Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: bleeping-computer Clear filter
ShinyHunters data leaks fuel $2,000 sextortion email scam

1mo ago · bleeping-computer

Threat actors are leveraging email addresses and company breach data leaked by the ShinyHunters extortion group to conduct a sextortion email campaign. The emails falsely claim that recipients' devices were compromised and threaten to release intimate videos unless $2,000 in Bitcoin is paid. The campaign uses legitimate breach details to appear credible, but there is no evidence of actual device compromise. ShinyHunters has denied involvement in the scam.

1 IoCs 1 Actors
Hackers exploit Cisco SNMP flaw to deploy rootkit on switches

1mo ago · bleeping-computer

Threat actors have exploited a recently patched SNMP vulnerability (CVE-2025-20352) in Cisco IOS and IOS XE devices to deploy a rootkit on vulnerable switches, enabling them to bypass access controls, manipulate logs, and move laterally across VLANs. The attacks, tracked as 'Operation Zero Disco' by Trend Micro, target older Linux systems lacking endpoint detection and response solutions. The rootkit includes fileless components that persist across reboots via IOSd hooks, and attackers also attempted to exploit the older CVE-2017-3881 vulnerability. Cisco confirmed the exploitation of CVE-2025-20352 as a zero day, with no reliable detection tool currently available.

OpenAI confirms ChatGPT is down worldwide

1mo ago · bleeping-computer

OpenAI has confirmed a worldwide outage affecting ChatGPT, with users across the U.S., Europe, India, Japan, Australia, and other regions reporting connectivity issues. The company is actively investigating the cause of the disruption, which began within the last 30 minutes. No evidence of a cyber attack or compromise has been provided in the article; the nature of the incident appears to be service degradation rather than malicious activity.

OnTrac notifies customers of data breach after network hack

1mo ago · bleeping-computer

OnTrac, a U.S.-based parcel delivery company, disclosed a data breach that occurred between March 20 and 22, 2026, where attackers accessed customer data. The breach was detected on March 23, and the company engaged a third-party specialist to investigate. While the exact data compromised is redacted, the company offered credit monitoring services to affected customers. No ransomware group has claimed responsibility, and there is no evidence of data leakage or fraud at this time.

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

1mo ago · bleeping-computer

Hackers are hijacking hotel and conference center Wi-Fi DNS settings to redirect users to fake Microsoft 365 login pages, enabling theft of credentials and bypassing multi-factor authentication via OAuth token authorization. The campaign, active since at least June 2026, targets traveling employees across multiple sectors including finance, healthcare, and legal services. The attack technique resembles previous router-based campaigns linked to the APT28 group. Researchers observed malicious domains and attempted abuse of WPAD for traffic interception.

4 IoCs 1 Actors
Hermes AI agent used to automate attack on Thai Finance Ministry

1mo ago · bleeping-computer

A threat actor leveraged the open-source Hermes AI agent in unattended 'YOLO' mode to automate post-exploitation activities during an alleged cyberattack on Thailand's Ministry of Finance. Evidence from exposed web directories indicates deployment of web shells, custom scripts, and a previously undocumented Go-based implant named Hades. The attackers targeted internal systems including Hadoop, Apache Ambari, GlassFish, and mail servers, using AI to perform privilege escalation, enumeration, and file traversal. While the Ministry has not confirmed a breach, artifacts suggest active intrusion and lateral movement within the network.

5 IoCs 2 Malware
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

1mo ago · bleeping-computer

Slopsquatting, Phantom Domains, and HalluSquatting represent a class of AI-driven attacks exploiting the predictability of hallucinated identifiers in AI coding agents. Attackers register these predicted names—such as fake package names, domains, or repositories—before they are requested, enabling malicious code delivery without phishing or credential theft. The core vulnerability lies in agents automatically fetching and executing unverified resources, creating scalable attack vectors for botnet-style compromise. This pattern highlights a systemic design flaw in late binding of untrusted AI-generated outputs.

