Skip to content

Source index

Feeds and primary sources we consider worth monitoring for future threat coverage.

High-value RSS / update feeds

  • Confiant Threat Intelligence (RSS watch for malvertising, ad-fraud, browser-delivery, cloaking, and cryptocurrency-user targeting with durable technical and infrastructure detail, such as SourTrade's ServiceWorker / SharedWorker browser-side assembly of per-session Windows executables from clean Bun runtime bytes, actor-supplied PE / JavaScriptCore payload material, and locally generated AES-CTR streams.)
  • VulnCheck Research (Atom watch; monitor exploitation telemetry, target-intelligence research, public exploit proliferation, and KEV-relevant updates with durable defender value, including Windmill CVE-2026-29059 path-traversal attempts, wp2shell proof-of-concept growth, affected-system estimates, and payload or infrastructure changes)
  • Wiz Research: wp2shell active exploitation (2026-07-20 priority follow-up; monitor CVE-2026-63030 / CVE-2026-60137 WordPress Core exploitation, batch-endpoint tooling changes, malicious-plugin and PHP-webshell variants, lateral movement or exfiltration findings, and CISA KEV or WordPress incident-response updates)
  • Sonatype Security Research (RSS watch; monitor package-registry and ecosystem compromise research such as Atomic Arch AUR orphan-package adoption, malicious npm dependency pivots like atomic-lockfile / js-digest / lockfile-js, Sonatype vulnerability guide entries, and Shai-Hulud / Miasma supply-chain follow-ups such as Leo Platform / RStreams package clarification, llxlr package confirmation, and Sonatype-2026-004261-style advisory pivots)
  • Aikido Security Research (HTML/RSS watch; monitor developer-machine, AI-toolchain, VS Code / extension, Codex-token, and package supply-chain compromises such as codexui-android OpenAI token theft, poisoned extensions, Laravel-Lang, Mini Shai-Hulud follow-ups, and SleeperGem-style RubyGems dormant-maintainer account takeovers that evade CI and persist on developer workstations)
  • QiAnXin XLab (HTML watch; monitor MODBEACON / Operation Phnom Penh Silver Fox Ghost-distributor activity, large-scale exploitation, botnet, ClickFix/page-poisoning, hosting-control-plane abuse such as Mr_Rot13 cPanel CVE-2026-41940, infrastructure writeups such as Ghost CMS CVE-2026-26980 mass compromise reports, recon/proxy botnets such as AryStinger legacy-router and QNAP Malware Remover exploitation, DDoS botnets such as RustDuck's Loader + Core transition from C to Rust with weak-password / IoT / Web-RCE propagation, AI-service and cloud-credential botnets such as NadMesh targeting MCP, ComfyUI, Ollama, n8n, Docker, Kubernetes, Redis, and Jenkins, and cybercrime-infrastructure / web-supply-chain reports such as Funnull RingH23 / MacCMS poisoning)
  • Wiz Research (HTML watch; prior RSS path returned 404 in current checks; monitor TeamPCP/Mini Shai-Hulud package waves including Miasma / @redhat-cloud-services, AsyncAPI / M-RED-TEAM-style branch-to-provenance package compromises, JINX-0164-style cryptocurrency developer targeting with fake meeting flows, macOS malware, GitHub/source-repository abuse, and post-compromise cloud/GitHub abuse reporting such as TruffleHog validation, ECS Exec / SSM execution, mass repository cloning, and workflow-log deletion; also monitor AI coding-assistant trust-boundary research such as Amazon Q Developer CVE-2026-12957 MCP auto-execution through .amazonq/mcp.json workspace configuration and GhostApproval symlink write-confusion / approval-prompt canonical-path failures affecting AI coding assistants)
  • Socket Security Researchhttps://socket.dev/api/blog/feed.atom and https://socket.dev/blog (Atom/HTML watch; monitor Shai-Hulud/Mini Shai-Hulud variants, registry-response notices such as npm token invalidation, TeamPCP/copycat reporting, enterprise developer-ecosystem compromises such as SAP CAP / Cloud MTA packages, cross-ecosystem Packagist/Composer and GitHub source-repository compromises, DPRK/Contagious Interview developer-targeting dead-drop campaigns such as StegaBin Pastebin/Vercel payload delivery, Famous Chollima Packagist dev-branch loaders, and PolinRider expansion across npm, Packagist, Go modules, Chrome extensions, fake .woff2 loaders, VS Code folderOpen tasks, Git history rewriting, and blockchain/RPC C2, RubyGems abuse such as GemStuffer or BufferZoneCorp-style RubyGems/Go module CI poisoning, Laravel-Lang-style Composer tag rewrites/backdoors, financial/enterprise SDK impersonation such as Braintree.Net NuGet payment-card / merchant-credential skimming, Sicoob.Sdk NuGet mTLS certificate theft, NuGet DotnetTool malware such as game-cheat pepesoft.exe downloaders using DNS-over-HTTPS, GitHub/Hugging Face staging, Google Sheets telemetry, and Telegram screenshot paths, and Paysafe / Skrill / Neteller npm+PyPI typosquat stealers, high-blast-radius package compromises such as Axios pulling plain-crypto-js RAT payloads and Mastra @mastra/* packages pulling easy-day-js, Hades-style PyPI wheel startup-hook branches of Miasma / Mini Shai-Hulud using *-setup.pth, Bun, _index.js, .abi3.so native extensions, and split loaders such as langchain-core-mcp, cryptocurrency SDK compromise such as the Injective SDK npm wallet stealer where @injectivelabs/sdk-ts@1.20.21 and pinned scoped packages exfiltrated mnemonics/private keys during normal key derivation, trusted developer-tool compromises such as jscrambler follow-on malicious releases that move from preinstall hooks to dist/index.js / dist/bin/jscrambler.js runtime trigger injection, Leo Platform / Miasma follow-ups such as llxlr package expansion, Immobiliare Labs Backstage plugin compromise, and Verana Blockchain Go source-repository poisoning through .claude/ / .vscode/ hooks, AI-toolchain supply-chain tradecraft such as MCP/coding-assistant poisoning and TrapDoor-style npm/PyPI/Crates.io credential-stealer campaigns, AI-scanner anti-analysis such as prompt-injection comments, safety-triggering text, context flooding, and payload-after-noise layouts, Open VSX / VS Code extension abuse such as GlassWASM TinyGo/WebAssembly malware with Solana memo C2, Operation Muck and Load-style malicious Go module / GitHub lure-network campaigns with commit-farmed repositories, public dead-drop resolvers, protected archive delivery, RAT/infostealer payloads, and ischhfd83 pivots, and browser-extension abuse such as Chrome Web Store live-wallpaper ad-fraud / traffic-laundering networks and staged VPN/proxy extension clipboard stealers such as VPN Go.)
