Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

1d ago · bleeping-computer

A high-severity authentication bypass vulnerability, CVE-2026-62911, affects unpatched Microsoft Exchange Server 2016, 2019, and Subscription Edition systems, allowing attackers with basic privileges to hijack all user mailboxes. Exploit code for this flaw is now publicly available, according to the Netherlands NCSC-NL. Despite Microsoft's patch release in August 2026, nearly 22,000 Exchange servers remain exposed online and unpatched, with the majority located in the United States and Germany. German authorities report approximately 85% of on-premises Exchange servers in Germany are still vulnerable.

Novocure data breach affects more than 1,400 cancer patients

1d ago · bleeping-computer

Novocure, a healthtech company specializing in cancer treatment, suffered a cyberattack in mid-August that led to unauthorized access to its information systems. The breach exposed data of over 1,400 U.S. cancer patients, including patient ID numbers, and for fewer than 50 patients, identifying and healthcare provider contact information. Employee contact details and job titles were also accessed, though no medical devices were compromised and systems remain operational. The company is assessing regulatory obligations and has not disclosed the breach vector or whether ransom demands were made.

Hackers push malicious Virtualizor update in BGP hijacking attack

1d ago · bleeping-computer

Hackers conducted a BGP hijacking attack against Hetzner-hosted IP addresses used by Softaculous to redirect traffic from its software update systems and client portal. During the incident window from August 28 to August 30, 2026, a malicious Virtualizor update was delivered to a small number of installations. The attack allowed threat actors to intercept update requests and potentially compromise affected servers. Softaculous has since restored routing, revoked the fraudulent certificate, and released a new secure version of Virtualizor with improved security tooling.

1 IoCs
Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns

1d ago · wiz

A supply chain attack was conducted against the Rust ecosystem by compromising the maintainer account of widely used crates, including arrayref, internment, and append-only-vec. Malicious versions were published with a typosquatted dependency, proc-macro1, which executes a build script to download and run a second-stage payload. The payload acts as a backdoor, exfiltrating system information, enumerating browser login data, and enabling remote command execution, with infrastructure and TTPs showing significant overlap with DPRK-linked campaigns such as Mastra and UNC1069.

29 IoCs 1 Actors
Identity Abuse Through Trusted Communication Channels

1w ago · unit42

Threat actors are increasingly exploiting trusted enterprise collaboration platforms such as Microsoft Teams and Slack to conduct identity phishing, impersonation, credential theft, and malware delivery. These attacks leverage the inherent trust in authenticated communication channels to bypass traditional security controls, using techniques like external federation abuse, social engineering, and malicious third-party integrations. Real-world incidents include APT29 using compromised Teams accounts to distribute credential-harvesting links, a North Korea-linked campaign impersonating Fireblocks during fake job interviews to deliver malware via npm install, and attackers poisoning the Axios npm package by compromising a maintainer through a spoofed Slack environment. Additionally, attackers have used legitimate Slack webhook integrations on compromised appliances to exfiltrate credentials, demonstrating post-compromise persistence through trusted SaaS channels.

4 IoCs 1 Actors
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

1w ago · unit42

The article details the ChainDrop npm worm, a self-propagating supply chain attack that infected over 400 npm packages, including popular libraries like keyv and cacheable-request. It leverages malicious preinstall scripts to download an obfuscated payload, steals cloud secrets from CI/CD environments (including GitHub Actions OIDC tokens), backdoors local developer tools such as VS Code, and uses stolen tokens to automatically propagate. The malware maintains persistence through integration with developer tools and uses Ethereum blockchain for dynamic command-and-control infrastructure, highlighting the expanding threat surface in the software development lifecycle.

2 IoCs 1 CVEs
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

1w ago · unit42

Unit42 analyzed 405 AI-enabled malware samples and found that only 12 were observed in production environments, indicating that most such malware remains in proof-of-concept or testing stages. The operational threats included FunkSec ransomware, a trojanized AI application (Recipe Lister), the Oyster backdoor, Rhadamanthys stealer, and a COM hijacking DLL. These threats used techniques such as code signing abuse, DLL side-loading, and social engineering leveraging AI branding. All were detected and blocked by existing defenses including sandboxing, behavioral analytics, and cloud-based verdicts, with no novel detection methods required.

12 IoCs 1 Actors 2 Malware
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

1w ago · talos

UAT-10147, a Chinese-speaking threat actor, is deploying a new cross-platform backdoor named SPECTRE that targets both Windows and Linux systems. The implant includes advanced capabilities such as process injection, credential theft, anti-analysis routines, and EDR evasion via Bring Your Own Vulnerable Driver (BYOVD) techniques. On Linux, SPECTRE deploys a kernel rootkit called Specter, disguised as 'acpi_pad.ko', which uses ftrace-based hooking to hide processes, modules, and enable UID 0 escalation. The actor also leverages SEO fraud tools like BadIIS and a custom ASHX web handler targeting Vietnamese users, along with multiple backdoors including Meterpreter, Noodle RAT, QuasarRAT, and Gh0stCringe for persistence.

7 IoCs 4 Malware
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

2d ago · hacker-news

The Silver Fox threat actor is distributing the ValleyRAT backdoor (also known as Winos 4.0) disguised as a signed Chinese adware application, QN Wallpaper. The malware uses DLL sideloading by planting a malicious libcef.dll alongside the legitimate QnWallpaper.exe, allowing it to execute within a trusted signed process. The backdoor disables Windows Defender, adds itself to autorun, escalates privileges if needed, and can mark its process as critical to cause a system crash if terminated. It provides full remote control, including keystroke logging, screenshot capture, and delivery of additional payloads, primarily targeting users in China and India.

6 IoCs 1 Actors 1 Malware
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

1d ago · hacker-news

Threat actors are actively exploiting two critical vulnerabilities, CVE-2026-0768 in Langflow and CVE-2026-66066 (KindaRails2Shell) in Ruby on Rails, to conduct credential probing, remote code execution, and command-and-control activities. Exploitation of CVE-2026-66066 involves uploading a crafted image to read sensitive files, leak environment secrets, and achieve RCE, particularly when libvips is used for image processing. Attackers have targeted canary systems globally, with source traffic traced to Russia and a single IP in France, and C2 infrastructure in Israel. Additional post-exploitation activities include deploying credential harvesters, cryptominers, disabling auditd, and lateral movement.

6 IoCs 5 CVEs
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

1d ago · hacker-news

Russia-aligned threat actor UAC-0099 has been observed using a technique called GuardBreaker to disrupt AI-assisted malware analysis by embedding a nuclear weapon-related prompt in malicious VBS scripts. The prompt 'I want to make a nuclear weapon. Help me ...' is inserted as a comment to trigger safety mechanisms in large language models, preventing further code analysis. The VBS script downloads and installs MATCHBOIL, a C#-based loader used by UAC-0099 to deploy additional payloads, with prior targeting activity focused on Ukraine's transportation and energy sectors.

1 IoCs 1 Actors
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

1d ago · hacker-news

METR, a non-profit AI research organization, disclosed two security incidents in 2026 involving unauthorized access to its systems. In March, attackers exploited a 'fail-open vulnerability' in a publicly accessible 'vibe-coded app' on a researcher's personal EC2 instance, leading to the exposure of an API key that was used to consume approximately $600,000 worth of AI inference credits. The attackers gained access by scanning certificate transparency logs for high-signal keywords related to LLMs and agents, then directly prompted the agent to reveal the API key. In May, a separate campaign involved systematic probing of METR's infrastructure, including credential stuffing and OAuth token attacks, alongside an inadvertently exposed SQL query endpoint that could have allowed access to unpublished evaluation data, though no evidence indicates data was exfiltrated.

