Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: bleeping-computer Clear filter
SonicWall warns of actively exploited SMA1000 zero-day flaws

13h ago · bleeping-computer

SonicWall has warned of an actively exploited zero-day vulnerability chain affecting its SMA1000 appliances, involving two critical command injection flaws. The first vulnerability (CVE-2026-83548) is a server-side request forgery (SSRF) in the WorkPlace interface, while the second (CVE-2026-83549) allows command injection in the Management Console by authenticated administrators. These vulnerabilities enable remote code execution, and attackers are actively exploiting them in the wild. Customers are urged to apply hotfixes immediately, though specific IOCs have not been released by SonicWall.

Sality botnet infrastructure dismantled in joint global takedown

11h ago · bleeping-computer

The Sality botnet, active for over two decades and responsible for infecting more than 15,000 devices, has been disrupted in a joint global takedown operation led by international law enforcement and private sector partners including Europol, FBI, and CrowdStrike. The botnet, attributed to the threat actor group SALTY SPIDER believed to be operating from Russia's Republic of Bashkortostan, used a peer-to-peer (P2P) architecture to distribute malware payloads, primarily EggJagger in recent years. EggJagger is a clipjacking tool that monitors and replaces cryptocurrency wallet addresses in the clipboard with attacker-controlled ones. The disruption was achieved by sinkholing the botnet’s super peer infrastructure, effectively severing communication between infected machines and preventing further propagation of malicious payloads.

1 Actors 1 Malware
US charges Russian for infecting 80,000 freelancers with malware

10h ago · bleeping-computer

A Russian national, Searzhudin Tamirlanovich Aktulaev, has been indicted for conducting a phishing campaign between June 2016 and November 2017 that infected approximately 80,000 freelancers with TVRAT and DarkVNC malware. The attacker used 255 fake accounts on a freelance platform to send malicious Excel attachments containing macros, which downloaded malware enabling remote access via TeamViewer and VNC Viewer. The malware exfiltrated stolen data, including e-commerce credentials and personally identifiable information, to command-and-control servers paid for with virtual currency, with thousands of infected systems in the U.S., particularly in the Northern District of California.

2 Malware
Hackers abuse Faronics Deploy admin tool to install ScreenConnect

22h ago · bleeping-computer

Hackers are exploiting the legitimate Faronics Deploy endpoint management tool to gain remote administrative access to victim systems by tricking users into installing a maliciously repurposed, signed installer disguised as an Adobe-related executable. The installer enrolls the victim's machine into an attacker-controlled Faronics deployment, enabling the execution of PowerShell scripts that deploy additional payloads, including ConnectWise ScreenConnect, a remote access tool used for persistent and interactive control. The attack uses phishing emails with business-themed lures, such as fake invoices, and includes anti-analysis techniques to evade detection in sandboxed environments. Activity declined after Faronics implemented anti-abuse measures in response to disclosure by Huntress.

1 IoCs
Critical Langflow flaw exploited to steal OpenAI and AWS keys

1d ago · bleeping-computer

Threat actors are actively exploiting a critical unauthenticated remote code execution vulnerability, CVE-2026-0768, in Langflow, an open-source AI application framework, to steal sensitive credentials including OpenAI and AWS API keys. The flaw exists in the code validator of Langflow's custom component editor, allowing arbitrary Python code execution with root privileges. Attack activity has been observed on honeypots, primarily originating from Russia, with over 360 exploitation attempts detected. Attackers query environment variables and sensitive files to harvest credentials and maintain persistence.

6 CVEs
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

1d ago · bleeping-computer

A high-severity authentication bypass vulnerability, CVE-2026-62911, affects unpatched Microsoft Exchange Server 2016, 2019, and Subscription Edition systems, allowing attackers with basic privileges to hijack all user mailboxes. Exploit code for this flaw is now publicly available, according to the Netherlands NCSC-NL. Despite Microsoft's patch release in August 2026, nearly 22,000 Exchange servers remain exposed online and unpatched, with the majority located in the United States and Germany. German authorities report approximately 85% of on-premises Exchange servers in Germany are still vulnerable.

