Victims
Last 90 days
Priority Threats
Live Feed Last 24 hours
Active IOC Feed
| IOC Value | Type | Malware / Family | Threat Type | Source | Confidence | First Seen | Ref |
|---|---|---|---|---|---|---|---|
9306bedaba887d94f7c1af4036f350a6ad4cf1228449fdb52a158691e33788b8
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
3c7203606976f78adfa02c808e4173758999cf372ecc19d0d356e2e7c278be76
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
265ff3e568105a01f8c6d52912715be58f550096b12332fdc86c7c4e80746323
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
1b25019515f53e931ab5674c97fbe2dcb109a3e4226b9cf2b93bf4aa4ccaddc5
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
57c6a7d728e2add09333753a42e39becc210158a53205f9b8a41ae529810bd4e
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
1f94437d559fb268a5a784f04fc95485c090e2662788aa3c61595084b13b505f
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
023fc9e49bca10e5d39539a199553d7899484f329bd9b7120e63a735e1e0ef3e
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
18d31c7a027f8dd95e8e75bc9b2dfd25a79d7311ae55977ab8cb55b86d5dd7bf
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
d594184a06faa8d0efe4a128989c48f00bbeeff36387c92fdc3145c3fe2ccb79
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
cf052a2c00dce756f16d06db530723c6e9d9384063a70aeb1ee23af3cbd83b57
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
4726abf9608a8384d8448d06ea2a9c0ffc990597f770567efb4418168dfdc090
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
13d253c14c9456f3056f2e1afba2ef838a0e16abff0511fa17b15ddc3c86ab94
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
f454fb057a70c17d31188a53caa79c1a6c559d409e63e7c2d5f0025a0c8686f0
|
sha256 | sh | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
02e3fad4ff84e80b387a30498768e8bc18431ae2299bfe05b049a467bd3e3c1b
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
http://115.57.60.24:40928/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://125.40.39.65:60395/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
124.198.132.77:1458
|
ip:port | win.dcrat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
160.25.140.132:443
|
ip:port | win.asyncrat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
94.96.192.87:3055
|
ip:port | win.extreme_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
195.58.140.131:33300
|
ip:port | win.sliver | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
151.241.154.42:31337
|
ip:port | win.sliver | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
196.188.116.63:31337
|
ip:port | win.sliver | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
91.193.18.177:4783
|
ip:port | win.quasar_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
207.56.26.11:2222
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
207.56.26.2:2222
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
dancewithus.ch
|
domain | js.clearfake | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://binsrbuddies.com/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
the-quest.co.uk
|
domain | js.clearfake | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
119.45.225.53:8889
|
ip:port | win.cobalt_strike | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
acf8e056e284ec144dabd9cc2bd05f374c887b76f85f1bbb02d5796d85831ef1
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
b5de902c316598edaf6ee7592468afcf53cd73733e3f9b10996c9dedc0a3b5f7
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
8b18851bcddc710ef0849fa8230e28c815b6d59081b3b786568b7bc0eef773f1
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
b6f906161b11079d7c95def676c01ddd95fd1bb7d377f6ac6bd664933085a0bc
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
915da068a86c7958157f5e3bde3f8545ad61cd101dd25cda907871cb6c4f63c5
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
7532bde42c51869a938632486cd20040dd8506721b3698d196810b72754bae88
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
04c01403ad7475b62702df25481eca153516ea44220edf862e52146498d1d631
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
54e5d84aee4855a9439ce57f0785d89d640e4d56976d4890feda43883bfee9c4
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
67b35d82ffff3d8259181bd22f251686f778ffce66395c4f12d04c77f3ace44c
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
be887c3115fc69c9d5698771ebfafcf68a324c880a44c350d76365794b9ba4d4
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
afecb4714ccff78f49a77be2ec0b8a92e7115f5cc19a4fe8e249141d2e0362d8
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
333db99631505673075e34107d9ef805facee207e42db9fdef89caae25d8a28a
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
a67d3eb948471ee21ee86c03eb76217c98a44d903109bb8d61ecab0289626352
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
cc83aaa6ffc335bda7548aeabf6af25f81d5d8ed8d70fe29e99493610b1abc9f
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
f403a488986b6dac214defc0ce00105994cefc11616de347df9c5e9faa6bfa56
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
1abe6dd23b0045d8f8ee25587315063673f7075b96767fd28004346db3e8d749
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
5e0093897ad69a9c8c9078512a48810548c3daa0e383ca6ac66e92b3976a3d04
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
6b5591d2cec085683d2087267c655dc9d9bfe75b86f7c014cf956ca8722672c4
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
d44926b66c423b7549793823ee63d19d6bff13ed503c8a01e7048dbeebc40e79
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
82d75976bb4947e9da7e3e8f4bbeefa33cf4ed2eceba40a255875e74c82e81b8
|
sha256 | js | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
http://103.249.199.5:39552/i
|
url | 32-bit, arm, elf, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
ck.erloro.com
|
domain | win.cobalt_strike | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
qyloa85467.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
lazorony.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
xapoluqi.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
9w36ncqf.en-leptozan-us.com
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
konya55488.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
www.bordeaux-aquitaine-boissons.fr
|
domain | js.clearfake | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
digitalisierungscheck.mit-aufwind.ch
|
domain | js.clearfake | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
30ddcc99e3c4380ca21df1c0b92e7867abe1657b42f4b86f35064ff394ae6575
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
671bc7f66ab714f660cb553bcda96f342a3f833a73ef268b4f33e08c457deae4
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
dd2c22752ad053325c2bce124c0984128bba7ed3148022e271f7827df65a81f6
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
af1762c75e7da96ca5bc1181e2cdb343b4b4309366e16aec1fe4bc0ff39d26fa
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
2d0fd92ec27d3ca45834545d8d461e856a0d75d293b51d31232f79b25214e0f3
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
1d70972c44664eb6f4b3f4a4fa11e44eaed32913a8cb4c02a11c27d70eef1edc
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
b5909f3325234e39e826c63b7424690c09800280f8b313e5ba71eee3c25ec99e
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
d256d5c55de076203b3ff997ca2dca466f72d97ee5d3ae6666717cee4baa7c1b
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
56ffd2771ef463a8b67ff3dcc8528e78b78e4a2ce9234ae941695118a73b3543
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
1b31ce2dc9f700aaf2765e44abf263f6a71a4e1630f4c57fdbbba6f6d57f5010
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
361cb8d273f677f336eb453700717d4ef85744354112a43a8d89f3e1d7126bc8
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
a248d97387d19b49b6b074d23d97e656305391aedd866d2fa0dd0477d315c074
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
9461ce465a3b0fa41aab50948190501d1574143daed369cd910de6d26b54afa1
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
03c1a932ee59cf97ca66760fbd64d5ff7ac9598113a3aea82d2a7a9cb486c64d
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
91fa1ef98caaf8740e666935ffdcfbe93085a6a02398b5fecb188a02031b393c
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
d76f26d8876a17edfa9efccfccc10a1648b08fa69dbc70756b20b13ef3918333
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
2853cdaa2ab6448c1161473e3ffe9a3c8fbe6a349a3cc435705683c9932dd1af
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
94eafdd65b213502396db5d9f7f6571984bd9cff62fc608b603475b28eb093d9
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
223b572c10f3b361959d74c5c59bf2868bcf63e49c0b2679f4df5528035331a4
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
c191cba2b5246213a4078d613e839dbdc47c9663d021afc0093f0ecc6f5a3168
|
sha256 | dll | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
6b4afe2d853d455f80a3e254a9dbb0aff9fde1bbf2b188d1e0e8f4d14be29ffb
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
73438ca34020990dc5e7733e4802e223b61338e26c33ea32376d6de7e1c85ee3
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
82bb90e27bfa33e74e9f0f4871e2ef16799a71f07d038d4a7ec7e82ff132cc40
|
sha256 | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 | |
a96860a8a4653e1f59620c443d05f006cc7049e0f9c216f2cb7a7e32fc21d3ff
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
e83ee79f9419395234a70b758b1295c5e73cb1be0357370a3d56e429b936f8d9
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
d441b20bb397bcfa6d0d62634cec198e6e83e73b57513bcadcbd9e0f785aee99
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
http://182.116.72.222:57147/bin.sh
|
url | 32-bit, arm, elf, mirai, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://112.198.186.249:60485/i
|
url | 32-bit, arm, elf, mirai, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://vztax.shop:9820/customers
|
url | win.remus | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
89.116.73.207:9820
|
ip:port | win.remus | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
graceful64.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
81deca370910eea773c0ebd4e8602930dd15e901c815db1689863b55ace711f2
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
3120eaff8db9ffa89a9f94e88e68741f57603b0498f75a5c20e06616daade5fb
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
95bdda0c1a9f6c321461e4e6451af8040c0afb7ac9f8c72e86e8ff2074a873f6
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
b3c023cc4dd7a59b9dbd9e0e352d82d3b8a8fba0da89a47805693c0d482c184d
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
f9b2120a061c50d6385976c360feadf9f1791b743bc43b3702e35734e718d25d
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
0d4391dff5042019739e753b18b7d79627ecc59e2c52b0ea681a484267f33004
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
a2bebd07b8b41a55452eea9794871762b34ccdc04b9ff354b530be2a44a3ffb8
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
38e64a68be595cf383e959c617c990f2a75db00076823ee4ab56e46b9e25f919
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
3c714b5438e80e0458bfaf9523cc2d7116afa71ef76d9f25a94e3464c044b471
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
682b0b39e3f74b2191762568e9166058d526abfc89e884dbba9686dc2908849c
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
bdf2afe29ab2a2c48d027dc9a4e0d8ea296c92021bfe90acaf2c1d214032999e
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
http://183.23.135.203:54790/i
|
url | 32-bit, arm, elf, mirai, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
qovoto.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
0054d2622e335797a8697982af417982
|
md5_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
34c53b495cd8216306cd4dff6986077c
|
md5_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
86f27425624e99fca1a6735b4ed5e192f575794e57f16c47a1e068bb1e608d6a
|
sha256_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
863adf6289db25fdc4ac0ef2e1a2ae63d43366b9
|
sha1_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
37e1c520d9d6359582f566e2c8339d6a2a66e546
|
sha1_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
fd669e1388907d25b8039b5ae22804a6b77a96d139c8f8bbff50c15c9968bfa2
|
sha256_hash | win.dcrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
55888979b9436e79d41aeb0b763de01ed99b85db
|
sha1_hash | win.dcrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
1bd88bbb0c82349303aa60c470c8b51e
|
md5_hash | win.dcrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
0beaf7839d3a1b2e0c86566fd597c159da9f154e2be236d482ecb2c9ff32e225
|
sha256_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
d1db4e527ecf5ebb601744ec216724d6d25a0c2468668acc4e121cadfaa59a52
|
sha256_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
88a8ad0a1d77f3f8b2f0a5fa267e8916206a5bcb
|
sha1_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
817d31c309449bb678cfa47b1f5feba5
|
md5_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
8f9a5a5bda7dc3faf1d5cb74f0b4dc63643ab3bb205f119e585c5f290adc9137
|
sha256_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
0c7481ffcf1ceee98e3500c552cec40c6d7d8fbe
|
sha1_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
0cd74763c8271e198bd5d3bcc2a3bb1e
|
md5_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
207.180.248.154:7242
|
ip:port | win.remus | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
http://coxnext.click:7242/files
|
url | win.remus | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
http://gofkaxz.click:8137/tasks
|
url | win.remus | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
http://nopxs.shop:8839/accounts
|
url | win.remus | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
832b4fe599627975316c0cd1af90154684f5774b51816ceedfd24b94bcbd2686
|
sha256 | sh | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
61534201ab9f84788d6363ad0c0c2d834a5a34813b2d84bb999fd81ddfdcd293
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
40cf6d42aae4f489f9f4f57fb348fcbc2dfbcb67d479f7e2c4fba6f59e2fba8e
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
6779560ebdc4411266279b13c26dadb8a5526fe335e5001da972d4e1addf89b5
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
4f634ca23ee5b0824f2c91d3c46771c2e0cd926b7f8a1335d7c758a1a903caf7
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
1f6a5984341f525415454ea54f53ea19aa7add7cf553f5c4a08dce28f963b21f
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
bdc8cadb11bd3d8c480f771f3a0184042abaed493566fcace9901acebeb8bb03
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
1bc4af20258b305211a827bd3325bc4d3b0790463761681a6a9db9f2814a6be5
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
8f9a5a5bda7dc3faf1d5cb74f0b4dc63643ab3bb205f119e585c5f290adc9137
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
734da1213841277b27b7f88de608e32e5a6cff4217daf1635fd2906d74dd59a2
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
d1db4e527ecf5ebb601744ec216724d6d25a0c2468668acc4e121cadfaa59a52
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
fd669e1388907d25b8039b5ae22804a6b77a96d139c8f8bbff50c15c9968bfa2
|
sha256 | DCRat | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
a58489d246ab118a08dbc039428c34d02802c55d10ba2ac21f4338f2c427e4f9
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
0beaf7839d3a1b2e0c86566fd597c159da9f154e2be236d482ecb2c9ff32e225
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
86f27425624e99fca1a6735b4ed5e192f575794e57f16c47a1e068bb1e608d6a
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
05b37b0056fcd2365b5caf484a08939fb2ef6310b36b187f2bf1002ef8bf6901
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
52c482233ebb1143e322a9148b529c95335ca83a7b57a05bb344b430cd25ebda
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
5a455a57291481d97b5eeaa52b16dd4ead7a7479412bb10710689f45c2935450
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
721fe1dae758430653e954320e0dfe853670b4f291ece1f80afbf4bc17281ede
|
sha256 | NetSupport | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
197c01de3a78c4f08ae805cda6a0796e4097644b695b19345a65cacc8fb13b00
|
sha256 | NetSupport | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
http://112.198.186.249:60485/bin.sh
|
url | 32-bit, arm, elf, mirai, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://180.115.74.175:32843/i
|
url | 32-bit, arm, elf, mirai, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://27.219.44.37:46482/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
8a57b2a9cbad582ca6211f7ee7686e6450782853
|
sha1_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
c1a774ce1a8b5aa8ccf6b7c4b1cfd0ee
|
md5_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
3d639a627186e77730ff2d1294df49a3
|
md5_hash | apk.loki | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
fba00f02ac5abe5b9f7185d74ba753aa12984517fd79ce70a17ffd0ab3fa9adb
|
sha256_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
89f6c08fa045d14eb73a0992145a724bc34d531d7af3dcc4901a1b7c7833aede
|
sha256_hash | apk.loki | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
dd971d09f94dbd77735a07fc297dd2836fd94616
|
sha1_hash | apk.loki | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
6b7a6595e3ba1deab9e3020e9fa535bd2ad83732e643d1e70e85d7c15d563d8e
|
sha256_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
9df5fb9011bd9f1ae2efdbc7701cf6ec606cf670
|
sha1_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
08cb4c76b11f7b8725282fb495c25c85
|
md5_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
02e0b6dd34553b2d1e4a0f023716061884893d84995b3641b388b02f4e04014d
|
sha256_hash | win.overlord | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
432fb29714e78ea2d8e8e907132bc7259d445cb4
|
sha1_hash | win.overlord | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
553f64001e0e802a9619bd934d791155
|
md5_hash | win.overlord | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
6ed072ae91ff6f7f0de6d9b1a382647968e76b34
|
sha1_hash | win.coinminer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
5e7f62683bb66cd08d61ea820bea6fe7
|
md5_hash | win.coinminer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
c3c4e615bdff2ac3b6f290c044931d49f483c5bb62e2d7ec4cbf936e5dbee6b5
|
sha256_hash | win.troystealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
2ff1e76cd7036ffa6e93e41e634bbcc0ee4a4c39
|
sha1_hash | win.troystealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
d840e5f63396eaf9d3801f630bde373b
|
md5_hash | win.troystealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
f0b45ac6bb1d96981900bb46d9129c6c3facf2575529cac1ff0145079ef96cbd
|
sha256_hash | win.coinminer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
4c3c4e06e9994eded388727f5744c0746b76cb66f49efc0113111c7e6f975802
|
sha256_hash | win.formbook | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
de348334e29485376b4e0f5487faf00184c51349
|
sha1_hash | win.formbook | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
e35bf4bd8ed78626b63cb917fb2fd576
|
md5_hash | win.formbook | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
66a1dfb08cb48494a16f60ecc6a827acb02388ddd364baafad3cc9774fcaae2d
|
sha256_hash | win.asyncrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
eddfa48ca1564f480b696e12f0e809dacc60ff97
|
sha1_hash | win.asyncrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
98597ac6d3479702b9efab392159bc48
|
md5_hash | win.asyncrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
adbc3683b11bd3a4fd6d99f7144f3904e0fe55839a91db66fd6a83c06a058f5c
|
sha256_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
78b8780c2200131209232320307410c0498c5a26
|
sha1_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
2422d08cd082f643c4996694764f888c
|
md5_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
381ab629fd8f5590643cbc93d9527038da1bc8aeef8ab1c7c2fada6a53be363a
|
sha256_hash | win.wannacryptor | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
518758f0de6d8969f456aafc46029bc9cbada419
|
sha1_hash | win.wannacryptor | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
1d011399cbf80ab0970a15c6c07868d9
|
md5_hash | win.wannacryptor | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
6decd2481cdb54b64b432e5632bfc91fddb8bcaa7d0d2289366ee1ae895025b9
|
sha256_hash | win.formbook | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
dcc8071900625e6e0df5de9ae0156c4da85b2c4b
|
sha1_hash | win.formbook | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
2e688af35698aadb14d24e425f5c5e8f
|
md5_hash | win.formbook | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
4f9df700891ba8fcf918a8bcdd527d9109c7888be2201876fa64d73bfdcfd98a
|
sha256_hash | win.formbook | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
78c69adac0710e8ee3fa14f442fb1dce22ee4bb3
|
sha1_hash | win.formbook | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
bf1e808d7e6812bed9d86fd5aea256dd
|
md5_hash | win.formbook | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