  • OX Security Research (HTML watch; monitor AI-toolchain and software-supply-chain malware such as Malware-Slop / mouse5212-super-formatter, Claude /mnt/user-data theft, GitHub Contents API exfiltration, leaked actor tokens, Shai-Hulud source-leak copycats such as chalk-tempalte / axois-utils / color-style-utils, TeamPCP follow-ons such as the Telnyx PyPI compromise after LiteLLM, Miasma / @redhat-cloud-services impact notes such as stolen-repository counts, earliest observed infection timing, six-stage loader loops, alternate Miasma : The Spreading Blight spacing, and firedalazer GitHub commit-search C2, MCP / AI-agent supply-chain trust-boundary research such as stdio command-execution configuration exposure, and AI-generated commodity npm malware tradecraft)
  • CrowdStrike Counter Adversary Operations (HTML watch; monitor developer-targeting botnet and supply-chain disruption reporting such as Glassworm, C2 takedowns, package/extension compromise, endpoint remediation guidance, and Windows execution/persistence research such as ClickOnce .application / .appref-ms abuse and HKCU COM hijacking)
  • Akamai Security Research (HTML watch; RSS blocked/unavailable in current checks; monitor active-exploitation and edge/WAF telemetry writeups such as Drupal CVE-2026-9082, exposed-AI-service abuse such as Ollama P2P cryptominer/RAT campaigns, APT exploit-chain analysis such as APT28 LNK / SmartScreen bypass / authentication-coercion findings, and infrastructure/botnet disruption notes)
  • SafeDep Research (HTML watch; monitor package-takedown evasion and rapid npm republishing such as @apexfdn/apex@copilot-mcp/apex, macOS AMOS-family postinstall theft, attacker-controlled remote MCP fronts, mutable GitHub release delivery, CI/CD, GitHub repository backdooring, package-registry compromise, Megalodon-style workflow backdoors, crypto/AI-tooling package malware such as Polymarket-themed wallet-drainer npm packages, actively maintained developer-targeting npm RATs such as forge-jsxy, MicrosoftSystem64 / js-logger-pack, and MYRA / apintergrationpost, Hugging Face / Discord exfiltration, typosquat infostealer campaigns such as faster-axios / turbo-axios Epsilon Stealer, runtime-triggered no-install-script npm backdoors such as nodemon-sudo / tslint-conf with detached child Node processes, Pinata IPFS staging, JsonKeeper dead drops, and Function-constructor execution, AI-brand scope-squatting credential harvesters such as @withgoogle/stitch-sdk, targeted dependency-confusion environment stealers such as the oob.moika.tech campaign and follow-on @marketfront / @tqm-mfe package waves with Internal package — Platform Engineering Team README markers, X-Secret exfil headers, RC4/XOR-hidden C2 configuration, and private-registry fallback targeting, build-config PR injection such as astro.config.mjs blockchain-C2 loaders and horizontal-whitespace diff hiding, Mastra / easy-day-js-style stale npm maintainer scope takeovers with provenance dropped and Hostwinds raw-IP RAT infrastructure, split-package Windows npm droppers such as procwire / routecraft with helper-package XOR C2 reconstruction and files.catbox.moe payload staging, multi-scope disposable-email npm infostealer campaigns such as the wshu.net package set with scrubbed latest tags, runtime execution, Rust stealers, user-level systemd persistence, and Telegram C2, LeoPlatform Miasma orphan snapshot-* branch / fake Dependabot workflow reconstruction, and Mini Shai-Hulud / AntV / Miasma-style detection pivots such as payload hashes, orphan GitHub commit delivery, two-wave trusted-publishing abuse, live-latest malicious releases, kitty-monitor, gh-token-monitor, AI-assistant persistence, and source-repository auto-execution through Claude Code / Gemini SessionStart, Cursor alwaysApply, VS Code folderOpen, and npm test launchers)
  • Lumen Black Lotus Labs (HTML watch; filter for Black Lotus Labs posts covering telecom, routing, botnet, and nation-state infrastructure research such as JDY / KV-botnet SOHO and IoT reconnaissance networks)
  • Snyk Blog / Security Research (watch Mini Shai-Hulud/TeamPCP follow-ups, registry-scale advisories, package-level vulnerability records, stale-maintainer npm scope compromises such as Mastra / easy-day-js, Composer/Packagist incident-response updates such as Laravel-Lang all-version compromise advisories, and AI-agent supply-chain boundary cases such as jqwik 1.10.0 maintainer prompt injection through build/test output, developer-environment MCP / skill inventory risk, and ToxicSkills-style public skill measurements)
  • Checkmarx Zero / Security Research (HTML watch; monitor malicious package and developer-supply-chain campaigns with package/version and infrastructure detail, including SuccessKey / ChainVeil and ViteVenom scoped npm impersonation, import-time execution, mixed clean/malicious releases, and Tron / Aptos / Binance Smart Chain C2 resolution)
  • JFrog Security Researchhttps://research.jfrog.com/ (HTML watch; monitor TeamPCP/Mini Shai-Hulud follow-ups, targeted NuGet business-logic manipulation such as Newtonsoftt.Json.Net using Harmony runtime patching and Seq-shaped exfiltration to rig Digitain betting results, PyPI import-time compromises such as Xinference and durabletask, optional-dependency GitHub-commit delivery, cloud/Kubernetes lateral-movement payload evolution, malicious developer/AI packages abusing platforms such as Hugging Face for CDN/exfiltration or prompt theft, cryptocurrency-developer package lures such as Solana FakeFix npm/PyPI patched-SDK packages, Injective SDK wallet-key theft follow-ups where runtime wrapper paths and X-Request-Id header exfiltration change scoping, GitHub issue spam, Telegram C2, fake MEV private-key prompts, and Deno loader persistence, PostCSS-themed npm impersonation such as postcss-minify-selector-parser / aes-decode-runner-pro leading to PowerShell and Nuitka Windows RATs, Rollup polyfill masquerading packages such as rollup-packages-polyfill-core / rollup-runtime-polyfill-core with JSONKeeper staging, browser/wallet theft, and Socket.IO / node-pty remote access, package-directory editor-task execution such as html-to-gutenberg / fetch-page-assets hiding VS Code folderOpen tasks behind fake font assets and blockchain dead drops, browser-side package-registry abuse such as Lucide Proxy student web proxies turning visitors into Wisp / WebSocket DDoS nodes, Miasma / @redhat-cloud-services follow-up indicators such as type-only package install hooks, GitHub commit-search C2, camouflage exfil destinations, and AI-scanner prompt-injection / refusal-evasion samples, plus IronWorm-style native Rust npm infostealers with eBPF rootkits, Tor C2, backdated GitHub commits, and trusted-publishing propagation; also monitor high-signal Linux/container-host vulnerability research such as DirtyClone / CVE-2026-43503 DirtyFrag-family local privilege escalation) and JFrog Blog RSS https://jfrog.com/blog/feed/ (watch npm v12 explicit-trust install controls such as allowScripts, --allow-git, and `--allow-remo... [truncated]
  • Unit 42 Research (watch recurring npm threat-landscape updates for Shai-Hulud/Mini Shai-Hulud wave metrics, SLSA/OIDC findings, containment-order warnings, cloud-identity tradecraft such as ROADtools / Entra ID abuse, cloud-control-plane defense-evasion research such as AWS CloudTrail / Google Cloud Logging route, destination, and KMS tampering, cross-cloud storage namespace risks such as bucket hijacking through deleted/recreated object-storage destinations, high-signal actor updates such as Screening Serpens / MiniUpdate / MiniJunk and CL-STA-1062 / UAT-7237 Southeast Asia government and critical-energy intrusions with TinyRCT, OT / industrial-control vulnerability research such as Siemens RUGGEDCOM ROX II CVE-2025-40948 / CVE-2025-40947 / CVE-2025-40949 chains from file disclosure to persistent root access, Miasma / Mini Shai-Hulud lineage updates such as AsyncAPI miasma-train-p1 AI/editor-driven runtime execution and canary-controlled propagation, collaboration-tool phishing / identity guidance such as Microsoft Teams external-chat abuse and federation hardening, large-scale credential campaigns such as FortiBleed cross-service password spraying against Fortinet / Sophos / MSSQL and configuration-theft feedback loops, cybercrime-economy updates that add durable TeamPCP / TGR-CRI-1135 monetization context such as LAPSUS$ / Vect extortion partnerships or public Shai-Hulud tooling claims, ransomware-economy and operational updates such as The Gentlemen / Storm-2697 / ArmCorp / Qilin affiliate-volume and affiliate-payout reporting, AI-agent skill supply-chain research such as Behavioral Integrity Verification for OpenClaw registry skills and ClawHub follow-ups covering unblocked macOS infostealer skills, scanner file-padding evasion, runtime affiliate injection, and agentic front-running, LLM-assisted malware engineering such as TuxBot v3 Evolution IoT botnet framework development, AI incident-response trend updates such as AI-compressed attack timelines, LLM/MCP-assisted C2, agentic ransomware, and cloud-AI token jacking, AI-hallucination supply-chain research such as Phantom Squatting where models invent domains that adversaries can pre-register for phishing, API/documentation poisoning, and autonomous-agent traffic capture, cloud-AI model lifecycle flaws such as Vertex AI default staging-bucket squatting / Pickle in the Middle, macOS malvertising/backdoor evolution such as CL-CRI-1089 Operation FlutterBridge / FlutterShell, and commodity stealer/miner campaigns with durable detection value such as Vidar / XMRig Factory-v3 malvertising, Go loader file inflation, fake Authenticode branding, MpClient.dll sideloading, and AMSI bypass tradecraft)
  • Elastic Security Labs and RSS (HTML/RSS watch for threat-intelligence and malware-analysis posts with concrete endpoint, cloud, and fraud-detection value, such as wp2shell host telemetry and lab validation covering web-stack-to-shell lineage, wp2shell_<hex> plugin staging, temp-write-test-* probes, PoC self-cleanup, and behavior-first detection; REF6045 / SCMBANKER Mexico-focused banking fraud using ClickFix fake-CAPTCHA delivery, validation.txt staging, bitsadmin / PowerShell retrieval, operator dashboards, clipboard account-number manipulation, vishing overlays, Remote Utilities escalation, exposed infrastructure, LLM-assisted tooling artifacts; developer-targeting DPRK / Contagious Interview updates such as REF9403 SVG-steganography coding-test projects that reassemble OTTERCOOKIE-aligned payloads through serverValidation.js; and new MaaS / modular malware writeups such as TELEPUZ spreading through ClickFix / VIDAR chains with Telegram, Steam, DNS, and Polygon fallback C2.)
  • Cisco Talos / Talos Intelligence Blog (HTML/RSS watch; monitor actor, malware, and network-device exploitation research with durable defender value, including China-nexus Operational Relay Box infrastructure such as UAT-7810 / LapDogs / LONGLEASH, router and embedded-device exploitation, secondary actor use of relay networks against critical infrastructure, and financially motivated workstation campaigns such as UAT-11795's Starland RAT / WLDR agent chain using ClickFix, trojanized installers, Python loaders, PowerShell memory C2, Telegram notifications, and Polygon fallback C2.)
  • Zscaler ThreatLabz (HTML watch for actor, campaign, malware, phishing, and network research with durable indicators and behavior, including East Asia-linked Middle East government targeting with TELESHIM Telegram C2, MIXEDKEY victim-bound environmental keying, BINDCLOAK, trusted-binary DLL side-loading, scheduled-task persistence, and captured post-compromise operator activity.)