Novocure data breach affects more than 1,400 cancer patients

1d ago · bleeping-computer

Novocure, a healthtech company specializing in cancer treatment, suffered a cyberattack in mid-August that led to unauthorized access to its information systems. The breach exposed data of over 1,400 U.S. cancer patients, including patient ID numbers, and for fewer than 50 patients, identifying and healthcare provider contact information. Employee contact details and job titles were also accessed, though no medical devices were compromised and systems remain operational. The company is assessing regulatory obligations and has not disclosed the breach vector or whether ransom demands were made.

Hackers push malicious Virtualizor update in BGP hijacking attack

1d ago · bleeping-computer

Hackers conducted a BGP hijacking attack against Hetzner-hosted IP addresses used by Softaculous to redirect traffic from its software update systems and client portal. During the incident window from August 28 to August 30, 2026, a malicious Virtualizor update was delivered to a small number of installations. The attack allowed threat actors to intercept update requests and potentially compromise affected servers. Softaculous has since restored routing, revoked the fraudulent certificate, and released a new secure version of Virtualizor with improved security tooling.

1 IoCs
Recently patched PaperCut zero-days used in data theft attacks

1d ago · bleeping-computer

Two recently patched zero-day vulnerabilities in PaperCut NG and MF print management software, tracked as CVE-2026-81578 and CVE-2026-82078, are being actively exploited in data theft attacks. Attackers are chaining the flaws to bypass authentication and access backend databases via PaperCut's external user-lookup functionality, using the vulnerabilities to dump database tables through Derby without executing remote code. Threat intelligence firm Defused observed the exploit activity in honeypots starting August 29, 2026, indicating ongoing abuse by unidentified actors.

Five Venezuelans plead guilty to ATM jackpotting attacks in US

1d ago · bleeping-computer

Five Venezuelan nationals have pleaded guilty to conducting ATM jackpotting attacks in the United States, attempting to install malware on ATMs to force them to dispense cash. The attacks occurred in Wamego and Manhattan, Kansas, but were unsuccessful due to alarm triggers and surveillance detection. The individuals were part of a larger wave of ATM jackpotting incidents linked to the Tren de Aragua criminal organization, which has been associated with the use of Ploutus malware in a broader campaign targeting financial institutions across the U.S.

Berlin confirms data theft after Rhysida ransomware attack claims

2d ago · bleeping-computer

The city administration of Berlin has confirmed a ransomware attack by the Rhysida group, which claims to have exfiltrated 5.79 TB of data from its administrative network. The stolen data includes sensitive government records, personal information, credentials, and critical infrastructure assessments, with attackers threatening to publish the data unless a ransom is paid. The incident was discovered in mid-August 2026, and investigations are ongoing, involving the State Criminal Police Office, public prosecutor, and federal security agencies. No evidence was found that election data was compromised, and the affected departments were disconnected from the state network on August 14.

Chinese Fire Ant hackers turn Cisco routers into spying platforms

2d ago · bleeping-computer

The Chinese state-sponsored threat actor Fire Ant has shifted tactics to compromise Cisco IOS XR routers, TACACS servers, and Linux management systems, turning routers into surveillance platforms via concealed GRE tunnels. The group deployed a custom backdoor named 'BridgeAgent', disguised as a Zabbix agent, enabling reverse shells and execution of additional payloads. Fire Ant uses stealthy persistence mechanisms, suppresses syslog messages, and exfiltrates network traffic PCAPs to FTP servers, aiming to map and access high-value networks through a 'target behind the target' strategy. The group's activity overlaps with UNC3886 but shows distinct implementation differences.