e79d0d5d3076c47bc83cf4d60cd9e2471535f137
|
sha1_hash | win.phorpiex | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
5a081c877716d922366a17238c18bcbb
|
md5_hash | win.phorpiex | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
d4fd4ff0709271323b8d401579270e6567b6e360
|
sha1_hash | win.netwire | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
752d5cdda2a1d93d27e38f98a5d23fc2
|
md5_hash | win.netwire | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
15e71f4e20634454a890c02d9494cc44b07e66cabea8d4bf3615dfde30d58e38
|
sha256_hash | win.phorpiex | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
ab9a2c07b3b1222f5ada4cb7c1fd144e
|
md5_hash | win.netwire | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35
|
sha256_hash | win.netwire | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
1404090db3128de503ba4d991a960c7c1bc3b910a62d06ecf7e7081a2fcf11b9
|
sha256_hash | win.netwire | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
22d5e961804073435cd193c1a4b7d3f4c39a64c4
|
sha1_hash | win.netwire | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
ee2579b3b0776a20be98c1cb605cd7eb39909951320b375e6aacfbd230104572
|
sha256_hash | win.valley_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
2e26a2fbd74b1e40119e1031d4776d1c55efcf5c
|
sha1_hash | win.valley_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
59ae169e146ffcc328c53b0feade92cb
|
md5_hash | win.valley_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
00df868e2b8a8f4014ac129bb65bb8b0d7e196966e5b30b44390dbb3914d219e
|
sha256_hash | win.valley_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
42e83488d452064f0628a22bb038d36fc1e45d3e
|
sha1_hash | win.valley_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
9165819cd48cc6eb816b22a27f85aefe
|
md5_hash | win.valley_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
3727f5bde57b562a6c66c1ffdedf2fc52daa47fe
|
sha1_hash | win.coinminer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
c6dc1c09565cf12e833d1e5b35688e4e
|
md5_hash | win.coinminer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
2899fcb03c3c0d5c6b504d2ab4f7b7dd
|
md5_hash | elf.elevator | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
4037fc3edbee83ac3544c8bb948b2d237c4bc7ca7f5fc23147d8350fa248e081
|
sha256_hash | win.coinminer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
9c9792f75ee324657d381b6eceee5336e0c752a5
|
sha1_hash | elf.elevator | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
2841cec724ba8a14f5f97527232596c0
|
md5_hash | elf.elevator | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
d32b480e2cae0fe8597f58d360816487c7fbe63d524810624768ca700eaa8541
|
sha256_hash | elf.elevator | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
c10622a661cc81f44a4559514e70e14fe38ff4ac
|
sha1_hash | elf.elevator | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
60bee9be8b1a782592243014d0d0907f3d660241
|
sha1_hash | win.masslogger | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
b980b243307e67831945f3171edd200c
|
md5_hash | win.masslogger | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
a0c6e277bbb4848c967a3d4bf6aa45aab28ffa3249180e3026a89f80360d83f7
|
sha256_hash | elf.elevator | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
f6639cc04bf97cd42f2b74b8d305c89e20a989a2
|
sha1_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
27fab16542978a904574e7bc7746e39f
|
md5_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
c522e49fa2f87b3e8e9925555377aa77a42ed9d1790c17b25c2ad052efa96569
|
sha256_hash | win.masslogger | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
84798b7f2d9b0a4eaac38348497fb4a63a811df9
|
sha1_hash | win.agent_tesla | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
862b5f62028a30d7f6c8ef20d4450f29
|
md5_hash | win.agent_tesla | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
b32a6cd6f6cc6fb39f3bc0477e5f5da1e2059649766742020f82b1f87aa05889
|
sha256_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
35daec4729842b66099ddbbe4bd1bc21240628d38f0e54a84b80d1fd11d2f1af
|
sha256_hash | jar.icerat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
83e1cffed0bad229afac9c8fa285173d6f07dbc1
|
sha1_hash | jar.icerat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
d4a19a109b091d66e0930bd553256b1b
|
md5_hash | jar.icerat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
3ab6ed7b7cb21244b34addf64ac6f64b1c38ee98236985511c4af47e8cc93cd4
|
sha256_hash | win.agent_tesla | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
63f3064a8023989933b7d294af76cd5a583eeea38aedfa464cd2ea2cf3a4ed73
|
sha256_hash | win.evilextractor | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
bb5cf9a62dab446da7ebb7650213748dc51037b3
|
sha1_hash | win.evilextractor | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
e384e7389a371c96e5d31effce1242ae
|
md5_hash | win.evilextractor | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
0a4750223a0c04e5a41b474eaf776a4b10129f498b1cf76693b2e54955361f8c
|
sha256_hash | win.krdownloader | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
4783e4bcbd97b4927afae1d8160222b53452831c
|
sha1_hash | win.krdownloader | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
7825ed42fd7c9d92b93f420b1653e8e9
|
md5_hash | win.krdownloader | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
2a67ec9b4db3954e30b1fa26fe87dea4f89ce4d011415e00d48f3200c9fe1f88
|
sha256_hash | win.darkvision_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
1b0614ebdc81d0a98e5c8c6013d6a0596be2ec2d
|
sha1_hash | win.darkvision_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
1150457afc7e499c3937a0f2bc430c29
|
md5_hash | win.darkvision_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
676a249f36ca2fe67297e167f622679023b4f474c634c690a7db96d75a00d8ad
|
sha256_hash | win.habitsrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
1d5c6e845ea6044dff2e504621e578cadadf7984
|
sha1_hash | win.habitsrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
b2b14596a08d505ce385c914c6a971f8
|
md5_hash | win.habitsrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
d4cab6229ea31ef21dcce6bfc2a3c221cd207a98dd2b97187f987b810db77b15
|
sha256_hash | win.xenorat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
3e90f1c5b78175bf8e806b0e6a61461ee6eb3164
|
sha1_hash | win.xenorat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
5c410bd8f7cbc29d00903db8efa47d0a
|
md5_hash | win.xenorat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
5bd1f26001082fb7888e986fd6b60df09d4ef91e438741dce7a2fe937644c764
|
sha256_hash | win.metastealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
b0643668907ff3f9faeb428380cc2bb20dc3b604
|
sha1_hash | win.metastealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
3c3fd9cd6a4bc0d223970bc7d7341269
|
md5_hash | win.metastealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
150cd29ec3f3156808da6121512c6bfc
|
md5_hash | win.pure_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
e20249d5c5933e8204a0da141d7a66937a7c5c24819eeebae8b653ec41be665a
|
sha256_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
c6f12b5953f9faac40b2171b93c2e9acc7ba763b
|
sha1_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
0b3dc07aab76fa54be44fc7519acc7e1
|
md5_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
150c73a7b6275381a1d06137a617cc94
|
md5_hash | win.luca_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
3b898adef43e54e9682f1358401ba2300ec3f39de75e2939d23e2bd60a725de6
|
sha256_hash | win.pure_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
06d5768088624218d0e571a136fcd3c01fd945b4
|
sha1_hash | win.pure_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
f708c405d13450a3886936d68e63ad841836d0a741fb6848fd7b58c83db988d2
|
sha256_hash | win.luca_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
d1884c7a8d101814ff59239953680c42b07d5a8e
|
sha1_hash | win.luca_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
9fef5ea2eb1866a07e355e42e8b5910de1c24cb7
|
sha1_hash | elf.xagent | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
446843cb5e2616cf8c3d91cba5e6afce
|
md5_hash | elf.xagent | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
3bb02bfec1d2c0723baac811b7a2ed2a9eff3d2c
|
sha1_hash | win.njrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
13fe4fd84d2f0fe65fe209c4ee390752
|
md5_hash | win.njrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
90ac7bf6e0b76245296e194bc1bd8a6388d013b7e11be906ae0352ff22c3f472
|
sha256_hash | elf.xagent | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
b002e551f74a52536e94d4ddaa8de2f5e480639f718f683bc4b5d4e6adf59a9b
|
sha256_hash | win.socks5_systemz | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
552ffd2655521bf451fffd7aaf3d38bb41c006e7
|
sha1_hash | win.socks5_systemz | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
b435c5fd83e345f30e7da1dbccf50aa6
|
md5_hash | win.socks5_systemz | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
895fea5f9576b02251d5c3b6d49e5d4611d4255789744d56599d5b5ede7dd563
|
sha256_hash | win.njrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
c2d4370aecc06016e4aaa606c635b1c9d219972e
|
sha1_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
e0859d1fc8816b37a16f4eb2a7232eb8
|
md5_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
4c16f5ebd5c633b7a793ffa2cd96daddc5a503d82ed4fbe636109d89164ec02b
|
sha256_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
a678d1972c9db49b4d917e5480a0c62d63f3d6b6
|
sha1_hash | win.salatstealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
e7722735a7128302b1c430d18a602917
|
md5_hash | win.salatstealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
d83f465bde16528aebdff1e523a46613a97a32234712fe4e9ef29d6a979a72f6
|
sha256_hash | win.salatstealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
e452d5cf8a9a7f37ad722e00f85aef7e419e736d
|
sha1_hash | win.salatstealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
982793e92a09243ed66c378aad812825
|
md5_hash | win.salatstealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
c02e2b1e61535024d4d7b829adf747907fb719bcb19560d753b0f6b10a95b0d8
|
sha256_hash | win.salatstealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
7d6142cfa025c44c947588f283c0275db4a24802
|
sha1_hash | win.valley_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
8e168e0cacef78f10dc13a69d5bd0b1a
|
md5_hash | win.valley_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
04aa7984d4ac5900ac796329af8c0557180dfbec0122ac178f2f4fc1e727eab2
|
sha256_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
b6dc96a0aa3bfcdeb516954831a66d1e6910185b
|
sha1_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
0d3e6cba3fbeb2bc490d982430748d9b
|
md5_hash | win.vidar | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
0b1d575c0c0a08ef48683113372d7580a42acfac4442a3927314b86dff616c4e
|
sha256_hash | win.valley_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
2b93212ee63dbb290d88bc845aafae192552b6de80d93a2f4a6453afb3738676
|
sha256_hash | win.coinminer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
77613a3182bd1f5034776bd971707a44bce37f78
|
sha1_hash | win.coinminer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
ab06fb2409787be402ccf1b4288b87b3
|
md5_hash | win.coinminer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
32295f0896a1603bdf37be339787dac7df37dc7c08bfae6bb1f5f157ca85b71c
|
sha256_hash | win.njrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
855275076a9a33ed95c0ad90ce1b620c0b1e19f0
|
sha1_hash | win.njrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
2f490ac81c015798c477a5d882f425d5
|
md5_hash | win.njrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
1fa24618993a4828e566da20b40bb181
|
md5_hash | win.dcrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
3e08292340a925412039c40af6eefec9a30fca1e60246baca93caf9f4bd3e53c
|
sha256_hash | win.njrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
b5a9f5007839560266d831d25d1db4429d07c9fc
|
sha1_hash | win.njrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
dee3308c48a52fc15394c3e89221226d
|
md5_hash | win.njrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
50ab6fa03c74aac498627a9949d88931f4b15fd8
|
sha1_hash | win.dcrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
f92d8a2f5c3d9140c233c0012d9ad43e
|
md5_hash | win.dcrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
c6d374bf20c20fd3a1b14a1e8a8334c41cdf9c3098bc2f8b1afbec7ac43881af
|
sha256_hash | win.dcrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
82454d9f0d4b22bc8357285e8397ee3a
|
md5_hash | win.dcrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
36cd6bffbae0e88e20b56251445092e57977a990ea2f92e84321ecc9a16eb53b
|
sha256_hash | win.dcrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
bc716d57de7f312667adfb4831c6ee419d23c1a9
|
sha1_hash | win.dcrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
9b93fde0cd1f8252a2abf2239ae56f9d
|
md5_hash | win.amadey | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
9c19c3b393c667beccc02574abdeb3e5b4793bb49550daadeab78af2e45cc97f
|
sha256_hash | win.dcrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
f8a6f532ba303705606a91a2416e09e8f4cc7263
|
sha1_hash | win.dcrat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
41cb7ed17731f8c1561399b381f42de3febcd6be
|
sha1_hash | win.valley_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
51f9befcc514d4468197647968767773
|
md5_hash | win.valley_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
0ebd28830251fc40845f4201396c683b0026828f3dc25873abdb6feac66820ad
|
sha256_hash | win.amadey | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
c5f12a9d191c2baf64d66eb1f2edd6754333260d
|
sha1_hash | win.amadey | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
a2a89a44d71f06730e57843f96ade00667b4f90a
|
sha1_hash | win.valley_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
5021094d588a1cc1f2cc9b61c717fda6
|
md5_hash | win.valley_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
de993daff7d97c547bc608c9e5f0233ca1f420adb4931d8615171c7ec8182849
|
sha256_hash | win.valley_rat | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
7f6e450810b169a163ff5eff32af8a7f760b819b
|
sha1_hash | py.venus_stealer | payload | ThreatFox | 95% | 2026-08-25 | 🔗 |
1f44284c85be477e6969685c02f302366f22fb8f2c2a3ac0b2dd9c99e1c4e67e
|
sha256 | msi | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
8b1e10c2b2534760b3b800b7b0830adc4bf8994a75730d4e5e72948984e24b8b
|
sha256 | Vidar | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
b6eb46746e026d8e9163ede8d005153c5588a186cbfc0d762fd68a6c28d7249a
|
sha256 | Vidar | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
http://42.227.135.249:48039/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://115.56.67.128:48264/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://158.94.211.113/
|
url | win.stealc | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
voidravenfortress.com
|
domain | unknown | cc_skimming | ThreatFox | 100% | 2026-08-25 | 🔗 |
66.179.29.5:5000
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
66.235.175.82:7443
|
ip:port | win.hype_agent | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
66.179.29.5:2000
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
64.89.160.140:7040
|
ip:port | win.hype_agent | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
64.89.160.140:7443
|
ip:port | win.hype_agent | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
45.61.178.41:3333
|
ip:port | elf.evilginx | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
45.145.41.185:6767
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
38.54.88.188:65533
|
ip:port | win.adaptix_c2 | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
37.244.224.146:4433
|
ip:port | win.danabot | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
23.226.68.34:443
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
213.35.118.205:4322
|
ip:port | unknown | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
185.242.3.249:7443
|
ip:port | win.hype_agent | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
172.245.209.209:7443
|
ip:port | win.hype_agent | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
172.237.88.168:443
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
172.111.134.94:3001
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
157.20.182.22:1973
|
ip:port | win.asyncrat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
147.124.212.136:7080
|
ip:port | win.hype_agent | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
104.239.66.99:56401
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
104.143.204.239:52310
|
ip:port | unknown | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
fapazate.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
http://shhsift.click:7647/files
|
url | win.remus | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
0b4dc32d947ae8371aaa88210787244bc31b7b9a5e6c35b41bc093f405533a71
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
736dedb3dc80fc3c7e584666082ff8ff9673a4356f5d88f85165792086e93c1d
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
feef37105fdda0fe2421e2aa73d2e68692effcc641421e296d312c3914c8652e
|
sha256 | dll | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
148322138dc8b3fe438007441b2eb6ef5546417f72204a0b3b5eb9cf0a4d6163
|
sha256 | zip | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
ad4b54a449ee7affd5d8a775d576db81007c58ee9a77c82d7962bde6caa93910
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
06c5913fc8918211e49ce30eb57516f4002632f40f2e0110b1f0b9d1b0229a67
|
sha256 | zip | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
f2049b7b8b9677fe80a01eb65c3b014e453ba53ce53b031899e70e5aafdedd23
|
sha256 | 7z | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
35850fc8c8d89cb0fd8a4d861bf9c19447c7ebb21a378f1d9f16ed4fbbdc9792
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
0ecf67573dd428c50ced01ff83d1fd658470f6727cb95ace325be1a6f49ac255
|
sha256 | iso | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
280b0baefd4928848659c6ae2a9ad75b8745cd000b84bb958b1b888af452be2e
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
81de4d530901a1df65b325368728f4eea2c39e7e53a2df97aec3744771d86a1e
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
ad9dd438fd00d4130d2e993d0765d2095c71aa68f156e2e7b53863f0e18446ee
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
http://36.84.112.102:54365/i
|
url | 32-bit, arm, elf, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://117.223.141.189:43389/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://115.61.18.207:50219/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
https://institutovitoria.com/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
cdken.com
|
domain | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
su15xgsq.en-en-usa-memorylift.com
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
piqucu.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
45.95.168.149:888
|
ip:port | unknown | botnet_cc | ThreatFox | 90% | 2026-08-25 | 🔗 |
white4588.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
caselywo.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
7274541ff85fa7563b8731fa5c403f756f8358dd127bb5d1810c06adf4b813a4
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
8191df46bde2355f90246149ed51e0817625f7d1f6fb1d3ceb76a53446aa1b51
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
c65d9c9ea01d0694836df4347e507ef58c49a18d1f274d4e895ca421bff926df
|
sha256 | 7z | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
7d33dd89511d48517917d9a9c7090f6e337aa1739a5b0e7d628e0517766b808c
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
http://219.157.23.252:47875/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://115.56.67.128:48264/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://117.223.141.189:43389/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://115.61.18.207:50219/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://zonxh.shop:7728/accounts
|
url | win.remus | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
http://shhsift.click:7647/reviews
|
url | win.remus | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
http://fresok.top:9048/collections
|
url | win.remus | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
https://hennemann.lol/api/v1/verify
|
url | js.kongtuke | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
https://hennemann.lol/api/v1/session
|
url | js.kongtuke | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
hennemann.lol
|
domain | js.kongtuke | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
http://fresok.top:9048/articles
|
url | win.remus | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
43.143.206.225:3307
|
ip:port | win.vshell | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
208.167.245.124:9993
|
ip:port | win.vshell | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
