CYBERSECURITY INTEL FREE'Dself-hosted CTI

LATEST // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 39 matching records.
AUTO-POLL // 2026-08-16 04:50 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-07-02 14:00 UTC
Vendor Research
TIER 2

Google’s Continued Disruption of Malicious Residential Proxy Networks

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the following actions: Disabled Google accounts and associated Google services used by NetNut for malware command and control (C2), which directly violates Google’s Terms of Service and Acceptable Use Po…

APT / Nation-StateLaw EnforcementMalwareMicrosoftMobile SecurityNetwork SecurityThreat Intelligence
P0
2026-06-25 14:00 UTC
Vendor Research
TIER 2

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyber espionage, this backdoor shares significant code and functional overlaps with KAZUAR, a successf…

APT / Nation-StateMalwareMicrosoftThreat ActorsThreat Intelligence
P0
2026-06-15 14:00 UTC
Vendor Research
TIER 2

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and abused enterprise administrative tools for covert data exfiltration. The threat actor had broad collectio…

AI SecurityCloud SecurityDFIRInitial AccessMalwareMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-05-29 14:19 UTC
Vendor Research
TIER 1

Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse

Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC

Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered a 1-click open redirection technique in Amazon Cognito that can be triggered by abusing the OAuth error-handling mechanism. The vulnerability stems from AWS's OAuth implementation validation sequence: if validation fails due to an unsupported scope, mismatched PKCE parameters, or an unsupported response type, the error handling processes the failure and automatically issues an HTTP redirect to an attacker-controlled redirect_uri. Because the identity platform evaluates th…

AppleCloud SecurityMalwarePhishingSecurity ResearchVulnerabilities
P0
2026-05-29 13:56 UTC
Vendor Research
TIER 1

Microsoft Entra ID 1-Click Open Redirection via OAuth Error Handling Abuse

Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC

Microsoft Entra ID 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered new techniques to trigger 1-click open redirection attacks in Microsoft Entra ID by abusing the OAuth error-handling mechanism. The attack relies on an initial setup phase where a threat actor registers an OAuth application in an actor-controlled tenant and configures its redirect_uri to point to an attacker-controlled domain. When a victim clicks on a specifically crafted authorization link on the trusted login.microsoftonline.com domain, combinations of malformed pa…

AppleMalwareMicrosoftPhishingSecurity ResearchThreat Actors
P0
2026-05-25 14:00 UTC
Vendor Research
TIER 2

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE). An unknown threat actor leveraged this access to inject malicious code into the LMS platform, with the goal of infecting users visiting the site. This vulnerability stems from the use of identi…

AppleDFIRMalwareMicrosoftThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-5426
P55
2026-05-11 14:00 UTC
Vendor Research
TIER 2

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a sophisticated engine for adversary operations and a high-value target for attacks. We explore the foll…

AI SecurityAppleAPT / Nation-StateCloud SecurityDFIRInitial AccessMalwareMicrosoftNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities
P60
2026-04-23 14:00 UTC
Vendor Research
TIER 2

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account outside their organization. The UNC6692…

Cloud SecurityInitial AccessMalwareMicrosoftPhishingThreat ActorsThreat Intelligence
P0
12