  • Trend Micro Research (HTML watch; monitor active-exploitation, AI-augmented intrusion, developer-targeting malware, banking malware, and Ukraine/Russia-aligned updates such as Void Dokkaebi / Famous Chollima Cython-compiled InvisibleFerret and BeaverTail evolution, WinRAR CVE-2025-8088 reuse by Earth Dahu / Gamaredon and UAC-0226 / SHADOW-EARTH-066, GIFTEDCROOK evolution, managed-software patch blind spots, SHADOW-AETHER agentic-AI tunneling / lateral-movement campaigns in Latin America, Patriot Bait / bandcampro-style AI-operated disposable C2 infrastructure using Gemini CLI, plain-text skill files, Cloudflare tunnels, and PowerShell polling agents, PeopleSoft / PeopleTools exploitation chain analysis such as PSIGW-to-PSEMHUB SSRF, XMLDecoder restart-triggered execution, and in-JVM observability gaps, exposed-AI-application exploitation such as Langflow CVE-2026-33017 cryptominer / SSH-worm delivery, Banana RAT / SHADOW-WATER-063 Brazilian banking-fraud tooling with Pix QR interception and polymorphic PowerShell builds, and distinct post-exploitation chains sharing a common exploit entry point; also monitor autonomous-ransomware analysis such as JADEPUFFER follow-ups covering adaptive payload counts, self-correction speed, model-invented indicator caveats, and behavior-first detection)
  • FortiGuard Labs Threat Research (HTML watch; monitor active exploitation, IoT/Linux botnets, router and appliance malware, cross-platform propagation research such as the C0XMO Gafgyt variant exploiting DD-WRT CVE-2021-27137, and Shai-Hulud / TeamPCP consequence reporting such as external reuse of Jenkins instance-role credentials, AWS IAM escalation, Secrets Manager enumeration, Redshift data collection, and S3/SSM/SES staging; preserve FortiGuard's caveat where host forensics do not definitively tie the cloud intrusion to a specific poisoned package.)
  • ESET WeLiveSecurity / ESET Research (HTML/RSS watch; monitor actor campaigns, supply-chain attacks against regional software ecosystems, and new malware/tooling such as OceanLotus / APT32 FireAnt MetaKit supply-chain delivery of SPECTRALVIPER, FishMonger / SprySOCKS Windows variants with kernel-driver stealth, ScarCruft BirdCall Android, FrostyNeighbor/Ghostwriter PicassoLoader chains, GopherWhisper Go tooling, mobile MaaS/RAT reporting such as BTMOB, ransomware defense-impairment tooling such as The Gentlemen / GentleKiller EDR-killer framework and rapid BYOVD PoC adoption, and Ukraine/Russia espionage retrospectives such as Gamaredon 2025 tunnel/worker/dead-drop/cloud-storage exfiltration tradecraft and Gamaredon / Turla collaboration caveats)
  • Sekoia.io Threat Research (HTML watch; monitor Russia-linked espionage, Gamaredon/UAC-0010 malware chains, dead-drop resolver tradecraft, USB/network-share propagation, and durable malware-family taxonomy such as GammaPhish, GammaLoad, GammaWorm, and GammaSteel; also monitor joint YesWeHack / Sekoia vulnerability-researcher supply-chain reporting such as ChocoPoC fake PoC repositories, PyPI dependency trojanization, native-extension loaders, Python .pth persistence, and Mapbox dead-drop resolvers)
  • Seqrite Labs / APT Team (HTML watch; monitor targeted espionage and sector-focused malware writeups with concrete malware chains and infrastructure such as Operation DragonReturn India tax-season Ministry of Finance / Income Tax Department impersonation, DcRAT-style multi-stage loaders, MixedSvc Windows service persistence, background.jpg payload containers, China-nexus attribution caveats, Operation Dragon Weave, RUSTCLOAK, AZUREVEIL, Adaptix C2, Azure Blob Storage dead-drop C2, Czech Republic / Taiwan lures, Operation XENOFISCAL / SideCopy XenoRAT chains, Operation GriefLure Southeast Asia LNK / ftp.exe droppers, Thailand healthcare RAR / Rouki-obfuscated batch / Python-stealer campaigns, and attribution-confidence caveats)
  • Acronis Threat Research Unit (HTML watch; monitor actor/campaign/tool reporting with concrete malware chains and SaaS-abuse pivots, such as Mustang Panda India government / hydropower targeting with SHARDLOADER, MINIRECON, ZOHOMURK, Solid PDF Creator DLL sideloading, Zoho WorkDrive C2 and exfiltration, and CERT-In coordination)
  • Microsoft Security Bloghttps://www.microsoft.com/en-us/security/blog/ and https://www.microsoft.com/en-us/security/blog/feed/ (HTML/RSS watch; monitor actor/campaign/tool reporting such as ShinyHunters-associated SaaS OAuth abuse against Salesforce connected apps, Salesloft Drift / Gainsight / Klue-style trusted integrations, and misconfigured Experience Cloud guest access; email and collaboration threat-landscape updates such as Tycoon2FA post-disruption measurements, Teams vishing growth, automated Amazon SES BEC, and nested-EML / ICS / Microsoft-authentication-redirect malware delivery; AI-chatbot/search-poisoned utility downloads; AI-brand impersonation phishing, malvertising, and browser-extension search interception; ClickFix-led infostealer chains such as ACR Stealer WebDAV / Python / EtherHiding and MSHTA / steganographic JPEG payload delivery; ScreenConnect abuse; SimpleRunPE / RuntimeHost GPU cryptojacking; edge-appliance intrusion chains; ransomware and destructive tooling such as Storm-2697 / The Gentlemen and GigaWiper; parallel-intrusion case studies such as Storm-2603 SharePoint-focused ransomware activity; StealC / Amadey disruption reporting; Crypto Clipper USB / .lnk worming; hospitality phishing and Node.js implants; Claude Code GitHub Action / AI-agent CI/CD trust-boundary cases; AutoJack-style local agent / localhost control-plane RCE; agent-memory poisoning defenses; MCP / acting-agent supply-chain trust boundaries; and npm supply-chain campaigns such as AsyncAPI miasma-train-p1 pwn-request / import-time execution, Miasma / Red Hat trusted-publishing abuse, Mastra / easy-day-js, vpmdhaj, and oob.moika.tech dependency-confusion clusters)
  • Microsoft Edge Vulnerability Research / Edge Extensions Security Team (HTML watch; monitor browser-extension ecosystem compromise and Edge Add-ons response writeups such as StegoAd, where malicious extensions hid JavaScript in PNG/WebP/WOFF2 assets, delayed execution, used server-side validation, stole Google / WordPress credentials and cookies, and monetized through ad fraud / affiliate hijacking)
  • Broadcom / Symantec Threat Intelligence (HTML watch; monitor incident-response-backed actor tradecraft such as Seedworm / MuddyWater Node.js-orchestrated PowerShell, signed-binary DLL sideloading, ChromElevator browser theft, Deno/Python backdoors such as Dindoor and Fakeset, Rclone-to-Wasabi exfiltration, Backblaze staging, and public file-transfer exfiltration, cybercrime access-broker tooling such as Backdoor.Mistic / MLTBackdoor, Woodgnat / KongTuke, ModeloRAT, ClickFix delivery, MpExtMs.exe / EndpointDlp.dll sideloading, and Qilin-linked ransomware access; ransomware / BYOVD chains such as GodDamn / Beast / Monster / Hyadina using PoisonX signed-driver defense evasion, AnyDesk, PsExec, NirSoft tooling, and Mimikatz; plus high-consequence tool research such as Fast16 LS-DYNA / AUTODYN nuclear-simulation sabotage)
  • Group-IB Threat Intelligence (HTML watch for actor, malware, identity, cloud, and espionage research with concrete telemetry and detection artifacts, such as HOLLOWGRAPH abuse of Microsoft 365 calendar events and Graph application permissions for C2 and exfiltration, AAAA-record credential refresh, Cavern framework linkage, and attribution-confidence caveats.)