Chick-fil-A data breach affects more than 13,000 customers

1mo ago · bleeping-computer

Chick-fil-A confirmed a data breach affecting over 13,000 customers due to credential stuffing attacks on its website and mobile app between June 17 and June 19, 2026. Attackers used credentials obtained from third-party sources to gain unauthorized access to Chick-fil-A One loyalty accounts. Compromised data includes names, email addresses, membership numbers, partial payment details, and potentially birth dates, phone numbers, and addresses.

Microsoft blames massive Microsoft 365 outage on maintenance bug

1mo ago · bleeping-computer

A massive Microsoft 365 and Azure outage occurred on July 23, 2026, beginning at 10:44 AM ET, primarily affecting services in the West US Azure region. The incident was caused by a bug in Microsoft's automated network maintenance system that incorrectly removed IP routes from more devices than intended, disrupting connectivity. Services including SharePoint, OneDrive, Teams, Power BI, and Microsoft Defender were impacted, with traffic rerouting and recovery efforts completed by 2:26 PM ET. Microsoft confirmed resolution of the incident and is conducting a full internal review of its maintenance processes.

Man gets six years for hacking 750 women's Snapchat accounts

1mo ago · bleeping-computer

An Illinois man, Kyle Svara, was sentenced to six years in prison for hacking over 750 women's Snapchat accounts using social engineering tactics to steal nude photos, which he traded or sold online. He posed as a Snap Inc representative, used anonymized phone numbers, and phished Snapchat access codes between May 2020 and February 2021. Svara also distributed child sexual abuse material and falsely denied involvement during investigation.

2 IoCs
Europol flags 4,340 URLs for removal in 'The Com' crackdown

1mo ago · bleeping-computer

Europol, in collaboration with law enforcement from nine countries, conducted a multi-week operation targeting 'The Com,' a decentralized network of violent extremist groups. The operation flagged 4,340 URLs for removal, focusing on content promoting self-harm, child sexual abuse, violence, and extremist ideologies. The Com operates through subgroups like Offline Com, Cyber Com, (S)extortion Com, and 764, which recruit and exploit minors via social media and gaming platforms. The network has been linked to ransomware attacks and child exploitation, with prior operations leading to dozens of arrests and victim identifications.

Clop ransomware targets Windchill, FlexPLM in data theft attacks

1mo ago · bleeping-computer

The Clop ransomware gang is conducting a new data theft extortion campaign by exploiting a critical vulnerability, CVE-2026-12569, in Internet-exposed PTC Windchill and FlexPLM instances. The flaw allows unauthenticated remote code execution, enabling attackers to deploy JSP webshells for data exfiltration. Organizations in high-risk sectors such as aerospace, defense, and manufacturing are targeted, with Clop using the email support@cryptohox.com for extortion demands.

1 IoCs
New Dolphin X malware uses AI to rank high-value targets

1mo ago · bleeping-computer

The Dolphin X remote access trojan (RAT) is a newly identified malware advertised on cybercrime forums that combines credential theft with an AI-powered 'AI Profiler' to rank infected users by their potential value to attackers. The AI Profiler analyzes application usage, browser domains, installed software, and other data to generate risk scores and daily summaries, enabling threat actors to prioritize high-value targets such as those with access to corporate networks, cloud environments, or cryptocurrency assets. The malware claims to target over 300 applications, including browsers, password managers, crypto wallets, and cloud tools, though its full capabilities remain unverified due to analysis limitations.

Fake Claude app promoted by Bing ads pushes SectopRAT malware

1mo ago · bleeping-computer

A malvertising campaign leveraging Bing ads promotes a fake Claude desktop application to distribute the SectopRAT remote access trojan. The malicious installer, ClaudeDesktop.exe, sideloads a malicious DLL to deploy the malware, which establishes persistence via a scheduled task under the name DockerDesktop.exe. SectopRAT, also known as ArechClient2, steals credentials, files, and sensitive data from browsers and messaging apps, using Ethereum transactions to retrieve C2 addresses. The campaign, dubbed FakeAgent, has compromised at least 29 organizations and uses anti-analysis techniques to evade detection.

3 IoCs 1 Malware
Australian energy provider Origin says data breach exposes client data

1mo ago · bleeping-computer

Australian energy provider Origin Energy confirmed a data breach involving unauthorized access to customer data, including personally identifiable information such as names, addresses, dates of birth, and partial financial details. The breach impacts an unknown number of customers, with threat actors claiming to possess data from 2 million individuals. Origin has launched an investigation, notified relevant authorities, and is contacting affected customers while working to prevent further unauthorized access.

