Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

2w ago · hacker-news

Open VSX removed 77 malicious 'evil twin' extensions that impersonated legitimate developer tools but were designed to exfiltrate sensitive developer environment data. The extensions, uploaded between July 26 and August 1, 2026, sent system information, workspace details, and CI/CD context to the domain mangorbit[.]com. Nineteen of them were more advanced reconnaissance payloads that collected Git metadata, installed extensions, CI environment variables, and telemetry settings. The malware included fallback mechanisms via DNS TXT records and persistence logic to distinguish between human and configuration-driven installations.

1 IoCs
Phishing service spoofs RingCentral to steal Microsoft 365 accounts

2w ago · bleeping-computer

The Greatness phishing-as-a-service (PhaaS) platform has evolved to conduct adversary-in-the-middle and device-code phishing attacks, primarily targeting Microsoft 365 accounts. It abuses the trusted reputation of RingCentral by spoofing emails from service@ringcentral[.]com, using lures like fake voicemail and performance review notifications to bypass email filters. Victims are redirected to phishing pages that capture MFA-approved tokens, enabling persistent access to mailboxes, Teams, SharePoint, and other Microsoft 365 services. The attackers may have leveraged data from a recent RingCentral breach to target legitimate users.

2 IoCs 1 Actors
TP-Link patches Omada ZTP flaws allowing hackers to breach networks

2w ago · bleeping-computer

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada business networking devices, which could be exploited to achieve remote code execution and network infiltration. The flaws, discovered by Forescout’s Vedere Labs, include hard-coded keys, information disclosure, device hijacking, and spoofing, and can be chained with previously disclosed command-injection vulnerabilities (CVE-2025-7850, CVE-2025-7851). Attackers could exploit a race condition during cloud adoption, use default credentials, and inject JavaScript to steal administrator credentials and reconfigure devices or establish unauthorized VPN access.

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

2w ago · hacker-news

Google removed three AI agent workflows from its Agent Development Kit (ADK) Python repository after Pillar Security demonstrated a supply chain attack vector. A malicious GitHub issue could trigger a prompt injection in a triage agent, leading to execution of a privileged code-fixing agent via a trusted bot account. This allowed arbitrary code execution on the CI runner and exfiltration of sensitive credentials, including a bot personal access token (PAT), a Google API key, and a Google Cloud service-account credential. Although no in-the-wild exploitation was observed, the attack chain exploited overly broad permissions and insufficient isolation between automation components.

77 Open VSX extensions found harvesting developer info

2w ago · bleeping-computer

Manifold Security discovered a campaign involving 77 malicious extensions on the Open VSX marketplace that impersonated legitimate developer tools to harvest system and development environment metadata. These 'evil twin' extensions exfiltrated information such as hostnames, workspace paths, Git metadata, CI/CD environment details, and developer identifiers to a common infrastructure at mangorbit[.]com. While source code and credentials were not accessed, the collected data could be used to profile organizations and private repositories. The extensions used tracking identifiers, supported fallback communication via DNS TXT records, and were removed from Open VSX by August 3, 2026, though manual removal from developer systems is required.

5 IoCs
New XCSSET variant targets macOS devs via compromised Xcode projects

2w ago · bleeping-computer

A new variant of the XCSSET malware, version 40, is targeting macOS developers by compromising Xcode projects and GitHub repositories. The malware spreads when developers build infected projects, enabling it to propagate across systems and deploy 17 modules for credential theft, keystroke logging, clipboard manipulation, browser hijacking, and data exfiltration. This variant includes new capabilities such as a Chrome hijacker that enables real-time web traffic interception and a Telegram trojanizer that replaces the legitimate Telegram Desktop app with a malicious version. The malware employs advanced evasion techniques, disables macOS security features, and uses encrypted, build-unique ciphers to avoid detection.

1 Malware
How legitimate cloud platforms enable phishers to bypass MFA

2w ago · securelist

Threat actors are leveraging legitimate cloud platforms such as Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS to host phishing infrastructure and bypass multi-factor authentication (MFA). The attack uses a multi-stage adversary-in-the-middle (AitM) technique involving contact harvesting, transparent proxy initialization via service workers, and browser-in-the-browser (BitB) spoofing to intercept credentials and session tokens. Phishing pages are hosted on trusted domains with good reputations, making detection difficult and enabling large-scale, low-cost deployment of malicious sites.

11 IoCs
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

2w ago · hacker-news

The Greatness PhaaS (Phishing-as-a-Service) platform has added device code phishing capabilities to bypass Multi-Factor Authentication (MFA) by abusing the OAuth 2.0 Device Authorization Grant. This enables attackers to steal authentication tokens without presenting fake login pages, making detection more difficult. The service supports multiple phishing methods including adversary-in-the-middle (AiTM) attacks, OAuth consent abuse, and phishing for iCloud, Yahoo, and Google Workspace. Post-compromise, attackers use stolen tokens to access Microsoft 365 resources via Microsoft Graph API and establish persistence by registering new devices to obtain Primary Refresh Tokens (PRTs).

5 IoCs
Massive ChainDrop npm supply-chain attack infects hundreds of packages

2w ago · bleeping-computer

A massive supply-chain attack dubbed ChainDrop has compromised over 1,300 npm packages with a combined 2 billion monthly downloads. The attack began with the compromise of the Keyv maintainer's GitHub account, allowing the threat actor to push malicious code directly to main branches and publish poisoned versions through legitimate CI/CD workflows. The malware, named ChainDrop and based on the Shai-Hulud worm, includes a dropper (setup.mjs) and an obfuscated infostealer (Math_Symbol.js) that collects developer and cloud credentials, encrypts them, and exfiltrates them to a public GitHub repository. The attack spreads laterally by self-propagating to other packages maintained by developers whose environments were infected.

5 IoCs 1 Malware
Worm compromises hundreds of popular npm packages

2w ago · datadog-security-labs

On August 4, 2026, a worm compromised several high-profile npm packages, including keyv, file-entry-cache, and flat-cache, each with around 150 million monthly downloads. The malicious commit (174f6a5) in the keyv package introduced a backdoor designed to propagate to adjacent npm packages, indicating a supply chain attack aimed at widespread distribution. The campaign represents a significant open-source software supply chain compromise with potential for broad impact due to the popularity of the affected packages.

4 IoCs
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2

2w ago · step-security

A self-propagating worm dubbed ChainDrop is actively compromising npm packages by publishing malicious versions using stolen maintainer credentials. The malicious packages include heavily obfuscated files such as setup.mjs and math_init.js, which execute during installation via preinstall scripts, enabling credential harvesting in CI/CD environments. The worm uses Ethereum-based dead-drop command-and-control infrastructure, and over 435 packages with more than 1,550 compromised versions have been identified since August 4, 2026. Organizations using affected packages should assume compromise and rotate all associated credentials and secrets.

2 IoCs
Almost Half of Malware Samples Communicate Direct to IP

2w ago · unit42

A significant portion of malware samples bypass DNS by communicating directly to IP addresses, evading DNS-based security controls. Analysis of 4 million dynamic reports shows 45.32% of malware with command-and-control (C2) activity used direct-to-IP (D2IP) connections, accounting for 23.17% of all C2 attempts. Threats identified include Phorpiex ransomware droppers, a data exfiltration campaign using obfuscated \GET requests, SectopRAT deployments targeting educational institutions, and IoT botnets like Mozi and a new Mirai variant named Boatnet. These threats leverage hard-coded IP addresses and custom HTTP methods to avoid detection and maintain persistence.

22 IoCs 3 Malware
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

2w ago · hacker-news

cPanel has patched a critical vulnerability, CVE-2026-58048 (CVSS 4.0: 9.4), that allows an authenticated hosting customer to execute SQL commands with full administrative database privileges, effectively crossing the privilege boundary into the server's root database context. The flaw resides in the database-renaming process, where SQL mode is not preserved, leading to execution in root context. This could lead to full operating system compromise depending on configuration. Two additional vulnerabilities were patched in the same release: CVE-2026-58047, an HTTP request-smuggling issue in cpsrvd, and a local privilege escalation in Exim via unsafe string expansion in .forward files.

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

2w ago · hacker-news

An active multi-wave campaign dubbed SMOKE#SCREEN by Securonix uses fake Adobe and Zoom update lures, along with business document themes, to deliver Remote Monitoring and Management (RMM) tools like ConnectWise ScreenConnect. The attack begins with spear-phishing emails containing obfuscated VBScript droppers that perform anti-analysis checks before deploying payloads. These payloads ultimately install ScreenConnect, providing attackers with persistent remote access through attacker-controlled relay servers. A separate but related campaign distributes the Powercat Java-based information stealer via fake Xeno Roblox cheat installers, enabling credential theft, surveillance, and remote control.

10 IoCs 1 Malware
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

2w ago · hacker-news

A malicious npm package worm originating from [email protected] has spread to hundreds of packages across multiple organizations, leveraging preinstall scripts to steal developer and CI credentials, including repository, cloud, and private-key material. The payload can propagate by republishing compromised packages using stolen npm credentials and includes secondary execution paths via .claude and .vscode hooks that activate when a user trusts the workspace. The attack leveraged legitimate GitHub Actions workflows, resulting in valid SLSA and OIDC provenance, making detection more difficult. The malware family is linked to prior PyPI compromises and is associated with the Shai-Hulud campaign, though the specific threat actor remains unidentified.

6 IoCs
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack

2w ago · socket-dev

An active supply chain attack has compromised multiple popular npm packages in the 'keyv' and 'cacheable' namespaces, attributed to a compromised maintainer account (Jaredwray). Malicious preinstall hooks in the packages execute a two-stage payload that downloads a standalone Bun runtime, harvests cloud credentials (including AWS, GCP, Azure, Kubernetes, HashiCorp Vault, GitHub Actions, and npm tokens), and self-propagates by republishing trojanized versions of other packages using stolen npm tokens. The attack leverages obfuscated JavaScript, exfiltrates data via DNS and GitHub repositories, and establishes persistence through autostart hooks in developer environments. The malicious packages remain live on npm, and the campaign is actively evolving with new packages being published.

5 IoCs
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI

2w ago · talos

Cisco Talos researchers analyzed how adversaries are weaponizing AI across multiple attack vectors, including malicious software development, criminal force multiplication, and vulnerability research. Threat actors with varying skill levels are using AI to create DDoS tools, bulk-email validation platforms, credential harvesters, and cryptojacking fleets, often bypassing model guardrails through simple evasion techniques like ownership claims or CTF labeling. A francophone actor developed an automated 'Token Pipeline' to exploit React2Shell vulnerabilities and harvest credentials from exposed Git configurations, while a Turkish-speaking actor leveraged AI to manage a Monero-mining operation via compromised torrent clients. Spanish and Russian-speaking actors used AI to conduct autonomous pentesting, build scam chatbots, and target Telegram Mini Apps for cryptocurrency theft.

5 IoCs
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

2w ago · hacker-news

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability, CVE-2026-18577, in N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. The flaw, stemming from incomplete patching of a prior vulnerability (CVE-2026-18556), enables authentication bypass and account takeover, allowing attackers to gain administrative access and pivot to managed endpoints using the Take Control feature. Indicators include malicious use of legitimate tools like Cloudflared and connections from specific IP addresses associated with Mullvad and NordVPN exit nodes. While no specific threat actor has been attributed, exploitation has been observed across multiple organizations, with attackers conducting reconnaissance, lateral movement, and persistence.