  • WatchGuard Secplicity / Threat Lab (HTML watch; monitor regional malware and fraud operations such as Grandoreiro campaigns using DLL sideloading, WebRTC/STUN/ICE communications camouflage, cloud-service abuse, and anti-analysis checks)
  • LevelBlue SpiderLabs (HTML watch; monitor malware/tooling research with durable cross-platform defender value, such as QuimaRAT Java RAT MaaS analysis covering Windows / Linux / macOS persistence, Netty C2, plugin loading, fileless execution, and concrete IOC sets)
  • Zimperium zLabs (HTML watch; monitor mobile malware, Android banking trojans, mobile MaaS, smishing, and device-fraud tradecraft such as RedWing / Rokarolla Telegram-sold Android banking malware with fake app-store sideloading, Accessibility abuse, overlay credential theft, SMS / notification interception, VNC control, call-forwarding abuse, and DDoS capability)
  • Arctic Wolf Labs (HTML watch; monitor incident-response-backed exploitation, identity-first phishing, and malware-delivery reporting such as Kali365 OAuth device-code PhaaS expansion across Microsoft / Okta / Xerox / MAX Messenger lures, FortiClient EMS CVE-2026-35616 abuse to push EKZ Infostealer through endpoint-management policy and fake Fortinet patch workflows, PAN-OS GlobalProtect CVE-2026-0257 follow-on intrusion detail such as unauthorized VPN tunnels followed by Impacket-style SMB / NTLM reconnaissance, and ransomware-affiliate tradecraft such as Anubis intrusions using CitrixBleed 2 / CVE-2025-5777, valid VPN credentials, RMM tools, cloudflared, authenticated proxies, SSH SOCKS tunnels, and backup/NAS targeting)
  • Rapid7 Labs / Threat Research (HTML/RSS watch; monitor incident-response-backed active campaigns, exposed attacker infrastructure, malware-delivery tooling, and vulnerability exploitation with concrete detection and IOC artifacts, such as Check Point SmartConsole CVE-2026-16232 exploitation updates that add companion CVE-2026-62144 / CVE-2026-62145 remediation scope and revised IP indicators, the exposed Simba Service WebDAV malware-delivery lab, Mexico-focused CURP search-ms campaign, CVE-2025-33053 working-directory-hijack test matrices, LLM-assisted lure QA, RTLO filename spoofing, and PureRAT delivery chains)
  • Blackpoint Cyber (HTML watch; monitor incident-response-backed RMM, identity, loader, ransomware, RAT, and infostealer intrusion chains such as SimpleHelp CVE-2026-48558 exploitation leading to TaskWeaver Node.js loader deployment and Djinn Stealer collection of cloud, source-control, package-registry, AI-assistant, SSH, browser, and wallet secrets, LabubaRAT-style Rust Windows RATs masquerading as NVIDIA runtime software with runtime C2 configuration, SQLite state, HTTPS / WebView2 / DNS-tunneling channels, and SOCKS5 proxying, plus Avalon / CrownX-style legal-lure ISO/LNK/MSBuild malware frameworks that combine credential theft, EDR-aware evasion, recovery disruption, and ransomware)
  • Ransom-ISAC (HTML watch for public ransomware and data-extortion case studies with negotiation transcripts, payment-flow analysis, actor-brand caveats, and public-sector defender lessons such as Kairos data-only extortion where no encryptor/locker sample was verified)
  • eSentire TRU advisories (HTML watch; monitor incident-response-backed active-exploitation advisories and edge-appliance exploitation telemetry such as Progress Kemp LoadMaster CVE-2026-8037 attempts, FortiBleed credential exposure, and concrete IOC / affected-version updates)
  • Kaspersky Securelist (HTML/RSS watch; monitor supply-chain compromises, signed-binary backdoors, RAT tooling, Windows exploitation writeups such as MiniPlasma Cloud Filter / CVE-2020-17103-adjacent LPE detection, and incident-response reports such as DAEMON Tools Lite CVE-2026-8398 with typosquatted C2, selective backdoor deployment, and QUIC RAT activity; trusted-software loading-path campaigns such as HelloNet using ViPNet update-component DLL sideloading, HelloInjector / HelloProxy / HelloBackdoor, reverse SSH tunnels, and low-confidence attribution caveats; Southeast Asia espionage toolchains such as GoSerpent, McMx, ThumbcacheService, Stowaway, and TmcLoader/TmcPayload delayed network-share exfiltration; Cloud Atlas updates such as PowerCloud, PowerShower, VBCloud, reverse SSH / ReverseSocks / Tor backup-channel use, and Russia/Belarus government targeting; North Korea/Kimsuky tooling evolution such as PebbleDash / AppleSeed, HelloDoor, HttpMalice, VS Code tunneling, DWAgent, and Cloudflare Quick Tunnel abuse; identity-phishing tradecraft such as Microsoft Identity Platform / OAuth device-code phishing where law-firm PDF lures, CAPTCHA-gated fake legal portals, clipboard-copied user_code values, and legitimate MFA flows lead to mailbox, OneDrive, and Teams token abuse; messaging-app malware such as WhatsApp-delivered VBScript chains that install ManageEngine Endpoint Central / RMM agents; ToddyCat / Umbrij Gmail OAuth abuse through headless Chromium remote debugging and STRD-style browser-session token acquisition; Armored Likho / BusySnake Stealer activity with AI-looking loaders, GitHub-hosted Python/PyArmor staging, WindowsHelper scheduled-task persistence, browser credential and cookie theft, and reverse SSH tunneling; ScreenConnect / RMM abuse campaigns such as freeware-impersonation SEO poisoning that silently installs ScreenConnect and deploys AsyncRAT through install.res.1033.dll, Defender exclusions, RegAsm process hollowing, and scheduled-task persistence; SharkLoader / StrikeShark-style Cobalt Strike loader campaigns using edge exploitation, custom droppers, DLL sideloading, and scheduled-task persistence; cryptocurrency-wallet malware frameworks such as OkoBot / TookPS / SeedHunter, where process injection into Trezor Suite / Ledger Wallet / Ledger Live and USB-gated prompts collect seed phrases from inside legitimate wallet applications; and durable cybercrime malware campaigns such as piracy-site fake-update SilentCryptoMiner / RAT delivery)
  • Jamf Threat Labs (HTML watch; monitor macOS malware, AppleScript/JXA delivery, MDM/endpoint-security tradecraft, notarized-dropper infostealers such as CrashStealer / Werkbit PIN-gated delivery, and infostealer research such as PamStealer's fake Maccy distribution, Rust Mach-O second stage, PAM-validated credential capture, login-item persistence, Finder / Software Update masquerading, Full Disk Access social engineering, and blockchain-RPC configuration pivots)
  • WithSecure Labs (HTML watch; monitor Russia-nexus, Ukraine-focused, and AI-assisted campaigns such as GREYVIBE / PhantomMail / PhantomClick / PrincessClub with PhantomRelay, FallSpy, LegionRelay, DAYLIGHT, TEASOUP, and cybercrime-overlap attribution notes)
  • Proofpoint Threat Insight (HTML watch; monitor email-threat and actor-cluster reporting such as TA4922 Chinese-speaking cybercrime expansion, localized HR/payroll/tax/invoice lures, ValleyRAT / Winos4.0, Atlas RAT, RomulusLoader, SilentRunLoader, Silver Fox / Void Arachne overlap caveats, and DPRK/developer-targeting repository-phishing clusters such as UNK_DeadDrop using GitHub/GitLab lures, VS Code / Cursor folderOpen tasks, malicious VSIX persistence, Overlord payloads, and cryptocurrency-wallet theft, and academic / mailserver exploitation clusters such as UNK_MassTraction Roundcube CVE-2024-42009 to CVE-2025-49113 chains using IceCube, SquareShell, SNOWLIGHT, and VShell)
  • ReliaQuest Threat Research (HTML watch; monitor incident-response-backed cluster and intrusion reporting such as OP-512 IIS web-shell espionage, cryptographically gated ASP.NET handlers, self-reporting DNS C2, and legacy .NET / IIS behavioral detections)
  • Volexity Threat Research (HTML watch; monitor incident-response-backed actor and appliance coverage such as VerdantBamboo / WARP PANDA / UNC5221 BRICKSTORM operations on Egnyte Storage Sync, pfSense, Synology NAS, MSP, Linux, FreeBSD, and other low-EDR management-plane systems; also monitor zero-day edge-appliance investigations such as UTA0533 chaining SonicWall SMA1000 CVE-2026-15409 / CVE-2026-15410, KNUCKLEBALL JVM injection, ROOTRUN, ORANGETAIL, Suo5, LDAP credential capture, and volatile-evidence guidance)
  • Sygnia research (HTML watch; monitor incident-response-backed China-nexus and infrastructure-persistence reporting such as Velvet Ant / Operation Highland authentication-stack backdoors, F5 BIG-IP abuse, Cisco Nexus CVE-2024-20399 / VELVETSHELL, PAM / OpenSSH tampering, segmented-network intrusion paths, and crypto supply-chain containment lessons such as developer endpoint → repo/CI → automation identity → Kubernetes/runtime → secrets → custody/transaction authority chains)
  • Gambit Security research (HTML watch; monitor recovery-denial and destructive-operation reporting such as Ababil of Minab / MOIS-linked backup, virtualization, and storage destruction campaigns)
  • Infoblox Threat Intel (HTML watch; monitor DNS-scale fraud, phishing, scam-infrastructure, malicious-domain clustering, and framework/template abuse such as DCloud Uni-App scam infrastructure where legitimate web/app scaffolding supports fake crypto exchanges, pig-butchering flows, WhatsApp phishing, scambling/fake gambling, brand impersonation, and wallet drainers.)
