intel
threat feed assembled at build time from ransomware.live and four news wires · refreshed daily · last pull just now
*feed window = the 100 most recent claims upstream publishes on the free tier · archive grows daily since 2026-08
latest ransomware claims
newest first · names as published by the groups| when | victim | group | sector | country |
|---|---|---|---|---|
| 5h ago | Vigatec · www.vigatec.com | qilin | Technology | DE |
| 7h ago | Invincible GG · www.invinciblegg.com | qilin | Technology | — |
| 10h ago | expresspros.com · expresspros.com | chaos | Professional Services | US |
| 10h ago | hoyletanner.com · hoyletanner.com | BrainCipher | Professional Services | GB |
| 10h ago | aecom.com · aecom.com | BrainCipher | Professional Services | US |
| 10h ago | Techwise · www.techwise.com.ar | qilin | Technology | AR |
| 10h ago | The Gran Hotel Ingles · www.granhotelingles.com | qilin | Hospitality | ES |
| 11h ago | xpera.ca · xpera.ca | BrainCipher | Technology | CA |
| 12h ago | Practice Management (maximizedrevenue.com) · maximizedrevenue.com | akira | Professional Services | US |
| 13h ago | Vetta | akira | Technology | — |
| 13h ago | Javep Chevrolet | akira | Retail & E-Commerce | — |
| 13h ago | Beckman Coulter, Inc · www.beckmancoulter.com | Healthcare | US | |
| 13h ago | AECOM · aecom.com | Professional Services | US | |
| 13h ago | Promantra, Inc · promantra.us | Technology | US | |
| 16h ago | STP Fashion Lab · stpfashionlab.it | Vexy Ransomware | Retail & E-Commerce | IT |
| 17h ago | Westbridge Institute of Technology, Inc. | emperador | Education | — |
| 19h ago | www.appliancefactory.com · www.appliancefactory.com | incransom | Manufacturing | US |
| 19h ago | www.diarco.com.ar · www.diarco.com.ar | incransom | Retail & E-Commerce | AR |
| 1d ago | HandyTrac Greystar AZ WARNING · new.handytrac.com | ShadowByt3$ | Other | US |
| 1d ago | RDA MOTORS S.P.A. | emperador | Manufacturing | IT |
most active (window)
- thegentlemen 26 claims 2 DLS
- qilin 20 claims 3 DLS
- akira 10 claims 1 DLS
- safepay 8 claims 5 DLS
- metaencryptor 5 claims 2 DLS
- BrainCipher 3 claims 1 DLS
full dossiers and raw leak-site addresses in the researcher vault.
security wire
the hacker news · bleepingcomputer · krebs on security · dark reading- [Virtual Event] Cybersecurity Outlook 2027
- New RatHat Android malware uses AI to automate device control
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]
- CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
The move is consistent with the agency's advice on the need for organizations to prioritize the vulnerabilities that actually matter.
- China's FamousSparrow APT Spies on US Politics in Latin America
Amid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.
- OpenAI details more cases of AI agents taking unauthorized actions
OpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed A…
- Brevo supply-chain attack injected ClickFix scripts on customer sites
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]
- What Recent AI-Powered Attacks Mean for Your Identity Security
AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that…
- Windows 11 24H2 Home and Pro reach end of support in October
Microsoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...]
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries…
- Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time…
- US takes down NightmareStresser DDoS-for-hire platform
The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms. [...]
- CISO's Expert Guide to Agentic Pentesting for Websites
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents…
- China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at lea…
- OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads
OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing…
- Chinese hackers use SparroWocky malware in govt espionage attacks
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. [...]
- Microsoft shares workaround for Windows domain login issues
Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. [...]
- BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server…
- Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It als…
- Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
- Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow a…
- U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser. The domains…
- Anthropic wants Claude to analyze your bank account and financial data
Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." [...]
- AI Security Spending Jumps as Fear Outpaces Proof of Value
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
- Windows 11 KB5124008 update breaks domain trust for some users
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...]
- Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]
- Data Broker Radaris Loses Domains in Privacy Fight
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recen…
- Fighting Your Dragons Through Tough Tech Times
Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.
- BragJack Attack Can Turn a Browser's Agentic AI Against It
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.…
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has i…
- One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft…
- Cyber Op Targets South Korean Media & Automotive Sectors
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.
- Microsoft Issues Emergency Fixes After Massive Patch Tuesday
You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.
- Black Hat USA 2026 | OpenAI's Deep Dive Into Hugging Face Incident
At Black Hat USA, OpenAI engineers reconstruct the Hugging Face incident and explore lessons learned about AI safeguards and cyber resilience.
- VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.
- 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.
- Maximum Severity GitLab Flaw Puts Supply Chains at Risk
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
- Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping…
- FBI Probes Service Selling 153M+ Drivers Licenses
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose…
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. I…
- Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily p…
- Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others th…
- Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used th…
- Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connecti…
- LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after…
- Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record…
darknet watchlist
official onion services, verified against publisher announcementsnews & media
major outlets that publish official Tor mirrors for readers under censorship
- BBC News
www.bbcnewsd73hkzno2ini43t4gblxvycyac5aw4gnv7t2rccijh7745uqd.onion/
official BBC News Tor mirror for censored regions
✓ verified 2026-08-23 · clearnet mirror
- The New York Times
www.nytimes3xbfgragh.onion/
NYT onion service, live since October 2017
✓ verified 2026-08-23 · clearnet mirror
- ProPublica
p53lf57qovyuvwsc6xnrppyply3vtqm7l6pcobkmyqsiofyeznfu5uqd.onion/
first major newsroom on Tor; full site mirror
✓ verified 2026-08-23 · clearnet mirror
privacy & tools
infrastructure you should only ever reach over its onion when privacy matters
- Tor Project
2gzyxa5ihm7nsggfxnu52rck2vv4rvmdlkiu3zzui5du4xyclen53wid.onion/
download Tor Browser without leaving the network
✓ verified 2026-08-23 · clearnet mirror
- DuckDuckGo
duckduckgogg42xjoc72x3sjasowoarfbgcmvfimaftt6twagswzczad.onion/
no-tracking search engine, native onion endpoint
✓ verified 2026-08-23 · clearnet mirror
- Proton Mail
protonmailrmez3lotccipshtkleegetolb73fuirgj7r4o4vfu7ozyd.onion/
encrypted mail over Tor; address unchanged since launch
✓ verified 2026-08-23 · clearnet mirror
government & reference
the odd but real corners: intelligence agencies, archives, and status trackers
- Facebook
facebookwkhpilnemxj7asaniu7vnjjbiltxjqhye3mhbshg7kx5tfyd.onion/
largest consumer site running an official onion since 2014
✓ verified 2026-08-22 · clearnet mirror
- CIA
ciadotgov4sjwlzihbbgxnqg3xiyrg7so2r2o3lt5wz5ypk4sxyjstad.onion/
the agency's official onion contact portal
✓ verified 2026-08-22 · clearnet mirror
- Archive.today
archiveiya74codqgiixo33q62qlrqtkgmcitqx5u2oeqnmn5bpcbiyd.onion/
webpage snapshot archive, reachable when clearnet blocks you
✓ verified 2026-08-22 · clearnet mirror
- dark.fail
darkfailenbsdla5mal2mxn2uz66od5vtzd5qozslagrfzachha3f3id.onion/
pgp-verified uptime tracker for popular onion services
✓ verified 2026-08-22 · clearnet mirror
claim archive
every claim the daily ingest has ever seen · …| discovered | victim | group | sector | country |
|---|
archive accumulates daily since 2026-08 · full export incl. leak-post links is a pro download in the vault