6 IoCs
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

2w ago · hacker-news

The DOUBLECUP loader-as-a-service (LaaS) is being used by threat actors to deliver malware such as CountLoader and a previously undocumented Python-based remote access trojan (RAT) called DeviceManager. The attack begins with social engineering lures via fake CRM login pages using ClickFix, which trigger the download of steganographically encoded PNG images into the browser cache. These images contain hidden payloads that, when extracted, execute malicious code to deploy the final malware. CountLoader uses environmental keying based on the victim's public IP address for decryption and establishes persistence by modifying browser shortcuts, while DeviceManager leverages blockchain-based C2 resolution via Ethereum/Polygon smart contracts using EtherHiding.

4 IoCs 1 Malware
New Pass-ta-key attacks let malware hijack Google-synced passkeys

2w ago · bleeping-computer

Security researchers from Palo Alto Networks' Unit 42 identified three novel attacks, collectively named 'Pass-ta-key,' that exploit weaknesses in Google Password Manager's handling of passkeys on Windows devices with TPM. The attacks allow malware on an already-compromised device to hijack synced passkeys, impersonate trusted devices, register attacker-controlled verification keys, and extract the master encryption key (security domain secret) from Chrome's memory. While the cryptography of passkeys remains intact, the attacks bypass user verification and enable account takeover, particularly on services that fail to properly validate user verification flags. eBay was found vulnerable but has since patched the issue.

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

2w ago · bleeping-computer

Microsoft has identified a global campaign dubbed CaptiveCrunch, attributed to the Russian threat actor Midnight Blizzard (also known as APT29 or Storm-2945), targeting hotel and conference center Wi-Fi networks. The attackers manipulate DNS settings on captive portal equipment to redirect users to phishing pages impersonating Microsoft 365 login portals or abusing Microsoft Entra ID device code authentication flows. They also deploy custom malware, including the Go-based RAT CornFlake and the PowerShell-based ChocoShell, to steal credentials, session tokens, and conduct surveillance. A previously undisclosed tactic involves fake OS and browser update prompts (ClickFix) delivering malware to Windows and Android devices.

3 IoCs 2 Actors
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

2w ago · hacker-news

A software supply chain attack has been uncovered involving 18 malicious npm packages that impersonate legitimate Alibaba-scoped packages, targeting Chinese-speaking developers. The packages deliver a cross-platform remote access trojan (RAT) through a multi-stage payload delivery mechanism that uses a rule engine and vm module to execute OS-specific malicious actions. On Windows, it trojanizes enterprise apps like Alilang; on Linux, it runs a memory-resident binary; and on macOS, it installs a persistent background script. The final payload enables command execution, file exfiltration, host reconnaissance, and lateral movement, suggesting industrial espionage as the likely motive.

20 IoCs
New DOUBLECUP ClickFix service hides malware in browser cache images

2w ago · bleeping-computer

A Russian loader-as-a-service named DOUBLECUP has been active since June 2026, enabling threat actors to conduct ClickFix attacks by hiding malicious payloads in steganographic PNG images cached in victims' browsers. The service provides infrastructure for hosting malicious images, managing sessions, and delivering payloads, which include an updated CountLoader malware and a new Python-based RAT called DeviceManager. Victims are lured to malicious sites impersonating legitimate services like NetSuite and Salesforce, where fake CAPTCHA prompts trick them into executing commands that extract and run malware from the browser cache. DeviceManager uses blockchain smart contracts (EtherHiding) to dynamically retrieve C2 addresses, enhancing resilience against takedown efforts.

3 IoCs 1 Malware
Fake Roblox Xeno script launcher pushes infostealer, RAT malware

2w ago · bleeping-computer

A malicious campaign distributes fake Xeno Executor installers to Roblox players, delivering a Java-based information stealer and remote access trojan (RAT). The malware is promoted through gaming forums and Discord, masquerading as an 'undetected' version of the legitimate tool. Once executed, it deploys a multi-stage payload that steals browser data, credentials, cryptocurrency wallets, and enables surveillance and full remote control of the infected system. Bitdefender links this campaign to a previously documented threat known as Powercat, now with enhanced capabilities and updated C2 infrastructure.