  • Hunt.io research (HTML watch; monitor exposed attacker-infrastructure recoveries, C2/toolkit leaks, cloud-abuse operations, provider/ASN-level malicious-infrastructure concentration reports such as the Middle East 1,350+ C2 / 98-provider Host Radar analysis and Eastern Europe 3,900+ C2 / 302-provider Host Radar analysis, phishing/smishing infrastructure such as the 19-country government / postal / telecom campaign with 1,628 URLs and a reusable 128-character page hash or GHOST STADIUM FIFA World Cup ticketing clones with reusable /fifa/ / Layui / same-origin credential-harvest pivots, managed-service / endpoint-management compromise blast-radius cases such as Quest KACE SMA CVE-2025-32975 exposed-toolkit reporting, Iranian-nexus exposed-C2 and staging operations such as Oman government webshell / Chisel / DotNetNuke targeting or Ababil of Minab exposed Python SimpleHTTP / Flask staging with LA Metro database-backup material, exposed DDoS-for-hire / IoT botnet operations such as xlabs_v1 ADB-on-TCP/5555 infection, Speedtest bandwidth tiering, and TCP/26721 fallback re-entry, TeamPCP Python toolkit / FIRESCALE fallback reporting, PCPJack-style proxy / SMTP relay infrastructure analysis, high-blast-radius npm compromise payload analysis such as Axios / plain-crypto-js cross-platform RAT delivery with TA444 / BlueNoroff infrastructure overlaps, and agentic-AI intrusion operations such as suspected China-linked Claude Code / DeepSeek-v4-pro use alongside TencShell, Gshell, ARL, DeepAudit, Vshell, open directories, government exploitation, and financial-services targeting)
  • SentinelOne SentinelLABS (HTML/RSS watch; monitor crimeware, cloud-worm, DPRK, ransomware, macOS malware, and actor/tool reporting such as PCPJack credential theft, exposed cloud service propagation, Sliver payloads, TeamPCP-adjacent artifact removal, analyst-targeting AI anti-analysis such as macOS.Gaslight Rust implants with Telegram C2, LaunchAgent persistence, keychain/browser theft, and prompt-injection payloads aimed at LLM-assisted triage, regional espionage convergence reporting such as suspected China- and India-nexus PlugX / ShadowPad / Cobalt Strike / Remcos activity against Pakistani law enforcement and Balochistan Police CMS implant hosting, and Iran-linked strategic assessments that distinguish access optionality, persona operations, service-provider/RMM paths, and evidence-backed OT effects from inflated public claims)
  • Sysdig Threat Research (HTML watch; monitor cloud-native, container, AI-workflow, DevOps platform, and post-exploitation reporting such as Gitea Docker CVE-2026-20896 reverse-proxy trusted-proxy wildcard probing, marimo CVE-2026-39987 LLM-agent post-exploitation, PraisonAI CVE-2026-44338 same-day endpoint validation, JADEPUFFER-style Langflow CVE-2025-3248 agentic ransomware / database-extortion operations and ENCFORGE AI-model ransomware using Docker-socket host escape, Cloudflare Workers egress fan-out, AWS Secrets Manager pivots, database theft from AI/notebook runtimes, and NATS-as-C2 / KeyHunter credential-harvesting worker infrastructure targeting AWS, AI keys, and code-sandbox secrets)
  • Securonix Threat Labs (HTML watch; monitor multi-stage malware delivery, infostealer, and living-off-the-land chains with concrete loader and detection detail, such as VEIL#DROP Blogger / Blogspot-hosted PowerShell loaders that deploy PureLogs Stealer through fake PDF JavaScript lures, dynamic URL mutation, reflective .NET loading, and signed Microsoft LOLBin fallbacks)
  • Permiso Security / P0 Labs (HTML watch; monitor AI identity, assistant-rendering, and indirect-prompt-injection research such as ChatGPhish page-summarization phishing through live Markdown links, auto-fetched images, spoofed alerts, and QR-code pivots)
  • Stripe OLT Threat Research (HTML watch for browser-extension, identity, and incident-response research with concrete detection artifacts, such as ModHeader signed-store builds with dormant browsing-history exfiltration capability, stanfordstudies.com / extensions-hub.com infrastructure, and extension-ID hunts.)
  • LayerX Security research (HTML watch for browser, SaaS, AI-browser, and indirect-prompt-injection research such as BioShocking, where malicious page/game context can steer agentic browsers and browser plugins into authenticated-site credential or data access)
  • Manifold Security research (HTML watch for AI-agent, browser-agent, MCP, and extension trust-boundary research such as ClaudeBleed Reopened / Claude for Chrome cross-extension steering, where another extension with claude.ai content-script access can coerce browser-agent reads of Gmail, Google Docs, and Calendar, especially when autonomous modes are enabled)
  • ANY.RUN Cybersecurity Blog (HTML watch for sandbox-backed phishing-kit, malware-family, and infrastructure research with repeatable detection pivots such as Kratos Microsoft 365 PhaaS asset pairs, exfiltration endpoints, page-generation changes, victimology, and co-hosting attribution caveats)
  • Mindgard research (HTML watch for AI developer-tool vulnerability disclosures and agent / IDE trust-boundary issues, such as Cursor Windows workspace-path binary hijack where a repository-root git.exe can execute when Cursor opens a project)
  • Tenet Security Threat Labs (HTML watch for AI-agent runtime and MCP trust-boundary research such as Sentry Agentjacking, where public observability events can inject fake remediation instructions that coding agents execute through package-manager or shell tools)
  • Noma Security / Noma Labs (HTML watch for agentic AI security research such as GitLost, where public GitHub issue text can indirectly prompt GitHub Agentic Workflows into reading private repositories and publishing results back to public issue comments)
  • SAND Security research (HTML watch for AI platform and sandbox-isolation research such as WriteOut, where Writer AI live previews forwarded user session cookies into attacker-controlled sandboxes before the vendor fix)
  • AIR Security research (HTML watch for AI-agent skill, MCP, plugin, and marketplace-abuse research such as mutable external-document skill swaps where clean submitted skills later fetch changed instructions from attacker-controlled product-adjacent domains)
  • Adversa AI research (HTML watch for AI-agent and coding-agent trust-boundary research such as GuardFall shell-guard bypasses, TrustFall prompt-to-command execution paths, and deny-rule bypasses where agent safety gates inspect different text than the shell or tool runtime executes)
  • AI Now Institute (HTML watch for AI-enabled cyber-defense risk research with concrete agent-runtime exploit paths, such as Friendly Fire repository-source prompt injection that steers Claude Code / Codex security-review modes into executing repository-local binaries)
  • Google Cloud / Mandiant Threat Intelligence (HTML/RSS watch; monitor incident-response-backed actor/campaign/tooling, exploited-product writeups such as KnowledgeDeliver CVE-2026-5426 ViewState deserialization, BLUEBEAM / Godzilla, Cobalt Strike follow-on activity, Oracle PeopleSoft CVE-2026-35273 zero-day exploitation by UNC6240 / ShinyHunters, GTIG AI Threat Tracker reporting on AI-assisted vulnerability exploitation, autonomous malware, obfuscated model access, TeamPCP / UNC6780 AI-environment supply-chain abuse, UNC6692 / SNOW malware social-engineering chains using Teams, browser-extension persistence, tunnels, and LSASS theft, PRC-nexus research-sector espionage such as UNC6508 REDCap / INFINITERED / mail content-compliance rule abuse against medical, academic, and military research organizations, Turla / Secret Blizzard tooling such as STOCKSTAY .NET WebSocket backdoors, KAZUAR overlap, K1MORPHER obfuscation, malicious GPO / RDP-file phishing deployment, and Ukrainian / foreign-policy targeting, criminal-market ecosystem reporting such as Chinese-language PhaaS real-time OTP interception / wallet-tokenization tradecraft, BlackFile / UNC6671 vishing extortion, UNC3753 / Luna Moth law-firm vishing with RMM and physical-impersonation pivots, AiTM SSO compromise, and SaaS data theft, plus residential-proxy / botnet disruption reporting such as NetNut / Popa with Google-account C2 disablement, Play Protect SDK enforcement, reseller-capacity migration, and threat-cluster abuse metrics)
  • Datadog Security Labs (HTML watch for cloud, SaaS, source-control, and detection-engineering research with durable defender pivots, such as coordinated GitHub API enumeration through dormant / ghost accounts, compromised OAuth tokens and PATs, and private-repository clone escalation.)
  • Hugging Face security and engineering posts (HTML/GitHub watch for model-hub, dataset-processing, inference, artifact-integrity, token, and platform-incident disclosures such as the July 2026 autonomous-agent production intrusion through remote-code dataset loading and dataset-configuration template injection, followed by node access, cloud/cluster credential theft, and cross-cluster lateral movement; monitor the joint OpenAI investigation for customer/partner scope, indicators, and reconciliation of the initial-access descriptions.)
  • OpenAI safety and security disclosures (HTML watch for cyber-capable model evaluation incidents, long-horizon autonomy, sandbox escapes, third-party impact, and containment changes such as OpenAI's July 2026 self-attribution of the Hugging Face intrusion to GPT-5.6 Sol and a pre-release model running ExploitGym with reduced cyber refusals.)
