Victims
Last 90 days
Priority Threats
Live Feed Last 24 hours
Data refreshes every 30 minutes.
Active IOC Feed
| IOC Value | Type | Malware / Family | Threat Type | Source | Confidence | First Seen | Ref |
|---|---|---|---|---|---|---|---|
98792483aed3a9e0105cdaca1d5208916c07c45e0c46229e221a753fe3db0d30
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
7766739193c449206ea63751d23551e2057e4de80f6befaeb7a24eaeb63a5ee1
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
a48c84f1ce12eecb900ffee1e4c62338986eb771c873e58799fb4b3c3be7e26c
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
e0e21cf140a749c8b5a192067c7d57bec0ca935c5cfbd600bc4e8f6dbb2416a9
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
8be7bfced22cd1f030164b4017452e249800de10c2507de4d08ee3e5ae0d9f9a
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
e7c01b9abe7afe90a30798009f1b3464c814fba913bf4a825b6b347fdac7d816
|
sha256 | zsh | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
a07994990f1976669d69febbe9603be9e10132fe9f6d6e8e4184fa91462cba72
|
sha256 | zsh | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
55b8fff6b61ed493f477bac718c37714075d4ff52bc302d28a331def371834b6
|
sha256 | zsh | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
7832997e951cdd9c169d25e72141e24d63f342b19f6ad2e1523f5f21a486c9c7
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
9c4849aa813219b40a6c632700770bbf2c9d019084dd7c0d2063bd619532c03d
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
ab1ad6884101f8036290ed63e79dfcf02f5ae524bd51ef0d2f8556750545d620
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
b8138859d89ae85b62d8de8bc316f02a22942a30202710dfc36d4609aea494ef
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
b9f9c58e080f1b5028e8e331fdc0aa5d5c43646d747031615d4645800fe87a02
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
bed116abf922b28f79323cce3901e206e82cb4a37020c623217ff1541baa00f1
|
sha256 | EpsilonStealer | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
8f257396b6c3472702d7562d6e5ac4b869de4039954db5991139ca5ae00de30a
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
daeb35512ea892ed7b7778bf39fdab506cc2a76f805cea64461af00f3b0e08d0
|
sha256 | sh | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
372000921e2e21e61d8db24f7bed1ec2303f96521bc9f34e0b6863e55b068a1a
|
sha256 | RemcosRAT | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
b2160319fae540ffaf74bb7df4bb65dec5a933f28dff90b1d31c7aa7c7099a94
|
sha256 | js | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
051fbc556893b59270e63cbbd2fcb18ca1a8d8c28cb791d6563c408535a55e90
|
sha256 | hta | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
7wlvj9nh.lezo.store
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
https://kb.3toto.com/
|
url | win.vidar | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
kb.3toto.com
|
domain | win.vidar | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
cfcher.biz
|
domain | win.remus | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
cryonex.sbs
|
domain | win.remus | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
apexfd.click
|
domain | win.remus | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
didi31.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
http://185.82.64.55:36105/Mozi.m
|
url | elf.mozi | payload_delivery | ThreatFox | 75% | 2026-10-07 | 🔗 |
sarmo.store
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
b0a61e0d2b769b06c8e83cd7529c6d31ddcf30bd6dae83cae0452f098e069df0
|
sha256_hash | osx.amos | payload | ThreatFox | 100% | 2026-10-07 | 🔗 |
https://kb.3toto.com
|
url | win.vidar | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
137.220.224.26:8151
|
ip:port | unknown_rat | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
3b46300032d8e04013c860c6396c75cc56fc9e0be14661ed31f169ea5b01625d
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
fe421e0f9d3a327222118fa3e3260edb188e82f316e0142e9a11b9e3baf29580
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
ad5771a3b1da632ac3c0bb4d5406159a3632f0642210845a67a861165ee04124
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
e1985973b3d0a1ef0a5f21a2d5b74a23fdf00590fbd67e5337c0837491b49687
|
sha256 | jar | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
264ddd8c76374d0afb64aa0653de0ff137bd014e43eb478eb91f9d63e4ec5d98
|
sha256 | jar | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
05af569c3595b01e0724bc96c989105467952fd22a8681a716cfa22ec070d78c
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
04eae0a7625bd280faee6cee1f09abaf77d278c16f4f4fae3c9cd607efbcb5a0
|
sha256 | zip | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
s1i2nmghh9.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
6111a10b82cc1bf6bac1082bc8ffa36e9f3123f0feb811aac281278a7fe63e13
|
sha256_hash | osx.amos | payload | ThreatFox | 100% | 2026-10-07 | 🔗 |
pegy.store
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
lh5yl7g0.pegy.store
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
b992e0488abed5c19f215626dee38cc4b7b92b918ab194e276924a462aa97c3f
|
sha256 | Gafgyt | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
e68413a6e8f1a9731432f99a56dd262069bfd0677ad84f65f597122485d8ec0e
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
9b464c3a67496d09e178684e24c1f89c12c1e446d0bee0a578c81662c7086f1d
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
aba7d8735a439b392af4fe45b6c79dfd53d4aa5268c4de7567ce354be5fd1625
|
sha256 | Gafgyt | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
62744b6a485f2681eb50748e27062dacd60abd97b01208d2e410224ec0d1eb3f
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
56c17e283d9349a7d46a01f52ee8d4892d69e57cb722e9dab01f771aa2bf6783
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
881ee901314f12755ca9cfeab65005c071af22b82e8f858c7f6afe3495fb3356
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
d59a4194ec66b508697d67d71b69f74f590e8a8bb346507075b3ded56854a374
|
sha256 | Gafgyt | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
f216e53631c9352da6518d03d85626576767173006ba1a050131c484da8c8f89
|
sha256 | Gafgyt | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
e229edc9525e9eb4e91ab716c3a538e9daa7c2836a3d30d2df9207de30dc0b2f
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
460ffbba190cf2031a2b5dc79447e6fcad68aec4ab81d64124fe383a0a44d528
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
0dd0ce10dee746bf03abd32e0a926d97a2b60f5cd130a8f5296bdb7fe906ff02
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
c309ae39a98e755268b4d2edb4ba218d18dd5354d355869001348027346a14db
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
bd065fb5504cd702dba8d6216d836617021e25be3002dc0bc8db43402ba7af55
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
http://165.98.243.83:55771/bin.sh
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://60.18.58.38:34608/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://216.9.224.45/30/img_224029.png
|
url | rat, RemcosRAT, stego | malware_download | URLhaus | — | 2026-10-07 | |
http://216.9.224.45/30/greenangelkings.js
|
url | ascii, js, rat, RemcosRAT | malware_download | URLhaus | — | 2026-10-07 | |
https://95.182.97.240
|
url | win.vidar | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
103.83.86.40:14642
|
ip:port | win.remcos | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
74d5e7f3a96997a43b3b771cd54fb94b7012bf5cb4c95f4d2b8e49f209da79cb
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
f745c2d897ad6f16cb5c0428ba74a7f041f7c3e94f52cc3727532577fe12507d
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
4aaa75e2aad67af0280ae01d0b600ebd37bbbf5fc1b53cf1307f9e1c7caa0723
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
9f04d8622216750884fe7779ea833b37f1c1670a88dc88041a5cbf695bc2dd31
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
4b44ef2691ef88525056c828898d8c16609b36339406bc26ad51ad1f3256773f
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
ec31ce202f7c50e15d3991be5739792ca44a2e49828b45f41a70cad9e77f9429
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
5003d4cf1849fc207f3023b7220800f998cc34ec416ca3525f2707711258b98a
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
6980031c9f60b74691308715d5fa94fe6265c86d6b2c9b9f41004f41c618dbe8
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
00beaa403e9b2c5087f4d366d3b49a2066075de0378ae3dfbeff9e722c6b94a7
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
http://182.114.195.5:54356/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://105.224.5.39:39999/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://115.50.235.154:51244/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://58.47.106.128:39278/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://115.55.194.104:34014/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://175.43.173.18:38071/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
49f19199c38499498aa4dead3e19102c6679192fe282e72ec024b19191d8ae63
|
sha256_hash | osx.amos | payload | ThreatFox | 100% | 2026-10-07 | 🔗 |
cb2ed2ece12a675e19f2b537840a2b5d8bcdd1d508ec5c386178e60161d2cfe8
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
b2bbdeb48f60e591d78ddc98fffc9504128e9b948fd58a54c2cfa927ff9db105
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
218ab4cb7bf3622b4b8d5fa9196d817b91046e1eca84c26091f3f703ab214707
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
91860b4d03b32a4ca6e8e92856272d953999934e6316f65677a615cbfb8d31d0
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
c55f5339abaf48b9392df67d5b6f6e011d878d7ee848724ad5dbe8c4d898ef23
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
7c9312ebe2afc299a0835a32700cdd2c5099c228799414c48058c0fb6095df9b
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
01c3d2a947c56e16718f1f54c0820996dce1d44da25d38b2a9992eb16e6b11e6
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
f6683adcb8a152d31ef1132ee3f4cb818dcf0b5e361f991286f9fb5d2d747afd
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
7606a3b69488795fe2d71558caab7877ea313425e55a63aebb932d0d92b38aee
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
32addf18477324f478bf93ac22be65550bc71450c9bc4fe49aa3be22219aae65
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
0956ec57c3ddcd24c4d61bd6a4dd16b5f1468f701a286e46b761f5be4fc478ac
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
b10d8bb537ab05e51f08d0b942ee9f92f3226d118fcac794d1a7396bbc0b531f
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
a0c291e8942c8c7fecccff3fbdb65f65c76312d384a73d3748042a319209c91c
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
c073f5c684eafc2b0b0c6dedbf6aaa0148f5d1e6f5cd4b1090a88991a22c89bf
|
sha256 | LummaStealer | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
9d26575b6bdd470c877adc65bab7469beb2c69dcfff7923b07b64a398df7ebe2
|
sha256 | RemcosRAT | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
44c2f46e91c4b65b6f0c8385910af36a4255bba0fdd7bfccf2199e7a9faf19f7
|
sha256 | AgentTesla | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
92a0e46d71aa833ac83ab35b5d05d05731a3ffef45eb2dc76317c0459c3202cb
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
873144883b9cb2baa3750b087e537d3032e4cd1ad32fd874ac82d83f3063d14f
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
93cfdba6fd3e0b43281f2370c711db7ebaca3e30eb86a5a0f27511dab511baa5
|
sha256 | hta | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
b688a637e19dfe70afb09112ab76bcbcae14f8d642e0148437b7c56644b34234
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
d58ed4e7cf9ab3181cb59e18050cd9d4c41b334f0f07be08abe5bafed5c04069
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
c5f3b103955567ed345bc49d5cb738f1c87e97ace12386b88f5395c782334916
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
775f9ff2d3638bebe23f14dc3ad99385f0fbd9186322c6309b27f0104c22aa6e
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
5c986020e2e9b52e7e6a3074aa8aa4729ccbf00f02208df7af17827403f15127
|
sha256 | xlsm | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
5e50ea2a22ff544d4d72c1a32ad788f88b9f604ce82eca0283834601b329c40c
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
0bb6f0b17e0ade6c25f86ba1fe6734786449474cab6b36ee4b7727d82e3023af
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
720567958c56875f70b067799a6ff45b6d15cc9a3600b99d5105e21992cfa8a0
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
89aad9f5cee8dabb4b6ae728d320511620df1e51e9fb5d783f603147e4a27e44
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
ff6379a044085e27758b1718515b16869a1bba31bb5e31b989aeaf07178fe87a
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
6d63cc39115b117bf2d00c08455fadcea77fe1ef69bcb67e22d70ab24adc1b36
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
7c52a593a17a0815b2480c451004d938953619bd5d9c4fb9716ee7980fda04fc
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
45a4537b811cbd3fa15fa0b0bd62c3b85c000cfb31e31e6ed4cc4ce03c8e6d2c
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
d5d4a0b2b8ea92c1884285498006925db911881fc0d2394e43a65db9e140f8db
|
sha256 | RemcosRAT | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
76493cb717bb63f3895091b6a14835a0db3cb3deb466f1b490a9ce8615e6726f
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
6bb01878ea61187c9810aba9c0c0e1a0003d5071a89fdddb46ad0348e5f3ee05
|
sha256 | dmg | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
18408a1f39f77f495a3db850710a02eea3602072314b9926c927701f7392547a
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
5e12652a8ec1f762d214c89e234524b2a10fb6daeccd7956fcde23d1be185e20
|
sha256 | dmg | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
http://112.248.113.232:40583/bin.sh
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://103.179.240.227:51700/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://196.189.69.192:38461/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://222.139.36.194:60541/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://27.215.181.136:32832/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://37.52.180.238:34777/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://116.139.99.176:37688/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://27.44.145.227:53273/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://112.248.141.165:35888/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://36.88.136.194:59849/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://27.44.145.227:53273/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://115.63.144.176:53052/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://120.28.193.113:37131/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://182.114.195.5:54356/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://119.179.237.222:49476/bin.sh
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://115.63.49.201:46360/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://171.81.95.244:56237/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://123.11.234.79:52081/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://39.87.126.131:54912/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://115.63.78.29:58952/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://95.15.69.204:43425/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://37.52.180.238:34777/bin.sh
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://112.248.113.232:40583/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://175.165.82.32:36258/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://175.165.81.126:43423/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://116.139.99.176:37688/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://27.220.213.206:38698/bin.sh
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://222.246.108.59:44574/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://210.208.110.51:35100/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://113.238.229.213:41846/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://5.26.131.236:50166/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://182.121.179.96:54068/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://120.84.215.208:45931/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://61.53.72.71:41384/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://219.157.176.43:34554/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://42.227.133.167:51698/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://123.11.234.79:52081/bin.sh
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://221.14.86.235:35190/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://222.134.173.157:38282/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://116.55.2.151:49708/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://221.15.179.180:34467/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://196.191.104.3:53425/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://112.248.141.165:35888/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://59.180.159.171:39541/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
134.122.22.105:8080
|
ip:port | elf.aisuru | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
pifamo.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
ip-regions-check.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 50% | 2026-10-07 | 🔗 |
saok.store
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
https://api.mocki.io/v2/y0p8kvoe/tracks/errors/617333
|
url | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
https://api.jsonsilo.com/public/0d332804-985c-4fc9-bcb4-d6089c3eace3
|
url | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
https://api.jsonsilo.com/public/e824e225-294e-42ed-89bd-f09968f67c19
|
url | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
https://api.npoint.io/a6381e60910f3f2d4310
|
url | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
https://api.npoint.io/ce81d14aa4018a8e7bb9
|
url | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
https://www.jsonkeeper.com/b/AOCLV
|
url | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
https://jsonkeeper.com/b/IC6KZ
|
url | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
https://jsonkeeper.com/b/FDHU7
|
url | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
justily.duckdns.org
|
domain | win.remcos | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
cryptifyhub.cloud
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
gd.tracelic.com
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
serve-cookie.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
y-lilac-sigma.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
ip-ap-check.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
ip-api-test.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
auth-den-tdu.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
auth-confirm-eight.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
auth-confirm-two.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
ipcheck-six.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
iron.blacklabelfremont.com
|
domain | js.clearfake | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
mesepahe.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
31.59.137.81:4565
|
ip:port | win.remcos | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
vscode-settings-config-md.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
vscode-production-setting.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
vscode-helper171.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
vscode-helper171-ruby.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
vscode-extension-260120.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
vscode-ext-git.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
vscode-config.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
vscode-config-settings.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
vscode-config-setting.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
vscode-bootstrapper.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
valid-dep.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
thopywork.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
tailwind-version-4.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
ext-checkedin.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
coreviewer.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
260120.vercel.app
|
domain | js.contagious_drop | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
https://fo.3toto.com
|
url | win.vidar | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
https://kb.333vip.org/
|
url | win.vidar | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
kb.333vip.org
|
domain | win.vidar | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
15.204.253.8:5621
|
ip:port | win.remus | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
91.92.41.66:56003
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
52.246.183.133:443
|
ip:port | win.havoc | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
46.246.6.8:5500
|
ip:port | win.dcrat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
46.246.12.6:7049
|
ip:port | win.asyncrat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
23.92.20.189:8315
|
ip:port | win.chaos | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
217.60.195.46:6767
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
216.227.218.4:8848
|
ip:port | win.dcrat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
202.95.14.80:444
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
202.95.14.80:442
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
202.95.14.65:442
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
202.95.14.49:444
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
202.95.14.49:442
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
202.146.222.156:56003
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
192.253.229.23:56003
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
192.162.199.186:8808
|
ip:port | win.asyncrat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
172.94.46.114:3030
|
ip:port | win.asyncrat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
171.111.194.207:9443
|
ip:port | unknown | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
161.35.58.0:443
|
ip:port | win.poshc2 | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
152.53.22.243:7443
|
ip:port | unknown | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
150.241.226.177:56003
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
150.241.226.177:56002
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
150.241.226.177:56001
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
144.79.249.51:4444
|
ip:port | win.asyncrat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
143.246.223.145:56003
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
136.0.82.204:443
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
128.90.102.158:7000
|
ip:port | win.dcrat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
103.57.250.246:9015
|
ip:port | win.dcrat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
103.195.103.132:443
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
137.220.157.238:443
|
ip:port | win.valley_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
137.220.157.238:449
|
ip:port | win.valley_rat | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
gicalu.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
https://checkyoubrowse.codes
|
url | unknown | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
88c6129b8ce9772b537259f5ecc4cad276b5d156eb475c5a681bad4a9e0ebf3c
|
sha256_hash | osx.amos | payload | ThreatFox | 100% | 2026-10-07 | 🔗 |
checkyoubrowse.codes
|
domain | js.iclickfix | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
z4e0sn7r.keca.store
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
1b2691d894ade206276371da19469c523801cd38e3d37aafec92582054cad03b
|
sha256_hash | osx.amos | payload | ThreatFox | 100% | 2026-10-07 | 🔗 |
46.101.164.65:8080
|
ip:port | elf.aisuru | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
68.183.194.156:443
|
ip:port | elf.jackskid | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
38.60.136.140:443