149.88.66.234:3000
|
ip:port | win.cobalt_strike | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
licohoqe.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
ea09d3cae042adabbc49eb127259419e171a561e028410ea69eca4a038f9f8a3
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
3ea27ecaa24b7c8609e268ab93e39e1f931fb3b22b0b55d35ab682ed3f5a9a22
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
364a99ff6b75ef80092705082e78a7d6ebd229771ec842ac2a341e402497d26d
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
43d35747c07a949254b43e294b14ad31ded4535d92c7d09a585581f24163eaea
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
c89fae311ab8968e63bb9ed41175b2aaae28c12db9f4b9bbc4d7ed08a5c6a752
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
cb9f49b49574486f6346714855417ea966c9c25e1525d235bcd65ab6ff48a778
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
http://112.248.188.197:43330/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://42.233.138.140:60584/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
k6h4y9sw.en-us-americaneaglependant.com
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
en-us-americaneaglependant.com
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
7c4888d19819857873d74da379275518d0cc6f1bdcfd91761622976fbf3abd34
|
sha256 | RustyStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
http://196.189.35.172:34687/bin.sh
|
url | mirai | malware_download | URLhaus | — | 2026-08-25 | |
http://91.92.242.236/files-129312398/files/file_2dedd67a4922be21.exe
|
url | 54e64e, dropped-by-amadey, rustystealer | malware_download | URLhaus | — | 2026-08-25 | |
http://210.208.111.100:60334/bin.sh
|
url | 32-bit, arm, elf, mirai, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://182.114.250.133:60170/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
e4riqeczl5.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
gerenagosto.duckdns.org
|
domain | win.asyncrat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
fw2w2up6ss.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
utanigeria.org
|
domain | js.clearfake | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
http://146.158.4.238:41633/Mozi.m
|
url | elf.mozi | payload_delivery | ThreatFox | 75% | 2026-08-25 | 🔗 |
b285d9d8aead39204623c4e85421e0e4b00b7e7a6bd39a443fb94a7caa5c55b1
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
689c485bde77370d62a36c7c86d1675e439b393ba0e6d7d5102d5009ea7e5dbe
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
78cc6707797ef77a94e80e6b30eef0fad0fbefd1f8a0bd16a41dc085182f29d2
|
sha256 | RemusStealer | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
99328f02c062e6f2d52c257e7df219789f9ef0d9167444b2d123c78bba75362b
|
sha256 | ValleyRAT | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
de993daff7d97c547bc608c9e5f0233ca1f420adb4931d8615171c7ec8182849
|
sha256 | ValleyRAT | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
0ebd28830251fc40845f4201396c683b0026828f3dc25873abdb6feac66820ad
|
sha256 | Amadey | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
9c19c3b393c667beccc02574abdeb3e5b4793bb49550daadeab78af2e45cc97f
|
sha256 | DCRat | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
36cd6bffbae0e88e20b56251445092e57977a990ea2f92e84321ecc9a16eb53b
|
sha256 | DCRat | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
c6d374bf20c20fd3a1b14a1e8a8334c41cdf9c3098bc2f8b1afbec7ac43881af
|
sha256 | DCRat | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
3e08292340a925412039c40af6eefec9a30fca1e60246baca93caf9f4bd3e53c
|
sha256 | njrat | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
32295f0896a1603bdf37be339787dac7df37dc7c08bfae6bb1f5f157ca85b71c
|
sha256 | njrat | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
8a7d3056a0c64c49aabd4c47319073bf2e3ed5bde698eb5c70bf597f85f8ca48
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
38.207.177.73:6666
|
ip:port | win.valley_rat | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
202.79.173.2:443
|
ip:port | win.valley_rat | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
http://cloudscrsolutions.com/v8sjh3hs8/index.php
|
url | win.amadey | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
http://atraflaxtt.com/g9sjh3djv/index.php
|
url | win.amadey | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
http://jazoopsloo.info/k92lsA3dpb/index.php
|
url | win.amadey | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
91.92.47.41:7044
|
ip:port | win.vjw0rm | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
http://cg618552.tw1.ru/L1nc0In.php
|
url | win.dcrat | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
http://cp447347.tw1.ru/L1nc0In.php
|
url | win.dcrat | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
http://cj537866.tw1.ru/L1nc0In.php
|
url | win.dcrat | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
162.35.173.212:1604
|
ip:port | win.njrat | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
104.250.167.93:7777
|
ip:port | win.njrat | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
186.169.37.83:8080
|
ip:port | win.njrat | botnet_cc | ThreatFox | 100% | 2026-08-25 | 🔗 |
ca4bbbca55ad78274956ae4851dc2eb2c3c6f381e60fe73963d279d32eaaabba
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
http://112.109.205.48:35136/i
|
url | 32-bit, arm, elf, mirai, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://91.92.242.236/files-129312398/files/file_6d132da8983cd728.exe
|
url | 54e64e, dropped-by-amadey | malware_download | URLhaus | — | 2026-08-25 | |
http://112.109.205.48:35136/bin.sh
|
url | 32-bit, arm, elf, mirai, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
https://md-projects.ca/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://nirmalrollingshutter.com/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
ravenenvoy.com
|
domain | js.clearfake | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
xerepole.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
tehnohome-ks.com
|
domain | js.clearfake | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
primalaser-eg.com
|
domain | js.clearfake | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
www.reha.org.af
|
domain | js.clearfake | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
51f95c0019b36f11423bc9cd7f3fc652f7d331ff819cb9410095b27f4b0acc58
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
f721dc04dd61504ef2940d2d430369fbb069f1551e99ea7f947214d7eda8b0de
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
cedce92ee7e0710c7621fe4950246db39e9321f5fb29acc6c919780be92d1a68
|
sha256 | Mirai | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
cd0657110e84c0787254f2a7fc2e9871da7433eacafed1503a298258866dec83
|
sha256 | elf | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
http://122.241.8.175:37163/bin.sh
|
url | mirai | malware_download | URLhaus | — | 2026-08-25 | |
https://nosygoats.com/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://smartinches.com/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://yemkoservices.com/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://nast-net.org/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://tasteofjollof.com/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://www.lavitasparta.com/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://vetrinacakescoffee.com/bakim-asamasi/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://stockvista.org/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://serracontabil.com.br/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://hasminaimportexport.com/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://bes-sicherheit.de/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://gayatripalace.co.in/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://aacc.edu.in/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://acadmicwriter.xyz/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://www.aavis.org/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://www.clinicadentalmonlleo.es/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://frontdoorinteriors.co.za/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://www.blackboxstands.com/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://priyagoenka.com/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://printandsign.co.za/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
https://premierdermatology.org/
|
url | unknown | payload_delivery | ThreatFox | 90% | 2026-08-25 | 🔗 |
e24903q7mc.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
f1git16x.eng--neurowave.us
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
47.111.171.130:8077
|
ip:port | win.vshell | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
m9zxgtiz.eng-usa-neurowave.us
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
kozyqa.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
162.35.99.110:31337
|
ip:port | win.sliver | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
45.142.143.176:31337
|
ip:port | win.sliver | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
203.159.90.207:59405
|
ip:port | win.sliver | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
106.54.62.203:65530
|
ip:port | win.sliver | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
eng--flashburn.com
|
domain | js.clearfake | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
2b93212ee63dbb290d88bc845aafae192552b6de80d93a2f4a6453afb3738676
|
sha256 | CoinMiner | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
http://116.138.107.198:36190/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://116.138.107.198:36190/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://42.233.138.140:60584/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
103.237.92.116:4782
|
ip:port | win.quasar_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
185.231.154.75:5555
|
ip:port | win.quasar_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
66.179.29.5:7070
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
217.60.195.89:443
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
193.233.126.164:56003
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
192.229.115.243:56003
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
192.229.115.243:56004
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
217.60.195.25:56003
|
ip:port | win.pure_rat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
77.110.124.109:1882
|
ip:port | win.dcrat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
46.246.14.6:8848
|
ip:port | win.dcrat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
107.173.47.158:8808
|
ip:port | win.asyncrat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
107.173.47.158:6606
|
ip:port | win.asyncrat | botnet_cc | ThreatFox | 75% | 2026-08-25 | 🔗 |
xyrifuwu.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
i5b0fml8zh.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
81d2227a5c8ee03d1eef8af946fed3e86fe79cd7336e7b78e165356f399dd408
|
sha256 | sh | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
55719ed6adc3433dd52068a5382a526631c29ce25892e999369c86e0ff01144f
|
sha256 | sh | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
ecb348cfb45f78da9b4329e05f626edcb3e5929a58713c76c7209a201f7b8d2d
|
sha256 | exe | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
04aa7984d4ac5900ac796329af8c0557180dfbec0122ac178f2f4fc1e727eab2
|
sha256 | Vidar | Malware Sample | MalwareBazaar | — | 2026-08-25 | 🔗 |
http://125.41.8.60:36872/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://42.231.64.103:58110/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://115.57.60.24:40928/i
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
http://115.55.54.253:54557/i
|
url | — | malware_download | URLhaus | — | 2026-08-25 | |
http://42.231.64.103:58110/bin.sh
|
url | 32-bit, elf, mips, Mozi | malware_download | URLhaus | — | 2026-08-25 | |
mavadulo.workers.dev
|
domain | php.shin_webshell | botnet_cc | ThreatFox | 50% | 2026-08-25 | 🔗 |
visitoldcastle.com
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
walpot-technics.be
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
waterandfiredamagewebsites.com
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
whatpond.com
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
yossiuzan.com
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
yourchoicevending.com.au
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
ypialukhuwah.com
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
yumyumspopcorn.com
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
trofeodelleindustrie.it
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
tvdeschefs.com
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
uicimmigration.com
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
underthewheels.com
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
up20perugia.it
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
usapathlite.com
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
usir.cz
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
velkacenamohelnice.cz
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
tera-terre.org
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
terapioghealing.dk
|
domain | unknown_loader | payload_delivery | ThreatFox | 100% | 2026-08-25 | 🔗 |
Analyst Tools
Paste raw text — emails, reports, logs — to automatically extract and classify all IOCs.
| IOC Value | Type | Defanged | Actions |
|---|
Enter any IOC — type is auto-detected and a curated set of intel sources appears.
Decode common obfuscation schemes found in malware, phishing kits, and threat reports.
Convert IOCs between defanged (report-safe) and live formats. Handles hxxp, [.], and [://] notations.
Convert timestamps between Unix epoch, UTC, and local time. Paste any format into any field.
Paste raw email headers to extract the sending chain, authentication results (SPF / DKIM / DMARC), originating IPs, and timing data.
Threat Intelligence News
The Hacker News
- Aug 25U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesCritical Infra
- Aug 25A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
- Aug 25WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and AndroidPhishing
- Aug 25Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
- Aug 25Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
Dark Reading
- Aug 25Hidden Prompts Trick AI Into False Email Summaries
- Aug 25Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
- Aug 25Is Cyber Facing an Affordability Crisis?
- Aug 24Exploited Zimbra Flaw Highlights Shrinking Window to Patch
- Aug 24Foul Language: WordlistLoader Disguises Malware as Ordinary TextMalware
The Record
- Aug 2558 arrested in international cybercrime crackdown
- Aug 25Insurance benefits platform Paylogix says hackers stole financial and health data
- Aug 25Ukraine to give Britain access to battlefield data to train AI
- Aug 25UK government seeks powers to secretly block risky tech suppliers
- Aug 25Large DDoS attack knocks Norwegian public services offline
CISA Alerts
- Aug 25Bendix EC80 Brake ECU
- Aug 25FURUNO FA-50 Class B AIS Transponder
- Aug 25Siemens SIMATIC IoT2050 Advanced
- Aug 25Zoneminder
- Aug 25PayRange API
SANS Internet Storm Center
- Aug 25Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
- Aug 25ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)
- Aug 24DOUBLECUP's PNG Payload, (Mon, Aug 24th)
- Aug 24ISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064, (Mon, Aug 24th)
- Aug 20Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)
Malwarebytes Labs
- Aug 25Encrypted instructions can fool AI assistants like Grok and Gemini
- Aug 25GTA 6 leak hunt could expose data belonging to thousands of Discord users
- Aug 25TikTok phishing: How to spot fake login and verification pagesPhishing
- Aug 24Fake GTA 6 Extended Look and demo sites deliver an infostealerMalware
- Aug 24Fake Microsoft security scans trick victims into uninstalling their antivirus
Infosecurity Magazine
- Aug 25ZeroTokens Phishing Platform Steers Attacks in Real TimePhishing
- Aug 25Fake Recruiter Scams Target Corporate Credentials on Mobile
- Aug 25Australia Warns of Active Exploitation of Critical TeamCity Server Flaw
- Aug 25Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure TakedownMalware
- Aug 25ReliaQuest Rejects Compromise Claims After ShinyHunters Incident
Ransomware activity
| Victim Name | Ransom Group | Industry / Sector | Country | Date Discovered |
|---|---|---|---|---|
|
Brazosport College
NEW
|
qilin | Education | US | 2026-08-25 |
|
ma***up
NEW
|
AuditTeam | General | RU | 2026-08-25 |
|
industry.airliquide.kr
NEW
|
safepay | Manufacturing | KR | 2026-08-25 |
|
parkderochie.com
NEW
|
chaos | Other | NL | 2026-08-25 |
|
mswalker.com
NEW
|
chaos | Professional Services | US | 2026-08-25 |
|
copcp.com
NEW
|
chaos | General | CN | 2026-08-25 |
|
SC PaderTeG Cabluri Electrice
NEW
|
qilin | Manufacturing | RO | 2026-08-25 |
|
National Kidney Registry
NEW
CRITICAL SECTOR
|
direwolf | Healthcare | US | 2026-08-25 |
|
Studio Legale ESE
NEW
|
direwolf | Professional Services | IT | 2026-08-25 |
|
Tiseo Paving
NEW
|
Global Secret Group | Transportation | US | 2026-08-25 |
|
Johnson City Honda
NEW
|
Global Secret Group | Retail & E-Commerce | US | 2026-08-25 |
|
Lockheed Architectural Solutions, Inc.
NEW
CRITICAL SECTOR
|
Global Secret Group | Government & Defense | US | 2026-08-25 |
|
Sinar Mas Agribusiness and Food Golden Agri-Resources)
NEW
|
ShadowByt3$ | Agriculture and Food Production | ID | 2026-08-25 |
|
A-Plus Software Limited
NEW
|
ShadowByt3$ | Technology | GB | 2026-08-25 |
|
Knottingham Trent University
NEW
|
ShadowByt3$ | Education | GB | 2026-08-25 |
|
S*******
NEW
|
genesis | General | Unknown | 2026-08-25 |
|
TINYpulse NINTENDO BREACH (nintendo.com)
NEW
|
ShadowByt3$ | Technology | JP | 2026-08-25 |
|
Redacted
NEW
|
kazu | General | Unknown | 2026-08-25 |
|
WINTER Ingenieure
NEW
|
akira | Manufacturing | DE | 2026-08-25 |
|
STRUCTURED SETTLEMENT CAPITAL LLC
NEW
|
qilin | Financial Services | US | 2026-08-25 |
|
Davis & Ferber
NEW
|
akira | Professional Services | Unknown | 2026-08-25 |
|
AGROLAND S.A.
NEW
|
qilin | Agriculture and Food Production | RO | 2026-08-25 |
|
Pump Engineering Company
NEW
|
Dark Project | Manufacturing | US | 2026-08-25 |
|
PCA Group Sdn. Bhd.
NEW
|
majinahanashi | Other | MY | 2026-08-25 |
|
Dentist in New Britain, CT
NEW
CRITICAL SECTOR
|
Dark Project | Healthcare | US | 2026-08-25 |
|
Cosmon
NEW
|
beast | Technology | US | 2026-08-25 |
|
Consultores de Seguros
|
qilin | Financial Services | Unknown | 2026-08-24 |
|
SHAHEEN LAW GROUP PLC - Richmond, Virginia, USA
|
Deadlock | Professional Services | US | 2026-08-24 |
|
FBC
|
Deadlock | General | ZA | 2026-08-24 |
|
lagegepesca.it
|
safepay | Agriculture and Food Production | IT | 2026-08-24 |
|
The Liberty Group
|
Dark Project | General | US | 2026-08-24 |
|
Jones, Little & Co., CPAs, LLP
|
Dark Project | Professional Services | US | 2026-08-24 |
|
Design-Aire Engineering, INC
|
Dark Project | Manufacturing | US | 2026-08-24 |
|
Furnished Quarters
|
Dark Project | Hospitality | US | 2026-08-24 |
|
Frato
|
dragonforce | Other | BR | 2026-08-24 |
|
Criba
|
dragonforce | Technology | AR | 2026-08-24 |
|
FFKR Architects
|
incransom | Professional Services | US | 2026-08-24 |
|
Brookview Financial
|
dragonforce | Financial Services | CA | 2026-08-24 |
|
Wozair
|
dragonforce | Other | AE | 2026-08-24 |
|
Bihl
|
akira | Other | DE | 2026-08-24 |
|
Davroc
|
Booba Project | Technology | GB | 2026-08-24 |
|
Chernyy & Associates
|
Booba Project | Professional Services | RU | 2026-08-24 |
|
ManagementPro
|
arcusmedia | Professional Services | Unknown | 2026-08-24 |
|
Mark’Techno
|
arcusmedia | Technology | Unknown | 2026-08-24 |
|
Government of Vojvodina
CRITICAL SECTOR
|
Panzer | Government & Defense | RS | 2026-08-24 |
|
Coldfish Seafood
|
qilin | Agriculture and Food Production | CA | 2026-08-24 |
|
www.ptesm.com
|
blackwater | General | PT | 2026-08-24 |
|
Meridian Forest Services
|
beast | Agriculture and Food Production | CA | 2026-08-24 |
|
Country-Wide Insurance
|
Booba Project | Financial Services | US | 2026-08-24 |
|
Federis Abogados
|
Booba Project | Professional Services | MX | 2026-08-24 |
|
Senvibe
|
Panzer | Technology | Unknown | 2026-08-24 |
|
A&E + SMA Design
|
qilin | Professional Services | AE | 2026-08-24 |
|
Sharp Motor Group
|
Storm | Transportation | AU | 2026-08-24 |
|
City of Mitchell
CRITICAL SECTOR
|
Storm | Government & Defense | US | 2026-08-24 |
|
resi.com
|
krybit | Retail & E-Commerce | DE | 2026-08-24 |
|
Hospitality Health ER (Longview)
CRITICAL SECTOR
|
genesis | Healthcare | US | 2026-08-23 |
|
Westwing Group SE
|
coinbasecartel | Retail & E-Commerce | DE | 2026-08-23 |
|
CyrusOne, LLC.
