Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: bleeping-computer Clear filter
Hackers breach govt webmail while running parallel crypto fraud

2w ago · bleeping-computer

The China-based threat actor Jewelbug (also known as Earth Alux and REF7707) has been conducting espionage operations against government and military organizations in the Middle East, Southeast Asia, and South Asia, while simultaneously running a large-scale cryptocurrency fraud operation. The group compromised a shared webmail platform used by multiple government tenants, injecting a malicious script into login and mailbox pages to steal cookies and credentials. Successful compromises led to the deployment of the Antino backdoor via fake Adobe Flash installers, enabling further payload delivery, including a malicious browser extension called 'PDF Viewer' that steals credentials and injects JavaScript. Symantec uncovered the group's infrastructure, revealing over one million implant check-ins, more than 580,000 stolen browser cookies, and extensive cryptocurrency fraud operations using AI-generated content and lookalike domains impersonating Binance and OKX.

2 IoCs 2 Actors
Trezor discloses data breach affecting nearly 14,000 customers

2w ago · bleeping-computer

Trezor disclosed a data breach affecting nearly 14,000 customers due to a compromise of its shipping provider, ShipMonk, which was breached via a zero-day SQL injection vulnerability in the analytics platform Metabase. The attackers accessed customer order data including names, email addresses, phone numbers, and shipping addresses. ShipMonk confirmed the breach stemmed from exploitation of a critical vulnerability in Metabase, which was also used to attack other companies like Framework and Tally. Trezor emphasized that its own systems were not compromised and device security remains intact, but warned affected users of increased phishing risks. The ShinyHunters extortion group has claimed responsibility, sending extortion emails to ShipMonk.

1 Actors
Critical VMware vCenter RCE flaw exploited for reverse SSH access

2w ago · bleeping-computer

A critical directory traversal vulnerability in VMware vCenter Syslog Server (CVE-2026-59310) is being actively exploited to gain remote code execution. Attackers are deploying the open-source reverse_ssh framework to establish reverse SSH connections for persistence and remote access. Compromised systems have been observed connecting to attacker infrastructure starting August 3, with 361 victim IPs identified across 47 countries by August 7. The campaign is suspected to be conducted by an advanced persistent threat (APT) actor, though attribution remains unconfirmed.

Android malware combo takes out loans and relays victims' credit cards

2w ago · bleeping-computer

A new Android malware campaign combines WindRelay, an NFC relay tool, with the SpyNote remote administration trojan to enable real-time financial fraud. Attackers socially engineer victims by impersonating bank employees, tricking them into sideloading a malicious APK that grants Accessibility Services, enabling remote device control. The attackers then install WindRelay to capture NFC payment card data and PINs during live phone calls, allowing them to conduct fraudulent transactions or take out loans in the victim's name. The attack chain was executed entirely over a 13-minute call, highlighting a shift toward real-time, voice-mediated social engineering without requiring persistent malware access.

6 IoCs 2 Malware
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

2w ago · bleeping-computer

The City-Forum data theft campaign targets misconfigured Salesforce Experience Cloud and ServiceNow portals by exploiting overly permissive guest user access. Attackers use a single server at IP 158.220.87.79 to enumerate and steal data exposed to unauthenticated users via custom techniques on both legacy Aura and newer Lightning Web Runtime (LWR) frameworks in Salesforce, as well as the ServiceNow Service Portal search API. The campaign has been active since at least March 2025, with increasing activity across multiple sectors including finance, telecom, and public-sector organizations. No vulnerability is exploited; instead, the theft relies on misconfigurations that allow public access to sensitive records.

2 IoCs 1 Actors
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

2w ago · bleeping-computer

Hackers are actively exploiting a critical vulnerability, CVE-2026-71362, in Adobe Commerce and Magento platforms to hijack customer accounts without authentication or user interaction. The flaw stems from improper handling of customer identity in account sessions, allowing attackers to switch between customer accounts. Security firm Sansec has observed exploitation attempts in the wild and confirms that the vulnerability enables unauthorized access to private customer data. Adobe released patches as isolated updates, urging administrators to apply them immediately to mitigate risk.

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

3w ago · bleeping-computer

Researchers Alejandro Hernando and Borja Martínez disclosed 'Plug and Pwn' attack techniques that exploit Windows Plug and Play to gain SYSTEM privileges by emulating malicious USB devices. The attacks abuse signed vendor software installed automatically by Windows during device enumeration, leveraging vulnerabilities in co-installers, services, or insecure update mechanisms. One variant, 'NoPlug & Pwn', abuses RDP USB redirection to perform the attack remotely without physical access. A demonstrated chain uses emulated Sierra Wireless and Sony FeliCa devices to manipulate DNS and hijack unencrypted downloads, ultimately achieving code execution as SYSTEM. Another RDP-based variant emulates an Intel RealSense camera to exploit DLL hijacking in a co-installer for privilege escalation.

