HackMyIP

Threat Intel News

345 stories tagged Threat Intel

← All cybersecurity news

2026-08-14SecurityWeek
AmnesiaStealer: Rust-Based macOS Stealer Hijacks Browser Sessions via ClickFix

A sophisticated Rust-based macOS information stealer dubbed AmnesiaStealer is being distributed through counterfeit GitHub download pages in active ClickFix social engineering camp...

MalwareThreat Intel
Read More → Use Tool →
2026-08-14SecurityWeek
Hackers Exploit Unpatched GeoServer Zero-Day Within Hours of Disclosure

Threat actors began exploiting an unpatched zero-day vulnerability in GeoServer within hours of its public disclosure, according to attack surface management firm WatchTowr. The se...

Zero-DayVulnerabilityThreat Intel
Read More → Use Tool →
2026-08-14KrebsOnSecurity
DecryptAds: Free Tool Exposes Hidden Ad Trackers and Data Brokers

Every website visit and mobile app interaction leaves behind a trail of adtech relationships that most users never see. A newly launched service called DecryptAds ...

PrivacyThreat IntelAI Threats
Read More → Use Tool →
2026-08-14The Record
France Tax Authority Breach: Hacker Claims 600,000 Victims' Data Stolen

France's Directorate General of Public Finances (DGFiP) confirmed that an attacker breached its information systems in late June, exfiltrating data belonging to individuals and bus...

Data BreachPrivacyThreat Intel
Read More → Use Tool →
2026-08-13The Record
White House Greenlights Private Cyber Firms for Offensive Strikes on Criminal Networks

The Trump administration has authorized vetted private cybersecurity companies to conduct offensive operations against transnational cybercrime organizations under a presidential m...

RegulationThreat IntelAPT
Read More → Use Tool →
2026-08-13Dark Reading
Critical VMware vCenter Flaw CVE-2026-59310 Exploited in Global Campaign

Security teams across the globe are scrambling to contain active exploitation of CVE-2026-59310, a critical vulnerability in VMware vCenter Server that threat actors began weaponiz...

VulnerabilityCloud SecurityThreat Intel
Read More → Use Tool →
2026-08-13The Record
New Mirai Variant Evooo1Bot Targets Routers With Stealth Proxy Features

Security researchers at FortiGuard Labs have uncovered a new Linux-based Mirai variant dubbed Evooo1Bot that has been actively exploiting unpatched vulnerabilities in internet-faci...

MalwareThreat IntelVulnerability
Read More → Use Tool →
2026-08-13The Hacker News
SharePoint CVE-2026-55040 Under Active Attack After Rapid7 PoC Release

Threat actors are actively weaponizing a critical Microsoft SharePoint authentication bypass vulnerability, CVE-2026-55040, following the public release of a proof-of-concept (PoC)...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-08-13Dark Reading
Jewelbug APT Group Blends Espionage With Crypto Theft in Dual-Panel Attacks

Security researchers have identified a sophisticated hacking-for-hire operation dubbed Jewelbug that is striking a rare balance between nation-state cyber espio...

APTThreat IntelMalware
Read More → Use Tool →
2026-08-12The Hacker News
Cisco ASA and FTD Flaw (CVE-2026-20349) Actively Exploited for DoS

Cisco has confirmed that a high-severity vulnerability in Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software is being acti...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-08-12Dark Reading
How Walmart Scaled Security Operations Through Trust and Innovation

Walmart, the world's largest retailer by revenue, has overhauled its security operations center (SOC) by leaning into a culture-first model that prioritizes psychological safety, t...

Incident ResponseThreat IntelCloud Security
Read More → Use Tool →
2026-08-12Dark Reading
Walmart's Purple Teaming: How Colocating Red and Blue Teams Strengthens Defenses

Walmart has adopted a 'trusted agent' model for purple teaming, physically colocating its offensive red team and defensive blue team to break down silos and accelerate the detectio...

Threat IntelIncident Response
Read More → Use Tool →
2026-08-12The Hacker News
VMware vCenter Flaw Actively Exploited for Persistent Remote Access

Threat actors are actively weaponizing a critical directory-traversal vulnerability in Broadcom VMware vCenter (CVE-2026-59310, CVSS 9.8) to establish persistent remote access on c...

APTVulnerabilityThreat Intel
Read More → Use Tool →
2026-08-12The Hacker News
Enterprise Defenses Strong at Perimeter, Weak Inside: Picus 2026

Enterprise defenses are having one of their strongest years on record at the network perimeter, but collapse almost entirely once an attacker is inside. According to Picus Labs' ne...

Threat IntelIncident ResponseVulnerability
Read More → Use Tool →
2026-08-12Dark Reading
City-Forum APT Campaign Steals Salesforce and ServiceNow Data Since March 2025

A long-running cyber-espionage operation dubbed "City-Forum" has been systematically exfiltrating sensitive data from enterprise Salesforce and ServiceNow instances since at least ...