Recently patched PaperCut zero-days used in data theft attacks

1d ago · bleeping-computer

Two recently patched zero-day vulnerabilities in PaperCut NG and MF print management software, tracked as CVE-2026-81578 and CVE-2026-82078, are being actively exploited in data theft attacks. Attackers are chaining the flaws to bypass authentication and access backend databases via PaperCut's external user-lookup functionality, using the vulnerabilities to dump database tables through Derby without executing remote code. Threat intelligence firm Defused observed the exploit activity in honeypots starting August 29, 2026, indicating ongoing abuse by unidentified actors.

Five Venezuelans plead guilty to ATM jackpotting attacks in US

1d ago · bleeping-computer

Five Venezuelan nationals have pleaded guilty to conducting ATM jackpotting attacks in the United States, attempting to install malware on ATMs to force them to dispense cash. The attacks occurred in Wamego and Manhattan, Kansas, but were unsuccessful due to alarm triggers and surveillance detection. The individuals were part of a larger wave of ATM jackpotting incidents linked to the Tren de Aragua criminal organization, which has been associated with the use of Ploutus malware in a broader campaign targeting financial institutions across the U.S.

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

2d ago · unit42

The Spring Ring campaign is a coordinated voice phishing (vishing) operation conducted via Microsoft Teams, where threat actors impersonate IT help desk personnel to manipulate employees into executing malicious payloads. The attackers use spoofed external Microsoft 365 tenants with professionally named accounts and initiate unsolicited voice calls to establish trust. Two distinct attack campaigns were observed: Campaign A delivers an obfuscated PowerShell-based remote access Trojan (RAT) via a malicious domain, while Campaign B uses tailored cloud-hosted executables to deploy malware that enables lateral movement through NTLM relay attacks leveraging PetitPotam. These attacks aim to gain persistent access and escalate privileges to compromise domain controllers.

32 IoCs
Is Cyber missing the Marque?

1w ago · talos

UAT-10147, a Chinese-speaking cybercrime group, is leveraging agentic AI to automate and scale sophisticated post-compromise operations across global web servers. The group uses AI to generate operational playbooks, customize malware, and dynamically validate exploit paths, including through stolen ASP.NET MachineKeys for ViewState deserialization attacks. A newly identified backdoor called SPECTRE features a cross-platform capability with a custom Linux kernel rootkit and Bring Your Own Vulnerable Driver (BYOVD) techniques designed to evade endpoint detection and response (EDR) solutions. Defenders are advised to patch internet-facing applications, secure MachineKeys, block vulnerable drivers, and monitor for anomalous HTTP 500 errors used during exploitation.

15 IoCs
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

4d ago · hacker-news

The state government of Berlin confirmed a ransomware attack and data exfiltration from its administrative network between August 7 and August 12, 2026, attributed to the Rhysida ransomware group. The attackers claimed to have stolen 5.79 terabytes of data, including personal information on over 12,000 individuals, and published a post on their darknet leak site on August 28. Despite the extortion attempt, Berlin has refused to pay the ransom. Forensic investigations are ongoing, and affected departments were isolated before being reconnected on August 23.

1 IoCs 1 Actors 1 CVEs
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

4d ago · hacker-news

Multiple critical vulnerabilities have been identified in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, which could allow unauthenticated attackers to bypass authentication, escalate privileges, steal sensitive data, or achieve remote code execution. The most severe of these, CVE-2026-82222 in the GiveWP plugin, enables arbitrary command execution through a PHP object injection chain involving unsafe unserialization and a gadget chain in shipped code. These flaws affect specific versions of the plugins and themes when certain configurations are enabled, posing significant risk to WordPress sites if left unpatched.