1 IoCs
Hackers leverage new Microsoft SharePoint exploit in attacks

3w ago · bleeping-computer

Attackers are actively exploiting CVE-2026-55040, a critical authentication bypass vulnerability in Microsoft SharePoint's JWT token validation pipeline, to perform unauthorized actions as SharePoint users or administrators. A proof-of-concept exploit was published by Rapid7 and has already been weaponized, with attacks observed targeting SharePoint honeypots. Microsoft patched the vulnerability in its July 2026 updates, but over 8,500 SharePoint servers remain exposed online. CISA has issued warnings urging organizations to secure internet-facing SharePoint servers and apply security hardening measures.

New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges

3w ago · bleeping-computer

A new zero-day vulnerability dubbed 'ShieldBreak' has been disclosed by security researcher Nightmare Eclipse, exploiting a bypass in Microsoft Defender that allows privilege escalation to SYSTEM level on fully patched Windows 10, 11, and Server systems. The flaw effectively circumvents the patch for CVE-2026-50656 (RoguePlanet), which Microsoft had previously addressed. The exploit has been successfully tested on Windows 11 25H2 (Canary) and Windows Server 2025 with a 100% success rate. Microsoft Defender must be enabled for the exploit to work, and the vulnerability remains unpatched at the time of publication.

Sandworm hackers target IT pros with trojanized WireGuard VPN client

3w ago · bleeping-computer

The Russian threat group Sandworm, operating as UAC-0145, has been targeting IT professionals and system administrators since at least May 2026 through a social engineering campaign involving fake job offers. The attackers pose as legitimate IT companies, such as Sopra Steria, and lure victims into downloading a trojanized WireGuard-based client called 'SopraVPN' from SourceForge. The malicious client contains a custom Base64 decoder and executes PowerShell code that establishes persistence via scheduled tasks on Windows or downloads additional payloads on Linux through attacker-controlled infrastructure.

2 IoCs 1 Actors
DeadLock ransomware uses blockchain to resist infrastructure takedown

3w ago · bleeping-computer

The DeadLock ransomware operation, active since mid-2025, employs double-extortion tactics by stealing and encrypting data to extort ransom payments. It uses blockchain infrastructure, specifically the Polygon blockchain, to store configuration data and leak site content, making takedown efforts more difficult. The ransomware communicates with victims via a decentralized Session network and hosts stolen data on Wasabi cloud, while using XChaCha20 encryption with Curve25519 key exchange to lock files, appending the '.dlock' extension and dropping ransom notes. Microsoft observed deployment by multiple threat groups, including affiliates linked to Lynx and INC ransomware ecosystems.

3 IoCs 2 Malware
Cisco warns of ASA and FTD VPN flaw exploited to crash devices

3w ago · bleeping-computer

Cisco has warned of active exploitation of a high-severity denial-of-service vulnerability, CVE-2026-20349, in its Secure Firewall ASA and Threat Defense (FTD) software. The flaw stems from insufficient error checking when processing HTTP requests, allowing an unauthenticated remote attacker to crash affected devices by sending a crafted HTTP request to the SSL VPN service. Exploitation leads to a reload of the device, causing a DoS condition, and no workarounds exist—only patching with fixed software releases mitigates the issue.

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

3w ago · bleeping-computer

Microsoft's August 2026 Patch Tuesday addresses 400 vulnerabilities, including three zero-days. One of these, CVE-2026-68820, was actively exploited in the wild by the North Korean threat actor Lazarus Group to elevate privileges and deploy a kernel-mode rootkit called FudModule. The other two zero-days, CVE-2026-62832 and CVE-2026-72971, were publicly disclosed but not confirmed as exploited. Check Point linked the exploitation of CVE-2026-68820 to Lazarus, highlighting ongoing targeting using local privilege escalation in Windows drivers.

1 Actors 1 Malware
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees

3w ago · bleeping-computer

Delta Air Lines investigated a Wi-Fi deauthentication attack that occurred on Flight 591 from Las Vegas to Atlanta, carrying attendees of the DEF CON 34 hacker conference. Passengers allegedly performed a deauth attack to disconnect others from the in-flight network and broadcast a rogue Wi-Fi access point named 'Delta WiFi Fast' to phish credentials. The cabin crew deactivated Wi-Fi for about 30 minutes, and upon landing, federal authorities boarded the aircraft to question suspects and seize hardware. The rogue network reportedly displayed a phishing page harvesting personal and Google login credentials.