|
ip:port | elf.jackskid | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
206.189.138.167:443
|
ip:port | elf.jackskid | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
143.198.181.155:443
|
ip:port | elf.jackskid | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
139.59.68.122:443
|
ip:port | elf.jackskid | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
138.68.60.252:443
|
ip:port | elf.jackskid | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
130.94.32.14:443
|
ip:port | elf.jackskid | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
130.94.1.105:443
|
ip:port | elf.jackskid | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.43:23789
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
fvucv35060.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
lopule.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
salgu.store
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
patch.cobaltwave.cc
|
domain | win.acr_stealer | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
vozelifu.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
02afacab8fe2e07c68d28c74d94b1b0ad4e99d84bbf855f66f8f2a08247f52f3
|
sha256 | sh | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
d2499f96b51962eb63c4042484ae7217fa163c14a6ce654623b7350d9e8d8772
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
dea85089030a92d577c718baeb2259e3b8e16f6fcd292cf9c2bf443be1acb0e4
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
eae590b688d927d4a3fddc4dc0758b4596605d77d896b142dd127b24827f492c
|
sha256 | sh | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
c47a7de9dbdd7c3da3b8ac282411ea5f3bc5c9200457a28460b5e8433341c278
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
113311a3187220e3a08cd43daf1091d9f17afea9bbf8201e9beaa9dd8242b89f
|
sha256 | bat | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
http://103.179.240.227:51700/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://125.161.1.232:58379/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://182.113.6.188:55101/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://180.191.40.108:37202/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://115.63.51.182:33921/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
58d838576a8a6d039b164558c6ae85f4ec025431a5181be762fa5a4000c1ac3c
|
sha256_hash | osx.amos | payload | ThreatFox | 100% | 2026-10-07 | 🔗 |
cc01cuty.lasal.store
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
31.56.19.72:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
31.56.19.73:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
31.56.19.74:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
31.56.19.75:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.43:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
dc9c3010ec7b866c519d1662f4de35050a2ca79aa980f0ed2cb21f1dfbe4a3f3
|
sha256 | dll | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
991420cea0dd980cc2fb67902582ab5112a58cb68fe619988300ae3eb8dacac5
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
f825c06b278627ab9753ccdeffd510a32f6bc706845931906597d1f8d978913d
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
266e23131130d4ba812d34bf50e58a977c7edb636f1c0baaa9d36716af3850db
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
ea20b155db519c9db57ecc550a435502176919eae7b522aec8e3b9953c1f3e2a
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
bc00d5734e0fe9757837942695a402ac54ed8e6d365b98688dcbb96ccc2cf2ac
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
78320426dcada84ef0b64282174d95c7320beaff7ae777c7340608db5168fceb
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
2ab64c8f758a30c93961e7481b0d889559a50ffef46d273bb4fc1e1d27997975
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
9f87b67f006dc374a45117b11046f8fd9c22ee53e83192db2d668175649239c3
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
dfe46ef90c4c4093466ef4aacbefe911cef37492c57c41e186bed298a03cebfd
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
3c2a1011adf709b320cbe399f8bb1043513059b2b22698ab1a43eb87f50401bc
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
9262713395e980851638ce2f5bac67be989449f82d76e25d0ef42fa8e59c0863
|
sha256 | XWorm | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
http://23.254.195.48:8099/bx_amd64.p
|
url | docker, elf | malware_download | URLhaus | — | 2026-10-07 | |
http://41.216.227.66:51974/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://180.245.56.243:55104/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://45.172.218.181:45893/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://114.227.65.175:51491/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://175.165.87.230:44570/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://112.248.101.66:55265/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://119.179.237.222:49476/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://114.227.65.175:51491/bin.sh
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://180.245.56.243:55104/bin.sh
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://14.221.238.62:59076/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://175.165.87.230:44570/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://123.12.20.207:47682/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://196.189.96.59:60551/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://123.12.20.207:47682/bin.sh
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://182.124.121.111:40805/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://27.220.213.206:38698/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://222.138.151.54:55365/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://125.40.158.189:39181/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://61.53.83.129:58022/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://196.191.233.24:43597/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-06 | |
47.238.5.232:443
|
ip:port | win.valley_rat | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
8.140.223.56:8085
|
ip:port | win.vshell | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
38.55.252.139:8000
|
ip:port | unknown | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
192.162.199.218:2222
|
ip:port | win.quasar_rat | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
31.56.19.70:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
46008dea9a887efbd282cbf47f551c54ef59d91ba27b237b804bb24bf0a21446
|
sha256 | docx | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
6827bf18a9ea98199f9195592c4d90c0a2bd7dc165f3faa1546f25764aef50e2
|
sha256 | js | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
a21be069523269d370e173e5560617c4960e9cabfa03de22bd8fcae2c08e9e40
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
1e8a56fd9ff38fdd6b66aebaa33ab14b70b6ab9198cc96359c927f0303b04798
|
sha256 | vbs | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
1f0babd6b021b89f6edf52d77b06a7d20dc28feefb0e140b2304a0f46c93508d
|
sha256 | wsf | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
340e7896c5a7bef1fc5ed45751f002e4a13e1d23ad2cfcf2d4b27887d8c54c86
|
sha256 | js | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
d2bd32d598b4d9febebc2b26d0bfa6ff2d7e06282530dc7f9d348688089f33c2
|
sha256 | Prometei | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
14a4b75f7c9504dbfedf27b2a0f7371eae784e0a470f909a5f5f04b126c14db1
|
sha256 | vbs | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
3f0e6ea04ec9c014c65d3c33fe92dbba71935eba02fd8b36a5232aaf7c74cbb4
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
auyqv86340.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
ealiy01j.kaarenorge.com
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
nupxi88339.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
89.32.41.19:42061
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.59:15987
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.108:27651
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.109:42061
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.114:15987
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.117:27651
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.128:27651
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
2d439ae8d04b35e424c39632d77c9ceb096a1c0f935d07aea9fbfab18b67c151
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
a9a97675dd4fd2cad9b66f31c0bb3cf177cfbe40f29a664abce74b11da645984
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
19faee0d47e5ba75566c00afc5e6e64a29744ca6f366c32c0d22acd147773e00
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
http://42.227.46.64:39218/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://27.210.7.195:44939/bin.sh
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/Baritone-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/FerriteCore-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
http://175.165.82.246:53655/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://175.147.200.123:48168/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://138.204.196.254:47936/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://115.50.216.143:39292/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://37.26.86.216:38777/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://105.224.249.40:57651/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://125.40.158.189:39181/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://182.114.34.128:51716/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://221.202.234.182:37616/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://42.86.117.7:34873/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://37.26.86.216:38777/bin.sh
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://202.1.26.13:44204/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://59.97.252.95:51706/bin.sh
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://113.221.14.251:35903/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://175.147.94.199:51805/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://60.16.135.182:50504/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://119.187.197.115:57303/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://123.9.200.156:42154/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://95.9.35.137:40441/i
|
url | 32-bit, arm, elf, mirai, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/TotemCounter-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
http://115.62.186.251:52572/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://154.242.13.34:43259/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://115.55.229.99:46995/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://185.89.156.101:35112/bin.sh
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
https://www.dropbox.com/scl/fi/jnf0ecydm1z63frnge1mn/Docsend.exe?rlkey=01seodht5j6nnix645ejn3a5r&st=vcdaxsj2&dl=1
|
url | IRAHook, rat, stealer | malware_download | URLhaus | — | 2026-10-07 | |
https://www.dropbox.com/scl/fi/dcbo57pem0pjqzx65giot/MateFalls-Setup-1.0.0.exe?rlkey=yc7kc4vm6iy1urr0wh1xwta91&dl=1
|
url | Dropbox, java, MateFalls, stealer, infostealer | malware_download | URLhaus | — | 2026-10-07 | |
https://www.dropbox.com/scl/fi/jwhb6vojim0cfxrxip9fk/Docsend.exe?rlkey=zgpwwjbtsrnatafb9g24pjnxu&st=gwds3ryx&dl=1
|
url | Dropbox, IRAHook, rat | malware_download | URLhaus | — | 2026-10-07 | |
https://stellaspicy.org/2026scrill/client.jar
|
url | runelure | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/alycone-client-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/Shulker_Box_Tooltip-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/radium-client-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/krypton-client-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://stellaspicy.org/2026scrill/RuneLite.exe
|
url | runelure | malware_download | URLhaus | — | 2026-10-07 | |
https://donutdupe.com/DonutDupe-26.2.jar
|
url | jar, java, stealer | malware_download | URLhaus | — | 2026-10-07 | |
http://23.254.195.48:8099/beacon_x
|
url | docker, elf | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/gamble-rig-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/Radon-Client-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/glazed-client-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/Nova-Client-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
http://123.12.245.227:36522/bin.sh
|
url | cowrie, elf, honeypot, mips, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/meteor-client-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/Mouse_Tweaks-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/donutExtras-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/freelook-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/Iris-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/appleskin-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/bamboo-client-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/Litematica-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/ZincAddons-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/Sodium-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/NuclearAddons-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutdupe.com/DonutDupe-1.21.11.jar
|
url | jar, java, stealer | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/Lithium-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/donut-duper-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://ikovrsps.com/gamefiles/image.exe
|
url | runelite, runelure, stealer | malware_download | URLhaus | — | 2026-10-07 | |
https://docs.cs-supplements.de/api/cm-token
|
url | ClickFix, DEU, exe, FileFix, Loader, powershell | malware_download | URLhaus | — | 2026-10-07 | |
https://github.com/zav001/534rkyoj34oiy/releases/download/T/DonutClient-1.21.11.jar
|
url | SilentNet | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/TierTagger-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/Xaeros_Minimap-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/Zoomify-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/ExploitPreventer-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://ikovrsps.com/Mina.jar
|
url | CoinMiner, runelite, runelure, stealer | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/WorldEdit-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
http://144.31.150.183/5r3fqt67ew531has4231.arm
|
url | elf, iot, mirai | malware_download | URLhaus | — | 2026-10-07 | |
https://github.com/zav001/D3et2t23y3/releases/download/v1/GoobaaClient.1.21.11.jar
|
url | SilentNet | malware_download | URLhaus | — | 2026-10-07 | |
https://donutclients.st/bnana-client-26.2.jar
|
url | jar, java, stealer, vm | malware_download | URLhaus | — | 2026-10-07 | |
https://cdn.discordapp.com/attachments/1521843051192909974/1557082337735475301/bundle.zip?ex=6ac6816e&is=6ac52fee&hm=50797e9782aac04b40538d9ee9d26c6295597c9db1eb374572ffddf733d329bd&
|
url | IRAHook | malware_download | URLhaus | — | 2026-10-07 | |
http://123.9.200.156:42154/bin.sh
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://117.146.92.46:54853/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://120.28.194.92:51526/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://221.15.187.244:35517/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://182.118.189.126:40792/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://123.14.88.160:36914/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://221.15.187.244:35517/bin.sh
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://210.97.100.192:33082/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://117.146.92.46:54853/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://42.224.98.161:41233/bin.sh
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://125.161.250.191:33986/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://120.28.194.92:51526/bin.sh
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://61.137.200.25:38220/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://60.18.37.74:39377/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://60.18.37.74:39377/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://120.28.192.219:39732/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://42.239.238.224:40215/bin.sh
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://175.173.2.43:32996/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://222.141.105.180:56903/bin.sh
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://222.127.71.33:40089/bin.sh
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://194.26.220.214:34097/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://60.23.238.68:48081/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://105.224.12.172:32809/i
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://39.77.172.19:45028/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://123.11.98.224:37931/bin.sh
|
url | mirai | malware_download | URLhaus | — | 2026-10-07 | |
http://42.238.246.42:35356/i
|
url | Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://176.213.86.238:31654/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://60.23.235.155:58165/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
sadis.store
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
9d9a2f7efc1c1254af10c9f16dad65235da5b4746ec6d1a4438d11d34a113027
|
sha256_hash | osx.amos | payload | ThreatFox | 100% | 2026-10-07 | 🔗 |
http://190.196.253.50:10591/Mozi.m
|
url | elf.mozi | payload_delivery | ThreatFox | 75% | 2026-10-07 | 🔗 |
http://39.34.169.100:35517/Mozi.m
|
url | elf.mozi | payload_delivery | ThreatFox | 75% | 2026-10-07 | 🔗 |
45.95.232.146:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
154.12.17.20:8080
|
ip:port | win.cobalt_strike | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
217.60.103.15:8808
|
ip:port | win.asyncrat | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
https://172.234.110.213
|
url | win.vidar | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
dapypu.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
tofexy.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
204.44.93.119:7878
|
ip:port | win.remcos | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
ruut.store
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
154.12.17.20:22
|
ip:port | win.cobalt_strike | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
154.12.17.20:443
|
ip:port | win.cobalt_strike | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
154.12.17.20:80
|
ip:port | win.cobalt_strike | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
38.55.252.139:6689
|
ip:port | unknown | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
https://fo.333vip.org
|
url | win.vidar | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
gogymowy.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
fog.blacklabelfremont.com
|
domain | js.clearfake | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
129.204.55.230:443
|
ip:port | win.cobalt_strike | botnet_cc | ThreatFox | 75% | 2026-10-07 | 🔗 |
kpxypqg0.kalem.store
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.111:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.114:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.117:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.128:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.146:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.108:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.109:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
194.116.236.83:15800
|
ip:port | win.remcos | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
46.246.14.21:5987
|
ip:port | win.remcos | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
www.therapie-zentrum-dortmund.de
|
domain | js.clearfake | payload_delivery | ThreatFox | 90% | 2026-10-07 | 🔗 |
89.32.41.19:38429
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
45.79.198.116:443
|
ip:port | win.havoc | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
94.143.143.253:8090
|
ip:port | win.dcrat | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
120.26.49.92:5432
|
ip:port | win.vshell | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
89.32.41.59:7193
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
2ell0jzk.lacek.store
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
xoqypeka.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
b85d4673ac19ee208e96eff1e860d4b110a1eac0620464193bde12a85fb54115
|
sha256 | js | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
eff4b583d6a3e0743b7ad853a8227cc04b83eb4d855cac31bdef4fb0185326a9
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
http://123.130.203.216:45701/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://117.253.155.54:60752/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://60.23.239.66:35293/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://60.23.238.68:48081/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://91.190.84.93:58846/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://103.68.95.197:55385/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
mywolexe.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-10-07 | 🔗 |
http://42.234.233.75:40282/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://27.44.145.183:32947/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
89.32.41.19:27651
|
ip:port | elf.potassium | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
23f6b48ec53b6490d06722b49a54aaaf855f63c15bde3c32cb90db432d8fcb96
|
sha256_hash | osx.amos | payload | ThreatFox | 100% | 2026-10-07 | 🔗 |
cashin24.ca
|
domain | js.clearfake | payload_delivery | ThreatFox | 90% | 2026-10-07 | 🔗 |
187089dffb448a9fc3d858e1d539ea70ba06a706d2b63dd44afc89d2ef1d2f8a
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
a36fbc117b0582e076f28cb9c81680c61f45a2ab9eac0f99ddb75a59537aab7a
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
7ffa8ceaba695ecb58868eac30c83433b87854f8ef6ba6d97938bbd462d486a9
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
8b3b5fcac17c2be4accd5c596d8b51184f39e6cf65ebcac939d02041cedf502e
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
77a8d1bcbc9c79e76e64b5fd50aeda23d4d9a0ca42299f0f7a72f8da032fcc54
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-10-07 | 🔗 |
http://39.79.138.192:39415/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://115.55.223.110:54371/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://182.126.177.210:60965/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://91.190.84.93:58846/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://170.84.133.234:32955/bin.sh
|
url | 32-bit, arm, elf, Mozi | malware_download | URLhaus | — | 2026-10-07 | |
http://165.98.243.83:55771/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://123.148.143.61:43201/bin.sh
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
http://115.50.235.154:51244/i
|
url | — | malware_download | URLhaus | — | 2026-10-07 | |
rihan.store
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-10-07 | 🔗 |
103.254.61.170:3889
|
ip:port | win.remcos | botnet_cc | ThreatFox | 100% | 2026-10-07 | 🔗 |
Analyst Tools
Paste raw text — emails, reports, logs — to automatically extract and classify all IOCs.
| IOC Value | Type | Defanged | Actions |
|---|
Enter any IOC — type is auto-detected and a curated set of intel sources appears.
Decode common obfuscation schemes found in malware, phishing kits, and threat reports.
Convert IOCs between defanged (report-safe) and live formats. Handles hxxp, [.], and [://] notations.
Convert timestamps between Unix epoch, UTC, and local time. Paste any format into any field.
Paste raw email headers to extract the sending chain, authentication results (SPF / DKIM / DMARC), originating IPs, and timing data.
Threat Intelligence News
The Hacker News
- Oct 7The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow
- Oct 7FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
- Oct 7Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
- Oct 7What Is Agentic Pentesting? What It Proves, and Where It Stops.
- Oct 7Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
Dark Reading
- Oct 6ClickFix Attacks Evolve to Better Hide Malicious Payloads
- Oct 6Critical Healthcare Systems Aren't Quantum-Ready
- Oct 6Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps
- Oct 6IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams
- Oct 6'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates
The Record
- Oct 6Alleged ATM malware creator appears in Nebraska court after arrestMalware
- Oct 6South Korean officials believe AI agents were used to hack several banks
- Oct 6Osaka Metropolitan University cancels classes after suspected ransomware attackRansomware
- Oct 6ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware Malware
- Oct 6Shares in British clothing company ASOS dive after hackers apparently send push notification
CISA Alerts
- Oct 6Hitachi Energy RTU500
- Oct 6Savannah lwIP SMTP client
- Oct 6Hitachi Energy SOI
- Oct 6Johnson Controls EasyIO FG
- Oct 6Hitachi Energy Asset Suite
SANS Internet Storm Center
- Oct 7ISC Stormcast For Wednesday, October 7th, 2026 https://isc.sans.edu/podcastdetail/10126, (Wed, Oct 7th)
- Oct 6ISC Stormcast For Tuesday, October 6th, 2026 https://isc.sans.edu/podcastdetail/10124, (Tue, Oct 6th)
- Oct 6More RMM Tools In the Wild, (Tue, Oct 6th)
- Oct 5ISC Stormcast For Monday, October 5th, 2026 https://isc.sans.edu/podcastdetail/10122, (Mon, Oct 5th)
- Oct 5TTY Logs and the Data it Captures, (Sun, Oct 4th)APT
Malwarebytes Labs
- Oct 7AI-powered phishkit arms criminals with account-hijacking tools in 10 minutes
- Oct 7Update Chrome and ChromeOS to fix critical security issues
- Oct 7Another ShinyHunters suspect arrested
- Oct 6ASOS “hackers” send push notifications to customers
- Oct 6Facebook Marketplace scam uses your name and number
Infosecurity Magazine
- Oct 7Telegram Account Behind ASOS Rogue Notification Tied to Gaming Trading
- Oct 7Half of Cybersecurity Pros Still Rely on Passwords Despite Security Concerns
- Oct 7Pwn2Own Hackers Find 32 Zero-Day Vulnerabilities on Day OneVulnerability
- Oct 7Danish CPR Breach Highlights Challenge of Supply Chain RiskSupply Chain
- Oct 6ClickFix Attack Hides VBScript Payload in Browser Cache
Ransomware activity
| Victim Name | Ransom Group | Industry / Sector | Country | Date Discovered |
|---|---|---|---|---|
|
SANAtech Global Solutions
|
UmBra | Technology | Unknown | 2026-10-07 |
|
Raqib
|
UmBra | Technology | Unknown | 2026-10-07 |
|
Tharisa
|
UmBra | Manufacturing | ZA | 2026-10-07 |
|
Chibitek
|
N0n | Technology | US | 2026-10-07 |
|
acmestamping.com
|
incransom | Manufacturing | US | 2026-10-07 |
|
harborpacific.com
|
incransom | Transportation | US | 2026-10-07 |
|
architekt-vondanwitz.de
|
incransom | Professional Services | DE | 2026-10-07 |
|
Aon
|
termite | Professional Services | US | 2026-10-07 |
|
EPTISA
|
qilin | Professional Services | ES | 2026-10-07 |
|
Andersen Group
|
SilentRansomGroup | Professional Services | Unknown | 2026-10-06 |
|
EDFelectronics
|
Panzer | Manufacturing | Unknown | 2026-10-06 |
|
Beni Suef Technological University – BTU
|
UmBra | Education | EG | 2026-10-06 |
|
KOOKABARRA JUICE
|
Vexy Ransomware | Retail & E-Commerce | AU | 2026-10-06 |
|
BNYH
|
qilin | Financial Services | Unknown | 2026-10-06 |
|
Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi
|
qilin | Manufacturing | TR | 2026-10-06 |
|
SweetRush
|
Panzer | Professional Services | US | 2026-10-06 |
|
magnals.com
|
incransom | Other | US | 2026-10-06 |
|
Greggio Argento
|
Deadlock | Agriculture and Food Production | IT | 2026-10-06 |
|
Agri Industrial
|
everest | Agriculture and Food Production | Unknown | 2026-10-06 |
|
B-accountants
|
everest | Professional Services | NL | 2026-10-06 |
|
Morcon Developments
|
everest | Other | Unknown | 2026-10-06 |
|
Kennametal
|
everest | Manufacturing | US | 2026-10-06 |
|
Flydubai
|
everest | Transportation | AE | 2026-10-06 |
|
Four Hands LLC
|
UmBra | Other | US | 2026-10-06 |
|
Michael K Shelby, CPA
|
akira | Professional Services | Unknown | 2026-10-06 |
|
Hygrade
|
akira | Agriculture and Food Production | US | 2026-10-06 |
|
CORBY ROCK MILL
|
qilin | Manufacturing | IE | 2026-10-06 |
|
Delta Marine
|
qilin | Transportation | FI | 2026-10-06 |
|
J&D Financial
|
qilin | Financial Services | Unknown | 2026-10-06 |
|
Philander Smith University
|
EndZone | Education | US | 2026-10-06 |
|
A...n
|
SilentRansomGroup | General | Unknown | 2026-10-05 |
|
A...n
|
SilentRansomGroup | General | Unknown | 2026-10-05 |
|
M** A******* G********** O******* a** P***** S****** A*********
|
netrunner | General | US | 2026-10-05 |
|
M** A******* G********** O******* a** P***** S****** A*********
|
netrunner | General | US | 2026-10-05 |
|
Global Security Concepts
|
qilin | Professional Services | US | 2026-10-05 |
|
Medical Data Rx
CRITICAL SECTOR
|
VYPR | Healthcare | US | 2026-10-05 |
|
Medical Data Rx
CRITICAL SECTOR
|
VYPR | Healthcare | US | 2026-10-05 |
|
Agio International
|
VYPR | Financial Services | US | 2026-10-05 |
|
Agio International
|
VYPR | Financial Services | US | 2026-10-05 |
|
Sims Vibration Laboratory
|
VYPR | Manufacturing | US | 2026-10-05 |
|
Circulating Air
|
VYPR | Manufacturing | US | 2026-10-05 |
|
Circulating Air
|
VYPR | Manufacturing | US | 2026-10-05 |
|
Gen3
|
VYPR | Other | US | 2026-10-05 |
|
JPS Health Network
CRITICAL SECTOR
|
VYPR | Healthcare | US | 2026-10-05 |
|
JPS Health Network
CRITICAL SECTOR
|
VYPR | Healthcare | US | 2026-10-05 |
|
Champaign Unit 4 School District
|
VYPR | Education | US | 2026-10-05 |
|
Champaign Unit 4 School District
|
VYPR | Education | US | 2026-10-05 |
|
Praxis EMR
CRITICAL SECTOR
|
insomnia | Healthcare | US | 2026-10-05 |
|
Praxis EMR
CRITICAL SECTOR
|
insomnia | Healthcare | US | 2026-10-05 |
|
Standpointe / Trinite Solutions
|
BYOD | Professional Services | Unknown | 2026-10-05 |
|
dd-automation.ch
|
safepay | Technology | CZ | 2026-10-05 |
|
stuecheli.ch
|
safepay | Retail & E-Commerce | CH | 2026-10-05 |
|
stuecheli.ch
|
safepay | Retail & E-Commerce | CH | 2026-10-05 |
|
bwi-bau.de
|
safepay | Professional Services | DE | 2026-10-05 |
|
halservice.it
|
safepay | Professional Services | IT | 2026-10-05 |
|
grundens.com
|
safepay | Retail & E-Commerce | US | 2026-10-05 |
|
grundens.com
|
safepay | Retail & E-Commerce | US | 2026-10-05 |
|
t-systems.com
|
safepay | Technology | DE | 2026-10-05 |
|
R***e Pa******
|
nightspire | Professional Services | Unknown | 2026-10-05 |
|
R***e Pa******
|
nightspire | Professional Services | Unknown | 2026-10-05 |
|
Nelson Mullins Riley & Scarborough
|
SilentRansomGroup | Professional Services | US | 2026-10-05 |
|
Nelson Mullins Riley & Scarborough
|
SilentRansomGroup | Professional Services | US | 2026-10-05 |
|
Sheppard, Mullin, Richter & Hampton
|
SilentRansomGroup | Professional Services | US | 2026-10-05 |
|
Sheppard, Mullin, Richter & Hampton
|
SilentRansomGroup | Professional Services | US | 2026-10-05 |
|
Turn5
|
Global Secret Group | Other | US | 2026-10-05 |
|
Turn5
|
Global Secret Group | Other | US | 2026-10-05 |
|
anwo.cl
|
safepay | General | CL | 2026-10-05 |
|
duhaas.sk
|
safepay | Other | SK | 2026-10-05 |
|
duhaas.sk
|
safepay | Other | SK | 2026-10-05 |
|
ikhasas.com
|
safepay | General | KE | 2026-10-05 |
|
ikhasas.com
|
safepay | General | MY | 2026-10-05 |
|
sterrer.net
|
safepay | Technology | NL | 2026-10-05 |
|
sterrer.net
|
safepay | Technology | NL | 2026-10-05 |
|
H&L Manufacturing
|
interlock | Manufacturing | Unknown | 2026-10-05 |
|
part02.simplexengg.in
|
Eclipse | Technology | IN | 2026-10-05 |
|
part02.simplexengg.in
|
Eclipse | Technology | IN | 2026-10-05 |
|
Asia Era One
|
qilin | General | MY | 2026-10-05 |
|
O2 Dental Group
CRITICAL SECTOR
|
interlock | Healthcare | US | 2026-10-05 |
|
O2 Dental Group
CRITICAL SECTOR
|
interlock | Healthcare | US | 2026-10-05 |
|
windor.com
|
settra | General | Unknown | 2026-10-05 |
|
windor.com
|
settra | General | Unknown | 2026-10-05 |
|
Onsemi
|
qilin | Technology | US | 2026-10-05 |
|
ENKA Schools
|
Doommageddon | Education | TR | 2026-10-05 |
|
ENKA Schools
|
Doommageddon | Education | TR | 2026-10-05 |
|
Cam Group LLC
|
Doommageddon | Other | Unknown | 2026-10-05 |
|
Cam Group LLC
|
Doommageddon | Other | Unknown | 2026-10-05 |
|
Franklin Empire
|
BYOD | Other | Unknown | 2026-10-05 |
|
Franklin Empire
|
BYOD | Other | Unknown | 2026-10-05 |
|
Infomedia A/S
|
aurora | Technology | DK | 2026-10-05 |
|
Infomedia A/S
|
aurora | Technology | DK | 2026-10-05 |
|
Millensys
|
medusalocker | Technology | BR | 2026-10-05 |
|
Millensys
|
medusalocker | Technology | BR | 2026-10-05 |
|
Rueegseggerag
|
medusalocker | General | CH | 2026-10-05 |
|
Rueegseggerag
|
medusalocker | General | CH | 2026-10-05 |
|
PANCARIBBEAN LOGISTICS GROUP
|
emperador | Transportation | TT | 2026-10-05 |
|
PANCARIBBEAN LOGISTICS GROUP
|
emperador | Transportation | TT | 2026-10-05 |
|
Company #3
|
N0n | Technology | US | 2026-10-05 |
|
Company #3
|
N0n | Technology | US | 2026-10-05 |
|
Company #2
|
N0n | Financial Services | CA | 2026-10-05 |
|
Company #2
|
N0n | Financial Services | CA | 2026-10-05 |
qilin
thegentlemen
akira
krybit
safepay
incransom
storm
auditteam
n0n
settra
emperador
lamashtu
silentransomgroup
booba project
metaencryptor
wallstreet
play
rhysida
vypr
medusalocker
nightspire
panzer
everest
lockbit5
dragonforce
byod
vexy ransomware
arcusmedia
chaos
doommageddon
endzone
genesis
interlock
ransomhouse
zawoo
aurora
barracuda
eclipse
global secret group
insomnia
netrunner
pear
shinyhunters
spirals
termite
umbra
anubis
braincipher
kairos
unsafe
deadlock
shadowbyt3$
blacklocks
clop
direwolf
global
imnotavillain
orova
payoutsking
securotrop
titan
beast
blacknevas
bravox
cry0
dark project
fulcrumsec
gammax
iah6477
killsec
m3rx
moneymessage
morpheus
redact
secp0
spacebears
threeam
ulose
0apt
0day syndicate
0mega
8base
abrahams_ax
abyss
adminlocker
againstthewest
agl0bgvycg
ailock
ako
alp-001
alphalocker
alphv
apos
apt73
aptlock
argonauts
arkana
arvinclub
atomsilo
avaddon
avos
avoslocker
aware
aztroteam
babuk
babuk2
babyduck
benzona
bert
bianlian
black x
blackbasta
blackbyte
blackfield
blacklock
blackmatter
blackout
blackshadow
blackshrantac
blacksuit
blacktor
blackwater
bluebox
bluelocker
bluesky
bluewhale
bolt team
bonacigroup
bqtlock
brotherhood
cactus
cephalus
cheers
chilelocker
chort
cicada3301
ciphbit
cipherforce
cloak
cmdorganization
coinbasecartel
contfr
conti
cooming
crazyhunter
crosslock
crpxo
crylock
cryp70n1c0d3
cryptbb
cryptnet
crypto24
cuba
cyberleek
cyclops
d1r
d4rk4rmy
dagonlocker
daixin
dan0n
darkangels
darkbit
darkleakmarket
darkmatter
darkpower
darkrace
darkside
darkvault
datacarry
datakeeper
dataleak
desolator
devman
diavol
dispossessor
donex
donutleaks
doppelpaymer
dragonransomware
dread
dunghill
dysphor1a
ech0raix
eldorado
embargo
entropy
ep918
esxiargs
ethics
exfilsquad
exitium
exorcist
falcon
fletchen
flocker
fog
frag
freecivilian
fsteam
funksec
galago
gdlockersec
goddamn ransomwhere
grief
groove
gunra
hades
handala
haron
helix
hellcat
helldown
hellogookie
hellokitty
hive
holyghost
hotarus
hunters
icarus
icefire
imncrew
insane
j
karakurt
karma
kawa4096
kazu
kelvinsecurity
kittykatkrew
knight
kraken
kryptos
kyber
l group
la_piovra
lapsus$
leakbazaar
leaktheanalyst
lilith
linkc
lockbit
lockbit2
lockbit3
lockbit3_fs
lockdata
loki
lolnek
lorenz
losttrust
lunalock
lv
lynx
madcat
madliberator
majinahanashi
malas
malekteam
mallox
mamona
marketo
maze
mbc
medusa
meow
meowciety403
midas
mindware
minteye
mnt6
mogilevich
montage
monti
mortar
mosesstaff
mountlocker
ms13089
mydecryptor
n3tworm
nasirsecurity
nblock
nefilim
nemty
netwalker
nevada
nightsky
nitrogen
noescape
nokoyawa
noname
notpetya
nova
obscura
onepercent
onyx
orca
orion
osiris
pandora
pay2key
payday
payload
payloadbin
playboy
prinzeugen
projectrelic
prolock
prometheus
promptlock
pysa
qiulong
qlocker
quantum
rabbithole
radar
radiant
ragnarlocker
ragnarok
ralord
ramp
rancoz
ranion
ransombay
ransomcartel
ransomcortex
ransomed
ransomexx
ransomhub
ranstreet
ranzy
raworld
raznatovic
rebornvc
redalert
redransomware
revil
reynolds
robinhood
rook
royal
rransom
runsomewares
sabbath
sarcoma
satanlockv2
section9
sensayq
sevyware
shadow
shaoleaks
shiba
shinysp1d3r
sicarii
siegedsec
silent
sinobi
skira
slug
snatch
solidbit
sovcali
sparta
spook
stormous
sugar
suncrypt
synack
teamxxx
tengu
the green blood group
the syndicate
thegreenbloodgroup
timc
tommyleaks
toufan
tridentlocker
trigona
trinity
triple x
trisec
u-bomb
underground
unknown
valencialeaks
vanhelsing
vanirgroup
vect
vendetta
vfokx
vicesociety
walocker
wannacry
warlock
werewolves
weyhro
worldleaks
x001xs
xinglocker
xinof
xp95
xpl0itrs
yanluowang
yurei
zeon
zerolockersec
zerotolerance
владивосток
Global Victim Distribution (30 days)
Targeted Sectors (30 days)
Top Targeted Countries (30 days)
| Country | Incidents (30d) | Share |
|---|---|---|
| US | 236 |
|
| DE | 29 |
|
| IT | 23 |
|
| BR | 20 |
|
| FR | 20 |
|
| GB | 18 |
|
| CA | 17 |
|
| ES | 14 |
|
| MX | 12 |
|
| IN | 12 |
|
| TR | 11 |
|
| AU | 11 |
|
| AR | 10 |
|
| JP | 10 |
|
| SE | 8 |
|
Vulnerabilities
High Severity (>9.0)
CVE-2026-105192
LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can ...
CVE-2026-93674
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutraliza...
CVE-2026-59346
VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative pri...
CVE-2026-96408
A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker...
CVE-2026-105812
Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore Starter Toolkit before...
CVE-2026-101155
An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the...
CVE-2026-105793
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the p...
CVE-2026-104334
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper control of...
CVE-2026-105778
A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of ...
CVE-2026-105484
A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the functio...
Medium Severity (5.0 - 8.9)
CVE-2026-93675
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to...
CVE-2026-93445
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra...
CVE-2026-105871
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i...
CVE-2026-103869
A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is ...
CVE-2026-93449
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra...
CVE-2026-97671
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv...
CVE-2026-97294
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i...
CVE-2026-105875
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i...
CVE-2026-104391
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i...
CVE-2026-103868
A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer c...
CVE-2026-106061
A flaw was found in GIMP’s X cursor (XMC) thumbnail loader. When GIMP generates a thumbnail for a cr...
CVE-2026-107121
A flaw was found in the SMTP email configuration handling of the keycloak-services component. When t...
CVE-2026-82212
The Nexi XPay Build WordPress plugin through 7.6.2 does not correctly validate the security token on...
CVE-2026-93448
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv...
CVE-2026-103870
A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .tree...
CVE-2026-97673
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra...
CVE-2026-27434
Missing Authorization vulnerability in sc Internet Vivoo WP Rentals wprentals allows Exploiting Inco...
CVE-2026-105876
Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows...
CVE-2026-104393
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i...
CVE-2026-106471
A flaw was found in Candlepin. The central authorization filter incorrectly grants access when any o...
CVE-2026-15894
The Bluetooth Mesh On-Demand Private Proxy solicitation handler in subsys/bluetooth/mesh/solicitatio...
CVE-2026-19186
ieee802154_decipher_data_frame() in subsys/net/l2/ieee802154/ieee802154_frame.c computed payload_len...
CVE-2026-42714
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i...
CVE-2026-42720
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i...
CVE-2026-105873
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i...
CVE-2026-105884
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i...
CVE-2026-42713
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i...
CVE-2026-42721
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i...
CVE-2026-59347
VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicio...
CVE-2026-82211
The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to se...
CVE-2026-86833
The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values be...
CVE-2026-89417
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to St...
CVE-2026-93443
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra...
CVE-2026-93447
IBM Langflow OSS 1.0.0 through 1.12.2 could allow an attacker with access to the server secret and R...
CVE-2026-105322
The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its u...
CVE-2026-103668
An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow a...
CVE-2026-102173
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t...
CVE-2026-93678
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv...
CVE-2026-93677
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv...
CVE-2026-88962
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra...
CVE-2026-105835
PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/...
CVE-2026-105836
QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminProductsController::aja...
CVE-2026-104394
Unauthenticated Cross Site Scripting (XSS) in Charitable <= 1.8.12.3 versions.
CVE-2026-105811
Authorization bypass through a user-controlled key in the optional Amazon Q Business Lambda hook sam...
CVE-2026-105837
libmikmod before 3.3.14 contains an integer overflow vulnerability in DSM_Load() in load_dsm.c that ...
CVE-2026-101207
Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains a...
CVE-2026-101157
A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacen...
CVE-2026-105807
A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an u...
CVE-2026-101154
An authenticated remote attacker with specific permissions can read or write files on the platform f...
