Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: bleeping-computer Clear filter
Spain arrests suspected member of pro-Russian hacktivist groups

1mo ago · bleeping-computer

Spanish authorities have arrested a man suspected of being an active member of the pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest. He allegedly provided logistical and operational support to a Ukrainian hacker within CARR and facilitated escape routes to Russia. The groups have been linked to attacks on critical infrastructure in the U.S. and Europe, including SCADA systems, and are loosely associated with the Russian state-backed APT44 (Sandworm). The suspect also participated in operations attributed to the hacktivist group NoName057(16), which promotes pro-Russian and anti-Western narratives.

3 Actors
New Januscape Linux flaw allows VM escape on Intel, AMD devices

1mo ago · bleeping-computer

A critical 16-year-old Linux kernel vulnerability named Januscape (CVE-2026-53359) enables guest-to-host virtual machine escape on both Intel and AMD architectures, posing significant risks to multi-tenant cloud environments. The flaw resides in KVM/x86's shadow MMU emulation and can be exploited by attackers with root access inside a guest VM to execute arbitrary code on the host or cause a denial-of-service by crashing the host kernel. It was used as a zero-day in Google's kvmCTF program, and when combined with the Dirty Frag privilege escalation, even unprivileged attackers could achieve full compromise. Administrators are urged to apply patch commit 81ccda30b4e8 to mitigate exposure.

1 IoCs
Webinar tomorrow: Why modern email attacks require a new approach to defense

1mo ago · bleeping-computer

Modern email attacks increasingly exploit trusted identities, legitimate services, and normal communication patterns to bypass traditional security controls. Techniques such as Device Code phishing, business email compromise (BEC), and account takeovers (ATO) are commonly used, allowing attackers to evade detection by avoiding malware and suspicious attachments. These attacks result in alert fatigue and manual investigation overhead for security teams. The article highlights the need for behavioral AI to automate detection and response in the evolving email threat landscape.

Microsoft testing new Cloud Rebuild Windows 11 recovery feature

1mo ago · bleeping-computer

Microsoft is testing a new Cloud Rebuild feature for Windows 11, designed to remotely reinstall the operating system on devices that are non-bootable or experiencing critical issues. This feature, part of the Windows Resiliency Initiative, allows for a full OS recovery without the need for physical media or a functioning OS. It is being rolled out to Windows Insider Experimental channel users as part of ongoing efforts to improve system recovery and resilience.

BeyondTrust warns of critical flaws in remote access software

1mo ago · bleeping-computer

BeyondTrust has disclosed two critical vulnerabilities, CVE-2026-40138 and CVE-2026-40139, in its Remote Support (RS) and Privileged Remote Access (PRA) software that allow unauthenticated attackers to bypass authentication and gain unauthorized access to affected systems. Exploitation requires specific configurations, though details were not disclosed. The vendor has patched cloud instances and urges self-hosted customers to update to version 25.3.3 or later. Previous vulnerabilities in the same software have been actively exploited in the wild by threat actors, including the Chinese state-backed group Silk Typhoon.

1 Actors
Microsoft to enable Windows settings backup by default for orgs

1mo ago · bleeping-computer

Microsoft is enabling the Windows settings backup and restore tool by default for enterprise devices joining or hybrid-joining Microsoft Entra, starting with Windows 11 version 26H2. This feature, previously opt-in, aims to streamline user settings backup during device resets, replacements, or upgrades. The default enablement applies only to eligible non-EU DMA-regulated devices where administrators have not explicitly configured backup policies. IT admins retain control via MDM solutions like Microsoft Intune or Group Policy to override defaults.

Vietnam arrests suspects behind HiAnime anime piracy service

1mo ago · bleeping-computer

Vietnamese authorities have arrested seven suspects linked to the operation of HiAnime, a major anime piracy service that attracted hundreds of millions of visitors monthly. The group allegedly created over 100 websites to distribute more than 26,000 pirated anime titles, generating $12.85 million in illicit advertising revenue between 2020 and April 2026. The service was previously rebranded from Zoro.to to Aniwatch.to and later to HiAnime.to, appearing on both the European Commission's and USTR's notorious markets lists. The Alliance for Creativity and Entertainment (ACE) commended the takedown, which resulted from a multi-year investigation supported by U.S. law enforcement.