1 IoCs
Wesco confirms security incident after ExfilSquad claims data theft

3w ago · bleeping-computer

Wesco confirmed a cybersecurity incident involving its cloud CRM environment after the data extortion group ExfilSquad claimed to have stolen and leaked 2.6 million records containing customer and employee PII, CRM data, and authentication metadata. The company stated it does not believe sensitive data is at risk and reported no ransomware or malicious software found in its systems. ExfilSquad, known for targeting improperly configured Microsoft Power Pages, published the data after Wesco did not meet a ransom deadline. Researchers link the group's past activity to misconfigured Microsoft Dynamics 365 instances.

Cisco warns of high-severity ClamAV flaws with public exploits

3w ago · bleeping-computer

Cisco has warned of two high-severity vulnerabilities in ClamAV, tracked as CVE-2026-20337 and CVE-2026-20338, affecting versions 1.5.0 through 1.5.3. These flaws reside in the ZIP archive parser and stem from improper boundary checks and memory handling, allowing unauthenticated remote attackers to cause a denial-of-service (DoS) condition by submitting a specially crafted ZIP file that crashes the ClamAV scanning process. Proof-of-concept exploit code is publicly available, though there is no evidence of active exploitation in the wild. The vulnerabilities have a high security impact on Windows platforms due to the privileged context in which ClamAV runs, and they were patched in ClamAV version 1.5.4 released on August 7, 2026.

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

3w ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are actively exploiting a high-severity remote code execution vulnerability, CVE-2026-45659, in Microsoft SharePoint. The flaw stems from deserialization of untrusted data, allowing low-privileged attackers to execute arbitrary code on unpatched servers with low attack complexity. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on July 1, mandating federal agencies to patch within three days, and warned that over 200 internet-exposed SharePoint servers remain unpatched despite available updates.

US and South Korea warn of Gunra ransomware targeting govt agencies

3w ago · bleeping-computer

US and South Korean agencies issued a joint advisory warning of Gunra ransomware attacks targeting government and critical infrastructure organizations. The ransomware, first observed in April 2025, is derived from the leaked Conti source code and uses double extortion tactics. Gunra actors exploit vulnerabilities in Fortinet devices (CVE-2024-55591, CVE-2025-24472) and misconfigured SSH access on internet-facing systems to gain initial access, and have expanded operations through a ransomware-as-a-service (RaaS) model under the alias 'Golden Community'. The group has also recruited initial access brokers, including penetration testers, and has extended attacks to Linux environments since mid-2025.

1 Actors
Hackers breached a small Polish energy plant via private APN last year

3w ago · bleeping-computer

In December 2025, a threat actor linked to the Russian Electrum group breached a small Polish combined heat-and-power (CHP) plant by exploiting a misconfigured private Access Point Name (APN) network. The attackers gained initial access through a compromised FortiGate firewall and Teltonika cellular router at a wind farm, then moved laterally through the private APN to reach the CHP plant's operational technology (OT) network. They exploited default credentials on a WAGO PFC200 PLC, used it as a bridge to access Siemens PLCs, and ultimately shut down critical systems including the steam turbine and water treatment system.

3 IoCs 1 Actors
BdThemes plugins supply-chain hack creates rogue WordPress admins

3w ago · bleeping-computer

A supply-chain attack on BdThemes, a developer of premium WordPress plugins, allowed a threat actor to compromise its infrastructure and inject malicious JavaScript into a remote JSON feed used by its plugins. This feed is loaded in the WordPress admin dashboard, where the attacker exploited a cross-site scripting (XSS) vulnerability in the Biggop Library to create rogue administrator accounts on affected sites. The attack was stealthy, required no user interaction, and used a webshell for persistence. The same actor is believed to be behind recent similar attacks on other WordPress plugins.

3 IoCs
Valve notifies Steam hardware customers of a data breach

3w ago · bleeping-computer

Valve notified European Steam hardware customers of a data breach resulting from a cyberattack on its shipping partner, CEVA Logistics, between July 29 and August 1, 2026. Attackers accessed CEVA's systems and likely exfiltrated customer data including names, addresses, phone numbers, email addresses, and details of hardware orders. Valve confirmed that no Steam account credentials, payment information, or other sensitive account data were exposed. The company warned customers about potential phishing attempts leveraging the stolen personal information.

New StormEncryptor ransomware used by former Medusa affiliate

3w ago · bleeping-computer

A China-based threat actor tracked as Storm-1175, previously associated with the Medusa ransomware operation, has shifted to using a new ransomware variant called StormEncryptor. The actor exploits a vulnerability in the N-central RMM tool (CVE-2026-18577) to gain initial access, then uses tools like AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz for lateral movement and credential dumping. StormEncryptor is written in C++, encrypts files appending the '.encrypted' extension, and drops a ransom note titled '!!!README_FIRST!!!.txt', threatening data leakage if payment is not negotiated within three days.