1 IoCs
Microsoft 365 outage affects Teams, SharePoint and other services

1mo ago · bleeping-computer

A widespread outage affecting Microsoft 365 services, including Teams, SharePoint, OneDrive, and the Admin Center, began on July 23, 2026, at 10:44 a.m. ET, primarily impacting users in North America. The issue has caused degraded functionality such as failed page loads, missing images in Teams, and inaccessible admin tools. Microsoft is investigating the incident, identified as MO1437424, and has initiated traffic rerouting to mitigate the impact, with partial recovery observed for some users.

Hackers abuse Notepad++ plugins to stealthily install malware

1mo ago · bleeping-computer

Ukraine's CERT has identified a campaign by threat cluster UAC-0099 that abuses Notepad++ plugins to stealthily deploy malware. The attackers distribute a malicious archive containing a legitimate Notepad++ installation alongside a malicious plugin named NppExport.dll, which loads the LunchPoke utility to establish persistence. LunchPoke extracts and executes BurnyBear, a loader for the MatchBoil V2 malware, enabling further malicious activity including scheduled task creation and C2 communication.

5 IoCs 2 Actors
Russian hackers exploit Zimbra zero-click flaw for email theft

1mo ago · bleeping-computer

Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting a patched zero-click XSS vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite to steal email data, including credentials, 2FA tokens, and the Global Address List. The group targets organizations in the Defense Industrial Base, government, education, energy, and technology sectors, using both the vulnerability and adversary-in-the-middle phishing kits to bypass MFA and maintain persistent access. Stolen data is exfiltrated via DNS and HTTPS to attacker-controlled infrastructure using the 'Flowerbed' collection framework.

6 IoCs 1 Actors 1 CVEs
New RefluXFS Linux flaw lets attackers gain root privileges

1mo ago · bleeping-computer

A race condition vulnerability in the Linux kernel's XFS filesystem, dubbed RefluXFS and tracked as CVE-2026-64600, enables local attackers to gain root privileges by exploiting reflink functionality. The flaw, present since Linux kernel 4.11, allows overwriting of protected files such as /etc/passwd or SUID-root binaries without triggering kernel logs or losing the SUID bit, making detection difficult. Exploitation is reliable, persistent across reboots, and bypasses standard security mechanisms like SELinux and KASLR. Immediate kernel patching is advised, as no practical mitigations exist.

EU fines Google $1 billion for search, app store antitrust violations

1mo ago · bleeping-computer

The article reports on regulatory and financial penalties imposed on Google by the European Union for violations of the Digital Markets Act (DMA), including favoring its own services in search results and restricting app developers' ability to promote alternative purchase options on the Google Play store. These actions are part of broader antitrust enforcement, not cyber threat activity. There is no mention of malicious cyber operations, threat actors, or technical indicators of compromise.

FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires

1mo ago · bleeping-computer

The article discusses the transition from FedRAMP Rev5 to FedRAMP 20X, emphasizing a shift from point-in-time compliance to continuous, machine-readable assurance. It highlights the importance of Key Security Indicators (KSIs) that require ongoing validation through automated systems and trustworthy evidence. The change aims to improve security posture by ensuring controls remain effective in dynamic cloud environments, moving beyond static documentation to real-time operational resilience.

Check Point warns of SmartConsole zero-day exploited in attacks

1mo ago · bleeping-computer

Check Point has disclosed an actively exploited zero-day vulnerability, CVE-2026-16232, in its SmartConsole GUI admin panel. The flaw is an authentication bypass that allows unauthenticated attackers to obtain administrator-level application tokens. Exploitation enables changes to security policies and configurations, requiring exposed Management Server IPs and unrestricted Trusted Clients. CISA has added the vulnerability to its known exploited catalog and mandated federal agencies to patch by July 25, 2026.

