<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Threxar Threat Intelligence Feed</title>
    <link>https://threxar.com</link>
    <description>Continuous real-time monitoring across dark web forums, ransomware leak portals, malware campaigns, and CVE disclosures.</description>
    <language>en-us</language>
    <lastBuildDate>Sun, 27 Sep 2026 12:05:48 GMT</lastBuildDate>
    <atom:link href="https://threxar.com/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title><![CDATA[Ventrix Corp Employee Database Exposed on Breach Forum]]></title>
      <link>https://threxar.com/feed/ventrix-corp-employee-database-leak</link>
      <guid isPermaLink="true">https://threxar.com/feed/ventrix-corp-employee-database-leak</guid>
      <pubDate>Fri, 25 Sep 2026 14:02:00 GMT</pubDate>
      <description><![CDATA[2.3 million employee records including names, hashed passwords, and internal email addresses listed by threat actor "v0idcrack".]]></description>
      <category>Leak</category>
    </item>
    <item>
      <title><![CDATA[StealCraft Loader Distributed via Fake Invoice PDFs - Active Campaign]]></title>
      <link>https://threxar.com/feed/stealcraft-loader-campaign-q3-2026</link>
      <guid isPermaLink="true">https://threxar.com/feed/stealcraft-loader-campaign-q3-2026</guid>
      <pubDate>Thu, 24 Sep 2026 09:30:00 GMT</pubDate>
      <description><![CDATA[A newly documented loader malware dubbed "StealCraft" is actively targeting finance and HR departments via spoofed invoice lures.]]></description>
      <category>Malware</category>
    </item>
    <item>
      <title><![CDATA[NocturnLock Ransomware Group Claims Attack on Meridian Health Systems]]></title>
      <link>https://threxar.com/feed/nocturnlock-claims-meridian-hospital</link>
      <guid isPermaLink="true">https://threxar.com/feed/nocturnlock-claims-meridian-hospital</guid>
      <pubDate>Wed, 23 Sep 2026 18:45:00 GMT</pubDate>
      <description><![CDATA[NocturnLock published 14GB of patient administrative records to their leak site after reporting no ransom payment was received.]]></description>
      <category>Ransomware</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-48821: Heap Overflow in Nginx 1.26.x Allows Remote Code Execution]]></title>
      <link>https://threxar.com/feed/cve-2026-48821-nginx-heap-overflow</link>
      <guid isPermaLink="true">https://threxar.com/feed/cve-2026-48821-nginx-heap-overflow</guid>
      <pubDate>Tue, 22 Sep 2026 10:00:00 GMT</pubDate>
      <description><![CDATA[A heap overflow vulnerability in the Nginx HTTP/2 stack allows an unauthenticated remote attacker to execute arbitrary code.]]></description>
      <category>CVE</category>
    </item>
    <item>
      <title><![CDATA[ClearTrack Spyware Targets Journalists and NGOs Across Southeast Asia]]></title>
      <link>https://threxar.com/feed/cleartrack-spyware-southeast-asia</link>
      <guid isPermaLink="true">https://threxar.com/feed/cleartrack-spyware-southeast-asia</guid>
      <pubDate>Mon, 21 Sep 2026 12:15:00 GMT</pubDate>
      <description><![CDATA[A previously undocumented mobile spyware framework is being deployed against civil society targets in three countries.]]></description>
      <category>Malware</category>
    </item>
    <item>
      <title><![CDATA[GlobalChain Logistics API Keys Exposed via Public GitHub Repository]]></title>
      <link>https://threxar.com/feed/globalchain-supply-api-keys-exposed</link>
      <guid isPermaLink="true">https://threxar.com/feed/globalchain-supply-api-keys-exposed</guid>
      <pubDate>Sun, 20 Sep 2026 08:00:00 GMT</pubDate>
      <description><![CDATA[Active production API keys for GlobalChain's freight management platform were committed to a public GitHub repository and exposed for 11 days.]]></description>
      <category>Leak</category>
    </item>
    <item>
      <title><![CDATA[PhishNet Kit v4.2 Targeting Online Banking Customers of 12 Regional Banks]]></title>
      <link>https://threxar.com/feed/phishnet-kit-targeting-banking-customers</link>
      <guid isPermaLink="true">https://threxar.com/feed/phishnet-kit-targeting-banking-customers</guid>
      <pubDate>Sat, 19 Sep 2026 15:30:00 GMT</pubDate>
