Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Campaigns

20 articles

SC Media Campaigns Google May 26

Fake AI tool websites used to steal developer data

The attack campaign employs SEO poisoning to elevate fake installation pages in search engine results, leading developers searching for AI tools like Google ...

SC Media →

Microsoft Security Blog Campaigns Microsoft May 26

From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities

Microsoft exposes a cryptojacking campaign using SEO poisoning and ScreenConnect to target high-performance PCs, with malicious sites also surfaced through A...

Microsoft Security Blog →

The Hacker News Campaigns Broadcom May 26

MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries

The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continent...

The Hacker News →

CSO Online Campaigns GitHub May 26

GitHub Actions abused by Megalodon attack to slip malicious commits into 5,500 repos

A large-scale automated GitHub backdooring campaign was caught pushing thousands of malicious commits into public repositories while posing as routine CI/CD ...

CSO Online →

SecurityWeek Campaigns May 26

Iranian APT Targets Aviation, Software Companies With Updated Tools

Nimbus Manticore has continued its operations during and after the US military campaign against Iran. The post Iranian APT Targets Aviation, Software Compani...

SecurityWeek →

Fortinet Blog Campaigns Oracle May 26

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data

FortiGuard Labs analyzed a new phishing campaign that uses obfuscated JavaScript, PowerShell, process hollowing, and PureLogs to steal sensitive data

T1566

Fortinet Blog →

CSO Online Campaigns Amazon GitHub May 26

TrapDoor malware campaign puts developer workstations in CISO spotlight

A malicious package campaign across npm, PyPI, and Crates.io has put developer workstations back under scrutiny, after researchers said it targeted developer...

1 IOC

CSO Online →

GBHackers Campaigns Microsoft Linux May 26

China-Linked Hackers Hit SEA Edge Routers With Custom Linux Implant

China-linked hackers are conducting a stealthy infrastructure-centric espionage campaign across Southeast Asia by compromising Linux-based edge routers with ...

GBHackers →

Infosecurity Magazine Campaigns May 26

Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign

Iran's Nimbus Manticore pushes AI-built MiniFast backdoor via phishing and SEO poisoning

T1566

Infosecurity Magazine →

Security Affairs Campaigns Check Point Zoom May 26

Nimbus Manticore Expanded Attacks With AI-Assisted Malware and Fake Zoom Installers

Nimbus Manticore accelerated cyberattacks during wartime, using AI-assisted malware, fake Zoom installers, and SEO poisoning. When the United States launched...

Security Affairs →

ESET Research Campaigns Google May 26

BTMOB: A stealthy RAT burrowing deep into Android devices

The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise

ESET Research →

Security Affairs Campaigns May 26

Lazarus APT unveils fileless remote access Trojan designed to evade detection

North Korea-linked Lazarus APT Group is using a stealthy memory-only RAT that leaves almost no forensic traces behind.

Security Affairs →

The Hacker News Campaigns May 26

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning

The Iranian state-sponsored threat actor known as Nimbus Manticore (aka Screening Serpens and UNC1549) has been attributed to a fresh campaign using lures im...

T1566

The Hacker News →

GBHackers Campaigns May 26

Malicious PDF LNK Files Deploy Cobalt Strike in Operation Dragon Whistle

A newly uncovered cyber campaign dubbed “Operation Dragon Whistle” is targeting China’s education sector with highly tailored spear-phishing attacks that dep...

T1566

GBHackers →

GBHackers Campaigns Trend Micro May 26

Jailbroken Gemini AI Abused in Credential Theft and Crypto Wallet Heist

Jailbroken Gemini AI has been weaponised in a long-running campaign that combined political influence, credential theft, and a cryptocurrency wallet heist, a...

T1078

GBHackers →

SANS ISC Campaigns Microsoft GitHub May 25

TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)

TeamPCP now operates across three package ecosystems in parallel, it reached GitHub&#;x26;#;39;s own internal codebase, it trojanized an officially Microsoft...

SANS ISC →

SANS ISC Campaigns Microsoft GitHub May 25

TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)

TeamPCP now operates across three package ecosystems in parallel, it reached GitHub&#;x26;#;39;s own internal codebase, it trojanized an officially Microsoft...

SANS ISC →

GBHackers Campaigns Microsoft May 25

APT Group Patches termsrv.dll to Enable Multiple RDP Sessions

A sustained cyber espionage campaign attributed to the Cloud Atlas advanced persistent threat (APT) group has introduced a stealthy technique that modifies t...

GBHackers →

GBHackers Campaigns May 25

Italian Authorities Dismantle CINEMAGOAL App Enabling Unauthorised Access to Streaming Platforms

Italian law enforcement agencies have dismantled a sophisticated piracy operation centered around the CINEMAGOAL application, which enabled unauthorized acce...

GBHackers →

The Hacker News Campaigns May 25

TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware.

T1195 1 IOC

The Hacker News →

«Previous page 1 ... 5 6 7 8 9 ... 18 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA