CYBERSECURITY INTEL FREE'Dself-hosted CTI

LATEST // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 44 matching records.
AUTO-POLL // 2026-08-16 04:50 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-06-15 14:00 UTC
Vendor Research
TIER 2

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and abused enterprise administrative tools for covert data exfiltration. The threat actor had broad collectio…

AI SecurityCloud SecurityDFIRInitial AccessMalwareMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-06-11 14:00 UTC
Vendor Research
TIER 2

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity p…

AppleCloud SecurityData BreachesLinuxMicrosoftThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-35273
P45
2026-06-10 06:47 UTC
Government
TIER 1

2026-007: Critical Vulnerability in Windows Netlogon

CERT-EU Security Advisories · indexed 2026-08-16 02:02 UTC

On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors. It is strongly recommended updating affected Windows servers as soon as possible.

MicrosoftThreat ActorsVulnerabilities
P10
2026-06-05 14:00 UTC
Vendor Research
TIER 2

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United States. UNC3753 leverages voice phishing (vishing) and social engineering deception techniques to achieve remote access into corporate environments. Using pretexts such as data migration o…

Data BreachesDFIRInitial AccessMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-05-29 13:56 UTC
Vendor Research
TIER 1

Microsoft Entra ID 1-Click Open Redirection via OAuth Error Handling Abuse

Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC

Microsoft Entra ID 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered new techniques to trigger 1-click open redirection attacks in Microsoft Entra ID by abusing the OAuth error-handling mechanism. The attack relies on an initial setup phase where a threat actor registers an OAuth application in an actor-controlled tenant and configures its redirect_uri to point to an attacker-controlled domain. When a victim clicks on a specifically crafted authorization link on the trusted login.microsoftonline.com domain, combinations of malformed pa…

AppleMalwareMicrosoftPhishingSecurity ResearchThreat Actors
P0
2026-05-25 14:00 UTC
Vendor Research
TIER 2

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE). An unknown threat actor leveraged this access to inject malicious code into the LMS platform, with the goal of infecting users visiting the site. This vulnerability stems from the use of identi…

AppleDFIRMalwareMicrosoftThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-5426
P55
2026-05-25 14:00 UTC
Vendor Research
TIER 2

2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that region. These services not only lower the barrier to entry for Chinese cyber criminals, but reveal broader patterns on the evolution of social engineering and credential theft. Late last year, Google…

AppleCybercrimePhishingThreat ActorsThreat IntelligenceUnderground Intelligence
P0
2026-05-19 17:49 UTC
Vendor Research
TIER 1

Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

On April 23, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an update to V1: Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices related to Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) products. According to the update, the ArcaneDoor threat actor has developed a previously unknown persistence mechanism that is preserved across upgrading to the fixed releases that were published in September 2025. This persistence mechanism resides in the Cisco Firepower eXtensible …

Network SecurityThreat ActorsVulnerabilities CVE-2025-20333CVE-2025-20362
P20
2026-05-15 14:00 UTC
Vendor Research
TIER 2

Welcome to BlackFile: Inside a Vishing Extortion Operation

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gains deep access to cloud environments. The group primarily targets Microsoft 365 and Okta infrastructu…

Data BreachesInitial AccessMicrosoftNetwork SecurityPhishingThreat ActorsThreat IntelligenceVulnerabilities
P0
2026-05-11 14:00 UTC
Vendor Research
TIER 2

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a sophisticated engine for adversary operations and a high-value target for attacks. We explore the foll…

AI SecurityAppleAPT / Nation-StateCloud SecurityDFIRInitial AccessMalwareMicrosoftNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities
P60
2026-04-23 14:00 UTC
Vendor Research
TIER 2

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account outside their organization. The UNC6692…

Cloud SecurityInitial AccessMalwareMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-04-16 14:00 UTC
Vendor Research
TIER 2

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

Google Threat Intelligence / Mandiant · Francis deSouza · indexed 2026-08-16 02:02 UTC

Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulnerabilities. Faced with this scenario, defenders have two critical tasks: hardening the software we u…

AI SecurityAPT / Nation-StateCloud SecurityDFIRMicrosoftRansomwareThreat Actor ChatterThreat ActorsUnderground IntelligenceVulnerabilities
P60
2026-04-15 14:00 UTC
Vendor Research
TIER 2

The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previously observed in the country during 2022 and 2023. Cyber Criminals Pivoting Back to Germany Germany moved to the forefront of European data leak targets in 2025. Following a 2024 period where the UK led…

CybercrimeData BreachesRansomwareThreat ActorsThreat IntelligenceUnderground Intelligence
P15
12