      <description><![CDATA[An updated phishing kit is circulating on criminal forums, claiming to target online banking portals across 12 regional financial institutions.]]></description>
      <category>News</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-51033: Apache Struts 2 Deserialization Flaw Enables Pre-Auth RCE]]></title>
      <link>https://threxar.com/feed/cve-2026-51033-apache-struts-deserialization</link>
      <guid isPermaLink="true">https://threxar.com/feed/cve-2026-51033-apache-struts-deserialization</guid>
      <pubDate>Fri, 18 Sep 2026 11:00:00 GMT</pubDate>
      <description><![CDATA[A Java deserialization vulnerability in Apache Struts 2.5.x and 6.0.x enables unauthenticated remote code execution via crafted OGNL expressions.]]></description>
      <category>CVE</category>
    </item>
    <item>
      <title><![CDATA[Authentication Bypass PoC Published for Fortinet FortiOS Admin Portal]]></title>
      <link>https://threxar.com/feed/fortinet-fortios-auth-bypass-poc</link>
      <guid isPermaLink="true">https://threxar.com/feed/fortinet-fortios-auth-bypass-poc</guid>
      <pubDate>Thu, 17 Sep 2026 16:20:00 GMT</pubDate>
      <description><![CDATA[A public exploit PoC for FortiOS admin portal authentication bypass (CVE-2026-47883) was released on GitHub.]]></description>
      <category>CVE</category>
    </item>
    <item>
      <title><![CDATA[ShadowRAT C2 Botnet Infrastructure Mapped Across 14 Hosting Providers]]></title>
      <link>https://threxar.com/feed/shadowrat-c2-botnet-infrastructure</link>
      <guid isPermaLink="true">https://threxar.com/feed/shadowrat-c2-botnet-infrastructure</guid>
      <pubDate>Wed, 16 Sep 2026 13:40:00 GMT</pubDate>
      <description><![CDATA[Telemetry correlation identified 38 active command-and-control nodes powering ShadowRAT info-stealer campaigns.]]></description>
      <category>Malware</category>
    </item>
    <item>
      <title><![CDATA[BlackByte Ransomware Syndicate Targets Regional Industrial Manufacturers]]></title>
      <link>https://threxar.com/feed/blackbyte-ransomware-manufacturing-sector</link>
      <guid isPermaLink="true">https://threxar.com/feed/blackbyte-ransomware-manufacturing-sector</guid>
      <pubDate>Tue, 15 Sep 2026 20:10:00 GMT</pubDate>
      <description><![CDATA[Three manufacturing firms added to BlackByte onion leak portal following double-extortion campaigns.]]></description>
      <category>Ransomware</category>
    </item>
    <item>
      <title><![CDATA[Malicious Chrome Extension "PDF QuickView" Stealing Session Tokens]]></title>
      <link>https://threxar.com/feed/credstealer-chrome-extension-malware</link>
      <guid isPermaLink="true">https://threxar.com/feed/credstealer-chrome-extension-malware</guid>
      <pubDate>Mon, 14 Sep 2026 11:05:00 GMT</pubDate>
      <description><![CDATA[A Chrome Web Store extension with 45,000 installs was discovered harvesting session cookies for SaaS applications.]]></description>
      <category>Malware</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-39102: Local Privilege Escalation Flaw in Linux Kernel io_uring]]></title>
      <link>https://threxar.com/feed/cve-2026-39102-linux-kernel-privilege-escalation</link>
      <guid isPermaLink="true">https://threxar.com/feed/cve-2026-39102-linux-kernel-privilege-escalation</guid>
      <pubDate>Sun, 13 Sep 2026 17:15:00 GMT</pubDate>
      <description><![CDATA[A use-after-free vulnerability in the Linux kernel io_uring subsystem allows local users to achieve root privileges.]]></description>
      <category>CVE</category>
    </item>
    <item>
      <title><![CDATA[890K Healthcare Employee Credentials Dumped on Dark Web Forum]]></title>
      <link>https://threxar.com/feed/dark-web-healthcare-credentials-dump</link>
      <guid isPermaLink="true">https://threxar.com/feed/dark-web-healthcare-credentials-dump</guid>
      <pubDate>Sat, 12 Sep 2026 09:50:00 GMT</pubDate>
      <description><![CDATA[Breach forum user lists aggregated stealer logs containing login records for regional hospital portals.]]></description>
      <category>Leak</category>
    </item>
    <item>
      <title><![CDATA[AWS IMDSv1 Misconfigurations Leveraged in Automated SSRF Attacks]]></title>