1 IoCs 1 Actors
Microsoft warns of TerminalFix attacks deploying reverse tunnels

2d ago · bleeping-computer

Microsoft has identified a new variant of ClickFix attacks dubbed TerminalFix, which uses fake Cloudflare CAPTCHA prompts on compromised websites to trick users into executing malicious PowerShell commands in Windows Terminal. The attack chain involves downloading a ZIP containing a signed executable and a malicious DLL, followed by steganographic retrieval of additional payloads from PNG images. A custom Python-based reverse-tunnel module establishes an encrypted WebSocket connection to gitnow[.]dev:443, enabling attackers to pivot into internal networks via SOCKS5-style proxying and perform reconnaissance on domain controllers, databases, and other critical systems.

2 IoCs
Cronos blockchain restarts after $74 million Tectonic exploit

1d ago · bleeping-computer

The Cronos blockchain was exploited via a price-manipulation attack on the Tectonic DeFi lending platform, resulting in the attacker borrowing $74 million worth of assets by artificially inflating the value of the TONIC token by 100x within 20 minutes. The attacker successfully withdrew approximately $6 million in Ethereum, while the remainder of the funds were frozen due to the blockchain's emergency response. Cronos halted operations, rolled back the chain state to before the exploit occurred, and has since resumed normal operations. A post-mortem analysis is expected to follow.

Pokémon Center data breach exposes customer info, cancels some orders

2w ago · bleeping-computer

Pokémon Center disclosed a data breach affecting customers in the United Kingdom and Germany due to a cyberattack on its third-party logistics provider, CEVA Logistics, which was compromised between July 29 and August 1, 2026. The breach exposed customer personal information including full names, mailing addresses, phone numbers, email addresses, and order details. Although payment card data was not accessed, the incident led to order cancellations and shipping delays. CEVA Logistics, a subsidiary of CMA CGM Group, confirmed the breach impacted multiple European retailers, including Valve, which also reported stolen customer data.

Hacker claims 3.6 million Azure account records stolen from major companies

2w ago · bleeping-computer

A threat actor using the alias 'TheHatman' is selling alleged employee databases stolen from the Microsoft Azure environments of multiple Fortune 500 companies, including McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels, Wyndham Hotels, Hexaware, and Kyndryl. The actor claims to have obtained the data using compromised credentials, potentially via password spray and MFA fatigue attacks. The datasets reportedly include employee names, email addresses, job titles, phone numbers, addresses, service accounts, and tenant-specific Azure structures. While some companies like Tata and Gap have stated there is no evidence of a breach and that the data may be outdated, cybersecurity firm Hudson Rock has analyzed samples and confirmed the data contains authentic corporate directory attributes and could be used for social engineering or spearphishing.

Certighost and the Privilege Hiding in Your Certificate Authority

2w ago · bleeping-computer

Certighost, tracked as CVE-2026-54121, is a critical vulnerability in Active Directory Certificate Services (AD CS) that allows a low-privileged domain user to coerce an Enterprise Certification Authority (CA) into issuing a valid authentication certificate for a Domain Controller. This is achieved by exploiting a 'chase' functionality flaw where the CA follows attacker-supplied routing information without validating the target endpoint, enabling the attacker to forge identity data and obtain a certificate impersonating a Domain Controller. The attacker can then use PKINIT to obtain a Ticket Granting Ticket, perform DCSync to extract credentials including the krbtgt hash, and achieve full domain compromise. The vulnerability was patched by Microsoft on July 14, 2026, but the underlying risk stems from standing privileges like default MachineAccountQuota settings that allow unprivileged users to create machine accounts.

Philips and GE investigating Clop ransomware data theft claims

2w ago · bleeping-computer

The Clop ransomware gang is conducting data theft attacks against organizations using PTC Windchill and PTC FlexPLM platforms, exploiting a critical vulnerability, CVE-2026-12569, that allows improper input validation. Companies including Philips, General Electric (GE), and Shell have confirmed they are investigating or have confirmed breaches. The attackers deploy JSP webshells to exfiltrate sensitive data such as project plans, blueprints, and internal backups. The U.S. CISA and Germany's BSI have issued urgent warnings, mandating immediate patching due to active exploitation in the wild.