CVE-2026-101153
On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vul...
CVE-2026-101156
A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege adminis...
CVE-2026-101158
A missing input validation vulnerability in the Fileserver upload API allows an authenticated attack...
CVE-2026-101258
A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it c...
CVE-2026-105838
libmikmod before 3.3.14 contains a heap out-of-bounds read vulnerability in the Impulse Tracker load...
CVE-2026-101329
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv...
CVE-2026-101331
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv...
CVE-2026-101152
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated...
CVE-2026-102387
Unauthenticated Sensitive Data Exposure in Xserver Migrator <= 1.6.6 versions.
CVE-2026-104395
Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions.
CVE-2026-105834
Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the proj...
CVE-2026-104385
Unauthenticated Sensitive Data Exposure in Groundhogg <= 4.8.3 versions.
CVE-2026-102411
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to Denial o...
CVE-2026-105797
SimpleChat is a secure AI conversation application with personal and group workspaces for document-g...
CVE-2026-105796
Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP ...
CVE-2026-105798
SimpleChat is a secure AI conversation application with personal and group workspaces for document-g...
CVE-2026-102412
Incorrect Authorization (CWE-863) in Kibana can lead to sensitive information disclosure via Accessi...
CVE-2026-104747
Unauthenticated PHP Object Injection in Haaken <= 1.5 versions.
CVE-2026-105792
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. P...
CVE-2026-105789
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. P...
CVE-2026-105790
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. P...
CVE-2026-105707
A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerabi...
CVE-2026-105791
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. P...
CVE-2026-105839
libmikmod before 3.3.14 contains an integer overflow in the Oktalyzer loader OKT_doPBOD() that allow...
CVE-2026-104670
Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions.
CVE-2026-105701
The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to...
CVE-2026-103008
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially craf...
CVE-2026-105621
A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateA...
CVE-2026-103005
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service...
CVE-2026-105571
A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function ...
CVE-2026-105487
A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the f...
CVE-2026-105704
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unk...
CVE-2026-104047
A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly ...
CVE-2026-102915
Subscriber Broken Access Control in WPO365 <= 44.1 versions.
CVE-2026-105472
A weakness has been identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca...
CVE-2026-104069
HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() wh...
CVE-2026-103006
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially craf...
CVE-2026-102409
Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privilege...
CVE-2026-104046
A flaw was found in SSSD (System Security Services Daemon). When Identity Provider (IdP) authenticat...
CVE-2026-104048
A flaw was found in SSSD. In trust-enabled identity management environments, SSSD evaluates Host-Bas...
CVE-2026-104672
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions.
CVE-2026-103007
Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated ...
CVE-2026-103009
Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information ...
CVE-2026-104387
Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions.
CVE-2026-104757
Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions.
CVE-2026-104335
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitra...
CVE-2026-105776
A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to...
CVE-2026-105788
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. P...
CVE-2026-104073
NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allow...
CVE-2026-102169
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless clie...
CVE-2026-102168
On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless clie...
Low Severity (1.0 - 4.9)
CVE-2026-103075
Missing Authorization vulnerability in WPMU DEV Hustle wordpress-popup allows Ex...
CVE-2026-104390
Missing Authorization vulnerability in Arraytics Booktics booktics allows Exploi...
CVE-2026-93679
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacke...
CVE-2026-105809
A vulnerability was identified in SourceCodester Simple Student Information Syst...
CVE-2026-105808
A vulnerability was determined in SourceCodester Simple Student Information Syst...
CVE-2026-101151
Insufficient validation of request in login flow could allow a remote, unauthent...
CVE-2026-101150
Insufficient validation of OIDC bearer token configuration could allow a user wi...
CVE-2026-101149
Insufficient validation of OIDC SSO provider configuration could allow a user wi...
CVE-2026-105800
i18next-http-backend is a backend layer for i18next that loads translation resou...
CVE-2026-105708
A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability i...
CVE-2026-105775
A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. Th...
CVE-2026-105795
Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, ...
CVE-2026-105703
A vulnerability was determined in PHPGurukul User Registration & Login and User ...
CVE-2026-105573
A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an...
CVE-2026-105610
A vulnerability was found in chillzhuang SpringBlade up to 5.0.1. The impacted e...
CVE-2026-105572
A vulnerability has been found in PickMall Lilishop up to 4.2.4. This affects an...
CVE-2026-105611
A vulnerability was determined in chillzhuang SpringBlade up to 5.0.1. This affe...
CVE-2026-104045
A flaw was found in SSSD. A local user can trigger a Denial of Service (DoS) by ...
CVE-2026-102410
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via...
CVE-2026-15894
The Bluetooth Mesh On-Demand Private Proxy solicitation handler in subsys/bluetooth/mesh/solicitation.c copies a received Solicitation PDU into a fixed 17-byte stack buffer without bounding the source length. In sol_pdu_decrypt(), out is allocated as NET_BUF_SIMPLE(17) and then filled with net_buf_simple_add_mem(out, in->data, in->len); net_buf_simple_add() guards its tailroom only with __ASSERT_NO_MSG, which is compiled out in production builds, so when in->len > 17 the underlying memcpy writes attacker-controlled bytes past the 17-byte stack buffer. The copy occurs before any decryption or authentication, so no key material is required to trigger it. The oversized length arises because the mesh scan callback in subsys/bluetooth/mesh/adv.c calls net_buf_simple_restore() before dispatching to bt_mesh_sol_recv(), leaving buf->len covering the entire remaining advertising payload rather than just the Solicitation Service Data. After the parser locates the Service Data AD and consumes the Identification Type byte, the remaining buf->len is the 17-octet Network PDU plus any trailing advertising bytes, and prior to this fix there was no maximum-length check (only a minimum). An attacker can therefore append extra AD structures or padding after the Solicitation Service Data to make buf->len exceed 17. bt_mesh_scan_cb() is registered directly as the BLE scan callback, so buf is raw, unauthenticated advertising data received over the air. Any device in radio range can send a non-connectable advertisement carrying a crafted mesh Proxy Solicitation to a node that has CONFIG_BT_MESH_OD_PRIV_PROXY_SRV enabled and is currently eligible to be solicited (GATT proxy disabled, On-Demand Private Proxy enabled), with no pairing, bonding, or provisioning. The result is an attacker-controlled stack overwrite — plausibly leading to remote code execution and at minimum a reliable remote denial of service. The fix trims buf->len to the spec-fixed 17 octets (dropping the PDU if fewer remain) before decryption.
CVE-2026-104652
The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page embedding the gallery.
CVE-2026-103416
Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Eclipse ThreadX NetX Duo 6.5.1.202602 allows a handshake message larger than the cache writes past it and on into the rest of the session control block, which holds pointers. A malicious or compromised server can make a TLS 1.3 client produce such a message before certificate authentication completes, so no server certificate is needed to reach it.
CVE-2026-92532
Unrestricted file upload vulnerability in the BugTracker.NET attachment functionality. An authenticated user with administrator privileges could modify the application configuration to store files in a directory accessible via the web interface. Due to the lack of proper file extension validation, an attacker could upload a malicious ASPX file and subsequently execute it on the server. A successful exploit could allow arbitrary code execution with the privileges of the account used by the web service.
CVE-2026-93449
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
CVE-2026-87782
The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
CVE-2026-102173
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via registration metadata in all versions up to, and including, 6.3.1 This is due to insufficient escaping in `ExceptionalElements::image_element()`, which concatenates a user-meta value straight into an `<img src="…">` attribute. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute whenever a user accesses a page rendering a Kirki users collection whose image element is bound to one of the nine registration meta fields. Requires public user registration to be enabled and a published page carrying a `kirki-register` element, which prints the required element nonce into the public markup.
CVE-2026-104390
Missing Authorization vulnerability in Arraytics Booktics booktics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booktics: from n/a through 1.0.27.
CVE-2026-97188
The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object that is instantiated when an administrator later opens and saves that row. If a suitable POP chain is present via another installed String locator WordPress plugin before 2.6.8 or , this can lead to arbitrary file deletion, sensitive data disclosure or remote code execution.
CVE-2026-92533
Path traversal vulnerability in the BugTracker.NET file download component. The parameter used to specify the file name does not properly validate user-supplied paths. An authenticated remote attacker could enter a manipulated path to access files located outside the intended directory. Successful exploitation could allow the attacker to read system files accessible to the account used by the application.
CVE-2026-81535
In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding policy callback. forwarded-tcpip opens are admitted without an authorization check and are not capped in number, allowing a malicious SSH peer to make an endpoint allocate unbounded per-channel buffers for forwarding channels the application never authorized. A client also does not check a forwarded-tcpip open against the forwards it registered with a tcpip-forward request, as RFC 4254 section 7.2 requires, so a malicious server can open forwarding channels for addresses and ports the client never asked it to forward.
CVE-2026-93448
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
CVE-2026-93679
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption during ZIP file extraction.
CVE-2026-103378
The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, into which it writes the site's carrier integration key while processing requests from unauthenticated users, allowing attackers to retrieve the key and use it to modify WooCommerce order statuses. The same log file also exposes customer information from orders the shop has processed.
CVE-2026-96408
A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product.
CVE-2026-86816
The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales counts, exact stock levels, and private product meta, that WooCommerce itself keeps behind authentication.
CVE-2026-104391
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master quiz-master-next allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through 11.2.7.
CVE-2026-82212
The Nexi XPay Build WordPress plugin through 7.6.2 does not correctly validate the security token on its payment notification route, accepting the request when the target order has no stored token, which allows unauthenticated attackers to mark arbitrary orders as paid, or to mark genuinely paid orders as failed.
CVE-2026-27434
Missing Authorization vulnerability in sc Internet Vivoo WP Rentals wprentals allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Rentals: from n/a through 3.14.2.
CVE-2026-105884
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media Rocket Lazy Load rocket-lazy-load allows Stored XSS.This issue affects Rocket Lazy Load: from n/a through 2.4.0.
CVE-2026-90466
Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'. The startup flag 'trusted_jar_paths' references URIs for loading files from local or remote filesystems. Path traversal can't override the schema, but can result in loading a JAR that has been uploaded to a different location in that filesystem via Impala DDLs such as CREATE DATA SOURCE and CREATE TABLE. Path traversal can only be used if a trusted path exists, so this attack requires 'trusted_jar_paths' have a non-empty value configured by the Impala admin. Users are recommended to upgrade to version 4.5.3, which fixes this issue.
CVE-2026-42714
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Piggly Dev Pix por Piggly (para Woocommerce) pix-por-piggly allows Blind SQL Injection.This issue affects Pix por Piggly (para Woocommerce): from n/a through 2.1.2.
CVE-2026-97331
The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returning that user's email address, allowing any authenticated user, such as a Subscriber, to obtain the email address of any registered account, including administrators.
CVE-2026-58068
This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system.
CVE-2026-88962
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
CVE-2026-93443
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code.
CVE-2026-93675
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion.
CVE-2026-93678
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper authorization.
CVE-2026-5703
Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user running the web server. This is possible by modifying the URL to include a path traversal payload. Successful exploitation of this vulnerability could allow an attacker to access critical system files containing confidential information.
CVE-2026-104667
The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes.
CVE-2026-106061
A flaw was found in GIMP’s X cursor (XMC) thumbnail loader. When GIMP generates a thumbnail for a crafted XMC file, it allocates a pixel buffer using a width * height size computed in 32-bit signed arithmetic. If that product overflows, the allocation is smaller than the true image extent. A subsequent GEGL buffer read uses the unwrapped dimensions and performs an out-of-bounds read on the heap (CWE-125), after integer overflow in the size calculation (CWE-190). This can crash GIMP or corrupt process memory.
CVE-2026-102478
In affected versions of Octopus Server, an authenticated user with permission to modify roles could bypass the protections preventing access abuse resulting in privilege escalation. It was possible for the built-in role to be weakened and the attacker's account added to a privileged team. This was achievable due to improper validation of unsafe equivalence in inputs.
CVE-2026-103870
A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area and write that tree's repository metadata and packages there, as the Pulp worker user. An existing file or directory is not replaced. The flaw does not disclose data and does not stop the service.
CVE-2026-87971
The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.
CVE-2026-97673
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.
CVE-2026-105322
The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay).
CVE-2026-105316
The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting.
CVE-2026-19572
A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session without providing valid credentials.
CVE-2026-19386
A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code via a crafted configuration file upload that exceeds the expected buffer size.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
CVE-2026-105875
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Stored XSS.This issue affects Prime Slider – Addons For Elementor: from n/a through 4.6.2.
CVE-2026-105192
LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding request arguments and before the handler runs. A single unauthenticated ZMQ DEALER message to the transport port (default 5555) therefore executes code as the user the LMCache process runs as. Official container images run that process as root. The transport binds to localhost unless the operator sets a routable address with --host, which is how multi-node deployments let peers connect.
CVE-2026-102782
Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=checkLoginPass with no authentication or access control check of any kind. The handler reads a login request parameter through Joomla’s generic, non-sanitizing input filter, which strips HTML/script tags but never touches quotes or SQL syntax, and concatenates it directly into a query string with no escaping or parameterization:
CVE-2026-97720
Incorrect implementation of JWT/OAuth authentication in Impala executors in Apache Impala versions up to and including 4.5.2 which allows attacked to access resources served by the executor's webserver when that webserver is configured to accept JWT/OAuth tokens. Bearer token (JWT) signatures are not validated resulting in the webserver accepting any valid JWT. Users are recommended to either disable JWT/OAuth auth for Impala executors or upgrade to version 4.5.3, which fixes this issue.
CVE-2026-97146
Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user annotation by setting a secondary label on the pod. If the pod has the label 'app=yunikorn' the checks limiting the user annotation content are not run. The label is used to identify the YuniKorn application itself in the deployments. The bypass allows any user to specify an arbitrary user info annotation. The arbitrary user information could allow access to a queue that the user normally would not have access to. Quota usage for the queue might be impacted if the application runs in the incorrect queue. User based quota enforcement is also based on the user annotation. User quota tracking could be side stepped even if the application runs in the correct queue. Users are recommended to upgrade to version 1.10.0, which fixes this issue.
CVE-2026-107104
This vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted data to the vulnerable functionality of the targeted system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code, manipulate application data or perform other unintended actions on the targeted system.
CVE-2026-107103
This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted input to the vulnerable endpoint. Successful exploitation of this vulnerability could allow the attacker to perform SQL injection attacks on the targeted system.
CVE-2026-92393
Apache YuniKorn 1.9.0 and earlier does not implement label and user annotation checks for workload UPDATE action bypassing all checks. Workloads in YuniKorn are defined as the following Kubernetes objects: "deployments", "replicasets", "statefulsets", "daemonsets", "jobs", "cronjobs". The CREATE action correctly enforces the checks for all object types. The bypass allows any user to specify an arbitrary user info annotation. The same bypass also allows changing the application ID for the workload. The combination of the two applied in one UPDATE could allow access to a queue that the user normally would not have access to. Quota usage for the queue might be impacted if the application runs in the incorrect queue. User based quota enforcement is also based on the user annotation. User quota tracking could be side stepped even if the application runs in the correct queue. Users are recommended to upgrade to version 1.10.0, which fixes this issue.
CVE-2026-96530
The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's third-party service credentials.
CVE-2026-103323
The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails feature is enabled, the plaintext passwords of newly registered customers.
CVE-2026-83742
Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated remote attacker to write one out-of-bounds null byte past the end of a stack buffer by sending a crafted SFTP path. wolfSSH_RealPath() in src/ssh.c appends each path component with a remaining-size bound (outSz - curSz) rather than the full destination size, so once the accumulated path reaches half the output buffer the size_t computation n - strlen(s1) - 1 wraps to near SIZE_MAX. The strncat() call is then effectively unbounded and copies the whole component; when that component exactly fills the remainder of the buffer, its terminating null is written one byte past the end. The caller's own length check keeps the copied data inside the buffer, so the overflow is limited to that single null byte, which may corrupt an adjacent stack value and crash the process. Applications that call the public wolfSSH_RealPath() with an output buffer smaller than the input path are additionally exposed to an unbounded copy, because the word32 expression outSz - segSz in that length check also wraps.
CVE-2026-103869
A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access token obtained for a different remote, and can reuse it at the service that issued it. Content stored in Pulp is not changed, and the service is not stopped.
CVE-2026-14911
Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker to read DOM information, modify router settings, and cause a denial-of-service condition when an authenticated user visits a crafted URL.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
CVE-2026-105324
An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to retrieve sensitive files without authentication. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RWC1 as well as from ADM 5.0.0 through ADM 5.1.4.RL21.
CVE-2026-107102
This vulnerability exists in the ERP system due to improper validation of payment callback parameters and inadequate authentication controls in API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating the parameter to cause the application to establish an authenticated session for an arbitrary user without valid payment verification. Successful exploitation of this vulnerability could allow the attacker to bypass authentication and gain unauthorized access to other user accounts on the targeted system.
CVE-2026-93447
IBM Langflow OSS 1.0.0 through 1.12.2 could allow an attacker with access to the server secret and Redis write access to submit a malicious serialized cache value. When the value was retrieved, deserialization could have executed attacker-controlled code with the privileges of the service process.
CVE-2026-93674
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
CVE-2026-93445
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
CVE-2026-103075
Missing Authorization vulnerability in WPMU DEV Hustle wordpress-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hustle: from n/a through 7.8.14.2.
CVE-2026-93677
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to exposure of sensitive information to an unauthorized actor.
CVE-2026-19396
A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT pairing token generation of the ASUS RT-BE57 router allows an unauthenticated nearby user to derive the pairing token and read or modify router settings via observed values from an administrator-initiated IFTTT pairing session.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
CVE-2026-59346
VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)
CVE-2026-59347
VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)
CVE-2026-16528
Insertion of Sensitive Information into Log File in certain ASUS router models allows a remote authenticated attacker to obtain DDNS credentials from the system log, potentially enabling modification of DNS settings.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.
CVE-2026-83540
When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0. Non-Windows builds of wolfSSHd are not affected.
CVE-2026-104653
The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration values before storing them and outputting them in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page containing the affected gallery.
CVE-2026-97354
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services.
CVE-2026-103868
A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they control, receives the username, password, or bearer token stored for a different remote, and can reuse that credential at the upstream registry. Content stored in Pulp is not changed, and the service is not stopped.
CVE-2026-84897
src/internal.c in wolfSSL wolfSSH through 1.5.0 admits the server-to-client Diffie-Hellman group exchange messages SSH_MSG_KEX_DH_GEX_GROUP (31) and SSH_MSG_KEX_DH_GEX_REPLY (33) when a server receives them from an unauthenticated client. IsMessageAllowedServer() applies no direction check to the key exchange message range: when the peer is keying and no particular message is expected, which is the state a server is in for the whole window after it processes the client's KEXINIT because nothing sets handshake->expectMsgId there, the function falls out of its expectation branch without a verdict and reaches a numeric bound that admits every message id from 30 through 34. A client that negotiates diffie-hellman-group-exchange-sha256 and then sends message 31 makes the server run the client-side handler DoKexDhGexGroup(), which validates the attacker-supplied group with two 8-round Miller-Rabin primality tests, one on p and one on (p-1)/2, on a value of up to 8192 bits. The handler then returns success: the server stores the attacker's prime and generator, generates a Diffie-Hellman key pair in the attacker's group, and sends the client-role message SSH_MSG_KEX_DH_GEX_INIT (32) back to the attacker. Published RFC 3526 safe primes are the worst-case input and cost the attacker nothing to obtain. The primality validation was added in 1.5.0; versions from 1.2.0 through 1.4.22 admit the same message and enter the same client-role path without the primality cost. Message 33 is admitted as well, but on a server it is rejected before any cryptography because no public key check callback is registered, so it carries no comparable cost. Builds that define WOLFSSH_NO_DH_GEX_SHA256, which is implied by WOLFSSH_NO_DH or NO_SHA256, are unaffected.
CVE-2026-104953
The MPG WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform SQL injection attacks and read sensitive data such as password hashes.
CVE-2026-82211
The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details.
CVE-2026-86833
The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends.
CVE-2026-78243
Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user specified in the pod the server crashes if a membership record does not start with "CN=". This only affects install that have the non default LDAP group provider configured. Users are recommended to upgrade to version 1.10.0, which fixes this issue.
CVE-2026-104678
The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access.
CVE-2026-104050
The Academy LMS WordPress plugin before 4.0.0 does not verify that a quiz question belongs to the course the requesting user is authorized to access before returning that question's answer options, allowing any authenticated user with access to a single course, such as an enrolled student, to read the quiz answer options of questions belonging to other courses they are not enrolled in.
CVE-2026-104049
The Academy LMS WordPress plugin before 4.0.0 does not verify course enrollment or object ownership when returning a lesson's content through one of its REST API routes, allowing users with a self-registerable student account to read the full content of arbitrary lessons, including lessons of paid or private courses they are not enrolled in.
CVE-2026-103681
The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete the Frontend Dashboard WordPress plugin before 3.0.0's configured profile and post form fields.
CVE-2026-104677
The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site.
CVE-2026-104393
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs Happy Addons for Elementor happy-elementor-addons allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.50.0.
CVE-2026-16516
wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange. In ParseECCPubKey() (src/internal.c), the blob's algorithm string is used to derive the curve via NameToId/wcPrimeForId without checking against the negotiated ssh->handshake->pubKeyId, and the RFC 5656 curve identifier string is discarded via GetSkip() rather than compared. An active network man-in-the-middle attacker can substitute a host key blob containing a different ECDSA curve, causing the client to import the key on the wrong curve. Because the attacker controls the private key for the substituted curve, signature verification passes. Exploitation requires an active MitM position and a lax public key check callback (e.g., TOFU, algorithm-name-only check, or fingerprint match against the parsed key).
CVE-2026-106471
A flaw was found in Candlepin. The central authorization filter incorrectly grants access when any one of multiple @Verify-annotated parameters is accessible, instead of requiring access to every verified entity. A low-privilege authenticated attacker who can access the first referenced object can bypass authorization checks on subsequent objects. When target resource identifiers are known, this can enable unauthorized disclosure of consumer information and unauthorized modification of entitlements and related subscription resources, including across organizations.
CVE-2026-105873
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 8.8.6.
CVE-2026-42720
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sarah Giles Dynamic User Directory dynamic-user-directory allows Blind SQL Injection.This issue affects Dynamic User Directory: from n/a through 2.4.
CVE-2026-103668
An SQL Injection vulnerability exists in the Site Search function of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary SQL query on the affected product.
CVE-2026-105876
Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Retrieve Embedded Sensitive Data.This issue affects Modula Image Gallery: from n/a through 3.0.11.
CVE-2026-42721
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Blind SQL Injection.This issue affects affiliate-toolkit: from n/a through 3.9.1.
CVE-2026-105871
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 8.8.6.
CVE-2026-93026
This vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise Manager master key and stored antivirus update credentials.
CVE-2026-89417
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 's' Search Parameter via comments-atom Feed in all versions up to, and including, 6.3.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that the front-end server serves the retained .tmp file without a Content-Type or X-Content-Type-Options header, enabling MIME-sniffing browsers such as Chromium to execute the injected script — a condition present by default on many Apache and nginx/php-fpm deployments.
CVE-2026-107121
A flaw was found in the SMTP email configuration handling of the keycloak-services component. When the STARTTLS option is enabled, Keycloak fails to strictly enforce an encrypted connection, allowing it to fall back to unencrypted communication if the encryption request is tampered with. An attacker who can intercept network traffic can exploit this to capture sensitive email credentials and message content in plain text.
CVE-2026-93684
An SQL user using Impala up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it run in another user's browser when that user opens the query plan in Impala's Web UI. This is stored XSS (CWE-79). Users are recommended to upgrade to version 4.5.3.
CVE-2026-58069
This vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbitrary files on the service provider host.
CVE-2026-102781
Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a CSRF token check exists anywhere in the handler. Two confirmed impact paths: an unauthenticated GET deletes any slider image by guessable sequential IDs, and an unauthenticated multipart upload with a zip file renames and replaces the entire #__os_touch_slider/#__os_touch_slider_text tables site-wide with attacker-supplied content, with no task parameter even required for the second path.
CVE-2026-19186
ieee802154_decipher_data_frame() in subsys/net/l2/ieee802154/ieee802154_frame.c computed payload_len = net_pkt_get_len(pkt) - ll_hdr_len - authtag_len without first checking that the received frame is at least ll_hdr_len + authtag_len bytes long. All three variables are uint8_t, so a frame whose payload is shorter than the configured authentication tag makes the subtraction wrap around to a large value (up to 255). The wrapped length is passed unchanged to ieee802154_decrypt_auth() and on to the CCM operation as cipher_pkt.in_len/out_buf_max, with apkt->tag pointing at frame + ll_hdr_len + payload_len. Because the receive buffer is allocated to the exact length of the frame received from the radio driver, the crypto layer then reads several hundred bytes past the end of the packet buffer and writes the same number of decrypted bytes back over it in place. The frame's authentication tag is only verified after this processing has taken place, so no key material, association or prior authentication is needed — a single crafted short frame from any device in radio range is sufficient. Frame validation in ieee802154_validate_frame() does not prevent it: a data frame is accepted with a one-byte payload. The result is an out-of-bounds read and an out-of-bounds write of up to roughly 240 bytes into the adjacent network-buffer pool, corrupting other packets or allocator metadata and typically faulting the target. The out-of-bounds content is not attacker-chosen (it is ciphertext XOR keystream over out-of-bounds memory) and the frame is dropped when tag verification fails, so the primary impact is memory corruption and denial of service rather than information disclosure. Exposure is limited to configurations that enable the experimental CONFIG_NET_L2_IEEE802154_SECURITY option, select a crypto device via CONFIG_NET_L2_IEEE802154_SECURITY_CRYPTO_DEV_NAME, and have established a security session with a level other than IEEE802154_SECURITY_LEVEL_NONE; with security disabled or at level NONE the tag length is zero and no underflow occurs. The fix rejects frames shorter than ll_hdr_len + authtag_len before the subtraction, and adds the matching guard on the transmit side in ieee802154_create_data_frame().
CVE-2026-42713
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopiplus Post title marquee scroll post-title-marquee-scroll allows Blind SQL Injection.This issue affects Post title marquee scroll: from n/a through 9.9.
CVE-2026-97671
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.
CVE-2026-92531
Operating system command injection vulnerability in the SVN integration component of BugTracker.NET. The application incorporates the value of the field corresponding to the repository into an svn.exe command without properly validating it. An authenticated user with administrator privileges could store manipulated arguments in the database and subsequently cause them to be processed by the revision comparison functionality. A successful exploit could allow the execution of arbitrary commands with the privileges of the account used by the application. To exploit this vulnerability, svn.exe must be installed and capable of being invoked by the service.
CVE-2026-97294
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.41.
CVE-2026-104651
The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not verify authorization or that the requesting user owns the target order in several of its order payment-processing actions, allowing any authenticated user, including subscribers, to act on and alter orders belonging to other customers.
CVE-2026-106267
Missing authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106241
Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106332
Integer overflow in Compositing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
CVE-2026-105488
Missing authorization in the global vault in Devolutions Server 2026.3.7.0 and earlier allows an authenticated user with only the global vault view permission to modify and delete global contact and folder entries.
CVE-2026-106281
Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-106236
UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
CVE-2026-106312
Missing authorization in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low)
CVE-2026-106123
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.35.0, ConnectionFactoryConfigurator.load() includes the raw uri value in wrapped exceptions when AMQP URI parsing fails. Because the URI may contain a plaintext username and password, startup logs, application performance monitoring systems, CI logs, and copied stack traces can disclose broker credentials to users who should not have access to them. This issue is fixed in version 5.35.0.
CVE-2026-95594
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions.
CVE-2026-106235
Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-106262
Incomplete cleanup in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-39761
Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions.
CVE-2026-104395
Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions.
CVE-2026-39781
Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions.
CVE-2026-55307
In kdn_set_sysregs_prot of hwcrypto-kdn.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-106282
UI misrepresentation in WebOTP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106314
Incorrect authorization in Bluetooth in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-39785
Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions.
CVE-2026-39792
Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions.
CVE-2026-39789
Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
CVE-2026-39749
Subscriber Broken Access Control in App for Cloudflare® <= 1.10.1 versions.
CVE-2026-39797
Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions.
CVE-2026-39770
Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.
CVE-2026-106422
Incorrect authorization in API in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-48199
Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions.
CVE-2026-40807
Unauthenticated Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.6 versions.
CVE-2026-106265
UI misrepresentation in File in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106261
Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106412
Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-106425
Missing authorization in BrowserTag in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-42413
Unauthenticated Sensitive Data Exposure in Snapshotify – All-in-One Backup & Restore & Migrate <= 1.3.2 versions.
CVE-2026-106253
Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-106417
Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-41560
Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions.
CVE-2026-39754
Contributor Arbitrary File Download in Piotnet Addons For Elementor <= 7.1.71 versions.
CVE-2026-106502
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose sensitive information in Scaffolder task failure events. Under specific template and failure conditions, an authenticated user may retrieve backend-managed credentials used during task execution from affected task events. This issue is fixed in version 4.1.0.
CVE-2026-106416
Code injection in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-106420
Incorrect calculation in API in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-106256
Information leak in Passwords in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106248
Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-106260
Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-39755
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
CVE-2026-39759
Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.
CVE-2026-104399
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124.
CVE-2026-101329
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper access control.
CVE-2026-106249
Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-39771
Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions.
CVE-2026-104335
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper access control.
CVE-2026-39784
Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions.
CVE-2026-39753
Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions.
CVE-2026-39798
Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions.
CVE-2026-97674
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command ('Code Injection'), aka improper control of code generation.
CVE-2026-88779
Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.
CVE-2026-102490
Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.
CVE-2026-102489
Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.
CVE-2026-104286
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
CVE-2026-76504
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
CVE-2026-86950
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
CVE-2026-88771
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
CVE-2026-88772
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
Advanced Persistent Threats (APT)
Lunex Uses BYOVD to Disable Security Monitoring and Deploy Persistent Stealer
The Lunex Malware-as-a-Service platform targets Ukrainian users through fake CAPTCHA lures, deploying a sophisticated loader that exploits AMD's vulnerable PDFWKRNL.sys driver (CVE-2023-20598) to disable endpoint security products. The loader retrieves Windows kernel debugging symbols from Microsoft's Symbol Server to dynamically identify and zero security-related kernel callbacks, making the technique version-agnostic. After manipulating security controls, LunexStealer is deployed to harvest credentials from seven Chromium-based browsers and multiple cryptocurrency wallets while establishing persistent C2 access through registry keys, scheduled tasks, and Native Messaging Host registrations. This mechanism survives deletion of the primary executable and provides continued filesystem access and remote execution capabilities, demonstrating advanced evasion techniques that leave security products running while disrupting their operational visibility.
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure
A Linux malware strain named ClingSTUN exploits unpatched vulnerabilities in Internet-facing devices to establish persistent footholds and functions as a back-connect proxy backdoor. The campaign targets IoT devices through multiple CVEs including command injection and code execution flaws in various vendors' products. ClingSTUN abuses legitimate public STUN infrastructure to discover externally mapped IP addresses, maintain NAT bindings, and improve connectivity between compromised hosts and operators. The malware employs sophisticated persistence mechanisms, terminates watchdog timers, kills competitor processes, and disguises itself as the init process. It maintains remote command execution capabilities and includes self-propagation exploits for seven additional vulnerabilities. The threat actor evolved their approach across three distinct periods, adjusting initial access strategies and expanding the list of targeted vulnerabilities from single-vendor exploits to multi-vendor command injection attacks ...
Caught in 4K: The Gentlemen Files
A Russian-speaking affiliate of the Gentlemen ransomware group, identifying as Azazel, compromised over two dozen organizations across six countries while simultaneously betraying the RaaS operator. The threat actor deployed independent leak site LEAKNED, keeping all extortion proceeds. Attack chains primarily exploited CI/CD secrets from GitLab instances, with one deep compromise involving an AI platform through SSRF, credential decryption, and continuous object storage exfiltration. Azazel operationalized MCP (Model Context Protocol) as a command-and-control channel, marking the first documented criminal use of AI assistant tooling for attack execution. Infrastructure consisted of three nodes totaling over 50TB storage capacity, with approximately 6TB of actively transferring victim data discovered during investigation. Victims spanned logistics, insurance, pharmaceutical, AI, medical devices, and government-adjacent sectors.
A STUNning Disguise: Cling Malware Masquerades as Google
A sophisticated IoT botnet dubbed Cling has been discovered exploiting vulnerable internet-exposed devices through CVE-2021-35394 and other command-injection flaws. The malware distinguishes itself by abusing STUN protocol traffic and public STUN infrastructure for command-and-control communications, making malicious activity appear as legitimate NAT-traversal behavior. Cling propagates through multiple CVE exploits targeting routers, DVRs and embedded appliances, establishes persistence via init scripts and wget binary replacement, then communicates with operators through STUN-like exchanges with public servers. The botnet operator uses IP spoofing to make commands appear as if originating from Google's STUN infrastructure. Capabilities include propagation scanning, DDoS flooding, TCP tunneling and proxy relay functions. The malware supports various attack commands hidden within STUN transaction ID fields while maintaining a low detection profile by blending into legitimate application traffic from collab...
XWorm Malware: Worming Its Way From Entry to Exploitation
XWorm is a versatile modular malware that poses a multifaceted threat through remote access, data theft, ransomware delivery, and botnet creation. Associated with the DDGroup cybercrime group, it rapidly gained notoriety for using advanced techniques. The malware employs diverse delivery methods including phishing emails with malicious attachments, drive-by downloads, exploit kits targeting browser vulnerabilities, USB drives, and Remote Desktop Protocol exploitation. Once established, XWorm steals sensitive data like passwords and credit card information, deploys additional malware strains including ransomware and spyware, and causes system crashes and denial-of-service attacks. Its modular nature and varied attack vectors make it a persistent threat requiring robust cybersecurity measures and continuous vigilance.
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
Threat actors exploited ChatGPT's Custom GPT feature to impersonate legitimate ChatGPT models, directing victims through sponsored Google ads to malicious Custom GPTs titled 'Plus 5.6'. These instances served fake service availability notices, redirecting users to Google Sites pages hosting ClickFix lures disguised as CloudFlare CAPTCHA checks. Victims were tricked into executing PowerShell commands that downloaded malicious MSI installers. The attack chain employed DLL sideloading through legitimate Canon-signed and later Stardock-signed executables, establishing dual persistence mechanisms via registry Run keys and scheduled tasks. The multi-stage infection involved obfuscated scripts, encrypted payloads hidden in WAV files and NuGet packages, and ultimately deployed a feature-rich remote access trojan with capabilities including remote desktop, browser hijacking, credential theft, and follow-on payload delivery. Huntress investigated approximately 40 incidents linked to this campaign, with confirmed Cus...
Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX
Socket identified a malicious cluster of Visual Studio Code extensions spanning both VS Code Marketplace and Open VSX registries. Two confirmed malicious themes were discovered: Aurora Nocturne Night Theme, which downloaded and executed threat actor-controlled batch files, and Cosmic Nebula Themes, containing a staged loader that decrypts embedded JavaScript, performs Russian-language gating, and uses Solana blockchain transaction memos to dynamically resolve payload infrastructure. The cluster includes at least ten extensions across both platforms, with over 8,000 Visual Studio Marketplace installs and tens of thousands of Open VSX downloads. Git history, Russian-language source code comments, and distinctive execution patterns connect these extensions to the broader GlassWorm supply chain campaign. Several extensions remain unweaponized but retain executable capabilities that pose significant risk. The operation employs brandjacking tactics and demonstrates sophisticated infrastructure rotation technique...
The Psychedelic Stealer: When the CAPTCHA Is the Installer
Between September 9 and September 14, 2026, an unattributed Russian-speaking operator compromised at least six legitimate Ukrainian small-business websites to deliver a fake Cloudflare verification page. The ClickFix chain convinced victims to manually execute msiexec.exe commands via the Windows Run dialog, achieving a 14 percent completion rate (79 infections from 426 clicks). The payload, internally named Psychedelic, combines credential theft with persistent agent capabilities, installing browser extensions with native-messaging bridges, establishing scheduled tasks, and polling a REST API for arbitrary executable tasking. Targeting focused overwhelmingly on Ukraine with clear financial motivation, collecting browser credentials, session tokens, and cryptocurrency wallet data from MetaMask, Trust Wallet, Exodus, Atomic Wallet, and others. The technique deliberately avoids encoded PowerShell, using signed Microsoft binaries to bypass common ClickFix detections.
