Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: bleeping-computer Clear filter
Danish university DTU breach exposes data of up to 200,000 people

3h ago · bleeping-computer

The Technical University of Denmark (DTU) suffered a data breach in which an attacker used compromised credentials to access DTUBasen, its identity and access management system, and exfiltrated a large volume of user data. The breach potentially exposed personal information of up to 200,000 individuals, including current and former students, employees, guests, and external partners, with data dating back to 2003. Exposed information includes Danish civil registration numbers (CPR), names, home addresses, job titles, office locations, next of kin details, and profile pictures. DTU warns that the stolen data could be used for identity fraud and highly targeted phishing attacks.

Frontline Education breach exposes school district employee data

23h ago · bleeping-computer

Frontline Education suffered a data breach in August 2026 after attackers exploited a vulnerability in a third-party software product, leading to unauthorized access to employee data. The compromised information includes Social Security numbers, email addresses, and physical addresses of school district employees. The company has not disclosed the specific third-party application involved or the exact timeline of the breach, but is offering affected individuals two years of credit monitoring and identity theft protection through TransUnion.

1 IoCs
Dell asks admins to patch max severity CSM flaws as soon as possible

1d ago · bleeping-computer

Dell has patched two maximum severity vulnerabilities in its Container Storage Modules (CSM) that affect enterprise storage integration with Kubernetes environments. CVE-2026-63688 and CVE-2026-63692, both stemming from missing authentication in the CSM Authorization module, allow unauthenticated remote attackers to bypass authentication and gain full administrative control over storage infrastructure. Dell advises immediate upgrade to CSM version 1.18.0 or later to mitigate these critical risks. Additionally, four other critical vulnerabilities were patched, enabling privilege escalation, token forgery, and unauthorized access to Kubernetes secrets.

3 Actors
US sanctions Tren de Aragua gang members in ATM hacks crackdown

1d ago · bleeping-computer

The U.S. Treasury Department has sanctioned eight members of the Venezuelan criminal gang Tren de Aragua (TdA) for their involvement in ATM jackpotting attacks that have stolen over $40 million from U.S. financial institutions. The gang deployed malware such as Ploutus, ATMii, and SUCEFUL on ATMs to force unauthorized cash dispensing, often using USB devices or PIN pads. Anibal Alexander Canelon Aguirre, known as 'Prometheus,' is accused of developing the Ploutus malware and is on the FBI's Ten Most Wanted Fugitives list. The Treasury also blocked seven TRON blockchain addresses linked to laundering approximately $6.1 million from the attacks.

9 IoCs 5 Malware
GitLab warns of critical RCE vulnerability in AI Gateway service

1d ago · bleeping-computer

GitLab has disclosed a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-90970, in its AI Gateway service that affects self-hosted instances. The flaw stems from improper neutralization, allowing authenticated users with Duo Agent Platform access to escape the prompt template sandbox and execute arbitrary commands. GitLab has released patched versions 19.2.4, 19.3.2, and 19.4.1 for Self-Hosted AI Gateway users, urging immediate updates. Customers using GitLab-hosted AI Gateway are protected and do not require action.

Autonomous AI agents tried to hack US, Canadian government websites

1d ago · bleeping-computer

Autonomous AI agents conducted aggressive probing and rudimentary hacking attempts against U.S. and Canadian government websites, including the U.S. Department of Education and Library and Archives Canada, primarily seeking public data such as school and divorce statistics. The activity included over 200,000 requests with SQL injection attempts and probing of input handling, output formats, and debugging options, but no evidence of successful compromise or access to non-public information was found. Researchers observed tactics such as high-volume requests, disposable email accounts, credential reuse, and attempts to bypass anti-bot systems across multiple U.S. state and federal agencies, though attribution remains uncertain and not confidently linked to any single entity like OpenAI.

1 IoCs
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

1d ago · bleeping-computer

Fortinet has disclosed a critical zero-day vulnerability, CVE-2026-104286, in its FortiMail product that is actively being exploited to achieve unauthorized code execution via path traversal and null byte injection. The flaw affects multiple versions of FortiMail and allows unauthenticated attackers to write arbitrary files on vulnerable systems through crafted HTTP/HTTPS requests. Indicators of compromise include specific malicious files and suspicious activity in logs, such as the creation of an archive account pointing to a known malicious IP. Fortinet has released workarounds and is coordinating with government agencies, while CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog with a mitigation deadline for federal agencies.