Microsoft working on Defender patch for ShieldBreak zero-day

2w ago · bleeping-computer

Microsoft is actively working on a security patch for a newly disclosed zero-day vulnerability in Microsoft Defender named 'ShieldBreak', tracked as CVE-2026-69414. The vulnerability, disclosed by security researcher Nightmare Eclipse, allows local attackers with limited privileges to escalate to SYSTEM-level access on fully patched Windows 10, Windows 11, and Windows Server systems. The exploit acts as a bypass for the previously patched RoguePlanet vulnerability (CVE-2026-50656), indicating an incomplete fix. Microsoft has acknowledged the issue but has not yet released a patch, while the researcher has publicly released a proof-of-concept exploit due to an ongoing dispute over disclosure practices.

French tax authority data breach affects 678,000 individuals

2w ago · bleeping-computer

The French Ministry of the Economy and Finance disclosed a data breach affecting 678,000 individuals after a threat actor using the handle 'ZeroBytes' claimed responsibility and listed a stolen database for sale on the PwnForums hacking forum on August 12, 2026. The attacker accessed the General Directorate of Public Finances (DGFiP) systems, extracting sensitive tax and cadastral data, including reference tax income, family quotient, withholding tax rate, company names, SIREN numbers, and property records. Access to sensitive systems was shut down, and the incident is under investigation with support from ANSSI, though user credentials were not compromised.

1 IoCs
SafePal data breach impacts 39,798 customers, stolen info for sale

2w ago · bleeping-computer

Cryptocurrency hardware wallet provider SafePal suffered a data breach affecting approximately 39,798 customers due to an authorization flaw in an order-tracking plugin, which allowed unauthorized access to customer order information. The exposed data includes names, email addresses, shipping addresses, phone numbers, and purchase details, but not wallet seed phrases, private keys, or payment information. A threat actor is now claiming to sell the stolen data on a cybercrime forum, and customers have reported receiving phishing emails and phone calls impersonating SafePal, warning of a firmware vulnerability in the X1 device to trick users into compromising their wallets.

1 IoCs
Large-scale DDoS attacks disrupted Threema secure messaging service

2w ago · bleeping-computer

Threema, a secure messaging service, was disrupted by large-scale distributed denial-of-service (DDoS) attacks that targeted both its infrastructure and its colocation partner, Nine. The attacks caused intermittent outages and service degradation for users in Switzerland, India, and China, despite internal status pages showing normal operations. The threat actor continuously changed attack patterns, making mitigation difficult, and an unrelated technical issue prevented timely status updates. Threema has since implemented specialized upstream DDoS protection to reduce future impact.

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

2w ago · bleeping-computer

AmnesiaStealer is a macOS-targeting information-stealing malware distributed via ClickFix campaigns using fake GitHub download pages. It steals browser profiles, passwords, cryptocurrency wallets, Apple Notes, keychain data, and documents. A key capability is its 'stream_module' component, which enables remote operators to control a headless browser instance loaded with the victim's cloned Chromium profile, allowing interactive access to authenticated web sessions via WebSocket-based remote control. This provides attackers with live screencast access and full input control (keyboard, mouse) over the victim's active sessions.

New Evooo1Bot Linux botnet turns routers into traffic relay nodes

2w ago · bleeping-computer

Evooo1Bot is a new Mirai-based modular Linux botnet targeting internet-facing routers and gateway devices to turn them into SOCKS5 traffic relay nodes. It exploits known vulnerabilities in devices from vendors including Alcatel, NETGEAR, Tenda, and D-Link, and includes capabilities such as SSH brute-forcing, credential sniffing, DDoS attacks, and encrypted C2 communications over port 443. The malware performs anti-analysis checks, establishes persistence via multiple methods, and supports file transfer and interactive shell access for remote control by attackers.

