Overview
Threat intelligence, unified.
HackerFeeds unifies four continuously ingested threat-intel sources — a ransomware tracker, CVE and vulnerability intelligence, web defacement records, and a data breach directory — alongside the CISA KEV catalog and a global threat map with per-country rollups. Analysts start here to scan the day's activity, then pivot into any feed to filter, track a group or country, and subscribe to what matters.
Ransomware Incidents
30,922
Defacements
1,434
CVEs (last 30d)
11,840
Last 24 Hours
68
Global threat map
Composite risk by country — hover for breakdown, click to drill in
Threat timeline
Daily activity across sources•1,352 events (13,084 incl. hidden) in last 30d•Click legend chip to toggle
Most active this week
Top actors by source — click to drill in
Stop chasing alerts. Route them.
Build watchlists by vendor, CVSS, ransomware group or country. Pipe matches to Slack, PagerDuty, Splunk, Sentinel, XSOAR — or pull raw via API & TAXII 2.1.
Custom feeds
Watchlists, dedupe, enrichment
Integrations
Slack, PagerDuty, SIEM
API + TAXII
JSON, STIX 2.1, raw archive
Live Activity
Latest events across ransomware, CVEs and defacements — interleaved by recency
- RANSOMWAREIntegrated Health Systems hit by coinbasecartelSW50ZWdyYXRlZCBIZWFsdGggU3lzdGVtc0Bjb2luYmFzZWNhcnRlbA==·by coinbasecartel·medium
- RANSOMWARETower Insurance hit by coinbasecartelVG93ZXIgSW5zdXJhbmNlQGNvaW5iYXNlY2FydGVs·by coinbasecartel·medium
- RANSOMWAREFlecha Bus hit by coinbasecartelRmxlY2hhIEJ1c0Bjb2luYmFzZWNhcnRlbA==·by coinbasecartel·medium
- RANSOMWAREOTEIS Conseil & Ingénierie hit by coinbasecartelT1RFSVMgQ29uc2VpbCAmIEluZ8OpbmllcmllQGNvaW5iYXNlY2FydGVs·by coinbasecartel·medium
- RANSOMWARELonghorn Investments hit by coinbasecartelTG9uZ2hvcm4gSW52ZXN0bWVudHNAY29pbmJhc2VjYXJ0ZWw=·by coinbasecartel·medium
- RANSOMWAREKessler Creative hit by coinbasecartelS2Vzc2xlciBDcmVhdGl2ZUBjb2luYmFzZWNhcnRlbA==·by coinbasecartel·medium
- RANSOMWAREKlasko Immigration Law Partners hit by coinbasecartelS2xhc2tvIEltbWlncmF0aW9uIExhdyBQYXJ0bmVyc0Bjb2luYmFzZWNhcnRlbA==·by coinbasecartel·medium
- RANSOMWAREPatel hit by coinbasecartelUGF0ZWxAY29pbmJhc2VjYXJ0ZWw=·by coinbasecartel·medium
- RANSOMWAREAbacus Advisors hit by coinbasecartelQWJhY3VzIEFkdmlzb3JzQGNvaW5iYXNlY2FydGVs·by coinbasecartel·medium
- RANSOMWARELifeBank Microfinance Foundation hit by coinbasecartelTGlmZUJhbmsgTWljcm9maW5hbmNlIEZvdW5kYXRpb25AY29pbmJhc2VjYXJ0ZWw=·by coinbasecartel·medium
- RANSOMWAREPT Perusahaan Jamu Air Mancur hit by coinbasecartelUFQgUGVydXNhaGFhbiBKYW11IEFpciBNYW5jdXJAY29pbmJhc2VjYXJ0ZWw=·by coinbasecartel·medium
- RANSOMWAREPT. Bank Perekonomian Rakyat Bintan hit by coinbasecartelUFQuIEJhbmsgUGVyZWtvbm9taWFuIFJha3lhdCBCaW50YW5AY29pbmJhc2VjYXJ0ZWw=·by coinbasecartel·medium
- CVECVE-2026-62382: PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion log…CVE-2026-62382·by NVD·unknown
- CVECVE-2026-62381: luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.…CVE-2026-62381·by NVD·medium
- CVECVE-2026-62380: Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain nul…CVE-2026-62380·by NVD·unknown
- CVECVE-2026-62243: Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable…CVE-2026-62243·by NVD·high
- CVECVE-2026-62204: SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install…CVE-2026-62204·by NVD·medium
- CVECVE-2026-60084: SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoin…CVE-2026-60084·by NVD·high
- CVECVE-2026-60083: SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to…CVE-2026-60083·by NVD·medium
- CVECVE-2026-59809: SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, a…CVE-2026-59809·by NVD·medium
- CVECVE-2026-59808: AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() retur…CVE-2026-59808·by NVD·high
- CVECVE-2026-59256: WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens witho…CVE-2026-59256·by NVD·high
- CVECVE-2026-58003: WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php …CVE-2026-58003·by NVD·high
- CVECVE-2026-58002: WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in th…CVE-2026-58002·by NVD·medium
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
CyberSecurity news
Live from BleepingComputer, Krebs, The Hacker News, Dark Reading, The Record, SecurityWeek & more.
- YSecurity assessment found open model near frontiersHacker News·brief
- YCyberStrike – open-source AI harness for offensive security (AGPL)Hacker News·brief
- YAWS Security makes an inscrutable choiceHacker News·brief
- Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the SpotlightSecurityWeek·brief
- YShow HN: PgExtAssure – pre-admission security evidence for PostgreSQL extensionsHacker News·brief
- Friday Squid Blogging: Neon Flying SquidSchneier on Security·brief
- Lawmakers call for investigation into impact of CISA staffing cutsThe Record·brief
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2The Hacker News·brief
- OWASP Flags Top AI Skill Risks in New Security BlueprintDark Reading·brief
- YWhere Security Fits in an AI Agent StackHacker News·brief
- YQuantum security misconceptions: Grover's algorithmHacker News·brief
- AI Is Learning to Write Genetic CodeSchneier on Security·brief