3 IoCs
Fake IT support calls on Microsoft Teams push EtherRAT malware

1mo ago · bleeping-computer

Threat actors are conducting fake IT support calls via Microsoft Teams to trick employees into installing the EtherRAT malware. The attack begins with a phishing email containing a malicious PDF, followed by a voice call from an external Teams account impersonating system administrators. Attackers use legitimate remote access tools like HopToDesk and AnyDesk, then deploy EtherRAT via a malicious MSI installer, enabling full system control and data theft. EtherRAT uses Ethereum smart contracts for C2 resilience, and the campaign is actively evolving with multiple malware versions observed.

4 IoCs 1 Malware
Phishing poses as big-brand job interview to steal Google accounts

1mo ago · bleeping-computer

A phishing campaign impersonates over 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, to target marketing professionals with fake job interviews. The attackers abuse legitimate platforms like PeopleForce and Salesforce Marketing Cloud to increase credibility, using nested redirects to deliver a malicious landing page. Victims are prompted to sign into their Google accounts via a fake 'Continue with Google' page that uses browser-in-the-browser (BitB) technique to mimic legitimate authentication, enabling credential theft.

3 IoCs
Max severity Adobe ColdFusion flaw now exploited in attacks

1mo ago · bleeping-computer

Threat actors are actively exploiting a maximum-severity vulnerability in Adobe ColdFusion, tracked as CVE-2026-48282, to achieve remote code execution on unpatched systems. The flaw affects ColdFusion versions 2025.9, 2023.20, and earlier. Exploitation began within two hours of public disclosure, prompting urgent warnings from KEVIntel and the Canadian Center for Cyber Security. Adobe urges administrators to apply patches immediately to mitigate risk.

Software Is Now Written at the Speed of Thought. Security Isn't.

1mo ago · bleeping-computer

The article discusses the evolution of software development from Waterfall to Agile, DevOps, and now 'Vibe Coding,' where generative AI enables rapid application creation through natural language prompts. This acceleration introduces significant security risks, as AI-generated code may contain vulnerabilities, architectural flaws, or compliance issues despite appearing functional. Traditional secure development practices like threat modeling, code review, and least privilege remain critical to mitigate these risks. The article warns that without proper governance, Vibe Coding could become a modern form of shadow IT—innovative but potentially dangerous.

JadePuffer ransomware used AI agent to automate entire attack

2mo ago · bleeping-computer

JadePuffer ransomware represents the first documented case of a ransomware operation fully automated by a large language model (LLM) agent. The AI-driven attack exploited CVE-2025-3248 in Langflow to gain initial access, then performed reconnaissance, credential theft, lateral movement, and encryption autonomously. The agent adapted to failures in real time, demonstrating human-like operational resilience and rapid iteration. It encrypted 1,342 Nacos configuration items and left a ransom note with a Proton Mail contact and a Bitcoin address, though the encryption likely used AES-128-ECB rather than AES-256 as claimed.

1 IoCs 2 CVEs
Flipper Zero firmware development continues with community help

1mo ago · bleeping-computer

Flipper Devices has announced a shift in its firmware development strategy for the Flipper Zero, transitioning to a community-driven model with a reduced internal team. While official firmware maintenance will continue, full-time feature development has ended, and future updates will depend on community contributions reviewed by the core team. The company aims to focus on new hardware like the Flipper One and Busy Bar, while leveraging community input to sustain the Flipper Zero platform. This change follows user backlash over perceived abandonment of firmware development.

CISA: Microsoft SharePoint RCE flaw now actively exploited

2mo ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that a high-severity remote code execution vulnerability in Microsoft SharePoint, tracked as CVE-2026-45659, is now under active exploitation. The flaw allows authenticated attackers with low privileges to execute arbitrary code remotely on unpatched SharePoint servers without user interaction. Microsoft addressed the vulnerability in May 2026 updates, but over 10,000 exposed servers remain at risk. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by a strict deadline.

