Back to Feed

Tag

Threat Intelligence

66 items tagged #threat-intelligence

Articles

APT-C-23 is back to targeting in Israel using Micropsia? 🤔 Found a possible interesting sample f...

APT-C-23 resurfaces targeting Israel with Micropsia malware.

New macOS stealer campaign uses Script Editor in ClickFix attack

New campaign delivers Atomic Stealer to macOS via Script Editor in ClickFix variant attack.

‼️🇺🇸 Threat actor TRD is allegedly selling two databases containing 2.1 million New York/Brookl...

Threat actor TRD selling databases of 2.1M NY residents and 918K Binance US users.

New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy

New Chaos malware variant targets misconfigured cloud deployments, adds SOCKS proxy capability.

Alleged Breach of Shanghai Fudan Microelectronics Leaks 175MB of IC Schematics, Internal Documents, and Intellectual Property

Threat actor s1ic3r leaks 175MB of IC schematics and IP from Shanghai Fudan Microelectronics.

‼️🇨🇳 Alleged Breach of Shanghai Fudan Microelectronics Leaks 175MB of IC Schematics, Internal D...

Shanghai Fudan Microelectronics breach leaks 175MB of IC schematics and internal documents.

‼️ Gunra Ransomware Claims 16 Victims 🇰🇷 KUKJE PHARM CO.,LTD. 🇹🇭 bkksky[.com 🇸🇬 triotech[....

Gunra ransomware gang claims 16 victims across multiple countries.

Hack-for-hire spyware campaign targets journalists in Middle East, North Africa

Bitter APT group conducts hack-for-hire spyware campaign targeting MENA journalists with ProSpy Android malware.

Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices

Masjesu botnet emerges as DDoS-for-hire service targeting IoT devices globally via Telegram.

tl;dr North Korean state-sponsored hacker accidentally detonates information stealer malware. St...

North Korean state-sponsored hacker accidentally exposes stolen data and credentials.

Operation Masquerade: FBI Disrupts Russian Router Hacking Campaign

FBI disrupts Russian GRU campaign hijacking routers via DNS attacks for espionage.

‼️🇺🇸 Actor coderx shared a 758MB database dump from Eastern Illinois University containing 93 C...

Actor coderx leaked 758MB database from Eastern Illinois University, citing retaliation for Iranian university attacks.

1/2‼️🇨🇴 Threat actors claim to be selling financial data from SUFI, a financing company within...

Threat actors claim to be selling financial data from SUFI, a Grupo Bancolombia financing company.

Most Organisations Face an Unsecured API Surge As AI Agents Outpace Security

Salt Security report: 92% of orgs lack security maturity for AI agents despite 66% API growth surge.

‼️ A threat actor claims to have leaked AMAInterview[.]ai database containing personal informatio...

Threat actor claims leak of AMAInterview.ai database with 24K+ users' personal data.

Montana Empire is an #AI-assisted #phishing kit mimicking a national postal service’s e-commerce...

Montana Empire AI-assisted phishing kit targets postal service customers with card and ID theft.

Iranian Threat Actors Disrupt US Critical Infrastructure Via Exposed PLCs

Iranian threat actors disrupted US critical infrastructure by compromising exposed programmable logic controllers.

FBI: Cybercrime Losses Neared $21 Billion in 2025

FBI reports $20.9 billion in cybercrime losses from 1M complaints in 2025, up 26% YoY.

Evasive Masjesu DDoS Botnet Targets IoT Devices

Masjesu DDoS botnet targets IoT devices across Vietnam, Brazil, India, Iran, Kenya, and Ukraine.

Russian Forest Blizzard Hackers Hijack Home Routers for Global Spying

Russian Forest Blizzard group hijacks home routers for DNS-based espionage targeting 5,000+ devices globally.

US Disrupts Russian Espionage Operation Involving Hacked Routers and DNS Hijacking

US disrupts Russian APT28 espionage operation using hacked routers for DNS hijacking and AitM attacks.

Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems

Anthropic's Claude Mythos AI model discovers thousands of zero-day vulnerabilities across major systems.

New ClickFix Attack Uses Node.js Malware via Tor to Steal Crypto

ClickFix campaign uses fake CAPTCHAs to deploy Node.js RAT malware via Tor to steal crypto.

Related archive contains legit signed WinWord.exe from Microsoft to load a malicious "AppvIsvSubs...

Legitimate signed WinWord.exe used to load malicious AppvIsvSubsystems64.dll

Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs

Iran-linked hackers disrupt U.S. critical infrastructure by targeting internet-exposed PLCs.