8 IoCs 1 Actors
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

3w ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are actively exploiting two recently patched vulnerabilities in SonicWall SMA1000 appliances, tracked as CVE-2026-15409 and CVE-2026-15410. These flaws, including a critical server-side request forgery (SSRF) vulnerability, were exploited in zero-day attacks as early as June 22, prior to public disclosure. A threat actor known as UTA0533 has been linked to the exploitation of these vulnerabilities to deploy custom malware such as KNUCKLEBALL, Sou5, ROOTRUN, and ORANGETAIL on vulnerable systems. CISA added the vulnerabilities to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch within three days.

Critical Progress LoadMaster flaw now actively exploited in attacks

3w ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that a critical command injection vulnerability, CVE-2026-8037, in Progress Kemp LoadMaster appliances is being actively exploited by attackers. The flaw allows unauthenticated remote attackers to execute arbitrary commands on unpatched systems due to unsanitized API inputs. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies to patch affected systems within three days under Binding Operational Directive 26-04. Given the widespread use of LoadMaster in enterprise and government environments, including Fortune 500 companies and the U.S. Air Force, the risk of exploitation is considered high, and all organizations are urged to apply patches immediately.

Hackers breach TrueConf to trojanize client installers with backdoors

3w ago · bleeping-computer

The hacktivist group Head Mare breached unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions delivering the PhantomCore and PhantomGraph backdoors. Attackers exploited vulnerabilities in TrueConf Server, including CVE-2026-3502, to gain unauthorized access, execute arbitrary code, and deploy web shells for persistent access. The malicious installers are distributed to organization members and third parties connecting to compromised servers, enabling credential theft via LSASS memory dumping and remote command execution through a OneDrive-based C2 channel.

4 IoCs 1 Actors 1 Malware
Unlimited Technology Systems breach impacts 3.8 million people

3w ago · bleeping-computer

In October 2025, Unlimited Technology Systems, a healthcare software provider, suffered a data breach that exposed sensitive personal and medical information of approximately 3.8 million individuals. The breach occurred due to unauthorized access to its commercial data center between October 5 and October 10, 2025, during which attackers accessed files containing personal, financial, and health-related data. The company detected the activity on October 19, 2025, and confirmed the breach in July 2026, though no threat actor has been identified and no ransomware or extortion claims were made.

North Carolina Ports confirms cyberattack disrupting operations

3w ago · bleeping-computer

The North Carolina Ports Authority confirmed a cyberattack that disrupted IT systems and port operations at the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. The incident was detected on August 4, 2026, leading to a systems-wide outage and operational delays starting August 5. The authority activated its cybersecurity contingency plan and began recovery efforts, but did not attribute the attack to a specific threat actor or confirm data exfiltration. Operations were gradually returning to normal by August 7, though delays were still expected.

Metabase SQLi zero-day exploited in customer data-theft attacks

3w ago · bleeping-computer

A critical unauthenticated SQL injection vulnerability in Metabase versions 1.58 and above was exploited in zero-day attacks to compromise customer instances, leading to data theft at organizations including Framework, Tally, and a third-party vendor used by LexisNexis. The vulnerability allowed attackers to gain administrator access to Metabase instances, enabling them to steal stored credentials, read accessible data, and export customer information. Metabase confirmed active exploitation and issued patches across multiple affected branches, urging self-hosted users to update immediately and rotate credentials.

2 IoCs
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

3w ago · bleeping-computer

Researchers Daniël Trujillo and Mengjia Yan from MIT CSAIL discovered a new CPU-side speculative execution attack named TONTOU that bypasses Spectre v2 mitigations on Intel and AMD processors. The attack exploits a timing window between branch predictor neutralization and use by injecting timer interrupts to re-poison the branch predictor, enabling unprivileged code to leak sensitive kernel memory. The researchers demonstrated the attack on an AMD Zen 2 system, successfully extracting password hashes from /etc/shadow with 91.97% accuracy at 5.47 bytes per second, requiring only user-level access.

Swiss government SharePoint breach compromised 200 accounts

3w ago · bleeping-computer

Hackers breached the Swiss federal government's Microsoft SharePoint servers by exploiting a vulnerability disclosed in mid-July 2026, compromising approximately 200 user accounts. The Federal Office for Information Technology and Telecommunication (BIT) detected suspicious activity on July 28 and confirmed the breach by July 31, leading to immediate mitigation steps including blocking external access and resetting passwords. The attack likely leveraged either CVE-2026-56164 or CVE-2026-50522, both critical SharePoint flaws patched in the July 2026 updates, though the exact vulnerability used remains unconfirmed. No evidence of data exfiltration beyond credentials has been found, and no threat actor has claimed responsibility.

← Previous Next →