|
shinyhunters | Technology | US | 2026-08-23 |
|
S.E.M.P. s.r.l.
|
qilin | Manufacturing | IT | 2026-08-23 |
|
adt.com
|
lockbit5 | Professional Services | US | 2026-08-23 |
|
Global Go
|
killsec | Transportation | PE | 2026-08-23 |
|
Euroflora srl
|
qilin | Agriculture and Food Production | IT | 2026-08-23 |
|
Tecnici Associati STP
|
qilin | Other | IT | 2026-08-23 |
|
Studio BOLDRIN PAOLO
|
qilin | Professional Services | IT | 2026-08-23 |
|
Aurore Development S.p.A.
|
qilin | Other | IT | 2026-08-23 |
|
compendiumusa.net
|
L Group | Professional Services | US | 2026-08-23 |
|
Clear Align
|
qilin | Professional Services | US | 2026-08-23 |
|
Difor
|
qilin | Technology | CL | 2026-08-23 |
|
Black Cat Engineering & Construction WLL
|
qilin | Manufacturing | QA | 2026-08-23 |
|
FRUCASTRO SL
|
emperador | Agriculture and Food Production | ES | 2026-08-23 |
|
PappyJoe: Healthcare Management System
CRITICAL SECTOR
|
kazu | Healthcare | US | 2026-08-23 |
|
Instituto Ferrero de Neurología y Sueño
CRITICAL SECTOR
|
kazu | Healthcare | AR | 2026-08-23 |
|
Brazil Mobilemed: Cloud PACS Platform
CRITICAL SECTOR
|
kazu | Healthcare | BR | 2026-08-23 |
|
Canada Yocale: Appointment Management System
|
kazu | Professional Services | CA | 2026-08-23 |
|
PawlyClinic: Digital Veterinary Care Platform
CRITICAL SECTOR
|
kazu | Healthcare | US | 2026-08-23 |
|
Dr Akbar Niazi Teaching Hospital
CRITICAL SECTOR
|
kazu | Healthcare | PK | 2026-08-23 |
|
Centro Médico Especializado OSI: Healthcare Solutions
CRITICAL SECTOR
|
kazu | Healthcare | MX | 2026-08-23 |
|
Meducar: Telemedicine and Patient Management System
CRITICAL SECTOR
|
kazu | Healthcare | BR | 2026-08-23 |
|
ConsultorioMovil: Telemedicine and Healthcare System
CRITICAL SECTOR
|
kazu | Healthcare | MX | 2026-08-23 |
|
Woodlore International Inc.
|
metaencryptor | Other | CA | 2026-08-23 |
|
Trailer Transit Inc
|
metaencryptor | Transportation | US | 2026-08-23 |
|
Weber Water Resources
CRITICAL SECTOR
|
metaencryptor | Energy & Utilities | US | 2026-08-23 |
|
MPA Pharma GmbH
CRITICAL SECTOR
|
metaencryptor | Healthcare | DE | 2026-08-23 |
|
Aquamar Inc
|
metaencryptor | Agriculture and Food Production | US | 2026-08-23 |
|
Corona Corporation
|
metaencryptor | Other | JP | 2026-08-23 |
|
FactoryFive
|
metaencryptor | Manufacturing | US | 2026-08-23 |
|
Skyline Implants & Periodontics
CRITICAL SECTOR
|
Barracuda | Healthcare | US | 2026-08-23 |
|
Namyang Industrial Co., Ltd.
|
Barracuda | Manufacturing | KR | 2026-08-23 |
|
Clinical Associates of the Finger Lakes (CAFL)
CRITICAL SECTOR
|
Barracuda | Healthcare | US | 2026-08-23 |
|
PCA *****
|
majinahanashi | General | Unknown | 2026-08-23 |
|
Ruggles Sign Company
|
Storm | Manufacturing | US | 2026-08-23 |
|
AutoDie
|
Storm | Manufacturing | US | 2026-08-23 |
|
Proveli
|
Storm | Technology | US | 2026-08-23 |
|
Pinnacle Hospital
CRITICAL SECTOR
|
Storm | Healthcare | US | 2026-08-23 |
|
Phoenix Group of Companies
|
Storm | Other | US | 2026-08-23 |
|
Schardein Mechanical
|
Storm | Manufacturing | US | 2026-08-23 |
|
The Cecilian Bank
|
Storm | Financial Services | US | 2026-08-23 |
|
Crystal Pharmatech
CRITICAL SECTOR
|
Eclipse | Healthcare | US | 2026-08-23 |
|
AGS Cinemas
|
thegentlemen | Hospitality | IN | 2026-08-23 |
|
Eyecare Center of Snohomish
CRITICAL SECTOR
|
thegentlemen | Healthcare | US | 2026-08-23 |
qilin
thegentlemen
global secret group
direwolf
clop
incransom
storm
l group
coinbasecartel
crpxo
section9
nightspire
settra
akira
deadlock
dragonforce
genesis
shinyhunters
safepay
kazu
panzer
aurora
krybit
lockbit5
xpl0itrs
booba project
metaencryptor
play
silentransomgroup
anubis
blacknevas
chaos
dark project
spacebears
cmdorganization
majinahanashi
medusalocker
pear
bravox
emperador
insomnia
payload
rhysida
shadowbyt3$
barracuda
ethics
everest
gunra
helix
interlock
kairos
orova
termite
unsafe
ailock
arcusmedia
auditteam
beast
black x
bluewhale
eclipse
gammax
m3rx
securotrop
wallstreet
blackwater
doommageddon
exfilsquad
iah6477
killsec
kyber
morpheus
ransomhouse
threeam
0apt
0day syndicate
0mega
8base
abrahams_ax
abyss
adminlocker
againstthewest
agl0bgvycg
ako
alp-001
alphalocker
alphv
apos
apt73
aptlock
argonauts
arkana
arvinclub
atomsilo
avaddon
avos
avoslocker
aware
aztroteam
babuk
babuk2
babyduck
benzona
bert
bianlian
blackbasta
blackbyte
blackfield
blacklock
blackmatter
blackout
blackshadow
blackshrantac
blacksuit
blacktor
bluebox
bluelocker
bluesky
bolt team
bonacigroup
bqtlock
braincipher
brotherhood
cactus
cephalus
cheers
chilelocker
chort
cicada3301
ciphbit
cipherforce
cloak
contfr
conti
cooming
crazyhunter
crosslock
cry0
crylock
cryp70n1c0d3
cryptbb
cryptnet
crypto24
cuba
cyclops
d1r
d4rk4rmy
dagonlocker
daixin
dan0n
darkangels
darkbit
darkleakmarket
darkmatter
darkpower
darkrace
darkside
darkvault
datacarry
datakeeper
dataleak
desolator
devman
diavol
dispossessor
donex
donutleaks
doppelpaymer
dragonransomware
dread
dunghill
dysphor1a
ech0raix
eldorado
embargo
entropy
ep918
esxiargs
exitium
exorcist
fletchen
flocker
fog
frag
freecivilian
fsteam
fulcrumsec
funksec
gdlockersec
global
goddamn ransomwhere
grief
groove
hades
handala
haron
hellcat
helldown
hellogookie
hellokitty
hive
holyghost
hotarus
hunters
icarus
icefire
imncrew
insane
j
karakurt
karma
kawa4096
kelvinsecurity
kittykatkrew
knight
kraken
kryptos
la_piovra
lamashtu
lapsus$
leakbazaar
leaktheanalyst
lilith
linkc
lockbit
lockbit2
lockbit3
lockbit3_fs
lockdata
loki
lolnek
lorenz
losttrust
lunalock
lv
lynx
madcat
madliberator
malas
malekteam
mallox
mamona
marketo
maze
mbc
medusa
meow
midas
mindware
minteye
mnt6
mogilevich
moneymessage
montage
monti
mortar
mosesstaff
mountlocker
ms13089
mydecryptor
n3tworm
nasirsecurity
nblock
nefilim
nemty
netrunner
netwalker
nevada
nightsky
nitrogen
noescape
nokoyawa
noname
notpetya
nova
obscura
onepercent
onyx
orca
orion
osiris
pandora
pay2key
payday
payloadbin
payoutsking
playboy
prinzeugen
projectrelic
prolock
prometheus
promptlock
pysa
qiulong
qlocker
quantum
rabbithole
radar
radiant
ragnarlocker
ragnarok
ralord
ramp
rancoz
ranion
ransombay
ransomcartel
ransomcortex
ransomed
ransomexx
ransomhub
ranstreet
ranzy
raworld
raznatovic
rebornvc
redact
redalert
redransomware
revil
reynolds
robinhood
rook
royal
rransom
runsomewares
sabbath
sarcoma
satanlockv2
secp0
sensayq
sevyware
shadow
shaoleaks
shiba
shinysp1d3r
sicarii
siegedsec
silent
sinobi
skira
slug
snatch
solidbit
sovcali
sparta
spook
stormous
sugar
suncrypt
synack
teamxxx
tengu
the green blood group
the syndicate
thegreenbloodgroup
timc
titan
tommyleaks
toufan
tridentlocker
trigona
trinity
triple x
trisec
u-bomb
ulose
underground
unknown
valencialeaks
vanhelsing
vanirgroup
vect
vendetta
vfokx
vicesociety
walocker
wannacry
warlock
werewolves
weyhro
worldleaks
x001xs
xinglocker
xinof
xp95
yanluowang
yurei
zeon
zerolockersec
zerotolerance
Global Victim Distribution (30 days)
Targeted Sectors (30 days)
Top Targeted Countries (30 days)
| Country | Incidents (30d) | Share |
|---|---|---|
| US | 292 |
|
| DE | 45 |
|
| IT | 32 |
|
| GB | 28 |
|
| CA | 25 |
|
| BR | 23 |
|
| IN | 21 |
|
| MX | 18 |
|
| FR | 15 |
|
| AU | 14 |
|
| JP | 11 |
|
| ES | 10 |
|
| AR | 10 |
|
| MY | 9 |
|
| AE | 8 |
|
Vulnerabilities
High Severity (>9.0)
CVE-2026-65093
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit...
CVE-2026-55536
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome ex...
CVE-2026-55640
Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.11...
CVE-2026-65083
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an in...
CVE-2026-63586
The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication u...
CVE-2026-59769
FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel'...
CVE-2026-55546
QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engin...
CVE-2026-45018
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0,...
CVE-2026-16286
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware...
Medium Severity (5.0 - 8.9)
CVE-2026-67578
FA-50 all versions miss authentication for some configuration. An attacker with access to the vesse...
CVE-2026-69104
An authenticated user may initiate repository migration operations without required repository permi...
CVE-2026-68515
OpenEXR is the reference implementation and specification for the EXR image format, widely used in t...
CVE-2026-68960
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If t...
CVE-2026-65091
NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS...
CVE-2026-65092
NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path tra...
CVE-2026-68062
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerabili...
CVE-2026-68514
OpenEXR is the reference implementation and specification for the EXR image file format, widely used...
CVE-2026-68959
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerabili...
CVE-2026-65087
NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected cred...
CVE-2026-65090
NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacke...
CVE-2026-61555
OpenEXR is the reference implementation and specification for the EXR image format, widely used in t...
CVE-2026-59985
OpenEXR is the reference implementation and specification for the EXR image format, widely used in t...
CVE-2026-65082
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker ...
CVE-2026-59984
OpenEXR is the reference implementation and specification for the EXR image format, widely used in t...
CVE-2026-68513
OpenEXR is the reference implementation and specification for the EXR image format, widely used in t...
CVE-2026-55528
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes Server...
CVE-2026-55581
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0...
CVE-2026-64202
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info...
CVE-2026-65089
NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an ...
CVE-2026-55609
sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant s...
CVE-2026-55663
mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm packag...
CVE-2026-65096
NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attack...
CVE-2026-65085
NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could ...
CVE-2026-65084
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker coul...
CVE-2026-55537
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhoo...
CVE-2026-48424
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in...
CVE-2026-48428
Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i...
CVE-2026-64204
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info...
CVE-2026-59983
OpenEXR is the reference implementation and specification for the EXR image format, widely used in t...
CVE-2026-59982
OpenEXR is the reference implementation and specification for the EXR image format, widely used in t...
CVE-2026-64203
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info...
CVE-2026-55529
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_or...
CVE-2026-65081
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker co...
CVE-2026-55525
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function val...
CVE-2026-55527
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor...
CVE-2026-24169
NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated ...
CVE-2026-55531
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post han...
CVE-2026-55530
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the...
CVE-2026-24225
NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be a...
CVE-2026-55534
PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents ...
CVE-2026-55540
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses ...
CVE-2026-55553
urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other re...
CVE-2026-65088
NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using v...
CVE-2026-55533
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows ...
CVE-2026-55588
ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORA...
CVE-2026-65086
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker c...
CVE-2026-65098
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an at...
CVE-2026-48419
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit...
CVE-2026-57863
Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that all...
CVE-2026-63587
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the ...
CVE-2026-66109
A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vu...
CVE-2026-48425
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in...
CVE-2026-48421
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit...
CVE-2026-48423
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in...
CVE-2026-48426
Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbi...
CVE-2026-48427
Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbi...
CVE-2026-48431
Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i...
CVE-2026-59981
OpenEXR is the reference implementation and specification for the EXR image file format, widely used...
CVE-2026-48430
Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i...
CVE-2026-48432
Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i...
CVE-2026-48433
Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result i...
CVE-2026-19851
A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 c...
CVE-2026-55099
icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 u...
CVE-2026-24167
NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authentica...
CVE-2026-55532
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin...
CVE-2026-24262
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could ...
CVE-2026-55419
Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exp...
CVE-2026-24166
NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacke...
CVE-2026-55526
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_bloc...
CVE-2026-19949
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archi...
CVE-2026-24168
NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker ...
CVE-2026-17587
The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to au...
CVE-2026-13216
The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during dri...
CVE-2026-24170
NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where a...
CVE-2026-48420
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit...
CVE-2026-18100
The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress i...
CVE-2026-55539
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function...
CVE-2026-55538
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses co...
CVE-2026-55571
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe...
CVE-2026-18323
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln...
CVE-2026-55582
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0...
CVE-2026-55585
QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, to...
CVE-2026-55619
eml_parser serves as a python module for parsing eml files and returning various information found i...
CVE-2026-55618
eml_parser serves as a python module for parsing eml files and returning various information found i...
CVE-2026-55620
eml_parser serves as a python module for parsing eml files and returning various information found i...
CVE-2026-16233
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info...
CVE-2026-18328
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln...
CVE-2026-16231
hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars...
CVE-2026-16234
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info...
CVE-2026-64201
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info...
CVE-2026-18444
There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images ...
CVE-2026-55535
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_ur...
CVE-2026-65097
NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker co...
CVE-2026-65099
NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker ...
CVE-2026-65105
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote att...
CVE-2026-21754
HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which cou...
CVE-2026-45019
Chainlit is a Python framework for building production-ready conversational AI applications. From 2....
CVE-2026-18445
There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered i...
CVE-2026-48418
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit...
CVE-2026-18547
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Mem...
CVE-2026-59184
OpenEXR is the reference implementation and specification for the EXR image format, widely used in t...
CVE-2026-18512
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner...
CVE-2026-47624
NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privile...
CVE-2026-47626
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could ...
CVE-2026-59335
Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Iden...
CVE-2026-48417
Substance3D - Sampler is affected by a Stack-based Buffer Overflow vulnerability that could result i...
CVE-2026-59186
OpenEXR is the reference implementation and specification for the EXR image format, widely used in t...
CVE-2026-59187
OpenEXR is the reference implementation and specification for the EXR image format, widely used in t...
CVE-2026-59189
OpenEXR is the reference implementation and specification for the EXR image format, widely used in t...
CVE-2026-48429
Substance3D - Designer is affected by a NULL Pointer Dereference vulnerability that could result in ...
CVE-2026-16601
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vu...
CVE-2026-24263
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could ...
CVE-2026-13217
The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the ...
CVE-2026-48422
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in...
CVE-2026-13478
The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ex...
CVE-2026-69665
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If thi...
Low Severity (1.0 - 4.9)
CVE-2026-62986
OpenEXR is the reference implementation and specification for the EXR image file...
CVE-2026-26211
Ekushey Project Manager CRM stores the administrator-configured system name and ...
CVE-2026-21753
HCL Hive is affected by weak software supply chain governance, which could lead ...
CVE-2026-21758
HCL Hive is affected by an information disclosure vulnerability, which could lea...
CVE-2026-79014
Race condition in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CVE-2026-79785
X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto_labeling/model.py built a context with ssl._create_unverified_context() and passed it to urllib.request.urlopen, so neither the certificate chain nor the hostname was checked on any model download, and models are fetched over HTTPS from the project's release host. Any party positioned to intercept that connection could therefore answer it with content of their own choosing. The response is written to a .part file and moved into place with os.replace, and the only post-download check, safe_check_model, validates the file's format rather than its provenance: no hash or signature is compared against an expected value. For an ONNX target the substituted file passes onnx.checker.check_model and is then used for inference, so the attacker chooses the model that produces the application's annotations. For a .pth or .pt target, which the shipped SAM2 video, YOLOE, UPN and open_vision configurations use, the check worker calls torch.load without weights_only, so a substituted file is unpickled and executes code of the attacker's choosing on PyTorch releases predating the weights_only default.
CVE-2026-79027
Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: High)
CVE-2026-75770
Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-79039
Use after free in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
CVE-2026-55546
QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strings directly to SymPy's parse_expr() after only normalizing caret syntax to Python exponent syntax, without restricting global_dict, removing Python built-ins, or validating the expression AST. Because parse_expr() calls Python's eval() with built-ins available, an attacker who can cause a downstream caller to pass untrusted input to this public library function can use Python import functionality to execute arbitrary operating-system commands as the qwed-mcp process user, read or modify accessible data, exfiltrate process secrets, or reach internal services. The default MCP tool registry does not expose verify_math_expression(), so exploitation requires a downstream integration that invokes the library API with attacker-controlled input. This issue is fixed in version 0.2.1.
CVE-2026-68959
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an incomplete fix for CVE-2024-41726.
CVE-2026-78942
Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)
CVE-2026-55535
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on socket.gaierror and does not bind the validated address to the later request. An attacker webhook_url can later resolve to 127.0.0.1, 169.254.169.254, or another internal address. This issue is fixed in version 4.6.58.
CVE-2026-21754
HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within internal communications.
CVE-2026-59981
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
CVE-2026-78969
Uninitialized resource in Video in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79249
Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted file. (Chromium security severity: Medium)
CVE-2026-59983
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to an out-of-bounds read. The vulnerability is reached when a crafted uncompressed deep-tile EXR causes the sample-count table size calculation in OpenEXRCore decoding.c to wrap before unpack_sample_table() iterates over the full attacker-controlled tile dimensions, allowing denial of service. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
CVE-2026-79773
Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authenticated users with cms.manage_assets permission to disclose arbitrary server-readable files by placing =include or =require directives in theme JavaScript assets. Attackers can reference files like .env outside the theme directory, and the combined output served through the combine route becomes readable by unauthenticated visitors, exposing application keys and database credentials.
CVE-2026-77133
The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default field configuration, allowing self-service privilege escalation into arbitrary frontend groups.
CVE-2026-55637
genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3.2, the Streamable HTTP transport in cmd/server/main.go creates an unauthenticated /mcp listener on the default MCP_LISTEN_ADDR value 127.0.0.1:8080 when MCP_AUTH_TOKEN is unset and the httpSrv.Start(addr) branch does not validate the Host or Origin headers. A malicious website can use DNS rebinding to send browser requests with attacker-controlled Host and Origin values to the loopback listener, initialize an MCP session, list tools, and invoke operations against the GenieACS NBI configured by ACS_URL. Successful exploitation can expose or modify CPE management state, including device reboots, firmware tasks, TR-069 parameter changes, presets, provisions, tags, connection requests, and task operations. The npm wrapper is not affected because it forces TRANSPORT=stdio and does not expose an HTTP listener. This issue is fixed in version 0.3.2.
CVE-2026-79258
Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-18798
Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable. CWE: CWE-415: Double Free Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_channel(), so it becomes part of the newly created connection. If port_bind_channel() fails, then it also frees the QRX object. Once port_bind_channel() returns, the port_default_packet_handler() detects the failure and proceeds to the error branch, where the same QRX object is freed for the second time. The failure in port_bind_channel() function can be induced with a relatively low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet carries DCID (destination connection ID) which is shorter than 8 bytes, then port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid() detects that the DCID has invalid length. FIPS impact: no The FIPS module is not affected, as the QUIC implementation is outside of the OpenSSL FIPS module boundary.
CVE-2026-76197
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-24263
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
CVE-2026-78962
Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-78948
Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-79271
Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-78937
Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-78957
Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low)
CVE-2026-76128
The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload bypasses WordPress's save-time wp_kses_post sanitization because the malicious content is stored inside shortcode brackets with no HTML tags; the tainted HTML output is only generated at render time by the shortcode handler.
CVE-2026-78909
Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-48421
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-79030
Observable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79195
Use after free in Script in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-66422
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CVE-2026-78887
A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation can lead to incorrect authorization. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is said to be difficult. Upgrading to version 3.1.0 will fix this issue. You should upgrade the affected component.
CVE-2026-79251
Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79106
Improper input validation in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-76193
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVE-2026-79117
Race condition in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app. (Chromium security severity: High)
CVE-2026-80182
In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.
CVE-2026-79659
Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL validation. Authenticated attackers can supply arbitrary URLs to access internal services and cloud metadata endpoints by triggering connection health checks or peer connection operations.
CVE-2026-78885
A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/services/oidcService.ts of the component OIDC Service. Such manipulation leads to improper authentication. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is regarded as difficult. Upgrading to version 3.1.0 is sufficient to resolve this issue. Upgrading the affected component is advised.
CVE-2026-79273
Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79054
Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-79155
Race condition in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-77680
An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed memory amplification when a client repeated the same range many times in a single Range header. Commit 9bb92f7a corrected merge correctness in soup_message_headers_get_ranges_internal() in libsoup/soup-message-headers.c, but the coalescing loop still removes merged ranges using g_array_remove_index() for each coalesced element. Because GArray is contiguous, each mid-array removal performs an O(N) memmove. When many identical satisfiable ranges are supplied (for example bytes=0-0 repeated thousands of times), the loop performs O(N²) work coalescing them into a single range. The vulnerable path is reachable server-side from handle_partial_get() in libsoup/server/http1/soup-server-message-io-http1.c when a SoupServer handler returns HTTP 200 with a non-empty body. No authentication is required. The number of ranges is bounded only by the maximum request header size (~100 KiB), allowing roughly 25,000 ranges per request. Reporter measurements on libsoup HEAD containing the CVE-2025-32907 fix show ~90 ms single-core CPU per such request at the wire maximum, blocking the server's event loop for that duration. This is a CPU exhaustion / availability issue only. No memory corruption or information disclosure occurs. Affected: libsoup versions containing the CVE-2025-32907 fix but not merge request !550. Fixed upstream: MR !550 merged 2026-08-20, replacing per-element removal with O(N) in-place compaction and rejecting Range headers requesting more than 200 ranges. Upstream report: https://gitlab.gnome.org/GNOME/libsoup/-/issues/538 Related: CVE-2025-32907
CVE-2026-79107
Incorrect authorization in TabGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially leak sensitive information via crafted network traffic. (Chromium security severity: Medium)
CVE-2026-79071
Race condition in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79200
Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-79221
Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79123
Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-68515
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap allocation when it combines two attacker-supplied, individually valid scanline EXR files whose union dataWindow is not aligned to one view's channel subsampling. The utility allocates sampled channel storage using a truncated union_width / xSampling, then reads the sampled input through a Slice based on the misaligned union window, producing a heap out-of-bounds write. The trigger is normal public-tool processing, such as exrmultiview left A.exr right B.exr out.exr with crafted but valid inputs, so this is not solely an API or caller-precondition issue. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
CVE-2026-79252
Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79007
Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79204
UI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79769
Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#initialize_copy_with_args helper behind Node#dup and #clone, which unwrapped its source argument as an xmlNode without a type check. If application code calls this protected method with a non-Node argument (e.g., a Namespace), it reads an xmlNs out of bounds, crashing the process. This is only triggerable by a programming error and cannot be triggered by untrusted input or normal use of the public API. Only CRuby is affected. Version 1.19.4 adds a type check and raises TypeError.
CVE-2026-75496
Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.
CVE-2026-12600
Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. When an application processes an untrusted PDF file containing specially crafted JPXDecode images, a remote attacker can cause uncontrolled memory consumption. The flaw occurs in the JPXStream::readCodestream() function, where values controlled from the SIZ segment (such as img.nComps) are used for the memory allocation of tiles and components without adequate validation. This allows an attacker to force excessive memory allocation and cause a resource exhaustion, ultimately causing the pdftoppm process to terminate due to out-of-memory (OOM) conditions.
CVE-2026-79098
UI misrepresentation in PermissionElement in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79792
A flaw has been found in zackees transcribe-anything up to 4.1.0. Affected is the function ytdlp_download of the file src/transcribe_anything/ytldp_download.py of the component Yt-dlp Download. This manipulation of the argument url causes os command injection. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is told to be difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-79068
Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-55663
mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded msworker and 0xAD81 magic values instead of a per-instance secret and HMAC, contrary to RFC 9260 Section 5.1.3. The cookie structure and validation in worker/include/RTC/SCTP/association/StateCookie.hpp and worker/src/RTC/SCTP/association/StateCookie.cpp allow an on-path attacker targeting PlainTransport or PipeTransport with SCTP enabled and without DTLS protection to forge a COOKIE-ECHO whose packet verification tag matches the attacker-controlled localVerificationTag. The forged cookie passes StateCookie::IsMediasoupStateCookie() and Association::HandleReceivedCookieEchoChunk(), establishes an unauthorized SCTP association, and permits DataChannel message injection as a trusted peer. WebRtcTransport is not affected because its SCTP runs inside DTLS. This issue is fixed in npm version 3.20.6 and Rust crate version 0.22.5.
CVE-2026-79033
Insufficient control flow management in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79078
Use after free in FedCM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-48431
Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-79045
Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-38466
A Stored XSS vulnerability in the torrent remaster custom title feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the remaster_custom_title parameter, which is stored during torrent upload or edit and later rendered in torrent title output.
CVE-2026-56095
The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object types, rather than a safe format. If user-generated content saved in the TYPO3 database can reach an indexed field, this exposes a PHP Object Injection surface.
CVE-2026-79227
Type confusion in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-80050
ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. Attackers can initialize chunked uploads, send file parts, and complete uploads to leave arbitrary files in the storage backend accessible via web server URLs.
CVE-2026-78896
Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79287
Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79038
Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79194
Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
CVE-2026-65633
Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. The bearer-token authentication helper AshAuthentication.Plug.Helpers.retrieve_from_bearer/3 verifies an Authorization: Bearer JWT's signature and rejects tokens containing an act claim, but performs no check that the token's purpose claim equals user at the bearer boundary. When the resource is configured with require_token_presence_for_authentication?: false (the DSL default), the follow-on validate_token/3 helper returns {:ok, nil} without consulting the token resource, so no downstream check on purpose takes place either. As a result, any valid, non-expired JWT the library itself issued for a narrow, single-purpose flow (most notably the purpose: sign_in token that WebAuthn always emits during sign-in, and that the Password strategy emits when sign-in tokens are enabled) is accepted directly as a general-purpose bearer credential and resolves to a full current_user assignment. This bypasses the library's intended token-exchange contract, in which the sign_in token is meant to be presented exactly once to a preparation that validates the purpose claim and immediately revokes the token. The first use of a still-valid sign-in token presented directly in the Authorization header succeeds because the stateless bearer path never scopes it to purpose == "user". An attacker who obtains a not-yet-exchanged sign-in token for a target subject (for example via log or referrer leakage, an intercepted magic-link delivery channel, or a partially compromised intermediary) can present it as a bearer token and be authenticated as that subject, fully bypassing the intended one-time-use and revocation semantics. Exploitation additionally requires that the host application wire up retrieve_from_bearer/3 on a reachable route and uses either WebAuthn (sign-in tokens are always issued) or the Password strategy with sign_in_tokens_enabled?: true. Resources configured with require_token_presence_for_authentication?: true (including applications scaffolded by the Igniter installer since v4.5.0) and the session-based path (authenticate_resource_from_session/4) enforce purpose == "user" against the stored token record and are not affected. This issue affects ash_authentication: from 3.10.5 before 4.14.2 and from 5.0.0-rc.0 before 5.0.0-rc.13.
CVE-2026-78893
Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79783
rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise.
CVE-2026-56096
The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to enumerate indexed field names and extract their stored values through boolean- and range-based blind extraction techniques, independent of any site-specific configuration.
CVE-2026-16233
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
CVE-2026-68525
Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.
CVE-2026-79179
Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-68569
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CVE-2026-55534
PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. A network caller can invoke configured agents without credentials even when an API key was supplied. This issue is fixed in version 4.6.58.
CVE-2026-78967
Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-21753
HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment.
CVE-2026-47626
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
CVE-2026-74932
The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files it embeds in the pages it caches, and does not include that header in the cache key, allowing unauthenticated attackers to poison cached pages with references to a server they control and have arbitrary JavaScript run for every subsequent visitor.
CVE-2026-78945
Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79010
Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-55540
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() rather than os.path.realpath() for the workspace boundary. A symlink inside workspace can point outside and still pass the check, allowing read_file and other code tools to access files outside the configured workspace. This issue is fixed in version 4.6.58.
CVE-2026-59982
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin. This vulnerability occurs because the API combines zero-based row access with an absolute-coordinate-adjusted base pointer, allowing a crash or limited information disclosure. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
CVE-2026-55532
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin.startswith(allowed), allowing the attacker-controlled localhost.attacker.com HTTP origin to satisfy the localhost allowlist. A webpage can send Content-Type: text/plain requests without preflight and invoke tools/call without an API key, including file writes that persist agent instructions. This issue is fixed in version 4.6.58.
CVE-2026-79138
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-79094
Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79019
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-59985
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to a heap out-of-bounds read. The issue occurs when a crafted RLE-compressed EXR causes the 64-bit unpacked size to truncate before allocation in OpenEXRCore decoding.c and unpack_32bit() reads beyond the resulting buffer, allowing denial of service. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
CVE-2026-57910
Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.
CVE-2026-79077
Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-39113
Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause a denial of service via the ext/misc/sqlar.c, sqlarUncompressFunc(), sqlar_uncompress(), sqlite3_value_int64(), sqlite3_malloc(int), uncompress() components
CVE-2026-79248
Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-16234
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
CVE-2026-55533
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows requests when auth=api-key lacks PRAISONAI_API_KEY or JWT authentication lacks PRAISONAI_JWT_SECRET. An externally bound Recipe server can therefore accept unauthenticated POST /v1/recipes/run requests despite authentication being enabled. This issue is fixed in version 4.6.58.
CVE-2026-48430
Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-79025
Improper input validation in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79095
Information leak in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-57863
Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequences to the unzip endpoint. Attackers can exploit unsanitized ZIP entry names passed to PHP's ZipArchive::extractTo() to write arbitrary PHP files into the web-accessible public directory and achieve remote code execution on the server.
CVE-2026-77996
Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector.
CVE-2026-69104
An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.
CVE-2026-18323
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) in all versions up to, and including, 1.57.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable because the Save-and-Continue draft submission AJAX endpoint is registered as nopriv, allowing unauthenticated attackers to bypass radio field option-membership validation and persist a crafted payload that, when rendered on the Submissions admin page, is auto-executed via the bundled Inputmask library's data-attribute callback binding.
CVE-2026-79199
Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-78943
Improper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-75497
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'CustomerMessage.php' file. Fixed in 123c97c.
CVE-2026-79082
Incorrect authorization in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CVE-2026-79066
Improper input validation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79241
Out of bounds read in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79196
Race condition in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-78935
Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-79291
Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79673
Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write operations including password changes. An attacker with an admin's profile:read access token can change the admin's password and login to obtain an unrestricted session token that bypasses all scope enforcement.
CVE-2026-65905
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is replayable once only while the associated nonceCount remains within the replay window. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CVE-2026-79046
Race condition in Permissions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-78938
Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-68763
Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CVE-2026-78977
Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79256
Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79088
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79228
Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-62986
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale heap data when reading a crafted deep scanline EXR that uses layer-prefixed RGB channels. With the default channel coalescing (separate_channels=False), the wrapper groups channels such as left.R, left.G, and left.B into a single RGB sample array, but the lane-offset calculation in PyPart::setDeepSliceData() only recognizes the exact unprefixed names G, B, and A. As a result, prefixed channels like left.G and left.B are decoded into lane 0 while lanes 1 and 2 are left uninitialized and returned to Python. A Python application that reads untrusted deep EXR files through the default OpenEXR.File API and then logs, serializes, previews, or otherwise processes the resulting NumPy sample arrays may expose uninitialized same-process heap contents, in addition to receiving incorrect green and blue channel data. This issue is fixed in versions 3.3.13 and 3.4.14.
CVE-2026-78963
Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79206
Out of bounds read in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79276
Improper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-38472
A Stored XSS vulnerability in forum reward comments in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote attackers to inject arbitrary JavaScript via the c parameter in /forums.php?action=ajax_get_jf which is later rendered in the data-tooltip attribute in /forums.php?action=viewthread and interpreted as HTML by the Tooltipster configuration.
CVE-2026-79149
Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-78959
Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79187
Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-78894
Race condition in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79116
Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79661
Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on the public router group without authentication or rate limiting. Unauthenticated attackers can increment the fav_count counter of any echo (including private echoes) by supplying its UUID, which can be harvested from the public GET /api/echo/page feed. Repeated requests are accepted without deduplication, each triggering a database write and a four-key cache invalidation, allowing attackers to inflate popularity metrics and amplify load on the database and cache. Fixed in 4.7.3.
CVE-2026-79004
Out of bounds read in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-65105
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
CVE-2026-79049
Incorrect reference resolution in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted file. (Chromium security severity: Medium)
CVE-2026-78980
Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-78906
Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-77140
The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UID of a visible employee record can send a direct POST request to the update action and overwrite that record without a valid edit link or any ownership check.
CVE-2026-79005
Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-48419
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-79288
Improper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
CVE-2026-63587
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.
CVE-2026-78968
Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially spoof address bar via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-78915
Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Low)
CVE-2026-65093
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CVE-2026-60004
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
CVE-2026-21962
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.
CVE-2026-73570
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
CVE-2026-72529
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
CVE-2026-72530
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
CVE-2026-64849
MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
CVE-2026-65400
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
CVE-2026-33824
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
CVE-2026-59310
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
CVE-2026-55040
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
CVE-2025-62593
Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
CVE-2026-20349
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
CVE-2026-68820
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2026-72898
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
Advanced Persistent Threats (APT)
What the Source Leak Says About HookBot
ERMAC and HookBot are two branches of one Android banking trojan sold as a service, forking from shared code originating with Cerberus. A copy of the builder, Laravel backend, and React panel leaked in August 2025, enabling unrelated operators to deploy panels with default credentials and keys still in place. The lineage runs Cerberus to ERMAC to Hook, confirmed through source code analysis showing identical database migrations and network protocol structures. HookBot added VNC remote control and 38 new commands while maintaining ERMAC's core. The leaked source includes a Docker stack, Obfuscapk builder, and IP-whitelist firewall that hides panels but leaves the builder port exposed. Operators target 484 apps across 40+ countries including Japanese banks, Brazilian financial institutions, Turkish banks, and cryptocurrency wallets. Detection artifacts survive in builder obfuscator flags and favicons, while panel titles remain easily changed.