> Be United States government > Say state-sponsored Iranian Threat Actors targeting PLCs &...

US government warns of Iranian state-sponsored threat actors targeting industrial PLCs.

Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks

Iran-linked hackers disrupt US critical infrastructure via PLC and SCADA attacks.

Feds quash widespread Russia-backed espionage network spanning 18,000 devices

FBI neutralizes Forest Blizzard espionage network compromising 18,000 routers across 120+ countries.

‼️ A threat actor shared a database dump from MHI[.]org containing personal and professional info...

Threat actor leaks database of 33,000+ users from MHI supply chain event website.

‼️🇫🇷 Threat actor NormalLeVrai is selling alleged Service Telecom database containing 2,835,372...

Threat actor NormalLeVrai selling alleged Service Telecom database with 2.8M user records and source code.

Justice Department Conducts Court-Authorized Disruption of DNS Hijacking Network Controlled by a Russian Military Intelligence Unit

DOJ and FBI conduct court-authorized disruption of GRU-controlled DNS hijacking network using compromised TP-Link

DOJ Disrupts Russian Military Intelligence DNS Hijacking Operation Through Court Order https://t...

DOJ disrupts Russian military intelligence DNS hijacking operation via court order.

Storm-1175 Deploys Medusa Ransomware at 'High Velocity'

Microsoft attributes Medusa ransomware deployments to Storm-1175 exploiting N-day and zero-day vulnerabilities.

Iran-Linked Hackers Are Sabotaging US Energy and Water Infrastructure

Iran-linked hackers sabotage US energy and water infrastructure via compromised industrial control devices.

‼️ CVE-2026-23398: Linux Kernel ICMP DoS Vulnerability PoC: https://t.co/qD3Vo8jHAF

CVE-2026-23398 Linux kernel ICMP DoS vulnerability disclosed with public PoC.

Snowflake customers hit in data theft attacks after SaaS integrator breach

Snowflake customers targeted in data theft after SaaS integrator Anodot breached and tokens stolen.

Threat Actor Selling 1.2 Million French FICOBA Banking Leads With IBANs, SSNs, and Tax IDs From 15+ Banks

Threat actor selling 1.2M French FICOBA banking records with IBANs, SSNs, and tax IDs from 15+ banks.

‼️🇫🇷 Threat Actor Selling 1.2 Million French FICOBA Banking Leads With IBANs, SSNs, and Tax IDs...

Threat actor sells 1.2M French banking records with IBANs, SSNs, and tax IDs from 15+ banks.

Anthropic Teams Up With Its Rivals to Keep AI From Hacking Everything

Anthropic launches Project Glasswing consortium with 45+ orgs to test Claude Mythos Preview's cybersecurity

Anthropic Unveils ‘Claude Mythos’ – A Cybersecurity Breakthrough That Could Also Supercharge Attacks

Anthropic unveils Claude Mythos, a frontier AI model that identifies thousands of zero-day vulnerabilities but risks

‼️ The FBI has released a joint Cybersecurity Advisory on Iranian-Affiliated cyber actors exploit...

FBI releases joint advisory on Iranian cyber actors exploiting PLCs in US critical infrastructure.

US warns of Iranian hackers targeting critical infrastructure

US agencies warn of Iranian APT targeting internet-exposed industrial control systems.

Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn

Iranian APT actors breach U.S. energy and water infrastructure OT devices, disrupt PLCs.

Hackers Pose as Non-Profit Developers to Deploy Monero Mining Malware

REF1695 group deploys Monero mining malware via fake non-profit installers since late 2023.

‼️🇨🇴 NyxarGroup and collaborators are allegedly selling personal information from Colombian gov...

NyxarGroup allegedly selling stolen Colombian government personal data online.

‼️🇺🇸 Threat actor McLovin is allegedly selling a database containing 4.6 million Robinhood Gold...

Threat actor McLovin offers 4.6M Robinhood Gold member records for sale.

‼️Threat actor OnarDev is allegedly selling a dataset containing personal information of 2 millio...

Threat actor OnarDev claims to sell dataset of 2M Coinbase users for $500.

‼️🇨🇳 Threat actor McLovin is selling a database containing 810 million Chinese shopping deliver...

Threat actor McLovin selling database of 810M Chinese delivery addresses for $1,000.

Russia Hacked Routers to Steal Microsoft Office Tokens

Russia's GRU-linked Forest Blizzard hacks routers to mass-harvest Microsoft Office authentication tokens from 18,000

Threat Actor Selling Root RCE Shell Access to Botswana Government Health Portal Firewall for $300

Threat actor Florence selling root RCE access to Botswana health portal firewall for $300.

Events