resale. Helix exhibits operational similarities to ShinyHunters and BlackFile, with potential ties based on infrastructure and tactics. The group's consistent use of automated SharePoint enumeration and exfiltration from a specific IP and user-agent provides a strong technical fingerprint.

1 IoCs 1 Actors
Compromised Injective SDK npm Package Exfiltrates Wallet Keys and Mnemonics

1mo ago · socket-dev

A compromised version of the @injectivelabs/sdk-ts npm package (1.20.21) was published with malicious code designed to exfiltrate cryptocurrency wallet private keys and mnemonic phrases. The backdoor was introduced via a compromised developer account and spread to 17 additional scoped packages that pinned the malicious version. The stolen data was exfiltrated via POST requests to a seemingly legitimate Injective Labs infrastructure endpoint, enabling attackers to reconstruct and access victims' wallets. Although the incident was quickly detected and mitigated, the malicious package versions remain downloadable.

23 IoCs
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

1mo ago · hacker-news

The GodDamn ransomware, attributed to the threat actor Hyadina, leverages the Microsoft-signed PoisonX kernel driver (g11.sys) to disable endpoint defenses via a bring your own vulnerable driver (BYOVD) technique. The attack chain includes credential harvesting with NirSoft tools, lateral movement using PsExec, and remote access via AnyDesk, which is deployed through PowerShell scripts and registered as a persistent service. This ransomware is considered a rebrand of Beast, which evolved from Monster, and demonstrates an escalation in defensive evasion capabilities through signed malicious drivers.

2 IoCs
Summer of Clearinghouses

1mo ago · hacker-news

The article discusses the emergence of 'clearinghouses' for managing pre-disclosure vulnerabilities in open source software, driven by AI-powered security research. These platforms aim to centralize vulnerability data, but the real value lies in automated actuation—turning findings into patched, signed software artifacts quickly. The author emphasizes that scale, speed of remediation, and upstream patching are critical for effectiveness, while warning that many announced clearinghouses are superficial. The long-term goal is to move beyond patching toward 'secure by design' systems that prevent vulnerabilities altogether.

1 CVEs
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up

1mo ago · hacker-news

The article discusses the increasing speed of cyberattacks powered by artificial intelligence, emphasizing that tasks which previously took days can now be executed in minutes. It highlights the use of AI models like Mythos to automate and scale attack operations, enabling rapid lateral movement and exploitation. The focus is on defensive strategies, particularly Zero Trust, to counter these fast-moving threats by reducing attack surface, blocking lateral movement, and deploying early detection mechanisms.

The Hidden Security Risks of Reduced Summer IT Coverage

1mo ago · bleeping-computer

Cybercriminals exploit reduced IT and security staffing during summer months to increase attack success rates, leveraging slower response times and reduced oversight. There is a 40% increase in cyberattacks during holiday periods, with phishing and Business Email Compromise (BEC) campaigns becoming more effective due to AI-driven social engineering. Lean staffing extends attacker dwell time, allowing for lateral movement, data theft, and ransomware deployment before detection.

New Forg365 phishing platform uses AI to target Microsoft 365 accounts

1mo ago · bleeping-computer

A new phishing-as-a-service (PhaaS) platform named Forg365 targets Microsoft 365 accounts using AI-generated lures, adversary-in-the-middle (AiTM) phishing, and device-code authentication exploits. The platform provides attackers with a comprehensive dashboard for campaign management, token handling, and persistent access via a browser extension called ForgCookie. It leverages legitimate services like Amazon SES and Cloudflare Pages to blend malicious activity with normal traffic, evading detection while enabling post-compromise persistence through OAuth token and cookie theft.

1 IoCs
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges

1mo ago · hacker-news

Microsoft has patched a privilege escalation vulnerability in the Microsoft Malware Protection Engine, dubbed RoguePlanet and tracked as CVE-2026-50656, which could allow attackers to gain SYSTEM-level privileges. The flaw stems from a race condition that can be exploited to spawn a privileged shell, even with real-time protection enabled. It affects systems updated with the June 2026 Patch Tuesday updates, and no customer action is required as updates are applied automatically. This is the fourth such vulnerability disclosed by researcher Chaotic Eclipse, following previous flaws like BlueHammer and UnDefend.

Police arrests 5,800 suspects in global anti-fraud crackdown

1mo ago · bleeping-computer

Operation First Light 2026, a global law enforcement initiative coordinated by INTERPOL, targeted social engineering fraud and money laundering across 97 countries, resulting in 5,811 arrests and the seizure of $293 million in illicit assets. The operation identified over 142,000 victims and disrupted thousands of financial fraud cases, including business email compromise, romance scams, and investment fraud. This effort is part of a broader series of coordinated actions, including Operation Synergia II and Operation Red Card 2.0, aimed at dismantling transnational cybercrime networks.

Microsoft to retire the OWA Light client in Exchange Server

1mo ago · bleeping-computer

Microsoft has announced the retirement of the OWA Light client in Exchange Server, citing modern browser capabilities, improved network conditions, and evolving security requirements as reasons. The lightweight web client, introduced two decades ago for older browsers and low-bandwidth environments, will be disabled in an upcoming update expected in August 2026. This move aims to reduce legacy attack surface and streamline engineering efforts toward the modern Outlook on the web experience.

Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes

1mo ago · hacker-news

A threat actor named Lurking Lizard has been operating a malicious residential proxy business since at least August 2022, using trojanized installers and fake mobile apps to recruit devices into a proxy botnet. The actor leverages lookalike domains, including '7zip[.]com', and impersonates legitimate proxy services to drive traffic to scam storefronts. Compromised devices are used to funnel third-party traffic, creating risks for users whose IP addresses may be abused for cyberattacks.

2 IoCs
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

1mo ago · hacker-news

Researchers at Wiz discovered a vulnerability pattern called GhostApproval affecting multiple AI coding assistants, including Amazon Q Developer, Claude Code, and Cursor. The flaw exploits symbolic links (symlinks) to redirect file writes to sensitive system files, such as SSH authorized_keys or shell startup files, bypassing user consent by showing misleading approval prompts. While some vendors have issued fixes, others dispute the severity, and the issue highlights a systemic design weakness in how AI agents handle file operations and user approvals.

3 IoCs 2 CVEs
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

1mo ago · hacker-news

AI coding agents from Anthropic and OpenAI, designed to review code for security issues, can be tricked into executing malicious payloads when operating in autonomous mode. Researchers demonstrated a 'Friendly Fire' attack where a seemingly benign README.md instructs the agent to run a malicious script disguised as a legitimate build artifact. The attack bypasses safety checks by blending into normal project workflows, enabling code execution on the host without user interaction. Although currently a proof-of-concept, it highlights a critical design flaw in how AI agents interpret and act on untrusted instructions.

1 IoCs
← Previous Next →