threat-intel Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler Iranian state-sponsored hacking group Nimbus Manticore (linked to Charming Kitten) has expanded its toolset with a TWOSTROKE-like backdoor and SSH tunneling utility, furthering its espionage activities targeting defense, aerospace, and IT service providers in the Middle East and the U.S. This expansion highlights the g… The Hacker News · 4d ago High IRMIEUsshbackdoorc2
threat-intel Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS Evooo1Bot, a Linux botnet derived from Mirai, has significantly expanded its capabilities beyond simple DDoS attacks. It now incorporates advanced features like encrypted C2 communications, SSH brute-force scanning, a re… Dark Reading · Aug 17, 2026 High CVE-2007-3010CVE-2016-6277CVE-2018-14558miraiddosbotnet
threat-intel Critical VMware vCenter Vulnerability in Attackers’ Crosshairs A critical vulnerability (CVE-2026-59310) in VMware vCenter is being actively exploited by an advanced persistent threat (APT) group, leading to remote code execution and persistent access for attackers. The vulnerabilit… SecurityWeek · Aug 13, 2026 Critical CVE-2026-59310DEUSTRvulnerabilityremote code executionssh
threat-intel Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine Polish power plant operators suffered a significant cyberattack that led to the shutdown of a steam turbine and process-water treatment system. The attack exploited a private cellular network used by the grid operator to… The Hacker News · Aug 11, 2026 High CVE-2023-32349CVE-2023-32350PLprivate apnindustrial control systemscyberattack
vulnerability Multiples vulnérabilités dans OpenSSH (11 août 2026) Multiple vulnerabilities have been discovered in OpenSSH, impacting versions prior to 10.5. The exact nature of the security issue is not specified by the publisher, but users are advised to consult the vendor's security… CERT-FR · Aug 11, 2026 Medium sshvulnerabilitysecurity
ransomware #StopRansomware: Gunra Ransomware The FBI, CISA, and other agencies have issued a joint advisory regarding the Gunra ransomware threat, a sophisticated double-extortion variant derived from the Conti ransomware. Gunra has rapidly expanded through a RaaS… CISA Advisories · Aug 10, 2026 Critical CVE-2024-55591CVE-2025-24472USREransomwaredouble extortionr0aas
threat-intel 22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th) A threat actor successfully exploited a vulnerable SSH honeypot within 22 seconds, injecting a backdoor SSH key, changing the root password, and clearing host-based access restrictions. This rapid post-exploitation seque… SANS Internet Storm Center · Aug 6, 2026 High CHsshautomationpost-exploitation
threat-intel Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th) This guest diary details a unique SSH reconnaissance bot that doesn't immediately deploy malware, but instead meticulously assesses a target's hardware capabilities before potentially launching a cryptomining attack. The… SANS Internet Storm Center · Jul 30, 2026 Medium NLreconnaissancesshcryptomining
vulnerability Vulnérabilité dans les produits Moxa (24 juillet 2026) A critical vulnerability has been identified in Moxa products, allowing attackers to elevate their privileges. This security issue stems from a flaw within the Linux kernel and requires immediate attention to prevent pot… CERT-FR · Jul 24, 2026 Critical CVE-2026-46333linuxsshprivilege-escalation
threat-intel OkoBot: new sophisticated malware framework targets cryptocurrency users OkoBot is a sophisticated and evolving malware framework developed by threat actors since 2025, primarily targeting cryptocurrency users. The framework utilizes a layered approach, starting with a PowerShell downloader (… Securelist · Jul 15, 2026 High ransomwarecryptocurrencybrowser
threat-intel _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th) A self-propagating bot, originating from Belarus (as claimed by its creator), has been scanning for open ports and attempting brute-force login attempts on various servers worldwide. The bot’s purpose is to raise awarene… SANS Internet Storm Center · Jul 9, 2026 Medium BYscanbrute-forcessh
vulnerability Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw A critical vulnerability, CVE-2026-55200, has been discovered in libssh2, a client-side SSH library embedded in various applications like curl, Git, and PHP. The flaw allows for code execution via an integer overflow, po… The Hacker News · Jun 29, 2026 Critical CVE-2026-55200CVE-2019-3855CVE-2026-55199GBsshlibssh2code execution
threat-intel FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation A Russian-speaking threat actor, dubbed FortiBleed, is conducting a large-scale credential harvesting operation targeting over 430,000 FortiGate firewalls globally. The campaign, active since February 2026, utilizes a Go… The Hacker News · Jun 23, 2026 High USINRUcredential harvestingfirewallactive directory
threat-intel Russian Initial Access Broker Behind FortiBleed Campaign A Russian initial access broker (IAB) is targeting over 430,000 FortiGate firewalls globally as part of the FortiBleed campaign, harvesting credentials and selling access to other malicious actors. The campaign utilizes… SecurityWeek · Jun 23, 2026 High USGBNLcredential harvestingfirewallsupply chain
threat-intel The Behavior of Coordinated SSH Brute Force Attacks over the last three months [Guest Diary], (Wed, Jun 17th) This report details a three-month analysis of coordinated SSH brute-force attacks conducted using a honeypot system, highlighting a correlation between attack activity and geopolitical events, law enforcement actions, an… SANS Internet Storm Center · Jun 18, 2026 High USIRILsshbrute-forcehoneypot
threat-intel Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline A junior hacker, identified as ‘Poisson,’ infiltrated a French automotive business by exploiting vulnerabilities and establishing persistent access after his command-and-control server was taken down. He utilized OpenSSH… The Hacker News · Jun 17, 2026 Medium FRDEpersistenceremote-accessssh
threat-intel Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks The ShinyHunters extortion gang is targeting Oracle PeopleSoft servers in ongoing data theft attacks, having already compromised over 300 instances across more than 100 organizations. They are exploiting a chain of old a… BleepingComputer · Jun 10, 2026 High UKpeoplesoftzero-daydata theft
malware C0XMO botnet spreads via DD-WRT router flaw, kills rival malware A new botnet, C0XMO, leveraging a DD-WRT router vulnerability (CVE-2021-27137) is spreading across various device architectures, including routers, DVRs, and Android devices. This botnet, developed by the Gafgyt group, i… BleepingComputer · Jun 7, 2026 High CVE-2021-27137DEJPddosbotnetexploit
threat-intel Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit An unknown threat actor exploited CVE-2026-39987 in Marimo to gain initial access, subsequently using a large language model (LLM) agent to conduct post-exploitation activities, including stealing credentials and exfiltr… The Hacker News · May 29, 2026 High CVE-2026-39987CNllmpost-exploitationcredential theft
vulnerability 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros A nine-year-old vulnerability in the Linux kernel, CVE-2026-46333, allows unprivileged users to execute commands as root, posing a significant risk to systems running affected distributions. The flaw stems from improper… The Hacker News · May 21, 2026 High CVE-2026-46333linuxkernelprivilege escalation