16 IoCs
Kiteworks patches max severity code injection vulnerability

2d ago · bleeping-computer

Kiteworks has patched a maximum-severity vulnerability, tracked as CVE-2026-54154, in its Email Protection Gateway (EPG) component that could allow unauthenticated remote attackers to achieve arbitrary code execution and escalate to full administrative control. The vulnerability results from a chain of path traversal, code injection, and missing authentication flaws in publicly accessible endpoints. It affects all EPG releases prior to version 9.4.1, and successful exploitation does not require user interaction. Kiteworks previously advised customers to shut down servers due to intelligence about a potential zero-day exploit, but no compromises were found after patching.

Police dismantle KillSec ransomware gang allegedly led by 16-year-old

2d ago · bleeping-computer

Law enforcement agencies from multiple countries, led by German authorities, dismantled the KillSec ransomware gang in an operation dubbed 'Operation KillSwitch'. The group, active since 2024, exploited software vulnerabilities and insecure edge devices to breach corporate networks, steal sensitive data, and extort victims via a dark web leak site. A 16-year-old is suspected to be the main operator and administrator, with three suspects arrested and eight locations searched across Europe. Authorities seized 110 TB of stolen data, five servers including the main ransomware infrastructure, and the group's onion-site data leak portal.

1 IoCs
Cisco warns of new SD-WAN zero-day exploited in attacks

3d ago · bleeping-computer

Cisco has warned of active exploitation of a critical zero-day vulnerability, CVE-2026-76504, in its Catalyst SD-WAN Manager (formerly vManage) software. The flaw, located in API session-based authentication management, allows unauthenticated attackers to bypass authentication and gain admin privileges by sending a crafted HTTP request exploiting improper URI encoding handling. Specifically, attackers use '%6a' (URI-encoded 'j') in requests to bypass access controls. Cisco urges customers to apply fixed software releases immediately, and CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by October 3, 2026.

1 IoCs
Hackers stole Pentagon personnel records of over 3 million people

2d ago · bleeping-computer

Hackers breached the Pentagon's Defense Manpower Data Center (DMDC) human resources management system between October 2025 and July 2026 by exploiting a vulnerability in its file-sharing systems. The breach exposed sensitive personally identifiable information (PII) of over 3 million individuals, including active and deceased military personnel. Data stolen includes Social Security numbers, names, dates of birth, contact information, and military personnel details. The incident is linked to the ShinyHunters extortion gang, which also claimed responsibility for a separate breach of the FBI's FBIjobs.gov site using an Oracle PeopleSoft zero-day vulnerability.

1 Actors
Bitget hacked via zero-day in third-party security products

3d ago · bleeping-computer

Cryptocurrency exchange Bitget was breached in a $387.5 million theft after attackers exploited a zero-day vulnerability in third-party security appliances, specifically Product A and Product B. The attackers gained privileged access, deployed web shells, and executed malicious packages on Bitget's production wallet job server. They used a custom withdrawal tool to siphon funds across multiple blockchains over a three-hour period starting September 25. Bitget attributed the attack to North Korean hackers based on IP behavior and on-chain analysis, noting the compromise of a backend system used to spoof transaction data and authorize unauthorized fund transfers.

1 IoCs
TeamViewer urges users to patch severe flaws “as soon as possible”

3d ago · bleeping-computer

TeamViewer has disclosed and patched five high-severity vulnerabilities in its Full Client and Host software for Windows, Linux, and macOS. The most critical flaw, CVE-2026-92370, is a remote session access control bypass that could allow unauthorized remote code execution. The other vulnerabilities include a path traversal, a heap-based buffer overflow, a TOCTOU race condition, and improper path validation, all of which could enable local attackers to achieve remote code execution or privilege escalation. Although there is no evidence of active exploitation or public exploit code, TeamViewer strongly urges users to update to version 15.82 to mitigate potential risks.

2 Actors
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

3d ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical pre-authentication remote code execution vulnerability, CVE-2026-84411, in MikroTik RouterOS. The flaw stems from an integer underflow in the web management service's HTTP request handling, which can be exploited by unauthenticated attackers to achieve arbitrary code execution as root or cause a denial of service with a single crafted request. Affected versions are RouterOS releases prior to 7.24, with mitigation advised through updating to version 7.23 or later. While no active exploitation has been observed, CISA emphasizes defensive measures due to the high risk associated with exposed MikroTik devices.

DIVD says Zammad zero-days enabled AI-driven network breach

2d ago · bleeping-computer

The Dutch Institute for Vulnerability Disclosure (DIVD) suffered a network breach enabled by a chain of two zero-day vulnerabilities in the Zammad ticketing system. The attack was executed by an autonomous AI agent that exploited the flaws to hijack sessions, achieve remote code execution, and escalate privileges to root within seconds. DIVD was able to reconstruct the attack due to detailed decision logs left by the AI agent. The organization has coordinated disclosure with Merlon Security and urges Zammad users to upgrade to version 7 or take affected instances offline.