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Analysis of over 400 AI-integrated malware samples reveals that approximately 97% exist only in research repositories and sandboxes, never reaching production environments. Of 405 samples examined, only 12 appeared on protected endpoints across three countries, spanning five malware families including FunkSec ransomware, trojanized AI applications, Oyster backdoor, Rhadamanthys stealer, and COM hijacking DLLs. All samples were successfully detected and blocked by existing behavioral detection, cloud-based sandboxing and endpoint analytics. The AI component influences code authorship rather than execution patterns, enabling faster development cycles as evidenced by FunkSec's seven variants compiled within six days. Findings indicate AI lowers barriers to malware creation but has not yet enabled evasion of established defensive mechanisms, with opportunistic rather than targeted distribution patterns observed.
Tracking PavinLoader across ClickFix and fake download campaigns
A sophisticated multi-stage loader dubbed PavinLoader has been identified across multiple distribution campaigns including ClickFix attacks, fake software downloads, and malicious RenPy games. The loader employs heavily obfuscated .NET DLLs, abuses legitimate Windows tools like MSBuild, and utilizes EtherHiding technique to retrieve command-and-control domains via blockchain. The infection chain consists of four main stages: a Loader DLL performing anti-forensics, an EtherHiding Loader obtaining C2 infrastructure, an Anti-Analysis DLL checking for virtualized environments, and a PE Loader delivering final payloads including Amatera Stealer. Evidence suggests PavinLoader may be offered as a Loader-as-a-Service, with common artifacts found across over 200 related files. The campaigns demonstrate sophisticated evasion techniques including custom obfuscation, API hashing, and extensive anti-analysis checks targeting virtualized environments and specific geographic regions.
Fake GTA 6 Extended Look and demo sites deliver an infostealer
Cybercriminals are exploiting the hype surrounding Grand Theft Auto VI by creating fake Rockstar Games websites that appear in search results offering a GTA 6 demo. These sites impersonate legitimate promotional material for Rockstar's official Extended Look scheduled for August 27 on Netflix. Visitors who click 'Play Now' buttons download gta6_installer.exe, a Vidar infostealer. The malware steals browser-saved passwords, cookies, authenticated sessions, autofill data, and FTP credentials from 19 different browsers including Chrome, Edge, and Firefox. The executable uses legitimate browser binaries in headless mode to access protected data, making credential theft more effective. Stolen session tokens can be reused without triggering two-factor authentication, allowing attackers persistent access even after password changes. The campaign exploited recent GTA 6 leaks that began circulating August 18.
Fake security scans trick victims into uninstalling their antivirus
A network of fraudulent websites branded as SysScan with Microsoft logos are conducting fake security scans to deceive victims into uninstalling legitimate antivirus software. Eleven sites hosted on a single server run convincing but fabricated security checks using basic browser data, deliberately constraining security scores between 13 and 30 out of 100 to guarantee failure. The scam falsely claims Windows no longer supports third-party antivirus and tricks victims into providing personal information, banking details, and remote-access credentials through a detailed form that transmits data directly to Telegram. After form submission, victims receive calls from supposed refund managers who exploit the removed security protections. The operation shows indicators of AI-generated code and targets both consumer and enterprise security software users.
Extended Rapid Response: RecruitTrap Recruit Scams are Targeting Enterprise Credentials on Mobile
Threat actors are conducting sophisticated recruitment-themed phishing campaigns by impersonating HR personnel from prominent companies. The attacks leverage Browser-in-the-Browser techniques on desktop, while mobile devices display full-screen counterfeit login pages without visible URL indicators. The malicious infrastructure actively screens victims, rejecting personal emails to specifically target corporate credentials and enterprise access. Analysis reveals persistent hosting patterns primarily using Amazon and SEDO networks, with attackers impersonating brands including Amazon, Louis Vuitton, Apple, FIFA, Emirates, Boeing, Heineken, Deloitte, and Lego. Traditional threat feeds show significant delays in detecting these domains, with detection gaps ranging from 7 days to over 6 years. The campaign enables credential harvesting, OAuth token theft, and lateral movement within organizations.
A ClickFix cluster: Observed activity from recent ClickFix campaigns
Multiple ClickFix campaigns were identified employing three distinct delivery mechanisms while sharing common characteristics including DLL sideloading, consistent file-naming conventions, and command-and-control dead drops. The first campaign used remotely hosted MSI packages containing legitimate software to sideload malicious DLLs. The second leveraged NodeJS to execute JavaScript files, while the third utilized Python 3.5 to conceal and execute payloads. All campaigns originated from ClickFix lures and employed aggressive social engineering tactics, including direct phone contact directing victims to compromised WordPress sites. Post-compromise activity included extensive discovery commands and Active Directory enumeration. Infrastructure overlap and tactics indicate connections to the Lorem Ipsum malware family and Vanilla Tempest operations, with potential ransomware deployment as the final objective.
Anatomy of a macOS ClickFix Crimekit that Weaponises EtherHiding
A sophisticated macOS campaign exploits ClickFix social engineering, deceiving victims into executing malicious AppleScript commands via fake CAPTCHA verification pages. The attack chain deploys a persistent backdoor agent that utilizes EtherHiding, storing C2 addresses in Polygon blockchain smart contracts, making infrastructure detection challenging. The infection establishes persistence through LaunchAgents and deploys multiple payloads including the AMOS stealer targeting cryptocurrency wallets, browser credentials, and macOS Keychain data, alongside XMRig cryptominer for sustained revenue generation. The operation demonstrates advanced evasion through character-ID obfuscation, blockchain-based infrastructure, and abuse of legitimate macOS utilities. Analysis of blockchain transactions reveals complete C2 rotation history and funding trails, providing defenders with infrastructure-level pivots despite the campaign's memory-resident execution model.
Head Mare APT Group exploits vulnerabilities in unpatched TrueConf server to deliver PhantomCore malware to conference participants
The Head Mare APT group exploited two vulnerabilities in TrueConf video conferencing servers to deliver PhantomCore malware to conference participants. Attackers used these vulnerabilities to execute arbitrary code, replace legitimate client installers with malicious versions, and deploy web shells. When participants downloaded the TrueConf client from compromised servers, they received infected installers that deployed PhantomCore backdoor, granting attackers full control over infected systems. On Linux servers, additional backdoors were installed using GitHub as a command and control channel. The vulnerabilities affected TrueConf server versions released since 2022 and were patched in versions 5.3.9, 5.4.9, and 5.5.5 released in June 2026. Organizations whose employees participated in video conferences using TrueConf may have been affected, even if they don't operate their own TrueConf servers.
SynkLoader: when you throw in everything but the kitchen sink
A sophisticated modular loader utilizing multiple programming languages to evade detection has been discovered. The attack begins with Microsoft Teams phishing where attackers impersonate IT helpdesk personnel, convincing targets to install a fake PowerShell cleaner via MSI installer. The malware deploys memory-resident components bridging Python, C#, C++, and PowerShell to profile systems, establish persistence via scheduled tasks, and deploy a fake Windows lock screen to phish user credentials. Additional modules include a reverse proxy for network tunneling, enabling threat actors to access internal corporate systems using compromised credentials, plus remote shell and VNC capabilities for hands-on-keyboard attacks. The elaborate multi-stage infection chain suggests potential ransomware operations or initial access brokering.
Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
On August 20, 2026, malicious versions of three Rust crates were published to crates.io: arrayref@0.3.10, internment@0.8.7, and append-only-vec@0.1.9. The malicious crates added a typosquatted dependency (proc-macro1) whose build script downloads and executes a remote binary at compile time. The payload is a featureful backdoor that beacons to C2 via HTTPS, exfiltrates host information, enumerates installed applications, reads browser profiles for saved logins, and persists via Registry Run key, LaunchAgent, or systemd user service. The campaign's infrastructure substantially overlaps with operations attributed to North Korean actors, including shared C2 endpoint patterns with the Mastra campaign and IP addresses used in the axios npm attack.
Popular Rust Crates Compromised in Build-Time Supply Chain Attack
A coordinated supply chain attack compromised three legitimate Rust crates maintained by David Roundy: arrayref, internment, and append-only-vec. The threat actor injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. This malicious package executed cross-platform malware automatically during Cargo builds through its build.rs script. The attack delivered platform-specific stage-2 backdoors for Linux, macOS, and Windows that profiled victims, collected browser data, established persistence, and provided remote command execution capabilities. The malware communicated with command-and-control infrastructure at 23.254.165.112 and included a domain generation algorithm for fallback. Developer workstations, CI/CD runners, and release infrastructure were particularly at risk, as the compromise occurred during normal compilation processes. The Rust Security Response Team removed the malicious releases and locked the maintainer account, believing the legitimate maintain...
How Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else's Product
Investigation into residential proxy networks reveals that bandwidth-sharing applications like PEER2PROFIT recruit users to share internet connections for payment, then monetize this bandwidth through commercial proxy service ASTROPROXY at up to 27 times the original cost. Over 72 hours, researchers identified 117,224 unique IPs across residential, mobile, and datacenter pools, with residential pools adding over 1,000 new IPs hourly. These applications install through official channels with user consent, making them invisible to traditional security tools. Reverse engineering of the Windows SDK revealed the communications protocol and backconnect infrastructure coordinating proxy sessions. Testing demonstrated that proxy networks could access internal network resources through simple DNS entries resolving to internal IPs, potentially exposing corporate assets. The scale, legitimacy, and internal network access capabilities present significant risks to organizations where employees may unknowingly expose co...
Distinct Clusters Target Individuals of Interest to Russia
Three distinct suspected Russian cyber espionage threat clusters—UNC6293, UNC7005, and UNC5976—are abusing legitimate authentication flows to target individuals in academia, aerospace, defense, governments, and think tanks across Europe and the United States. These groups conduct sophisticated phishing campaigns using app password phishing, OAuth phishing, device code phishing, and malware deployment. UNC6293 and UNC7005 are assessed with moderate confidence to be initial access clusters linked to ICE RELIC (formerly APT29), while UNC5976 appears distinct. Operations leverage social engineering through fake diplomatic invitations, conference registrations, and file sharing pages. UNC7005 was tied to hospitality captive portal redirects and deployed MaaS infostealers including VIDAR and ATOMIC. These actors abuse legitimate authentication mechanisms including Google OAuth, Microsoft device codes, and WhatsApp device linking to compromise personal accounts, making detection challenging for organizations.
N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it
N4D Mesh Controller is an active Linux malware campaign exploiting exposed Model Context Protocol (MCP) servers and various internet-facing services for credential theft, lateral movement, and command and control. First documented in June 2026, recent analysis reveals evolved tactics including a new loader-to-agent chain, rotated infrastructure using IP 209.99.186.235, and an agent labeled "33.8-go-titan" that enumerates MCP tools and executes commands. The campaign automates discovery and abuse of dangerous MCP capabilities, particularly command execution tools, without requiring traditional vulnerabilities. The agent establishes persistence through multiple mechanisms including cron entries, systemd units, SSH keys, and watchdog scripts, while scanning for additional targets across databases, container platforms, AI infrastructure including Ray Dashboard and LightLLM, and cloud services. Secondary access is maintained through Cloudflare Quick Tunnels.
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.
BRIDGEHEAD: An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer
In August 2026, an operator published forty typosquatted npm packages mimicking popular libraries like chalk, axios, commander, lodash, react, and typescript. Each package contained an install script that profiles the host and, when detecting Windows or WSL environments, downloads a 22MB Rust-based executable from GitHub. This payload runs entirely in memory without dropping files to disk, targeting cryptocurrency wallets, browser credentials, cookies, and Telegram sessions. The malware uses legitimate services for reconnaissance and exfiltration, making detection and takedown difficult. While npm packages were removed within 84 minutes, the GitHub-hosted payload remained active for an additional 39 hours, and the command-and-control server continued operating. The campaign specifically targets developers using WSL by crossing the boundary between Linux environments and underlying Windows systems.
Chinese-speaking adversary integrates agentic AI into post-compromise operations
A Chinese-speaking cybercrime group designated UAT-10147 has been identified targeting Windows and Linux web servers worldwide, affecting organizations across government, education, media, technology, and gaming sectors. The adversary exploits publicly disclosed vulnerabilities to achieve initial access at scale, then deploys AI-driven tooling throughout exploitation, reconnaissance, payload generation, validation, and persistence workflows. The operation leverages open-source offensive frameworks including Metasploit, ysoserial, PentestGPT, and DeepAudit to automate intrusion operations. UAT-10147 demonstrates an emerging capability of integrating semi-autonomous AI systems for iterative exploit refinement, adaptive troubleshooting, and operational documentation generation. Targeting includes approximately 170,000 URLs across multiple countries, with post-compromise activities involving deployment of various implants, BadIIS installations, and SEO fraud operations.
Back-to-School Cyber Risks Surge as Education Remains the World's Most Attacked Sector
Educational institutions continue to be the most targeted sector globally, experiencing an average of 4,696 weekly cyberattacks per organization between January and July 2026, representing an 8% increase year-over-year and more than double the cross-industry average. The back-to-school period sees intensified malicious activity, with July 2026 recording 4,848 weekly attacks. Threat actors are registering thousands of education-themed domains, with one in every 226 newly registered domains being malicious. APAC leads with 7,452 weekly attacks, while Europe and Latin America show the fastest growth at 18% and 42% respectively. Attackers deploy phishing campaigns impersonating retailers, schools, and Microsoft 365 to steal credentials and financial information from students, educators, and families during peak enrollment periods.
Blend between Banking Malware & Spyware
A newly identified Android malware family named Manic combines banking malware and mobile spyware capabilities, targeting Ukrainian banks, government services, messaging applications, Russian and European financial institutions, and global fintech and cryptocurrency services. Active since February 2026, Manic enables extensive Device Takeover operations through sophisticated surveillance and remote-control features. It employs advanced PIN stealing techniques without requiring traditional overlay attacks, utilizing Accessibility services as a UI keylogger to capture lock-screen inputs, recovery phrases, and authentication codes. A distinctive feature is its Wi-Fi mesh egress technique, allowing compromised devices to relay stolen data through other infected phones via Wi-Fi Direct, Bluetooth, or BLE when direct C2 access is unavailable. The malware monitors 169 applications including banks, cryptocurrency wallets, government eID services, and military-focused messengers across multiple countries.
41 deceptive download sites show a real link, then send you somewhere else
A network of 41 fraudulent websites has been identified impersonating popular games and Windows software to redirect users toward Download Studio installer. These sites advertise legitimate products including Counter-Strike, Half-Life, Fallout, Roblox, VLC, 7-Zip, and VMware using authentic product information and real download links. The deception employs JavaScript to display legitimate URLs when hovering over download buttons, but redirects users elsewhere upon clicking. Sites target users seeking everyday software and security tools, pushing them through affiliate redirects to Download Studio installation. The campaign is particularly concerning as Download Studio's automatic updater was previously compromised in 2020 to distribute FakeMBAM backdoor and cryptocurrency miners, though no current malicious activity is confirmed.
SilkParasite: Tracking a China-Nexus APT Across Central Asia
SilkParasite is a cyberespionage operation assessed with medium confidence as China-nexus that targeted government bodies across Central Asia. Seven remote access tool families were deployed, five of which were previously undocumented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. The toolset is small, modular, and professionally engineered with traces of AI-assisted development. Initial access occurred through malicious Microsoft Office documents delivered via spear-phishing, using regionally tailored lures impersonating government ministries. The operation leveraged DLL sideloading as the primary delivery mechanism and used Google Drive for command-and-control communications to hide within trusted services. Infrastructure analysis identified connections to China Unicom's backbone network, and operational patterns suggest a functioning software organization with maintained build pipelines and careful operational security.
77 Firefox Extensions Linked to Crypto Wallet and Credential Theft
Socket identified a coordinated campaign involving 77 Firefox extensions designed to steal cryptocurrency wallet secrets and credentials. The operation, tracked as 'Offside Wallet Theft Factory', includes 40 confirmed malicious extensions that exfiltrate recovery phrases, private keys, and credentials through Supabase-controlled remote switches, Cloudflare Workers, and hardcoded command-and-control infrastructure. An additional 37 deceptive sports-score shells share publishing artifacts and version histories showing transitions from benign utilities into wallet-stealing malware. The campaign operated from at least March 2026 through August 2026, targeting Web3 users through impersonations of OKX, Rabby Wallet, TronLink, and other cryptocurrency products. Extensions capture secrets through phishing interfaces, modified wallet code, and direct credential theft, enabling immediate cryptocurrency theft and financial harm.
Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign
Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.
Backdoor delivered through software updates
A sophisticated backdoor disguised as a legitimate Malwarebytes installer was distributed to over 100,000 machines through compromised automatic updates of one torrent client (Download Studio) and three adblockers (NetShield Kit, My AdBlock, and Net AdBlock). The backdoor creates a fake Malwarebytes installation directory containing legitimate signed files alongside malicious DLL files. Once executed, it establishes persistence through a Windows service and communicates with command-and-control servers to receive configuration updates and additional payloads. The primary observed payloads were cryptocurrency miners, though the infrastructure supports delivery of multiple persistent threats. The attack demonstrates abuse of software update mechanisms and affects primarily users in Russia, Ukraine, and Kazakhstan.
Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware
Following Black Hat and DEF CON conferences, a threat actor targeted attendees through X direct messages, posing as CoinDesk's VP and Head of Marketing to establish trust under the pretext of conference planning. The campaign employed a malicious Google Apps Script embedded in a Google Doc that presented ClickFix-style instructions and manual download options. The attack delivered different payloads based on the victim's operating system: macOS users received AMOS infostealer, while Windows users were infected with NetSupport RAT, a Ledger wallet implant, and a TLS-intercepting proxy. A secondary lure masqueraded as a DocSend installer to deliver additional payloads. The operation demonstrated sophisticated social engineering by leveraging trusted platforms and post-conference networking expectations.
