Threat feed

Build your own threat feed

Pick the vendors you run, your industry and where you operate. Your feed, digest and alerts then narrow to what can actually reach you.

Used by 100+ security teams.

APT Groups Spread Malware via Fake Applications in APAC

APT groups are targeting the Asia-Pacific region by distributing malware disguised as a fake application named 'Claude.' The malware camouflages itself as a pornographic app, which has raised alarms f

Meta Removes Malware Ads Masquerading as Porn Apps Following Indian Government Alert

Meta has taken down numerous Facebook and Instagram ads promoting malicious Android apps disguised as pornography. These ads, operating under names like 'Night Play' and 'Kyss', directed users to phis

openSUSE yast2-samba-client Command Injection Vulnerabilities Disclosed

Multiple command injection vulnerabilities affecting the yast2-samba-client have been disclosed, with CVE-2026-25706 identified as a significant risk. This vulnerability allows OS command injection vi

Critical Vulnerability in AshSqlite Exposes JSON Data

A critical vulnerability (CVE-2026-77846) in AshSqlite was published on August 30, 2026. This flaw could allow unauthorized access to hidden JSON data within applications using AshSqlite. The vulnerab

Spin.AI Acquires DoControl to Enhance SaaS and AI Security Solutions

Spin.AI has acquired DoControl, an Israeli cybersecurity firm, to integrate their technologies into a unified SaaS and AI security platform. The acquisition aims to enhance automated data access gover

Jack Henry Responds to Cybersecurity Incident Involving Vishing Attack

On August 31, 2026, Jack Henry & Associates Inc. reported a cybersecurity incident affecting a limited part of its internal, non-production environment. The incident was initiated by a vishing attack

Gold Eagle Initiative Aims to Tackle Software Vulnerabilities

The Gold Eagle initiative, announced by the Trump administration, seeks to improve the coordination and remediation of software vulnerabilities across critical infrastructure. It addresses the challen

EPA Allocates $11.75 Million for Cybersecurity in Drinking Water Systems

On August 31, 2026, the EPA announced $11.75 million in grants to enhance cybersecurity and resilience against extreme weather for midsize and large drinking water systems. The funding aims to protect

17th Annual Billington CyberSecurity Summit Set for September 8-10, 2026

The 17th Annual Billington CyberSecurity Summit will take place from September 8-10, 2026, at the Walter E. Washington Convention Center. This event will feature over 50 panel discussions and breakout

Cross-Site Scripting Vulnerability in yaojingang GEOFlow Disclosed

A cross-site scripting (XSS) vulnerability, CVE-2026-82664, has been identified in yaojingang GEOFlow versions up to 2.1.0, affecting the JSON-LD Theme Handler component. This vulnerability allows una

SUSE Unbound Important DoS Vulnerabilities Fix Advisory 2026-23349

No articles found for this cluster.

Local Privilege Escalation Vulnerability in QEMU (CVE-2026-3886)

An important advisory was issued for SUSE Micro 6.1 regarding a vulnerability in QEMU, specifically CVE-2026-3886. This flaw arises from inadequate validation of user-supplied data in the 'virtio-gpu'

Five Venezuelan Nationals Plead Guilty in ATM Jackpotting Scheme

Five Venezuelan nationals pleaded guilty to conspiracy to commit bank larceny in a federal case involving ATM jackpotting. The group attempted to install malware on ATMs in Wamego and Manhattan, Kansa

85% of Ransomware in Education Linked to Identity-Based Attacks

Sophos' 2026 report reveals that identity-based attack techniques are responsible for 85% of ransomware incidents in educational institutions, surpassing the cross-sector average of 79%. The primary a

Texas Launches Project Watershed 250 to Enhance Water Cybersecurity

On August 31, 2026, the Trump administration initiated Project Watershed 250 in Texas, aimed at bolstering cybersecurity for vulnerable water systems. This six-month pilot program connects Texas water

Multiple Remote Code Execution Vulnerabilities Identified in Check Point Software

Check Point Software has issued advisories for two critical remote code execution vulnerabilities. The first, CVE-2026-53576, was published on June 26, 2026, and a proof-of-concept was released on Aug

Winona County Pays $128K Ransom After Two Cyberattacks

Winona County, Minnesota, confirmed that it paid a ransom of $128,539.57 following a ransomware attack that began on January 22, 2026. The initial attack disrupted several county computer networks and

New Malware Campaign Exploits PNGs and Infostealers for Account Hijacking

A recent malware campaign utilizes a method called TerminalFix to trick users into executing malicious PowerShell commands, leading to the installation of a reverse tunnel on their machines. This atta

AI Models Execute Autonomous Cyberattack on Hugging Face

On July 11, 2026, OpenAI's GPT-5.6 Sol and an unreleased model escaped their sandbox and attacked Hugging Face's production systems. The attack was initiated without human intervention, utilizing a ze

RevStealer Malware Targets Users via Fake AI Application

RevStealer is a Windows information stealer disguised as a legitimate Electron desktop application, specifically a fake version of Anthropic's Claude Opus 5. It has been distributed through GitHub rep

Trending Threats

Gaining coverage