  • Google safety / affirmative litigationhttps://blog.google/innovation-and-ai/technology/safety-security/ and https://affirmativelitigation.withgoogle.com/ (HTML watch for Google-filed abuse-disruption cases, AI-enabled scam operations, smishing / PhaaS infrastructure such as Outsider Enterprise, and law-enforcement or carrier-coordination details that add durable defender pivots)
  • GitHub Security Blog / Changeloghttps://github.blog/security/ and https://github.blog/changelog/ (HTML watch for GitHub platform incident notes, postmortems, incident-response controls such as enterprise self-service credential revocation, and supply-chain security-default changes such as npm v12 script approval / allowScripts, --allow-git, and --allow-remote defaults and Dependabot's default three-day cooldown for non-security version updates, plus GitHub Actions trust-boundary hardening such as actions/checkout pwn-request refusal in pull_request_target / workflow_run contexts and workflow execution protections that restrict allowed triggering actors and events; also monitor source-repository provenance research affecting GitHub trust indicators, such as Git hash chain malleability / verified-commit ambiguity)
  • Huntress incident posts (HTML watch for transparent customer-side incident reports and SaaS / identity supply-chain lessons such as Klue OAuth token abuse impacting Salesforce-connected customer environments, Azure CLI / Microsoft Entra ID password-spray campaigns abusing ROPC and Conditional Access policy gaps such as LSHIY / AS32167 activity, and identity telemetry pivots that separate high-volume spray noise from confirmed credential validity)
  • ZeroBEC research (HTML watch for identity, phishing, RMM abuse, and cloud-post-exploitation reporting with concrete Microsoft 365 / Entra and endpoint pivots such as Forg365 Telegram-distributed PhaaS, O-UNC-066 Entra passkey enrollment vishing / attacker-controlled FIDO2 registration tradecraft, DEBULL device-code phishing, Microsoft Authentication Broker token brokering, exposed PhaaS panels, GraphSpy / Microsoft Graph post-authentication artifacts, and Operation BlueDash workplace-app lures that use fake Microsoft Store pages, hidden PowerShell or JScript, and attacker-controlled Level RMM, ScreenConnect, and Tactical RMM enrollment)
  • Lexfo CTI / research (HTML watch for exposed attacker-infrastructure, phishing-kit, and identity-abuse investigations with concrete Microsoft 365 defender pivots such as Evilginx forks, OAuth device-code flow abuse, token auto-refresh, open-directory operational leaks, RMM/tooling exposure, and PhaaS supplier relationships)
  • Google Chrome Releases (HTML/RSS watch for actively exploited Chrome / Chromium client-side zero-days such as V8 CVE-2026-11645 and rollout details for fixed stable builds)
  • Island Security Research (HTML watch for browser-extension and enterprise-browser trust-boundary research such as BadBlocker / Adblock for YouTube remote-script injection risk, and developer/AI-capability discovery attacks such as FakeGit / AgentBaiting, where lookalike GitHub profiles, copied repositories, attacker-authored READMEs, public Skill/MCP registry listings, malicious ZIPs, renamed LuaJIT runtimes, SmartLoader, and StealC turn agent-assisted software discovery into credential and session theft)
  • McAfee Labs (HTML watch for commodity malware, browser-extension, and cryptocurrency-theft campaigns such as Silent Swap / Google Notes crypto clippers that combine unsigned installers, Chromium profile tampering, clipboard address replacement, and EtherHiding blockchain C2/dead-drop resolution)
  • Check Point Research / advisorieshttps://research.checkpoint.com/, https://blog.checkpoint.com/security/, and https://support.checkpoint.com/ (HTML watch for active edge, VPN, firewall, and ransomware-affiliate exploitation reporting such as Remote Access VPN / Mobile Access CVE-2026-50751 IKEv1 authentication bypass and companion SK hotfix guidance; Iran-linked actor/tool reporting such as Cavern Manticore / Cavern modular .NET C2 framework activity against Israeli government and IT-provider targets; AI-agent framework research such as LangGraph checkpointer injection / unsafe deserialization chains; and social-proof / reputation-manipulation malware distribution such as fake GitHub / SourceForge / YouTube / VirusTotal engagement around cryptocurrency clipboard hijackers)
  • Ammar Askar security research (HTML watch for developer-tooling, VS Code, GitHub.dev, and source-control token-boundary research such as browser IDE OAuth token theft)
  • GMO Flatt Security Research (HTML watch for AI-agent, Claude Code, GitHub Actions, and repository-permission boundary research such as Claude Code GitHub Action prompt-injection and workflow takeover paths)
  • The Hacker News (monitor active-exploitation reports and secondary pointers to primary actor/tool research that add concrete affected-version, exploit-status, or response guidance, such as Fastjson CVE-2026-16723 exploitation-attempt reconciliation across Alibaba, FearsOff, ThreatBook, Imperva, NVD, and CISA KEV; Hugging Face's July 2026 autonomous-agent production-intrusion disclosure; Januscape KVM/x86 CVE-2026-53359 guest-to-host escape public PoC coverage; NGINX CVE-2026-42533 two-pass regex-capture clobbering and researcher-claimed ASLR-bypass RCE analysis; LiteSpeed/cPanel CVE-2026-48172; Cisco Catalyst SD-WAN Manager CVE-2026-20245; Cisco Unified CM CVE-2026-20230 WebDialer-gated file-write exploitation; Oracle E-Business Suite CVE-2026-46817 Oracle Payments exploitation telemetry; Lazarus RemotePE coverage; Malware-Slop / Claude user-data npm infostealer pointers to OX Security; WithSecure GREYVIBE pointers; Sysdig marimo LLM-agent post-exploitation pointers; Permiso ChatGPhish AI-summary phishing pointers; ClickFix payload-as-a-service / API-driven delivery analysis pointers; public exploit / kernel-patch pivots such as Bad Epoll CVE-2026-46242; and cross-source campaign roundups such as Grandoreiro / BTMOB)
  • Wordfence vulnerability intelligencehttps://www.wordfence.com/threat-intel/vulnerabilities and https://www.wordfence.com/blog/category/vulnerabilities/ (HTML watch; monitor WP-SHELLSTORM-style webshell access brokerage across WordPress/Joomla plugin CVEs, active WordPress plugin exploitation with concrete affected versions, exploit telemetry, and mitigation details such as WP Maps Pro CVE-2026-8732 administrator-account creation, Everest Forms Pro CVE-2026-3300 calculation-field RCE, and Gravity SMTP CVE-2026-4020 email-provider API-key exposure)
  • Fox-IT / NCC Group research blog (HTML watch; monitor incident-response-backed actor/tool research such as Lazarus RemotePE, DPAPI/environmental-keying loaders, and memory-only RAT tradecraft)
  • Boost Security Labs (watch CI/CD supply-chain techniques such as deployment poisoning, TeamPCP follow-ups, GitHub Actions OIDC trust-boundary research such as Sleeper Squats subject-claim delimiter collisions, and trusted-publishing/provenance trust-boundary analysis such as the Miasma / Red Hat throwaway-branch OIDC publication path)
  • Novee Security (HTML watch; monitor CI/CD workflow-composition research such as Cordyceps, where untrusted pull-request comments, branch names, artifacts, or metadata cross into privileged GitHub Actions automation with secrets or write tokens)
  • watchTowr Labs (HTML watch for fast edge-appliance, security-platform, and enterprise-web-platform exploit analysis plus detection artifacts, such as Ivanti Sentry CVE-2026-10520 / CVE-2026-10523 pre-auth command-injection and authentication-bypass research, Splunk Enterprise CVE-2026-20253 PostgreSQL Sidecar Service pre-auth file-write-to-RCE analysis, Progress Kemp LoadMaster CVE-2026-8037 API-enabled pre-auth RCE / uninitialized-heap command-injection analysis, Citrix NetScaler CVE-2026-8451 CitrixBleed-class SAML IdP memory-overread validation, and Adobe ColdFusion APSB26-68 CVE-bonanza follow-ups covering CFIDE / FILEIO arbitrary file read-write and path-traversal primitives)
  • StepSecurity blog (watch compromised scientific and research packages such as mrmustard==0.7.4, source-artifact-only PyPI injection, maintainer-account takeover, CI publishing-token theft, self-hosted-runner reconnaissance, import-time credential collection, and cron / .pth / shell persistence; Mini Shai-Hulud / Nx Console follow-ups, Miasma-style @redhat-cloud-services, Leo Platform, and internal-developer-platform package compromises such as Immobiliare Labs Backstage plugins, CI/CD workflow-backdoor campaigns such as Megalodon, GitHub Actions tag-retargeting compromises such as codfish/semantic-release-action and simonecorsi/mawesome, JINX-0164-adjacent package compromises such as Velora DEX SDK / MINIRAT, npm native-addon build-path execution such as binding.gyp CI/CD worms, AI-assistant/editor repository reinfections such as Azure/durabletask, source-repository force-push compromises such as Pythagora-io/gpt-pilot, stale-maintainer npm scope compromises such as Mastra / easy-day-js, RubyGems dormant-maintainer compromises such as SleeperGem / git_credential_manager / Dendreo / fastlane-plugin-run_tests_firebase_testlab with CI evasion and developer-host persistence, IDE marketplace credential theft such as malicious JetBrains AI plugins stealing OpenAI / DeepSeek / SiliconFlow API keys, developer-machine package-manager configuration drift such as npm / Python registry, cooldown, and auth policy checks, downstream GitHub Actions availability impacts such as Azure/functions-action repository disablement, Composer/GitHub tag-rewrite incidents such as Laravel-Lang, AsyncAPI generator / spec-json-schemas release-workflow compromises with valid npm OIDC provenance, runtime require()-triggered Miasma payloads, IPFS sync.js staging, and Hades-style PyPI import-hook waves with graph-ML / bioinformatics package compromise, LLM-analysis prompt-injection evasion, cross-platform runner-memory scraping, SSH/SCP lateral movement, wiper-deterrent persistence, developer-machine suspicious-file detection pivots such as binding.gyp, injected __init__.py, .vscode/tasks.json, and .claude/setup.mjs, and trusted developer-tool npm compromises such as jscrambler@8.14.0 preinstall native-binary stealers with browser credential / wallet theft and eBPF capability)
  • Trail of Bits blog (watch AI-agent skill distribution and scanner-bypass research such as public marketplace poisoning, ClawHub / skills.sh / Cisco skill-scanner bypasses, bytecode/document indirection, prompt-injection framing, and broader AI/ML supply-chain hardening; cross-check OpenClaw-family advisories and independent writeups for chat-to-host / Gateway execution boundary flaws such as WhatsApp-to-host chains, GHSA-hjr6-g723-hmfm, GHSA-9969-8g9h-rxwm, and GHSA-575v-8hfq-m3mc)
  • arXiv agentic-security papers (HTML watch; promote only papers with immediate defender value for AI-agent, coding-agent, MCP, skill, and autonomous-workflow security, such as SkillCloak / SkillDetonate measurements of agent-skill scanner evasion and runtime detonation, or HalluSquatting / agentic-botnet research where predictable hallucinated repositories or skills create an indirect prompt-injection path to tool execution)
  • CleverHans Lab (HTML/arXiv watch for adversarial-ML and agentic-security research with operational defender value, such as adaptive computer worms using local open-weight LLMs on compromised hosts)
  • PortSwigger Research
  • depthfirst research (HTML watch for memory-safety, parser, dependency, and developer-platform vulnerability research with operational defender value, including the GitLab Oj notebook-diff chain where authenticated project members can combine a heap-pointer disclosure and out-of-bounds write for command execution as git; monitor CVE assignment, exploit portability, GitLab advisory changes, fixed-version guidance, and any confirmed exploitation.)