APTData BreachThreat Intel
Read More → Use Tool →
2026-08-12Dark Reading
Ransomware Hits Colombia Justice Ministry Before Transition

Colombia’s Ministry of Justice and Law was hit by a ransomware attack only days before the country’s presidential transition, according to Dark Reading. The incident disrupted the ...

RansomwareIncident ResponseThreat Intel
Read More → Use Tool →
2026-08-12SecurityWeek
SharePoint Auth Bypass CVE-2026-55040 Exploited After Rapid7 PoC Release

Microsoft's July Patch Tuesday addressed CVE-2026-55040, a SharePoint vulnerability rooted in weak authentication that allows remote, unauthenticated attackers to bypass securit...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-08-11The Hacker News
North Korean IT Workers Caught in Fake Crypto Startup Sting

Security researchers from BCA LTD, NorthScan, and ANY.RUN ran a deliberate insider-threat experiment in 2026, posing as a cryptocurrency startup called Ballena Azul and recruiting ...

APTThreat IntelPrivacy
Read More → Use Tool →
2026-08-11The Hacker News
DeadLock Ransomware Uses Polygon Smart Contracts to Hard-Proof Extortion

The DeadLock ransomware group has adopted a decentralized operational model that combines the Session messaging network with blockchain-backed services to make its extortion infras...

RansomwareEncryptionThreat Intel
Read More → Use Tool →
2026-08-11The Hacker News
Zoom Annotation Vulnerabilities Enable Hijacking of Meeting Participants

Three serious vulnerabilities in Zoom's annotation feature could have allowed meeting participants to hijack the computers of other attendees. The flaws, tracked as CVE-2026-53413 ...

VulnerabilityAI SecurityThreat Intel
Read More → Use Tool →
2026-08-11The Hacker News
Kimwolf v7 Botnet Masks HTTP/2 DDoS Traffic as Legitimate Browsing

Palo Alto Networks Unit 42 researchers Asher Davila, Chris Navarrete, and Doel Santos have uncovered Kimwolf v7, a significantly re-engineered iteration of the Kimwolf/AISURU Andro...

MalwareThreat IntelVulnerability
Read More → Use Tool →
2026-08-10Dark Reading
Sherlock Holmes: The OG Social Engineer and His Modern Hacking Lessons

Long before phishing emails and OSINT frameworks, Arthur Conan Doyle's Sherlock Holmes was already mastering the art of social engineering—wearing disguises, cultivating intelligen...

PhishingThreat IntelPrivacy
Read More → Use Tool →
2026-08-10Dark Reading
Coruna and DarkSword iOS Exploits Spread to Cybercrime Groups

Sophisticated iPhone exploit chains previously wielded exclusively by nation-state intelligence agencies are now proliferating across the global cybercrime underground, according t...

Zero-DayAPTThreat Intel
Read More → Use Tool →
2026-08-10The Record
Russian APT Breached Polish Heat Plant via Cellular Network & Default Credentials

Poland's CERT Polska has disclosed a previously unknown cyberattack that disrupted a combined heat and power (CHP) plant supplying heat to roughly 50,000 residents during last wint...

APTThreat IntelAuthentication
Read More → Use Tool →
2026-08-10Dark Reading
Stop Checklist Patching: Why Choke-Point Defense Beats CVSS Scores

For decades, vulnerability management has been driven by the Common Vulnerability Scoring System (CVSS) — a framework that assigns numeric severity ratings to CVEs based on intrins...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-08-10Dark Reading
Iran-Linked Cyberattacks Hit US Water Systems in 12 States via Exposed PLCs

Cyberattacks targeting US water utilities have expanded to at least a dozen states, with cybersecurity investigators pointing to Iran-linked threat actors as the likely perpetrator...

APTVulnerabilityThreat Intel
Read More → Use Tool →
2026-08-10The Hacker News
Malicious VS Code Extensions Steal Crypto Wallets and Credentials

Cybersecurity researchers at Yeeth Security have flagged two malicious Visual Studio Code extensions posing as Solidity development tools that deliver a full-fledged information st...

MalwareSupply ChainThreat Intel
Read More → Use Tool →
2026-08-10SecurityWeek
Iranian Hackers Hit 12 US States in Water Utility Cyberattack Campaign

New Jersey and Alabama have joined the growing list of US states confirming that their water and wastewater facilities were targeted in a coordinated hacking campaign that began in...

APTIncident ResponseThreat Intel
Read More → Use Tool →
2026-08-08The Hacker News
CISA Adds Critical Kemp LoadMaster Command Injection Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical-severity command injection vulnerability in Progress Kemp LoadMaster to its Known Exploited Vu...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-08-07The Hacker News
800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Security researchers have uncovered a sprawling npm registry campaign in which nearly 800 malicious packages distribute a cross-platform remote access trojan (RAT) and infostealer ...