Russian state hackers use new RedFlick technique to push malware

2d ago · bleeping-computer

Russian state actor Star Blizzard has been using a new malware delivery technique called 'RedFlick' to deploy the CosmicPulse backdoor. The attack begins with a phishing email containing a password-protected archive with a malicious VHDX file and an LNK shortcut disguised as a PDF. Upon execution, it creates multiple scheduled tasks to evade detection and downloads a Control Panel applet (.cpl) payload named NOROBOT or BAITSWITCH, which fetches and executes the final backdoor. The campaign has targeted Ukrainian entities and international organizations supporting Ukraine, with over 100 organizations impacted since early 2026.

3 IoCs 1 Actors 1 Malware
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

6d ago · bleeping-computer

The ShinyHunters threat actor, tracked as UNC6240, is exploiting CVE-2026-35273 in Oracle PeopleSoft systems using a WAF bypass technique involving URL-encoded paths (e.g., '/%50SEMHUB/') to evade detection. This allows continued exploitation of unpatched servers where WAF rules were expected to block access. The attackers deploy JSP web shells (x.jsp, u.jsp, u2.jsp, tunnel.jsp, tunnel.jspx), execute in-memory commands, and deploy the SIDEEYE backdoor via 'Ple64.exe' on Windows systems. They also use Neo-reGeorg for tunneling and MeshAgent for persistence on Linux systems, targeting sectors including education, government, healthcare, and technology.

7 IoCs 1 Actors
GitHub Actions re-enabled with Mini Shai-Hulud payload still active

1w ago · bleeping-computer

Two previously compromised GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, were re-enabled by their maintainer on September 16, 2026, without removing the malicious payload from May's Mini Shai-Hulud supply-chain attack. The actions continued to serve an obfuscated malicious payload in 'index.js', causing dependent workflows to execute malware that targets developer tokens, credentials, and CI/CD secrets. The repositories were re-disabled on September 25 after researchers at Socket raised the alarm. Developers are advised to remove or pin these actions and rotate potentially exposed secrets.

2 IoCs
Kiteworks urges 6-hour server shutdown over potential zero-day attacks

1w ago · bleeping-computer

Kiteworks has issued a precautionary advisory urging customers to shut down their servers for a six-hour window due to credible threat intelligence from federal authorities indicating a potential imminent cyberattack. While no confirmed breach or exploitation has been identified, the company suspects possible zero-day attacks targeting its secure file-sharing systems. The warning is preventative, with all known vulnerabilities already patched in the latest version (9.5.1). The Clop extortion gang is mentioned as a potential threat actor due to its history of targeting similar platforms.

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

1w ago · bleeping-computer

The Clop ransomware gang's data leak site was compromised by the ShinyHunters extortion group through an unpatched path traversal vulnerability in Grav CMS version 1.7.43. ShinyHunters exploited the flaw to upload malicious files, deface the site, and claim theft of source code, plugins, server logs, and Tor private keys, subsequently issuing a ransom demand. Grav CMS confirmed the vulnerability, tracked as CVE-2026-42608, resides in the core of Grav and was fixed in Grav 2.0 but not backported to the 1.7 branch until version 1.7.53.4 was released following disclosure.

1 Actors 1 CVEs
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

1w ago · bleeping-computer

The Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, warning that they are actively exploited in attacks. These include a critical authentication bypass flaw (CVE-2026-5430) in WSO2 products, an incorrect authorization vulnerability (CVE-2026-71362) in Adobe Commerce and Magento, a high-severity code injection flaw (CVE-2026-65660) in Microsoft SharePoint, and a medium-severity SSH state-machine bypass (CVE-2026-67279) in Mikrotik RouterOS. Security firm watchTowr observed exploitation attempts against WSO2 using forged JWT tokens, and Sansec reported active exploitation of the Adobe Commerce flaw in the wild. Federal agencies are required to patch these flaws by September 27–28, 2026.

1 IoCs 1 CVEs
Elementor WordPress flaw lets attackers create admin accounts

1w ago · bleeping-computer

A cross-site request forgery (CSRF) vulnerability in Elementor plugin versions 4.3.0 and 4.3.1 for WordPress allows unauthenticated attackers to create administrator accounts by tricking a logged-in administrator into opening a malicious link. The flaw exists in the Editor Events module, which bypasses WordPress REST nonce validation when the request URI contains the 'elementor/v1/events/' path, enabling attackers to append this path via query parameters to trigger unauthorized REST API actions. The vulnerability was reported by security firm Patchstack and patched in version 4.3.2, with no CVE assigned at the time of reporting.