  • ProjectDiscovery blog (watch active-exploitation research and cyber-agent evaluation lessons such as Oh My Rogue Agent, including unintended environment-variable, filesystem, local-network, tracing-service, cross-challenge SSRF, mounted-secret, Unix-socket, and public-benchmark-source pivots plus hard isolation, trajectory review, turn, cost, and time controls)
  • runZero Research (HTML watch for exposure-management and IT/OT/IoT vulnerability research with durable defender value, such as FatFs CVE-2026-6682 through CVE-2026-6688 embedded-filesystem flaws affecting removable-media and firmware-update paths across Espressif ESP-IDF, STM32Cube, Zephyr RTOS, MicroPython, ArduPilot, RT-Thread, Mbed, Samsung TizenRT, SWUpdate, and downstream IoT/OT products.)
  • Synacktiv publications (HTML watch for offensive research with durable defender impact, especially CI/CD, Kubernetes, cloud, and supply-chain control-plane flaws such as unpatched Argo CD repo-server gRPC / Redis reachability leading to unauthenticated code execution and arbitrary Kubernetes manifest deployment.)
  • CISA KEV / alertshttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json and https://www.cisa.gov/news-events/cybersecurity-advisories (promote entries and alerts when they add active exploitation evidence, actor linkage, or high-impact platform exposure such as FortiOS SSL-VPN CVE-2025-68686 post-compromise symlink-persistence bypass and configuration exposure, Check Point SmartConsole CVE-2026-16232 application-token authentication bypass, Microsoft SharePoint CVE-2026-50522 deserialization RCE, WordPress wp2shell CVE-2026-63030 / CVE-2026-60137, Langflow pre-authentication RCE CVE-2026-0770, C0XMO-linked DD-WRT CVE-2021-27137, Cisco IOS 12.4 CVE-2008-4128 CSRF command-execution exposure, Langflow CVE-2025-34291 and CVE-2026-55255, Joomla extension upload-to-code-execution flaws CVE-2026-48908, CVE-2026-56290, CVE-2026-56291, and CVE-2026-48939, Adobe ColdFusion CVE-2026-48282, PAN-OS GlobalProtect CVE-2026-0257, managed-file-transfer availability attacks such as SolarWinds Serv-U CVE-2026-28318, Magento / Adobe Commerce extension RCE such as Mirasvit Cache Warmer CVE-2026-45247, credential-exposure activity against edge/VPN devices such as FortiBleed, enterprise application RCE such as Oracle E-Business Suite CVE-2026-46817 and PTC Windchill / FlexPLM CVE-2026-12569, remote-support/RMM authentication bypass such as SimpleHelp CVE-2026-48558, identity/collaboration and edge-appliance KEV additions such as Microsoft ADFS CVE-2026-56155, Microsoft SharePoint CVE-2026-56164, and SonicWall SMA1000 CVE-2026-15409 / CVE-2026-15410, building-automation / OT device-lockout exposure such as KNX Protocol CVE-2023-4346, or edge / ICS / enterprise-application command-execution exposure such as UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910, Lantronix EDS5000 CVE-2025-67038, and Microsoft SharePoint CVE-2026-45659)
  • CISA joint Zimbra advisory AA26-204Ahttps://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a (July 23, 2026 priority follow-up; monitor Russian state-supported LAUNDRY BEAR / Void Blizzard / CL-STA-1114 / TA488 use of Ulej and the Flowerbed collection framework, Zimbra CVE-2025-66376 victim scope, browser localStorage and mailbox-log artifacts, infrastructure and certificate rotation, STIX revisions, and actor-label reconciliation)
  • CERT/CC Vulnerability Notes (HTML/RSS/API watch for high-impact vulnerability notes with durable defender value, especially edge-device, router, appliance, and supply-chain flaws where vendor coordination is incomplete or no patch is available, such as Tenda firmware CVE-2026-11405 hidden web-management authentication backdoors.)
  • GitHub Security Advisories
  • CERT-UA (HTML/API watch for Ukraine-focused actor campaigns, UAC cluster reports, malware component names, and indicator bundles, including UAC-0145 / Sandworm subcluster access evolution, ClickFix on compromised sites, SMARTAXE smart-contract domain resolution, and COWARDDUCK Android activity; article pages can be queried via /api/articles/byId?id=<article-id>)
  • Europol / Eurojust / FBI IC3 / SBU public cyber notices — watch for criminal infrastructure takedowns, seized domains, exit-node indicators, ransomware-enabler service descriptions, TDS / fake-update warnings, and law-enforcement caveats that can update tool/infrastructure pages such as the June 2026 Operation Endgame SocGholish / FakeUpdates disruption; also monitor FBI/CISA/SBU messaging-application targeting advisories such as Russian Intelligence Services / FSB commercial-messaging phishing tracked as UNC5792 / UNC4221, Backup Recovery Key theft against Signal users, SMS-style fake-support lures, and QR-code account-linking attempts.
  • BKA / German cybercrime prosecutors and Indonesian police public notices — monitor phishing-as-a-service infrastructure disruptions, arrests, victim-notification updates, server and customer counts, seized indicator releases, and service-resilience findings following the July 2026 Kratos takedown.
  • AIVD / MIVD public cyber advisorieshttps://english.aivd.nl/cyberadvisories and https://english.defensie.nl/ (watch intelligence-derived Russian and other state-actor advisories with operational defender value, including internet-exposed IP-camera compromise for image-recognition-assisted collection on military vehicles, cargo, logistics routes, weapons deliveries, and personnel in Ukraine and EU/NATO states.)
  • NCSC-NL / Dutch Police cyber noticeshttps://www.ncsc.nl/nieuws and https://www.politie.nl/nieuws (watch Netherlands-hosted criminal infrastructure, botnet takedowns, residential-proxy / IoT-device abuse, hosting-provider disruptions, seized servers, and follow-up victim-notification or indicator releases such as the 17-million-device botnet disruption).

  • Nebula Security research (HTML watch for kernel, virtualization, and exploit-development research with durable defender value such as GhostLock / CVE-2026-43499 local-root and container-escape writeups, public exploit release, and kernelCTF context.)

  • Varonis Threat Labs (HTML watch for SaaS, identity, data-security, and AI-agent platform research such as Rogue Agent Dialogflow CX Code Blocks shared-runtime compromise, managed Cloud Run egress, VPC Service Controls bypass, IMDS exposure, and audit-log visibility gaps.)

Maintainer / vendor incident posts to watch during active campaigns

  • ServiceNow security advisorieshttps://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3137947 (watch CVE-2026-6875 AI Platform sandbox-escape exploitation for fixed-release changes, public indicators, victim scope, and vendor incident-response guidance; keep it distinct from the June hosted-instance table-query issue)
  • Hugging Face incident follow-upshttps://huggingface.co/blog/security-incident-july-2026 and https://github.com/huggingface/blog/blob/main/security-incident-july-2026.md (watch for affected partner/customer scope, exact timeline, CVEs, indicators, public-service C2 detail, token impact, forensic findings, and changes to the initial no-public-artifact-tampering assessment.)
  • Nx / nrwl security advisories and issueshttps://github.com/nrwl/nx/security/advisories and https://github.com/nrwl/nx/issues
  • Grafana Labs security posts
  • PyPI project and malware-report pages for affected packages — use package-specific release history as confirmation for yanked or restored versions.
  • Packagist package pages and maintainer incident notes — watch package metadata/tag movement and unexpected composer-plugin conversions during Mini Shai-Hulud-style cross-ecosystem incidents.
  • LiteSpeed / cPanel security notices — watch vendor advisories and cPanel support notices for actively exploited hosting-control-plane flaws and forced-removal/patch guidance, including LiteSpeed cPanel Plugin CVE-2026-54420 root escalation on CloudLinux / CageFS shared-hosting systems.
