Overview
Threat intelligence, unified.
HackerFeeds unifies four continuously ingested threat-intel sources — a ransomware tracker, CVE and vulnerability intelligence, web defacement records, and a data breach directory — alongside the CISA KEV catalog and a global threat map with per-country rollups. Analysts start here to scan the day's activity, then pivot into any feed to filter, track a group or country, and subscribe to what matters.
Ransomware Incidents
29,781
Defacements
1,179
CVEs (last 30d)
9,282
Last 24 Hours
17
Global threat map
Composite risk by country — hover for breakdown, click to drill in
Threat timeline
Daily activity across sources•1,332 events (10,298 incl. hidden) in last 30d•Click legend chip to toggle
Most active this week
Top actors by source — click to drill in
Stop chasing alerts. Route them.
Build watchlists by vendor, CVSS, ransomware group or country. Pipe matches to Slack, PagerDuty, Splunk, Sentinel, XSOAR — or pull raw via API & TAXII 2.1.
Custom feeds
Watchlists, dedupe, enrichment
Integrations
Slack, PagerDuty, SIEM
API + TAXII
JSON, STIX 2.1, raw archive
Live Activity
Latest events across ransomware, CVEs and defacements — interleaved by recency
- CVECVE-2026-63720: datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who contr…CVE-2026-63720·by NVD·high
- CVECVE-2026-17434: A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/mod…CVE-2026-17434·by NVD·medium
- CVECVE-2026-17433: A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of t…CVE-2026-17433·by NVD·medium
- DEFACEMENThttps://cananea.gob.mx/0x.txt defaced by chinafanshttp://www.zone-h.org/mirror/id/42747586·by chinafans🇲🇽
- CVECVE-2026-15962: The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i…CVE-2026-15962·by NVD·high
- CVECVE-2026-17432: A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functio…CVE-2026-17432·by NVD·medium
- RANSOMWAREVinilon hit by DeadlockVmluaWxvbkBEZWFkbG9jaw==·by Deadlock·medium
- DEFACEMENThttps://www.economiasalta.gob.ar/cdg.htm defaced by CoupDeGracehttp://www.zone-h.org/mirror/id/42747282·by CoupDeGrace🇦🇷
- CVECVE-2026-10681: In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thre…CVE-2026-10681·by NVD·medium
- RANSOMWAREA&A Safety hit by bravoxQSZBIFNhZmV0eUBicmF2b3g=·by bravox·medium
- RANSOMWAREmsgas.com.br hit by blackwaterbXNnYXMuY29tLmJyQGJsYWNrd2F0ZXI=·by blackwater·medium
- RANSOMWAREJubilee Jobs hit by qilinSnViaWxlZSBKb2JzQHFpbGlu·by qilin·medium
- RANSOMWAREThe Myers Y Cooper hit by qilinVGhlIE15ZXJzIFkgQ29vcGVyQHFpbGlu·by qilin·medium
- RANSOMWAREGuntert & Zimmerman hit by qilinR3VudGVydCAmIFppbW1lcm1hbkBxaWxpbg==·by qilin·medium
- RANSOMWAREPrinciple Diagnostics Laboratory hit by qilinUHJpbmNpcGxlIERpYWdub3N0aWNzIExhYm9yYXRvcnlAcWlsaW4=·by qilin·medium
- RANSOMWAREYourway Transportation hit by moneymessageWW91cndheSBUcmFuc3BvcnRhdGlvbkBtb25leW1lc3NhZ2U=·by moneymessage·medium
- CVECVE-2026-66013: OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows una…CVE-2026-66013·by NVD·unknown
- CVECVE-2026-66012: SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated onl…CVE-2026-66012·by NVD·critical
- CVECVE-2026-66011: ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid optio…CVE-2026-66011·by NVD·low
- DEFACEMENThttps://wuri.gov.bf/pwnd.html defaced by TeaM_CChttp://www.zone-h.org/mirror/id/42747183·by TeaM_CC
- CVECVE-2026-64529: In the Linux kernel, the following vulnerability has been resolved: crypto: qat - remove unused character device and IO…CVE-2026-64529·by NVD·unknown
- CVECVE-2026-64528: In the Linux kernel, the following vulnerability has been resolved: tty: serial: samsung: Remove redundant port lock ac…CVE-2026-64528·by NVD·unknown
- CVECVE-2026-64527: In the Linux kernel, the following vulnerability has been resolved: drm/hyperv: validate VMBus packet size in receive c…CVE-2026-64527·by NVD·unknown
- CVECVE-2026-64526: In the Linux kernel, the following vulnerability has been resolved: ethtool: tsconfig: fix missing ethnl_ops_complete()…CVE-2026-64526·by NVD·unknown
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
CyberSecurity news
Live from BleepingComputer, Krebs, The Hacker News, Dark Reading, The Record, SecurityWeek & more.
- YExploitGym – Can AI Agents Turn Security Vulnerabilities into Real Attacks?Hacker News·brief
- YCar Hacking and Vulnerability Reporting in 2026Hacker News·brief
- Malvertising Sends Malware in Pieces, Then Makes the Browser Build the ExecutableThe Hacker News·brief
- YTile's Security Is So Bad It's a Feature for StalkersHacker News·brief
- YAI in the Breach: How an Adversary Leveraged AI to Target a Water Utility's OTHacker News·brief
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched AvailableThe Hacker News·brief
- CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account HijackingThe Hacker News·brief
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCEThe Hacker News·brief
- DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate PayoutsThe Hacker News·brief
- Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as GitThe Hacker News·brief
- Rockwell Patches Code Execution Flaws in Arena Simulation SoftwareSecurityWeek·brief
- YUS Blocks SSL Security Certificates for Iran's Fars News AgencyHacker News·brief

