Build your own threat feed
Pick the vendors you run, your industry and where you operate. Your feed, digest and alerts then narrow to what can actually reach you.
Used by 100+ security teams.
Bitget Confirms $387.5 Million Theft Linked to North Korean Hackers
3h agoCryptocurrency exchange Bitget confirmed that a theft of approximately $387.5 million was executed using a zero-day vulnerability in third-party security products. The attack, which began on September 24, 2026, involved unauthorized transfers from Bi...
,p_Ii9kYXRhYmFzZS93b3JkcHJlc3MvcGx1Z2luL3NpdGVza2l0ZS92dWxuZXJhYmlsaXR5L3dvcmRwcmVzcy1zaXRlc2tpdGUtcGx1Z2luLTItMS04LXJlbW90ZS1jb2RlLWV4ZWN1dGlvbi1yY2UtdnVsbmVyYWJpbGl0eSI,s__DbMe5dVBwz8g5hf.png)
Multiple WordPress Plugins Face Vulnerabilities Requiring Immediate Updates
4h agoThree WordPress plugins have been reported with vulnerabilities: the GiveWP plugin (version 4.16.9) has a Cross Site Scripting (XSS) vulnerability, while both the Siteskite (version 2.1.8) and Cartflows (version 3.2.0) plugins have Remote Code Execut...

Apple Addresses CoreGraphics Zero-Day Vulnerability Amid
11h agoOn September 30, 2026, Apple released a patch for a zero-day vulnerability in CoreGraphics that was reportedly being. The flaw, identified as CVE-2026-1234, allows attackers to execute arbitrary code on affected systems. Users of macOS and iOS are pa...

Critical Vulnerabilities in Python-Tornado6 Affecting openSUSE and SUSE Systems
14h agoOn September 30, 2026, multiple vulnerabilities were disclosed in python-tornado6, impacting openSUSE and SUSE systems. The vulnerabilities include CVE-2023-54397, a critical HTTP request smuggling flaw, and CVE-2026-91990, which allows for denial of...

MALFEX Campaign Targets npm with Windows RAT and Data Theft
15h agoThe MALFEX campaign, uncovered by CloudSEK, has been active since August 2023, using malicious npm packages to deploy the Overlord RAT and steal data from Windows systems. The operator, identified as Portuguese-speaking, has uploaded at least 12 npm...
Explore the intelligence behind this feed
Every actor, malware family, CVE and company in the reporting has its own intelligence page — AI overview, timeline, relationships, IOCs. No login needed.

Critical Chrome Update Addresses 33 Security Flaws Including CVE-2026-102331
22h agoOn September 29, 2026, Google released a Chrome update addressing 33 security vulnerabilities, including a critical buffer overflow flaw in ANGLE, tracked as CVE-2026-102331. This update affects Chrome versions 154.0.8037.92/.93 for Windows and macOS...

PraisonAI Framework Vulnerability Allows Authentication Bypass
20h agoOn May 11, 2026, a vulnerability (CVE-2026-44338) was disclosed in PraisonAI's multi-agent orchestration framework, where authentication was hard-coded to be disabled in versions 2.5.6 to 4.6.33. This flaw, with a CVSS score of 7.3, allows unauthoriz...

Critical RCE Vulnerabilities Disclosed in Popular WordPress Plugins
3h agoMultiple critical vulnerabilities have been disclosed affecting popular WordPress plugins, including SiteSkite and LatePoint. CVE-2026-96349 and CVE-2026-92966 both allow unauthenticated remote code execution, with CVSS scores of 10.0 and 9.1 respect...

Ukraine's Cultural Heritage and Steel Industry Devastated by Russian Attacks
18h agoIn August and September 2026, Ukraine faced intensified Russian missile strikes, severely damaging its cultural heritage and steel industry. Odesa reported damage to six UNESCO-protected sites amid broader destruction, with 148 cultural heritage site...

Russia Deploys New Drone Warhead Against Ukrainian Power Infrastructure
15h agoOn September 30, 2026, Russia utilized a jet-powered drone equipped with a newly developed warhead designed to destroy high-voltage power pylons for the first time, according to Ukrainian presidential adviser Serhii 'Flash' Beskrestnov. The attack is...
Sign up to keep reading
There's a lot more below this.
A free account unlocks the rest of today's feed, a feed built around your own stack and sector, and the daily digest. 20,000+ sources, clustered in real time.
Free forever. No card. 5 tracked interests + the daily digest included.
How this feed is built
- 20,000+ sources monitored. News, vendor research, CERT advisories, ransomware leak sites. Collected continuously.
- Clustered into incidents. One story becomes one record: deduplicated, scored, with the actors, CVEs and IOCs extracted.
- Rebuilt around you. A free account turns this into your feed, plus the daily digest and alerts.
Trending Threats
Gaining coverage in the last 24 hours
Ransomware victims
Live from our dark web monitoring
Daily Digest
Today's top threats from 20,000+ sources — one five-minute email each morning instead of an hour of scanning. Free, no account needed.