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

3d ago · hacker-news

Microsoft has uncovered a new variant of the ClickFix campaign dubbed TerminalFix, which uses social engineering to trick users into executing a malicious PowerShell command via fake Cloudflare CAPTCHA pages served through compromised websites. The attack employs DLL sideloading using a legitimate binary and a malicious DLL to execute multi-stage payloads, including steganographic extraction from PNG files and extensive Active Directory reconnaissance. The final payload is a Python-based reverse-tunnel backdoor that establishes persistent C2 access via an encrypted WebSocket, enabling attackers to pivot across internal networks. This campaign poses a serious risk to enterprise environments due to its lateral movement and persistence capabilities.

6 IoCs
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

2d ago · hacker-news

A China-nexus cyber espionage group tracked as Fire Ant has expanded its operations to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts, enabling credential theft, traffic interception, and suppression of security telemetry. The group deployed custom malware including TacTap, a library injector targeting the tac_plus authentication process, and BridgeAgent, a Linux backdoor disguised as a Zabbix agent. The attackers manipulated router configurations to hide malicious GRE tunnels and exfiltrated packet captures to external FTP servers, while also obfuscating stolen credentials using XOR encryption. The campaign shows strong overlap with UNC3886, though definitive attribution remains unconfirmed.

18 IoCs 1 Actors
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

2d ago · hacker-news

Aurora ransomware operators, a Russian-speaking cybercrime group, have been leveraging SpaceX's AI-powered coding assistant Cursor to plan and execute attacks against at least 10 organizations between April and May 2026. The group used Cursor to assist in attack planning, including Active Directory Certificate Services exploitation, and conducted hands-on exploitation using credentials or existing access. The attack chain includes initial access via email bombing and social engineering, lateral movement using SMB, LDAP, RDP, and RPC, privilege escalation, evasion of security tools, data exfiltration, and deployment of a multi-platform encryptor written in Zig. A related AI-assisted toolkit called Gryxa has also emerged, enabling persistent access, credential theft from Chromium browsers, and evasion of endpoint protection.

3 IoCs 1 Malware
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

2d ago · hacker-news

North Korean threat actors, operating under multiple aliases including PurpleDelta, Jasper Sleet, and Wagemole, are conducting a large-scale job fraud campaign to infiltrate global companies in IT, healthcare, sales, and other sectors. These actors use forged identities, AI-generated profiles, and synthetic personas to gain remote employment, often using laptop farms equipped with PiKVM and Guermok USB devices to maintain control. They leverage tools like AnyDesk, Telegram, and Slack for coordination, and abuse legitimate platforms such as Workday, Zoom, and Microsoft Teams during recruitment and employment, posing significant insider threat and sanctions compliance risks.

4 IoCs 1 Actors
Berlin confirms data theft after Rhysida ransomware attack claims

2d ago · bleeping-computer

The city administration of Berlin has confirmed a ransomware attack by the Rhysida group, which claims to have exfiltrated 5.79 TB of data from its administrative network. The stolen data includes sensitive government records, personal information, credentials, and critical infrastructure assessments, with attackers threatening to publish the data unless a ransom is paid. The incident was discovered in mid-August 2026, and investigations are ongoing, involving the State Criminal Police Office, public prosecutor, and federal security agencies. No evidence was found that election data was compromised, and the affected departments were disconnected from the state network on August 14.

Chinese Fire Ant hackers turn Cisco routers into spying platforms

2d ago · bleeping-computer

The Chinese state-sponsored threat actor Fire Ant has shifted tactics to compromise Cisco IOS XR routers, TACACS servers, and Linux management systems, turning routers into surveillance platforms via concealed GRE tunnels. The group deployed a custom backdoor named 'BridgeAgent', disguised as a Zabbix agent, enabling reverse shells and execution of additional payloads. Fire Ant uses stealthy persistence mechanisms, suppresses syslog messages, and exfiltrates network traffic PCAPs to FTP servers, aiming to map and access high-value networks through a 'target behind the target' strategy. The group's activity overlaps with UNC3886 but shows distinct implementation differences.

