Skip to content
Threat Feed

Vendor

Cloudflare

15 briefs RSS
high threat

GreyVibe Targets Ukraine with AI-Generated Lures and Custom Malware

The likely Russian-aligned GreyVibe group is targeting Ukrainian organizations with AI-generated lures delivered via spear-phishing and malicious websites, deploying custom malware such as PhantomRelay, LegionRelay, and FallSpy to exfiltrate sensitive data.

google drive +8 GreyVibe ai-generated-lures cyberespionage ukraine malware phantomrelay legionrelay fallspy
2r 8t
medium advisory

@hulumi/policies Evidence Bypass Vulnerability

@hulumi/policies versions before 1.3.2 allowed unrelated compliant-looking evidence to suppress violations for different zones, hostnames, origins, or repositories in the same stack, bypassing Cloudflare and deployment-governance guardrails.

@hulumi/policies dependency-confusion security-bypass cloud
2r
high advisory

Tycoon2FA Phishing Kit Targets Microsoft 365 Accounts with Device-Code Phishing

The Tycoon2FA phishing kit now supports device-code phishing attacks targeting Microsoft 365 accounts, abusing Trustifi click-tracking URLs, redirecting victims through Cloudflare Workers to a fake Microsoft CAPTCHA page, tricking them into entering a device code, and granting attackers OAuth tokens and access to their Microsoft 365 accounts.

Microsoft 365 +2 phishing device-code phishing oauth tycoon2fa
2r 2t
medium advisory

Better Auth Rate Limiter Bypass via IPv6 Prefix Rotation (CVE-2026-45364)

Better Auth versions before 1.4.17 and pre-release versions before 1.5.0-beta.9 are vulnerable to CVE-2026-45364, a rate-limiting bypass that allows IPv6 clients to rotate through numerous source addresses or vary the textual encoding of one IPv6 address, effectively defeating rate limiting on authentication endpoints, potentially leading to credential stuffing, account enumeration, and amplification of password-reset email fan-out.

better-auth +4 rate-limiting authentication ipv6 cve-2026-45364
2r
high threat

FrostyNeighbor Targets Ukraine with Updated PicassoLoader Chain

The FrostyNeighbor threat actor is targeting Ukrainian governmental organizations with spearphishing emails containing malicious PDFs that deliver a JavaScript dropper (PicassoLoader) and ultimately a Cobalt Strike beacon.

Cobalt Strike +2 FrostyNeighbor cyberespionage cobaltstrike picassoloader ukraine
2r 3t 3i
high threat

Kimsuky Targets Organizations with Evolving PebbleDash-Based Tools

Kimsuky, a North Korean APT group, is actively targeting organizations, primarily in South Korea, with evolving tactics and tools, leveraging spear-phishing emails and messenger contacts to deploy malware such as PebbleDash and AppleSeed for establishing backdoors and stealing information.

VSCode +2 Kimsuky +4 apt spear-phishing malware pebbledash appleseed
2r 4t 5i
high threat

Device Code Phishing Exploiting OAuth 2.0 Device Authorization Grant Flow

Threat actors are increasingly using device code phishing, often via Phishing-as-a-Service platforms, to compromise user accounts by abusing the OAuth 2.0 device authorization grant flow and capturing authentication tokens, enabling account takeover, data theft, and business email compromise.

Microsoft 365 +3 TA4903 device-code-phishing phishing credential-theft oAuth
2r 5t
high advisory

Sophisticated AitM Phishing Campaign Targeting US Organizations

A sophisticated phishing campaign targeting US organizations uses a 'code of conduct review' theme to lure victims to a malicious website, employing adversary-in-the-middle (AitM) techniques to capture authentication tokens and gain account access.

Microsoft account +1 phishing aitm credential-access initial-access
2r 2t
high threat

Inngest SDK Exposes Environment Variables via Unhandled HTTP Methods

Inngest TypeScript SDK versions 3.22.0 through 3.53.1 expose environment variables via the serve() handler on unhandled HTTP methods, allowing unauthenticated remote attackers to exfiltrate environment variables from the host process via `PATCH`, `OPTIONS`, or `DELETE` requests to the `serve()` HTTP handler.

exploited inngest TypeScript SDK +2 environment-variable-exposure inngest cve-2026-42047
2r 1t 2i
medium advisory

Potential Protocol Tunneling via Cloudflared

Adversaries may abuse Cloudflare Tunnel (cloudflared) on Windows systems to proxy command and control traffic or exfiltrate data through Cloudflare's edge, evading direct connection blocking.

M365 Defender +1 cloudflare tunneling command and control proxy
2r 2t 1i
medium advisory

Atomic Red Team MCP Server Automates Adversary Emulation

The Atomic Red Team Model Context Protocol (MCP) server integrates security tests from the Atomic Red Team project with AI assistants, enabling natural language interaction with security tools, bridging the gap between threat intelligence and execution, allowing for automated validation, multi-platform testing, and rapid playbook creation.

Splunk +5 red-teaming adversary-emulation ai
2r 4t
medium advisory

Windows Hosts Querying Abused Web Services

Adversaries may use abused web services such as paste sites, VoIP, and file hosting to host malicious payloads or facilitate command and control, detected via DNS queries from Windows hosts to these services.

githubusercontent.com +34 abused-web-service command-and-control initial-access windows
2r 1t 34i
medium advisory

Potential Cloudflared Network Tunnel Detection

This brief detects network connection events associated with the Cloudflared tool, used to create tunnels via Cloudflare, potentially for unauthorized access or exfiltration, by establishing outbound connections to Cloudflare Edge Servers.

Cloudflared +3 reverse-proxy tunneling network-tunnel
2r 1t
high advisory

Potential Abuse of Cloudflare Tunnels via Cloudflared

Attackers are increasingly abusing Cloudflare tunnels, created via the cloudflared client, for establishing stealthy command and control channels and evading network defenses by proxying traffic through Cloudflare's infrastructure.

Cloudflared +3 cloudflare reverse-proxy tunnel command-and-control
2r 2t
high advisory

livewire-markdown-editor Arbitrary File Upload Vulnerability

The livewire-markdown-editor versions before v1.3 contain an arbitrary file upload vulnerability in the MarkdownEditor::updatedAttachments() Livewire handler, allowing authenticated users to upload any file type, potentially leading to stored XSS, phishing, malware distribution, and markdown injection.

mckenziearts/livewire-markdown-editor +3 arbitrary-file-upload stored-xss vulnerability
2r 1t