ThreatFeed Logo

ThreatFeed Dashboard

by Jerry Craft, ALM-MIS, CISSP, GSEC, GPEN, GCFE

🌍 Timezone not configured. You're using UTC. Set your timezone to see "today's" articles in your local time.
CVE Search Breaches Trends Industries Vendors MITRE ATT&CK MITRE ATLAS Threat Actors Attack-Tools Alerts Investigations Options Login
🎯 Executive Threat Briefings

Daily Digest

Pending Digest pending

Weekly Digest

2026-08-03 to 2026-08-09 330 articles • 90 CVEs • 45 breaches

Monthly Digest

July 2026 2484 articles • 1533 CVEs • 148 breaches

Quarterly Digest

Q2 2026 3 months analyzed

📊 Breach Metrics

Last 354 days: 1821 breaches (5.1/day), 25.2B records + 4.61PB data exposed, $92.6B in total loss costs (avg $411.4M across 225 breaches reporting costs)

🤖 MITRE ATLAS Metrics

Attacks on AI systems,
and attacks carried out with AI
Top 10:
AML.T0051 LLM Prompt Injection (198)
AML.T0046 Spamming AI System with Chaff Data (12)
AML.T0048 External Harms (11)
AML.T0049 Exploit Public-Facing Application (11)
AML.T0036 Data from Information Repositories (10)
AML.T0037 Data from Local System (10)
AML.T0042 Verify Attack (10)
AML.T0043 Craft Adversarial Data (10)
AML.T0017 Develop Capabilities (9)
AML.T0054 LLM Jailbreak (9)

⚔️ MITRE ATT&CK Metrics

564 unique techniques observed
🔥 = Observed in Nth RRA
🥷 = Observed in Nth Pentesting
Top 10:
T1566 Phishing (1723) 🥷
T1059 Command and Scripting Interpreter (934) 🔥 🥷
T1078 Valid Accounts (822) 🔥 🥷
T1190 Exploit Public-Facing Application (713) 🥷
T1071 Application Layer Protocol (376)
T1068 Exploitation for Privilege Escalation (361) 🥷
T1203 Exploitation for Client Execution (300)
T1566.002 Spearphishing Link (294) 🥷
T1071.001 Web Protocols (268)
T1082 System Information Discovery (246) 🥷

🛠️ Attacker Tools

2338 unique tools tracked: 1920 malware families, 109 attack frameworks

🌍 Top Nation-State Activity (90 Days)

View Actors
Trending Up Cooling Off Stable

🤖 AI Investigation Types

View Investigations

🔍 Recent AI Investigations

CRITICAL Lazarus Group (Operation Dream Job) is actively exploiting CVE-2026-68820, a Windows privilege escalation zero-day, to deploy the ForestTiger/Troy backdoor targeting defense and aerospace sectors across France, Germany, Brazil, and India
2026-08-14
HIGH This cluster reveals a diversified ransomware ecosystem involving multiple active groups: DeadLock (using blockchain-based infrastructure for resilience), Akira (exploiting safe mode to bypass EDR), Chaos (leveraging Teams vishing and browser-based C2), Qilin (exploiting PAN-OS vulnerabilities), and Lynx/INC (linked to FortiBleed credential theft)
2026-08-13
CRITICAL CVE-2026-59310, a critical CVSS 9.8 directory traversal vulnerability in VMware vCenter Syslog Server, is being actively exploited in the wild to deploy reverse SSH tools for persistent remote access
2026-08-13
CRITICAL A critical authorization vulnerability in Adobe Commerce (CVE-2026-71362, CVSS 9.1) is being actively exploited in the wild to hijack customer accounts by switching session identities without authentication
2026-08-13
HIGH A coordinated financial fraud campaign utilizes the SpyNote RAT to gain remote Android device access, followed by WindRelay malware that relays victim credit card data via NFC in real-time
2026-08-13
View All Investigations
Article filters:
Clear

Showing 40 articles.