5 IoCs 2 Malware
Microsoft working to fix Exchange Online mailbox quarantine issue

1mo ago · bleeping-computer

Microsoft is addressing an ongoing issue in Exchange Online that has mistakenly quarantined user mailboxes since July 19, 2026, due to a recent infrastructure change causing excessive memory consumption. The out-of-memory condition triggered incorrect mailbox quarantines, blocking users from sending and receiving emails and accessing calendars. This incident, identified as EX1436407, is a recurrence of a previous issue (EX1434354), and Microsoft is performing cleanup operations to restore affected mailboxes.

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

1mo ago · bleeping-computer

The Chaos ransomware gang is deploying a new Rust-based backdoor named msaRAT that leverages Chrome or Edge browsers to route command-and-control (C2) traffic, evading detection by avoiding direct network connections. The malware uses the Chrome DevTools Protocol to control a headless browser session and establishes encrypted communication via WebRTC through Twilio TURN servers and a Cloudflare Workers endpoint. This dual-layer infrastructure hides the attacker's true C2 server and complicates traceback efforts, while also bypassing firewalls and allowlists by blending with legitimate web traffic.

1 IoCs 1 Actors
Upbound says hack caused $13 million in fraudulent Acima leases

1mo ago · bleeping-computer

The Upbound Group, a fintech company formerly known as Rent-A-Center, disclosed a cybersecurity incident in which unauthorized actors accessed non-sensitive customer data and documents. The stolen information was used to fraudulently obtain goods through Acima's lease-to-own system, resulting in approximately $13 million in losses. The company has engaged external cybersecurity experts, implemented enhanced security controls, and notified law enforcement, but no ransomware group has claimed responsibility.

South Korea discloses data breach impacting diplomats worldwide

1mo ago · bleeping-computer

South Korea disclosed a data breach affecting diplomats worldwide after hackers compromised the National Diplomatic Academy's online education system. The breach occurred between April 2025 and February 2026, exposing personal information such as names, email addresses, IDs, and encrypted passwords of at least 6,000 individuals, including current and former Ministry of Foreign Affairs employees. The attack went undetected for ten months due to the server's location within MFA headquarters and lack of regular security scrutiny, with the National Intelligence Service ultimately uncovering the compromise.

New InfraTrust report reveals infrastructure flaws admins should patch first

1mo ago · bleeping-computer

The July 2026 InfraTrust Pulse report by Eclypsium highlights critical infrastructure vulnerabilities that administrators should prioritize, focusing on those that are actively exploited, remotely accessible, or unauthenticated. Key vendors affected include SonicWall, Fortinet, Dell, F5, Juniper, and NVIDIA, with flaws impacting network edge devices, data center infrastructure, and firmware components. Russian and Chinese state-sponsored actors are increasingly targeting such infrastructure, as seen in campaigns linked to Volt Typhoon and Salt Typhoon. The report emphasizes risk-based prioritization over CVSS scores alone, noting that internet-exposed flaws pose significant real-world threats even if their severity scores are lower.

2 Actors
How enterprise GenAI can amplify ransomware risk — and how to contain it

1mo ago · bleeping-computer

Enterprise adoption of generative AI is amplifying existing ransomware risks by increasing the speed and scale of attacks, particularly through identity compromise and excessive permissions granted to AI systems. Attackers are leveraging AI to enhance phishing, code generation, reconnaissance, and extortion, while compromised AI agents can accelerate data theft and lateral movement. The threat is not from AI itself but from how it expands the attack surface when integrated with business systems without proper governance.

Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

1mo ago · bleeping-computer

Swiss rail manufacturer Stadler Rail was targeted by the Everest ransomware gang, which stole technical data from a supplier's shared data exchange platform and demanded a $12.3 million ransom. Stadler confirmed the breach but stated that its IT systems and global production operations were unaffected. The company refused to pay the ransom and filed a criminal complaint, asserting that no personal or security-relevant data was compromised.

Microsoft to stop Exchange 2016 / 2019 security updates in October

1mo ago · bleeping-computer

Microsoft has announced that the Extended Security Update (ESU) program for Exchange Server 2016 and 2019 will end in October 2026, with no further extensions. After this date, no security updates will be provided, leaving unpatched systems vulnerable to exploitation. Organizations are advised to upgrade to Exchange Server Subscription Edition or migrate to Exchange Online to maintain security and support.

← Previous Next →