Scammers are using fake crypto AML checkers to drain your wallet
Cybercriminals are deploying fraudulent cryptocurrency wallet-checking websites that impersonate legitimate anti-money laundering (AML) services to steal digital assets. These fake sites, often mimicking AMLBot or using names like 'AML Check,' replicate the appearance and branding of authentic wallet-screening platforms. Instead of simply requesting a wallet's public address for legitimate screening, these malicious sites prompt users to connect their wallets and approve transactions. The scam exploits users' security consciousness by displaying fake progress bars, compliance verification messages, and fraudulent error notifications requesting small fees. Once victims approve transactions or grant token permissions, attackers can drain their cryptocurrency holdings. The scam's effectiveness lies in its professional appearance and exploitation of legitimate security practices, making fraudulent requests appear routine.
Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking
A sophisticated Phishing-as-a-Service platform called Balonx Sistema, operated from Mexico, targets over 20 financial institutions through tiered subscriptions. The platform employs real-time WebSocket session hijacking to defeat multi-factor authentication, distributing a Spyroid-based Android RAT via fake security alerts. Since October 2025, over 1,100 victims' credentials have been harvested. The operation includes CallFlow, an AI-driven vishing module using GPT-4o-mini, ElevenLabs synthetic voice, and OpenAI Whisper for automated telephone fraud, eliminating human operators. The platform uses continuous domain rotation across 350+ domains since 2019, maintains centralized PostgreSQL infrastructure, and is openly promoted through Facebook groups. The operator, identified as 'balonx', manages a sophisticated criminal enterprise generating approximately $99,000 USD through subscription-based access priced between 3,000-6,000 MXN weekly.
https://malbearlabs.com/shadow-hvnc-and-shadow-loader-the-kit-that-protects-its-license-better-than-its-customers-dd99520b6af3
No description provided.
From ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panel
A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.
Beware of Phishing Emails Disguised as Quote Confirmation Requests (PhantomStealer)
A phishing campaign has been identified where attackers impersonate sales staff from specific overseas companies, requesting quotation modifications and product version confirmations. The email contains a malicious GZ compressed file that, when extracted, delivers an injector-type executable. This injector employs multiple UAC bypass techniques including SSPI-based authentication and CMSTPLUA COM exploitation to gain elevated privileges. It then performs BYOVD attacks using the vulnerable DCRCVDrv.sys driver to terminate security products through kernel-level access. Following security product neutralization, the injector uses process hollowing to inject PhantomStealer into the legitimate AddInProcess32.exe process. PhantomStealer then executes comprehensive information theft including keylogging, screen capture, browser credentials, cryptocurrency wallet data, and clipboard manipulation to replace wallet addresses with attacker-controlled ones.
Clop Returns with Custom Implant in Mass-Extortion Campaign
The Clop threat group has returned to mass exploitation tactics by leveraging CVE-2026-12569 in PTC Windchill, deploying a sophisticated custom web shell designed specifically for data theft and extortion. This purpose-built implant provides immediate full data-theft capability without requiring additional tooling, featuring built-in credential harvesting, database enumeration, and a custom Java class loader for executing arbitrary code in memory. The web shell decrypts credentials from Windchill's keystore, including LDAP manager passwords that could enable enterprise-wide compromise. Its application-specific design allows malicious activity to blend seamlessly with legitimate traffic, making detection significantly more challenging. The implant targets sensitive intellectual property and engineering data stored in Windchill installations across manufacturing enterprises globally.
CopyCop Targets AI Investment in Armenia
The Russian influence network CopyCop conducted a coordinated disinformation campaign targeting the US-Armenian joint Firebird AI data center in Hrazdan between June and July 2026. Through three escalating operations, CopyCop fabricated narratives about earthquake risks, power grid instability, and Iranian military threats against the facility. The campaign employed media impersonations of TechCrunch and Gizmodo, with the final operation achieving over 1.6 million views. These operations aim to undermine Armenia's westward geopolitical realignment and Western investment projects. Additional high-profile targets likely include the TRIPP corridor, Metsamor nuclear power plant modernization, and critical minerals development initiatives, all representing significant US-Armenian cooperation that threatens Russia's regional influence.
Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US
Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle attacks. Analysis shows 63.7% of identified victims are in the US, with Technology, Manufacturing, and Education among the most targeted industries. The operation generated thousands of compromise events between 2024 and 2026, including stolen session cookies, passwords, and SSO access. Once a Microsoft 365 session is hijacked, attackers gain access to corporate email, sensitive data, and trusted business accounts. The toolkit uses browser-based delivery through .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket-based AiTM activity. Of 9,426 unique targeted email addresses, 4,532 were potentially compromised, representing approximately 48% success rate.
MacSync Stealer: C2 Infrastructure Rotation
On 5 May 2026, a Jamf Protect deployment blocked a download attempt from jacksonvillemma[.]com, four days after the operator's previous MacSync C2 was publicly disclosed. The new C2's TLS certificate was issued within 24 hours of that disclosure. Analysis revealed a Stage 2 zsh loader containing a static api-key value observed across four distinct C2 domains spanning December 2025 to May 2026. URI-pattern pivoting through any.run identified eleven additional candidate C2 domains dating back to February 2026, suggesting parallel infrastructure operation rather than sequential rotation. The loader exfiltrates macOS credentials, browser data, and cryptocurrency wallets, and transmits the victim's account password in cleartext via URL query strings, making it visible in web proxy logs.
Signed Overwolf Binary Sideloads ValleyRAT Malware in India
A phishing campaign targets Indian organizations by impersonating the Indian Income Tax Department. Victims receive emails containing links to spoofed notice pages that download ZIP archives. These archives include a legitimately signed Overwolf executable and two hidden files: a malicious DLL and an encrypted binary. When executed, the signed binary side-loads the malicious DLL through DLL hijacking. The DLL is UPX-packed and modified with Astral-PE, and decrypts the binary file containing ValleyRAT. The payload uses modified RC4 encryption with a 115-byte key and deploys entirely in memory. Once active, ValleyRAT establishes persistence through scheduled tasks masquerading as OneDrive entries, marks dropped files as hidden and system files, and performs process hollowing into svchost.exe to evade detection before connecting to command and control infrastructure.
Fraudulent Employment Operations
Multiple clusters of North Korean IT workers, designated as PurpleDelta, have been identified applying to over 1,100 companies between late 2024 and early 2025, primarily targeting software, technology, staffing, consulting, and healthcare sectors. The operators maintained at least 22 fabricated personas supported by AI-generated profile photos, custom ChatGPT assistants, and fraudulent identity documents. They demonstrated sophisticated tradecraft, applying to up to 60 positions daily using multi-account management browsers and detailed tracking spreadsheets. During interviews, operators employed screen recording software and AI transcription tools to generate real-time answers, often repeating ChatGPT responses verbatim. Once employed at ten or more organizations, they recorded internal meetings, used personal devices and bank accounts, and coordinated via Telegram and Slack with facilitators who maintained company-issued hardware. This activity represents an ongoing insider threat to organizations hirin...
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...
Beware of Phishing Emails Disguised as Transaction Receipts
A sophisticated phishing campaign has been identified where attackers impersonate employees of a US company, sending emails that claim to contain transaction receipts. Recipients are urged to verify fund deposits by opening an attached PDF file. The malicious PDF displays a fake Adobe Flash Player update prompt, which when clicked, downloads a VBS script. This script executes with administrator privileges, displays a decoy payment receipt document, and silently installs ScreenConnect remote management software via an MSI package. The installation establishes persistent remote access to the compromised system, enabling attackers to execute commands, transfer files, and deploy additional payloads using legitimate administrative tools in a Living-off-the-Land attack technique.
Projextor: Abusing Electron in Trojanized Productivity Applications
Projextor is a malware campaign that leverages Electron-based productivity applications to deliver malicious payloads. The threat disguises itself as legitimate document converters, meal planners, and PDF management tools with working user interfaces. Distribution occurs through impersonating websites that mimic genuine services, using high-ranking search results to lure victims. Applications like Kitchen Canvas, Food Formula, DocConvertWizard, and PDFGrip contain insecure Electron configurations that enable dynamic JavaScript execution and desktop capture capabilities. The infection chain begins with NSIS, Squirrel, or Inno Setup installers that download the main Electron application. Preload scripts abuse privileged Node.js APIs with intentionally disabled security features, allowing arbitrary code execution and screen monitoring. This enables threat actors to capture sensitive information, monitor user activity, and execute remote commands while maintaining the appearance of functional productivity soft...
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
In July 2026, a new Rust-based malware family called C2Looper was identified, likely used by ransomware-related threat actors. The malware is assessed with low to medium confidence to be delivered through multi-stage ClickFix infection chains. C2Looper provides backdoor capabilities including remote shell execution, reconnaissance, and deploying additional payloads. It dynamically resolves Windows APIs and encrypts strings using XOR operations. The malware communicates via plaintext HTTP initially, but an evolved version uses GitHub repositories for command-and-control operations, storing commands and exfiltrated data in JSON files. Version 2 introduces additional commands such as reconnaissance collection, drive enumeration, shellcode injection, and file listing. The malware demonstrates active development with refined capabilities, likely serving initial access brokers for data theft and ransomware deployment.
Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor
A China-nexus threat actor is targeting Myanmar government personnel and diplomats through Operation QUICSILVER, delivering malware via Virtual Hard Disk files disguised as JPEG images. The campaign uses Burmese-language lures impersonating Myanmar's Information Technology and Cyber Security Department, including graduation ceremony invitations. The multi-stage infection chain begins with a malicious LNK file that abuses ftp.exe to execute scripts, reconstructs payloads from split files, and deploys QUICAgent, a custom Go-based backdoor. The implant retrieves C2 infrastructure through Cloudflare Workers, communicates over HTTP/3 using QUIC protocol, and employs RC4 encryption. Deleted documents recovered from the VHD reveal interest in ASEAN affairs, BIMSTEC, and Myanmar diplomatic activities. Three related campaigns were identified between April and July 2026, sharing similar TTPs and infrastructure.
The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications
Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.
Abyssos: Technical Analysis of a New Modular RAT
In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...
Investigating a Multi-Stage PowerShell Loader
A threat hunting investigation identified suspicious PowerShell content served from an IP address (203.188.171.166) and domain (dorenzaa.com), both retrieving ZIP archives from Vercel-hosted infrastructure. The PowerShell loaders extract and execute payloads locally, including Grape.exe, UltraToolliteSetup.exe, and draw.io.exe. Analysis revealed heavily obfuscated PowerShell stages utilizing Base64 encoding, XOR-based obfuscation with the key 'Write', dynamically constructed IEX commands, and hidden PowerShell execution. A decoy 'Verification complete!' message disguised as Google.com was presented to victims during execution. Multiple Vercel instances hosted additional artifacts including loader scripts and executables. The initial infection vector remains unidentified, suggesting these PowerShell-hosting URLs represent second-stage delivery points in a multi-stage attack chain.
Integrating AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
The Kimsuky threat group has integrated artificial intelligence capabilities into its attack operations, establishing local large language model environments using Ollama, GPT4All, and Msty. Evidence indicates the group is accumulating technologies to incorporate AI across attack operations, including AI-generated decoy documents and retrieval-augmented generation for document analysis. The campaign, dubbed Operation GitPower, continues targeting foreign diplomatic missions and sectors including military, security, and virtual assets. Attacks utilize malicious LNK files contained in ZIP archives, executing obfuscated PowerShell scripts that abuse Git-based repositories as command-and-control infrastructure. The group distributes encrypted AsyncRAT payloads disguised as image files through GitHub. Linguistic indicators including North Korean vocabulary patterns such as "싸이트", "가입리력", and "로출되였는지" support attribution to North Korean state-sponsored operations under the Reconnaissance General Bureau.
Powercat malware campaign: Fake game cheats deliver infostealer
In February 2026, an active malware delivery campaign named Powercat was observed distributing infostealer malware disguised as utility or cheat software for popular PC games including Roblox, Minecraft, and Grand Theft Auto V. The multi-stage infection chain begins with an initial executable that profiles victims and establishes persistence, followed by a Java-based loader that deploys the final infostealer payload. The malware targets cryptocurrency wallets (Exodus, Atomic, Monero-Gui), browser data from Chromium-based applications, Discord tokens, and gaming accounts with payment information. It includes surveillance capabilities such as keylogging, webcam capture, and screen recording. The campaign particularly targets children who frequent gaming platforms and pay-to-cheat websites, with evidence suggesting collected personal information may be used for blackmail or coercion into illegal activities.
Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.
Inside a Self-Propagating npm Worm
A self-propagating npm worm dubbed ChainDrop infected over 400 packages downloaded hundreds of millions of times weekly, including popular packages like keyv and cacheable-request. The worm steals cloud credentials, npm and GitHub tokens, SSH keys, and sensitive developer data while extracting temporary credentials from GitHub Actions runner memory. It uses stolen npm publishing tokens to infect additional packages while maintaining their legitimate functionality. The attackers established persistence through VS Code and Claude Code configurations, employed blockchain-based command-and-control resolution via Ethereum smart contracts, and can execute attacker-supplied code. The operator demonstrated ability to silently reconfigure C2 infrastructure through Ethereum transactions without updating deployed instances. ChainDrop employs three layers of obfuscation and encryption, exfiltrates data through encrypted channels, and publishes stolen tokens in public commit messages.
Stealth Mango and Tangelo
This threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense secto…
1937CN
1937CN is a Chinese hacking group that has been active since at least 2013. The group is known for targeting Vietnamese organizati…
313 Team
313 Team is an Iraq-based threat actor that has conducted coordinated DDoS campaigns targeting multiple government servers in the …
APT-C-27
A threat actor which is ac tive since at least November 2014. This group launched long-term at tacks against organizations in the …
APT.3102
APT1
PLA Unit 61398 (Chinese: 61398部队, Pinyin: 61398 bùduì) is the Military Unit Cover Designator (MUCD)[1] of a People's Liberation Ar…
APT10
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in ass…
APT12
A group of China-based attackers, who conducted a number of spear phishing attacks in 2013.
APT14
PLA Navy Anchor Panda is an adversary that CrowdStrike has tracked extensively over the last year targeting both civilian and mili…
APT15
This threat actor uses phishing techniques to compromise the networks of foreign ministries of European countries for espionage pu…
APT16
Between November 26, 2015, and December 1, 2015, known and suspected China-based APT groups launched several spear-phishing attack…
APT17
FireEye described APT17 in a 2015 report as: 'APT17, also known as DeputyDog, is a China based threat group that FireEye Intellige…
APT18
Wekby was described by Palo Alto Networks in a 2015 report as: 'Wekby is a group that has been active for a number of years, targe…
APT19
Adversary group targeting financial, technology, non-profit organisations.
APT2
Putter Panda were the subject of an extensive report by CrowdStrike, which stated: 'The CrowdStrike Intelligence team has been tra…
APT20
We’ve uncovered some new data and likely attribution regarding a series of APT watering hole attacks this past summer. Watering ho…
APT21
APT22
Suckfly is a China-based threat group that has been active since at least 2014
APT23
TrendMicro described Tropic Trooper in a 2015 report as: 'Taiwan and the Philippines have become the targets of an ongoing campaig…
APT24
The Pitty Tiger group has been active since at least 2011. They have been seen using HeartBleed vulnerability in order to directly…
APT26
APT27
A China-based actor that targets foreign embassies to collect data on government, defence, and technology sectors.
APT28
The Sofacy Group (also known as APT28, Pawn Storm, Fancy Bear and Sednit) is a cyber espionage group believed to have ties to the …
APT29
A 2015 report by F-Secure describe APT29 as: 'The Dukes are a well-resourced, highly dedicated and organized cyberespionage group …
APT3
Symantec described UPS in 2016 report as: 'Buckeye (also known as APT3, Gothic Panda, UPS Team, and TG-0110) is a cyberespionage …
APT30
APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT3…
APT31
FireEye characterizes APT31 as an actor specialized on intellectual property theft, focusing on data and projects that make a part…
APT32
Cyber espionage actors, now designated by FireEye as APT32 (OceanLotus Group), are carrying out intrusions into private sector com…
APT33
Our analysis reveals that APT33 is a capable group that has carried out cyber espionage operations since at least 2013. We assess …
APT35
FireEye has identified APT35 operations dating back to 2014. APT35, also known as the Newscaster Team, is a threat group sponsored…
APT37
APT37 has likely been active since at least 2012 and focuses on targeting the public and private sectors primarily in South Korea.…
APT39
APT39 was created to bring together previous activities and methods used by this actor, and its activities largely align with a gr…
APT4
APT40
Leviathan is an espionage actor targeting organizations and high-value targets in defense and government. Active since at least 20…
APT41
APT41 is a prolific cyber threat group that carries out Chinese state-sponsored espionage activity in addition to financially moti…
APT42
Iranian state-sponsored cyber espionage group tasked with conducting information collection and surveillance operations against in…
APT45
APT45 is a North Korean cyber threat actor that has been active since at least 2009. They have conducted espionage campaigns targe…
APT5
We have observed one APT group, which we call APT5, particularly focused on telecommunications and technology companies. More than…
APT6
The FBI issued a rare bulletin admitting that a group named Advanced Persistent Threat 6 (APT6) hacked into US government computer…
APT9
APT9 engages in cyber operations where the goal is data theft, usually focusing on the data and projects that make a particular or…
APTIran
APTIran has claimed responsibility for a large-scale campaign targeting Israeli critical infrastructure, asserting infiltration of…
Ababil of Minab
Ababil of Minab is an emerging pro-Iranian hacktivist group with a limited public profile and little verifiable prior activity in …
Altahrea Team
Altahrea Team is a pro-Iranian hacking group that has been active since at least 2020. The group has claimed responsibility for a …
Amaranth-Dragon
Amaranth-Dragon is a previously untracked threat actor assessed to be closely linked to the China-affiliated APT 41 ecosystem, exh…
Amethyst Rain
Microsoft threat actor profile. Origin/Threat: Lebanon.
