AI Threat Intelligence

Threat intelligence, automated.

AI-researched threat write-ups, live IOC feeds, and MITRE ATT&CK mappings — human-reviewed before every publish. Built for defenders.

Threats tracked—
IOCs published—
MITRE techniques—
Last updated—
Latest Report
CRITICALvulnerability

FBI Warns of Ongoing FortiBleed Attacks Locking Out FortiGate VPN Admins

The FBI has issued a warning regarding ongoing ‘FortiBleed’ attacks targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways. These attacks are leading to the lockout of legitimate administrators, indicating successful unauthorized access and control over critical network infrastructure.

Read full report →
Recent Threats
CRITICALvulnerability

SonicWall SMA1000 Gateways Vulnerable to Max Severity SSRF

SonicWall has issued hotfixes for a critical Server-Side Request Forgery (SSRF) vulnerability affecting its SMA1000 series appliances. This flaw, rated at maximum severity, could allow attackers to force the gateway to make requests to internal network resources, potentially leading to information disclosure or further compromise. Immediate patching is recommended for all affected deployments.

Read report →
HIGHapt

Blinder Tunnel Campaign Targets Iraqi Infrastructure

The Blinder Tunnel campaign, attributed to an Iran-nexus APT, is actively targeting critical infrastructure in Iraq. Attackers leverage fake Dubai Airports recruitment lures to deliver custom malware that utilizes GitHub for command and control (C2), aiming for initial access and persistent control within target environments.

Read report →
HIGHvulnerability

LibreOffice and OpenOffice Code Execution Vulnerability via Malicious Spreadsheets

Security researchers have demonstrated a proof-of-concept vulnerability in LibreOffice and Apache OpenOffice that allows malicious spreadsheets to execute arbitrary code upon opening, bypassing macro security warnings. The exploit relies on Java support being enabled within the office suite, posing a significant risk for silent code execution.

Read report →
HIGHthreat

ASOS Confirms Data Breach Following Snowflake Environment Compromise

UK fashion retailer ASOS confirmed a data breach after threat actors sent unauthorized “HACKED” push notifications to customers via its mobile app. The attackers claimed to have exfiltrated customer data from ASOS’s Snowflake cloud data warehousing environment, indicating a compromise of cloud infrastructure.

Read report →
CRITICALvulnerability

Ninja Forms Plugin Flaw Exploited to Hack WordPress Sites

A stored Cross-Site Scripting (XSS) vulnerability in the Ninja Forms WordPress plugin is being actively exploited. Attackers are leveraging this flaw to inject malicious scripts, leading to the installation of backdoors and the creation of unauthorized administrative accounts on compromised WordPress sites. Immediate patching and security review are critical for affected installations.

Read report →
HIGHmalware

ClickFix Attacks Evolve to Leverage DNS TXT Records and Browser Pre-fetching for Payload Hiding

ClickFix attacks are evolving to evade detection by using DNS TXT records to hide malicious payloads and browser cache pre-fetching to stage them. This sophisticated technique makes early-stage attack identification more challenging for defenders, as it obscures the initial delivery mechanisms.

Read report →
CRITICALvulnerability

Rejetto HFS Servers Actively Scanned for Critical RCE Flaw (CVE-2026-61500)

Threat actors are actively scanning for a critical Remote Code Execution (RCE) vulnerability, CVE-2026-61500, affecting Rejetto HFS (HTTP File Server) instances. This flaw, stemming from a weak signing key, allows for session forgery, account takeover, and arbitrary code execution on vulnerable servers. Immediate action is advised for organizations operating Rejetto HFS.

Read report →
HIGHransomware

University of Illinois Chicago College of Medicine Ransomware Incident

The University of Illinois Chicago (UIC) College of Medicine experienced a ransomware attack that resulted in the exfiltration of data from its servers. This incident underscores the persistent threat ransomware poses to educational and healthcare institutions, often leading to data theft in addition to system disruption.

Read report →

Transparently AI-authored

Every report on this site is researched and drafted by an AI agent, then reviewed and approved by a human analyst before publication. The Agent Logbook shows every step — sources consulted, enrichment calls, tokens used, and approval status — in real time.