  • Progress / ShareFile status and advisories and Progress security notices (watch emergency shutdown or access-disablement guidance for customer-operated ShareFile Storage Zone Controllers, including July 2026 credible external security threat reporting, safe-restart instructions, CVE assignment, IOCs, and affected-version ranges; cross-reference watchTowr's Storage Zone Controller CVE-2026-2699 / CVE-2026-2701 pre-authentication RCE chain for safe exposure-validation and web-shell hunt pivots without assuming it is the current incident path.)
  • BeyondTrust security advisories (HTML watch; monitor Remote Support / Privileged Remote Access authentication-bypass and appliance-control flaws such as BT26-03 / CVE-2026-40138 / CVE-2026-40139, especially where exposed RS/PRA systems have prior web-shell / backdoor exploitation history.)
  • DAEMON Tools / Disc Soft notices and release notes; watch follow-ups to DAEMON Tools Lite CVE-2026-8398, installer integrity claims, rebuild/version guidance, and infrastructure-remediation details.
  • Visual Studio Code release notes / Marketplace security changeshttps://code.visualstudio.com/updates/ and https://marketplace.visualstudio.com/VSCode (watch extension-marketplace mitigations, delayed auto-update changes, publisher-trust exceptions, and response details following poisoned-extension incidents such as Nx Console.)

Notes

  • Prefer RSS/Atom over ad hoc web searches.
  • If a feed URL changes, update this page and the monitoring config together.
  • If a source produces repeated noise, lower its priority before removing it.

Active watch topics

  • FortiOS CVE-2025-68686 symlink-persistence bypass — monitor CISA, Fortinet, national CERTs, and incident responders for precursor-CVE attribution, malicious-link and HTTP-request detection artifacts, affected-device or victim scope, configuration-theft consequences, actor linkage, and reconciliation of Fortinet's March advisory status with CISA's July 27 exploitation determination.
  • TELESHIM / MIXEDKEY / BINDCLOAK Middle East government campaign — monitor Zscaler ThreatLabz, regional CERTs, Telegram, and incident responders for Part 2 BINDCLOAK analysis, initial-access detail, additional victims or countries, infrastructure and sample changes, and evidence that can refine or name the currently unattributed East Asia-linked cluster.
  • Fastjson CVE-2026-16723 active exploitation — monitor Alibaba, FearsOff, ThreatBook, Imperva, CISA, NVD, Spring, and incident responders for a patched 1.x artifact or advisory revision, KEV status, successful-exploitation evidence, victim and actor scope, raw request and infrastructure indicators, deployment-matrix changes, and reconciliation of the vendor's 1.2.68–1.2.83 range with broader third-party claims.
  • MrMustard PyPI compromise — monitor XanaduAI, PyPI, GitHub, StepSecurity, Aikido, Codecov, and incident responders for a maintainer postmortem, artifact hashes, exact upload and removal times, credential or self-hosted-runner impact, downstream use of stolen SSH/cloud/Kubernetes material, additional versions or packages, and confirmation of account recovery and trusted-publishing controls.
  • Fake Corepack developer-tool impersonation — monitor Socket, Node.js, OpenJS, the registrar, browser/search providers, and incident responders for domain takedown status, search-result suppression, payload hashes, signer and persistence detail, additional redirect infrastructure, victim scope, and confirmed credential or proxy-exit-node abuse tied to corepack.org.
  • CL-STA-1114 / Void Blizzard Zimbra exploitation — monitor CISA and AA26-204A partners, Unit 42, Proofpoint, Microsoft, Seqrite, Zimbra, and incident responders for CVE-2025-66376 exploitation scope, Ulej / Flowerbed changes, additional victims and infrastructure, app-specific-password persistence, reconciliation of the LAUNDRY BEAR / Void Blizzard / CL-STA-1114 / TA488 labels with Seqrite's APT28 assessment, KEV status, and confirmation of affected and fixed builds.
  • GitHub Actions cPanel exploitation campaign — monitor GitHub, Socket, cPanel, Packagist, and incident responders for confirmed repository/victim counts, workflow or payload changes, infrastructure rotation, successful CVE-2026-41940 exploitation scope, source-control token reuse, and platform containment actions following the July 22 distributed-runner campaign.
  • CISA KEV July 22 additions — monitor Check Point, Microsoft, CISA, and incident responders for CVE-2026-16232 victim or actor scope, additional application-token indicators, affected-branch fixes, and reconciliation of the conflicting CVE-2026-50522 privilege prerequisites plus SharePoint exploit-chain and post-exploitation detail.
  • Check Point SmartConsole emergency patch scope — monitor Check Point, CISA, Rapid7, and incident responders for additional CVE-2026-16232 exploitation indicators or victim scope, release-specific fixes for older branches, and any exploitation of companion management-authentication flaw CVE-2026-62144 or GaiaOS WebUI local-privilege-escalation flaw CVE-2026-62145.
  • Iran-linked access optionality and selective disruption — monitor SentinelLABS, CISA/FBI, Microsoft, Unit 42, Check Point, Broadcom, OT vendors, and incident responders for identity/cloud/RMM/service-provider access converted from espionage to disruption, persona infrastructure changes after seizures, verified OT process effects, and evidence that distinguishes supplier access from downstream software-supply-chain compromise.
  • WordPress wp2shell active exploitation — monitor WordPress, Wiz, Searchlight Cyber, hosting providers, Wordfence, CISA, and incident responders for KEV status, exploit-tool changes, malicious-plugin / web-shell variants, affected-host scope, and post-exploitation lateral movement or data theft tied to CVE-2026-63030 and CVE-2026-60137.
  • CISA KEV July 21 additions — monitor CISA, WordPress, Langflow, DD-WRT, FortiGuard, and incident responders for wp2shell post-exploitation changes, Langflow CVE-2026-0770 payload or actor detail, and C0XMO / DD-WRT CVE-2021-27137 infrastructure or propagation updates.
  • UAC-0145 / Sandworm access evolution — monitor CERT-UA and partner reporting for additional compromised sites, SMARTAXE contracts/domains, GHETTOVIBE/SCOUTCURL/FREAKYPOLL/FLUIDLEECH/LOADLOOP changes, and COWARDDUCK mobile delivery or infrastructure.
  • UTA0533 SonicWall SMA1000 exploitation — monitor SonicWall, Volexity, Rapid7, and CISA for fixed-build changes, additional victims, YARA/IOC revisions, actor attribution, and evidence of KNUCKLEBALL/ORANGETAIL/Suo5 persistence or credential capture.
  • Shai-Hulud downstream credential-reuse incidents — monitor public incident reporting where credentials dumped by the 2025 worm are reused months later, such as the July 2026 Suno breach reporting that links one infected employee to source-code, customer-list, cloud, GitHub, and Stripe-related exposure.
  • CISA KEV July 2026 emergency additions — track same-week Microsoft SharePoint, ADFS, SonicWall SMA1000, and Fortinet FortiSandbox KEV entries for vendor guidance, exploit-chain reporting, and appliance compromise indicators.
  • Shai-Hulud / Mini Shai-Hulud / TeamPCP supply-chain activity — monitor vendor research, affected-package appendices, maintainer postmortems, CISA/GitHub advisories, and registry notices for new package families, propagation methods, persistence paths, infrastructure, and attribution changes.
  • Russian state IP-camera military espionage — monitor AIVD, MIVD, NCSC partners, camera vendors, and incident-response reporting for named-service attribution, affected products or vulnerabilities, public indicators, victim scope, and changes to the assessment that camera-derived intelligence has supported attacks only inside Ukraine.
  • Kratos PhaaS post-takedown activity — monitor BKA, Indonesian authorities, Microsoft, ANY.RUN, hosting providers, and incident responders for victim-notification guidance, seized indicators, affiliate migration, surviving phishing deployments, copied-kit reappearance, and evidence that central disruption did or did not invalidate stolen sessions.
  • Azure DevOps MCP pull-request prompt injection — monitor Microsoft and the public azure-devops-mcp repository for a CVE, fixed release, consistent external-content wrapping, hosted-service impact clarification, and audit or policy controls that prevent cross-project confused-deputy tool sequences.
  • OpenAI / Hugging Face evaluation-driven intrusion — monitor OpenAI, Hugging Face, the unnamed package-registry proxy/cache vendor, and incident-response follow-ups for the zero-day identity and fix, full timeline, affected customer/partner scope, indicators, independent validation, and controls that prevent long-horizon model evaluations from crossing sandbox, corporate-network, and third-party boundaries.
  • GitLab Oj notebook-diff authenticated RCE — monitor GitLab, depthfirst, Oj, CISA, and incident responders for CVE assignment, changes to affected or fixed versions, exploit portability beyond the public GitLab 18.11.3 x86-64 reference, confirmed exploitation, detection artifacts, and clarification of the June 10 release-note classification.
  • Operation BlueDash multi-RMM workplace phishing — monitor ZeroBEC, Microsoft, GitHub, RMM vendors, hosting providers, and incident responders for repository or domain containment, new workplace-brand lures, changed loaders, replacement enrollment infrastructure, victim scope, final post-access objectives, and corroboration or refinement of the Nigeria-based developer-group assessment.