Articles Today

BleepingComputer (10)
BleepingComputer
Published: 2026-08-13T21:12:47+00:00 | Fetched: 2026-08-13T22:00:11+00:00
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...]
BleepingComputer
Published: 2026-08-13T20:47:02+00:00 | Fetched: 2026-08-13T21:00:09+00:00
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]
BleepingComputer
Published: 2026-08-13T18:15:19+00:00 | Fetched: 2026-08-13T19:00:10+00:00
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]
BleepingComputer
Published: 2026-08-13T17:46:20+00:00 | Fetched: 2026-08-13T18:00:10+00:00
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]
BleepingComputer
Published: 2026-08-13T17:33:28+00:00 | Fetched: 2026-08-13T18:00:11+00:00
Read more ▼
BleepingComputer
Published: 2026-08-13T16:40:23+00:00 | Fetched: 2026-08-13T17:00:09+00:00
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]
BleepingComputer
Published: 2026-08-13T15:13:19+00:00 | Fetched: 2026-08-13T16:00:11+00:00
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping provider and logistics partner, got hacked. [...]
BleepingComputer
Published: 2026-08-13T14:00:10+00:00 | Fetched: 2026-08-13T15:00:11+00:00
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]
BleepingComputer
Published: 2026-08-13T13:30:53+00:00 | Fetched: 2026-08-13T14:00:10+00:00
A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. [...]
BleepingComputer
Published: 2026-08-13T11:50:22+00:00 | Fetched: 2026-08-13T12:00:23+00:00
WhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. [...]
Cisco Talos Blog (2)
Cisco Talos Blog
Published: 2026-08-13T18:00:18+00:00 | Fetched: 2026-08-13T19:00:06+00:00
In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.
Cisco Talos Blog
Published: 2026-08-13T10:00:35+00:00 | Fetched: 2026-08-13T11:00:20+00:00
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.
Dark Reading (3)
Dark Reading
Published: 2026-08-13T20:45:17+00:00 | Fetched: 2026-08-13T22:00:08+00:00
Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.
Dark Reading
Published: 2026-08-13T10:00:00+00:00 | Fetched: 2026-08-13T10:00:19+00:00
Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.
Dark Reading
Published: 2026-08-13T07:00:00+00:00 | Fetched: 2026-08-13T09:00:24+00:00
The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.
DataBreaches.Net (4)
DataBreaches.Net
Published: 2026-08-13T15:05:06+00:00 | Fetched: 2026-08-13T16:00:13+00:00
Read more ▼
DataBreaches.Net
Published: 2026-08-13T15:02:37+00:00 | Fetched: 2026-08-13T16:00:13+00:00
Read more ▼
DataBreaches.Net
Published: 2026-08-13T00:48:04+00:00 | Fetched: 2026-08-13T01:00:21+00:00
Read more ▼
DataBreaches.Net
Published: 2026-08-13T00:32:14+00:00 | Fetched: 2026-08-13T01:00:21+00:00
Read more ▼
Have I Been Pwned latest breaches (1)
Have I Been Pwned latest breaches
Published: 2026-08-13T10:54:40+00:00 | Fetched: 2026-08-13T14:00:09+00:00
Read more ▼
KnowBe4 Blog (3)
KnowBe4 Blog
Published: 2026-08-13T20:00:02+00:00 | Fetched: 2026-08-13T21:00:08+00:00
Read more ▼
KnowBe4 Blog
Published: 2026-08-13T16:00:00+00:00 | Fetched: 2026-08-13T17:00:08+00:00
An initial access broker for ransomware gangs is targeting organizations with voice phishing (vishing) attacks through Microsoft Teams, according to researchers at Zscaler’s ThreatLabz.
KnowBe4 Blog
Published: 2026-08-13T13:00:03+00:00 | Fetched: 2026-08-13T14:00:07+00:00
The Iran-linked threat actor APT42 is using AI-assisted phishing attacks to target U.S. organizations amidst the Iran-US war, according to researchers at DarkAtlas.
Malwarebytes (2)
Malwarebytes
Published: 2026-08-13T11:34:25+00:00 | Fetched: 2026-08-13T12:00:22+00:00
Social engineering, a Remote Access Trojan (RAT), and NFC relay malware walk up to an ATM. It's no joke. Together, they can empty your bank account.
Malwarebytes
Published: 2026-08-13T09:59:48+00:00 | Fetched: 2026-08-13T11:00:22+00:00
It's the biggest legal challenge yet to addictive social media design and its impact on children.
Qualys Security Blog (1)
Qualys Security Blog
Published: 2026-08-13T17:00:00+00:00 | Fetched: 2026-08-13T17:00:07+00:00
Read more ▼
SecurityWeek (8)
SecurityWeek
Published: 2026-08-13T14:41:44+00:00 | Fetched: 2026-08-13T15:00:13+00:00
Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm. The post Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 appeared first on SecurityWeek.
SecurityWeek
Published: 2026-08-13T14:17:44+00:00 | Fetched: 2026-08-13T15:00:13+00:00
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek.
SecurityWeek
Published: 2026-08-13T12:53:56+00:00 | Fetched: 2026-08-13T13:00:24+00:00
Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek.
SecurityWeek
Published: 2026-08-13T11:42:48+00:00 | Fetched: 2026-08-13T12:00:24+00:00
The Israeli company has nearly $2 billion in total assets under management since 2014. The post Venture Firm Team8 Secures Additional $365 Million appeared first on SecurityWeek.
SecurityWeek
Published: 2026-08-13T10:40:57+00:00 | Fetched: 2026-08-13T11:00:24+00:00
The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek.
SecurityWeek
Published: 2026-08-13T09:53:04+00:00 | Fetched: 2026-08-13T10:00:23+00:00
Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements. The post White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs appeared first on SecurityWeek.
SecurityWeek
Published: 2026-08-13T09:06:40+00:00 | Fetched: 2026-08-13T10:00:23+00:00
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.
SecurityWeek
Published: 2026-08-13T08:38:03+00:00 | Fetched: 2026-08-13T09:00:28+00:00
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared first on SecurityWeek.
The Hacker News (1)
The Hacker News
Published: 2026-08-13T06:09:48+00:00 | Fetched: 2026-08-13T09:00:18+00:00
Read more ▼
The Record from Recorded Future News (5)
The Record from Recorded Future News
Published: 2026-08-13T16:47:00+00:00 | Fetched: 2026-08-13T17:00:10+00:00
All Flock Safety customers will be required to adopt its "Audit Assistance" feature for tracking abnormal uses, and the company says it will hold license plate data for only seven days in most cases.
The Record from Recorded Future News
Published: 2026-08-13T15:52:00+00:00 | Fetched: 2026-08-13T16:00:12+00:00
Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.
The Record from Recorded Future News
Published: 2026-08-13T13:37:32+00:00 | Fetched: 2026-08-13T14:00:11+00:00
Discord's Go Live feature contributed to a 13-year-old girl's death by suicide, according to Brazilian regulators, who told the company to suspend the streaming technology.
The Record from Recorded Future News
Published: 2026-08-13T13:30:00+00:00 | Fetched: 2026-08-13T14:00:11+00:00
The Trump administration will allow private companies to launch attacks on cybercrime organizations, the White House announced.
The Record from Recorded Future News
Published: 2026-08-13T12:45:00+00:00 | Fetched: 2026-08-13T13:00:24+00:00
Germany’s cabinet approved legislation that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in the biggest overhaul of the country’s spy laws of the postwar era.