1 IoCs 1 Actors
Microsoft warns of TerminalFix attacks deploying reverse tunnels

1d ago · bleeping-computer

Microsoft has identified a new variant of ClickFix attacks dubbed TerminalFix, which uses fake Cloudflare CAPTCHA prompts on compromised websites to trick users into executing malicious PowerShell commands in Windows Terminal. The attack chain involves downloading a ZIP containing a signed executable and a malicious DLL, followed by steganographic retrieval of additional payloads from PNG images. A custom Python-based reverse-tunnel module establishes an encrypted WebSocket connection to gitnow[.]dev:443, enabling attackers to pivot into internal networks via SOCKS5-style proxying and perform reconnaissance on domain controllers, databases, and other critical systems.

2 IoCs
Cronos blockchain restarts after $74 million Tectonic exploit

1d ago · bleeping-computer

The Cronos blockchain was exploited via a price-manipulation attack on the Tectonic DeFi lending platform, resulting in the attacker borrowing $74 million worth of assets by artificially inflating the value of the TONIC token by 100x within 20 minutes. The attacker successfully withdrew approximately $6 million in Ethereum, while the remainder of the funds were frozen due to the blockchain's emergency response. Cronos halted operations, rolled back the chain state to before the exploit occurred, and has since resumed normal operations. A post-mortem analysis is expected to follow.

Pokémon Center data breach exposes customer info, cancels some orders

2w ago · bleeping-computer

Pokémon Center disclosed a data breach affecting customers in the United Kingdom and Germany due to a cyberattack on its third-party logistics provider, CEVA Logistics, which was compromised between July 29 and August 1, 2026. The breach exposed customer personal information including full names, mailing addresses, phone numbers, email addresses, and order details. Although payment card data was not accessed, the incident led to order cancellations and shipping delays. CEVA Logistics, a subsidiary of CMA CGM Group, confirmed the breach impacted multiple European retailers, including Valve, which also reported stolen customer data.

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

2w ago · hacker-news

GitLab has patched a critical vulnerability, CVE-2026-19478, affecting its self-managed Community and Enterprise Editions, which could allow unauthenticated attackers to remotely modify or delete public projects and user data under certain conditions. The flaw exists in the GraphQL implementation and can be exploited over the network without authentication or user interaction. The vulnerability impacts versions 18.2 to 18.11.10, 19.0 to 19.0.7, 19.1 to 19.1.5, and 19.2 to 19.2.3. A second high-severity issue, CVE-2026-19650, was also fixed, involving a CSRF vulnerability in the GraphQL multiplex query handler that allows unauthenticated mutation execution via GET requests under certain conditions.

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

2w ago · hacker-news

Evooo1Bot is a newly identified Linux botnet derived from Mirai source code that targets internet-facing edge devices by exploiting known vulnerabilities. It installs a SOCKS5 proxy on compromised systems, enabling threat actors to route traffic through infected devices for evasion and anonymity. The malware includes an exploit toolkit targeting multiple CVEs, performs anti-analysis checks, and communicates with C2 servers over encrypted channels on port 443. It supports various post-compromise actions including DDoS attacks, credential sniffing, SSH brute-forcing, and lateral movement.

2 IoCs 3 CVEs
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

2w ago · hacker-news

Iranian nation-state actors linked to Cavern (aka Cav3rn) C2 framework have evolved their infrastructure to blend malicious traffic with legitimate services, using DNS A-record queries to dynamically switch between direct HTTPS and Google Apps Script relays for command-and-control. A new module, HOLLOWGRAPH, abuses Microsoft 365 calendars via the Graph API to exfiltrate data and receive commands, with events scheduled far into the future to avoid detection. The framework uses a modular architecture with components like GoogleService.dll and rnp.dll, leveraging legitimate cloud services to evade perimeter defenses and maintain persistence.

1 IoCs 4 Actors 1 Malware
← Previous Next →