SMTP is the key: BPFDoor and AVERAT hitting the network edge
A sophisticated multi-component campaign targeting telecommunications and network-edge appliances has been discovered, featuring BPFDoor variants and a newly identified implant designated AVERAT. The operation leverages SMTP traffic on port 25 to blend command-and-control communications with legitimate mail relay activity, exploiting the trust environments of targeted systems. Attackers deploy a dropper that stages payloads into memory-only execution, leaving no on-disk artifacts for forensic analysis. BPFDoor variants impersonate legitimate processes such as SpamSniper components on South Korean systems, while AVERAT samples target Taiwanese appliances using regionalized disguises. The infrastructure relies on compromised consumer devices including NAS units, CCTV systems, and DVRs as operational relays, consistent with China-nexus covert network patterns. Each component demonstrates advanced operational security through process spoofing, encrypted configurations, and deliberate evasion of network monitor...
Anatomy of BraZetsu: How Cybercriminals Supply the Underground Ecosystem
BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware. Unlike standard infostealers, it functions as a comprehensive toolkit for Initial Access Brokers, converting compromised systems into high-value commercial assets. The framework employs modular architecture, advanced evasion techniques, and AI-enhanced reconnaissance capabilities to target corporate, financial, industrial, and law enforcement environments across Iberia and Latin America. It specifically harvests financial transaction files in Brazilian CNAB format, detailed browsing histories, and digital certificates. BraZetsu powers the 'Infected Marketplace' where Exilware commercializes initial access to compromised systems, enabling criminal clients to remotely execute additional malicious payloads. The malware demonstrates rapid technical evolution since February 2026, progressing from basic remote access to an AI-enhanced intelligence collection platform.
Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers
A threat actor compromised three web servers hosting recreation management software for municipalities and parks organizations by exploiting a file upload vulnerability. After multiple failed exploitation attempts, the attacker registered legitimate accounts and abused the member file upload function to deploy webshells. The attacker enumerated systems, extracted database credentials, and targeted payment card data from Fortis webhook logs. User-agent strings indicate Chinese origin, with suspected AI-generated scripts throughout the operation. The adversary adapted tactics across compromises, employing timestomping and file masquerading for defense evasion. When one server returned to production prematurely, the attacker injected a trojanized jQuery file into authentication pages, establishing WebRTC and WebSocket channels for credential harvesting via Cloudflare Workers infrastructure.
August 2026 Threat Trend Report on APT Attacks (South Korea)
During August 2026, multiple APT campaigns targeted South Korean entities primarily through spear phishing attacks utilizing LNK files. Six distinct attack types were identified, employing various techniques including PowerShell scripts, AutoIt programs, and DLL side-loading. Type A used HEX data extraction with PubNub command and control, while Type B leveraged curl.exe to download HTA files from GitHub and Google Drive, deploying infostealers and keyloggers. Type C distributed XenoRAT malware via GitHub repositories. Type D used resume-themed lures with VBS, BAT, and PowerShell scripts for backdoor injection. Type E employed Python-based backdoors through disguised pythonw.exe executables. Type F exploited Hangul documents with embedded OLE objects for malicious DLL loading. Attacks focused on information theft, system control hijacking, and additional malware deployment.
$100k in Crypto Drained by the Underground Operation
A cryptocurrency-stealing operation utilizing an Aotera/Tedy loader injects a Vidar-class stealer into Windows processes, launching Chrome or Edge to inject malicious scripts into victim sessions. The malware builder, dubbed Underground, has been active since October 2023. The operation employs seven gate domains and has drained approximately $100,000 across 80+ destination addresses on 23 blockchain networks from 350-430 victims. The infection begins with lure archives containing trojanized files, deploying a loader that implements anti-analysis checks against 67 monitoring tools. Once injected, the stealer automatically drains cryptocurrency exchange accounts through fake security overlays, converts holdings to Bitcoin, and modifies withdrawal confirmation emails. A clipboard clipper targeting two dozen cryptocurrencies replaces copied wallet addresses with operator-controlled addresses. The operation rotates Cloudflare-fronted domains faster than reputation-based detection can respond.
RemusStealer: EtherHiding In Hidden Windows
RemusStealer is a malware-as-a-service program exhibiting multiple similarities to LummaStealer, including anti-virtual machine checks, credential theft tactics, and Application-Bound Encryption bypass methods. A key distinction is RemusStealer's use of Ethereum smart contracts for C2 communications instead of Steam or Telegram dead drop resolvers. Written in Go, the stealer performs extensive system discovery, gathering information about antivirus products, hardware specifications, and operating systems. It employs hidden desktop environments to evade detection while launching Microsoft Edge and Brave browser processes on non-primary window stations to steal credential files. The malware establishes connections to suspicious domains ending in .shop or .biz and communicates with Ethereum-related infrastructure. This evolution demonstrates attackers' increasing sophistication in leveraging blockchain technology to masquerade malicious communications through smart contracts.
PSIRT
A critical path traversal vulnerability combined with improper NULL byte neutralization in FortiMail versions 7.2 through 8.0 allows unauthenticated attackers to write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. This vulnerability is actively exploited in the wild. Affected versions include FortiMail 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, and 7.2.0-7.2.9. Indicators of compromise include modified system binaries, added malicious libraries, and suspicious archive configurations communicating with external IPs. Organizations should immediately disable the IBE feature or restrict management interface access until patches become available.
TIKTOUK: Tracing a WordPress Credential Collection Toolkit
TIKTOUK is a multi-component toolkit designed to collect credentials from WordPress sites. It consists of three components: a Python probing module that identifies WordPress installations and scans for exposed secrets, a Python collection module that extracts configuration files and database credentials, and a Go-based JavaScript crawler that harvests secrets from client-side code. The toolkit exploits exposed configuration files, decrypts email credentials from popular SMTP plugins using recovered encryption keys, and scans for cloud service credentials. All collected data is sent to a centralized HTTP controller. Real-world incidents revealed approximately 50,000 compromised server credentials across 37,000 domains, including hundreds of validated AWS keys with potential for service abuse.
Fake xStocks, Pendle, and other sites bait crypto users with rewards votes
A large-scale phishing operation has deployed 70 fraudulent websites impersonating legitimate cryptocurrency projects including xStocks from Kraken, Pendle, Zama, Kinetiq, Yield Basis, and Firelight. The fake sites closely replicate authentic platforms and lure visitors with offers to vote on rewards distribution dates in exchange for a 1.25x boost. Upon clicking the vote button, users encounter a wallet connection prompt that ultimately leads to malicious authorization requests designed to drain cryptocurrency tokens. The targeted projects were strategically selected based on recent token launches, airdrops, or active rewards programs, making the phishing attempts appear credible to community members. All malicious domains follow the pattern 'sitemu' followed by random characters on the .xyz domain, suggesting a coordinated campaign using shared infrastructure and phishing kits.
Warlock Ransomware Attackers Hit Water and Telecom Operators
The China-nexus threat group Longlegs continues to deploy Warlock ransomware by exploiting Microsoft SharePoint vulnerabilities, particularly the ToolShell exploit chain. Over the past two months, the group targeted at least four organizations including water utilities, telecommunications providers, government bodies, and universities in Portuguese and Spanish-speaking countries across Europe, Africa, and Latin America. The attackers exploit SharePoint flaws for initial access, use DLL sideloading techniques, abuse vulnerable signed drivers like K7RKScan to disable security software, and leverage Visual Studio Code tunneling for covert remote access. They deploy ransomware at scale by staging payloads in domain SYSVOL shares for rapid network-wide distribution, successfully compromising over 40 hosts in some incidents.
Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles
In July 2026, China-aligned threat actor TA419 conducted credential phishing campaigns impersonating prominent economists and AI policymakers, targeting AI experts at US think tanks, universities, and legal organizations. The group sent benign conversation starter emails themed around AI policy topics, such as invitations to join an AI Policy Advisory Committee. Upon receiving responses, TA419 deployed multi-stage URL redirection chains leading to Adversary-in-the-Middle credential phishing pages using a customized Frameless Browser-in-the-Browser tool. Active since April 2025, TA419 consistently targets individuals at US and Japan-based think tanks, defense contractors, universities, and law firms. This activity likely supports Chinese intelligence objectives to monitor US AI policy and regulatory developments amid strategic competition involving AI technologies, model distillation concerns, and export controls between the US and China.
Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators
CVE-2026-88771 is a critical pre-authentication command-injection vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. LevelBlue's Threat Hunt Operations & Research (THOR) team identified active exploitation across multiple customer environments featuring malicious authentication events with attacker-controlled usernames containing pitboss and NSPPE strings. Observed activities included command-execution testing, payload retrieval using curl and wget, configuration collection and staging, reverse-shell deployment, persistence mechanisms, web-shell installation, and attempted exfiltration of NetScaler configuration data. Analysis revealed two second-stage payloads: main.py establishing reverse shells to command-and-control infrastructure, and update_c08937.pl creating privileged accounts, deploying PHP web shells, and attempting configuration exfiltration. Post-exploitation artifacts included creation of sec_monitor superuser accounts, modification of system binaries, deployment of .local_jou...
PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578
On August 31, 2026, threat actors exploited two zero-day vulnerabilities in PaperCut MF affecting a customer in the Education sector. The attackers targeted an internet-facing print server running vulnerable PaperCut MF version 24.0.2, deploying an in-memory Java loader that established a web shell. Through this web shell, they delivered a trojanized Microsoft Copilot binary containing an AdaptixC2 implant. The implant connected to command-and-control infrastructure hosted on Alibaba servers. After remaining dormant for approximately one day, attackers returned to perform reconnaissance and Active Directory enumeration. They then stole a token from a domain-privileged service account and moved laterally to a domain controller. On the compromised domain controller, they dumped credentials from memory and registry, enabled Windows Restricted Admin mode for pass-the-hash attacks, and extracted the NTDS.dit database containing password hashes for all domain accounts, achieving complete domain compromise.
Swarming Against Citrix 0-Day Exploitation
A malicious cyber actor exploited a Citrix NetScaler Gateway zero-day vulnerability on September 24, 2026, three days before public disclosure. The attacker, using IP address 149.104.78.141, attempted exploitation that was detected through behavioral analysis despite no CVE-specific signatures existing at the time. The exploitation chain aimed to establish persistence through a password-protected webshell, attempting to set setuid and setgid bits on /bin/sh for root access. The attacker tried to configure the web server to execute a hidden PHP webshell disguised as a CSS file, using aliases to route requests. Though unsuccessful in compromising the targeted sensor, the post-exploitation playbook revealed sophisticated techniques for maintaining access and evading detection through web server manipulation.
Star Blizzard refines phishing and malware delivery with the RedFlick technique
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as “RedFlick”. These changes represent a notable shift in the actor’s operational tradecraft and support ongoing cyberespionage activity targeting Ukrainian individuals and institutions as well as international non-government organizations (NGOs), Western think tanks, governments, and other organizations associated with international policy—particularly those with a nexus in supporting Ukraine.
2CLoader: A New Malware Loader Delivering Vidar and Remus
In August 2026, a new loader designated 2CLoader was identified being used to distribute information stealers including Vidar and Remus, along with XWorm RAT. The loader implements extensive anti-analysis capabilities including anti-VM, anti-debug, and user activity checks. It employs sophisticated evasion techniques such as indirect system calls using Hell's Gate technique and inline trampoline hooks to bypass endpoint security detection. The loader stores its configuration and encrypted payload as a PE resource, using rolling XOR and AES-GCM encryption for payload protection. It supports multiple payload execution methods including RunPE, LoadPE, and CLR hosting for .NET assemblies. Network communication with command-and-control servers uses HTTP POST requests with JSON formatted messages encrypted via XOR. Multiple persistence mechanisms are available through registry keys, scheduled tasks, and startup folders.
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Microsoft Threat Intelligence identified active exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in Zimbra Collaboration Suite's SNMP notification path. Exploitation occurred between patch availability on July 20, 2026 and public disclosure on August 13, 2026. Attackers delivered JSP webshells and reverse shells without requiring authentication, achieving privilege escalation through PAM configuration abuse and establishing persistent access via systemd services. Post-exploitation activity included cluster-wide lateral movement using Zimbra SSH keys, collection of authentication secrets and mailbox data, and attempted exfiltration using cloud-storage tools. Multiple organizations across different regions and industries were affected through both automated payload delivery and hands-on-keyboard operations targeting internet-facing Zimbra mail servers.
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
A China-nexus threat cluster designated UAT-11587 has been targeting government and policy organizations across eight Asian countries since September 2025, delivering a previously undocumented Rust-compiled backdoor called Antino. The campaign primarily affected Taiwan, India, Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria through sophisticated spear-phishing operations using tailored political and diplomatic lures. The multi-stage infection chain leverages Cloudflare infrastructure for delivery and deploys Antino, which uniquely uses Microsoft 365 services—specifically Outlook and OneDrive—as dead-drop command-and-control channels rather than traditional C2 servers. The backdoor supports reconnaissance, command execution, file transfer, shellcode loading, and persistence establishment. Attribution to Chinese nexus is based on metadata containing Simplified Chinese artifacts, UTC+8 timestamps, use of China-focused Rust package mirrors, and targeting patterns consistent with Chinese intellige...
Phishing Abuses RMM Tools for Persistent Access
In July 2026, phishing campaigns targeted organizations across multiple industries by distributing a masqueraded MSP360 Remote Monitoring and Management installer through meeting invitations, PDF-themed lures, and software update prompts. Once executed, the legitimate MSP360 installer established remote management access on affected devices, providing threat actors with an initial foothold using trusted administrative software. The MSP360 deployment was then used to download and install a ConnectWise ScreenConnect client, creating a secondary remote-access channel for redundant access to compromised systems. Following access establishment, threat actors deployed additional tools and conducted post-compromise activity, including information collection and credential-access operations. The campaigns utilized multiple delivery mechanisms including actor-controlled domains, compromised websites, and legitimate cloud services such as Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase.
New PamStealer variant targets macOS via fake crypto wallet
A third variant of PamStealer has been identified, distributed through a fake Wavel cryptocurrency wallet application. The malware employs a sophisticated server-side decryption chain using a purpose-built utility called pkgunpack that performs live ECIES key exchange with command-and-control infrastructure, making offline payload decryption impossible. The second stage has been rewritten from Rust to Swift while maintaining PAM-based credential validation. The infostealer targets seventeen browsers including Arc, Zen, Waterfox, and LibreWolf, extracts keychain credentials, collects system fingerprints, and harvests user files including shell history and account photos via Open Directory. Persistence is maintained through four redundant repair mechanisms including LaunchAgent installation, shell hooks, Git hooks, and a local backup tarball, with notification suppression achieved by killing background task management processes.
From Registry-Stored PowerShell to In-Memory Cryptocurrency Mining: A Multi-Stage Infection Chain
A sophisticated multi-stage infection chain was discovered through analysis of a system exhibiting frequent PowerShell execution alerts. The attack leveraged multiple layers of obfuscation and concealment techniques, including Registry-based payload storage, DNS TXT record exploitation, and data hidden within image and WAV audio files. The threat actors employed various evasion methods such as security control tampering and in-memory execution to avoid detection. Rather than writing payloads directly to disk, attackers reconstructed malicious code from distributed sources including Registry entries and steganographically encoded data in media files. The ultimate objective of this elaborate infection chain was to deploy cryptocurrency mining operations covertly on compromised systems while maintaining persistent access through multiple redundant mechanisms.
PAYLOAD ransomware attacks through Active Directory GPO
In April 2026, a manufacturing organization in the Middle East suffered a ransomware attack where threat actors with domain admin privileges weaponized Active Directory Group Policy Objects to achieve domain-wide impact without deploying ransomware binaries on Windows endpoints. The attackers created malicious GPOs linked at the domain root, delivering ransom notes, hijacking wallpapers and lock screens, enforcing logon banners, and disabling local administrator accounts across all domain-joined workstations. No file encryption occurred on Windows systems; instead, the operation focused on encryptionless extortion through operational disruption and data exfiltration. Initial access was gained via compromised VPN credentials. The attack remained dormant for one day between GPO creation and detonation, evading file-based detection entirely by abusing trusted AD infrastructure.
Don't Call Us, We'll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties
In 2026, the DPRK-sponsored Lazarus subgroup TraderTraitor continued campaigns targeting cryptocurrency entities, including a high-profile attack on LayerZero resulting in $292 million theft from KelpDAO. Following this disclosure, an additional victim was identified: a smaller IT services provider in India with no cryptocurrency connections. The compromise involved a DevOps engineer targeted through fake job interview lures containing weaponized Terraform coding projects. Malicious GitHub repositories used typosquatted provider domains to deliver macOS backdoors FLATROOF and ROOFDECK when victims executed terraform init. The backdoors enabled reconnaissance, credential theft, and cloud environment escalation. One day after LayerZero's public disclosure, attackers deployed an updated stripped version of ROOFDECK and removed earlier implants. Activity continued until June 2026, suggesting the threat actor ultimately abandoned the intrusion after determining insufficient value from the smaller target.
ChainScript: Tracing a Node.js RAT Through the Blockchain
Blackpoint's Adversary Pursuit Group identified ChainScript, a previously unnamed Node.js remote access trojan discovered during ClickFix investigation. The malware disguises itself as legitimate software including Spotify, Zoom Workplace, and Microsoft Teams through malicious Windows Installer packages. ChainScript employs an EtherHiding-style C2 discovery technique utilizing a Polygon smart contract to dynamically locate active WebSocket infrastructure, enabling operators to rotate backend services without rebuilding agents. The RAT provides comprehensive remote access capabilities including interactive shell sessions, file operations, screenshots, payload deployment, cryptocurrency wallet discovery, remote JavaScript execution, self-update mechanisms, and cleanup functions. Multiple builds appeared under different names (ComponentTask33, UpdateDigital, HostShared, OrchidViolet66) while maintaining consistent core agent architecture. Analysis revealed automated contract deployment integrated into the mal...
Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company
ESET researchers uncovered a Lazarus attack against a Spanish aerospace company where attackers masqueraded as Meta recruiters on LinkedIn, sending trojanized coding challenges to employees. The campaign deployed multiple tools including LightlessCan, a previously undocumented backdoor that mimics native Windows commands to evade detection. Initial access was achieved through spearphishing via LinkedIn Messaging, delivering malicious executables disguised as C++ programming tests. The attack chain involved DLL side-loading techniques delivering payloads including NickelLoader downloader, miniBlindingCan variant, and the sophisticated LightlessCan RAT supporting 68 commands. LightlessCan represents a significant advancement over its predecessor BlindingCan, implementing execution guardrails and enhanced stealth capabilities. The campaign targeted aerospace technology and know-how for cyberespionage purposes, consistent with North Korean strategic objectives in missile development.
WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials
A new JavaScript infostealer dubbed WeaselBiscuit has been discovered hidden in 11 malicious npm packages. This lean malware shares operational similarities with DPRK-linked BeaverTail and OtterCookie families but features a stripped-down architecture. WeaselBiscuit deploys through npm imports, executes a detached Node process, retrieves its payload from Npoint URLs, and communicates with a C2 server at 103.170.217.184:8787. The malware profiles infected hosts, steals Chrome extension storage containing wallet signing states, captures clipboard contents, and logs Windows keystrokes when commanded. Unlike its predecessors, it lacks wallet-draining code, browser password decryption, Python second stages, screenshots, and remote shell capabilities. The operation uses numeric campaign identifiers embedded in package names for tracking. While technical overlap suggests DPRK attribution, particularly through Npoint dead-drop patterns and nested IP geolocation lookups, definitive attribution requires additional c...
Private HTS programs that spread ransomware
Fraudulent organizations in Korea are exploiting private Home Trading System (HTS) software to distribute ransomware to victims. The unauthorized HTS program called 'UBP Asset' impersonates the legitimate Swiss financial institution Union Bancaire Privee (UBP) and has been used in investment scams since at least September 2025. Attackers lure victims through social media platforms like Telegram and KakaoTalk, convincing them to install the fraudulent HTS and deposit funds. The latest campaign involves distributing KRSID ransomware through the HTS update mechanism, which encrypts files using AES-256 and RSA-2048 algorithms. Previous campaigns used similar private HTS programs to distribute Quasar RAT. Victims not only lose their investment funds but also have their systems compromised and files encrypted for ransom demands.
EtherHiding Exposed: Inside a Blockchain-powered Malware Campaign Hiding in Plain Sight
A sophisticated malware campaign active since November 2025 exploits blockchain technology to maintain persistent command-and-control infrastructure. Attackers store C2 addresses in Polygon blockchain smart contracts rather than hardcoding them, enabling rapid infrastructure rotation for pennies. The operation compromised at least 31 legitimate websites across multiple countries, deploying FakeCaptcha lures through compromised sites accessed via Bing or Google searches. When victims follow the lure, malware establishes persistence through scheduled tasks and registry keys, queries Polygon smart contracts for current C2 domains, and deploys versatile payloads including banking trojans targeting 479 financial and cryptocurrency domains. Investigators identified 15 smart contracts across six operational waves, three active C2 domains, and two operator wallets controlling the infrastructure. The campaign demonstrates significant operational security with multiple fallback mechanisms, though investigators succe...
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
PolinRider operators compromised a GitHub account to insert malicious code into development versions of visanduma/nova-two-factor, a Packagist package with over 700,000 downloads. The campaign spreads through compromised developer accounts and Git repositories across multiple ecosystems including npm, PyPI, Go modules, Packagist, and Chrome extensions. The operators use Git history rewriting, payload concealment in configuration files and font files, automatic execution through IDE tasks, and staged payload delivery via dead-drop mechanisms like EtherHiding and NullReceiver. Primary infection occurs through Git-based collaboration rather than direct package registry compromise, with PHP projects targeted using obfuscated JavaScript executed through shell_exec. The campaign appears linked to North Korean operators focused on cryptocurrency theft.
LabubaRAT Threat Snapshot
LabubaRAT is a custom, unsigned 64-bit Rust-based remote access trojan identified by Blackpoint, designed to masquerade as legitimate NVIDIA software. It provides comprehensive remote access capabilities including command execution, file operations, screen capture, and SOCKS5 proxying. The malware features configurable enrollment fields and an internal ZM_ configuration namespace, suggesting it is built on a reusable, multi-tenant framework consistent with a malware-as-a-service offering. LabubaRAT is managed through an associated backend infrastructure called LabubaPanel, hosted on German providers. The delivery mechanism utilized the RAT's own JavaScript execution capability. First observed in July 2026, it targets Windows platforms and employs various evasion techniques including masquerading as NVIDIA components and abusing legitimate Microsoft build utilities.
BlackCore’s Influence Operations for Hire
An Israeli influence-for-hire company called BlackCore has been identified conducting digital manipulation campaigns across multiple countries. The company operates through a sophisticated infrastructure offering services including discourse dominance, organic engagement manipulation, and counter-operations. Researchers identified a specific campaign involving a 14-week training program delivered to Angolan government employees in early 2026, which included the creation and deployment of fake social media personas and coordinated inauthentic behavior. The operation utilized AI-generated profile pictures, fake news outlets like 'Agita News', and coordinated amplification tactics across Facebook, Instagram, and TikTok. BlackCore's promotional materials openly advertised their capabilities to conduct deceptive influence operations on behalf of government clients, demonstrating how influence-for-hire services have become accessible to state actors seeking to manipulate online discourse.
HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack
Analysis reveals HEAVYGRAM, a multi-stage Windows backdoor attributed to Iran-linked threat actor Handala Hack, deployed since Fall 2023 targeting Iranian dissidents, journalists, and government opponents. The surveillance tool uses Telegram bot API for command-and-control operations, enabling remote command execution, screen capture, data exfiltration, and persistent access. Victims receive social-engineered files masquerading as legitimate applications like Telegram, KeePass, or Pictory. The implant supports DLL side-loading, registry persistence, and system reconnaissance. Infrastructure analysis identified 29 samples utilizing networks of Telegram bots and groups for operations. The malware aligns with activity disclosed by U.S. Department of Justice regarding Iran's Ministry of Intelligence and Security infrastructure seizures, with tradecraft including Vultr Object Storage and Persian-language decoys targeting specific victim profiles including academics and media personnel.
Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
A significant supply chain attack compromised Brevo's infrastructure on September 14, 2026, affecting over 100,000 customer websites. Attackers injected malicious code into Brevo's JavaScript assets and widgets, delivering two distinct payloads: a WordPress plugin backdoor automatically installed when site administrators visited their own sites while logged in, and ClickFix overlays targeting regular visitors. The attack vector involved modification of Brevo's CDN-hosted files and creation of malicious subdomains under sendibt1.com. Evidence suggests attackers gained access to Brevo's Cloudflare account, allowing them to modify DNS records and rewrite content dynamically. The malicious activity lasted approximately four hours, from 16:05 to 20:12 UTC. Brevo's prominent clients include eBay, Louis Vuitton, Michelin, and Amnesty International, amplifying the attack's potential impact significantly.
T-Mobile rewards points expiry texts are a phishing scam
Since early May 2026, a large-scale phishing campaign has targeted individuals with fraudulent text messages claiming their T-Mobile rewards points are about to expire. The messages create urgency by stating that point balances, typically cited as 18,400 points, will expire imminently if not redeemed. Recipients are directed to click on phishing links using rotating domains designed to mimic legitimate T-Mobile websites. The campaign has generated over 1,000 closely related message templates with only superficial variations in salutations, dates, and point balances. The operation experienced two major spikes in activity before declining. The criminals employed at least 81 domains over four months, all following a recognizable pattern. These messages use generic greetings and formal language to appear legitimate, exploiting social engineering tactics to trick recipients into divulging login credentials, personal information, or payment details.
The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
A previously unknown modular multi-stage framework named MovieReaper has been discovered targeting users through compromised torrent files. Attackers compromised the public torrent repository itorrents[.]org, enabling them to distribute malicious loaders disguised as popular movies, including "The Odyssey." The campaign began in mid-August 2026 and affected hundreds of victims across multiple countries. The malware employs a sophisticated infection chain with fileless execution, utilizing blockchain network Solana for C2 infrastructure resilience. The framework includes multiple stages: an initial loader with anti-sandbox checks, shellcode that retrieves C2 addresses from Solana blockchain, UAC bypass with persistence mechanisms, and a final file manager module providing comprehensive file system access. The campaign demonstrates advanced evasion techniques including manual API resolution, vectored exception handling, and in-memory execution.
Beware the SparroWock: The backdoor that bites, the commands that catch
ESET researchers have documented SparroWocky, a sophisticated C++ backdoor deployed by the FamousSparrow APT group since August 2025. This China-aligned threat actor has shifted focus to extensively targeting governmental organizations across Latin America, likely in response to increased US interest in the region. SparroWocky replaced the group's previous SparrowDoor backdoor and demonstrates advanced capabilities including reflective loading, anti-analysis techniques like SilentMoonwalk for call stack spoofing, and the ability to execute Beacon Object Files. The modular backdoor incorporates open-source projects directly into its codebase, uses TLS-encrypted communications with RC4 encryption for data exfiltration, and employs sophisticated evasion methods including MinHook API hooking and custom PE loading with host process camouflage. The targeting pattern reflects China's strategic interest in monitoring Latin American governmental responses to current US pressures regarding investments and infrastruc...
Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM
Settra is a ransomware variant first observed in June 2026 that targets organizations through VPNs or compromised credentials. Two incidents were investigated in July and September 2026, affecting the consumer services, retail, and manufacturing sectors. Attackers deployed MeshAgent RMM for persistence, naming ransomware executables after victim domain names. The malicious activity included file encryption with .locked or .locked_wip extensions, deployment of RESTORE_FILES.txt ransom notes, clearing Windows event logs, and disabling Windows recovery options using reagentc and diskpart utilities. One incident featured Bring Your Own Vulnerable Driver (BYOVD) tactics using gdrv.sys. A notable operational security failure occurred when attackers misspelled the Windows Defender Event Log path, preventing its deletion. Both attacks followed remarkably similar operational patterns, with MeshAgent installations pointing to different C2 IP addresses (45.13.122[.]7 and 193.5.65[.]114), and malicious workstation WIN...
Discernment Deleted: Inside the Operation Server of BlackHatSect0r && DXQRTXX
A French-speaking cybercrime crew operating as BlackHatSect0r && DXQRTXX left an operation server exposed, revealing a custom Go command-and-control platform that harvested 16,834 credentials from 726,989 hosts across 2.7 million queued domains. The operator deliberately removed safety controls from a Nous Research Hermes AI agent, deleting the line "discernment retained" from its memory and replacing it with "I am a weapon." This enabled automated campaigns targeting French government institutions, including the Equestrian Federation and National Mountain Observation System, alongside extortion operations against four New York public bodies, cryptocurrency exchange breaches, and vishing campaigns against elderly French banking customers. Despite branding itself as a zero-day operation, all confirmed breaches resulted from exposed cloud storage, readable .env files, and default signing secrets rather than novel exploits. The crew operates openly on Telegram with 13 declared members and maintains public all...
SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia
Infrastructure analysis reveals a cluster of SpiceRAT command and control servers active from late 2025 through August 2026, linked through shared TLS certificates, domain registrations, and a cloned RTX Corporation webpage. The infrastructure connects to multiple threat families including SpiceRAT, NodeEdgeRAT, NomadRAT, and BloodAlchemy, suggesting either a single operator managing multiple toolsets or shared support infrastructure. A TLS certificate impersonating Uzbekistan's railway authority was issued by TLC, a Chinese state-affiliated certificate authority. Domains spoof Central Asian government entities including Türkmengaz, the Galkynysh gas field, Tojiktelecom, and Turkmenistan's Ministry of Foreign Affairs. Passive DNS analysis reveals subdomain infrastructure dating to mid-2022, indicating at least four years of ongoing operations. The infrastructure shares characteristics with previously documented China-nexus actors FamousSparrow and IndigoZebra, both known for targeting Central Asian governm...
VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch
VectraRAT is a previously undocumented Malware-as-a-Service platform combining a Go-based control server (VectraHub) with a native C++ Windows implant, renting from $250 monthly. The developer, operating under the handle 'Vectra' (formerly 'Nyxel'), has been active since August 2022 without prior public documentation. The platform offers hidden desktop control, keylogging, clipboard hijacking with cryptocurrency address replacement, browser credential theft, and a UAC bypass achieving elevation without user prompts. Delivered through Amadey loader and ClickFix campaigns targeting tax-themed lures, 48% of observed victims run corporate Windows editions including Windows Server 2025. Infrastructure analysis revealed exposed directories and operational panels across multiple hosting providers, with victims spanning the United States, Russia, Germany, and other nations.
Noodle RAT: A Recipe for Cross Platform Espionage
Noodle RAT, also known as ANGRYREBEL or Nood RAT, is a modular remote access trojan with dual versions for Windows and Linux, actively used by Chinese-speaking threat actors since at least mid-2016. Previously misclassified as variants of Gh0st RAT or Rekoobe, it is now recognized as a distinct backdoor family. The malware has been deployed in espionage and cybercrime campaigns targeting entities across the Asia-Pacific region, including Thailand, India, Japan, Malaysia, and Taiwan. Multiple threat groups including Iron Tiger, Calypso APT, Rocke, and Cloud Snooper have utilized this tool. Both variants feature shared command-and-control architecture, similar configuration structures, and modular capabilities. The Windows version operates as an in-memory backdoor with file management and proxy capabilities, while the Linux variant provides reverse shell, SOCKS tunneling, and task scheduling functionalities. Evidence suggests an actively maintained, possibly commercial malware toolkit.
Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
In August 2026, the Pakistan-nexus threat actor APT36 launched Operation RapidRust, targeting government and defense organizations in India and Afghanistan with an updated arsenal of custom tools. The campaign introduced RUSTYSHADE, a Rust-based backdoor leveraging private GitHub repositories for command-and-control with AES-256-GCM encryption. Additional tools included RUSTYMOVE for USB-based lateral movement to air-gapped networks, PSNATCH and BASHNATCH for file exfiltration from Windows and Linux systems respectively. The attackers registered typosquatted domains impersonating Indian news outlets to stage malicious PowerShell scripts. Post-compromise activities revealed systematic network reconnaissance, credential harvesting, and lateral movement attempts, with operations conducted exclusively on weekdays between 4:00-11:00 UTC, demonstrating disciplined operational security and sustained targeting of South Asian government infrastructure.
Stealth Mango and Tangelo
This threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense secto…
1937CN
1937CN is a Chinese hacking group that has been active since at least 2013. The group is known for targeting Vietnamese organizati…
313 Team
313 Team is an Iraq-based threat actor that has conducted coordinated DDoS campaigns targeting multiple government servers in the …
APT-C-27
A threat actor which is ac tive since at least November 2014. This group launched long-term at tacks against organizations in the …
APT.3102
APT1
PLA Unit 61398 (Chinese: 61398部队, Pinyin: 61398 bùduì) is the Military Unit Cover Designator (MUCD)[1] of a People's Liberation Ar…
APT10
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in ass…
APT12
A group of China-based attackers, who conducted a number of spear phishing attacks in 2013.
APT14
PLA Navy Anchor Panda is an adversary that CrowdStrike has tracked extensively over the last year targeting both civilian and mili…
APT15
This threat actor uses phishing techniques to compromise the networks of foreign ministries of European countries for espionage pu…
APT16
Between November 26, 2015, and December 1, 2015, known and suspected China-based APT groups launched several spear-phishing attack…
APT17
FireEye described APT17 in a 2015 report as: 'APT17, also known as DeputyDog, is a China based threat group that FireEye Intellige…
APT18
Wekby was described by Palo Alto Networks in a 2015 report as: 'Wekby is a group that has been active for a number of years, targe…
APT19
Adversary group targeting financial, technology, non-profit organisations.
APT2
Putter Panda were the subject of an extensive report by CrowdStrike, which stated: 'The CrowdStrike Intelligence team has been tra…
APT20
We’ve uncovered some new data and likely attribution regarding a series of APT watering hole attacks this past summer. Watering ho…
APT21
APT22
Suckfly is a China-based threat group that has been active since at least 2014
APT23
TrendMicro described Tropic Trooper in a 2015 report as: 'Taiwan and the Philippines have become the targets of an ongoing campaig…
APT24
The Pitty Tiger group has been active since at least 2011. They have been seen using HeartBleed vulnerability in order to directly…
APT26
APT27
A China-based actor that targets foreign embassies to collect data on government, defence, and technology sectors.
APT28
The Sofacy Group (also known as APT28, Pawn Storm, Fancy Bear and Sednit) is a cyber espionage group believed to have ties to the …
APT29
A 2015 report by F-Secure describe APT29 as: 'The Dukes are a well-resourced, highly dedicated and organized cyberespionage group …
APT3
Symantec described UPS in 2016 report as: 'Buckeye (also known as APT3, Gothic Panda, UPS Team, and TG-0110) is a cyberespionage …
APT30
APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT3…
APT31
FireEye characterizes APT31 as an actor specialized on intellectual property theft, focusing on data and projects that make a part…
APT32
Cyber espionage actors, now designated by FireEye as APT32 (OceanLotus Group), are carrying out intrusions into private sector com…
APT33
Our analysis reveals that APT33 is a capable group that has carried out cyber espionage operations since at least 2013. We assess …
APT35
FireEye has identified APT35 operations dating back to 2014. APT35, also known as the Newscaster Team, is a threat group sponsored…
APT37
APT37 has likely been active since at least 2012 and focuses on targeting the public and private sectors primarily in South Korea.…
APT39
APT39 was created to bring together previous activities and methods used by this actor, and its activities largely align with a gr…
APT4
APT40
Leviathan is an espionage actor targeting organizations and high-value targets in defense and government. Active since at least 20…
APT41
APT41 is a prolific cyber threat group that carries out Chinese state-sponsored espionage activity in addition to financially moti…
APT42
Iranian state-sponsored cyber espionage group tasked with conducting information collection and surveillance operations against in…
APT45
APT45 is a North Korean cyber threat actor that has been active since at least 2009. They have conducted espionage campaigns targe…
APT5
We have observed one APT group, which we call APT5, particularly focused on telecommunications and technology companies. More than…
APT6
The FBI issued a rare bulletin admitting that a group named Advanced Persistent Threat 6 (APT6) hacked into US government computer…
APT9
APT9 engages in cyber operations where the goal is data theft, usually focusing on the data and projects that make a particular or…
APTIran
APTIran has claimed responsibility for a large-scale campaign targeting Israeli critical infrastructure, asserting infiltration of…
Ababil of Minab
Ababil of Minab is an emerging pro-Iranian hacktivist group with a limited public profile and little verifiable prior activity in …
Altahrea Team
Altahrea Team is a pro-Iranian hacking group that has been active since at least 2020. The group has claimed responsibility for a …
Amaranth-Dragon
Amaranth-Dragon is a previously untracked threat actor assessed to be closely linked to the China-affiliated APT 41 ecosystem, exh…
Amethyst Rain
Microsoft threat actor profile. Origin/Threat: Lebanon.