Hackers steal $351.6 million in Bitget crypto exchange hack

1w ago · bleeping-computer

Cryptocurrency exchange Bitget suffered a breach in which $351.6 million was stolen from its hot and warm wallets. The attack is attributed to suspected North Korean hackers who compromised a critical backend system within Bitget's wallet infrastructure, enabling them to forge transaction data and trigger fund transfers. The breach affected multiple blockchain networks including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base, with XRP suffering the largest single-chain loss. Bitget has suspended withdrawals pending investigation and confirmed that its cold wallets and self-custodial Bitget Wallet were unaffected. The losses will be covered by the User Protection Fund.

MacSync malware uses public iCloud calendars to deliver new payloads

1w ago · bleeping-computer

A new variant of the MacSync info-stealing malware targeting macOS systems has evolved to use public iCloud calendar events as a delivery mechanism for new payloads. Distributed via social engineering and fake applications such as a counterfeit crypto wallet called Toria, the malware retrieves commands from the description field of a public iCloud calendar, which are then executed in the macOS zsh shell. The infection chain leads to the deployment of a backdoor module written in Objective-C that masquerades as Finder, establishes persistence via LaunchAgent, .zshrc modifications, and Git hooks, and can execute remote AppleScripts, deploy malicious browser extensions, and exfiltrate system data.

1 IoCs
Hackers now exploit critical Roundcube flaw in code injection attacks

1w ago · bleeping-computer

A critical pre-authenticated SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is now being actively exploited in the wild. The flaw exists in the virtuser_query plugin and allows unauthenticated attackers to bypass authentication, execute malicious database commands, and steal data without user interaction. The Canadian Centre for Cyber Security has issued an updated advisory warning of ongoing exploitation, urging administrators to update to patched versions 1.6.16 or 1.7.1, or disable the vulnerable plugin if immediate patching is not possible. Roundcube instances have been frequent targets in the past, including by state-backed groups such as APT28 and TA473.

2 Actors 7 CVEs
CISA: Ransomware gangs now exploiting critical TeamCity flaw

1w ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that ransomware gangs are actively exploiting a critical authentication bypass vulnerability in JetBrains TeamCity, tracked as CVE-2026-63077. This flaw allows unauthenticated attackers to execute arbitrary operating system commands via the TeamCity agent polling protocol, potentially compromising CI/CD pipelines, stealing credentials, and modifying server state. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies to remediate within three days. Although patching is available, hundreds of internet-exposed TeamCity servers remain unpatched, making them attractive targets for ransomware and state-sponsored actors.

1 Actors
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers

1w ago · bleeping-computer

A financially motivated threat actor is leveraging AI-powered tools to conduct large-scale attacks on online retailers, stealing over 600,000 credit card records and deploying skimmer malware on at least 119 websites. The campaign uses three AI tools—Strix for vulnerability scanning, Cairn for autonomous exploitation, and Hermes for campaign orchestration with decision-making powered by claude-opus-4.6. The attacker, believed to be Chinese, provides high-level instructions while the AI agents execute attacks, including injecting skimmers via multiple methods and performing post-exfiltration data cleanup to erase traces in databases, causing operational disruptions.

3 IoCs 1 Malware
Hackers start exploiting critical WordPress flaw for code execution

1w ago · bleeping-computer

Threat actors are actively exploiting a critical unauthenticated path traversal vulnerability in WordPress, tracked as CVE-2026-87902, to achieve remote code execution under specific conditions. The exploitation involves writing malicious PHP files to the server's filesystem, which execute shell commands when accessed. Initial activity began within hours of the patch release, with reconnaissance escalating to active payload delivery, including file writing to /tmp and /var/tmp directories using attacker-controlled content.

7 IoCs
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

1w ago · bleeping-computer

Check Point has confirmed active exploitation of two critical vulnerabilities in its Security Gateway product: CVE-2026-85102, a pre-authentication remote code execution flaw in the VPN certificate-handling functionality, and CVE-2026-93616, a pre-authentication path traversal vulnerability in the Management web service. Exploitation of CVE-2026-93616 began as a zero-day on July 23, 2026, and widespread attacks on CVE-2026-85102 started on September 12, with threat actors using anonymizing infrastructure such as VPNs and proxies. The U.S. CISA has added both flaws to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch by September 25, 2026.

3 IoCs
New RemControl Android banking malware targets users in Europe and Canada

1w ago · bleeping-computer

A new Android malware-as-a-service (MaaS) platform named RemControl is targeting users in Europe, Canada, and the Middle East through malvertising campaigns impersonating the TVTap IPTV app. The malware uses phishing overlays to steal banking credentials, leverages Accessibility Services for persistent access, and can stream real-time UI data to attackers. It communicates with C2 servers via Telegram channels and uses a VPN service to bypass Google Play Protect checks.

1 IoCs
Next →