Angry Likho
Angry Likho is an APT group that has been active since 2023, primarily targeting large organizations and government agencies in Ru…
Anonymous64
Anonymous 64 is a group accused by China's national security ministry of attempting to gain control of web portals, outdoor electr…
Antlion
Antlion is a Chinese state-backed advanced persistent threat (APT) group, who has been targeting financial institutions in Taiwan.…
Aoqin Dragon
SentinelLabs has uncovered a cluster of activity beginning at least as far back as 2013 and continuing to the present day, primari…
AppMilad
AppMilad is an Iranian hacking group that has been identified as the source of a spyware campaign called RatMilad. This spyware is…
AridViper
AridViper is a state-sponsored APT primarily targeting military personnel, journalists, and dissidents in the Middle East, with a …
Aslan Neferler Tim
Turkish nationalist hacktivist group that has been active for roughly one year. According to Domaintools, the group’s site has bee…
Avivore
The group’s existence came to light during Context’s investigation of a number of attacks against multinational enterprises that c…
Ayyıldız Tim
Ayyıldız (Crescent and Star) Tim is a nationalist hacking group founded in 2002. It performs defacements and DDoS attacks against …
AzzaSec
AzzaSec is a hacktivist group that originated in Italy. Known for their pro-Palestine stance, they have been involved in various c…
BANISHED KITTEN
BANISHED KITTEN is an Iranian state-nexus adversary active since at least 2008. While the adversary’s most prominent activity is t…
BIG PANDA
BRONZE EDGEWOOD
In early 2021 CTU researchers observed BRONZE EDGEWOOD exploiting the Microsoft Exchange Server of an organization in Southeast As…
BRONZE HIGHLAND
BRONZE HIGHLAND has been observed using spearphishing as an initial infection vector to deploy the MgBot remote access trojan agai…
BRONZE SPIRAL
In December 2020, the IT management software provider SolarWinds announced that an unidentified threat actor had exploited a vulne…
BRONZE SPRING
BRONZE SPRING is a threat group that CTU researchers assess with high confidence operates on behalf of China in the theft of intel…
BRONZE STARLIGHT
BRONZE STARLIGHT has been active since mid 2021 and targets organizations globally across a range of industry verticals. The group…
BRONZE VAPOR
BRONZE VAPOR is a targeted threat group assessed with moderate confidence to be of Chinese origin. Artefacts from tools associated…
BatShadow
BatShadow is a Vietnamese threat actor that targets job seekers and digital marketing professionals through social engineering cam…
Bearlyfy
Bearlyfy has been attributed to over 70 cyber attacks targeting Russian companies since its emergence in January 2025, employing a…
Beijing Group
BiBiGun
A pro-Hamas hacktivist group developed a wiper called BiBi-Linux to target and destroy data on Israeli systems. The malware impers…
Bignosa
Bignosa is a threat actor known for launching malware campaigns targeting Australian and US organizations using phishing emails wi…
BlackJack
Blackjack, a threat actor linked to Ukraine's security apparatus, has targeted critical Russian entities such as ISPs, utilities, …
BlackTech
BlackTech is a cyber espionage group operating against targets in East Asia, particularly Taiwan, and occasionally, Japan and Hong…
Blackatom
Recent campaigns suggest Hamas-linked actors may be advancing their TTPs to include intricate social engineering lures specially c…
Blackgear
BLACKGEAR is an espionage campaign which has targeted users in Taiwan for many years. Multiple papers and talks have been released…
Blackmeta
BLACKMETA is a pro-Palestinian hacktivist group that has claimed responsibility for a series of DDoS attacks and data breaches tar…
Blackwood
Blackwood is a China-aligned APT group that has been active since at least 2018. They primarily engage in cyberespionage operation…
BladedFeline
BladedFeline is an Iran-aligned APT group that has been active since at least 2017, targeting Iraqi and Kurdish government officia…
Blue Termite
Blue Termite is a group of suspected Chinese origin active in Japan.
Blue Tsunami
Blue Tsunami, also known as Black Cube, is a cyber mercenary group associated with the private intelligence firm Black Cube. They …
Bohrium
Bohrium is an Iranian threat actor that has been involved in spear-phishing operations targeting organizations in the US, Middle E…
Boulder Bear
First observed activity in December 2013.
BrazenBamboo
BrazenBamboo is a Chinese state-affiliated threat actor known for developing the LIGHTSPY, DEEPDATA, and DEEPPOST malware families…
Budminer
Based on the evidence we have presented Symantec attributed the activity involving theDripion malware to the Budminer advanced thr…
BuhTrap
Buhtrap has been active since 2014, however their first attacks against financial institutions were only detected in August 2015. …
CIRCUS SPIDER
According to Crowdstrike, the NetWalker ransomware is being developed and maintained by a Russian-speaking actor designated as CIR…
CL-STA-0043
CL-STA-0043 is a Chinese state-nexus cyber-espionage actor tracked by Palo Alto Networks Unit 42, which promoted the activity clus…
CL-STA-0048
CL-STA-0048 is a Chinese state-backed APT that targets strategic sectors in South Asia, particularly government and telecommunicat…
CL-STA-1087
CL-STA-1087 is a suspected state-sponsored espionage campaign operating out of China, targeting military organizations in Southeas…
CL-UNK-1068
CL-UNK-1068 is a Chinese threat actor that has targeted critical infrastructure in Asia, primarily focusing on cyberespionage. The…
Cadelle
Symantec telemetry identified Cadelle and Chafer activity dating from as far back as July 2014, however, it’s likely that activity…
Callisto
The Callisto Group is an advanced threat actor whose known targets include military personnel, government officials, think tanks, …
Calypso
For the first time, the activity of the Calypso group was detected by specialists of PT Expert Security Center in March 2019, duri…
Camaro Dragon
In early 2023, the Check Point Incident Response Team (CPIRT) team investigated a malware incident at a European healthcare instit…
CardinalLizard
CardinalLizard, a cyber threat actor linked to China, has targeted entities in Asia since 2018. Their methods include spear-phishi…
Careto
This threat actor targets governments, diplomatic missions, private companies in the energy sector, and academics for espionage pu…
Carmine Tsunami
Carmine Tsunami is a threat actor linked to an Israel-based private sector offensive actor called QuaDream. QuaDream sells a platf…
Cavern Manticore
Cavern Manticore is an Iran-nexus APT primarily targeting Israeli organizations in the government and IT sectors, linked to the MO…
CeranaKeeper
CeranaKeeper is a China-aligned APT that has been active since at least early 2022, primarily targeting governmental institutions …
Charming Kitten
Charming Kitten (aka Parastoo, aka Newscaster) is an group with a suspected nexus to Iran that targets organizations involved in g…
Chaya_004
Chaya_004 is a Chinese threat actor identified through malicious infrastructure, including a network of servers hosting Supershell…
Chernovite
Chernovite is a highly capable and sophisticated threat actor group that has developed a modular ICS malware framework called PIPE…
Cleaver
A group of cyber actors utilizing infrastructure located in Iran have been conducting computer network exploitation activity again…
Clever Kitten
Conference Crew
Conference Crew is a China-nexus threat cluster renamed CONFERENCE CASTLE under Google Threat Intelligence's updated naming system…
Confucious
Confucius is an APT organization funded by India. It has been carrying out cyber attacks since 2013. Its main targets are India's …
CopyKittens
CoralRaider
CoralRaider is a financially motivated threat actor of Vietnamese origin, targeting victims in Asian and Southeast Asian countries…
Corsair Jackal
Cotton Sandstorm
Cotton Sandstorm is an Iranian threat actor involved in hack-and-leak operations. They have targeted various organizations, includ…
Cuboid Sandstorm
Cuboid Sandstorm is an Iranian threat actor that targeted an Israel-based IT company in July 2021. They gained access to the compa…
Curious Gorge
Curious Gorge, a group TAG attributes to China's PLA SSF, has conducted campaigns against government and military organizations in…
Curly COMrades
Curly COMrades is a threat actor identified by Amazon Threat Intelligence and Bitdefender, believed to operate in support of Russi…
Cutting Kitten
One of the threat actors responsible for the denial of service attacks against U.S in 2012–2013. Three individuals associated with…
Cyber Alliance
The Ukrainian Cyber Alliance is a pro-Ukraine hacktivist group formed in 2016, primarily targeting Russian entities since the inva…
Cyber Av3ngers
Cyber Av3ngers is an Iranian IRGC Cyber-Electronic Command-affiliated threat actor that targets internet-exposed operational techn…
Cyber Berkut
Cyber Islamic Resistance
Cyber Islamic Resistance is a hacktivist collective ideologically aligned with Iran, engaging in operations such as website deface…
Cyber Partisans
The Cyber Partisans, a hacktivist group based in Belarus, has been involved in various cyber-attacks targeting organizations and i…
Cyber Serp
UAC-0255 is a threat actor that conducted a phishing campaign impersonating CERT-UA to distribute the AGEWHEEZE RAT, targeting org…
Cyber Toufan
Cyber Toufan is a threat actor group that has gained prominence for its cyberattacks targeting Israeli organizations. The group's …
Cyber fighters of Izz Ad-Din Al Qassam
Cyber.Anarchy.Squad
Cyber Anarchy Squad is a pro-Ukrainian hacktivist group known for targeting Russian companies and infrastructure. They have carrie…
DAGGER PANDA
Operate since at least 2011, from several locations in China, with members in Korea and Japan as well. Possibly linked to Onion D…
DEV-0147
DEV-0147 is a China-based cyber espionage actor was observed compromising diplomatic targets in South America, a notable expansion…
DEV-0270
Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also…
DEV-0586
MSTIC has not found any notable associations between this observed activity, tracked as DEV-0586, and other known activity groups.…
Dalbit
The group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and de…
Dark Caracal
Lookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal, a persistent and prolific actor, who at the time of…
DarkHotel
Kaspersky described DarkHotel in a 2014 report as: '... DarkHotel drives its campaigns by spear-phishing targets with highly advan…
Deadeye Jackal
The Syrian Electronic Army (SEA) is a group of computer hackers which first surfaced online in 2011 to support the government of S…
Denim Tsunami
Denim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers. …
DiceyF
DiceyF is an advanced persistent threat group that has been targeting online casinos and other victims in Southeast Asia for an ex…
Domestic Kitten
An extensive surveillance operation targets specific groups of individuals with malicious mobile apps that collect sensitive infor…
DragonForce
DragonForce is a hacktivist group based in Malaysia that has been involved in cyberattacks targeting government institutions and c…
DragonOK
Threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tool…
DragonSpark
DragonSpark is a threat actor that has been conducting attacks primarily targeting organizations in East Asia. They utilize the op…
Dragonbridge
DRAGONBRIDGE is a Chinese state-sponsored threat actor known for engaging in information operations to promote the political inter…
DriftingCloud
DriftingCloud is a persistent threat actor known for targeting various industries and locations. They are skilled at developing or…
DustSquad
Prodaft researchers have published a report on Paperbug, a cyber-espionage campaign carried out by suspected Russian-speaking grou…
ELECTRIC PANDA
ELOQUENT PANDA
ELUSIVE COMET
ELUSIVE COMET is a threat actor responsible for significant cryptocurrency theft through sophisticated social engineering attacks,…
ENERGETIC BEAR
A Russian group that collects intelligence on the energy industry.
Earth Alux
Earth Alux is a China-linked APT group known for conducting cyberespionage attacks across various sectors, including government, t…
Earth Baxia
Earth Baxia is a threat actor opearting out of China, targeting government organizations in Taiwan and potentially across the APAC…
Earth Berberoka
According to TrendMicro, Earth Berberoka is a threat group originating from China that mainly focuses on targeting gambling websit…
Earth Freybug
Earth Freybug, identified as a subset of APT41, is a cyberthreat group active since at least 2012, engaging in espionage and finan…
Earth Krahang
Earth Krahang is an APT group targeting government organizations worldwide. They use spear-phishing emails, weak internet-facing s…
Earth Lamia
Earth Lamia is a China-nexus APT that targets organizations across multiple sectors, including finance, logistics, and government,…
Earth Lusca
Earth Lusca is a threat actor from China that targets organizations of interest to the Chinese government, including academic inst…
Earth Naga
Earth Naga is an APT group that has persistently targeted high-value organizations, including government agencies, telecommunicati…
Earth Wendigo
Earth Wendigo is a threat actor from China that has been targeting several organizations — including government organizations, res…
Edalat-e Ali
Edalat-e Ali is a hacktivist group known for disrupting Iranian state-run TV and radio transmissions during significant events, su…
Educated Manticore
Educated Manticore is an Iranian APT group aligned with the Islamic Revolutionary Guard Corps, primarily engaged in espionage targ…
Equation Group
The Equation Group is a highly sophisticated threat actor described by its discoverers at Kaspersky Labs as one of the most sophis…
Evasive Panda
Evasive Panda is an APT group that has been active since at least 2012, conducting cyberespionage targeting individuals, governmen…
EvilWeb
EvilWeb is a pro-Russian hacktivist group created in March 2024 that targets American and European entities using a hack-and-leak …
FIN1
FireEye first identified this activity during a recent investigation at an organization in the financial industry. They identified…
FIN13
Since 2017, Mandiant has been tracking FIN13, an industrious and versatile financially motivated threat actor conducting long-term…
FIN7
Groups targeting financial organizations or people with significant financial assets.
FOXY PANDA
Adversary group targeting telecommunication and technology organizations.
Femwar02
Femwar02 is a previously unknown pro-Russian ransomware threat actor that emerged in early 2026, linked to a major cyberattack on …
Ferocious Kitten
Ferocious Kitten is an APT group that has been active against Persian-speaking individuals since 2015 and appears to be based in I…
Flax Typhoon
Flax Typhoon is a Chinese state-sponsored threat actor that primarily targets organizations in Taiwan. They conduct espionage camp…
Flying Kitten
Activity: defense and aerospace sectors, also interested in targeting entities in the oil/gas industry.
FlyingYeti
FlyingYeti is a Russia-aligned threat actor targeting Ukrainian military entities. They conduct reconnaissance activities and laun…
Fox Kitten
PIONEER KITTEN is an Iran-based adversary that has been active since at least 2017 and has a suspected nexus to the Iranian govern…
FrostyNeighbor
FrostyNeighbor is a Belarus-aligned APT group known for conducting influence and disinformation campaigns, particularly targeting …
GALLIUM
GALLIUM, is a threat actor believed to be targeting telecommunication providers over the world, mostly South-East Asia, Europe and…
GCMAN
GCMAN is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services.
GHOST STADIUM
GHOST STADIUM is a Chinese-speaking, financially motivated threat actor operating a sophisticated phishing campaign across over 30…
GIBBERISH PANDA
GOBLIN PANDA
Goblin Panda is one of a handful of elite Chinese advanced persistent threat (APT) groups. Most Chinese APTs target the United Sta…
GREF
GREF is a China-aligned APT group that has been active since at least March 2017. They are known for using custom backdoors, loade…
GTG-1002
GTG-1002 is a Chinese state-sponsored APT that conducted a large-scale autonomous cyber espionage campaign targeting approximately…
Gamaredon Group
Unit 42 threat researchers have recently observed a threat group distributing new, custom developed malware. We have labelled this…
GhostEmperor
GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They emp…
GhostRedirector
GhostRedirector is a China-aligned threat actor that has compromised at least 65 Windows servers across various sectors, primarily…
Ghostwriter
Ghostwriter is referred as an 'activity set', with various incidents tied together by overlapping behavioral characteristics and p…
GoldFactory
GoldFactory is a threat actor group attributed to developing sophisticated mobile banking malware targeting victims primarily in t…
GopherWhisper
GopherWhisper is a China-aligned APT that routes C2 traffic through legitimate enterprise platforms like Slack, Discord, and Micro…
Gray Sandstorm
Gray Sandstorm is an Iran-linked threat actor that has been active since at least 2012. They have targeted defense technology comp…
Grayling
Grayling activity was first observed in early 2023, when a number of victims were identified with distinctive malicious DLL side-l…
GreedyBear
GreedyBear is a sophisticated threat actor responsible for over $1 million in cryptocurrency theft through a campaign involving 15…
GreenSpot
GreenSpot is an APT group believed to operate from Taiwan, active since at least 2007, primarily targeting government, academic, a…
Greenbug
Greenbug was discovered targeting a range of organizations in the Middle East including companies in the aviation, energy, governm…
GreyVibe
GREYVIBE is a low-to-moderately sophisticated threat actor associated with Russian state interests, primarily targeting Ukrainian …
Groundbait
Groundbait is a group targeting anti-government separatists in the self-declared Donetsk and Luhansk People’s Republics.
HAFNIUM
HAFNIUM primarily targets entities in the United States across a number of industry sectors, including infectious disease research…
HAZY TIGER
The Bitter threat group initially started using RAT tools in their campaigns, as the first Bitter versions, for Android released i…
HURRICANE PANDA
We have investigated their intrusions since 2013 and have been battling them nonstop over the last year at several large telecommu…
Handala
Handala is a pro-Palestinian hacktivist group that targets Israeli organizations, employing tactics such as phishing, data theft, …
Hellsing
This threat actor uses spear-phishing techniques to compromise diplomatic targets in Southeast Asia, India, and the United States.…
HenBox
This threat actor targets Uighurs—a minority ethnic group located primarily in northwestern China—and devices from Chinese mobile …
HiddenArt
It was observed that a mobile network threat actor designated as ‘HiddenArt’ actively sustains a capacity to remotely access the p…
Higaisa
The organization often uses important North Korean time nodes such as holidays and North Korea to conduct fishing activities. The …
HomeLand Justice
HomeLand Justice is an Iranian state-sponsored cyber threat group that has been active since at least May 2021. They have targeted…
Houken
Houken is a Chinese state-sponsored threat actor that exploits zero-day vulnerabilities in Ivanti Cloud Services Appliance devices…
Houndstooth Typhoon
Microsoft threat actor profile. Origin/Threat: China.
HummingBad
This group created a malware that takes over Android devices and generates $300,000 per month in fraudulent ad revenue. The group…
Hunt3r Kill3rs
Hunt3r Kill3rs is a newly emerged threat group claiming expertise in cyber operations, including ICS breaches and web application …