Angry Likho
Angry Likho is an APT group that has been active since 2023, primarily targeting large organizations and government agencies in Ru…
Anonymous64
Anonymous 64 is a group accused by China's national security ministry of attempting to gain control of web portals, outdoor electr…
Antlion
Antlion is a Chinese state-backed advanced persistent threat (APT) group, who has been targeting financial institutions in Taiwan.…
Aoqin Dragon
SentinelLabs has uncovered a cluster of activity beginning at least as far back as 2013 and continuing to the present day, primari…
AppMilad
AppMilad is an Iranian hacking group that has been identified as the source of a spyware campaign called RatMilad. This spyware is…
AridViper
AridViper is a state-sponsored APT primarily targeting military personnel, journalists, and dissidents in the Middle East, with a …
Aslan Neferler Tim
Turkish nationalist hacktivist group that has been active for roughly one year. According to Domaintools, the group’s site has bee…
Avivore
The group’s existence came to light during Context’s investigation of a number of attacks against multinational enterprises that c…
Ayyıldız Tim
Ayyıldız (Crescent and Star) Tim is a nationalist hacking group founded in 2002. It performs defacements and DDoS attacks against …
AzzaSec
AzzaSec is a hacktivist group that originated in Italy. Known for their pro-Palestine stance, they have been involved in various c…
BANISHED KITTEN
BANISHED KITTEN is an Iranian state-nexus adversary active since at least 2008. While the adversary’s most prominent activity is t…
BIG PANDA
BRONZE EDGEWOOD
In early 2021 CTU researchers observed BRONZE EDGEWOOD exploiting the Microsoft Exchange Server of an organization in Southeast As…
BRONZE HIGHLAND
BRONZE HIGHLAND has been observed using spearphishing as an initial infection vector to deploy the MgBot remote access trojan agai…
BRONZE SPIRAL
In December 2020, the IT management software provider SolarWinds announced that an unidentified threat actor had exploited a vulne…
BRONZE SPRING
BRONZE SPRING is a threat group that CTU researchers assess with high confidence operates on behalf of China in the theft of intel…
BRONZE STARLIGHT
BRONZE STARLIGHT has been active since mid 2021 and targets organizations globally across a range of industry verticals. The group…
BRONZE VAPOR
BRONZE VAPOR is a targeted threat group assessed with moderate confidence to be of Chinese origin. Artefacts from tools associated…
BatShadow
BatShadow is a Vietnamese threat actor that targets job seekers and digital marketing professionals through social engineering cam…
Bearlyfy
Bearlyfy has been attributed to over 70 cyber attacks targeting Russian companies since its emergence in January 2025, employing a…
Beijing Group
BiBiGun
A pro-Hamas hacktivist group developed a wiper called BiBi-Linux to target and destroy data on Israeli systems. The malware impers…
Bignosa
Bignosa is a threat actor known for launching malware campaigns targeting Australian and US organizations using phishing emails wi…
BlackJack
Blackjack, a threat actor linked to Ukraine's security apparatus, has targeted critical Russian entities such as ISPs, utilities, …
BlackTech
BlackTech is a cyber espionage group operating against targets in East Asia, particularly Taiwan, and occasionally, Japan and Hong…
Blackatom
Recent campaigns suggest Hamas-linked actors may be advancing their TTPs to include intricate social engineering lures specially c…
Blackgear
BLACKGEAR is an espionage campaign which has targeted users in Taiwan for many years. Multiple papers and talks have been released…
Blackmeta
BLACKMETA is a pro-Palestinian hacktivist group that has claimed responsibility for a series of DDoS attacks and data breaches tar…
Blackwood
Blackwood is a China-aligned APT group that has been active since at least 2018. They primarily engage in cyberespionage operation…
BladedFeline
BladedFeline is an Iran-aligned APT group that has been active since at least 2017, targeting Iraqi and Kurdish government officia…
Blue Termite
Blue Termite is a group of suspected Chinese origin active in Japan.
Blue Tsunami
Blue Tsunami, also known as Black Cube, is a cyber mercenary group associated with the private intelligence firm Black Cube. They …
Bohrium
Bohrium is an Iranian threat actor that has been involved in spear-phishing operations targeting organizations in the US, Middle E…
Boulder Bear
First observed activity in December 2013.
BrazenBamboo
BrazenBamboo is a Chinese state-affiliated threat actor known for developing the LIGHTSPY, DEEPDATA, and DEEPPOST malware families…
Budminer
Based on the evidence we have presented Symantec attributed the activity involving theDripion malware to the Budminer advanced thr…
BuhTrap
Buhtrap has been active since 2014, however their first attacks against financial institutions were only detected in August 2015. …
CIRCUS SPIDER
According to Crowdstrike, the NetWalker ransomware is being developed and maintained by a Russian-speaking actor designated as CIR…
CL-STA-0043
CL-STA-0043 is a Chinese state-nexus cyber-espionage actor tracked by Palo Alto Networks Unit 42, which promoted the activity clus…
CL-STA-0048
CL-STA-0048 is a Chinese state-backed APT that targets strategic sectors in South Asia, particularly government and telecommunicat…
CL-STA-1087
CL-STA-1087 is a suspected state-sponsored espionage campaign operating out of China, targeting military organizations in Southeas…
CL-UNK-1068
CL-UNK-1068 is a Chinese threat actor that has targeted critical infrastructure in Asia, primarily focusing on cyberespionage. The…
Cadelle
Symantec telemetry identified Cadelle and Chafer activity dating from as far back as July 2014, however, it’s likely that activity…
Callisto
The Callisto Group is an advanced threat actor whose known targets include military personnel, government officials, think tanks, …
Calypso
For the first time, the activity of the Calypso group was detected by specialists of PT Expert Security Center in March 2019, duri…
Camaro Dragon
In early 2023, the Check Point Incident Response Team (CPIRT) team investigated a malware incident at a European healthcare instit…
CardinalLizard
CardinalLizard, a cyber threat actor linked to China, has targeted entities in Asia since 2018. Their methods include spear-phishi…
Careto
This threat actor targets governments, diplomatic missions, private companies in the energy sector, and academics for espionage pu…
Carmine Tsunami
Carmine Tsunami is a threat actor linked to an Israel-based private sector offensive actor called QuaDream. QuaDream sells a platf…
Cavern Manticore
Cavern Manticore is an Iran-nexus APT primarily targeting Israeli organizations in the government and IT sectors, linked to the MO…
CeranaKeeper
CeranaKeeper is a China-aligned APT that has been active since at least early 2022, primarily targeting governmental institutions …
Charming Kitten
Charming Kitten (aka Parastoo, aka Newscaster) is an group with a suspected nexus to Iran that targets organizations involved in g…
Chaya_004
Chaya_004 is a Chinese threat actor identified through malicious infrastructure, including a network of servers hosting Supershell…
Chernovite
Chernovite is a highly capable and sophisticated threat actor group that has developed a modular ICS malware framework called PIPE…
Cleaver
A group of cyber actors utilizing infrastructure located in Iran have been conducting computer network exploitation activity again…
Clever Kitten
Conference Crew
Conference Crew is a China-nexus threat cluster renamed CONFERENCE CASTLE under Google Threat Intelligence's updated naming system…
Confucious
Confucius is an APT organization funded by India. It has been carrying out cyber attacks since 2013. Its main targets are India's …
CopyKittens
CoralRaider
CoralRaider is a financially motivated threat actor of Vietnamese origin, targeting victims in Asian and Southeast Asian countries…
Corsair Jackal
Cotton Sandstorm
Cotton Sandstorm is an Iranian threat actor involved in hack-and-leak operations. They have targeted various organizations, includ…
Cuboid Sandstorm
Cuboid Sandstorm is an Iranian threat actor that targeted an Israel-based IT company in July 2021. They gained access to the compa…
Curious Gorge
Curious Gorge, a group TAG attributes to China's PLA SSF, has conducted campaigns against government and military organizations in…
Curly COMrades
Curly COMrades is a threat actor identified by Amazon Threat Intelligence and Bitdefender, believed to operate in support of Russi…
Cutting Kitten
One of the threat actors responsible for the denial of service attacks against U.S in 2012–2013. Three individuals associated with…
Cyber Alliance
The Ukrainian Cyber Alliance is a pro-Ukraine hacktivist group formed in 2016, primarily targeting Russian entities since the inva…
Cyber Av3ngers
Cyber Av3ngers is an Iranian IRGC Cyber-Electronic Command-affiliated threat actor that targets internet-exposed operational techn…
Cyber Berkut
Cyber Islamic Resistance
Cyber Islamic Resistance is a hacktivist collective ideologically aligned with Iran, engaging in operations such as website deface…
Cyber Partisans
The Cyber Partisans, a hacktivist group based in Belarus, has been involved in various cyber-attacks targeting organizations and i…
Cyber Serp
UAC-0255 is a threat actor that conducted a phishing campaign impersonating CERT-UA to distribute the AGEWHEEZE RAT, targeting org…
Cyber Toufan
Cyber Toufan is a threat actor group that has gained prominence for its cyberattacks targeting Israeli organizations. The group's …
Cyber fighters of Izz Ad-Din Al Qassam
Cyber.Anarchy.Squad
Cyber Anarchy Squad is a pro-Ukrainian hacktivist group known for targeting Russian companies and infrastructure. They have carrie…
DAGGER PANDA
Operate since at least 2011, from several locations in China, with members in Korea and Japan as well. Possibly linked to Onion D…
DEV-0147
DEV-0147 is a China-based cyber espionage actor was observed compromising diplomatic targets in South America, a notable expansion…
DEV-0270
Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also…
DEV-0586
MSTIC has not found any notable associations between this observed activity, tracked as DEV-0586, and other known activity groups.…
Dalbit
The group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and de…
Dark Caracal
Lookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal, a persistent and prolific actor, who at the time of…
DarkHotel
Kaspersky described DarkHotel in a 2014 report as: '... DarkHotel drives its campaigns by spear-phishing targets with highly advan…
Deadeye Jackal
The Syrian Electronic Army (SEA) is a group of computer hackers which first surfaced online in 2011 to support the government of S…
Denim Tsunami
Denim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers. …
DiceyF
DiceyF is an advanced persistent threat group that has been targeting online casinos and other victims in Southeast Asia for an ex…
Domestic Kitten
An extensive surveillance operation targets specific groups of individuals with malicious mobile apps that collect sensitive infor…
DragonForce
DragonForce is a hacktivist group based in Malaysia that has been involved in cyberattacks targeting government institutions and c…
DragonOK
Threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tool…
DragonSpark
DragonSpark is a threat actor that has been conducting attacks primarily targeting organizations in East Asia. They utilize the op…
Dragonbridge
DRAGONBRIDGE is a Chinese state-sponsored threat actor known for engaging in information operations to promote the political inter…
DriftingCloud
DriftingCloud is a persistent threat actor known for targeting various industries and locations. They are skilled at developing or…
DustSquad
Prodaft researchers have published a report on Paperbug, a cyber-espionage campaign carried out by suspected Russian-speaking grou…
ELECTRIC PANDA
ELOQUENT PANDA
ELUSIVE COMET
ELUSIVE COMET is a threat actor responsible for significant cryptocurrency theft through sophisticated social engineering attacks,…
ENERGETIC BEAR
A Russian group that collects intelligence on the energy industry.
Earth Alux
Earth Alux is a China-linked APT group known for conducting cyberespionage attacks across various sectors, including government, t…
Earth Baxia
Earth Baxia is a threat actor opearting out of China, targeting government organizations in Taiwan and potentially across the APAC…
Earth Berberoka
According to TrendMicro, Earth Berberoka is a threat group originating from China that mainly focuses on targeting gambling websit…
Earth Freybug
Earth Freybug, identified as a subset of APT41, is a cyberthreat group active since at least 2012, engaging in espionage and finan…
Earth Krahang
Earth Krahang is an APT group targeting government organizations worldwide. They use spear-phishing emails, weak internet-facing s…
Earth Lamia
Earth Lamia is a China-nexus APT that targets organizations across multiple sectors, including finance, logistics, and government,…
Earth Lusca
Earth Lusca is a threat actor from China that targets organizations of interest to the Chinese government, including academic inst…
Earth Naga
Earth Naga is an APT group that has persistently targeted high-value organizations, including government agencies, telecommunicati…
Earth Wendigo
Earth Wendigo is a threat actor from China that has been targeting several organizations — including government organizations, res…
Edalat-e Ali
Edalat-e Ali is a hacktivist group known for disrupting Iranian state-run TV and radio transmissions during significant events, su…
Educated Manticore
Educated Manticore is an Iranian APT group aligned with the Islamic Revolutionary Guard Corps, primarily engaged in espionage targ…
Equation Group
The Equation Group is a highly sophisticated threat actor described by its discoverers at Kaspersky Labs as one of the most sophis…
Evasive Panda
Evasive Panda is an APT group that has been active since at least 2012, conducting cyberespionage targeting individuals, governmen…
EvilWeb
EvilWeb is a pro-Russian hacktivist group created in March 2024 that targets American and European entities using a hack-and-leak …
Exilware
Exilware is a Brazilian threat actor operating the "Infect Marketplace," which commercializes access to compromised systems using …
FIN1
FireEye first identified this activity during a recent investigation at an organization in the financial industry. They identified…
FIN13
Since 2017, Mandiant has been tracking FIN13, an industrious and versatile financially motivated threat actor conducting long-term…
FIN7
Groups targeting financial organizations or people with significant financial assets.
FOXY PANDA
Adversary group targeting telecommunication and technology organizations.
Femwar02
Femwar02 is a previously unknown pro-Russian ransomware threat actor that emerged in early 2026, linked to a major cyberattack on …
Ferocious Kitten
Ferocious Kitten is an APT group that has been active against Persian-speaking individuals since 2015 and appears to be based in I…
Flax Typhoon
Flax Typhoon is a Chinese state-sponsored threat actor that primarily targets organizations in Taiwan. They conduct espionage camp…
Flying Kitten
Activity: defense and aerospace sectors, also interested in targeting entities in the oil/gas industry.
FlyingYeti
FlyingYeti is a Russia-aligned threat actor targeting Ukrainian military entities. They conduct reconnaissance activities and laun…
Fox Kitten
PIONEER KITTEN is an Iran-based adversary that has been active since at least 2017 and has a suspected nexus to the Iranian govern…
FrostyNeighbor
FrostyNeighbor is a Belarus-aligned APT group known for conducting influence and disinformation campaigns, particularly targeting …
GALLIUM
GALLIUM, is a threat actor believed to be targeting telecommunication providers over the world, mostly South-East Asia, Europe and…
GCMAN
GCMAN is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services.
GHOST STADIUM
GHOST STADIUM is a Chinese-speaking, financially motivated threat actor operating a sophisticated phishing campaign across over 30…
GIBBERISH PANDA
GOBLIN PANDA
Goblin Panda is one of a handful of elite Chinese advanced persistent threat (APT) groups. Most Chinese APTs target the United Sta…
GREF
GREF is a China-aligned APT group that has been active since at least March 2017. They are known for using custom backdoors, loade…
GTG-1002
GTG-1002 is a Chinese state-sponsored APT that conducted a large-scale autonomous cyber espionage campaign targeting approximately…
GTG-20006
GTG-20006 is a Russian espionage operator that has targeted over 20 organizations in Ukrainian and European government, defense, a…
Gamaredon Group
Unit 42 threat researchers have recently observed a threat group distributing new, custom developed malware. We have labelled this…
GhostEmperor
GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They emp…
GhostRedirector
GhostRedirector is a China-aligned threat actor that has compromised at least 65 Windows servers across various sectors, primarily…
Ghostwriter
Ghostwriter is referred as an 'activity set', with various incidents tied together by overlapping behavioral characteristics and p…
GoldFactory
GoldFactory is a threat actor group attributed to developing sophisticated mobile banking malware targeting victims primarily in t…
GopherWhisper
GopherWhisper is a China-aligned APT that routes C2 traffic through legitimate enterprise platforms like Slack, Discord, and Micro…
Gray Sandstorm
Gray Sandstorm is an Iran-linked threat actor that has been active since at least 2012. They have targeted defense technology comp…
Grayling
Grayling activity was first observed in early 2023, when a number of victims were identified with distinctive malicious DLL side-l…
GreedyBear
GreedyBear is a sophisticated threat actor responsible for over $1 million in cryptocurrency theft through a campaign involving 15…
GreenSpot
GreenSpot is an APT group believed to operate from Taiwan, active since at least 2007, primarily targeting government, academic, a…
Greenbug
Greenbug was discovered targeting a range of organizations in the Middle East including companies in the aviation, energy, governm…
GreyVibe
GREYVIBE is a low-to-moderately sophisticated threat actor associated with Russian state interests, primarily targeting Ukrainian …
Groundbait
Groundbait is a group targeting anti-government separatists in the self-declared Donetsk and Luhansk People’s Republics.
HAFNIUM
HAFNIUM primarily targets entities in the United States across a number of industry sectors, including infectious disease research…
HAZY TIGER
The Bitter threat group initially started using RAT tools in their campaigns, as the first Bitter versions, for Android released i…
HURRICANE PANDA
We have investigated their intrusions since 2013 and have been battling them nonstop over the last year at several large telecommu…
Handala
Handala is a pro-Palestinian hacktivist group that targets Israeli organizations, employing tactics such as phishing, data theft, …
Hellsing
This threat actor uses spear-phishing techniques to compromise diplomatic targets in Southeast Asia, India, and the United States.…
HenBox
This threat actor targets Uighurs—a minority ethnic group located primarily in northwestern China—and devices from Chinese mobile …
HiddenArt
It was observed that a mobile network threat actor designated as ‘HiddenArt’ actively sustains a capacity to remotely access the p…
Higaisa
The organization often uses important North Korean time nodes such as holidays and North Korea to conduct fishing activities. The …
HomeLand Justice
HomeLand Justice is an Iranian state-sponsored cyber threat group that has been active since at least May 2021. They have targeted…
Houken
Houken is a Chinese state-sponsored threat actor that exploits zero-day vulnerabilities in Ivanti Cloud Services Appliance devices…
Houndstooth Typhoon
Microsoft threat actor profile. Origin/Threat: China.
HummingBad
This group created a malware that takes over Android devices and generates $300,000 per month in fraudulent ad revenue. The group…
