Skip to content

Threat Feed

Real-time threat intelligence: 20,000+ sources, clustered into one live feed.

219 new clusters in the last 24h · 1,018 sources reporting · 3 trending topics

Fetch this feed from the API

Build your own threat feed

Pick the vendors you run, your industry and where you operate. Your feed, digest and alerts then narrow to what can actually reach you.

No matches — try another spelling.

Used by 100+ security teams.

Bitget Confirms $387.5 Million Theft Linked to North Korean Hackers
HOT 2 New Articles Zero-Day

Bitget Confirms $387.5 Million Theft Linked to North Korean Hackers

3h ago

Cryptocurrency exchange Bitget confirmed that a theft of approximately $387.5 million was executed using a zero-day vulnerability in third-party security products. The attack, which began on September 24, 2026, involved unauthorized transfers from Bi...

ThehackernewsSilicon2 sources
76
Multiple WordPress Plugins Face Vulnerabilities Requiring Immediate Updates
1 New Article Vulnerability

Multiple WordPress Plugins Face Vulnerabilities Requiring Immediate Updates

4h ago

Three WordPress plugins have been reported with vulnerabilities: the GiveWP plugin (version 4.16.9) has a Cross Site Scripting (XSS) vulnerability, while both the Siteskite (version 2.1.8) and Cartflows (version 3.2.0) plugins have Remote Code Execut...

Remote Code ExecutionXSSZero-Day ExploitWordPressT1059 - Command And Scripting Interpreter+2
patchstack.com1 source1 TTP
75
ThreatCluster
1 New Article Vulnerability

Apple Addresses CoreGraphics Zero-Day Vulnerability Amid

11h ago

On September 30, 2026, Apple released a patch for a zero-day vulnerability in CoreGraphics that was reportedly being. The flaw, identified as CVE-2026-1234, allows attackers to execute arbitrary code on affected systems. Users of macOS and iOS are pa...

Supply Chain AttackCoreGraphicsT1195 - Supply Chain Compromise
Mixed-NewsOrfonlineMacobserverMinterellison4 sources1 TTP
73
Critical Vulnerabilities in Python-Tornado6 Affecting openSUSE and SUSE Systems
Vulnerability

Critical Vulnerabilities in Python-Tornado6 Affecting openSUSE and SUSE Systems

14h ago

On September 30, 2026, multiple vulnerabilities were disclosed in python-tornado6, impacting openSUSE and SUSE systems. The vulnerabilities include CVE-2023-54397, a critical HTTP request smuggling flaw, and CVE-2026-91990, which allows for denial of...

Denial Of ServiceCVE-2023-54397CVE-2024-58384CVE-2026-91990CVE-2026-91991+1
Linuxsecurity1 source
73
MALFEX Campaign Targets npm with Windows RAT and Data Theft
1 New Article 2 IOCs Malware

MALFEX Campaign Targets npm with Windows RAT and Data Theft

15h ago

The MALFEX campaign, uncovered by CloudSEK, has been active since August 2023, using malicious npm packages to deploy the Overlord RAT and steal data from Windows systems. The operator, identified as Portuguese-speaking, has uploaded at least 12 npm...

MalwareSupply Chain AttackMalfexShai-HuludMovinlike+11
CloudsekHackread2 sources6 TTPs
73

Explore the intelligence behind this feed

Every actor, malware family, CVE and company in the reporting has its own intelligence page — AI overview, timeline, relationships, IOCs. No login needed.

Critical Chrome Update Addresses 33 Security Flaws Including CVE-2026-102331
APT

Critical Chrome Update Addresses 33 Security Flaws Including CVE-2026-102331

22h ago

On September 29, 2026, Google released a Chrome update addressing 33 security vulnerabilities, including a critical buffer overflow flaw in ANGLE, tracked as CVE-2026-102331. This update affects Chrome versions 154.0.8037.92/.93 for Windows and macOS...

Star BlizzardZero-Day ExploitOracle PeopleSoft CampaignSpectre V2CVE-2026-102299+22
XSecurityweek2 sources
72
PraisonAI Framework Vulnerability Allows Authentication Bypass
Vulnerability

PraisonAI Framework Vulnerability Allows Authentication Bypass

20h ago

On May 11, 2026, a vulnerability (CVE-2026-44338) was disclosed in PraisonAI's multi-agent orchestration framework, where authentication was hard-coded to be disabled in versions 2.5.6 to 4.6.33. This flaw, with a CVSS score of 7.3, allows unauthoriz...

Data BreachZero-Day ExploitCarbonatoCVE-DetectorCVE-Detector/1.0+6
Forkast.Newsgithub.comcwe.mitre.orgCryptorank4 sources
71
Critical RCE Vulnerabilities Disclosed in Popular WordPress Plugins
HOT 2 New Articles Vulnerability

Critical RCE Vulnerabilities Disclosed in Popular WordPress Plugins

3h ago

Multiple critical vulnerabilities have been disclosed affecting popular WordPress plugins, including SiteSkite and LatePoint. CVE-2026-96349 and CVE-2026-92966 both allow unauthenticated remote code execution, with CVSS scores of 10.0 and 9.1 respect...

Zero-Day ExploitPoCbitCVE-2026-102424CVE-2026-102425CVE-2026-67364+7
Sploitus1 source2 TTPs
71
Ukraine's Cultural Heritage and Steel Industry Devastated by Russian Attacks
Geopolitical

Ukraine's Cultural Heritage and Steel Industry Devastated by Russian Attacks

18h ago

In August and September 2026, Ukraine faced intensified Russian missile strikes, severely damaging its cultural heritage and steel industry. Odesa reported damage to six UNESCO-protected sites amid broader destruction, with 148 cultural heritage site...

UkraineArcelor Mittal Kryvyi RihMetinvestZaporizhstal
Bbcwww.bbc.co.uk2 sources
74
Russia Deploys New Drone Warhead Against Ukrainian Power Infrastructure
Drone & EW

Russia Deploys New Drone Warhead Against Ukrainian Power Infrastructure

15h ago

On September 30, 2026, Russia utilized a jet-powered drone equipped with a newly developed warhead designed to destroy high-voltage power pylons for the first time, according to Ukrainian presidential adviser Serhii 'Flash' Beskrestnov. The attack is...

RussiaUkraineEnergy
KyivindependentPravda.Ua2 sources
74

How this feed is built

  • 20,000+ sources monitored. News, vendor research, CERT advisories, ransomware leak sites. Collected continuously.
  • Clustered into incidents. One story becomes one record: deduplicated, scored, with the actors, CVEs and IOCs extracted.
  • Rebuilt around you. A free account turns this into your feed, plus the daily digest and alerts.

Daily Digest

Today's top threats from 20,000+ sources — one five-minute email each morning instead of an hour of scanning. Free, no account needed.

Learn more