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

2w ago · bleeping-computer

The Netherlands' National Cyber Security Centre (NCSC) has issued a warning that attackers are actively exploiting a macOS Screen Sharing vulnerability, CVE-2026-65400, to gain unauthorized access to systems with exposed port 5900. The flaw allows network-based attackers to bypass authentication and obtain root access without valid credentials. In confirmed attacks, the threat actors have deployed Monero cryptocurrency miners on compromised systems. Apple has patched the vulnerability in recent macOS updates, including Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.

1 Malware
Max severity SAP Commerce Cloud flaw now targeted in attacks

2w ago · bleeping-computer

A critical remote code execution vulnerability, CVE-2026-58231, in SAP Commerce Cloud is being actively exploited in the wild just three days after the patch was released. The flaw, which has a CVSS score of 10.0, stems from improper authorization in the Data Hub Adapter extension, allowing unauthenticated attackers to execute arbitrary code by exploiting a default authentication client. Threat intelligence firm Defused confirmed exploitation attempts are already occurring, as observed through honeypot traffic, despite the absence of a public proof-of-concept. The vulnerability affects internet-exposed SAP Commerce Cloud instances, with over 4,200 such systems identified globally, primarily in Europe and North America.

1 CVEs
Shell investigates 'potential incident' after Clop data theft claims

2w ago · bleeping-computer

The Clop ransomware gang claimed responsibility for stealing 89GB of data from energy giant Shell, allegedly exploiting a critical vulnerability, CVE-2026-12569, in Internet-exposed PTC Windchill and FlexPLM instances. The same vulnerability was actively exploited to target other major companies, including General Electric and Philips, with attackers deploying JSP webshells to exfiltrate sensitive data such as engineering drawings, project plans, and facility reports. U.S. CISA and German BSI issued urgent advisories urging immediate patching, and the flaw has been added to CISA's Known Exploited Vulnerabilities catalog.

RingCentral data breach exposed info of 1.6 million accounts

2w ago · bleeping-computer

In July 2026, the ShinyHunters extortion group breached RingCentral through a sophisticated social engineering campaign, exfiltrating personal information from 1.6 million customer accounts. The stolen data included names, email addresses, phone numbers, and physical addresses. After RingCentral refused to pay a ransom, ShinyHunters leaked a 280GB compressed archive of the stolen data on their dark web leak site. The breach did not impact RingCentral's core platform, and no further unauthorized activity has been observed since remediation efforts were implemented.

1 Actors
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

2w ago · bleeping-computer

An Akira ransomware affiliate gained initial access via an exposed SonicWall VPN without MFA, then used RDP to move laterally and exfiltrate data. The attacker rebooted the compromised host into Safe Mode with Networking to disable EDR and AV solutions, including the Huntress agent and Microsoft Defender. Data was stolen using s5cmd and uploaded to an attacker-controlled S3 bucket, while AnyDesk was installed and configured to persist in Safe Mode. The ransomware payload (akira.exe) failed to execute due to low virtual memory, preventing encryption. Despite the failure, the actor exfiltrated sensitive data within five hours.

1 IoCs 1 Actors
Microsoft patches LegacyHive Windows zero-day vulnerability

2w ago · bleeping-computer

Microsoft has patched a Windows zero-day vulnerability known as 'LegacyHive' (CVE-2026-62832), which affects the Windows User Profile Service and allows authenticated local attackers to gain administrator privileges by exploiting improper link resolution during registry hive loading. The vulnerability was publicly disclosed and demonstrated by security researcher Nightmare Eclipse, who criticized Microsoft's disclosure practices. Exploitation does not require user interaction and enables privilege escalation by modifying another user's registry hive when they log in.

Next →