Cisco finally confirms attackers exploiting Unified CM flaw

2mo ago · bleeping-computer

Cisco has confirmed active exploitation of a critical vulnerability (CVE-2026-20230) in its Unified Communications Manager (Unified CM) software. The flaw allows unauthenticated attackers to perform server-side request forgery (SSRF) attacks via crafted HTTP requests. Cisco urges customers to apply patches immediately or disable the vulnerable WebDialer service as a mitigation. The vulnerability follows a trend of repeated security issues in Cisco Unified CM devices.

Microsoft fixes bug that removed Copilot buttons in Outlook

2mo ago · bleeping-computer

Microsoft resolved a bug that caused Copilot buttons to disappear in Classic Outlook for Windows users with the Copilot Chat (Basic) license. The issue was fixed via a service update on June 29, 2026, and users are advised to restart Outlook or update to the latest build. Microsoft is also investigating Outlook crashes linked to Kaspersky Antivirus's Kaspersky Mail Checker (mcou.dll).

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

2mo ago · bleeping-computer

ConsentFix and ClickFix are social engineering attacks that hijack Microsoft 365 accounts by exploiting user trust in routine workflows. ClickFix tricks users into executing malicious commands via fake verification prompts, while ConsentFix abuses OAuth consent flows by luring victims into dragging a localhost callback link, surrendering OAuth tokens. These attacks bypass traditional security measures by mimicking legitimate processes, requiring no malware or credential theft. Attackers leverage publicly shared blueprints and common platforms like Dropbox to distribute lures.

Google loses final appeal to overturn €4.1 billion EU fine

2mo ago · bleeping-computer

The article discusses the European Union's antitrust case against Google, culminating in a final ruling by the Court of Justice of the European Union (CJEU) dismissing Google's appeal against a €4.1 billion fine. The case centers on Google's historical use of Android licensing agreements to promote its Chrome browser and search services, which was deemed anti-competitive. There is no mention of cyber threat activity, malware, or malicious infrastructure in the article.

Claude Fable relaunch disappoints users with nerfed performance

2mo ago · bleeping-computer

The relaunch of Claude Fable, Anthropic's powerful AI model, has disappointed users due to degraded performance and increased restrictions. Despite being available to all users, the model is heavily capped and frequently falls back to the less capable Opus 4.8 due to strict safety guardrails. Users report that prompts involving security-related terms or systems programming trigger fallbacks, impacting usability. Anthropic attributes this behavior to an expanded safety margin rather than intentional model degradation.

Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says

2mo ago · bleeping-computer

Anthropic has temporarily removed access to its powerful Claude Fable 5 model from subscription plans after July 7, shifting usage to a credit-based system due to unexpectedly high demand and capacity constraints. The company clarifies this is not a permanent change and intends to reintegrate Fable 5 into subscription plans once sufficient infrastructure capacity is available. Fable 5 remains fully accessible via the Claude API and consumption-based Enterprise plans. Users are advised that the model may return to subscriptions in the future as capacity allows.

ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit

2mo ago · bleeping-computer

ARToken, a phishing-as-a-service (PhaaS) platform, is linked to the EvilTokens Microsoft 365 phishing toolkit, enabling attackers to steal authentication tokens and bypass multi-factor authentication via device code phishing. The platform provides affiliates with persistent access through Primary Refresh Tokens (PRTs) and supports automated business email compromise (BEC) operations using AI. It allows for mailbox monitoring, file exfiltration from SharePoint and OneDrive, and deployment via Cloudflare Workers, indicating a sophisticated, multi-tenant attack infrastructure.

2 IoCs
NetNut proxy network disrupted, 2 million infected devices cut off

2mo ago · bleeping-computer

A joint operation led by Google and the FBI disrupted the NetNut residential proxy network, which leveraged at least 2 million compromised Android devices, including smart TVs and streaming boxes, to provide anonymized internet access for cybercriminals and espionage groups. The botnet, powered by trojanized applications like Badbox 2.0, enabled malicious actors to conceal their traffic using victims' residential IP addresses. The disruption involved seizing infrastructure, disabling C2 accounts on Google's platforms, and warning users via Play Protect, significantly impacting the broader proxy services ecosystem.

1 IoCs
← Previous