2 IoCs
Before the first prompt: Code execution paths in trusted coding-agent projects

2w ago · datadog-security-labs

This article details two novel code execution techniques in trusted coding-agent projects that occur after project trust but before the first user prompt, bypassing traditional security controls. In Codex, a malicious project can define a project-scoped Model Context Protocol (MCP) server in .codex/config.toml, causing immediate execution of attacker-controlled processes upon project open. In Claude Code, an attacker can manipulate the PATH environment variable via .claude/settings.json to hijack Git calls and execute a malicious git wrapper script from within the repository. These techniques allow code execution without model interaction or user approval, highlighting the risk of treating project trust as safe.

5 IoCs
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

2w ago · hacker-news

The INC Ransomware group has become the dominant threat actor exploiting zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances, specifically CVE-2026-15409 and CVE-2026-15410, which allow for arbitrary command execution. The group has exploited these flaws since at least June 22, 2026, deploying a Python script called KNUCKLEBALL to launch the Suo5 proxy and a custom Java web shell named ORANGETAIL. Victims span multiple countries including the U.S., Australia, and Switzerland, with attackers using social engineering tactics such as phone calls from an individual claiming to be 'Andrew' and using the number +1 (304) 384-0401 to pressure victims into negotiations via info@helprans[.]com.

4 IoCs
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

2w ago · hacker-news

Unit 42 researchers identified three post-compromise attack paths—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—targeting Chrome's Google Password Manager on Windows systems with TPM. These attacks allow malware with local access to hijack passkey-protected accounts by exploiting weaknesses in device key handling, user-verification key re-enrollment, and extraction of the 32-byte Security Domain Secret (SDS) from memory. While no active exploitation in the wild is reported, the techniques enable silent authentication, persistent access, and passkey decryption if an attacker gains initial endpoint access.

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

2w ago · bleeping-computer

The ExfilSquad data extortion group claimed responsibility for a cyberattack on the U.K.'s Police National Legal Database (PNLD), compromising contact data of over 100,000 police officers, staff, and criminal justice professionals. The breach exposed full names, organizations, and email addresses of PNLD subscribers and Ask the Police users. ExfilSquad claims to have stolen 1.9 GB of data containing approximately 135,000 records and demanded a ransom to prevent further data release. The incident is under investigation with support from cybersecurity experts and the National Crime Agency (NCA), though no passwords or sensitive investigative data were compromised.

N-able warns of N-central auth bypass flaw exploited in attacks

2w ago · bleeping-computer

N-able has warned customers of active exploitation of an authentication bypass vulnerability, CVE-2026-18577, affecting both hosted and on-premises versions of its N-central Remote Monitoring and Management (RMM) platform. The flaw, stemming from an incomplete patch for a previously addressed vulnerability (CVE-2026-18576), allows attackers to achieve administrative account takeover. N-able released hotfix 2026.3.1.7 to remediate the issue and urged all customers to upgrade immediately, with hosted deployments already updated. Indicators of compromise include malicious use of Cloudflared, suspicious IP addresses, and 'svchost.exe' located in user documents folders.

6 IoCs
An analysis of incidents at Brazilian educational institutions

2w ago · securelist

SecureList analyzed cyber incidents at Brazilian educational institutions from 2025 to 2026, identifying ransomware attacks and insider threats. Two major ransomware families observed were LockBit 3 and DragonForce, with attackers using leaked LockBit builders and valid credentials for initial access. In one case, LockBit was deployed via PsExec after disabling defenses using a batch script; in another, DragonForce was delivered via AnyDesk. An insider used a custom Python keylogger to capture credentials on shared machines, storing logs in hidden files later retrieved via USB.

7 IoCs 1 Actors
← Previous Next →