      <link>https://threxar.com/feed/cloud-metadata-exfiltration-aws-imds</link>
      <guid isPermaLink="true">https://threxar.com/feed/cloud-metadata-exfiltration-aws-imds</guid>
      <pubDate>Fri, 11 Sep 2026 14:30:00 GMT</pubDate>
      <description><![CDATA[Automated scanners targeting public web applications to steal AWS IAM role tokens via IMDSv1 metadata endpoints.]]></description>
      <category>News</category>
    </item>
    <item>
      <title><![CDATA[Polkit Privilege Escalation Variant "PwnKit-v2" Observed in the Wild]]></title>
      <link>https://threxar.com/feed/pwnkit-v2-active-exploitation</link>
      <guid isPermaLink="true">https://threxar.com/feed/pwnkit-v2-active-exploitation</guid>
      <pubDate>Thu, 10 Sep 2026 18:00:00 GMT</pubDate>
      <description><![CDATA[Refactored privilege escalation exploit targeting unpatched Linux servers for crypto-miner deployment.]]></description>
      <category>Malware</category>
    </item>
    <item>
      <title><![CDATA[SCADA Schematics & PLC Logic Code Leaked on TOR Underground Portal]]></title>
      <link>https://threxar.com/feed/tor-leak-portal-industrial-scada</link>
      <guid isPermaLink="true">https://threxar.com/feed/tor-leak-portal-industrial-scada</guid>
      <pubDate>Wed, 09 Sep 2026 10:15:00 GMT</pubDate>
      <description><![CDATA[Internal engineering documents and PLC programming files for a European water treatment plant listed online.]]></description>
      <category>Leak</category>
    </item>
    <item>
      <title><![CDATA[Automated Telegram Bot Ecosystem Distributes Fresh Infostealer Logs]]></title>
      <link>https://threxar.com/feed/stealer-log-parser-telegram-bot</link>
      <guid isPermaLink="true">https://threxar.com/feed/stealer-log-parser-telegram-bot</guid>
      <pubDate>Tue, 08 Sep 2026 15:45:00 GMT</pubDate>
      <description><![CDATA[Underground Telegram bot network provides automated searching across 10M+ harvested stealer credentials.]]></description>
      <category>News</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-44011: Remote Code Execution in NGINX Ingress Controller for Kubernetes]]></title>
      <link>https://threxar.com/feed/cve-2026-44011-kubernetes-ingress-rce</link>
      <guid isPermaLink="true">https://threxar.com/feed/cve-2026-44011-kubernetes-ingress-rce</guid>
      <pubDate>Mon, 07 Sep 2026 12:00:00 GMT</pubDate>
      <description><![CDATA[A high-severity command injection flaw in Kubernetes NGINX Ingress Controller allows container escape.]]></description>
      <category>CVE</category>
    </item>
    <item>
      <title><![CDATA[Former BlackCat Affiliates Regroup Under New "Vortex" Ransomware Flag]]></title>
      <link>https://threxar.com/feed/ransomware-alphv-rebrand-analysis</link>
      <guid isPermaLink="true">https://threxar.com/feed/ransomware-alphv-rebrand-analysis</guid>
      <pubDate>Sun, 06 Sep 2026 19:30:00 GMT</pubDate>
      <description><![CDATA[Threat actor telemetry confirms former ALPHV/BlackCat operators initiating new attacks using Rust-based encryptor.]]></description>
      <category>Ransomware</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-39104: OpenVPN TLS Remote Memory Disclosure Vulnerability]]></title>
      <link>https://threxar.com/feed/openvpn-tls-remote-heap-disclosure</link>
      <guid isPermaLink="true">https://threxar.com/feed/openvpn-tls-remote-heap-disclosure</guid>
      <pubDate>Sat, 05 Sep 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[A heap buffer over-read in OpenVPN 2.6.x TLS handshake parser leaks server memory contents.]]></description>
      <category>CVE</category>
    </item>
    <item>
      <title><![CDATA[Q3 Global Sensor Grid Telemetry: 14M Exploitation Attempts Logged]]></title>
      <link>https://threxar.com/feed/zero-day-traps-honeypot-telemetry-q3</link>
      <guid isPermaLink="true">https://threxar.com/feed/zero-day-traps-honeypot-telemetry-q3</guid>
      <pubDate>Fri, 04 Sep 2026 11:00:00 GMT</pubDate>
      <description><![CDATA[Threxar global honeypot network captured raw exploit payloads, SSH brute-force clusters, and emerging zero-day probes.]]></description>
      <category>News</category>
    </item>
  </channel>
</rss>