Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Campaigns

20 articles

BleepingComputer Campaigns GitHub 1d ago

Laravel Lang packages hijacked to deploy credential-stealing malware

A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after a...

T1195

BleepingComputer →

The Hacker News Campaigns Oracle GitHub Linux 1d ago

Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved f...

T1195

The Hacker News →

The Hacker News Campaigns 1d ago

Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer

Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to del...

T1195

The Hacker News →

Security Affairs Campaigns 1d ago

Ghostwriter Is Back, Using a Ukrainian Learning Platform as Bait to Hit Government Targets

Ghostwriter targeted Ukrainian government agencies with phishing emails delivering malware and Cobalt Strike payloads. The Belarus-nexus APT group Ghostwrite...

T1566

Security Affairs →

GBHackers Campaigns Google 1d ago

Hackers Use SEO Poisoning to Fake Gemini CLI, Claude Installers

Financially motivated threat actors are running an active campaign that impersonates Google’s Gemini CLI and Anthropic’s Claude Code, using SEO poisoning to ...

GBHackers →

The Hacker News Campaigns 2d ago

Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware

The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine's National Security and Defense Council) has been observed using lures...

T1566

The Hacker News →

SC Media Campaigns Google 2d ago

Trapdoor ad fraud campaign used hundreds of Android apps

The Trapdoor campaign initially distributed seemingly legitimate utility apps, such as PDF readers, through the Google Play Store.

SC Media →

Unit 42 Campaigns 2d ago

Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns. The post Tr...

Unit 42 →

The Hacker News Campaigns GitHub 2d ago

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub reposit...

T1041

The Hacker News →

Infosecurity Magazine Campaigns 2d ago

Fake Gemini and Claude Code Sites Spread Infostealers Through SEO Poisoning

The infostealer payload in this campaign collect a vast amount of data, from collaboration authentication keys to cryptocurrency wallets

Infosecurity Magazine →

Help Net Security Campaigns 2d ago

Suspected KimWolf botnet admin arrested over DDoS-for-hire operation

U.S.

Help Net Security →

GBHackers Campaigns 2d ago

Hackers Use Six-Layer Persistence on FreePBX Systems

Hackers are actively exploiting FreePBX systems using a highly resilient six-layer persistence mechanism. The campaign has been attributed with high confiden...

T1190

GBHackers →

GBHackers Campaigns 2d ago

Hackers Weaponize NF-e Invoice Lures to Deploy Banana RAT

Hackers are actively using Brazil’s electronic invoice system (NF-e) as a lure to distribute a sophisticated banking trojan known as Banana RAT. The campaign...

T1598

GBHackers →

Help Net Security Campaigns Microsoft 2d ago

Microsoft 365 users targeted by new phishing threat that bypasses MFA

Microsoft 365 access tokens are being targeted by an emerging Phishing-as-a-Service (PhaaS) platform called Kali365, the FBI is warning. First observed in Ap...

T1566

Help Net Security →

GBHackers Campaigns Google 2d ago

Android Malware Secretly Signs Users Up for Premium Services

Android users are being targeted by a large-scale malware campaign that silently subscribes victims to premium mobile services without their knowledge. The m...

GBHackers →

The Hacker News Campaigns 2d ago

Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks

The U.S.

The Hacker News →

GBHackers Campaigns GitHub 2d ago

Megalodon Malware Rapidly Infects Over 5,500 GitHub Repositories

A newly identified malware campaign dubbed “Megalodon” has compromised more than 5,500 GitHub repositories, raising serious concerns about the security of op...

GBHackers →

GBHackers Campaigns 2d ago

Hackers Abuse Hugging Face to Deliver npm Malware

A newly uncovered supply chain attack targeting the npm ecosystem has been linked to North Korean (DPRK)-aligned threat actors. The campaign centers around a...

T1041 T1195

GBHackers →

GBHackers Campaigns Oracle 2d ago

Mini Shai-Hulud Attack Prompts npm to Revoke 2FA-Bypass Tokens

npm has forced a platform-wide reset of granular access tokens that bypass two-factor authentication (2FA) after a wave of supply chain attacks linked to the...

T1195

GBHackers →

SC Media Campaigns 2d ago

'First VPN' service used by cybercriminals dismantled in international operation

First VPN marketed itself on Russian-speaking cybercrime forums as a reliable tool for anonymity, offering features like anonymous payments and concealed inf...

SC Media →

1 2 3 ... 11 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA