logo

Threat Intelligence, Vulnerability Analysis, and Cyber Attack Research

ID: dd04d829-865b-545c-951d-f99c1e081580

STIX ID: report--dd04d829-865b-545c-951d-f99c1e081580

Feed Name: NoHackie

Threat Score
90/100

Date Published: 2026-03-12

Date Updated: 2026-04-19

...
...

Feed reports an active, large-scale supply-chain exploitation campaign using CVE-2026-1731 (CVSS 9.9) that has weaponized ~695,000 links; multiple actors (UNC6201, UAT-10027, and SafePay RaaS) are active, employing DoH C2 via Cloudflare for evasion, an OAuth device-flow vector that bypasses MFA, and a BADBOX + Triada malware chain, with exploitation observed as quickly as three days post-PoC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.