MalwareSupply ChainThreat Intel
Read More → Use Tool →
2026-08-07The Hacker News
ClickFix Attacks Deploy macOS Crypto-Draining Stealer

A new wave of ClickFix-style social engineering attacks is delivering a Go-based macOS stealer engineered to silently siphon funds from cryptocurrency wallets while harvesting brow...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-08-07The Hacker News
UNC6671 Vishing Attacks Hijack Personal Phones to Steal SaaS Data

A financially motivated threat cluster tracked as UNC6671 has intensified its voice phishing (vishing) operations against enterprise employees in financial services, private equity...

PhishingThreat IntelCloud Security
Read More → Use Tool →
2026-08-07The Record
DEF CON Franklin, NRWA Launch Water Watch Center for Rural Utilities

The National Rural Water Association (NRWA) has launched a new partnership with DEF CON Franklin to establish the Water Watch Center (WWC), a program aimed at delivering threat ...

Threat IntelIncident ResponseRegulation
Read More → Use Tool →
2026-08-07The Hacker News
Microsoft 365 AitM Phishing Campaign Hijacks Payroll Accounts

Arctic Wolf Labs has revealed a widespread adversary-in-the-middle (AitM) phishing campaign targeting Microsoft 365 accounts at organizations across healthcare, education, manufact...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-08-07The Hacker News
NatJack Attacks Hijack TCP Sessions and Spoof DNS via NAT Table Manipulation

Security researcher Malcolm Stagg has unveiled a new attack class dubbed NatJack that weaponizes network address translation (NAT) connection state to hijack active TCP sessions, s...

VulnerabilityThreat Intel
Read More → Use Tool →
2026-08-06Dark Reading
Why Cybercriminals Outpace Fragmented Law Enforcement Response

Law enforcement agencies worldwide continue to face a structural problem that undermines the global fight against cybercrime: their siloed operations are no match for the coordinat...

Threat IntelRegulationIncident Response
Read More → Use Tool →
2026-08-06The Hacker News
Weekly Cyber Threats: SideWinder Phishing, npm Supply Chain & More

This week's threat landscape underscores how ordinary development and communication tools continue to be weaponized at scale. From nation-state-aligned telecom exposure to automate...

Supply ChainAPTThreat Intel
Read More → Use Tool →
2026-08-06The Hacker News
4,400+ Rockwell PLCs Exposed Online; 22 Found in US Water Attack Cities

A new Forescout analysis has identified 4,407 internet-facing Rockwell Automation programmable logic controllers (PLCs) worldwide as of August 3, including 2,844 located in the Uni...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-08-06The Hacker News
khunt Toolkit Turns Oracle SQL Injection Into Windows SYSTEM Access

Huntress researchers have detailed a stealthy intrusion in which attackers exploited a SQL injection flaw in a public-facing web application to install a post-exploitation toolkit ...

VulnerabilityIncident ResponseThreat Intel
Read More → Use Tool →
2026-08-06The Hacker News
Ransom Cartel Creator Maksim Silnikau Sentenced to 16 Years

A federal judge in Alexandria, Virginia sentenced Belarusian national Maksim Silnikau to 16 years in prison on August 5, 2026, for building and operating Ransom Cartel, a ransomwar...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-08-05The Hacker News
250+ ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware

Microsoft Threat Intelligence has tracked a macOS ClickFix operation spanning more than 250 front-end domains that fingerprints visitors before serving a malware lure, hiding the m...

MalwareThreat IntelPhishing
Read More → Use Tool →
2026-08-05The Hacker News
North Korean Hackers Use NullReceiver to Hide C2 IPs in Blockchain Transfers

Cybersecurity researchers have uncovered a sophisticated evolution of the EtherHiding technique, dubbed NullReceiver, that hides command-and-control (C2) server IP addresses inside...

Supply ChainThreat IntelAPT
Read More → Use Tool →
2026-08-04Dark Reading
Smoke#Screen Campaign Weaponizes ScreenConnect for RMM Takeovers

A threat actor tracked as "Smoke#Screen" is leveraging ConnectWise ScreenConnect and other legitimate remote monitoring and management (RMM) tooling to establish persistent foothol...

PhishingMalwareThreat Intel
Read More → Use Tool →
2026-08-04The Hacker News
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has evolved into a more dangerous offering, adding support for device code phishing to its existing arsenal ...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-08-04The Hacker News
SMOKE#SCREEN Campaign Deploys ScreenConnect via Fake Adobe and Zoom Updates

Cybersecurity researchers at Securonix Threat Research have disclosed an active, multi-wave campaign codenamed SMOKE#SCREEN that leverages social engineering lures themed around Ad...

Threat IntelMalwarePhishing
Read More → Use Tool →
2026-08-04The Hacker News
Vibe Hacking: How AI Is Turning Script Kiddies Into Capable Attackers

The cybersecurity industry has long measured risk by ranking attacker sophistication—nation-state actors at the top, organized criminal groups in the middle, and inexperienced "scr...

AI ThreatsAI SecurityThreat Intel
Read More → Use Tool →
2026-08-04The Hacker News
DOUBLECUP Loader Uses ClickFix & Steganographic PNGs to Deploy RATs

A Russian-language loader-as-a-service (LaaS) tracked as DOUBLECUP has been weaponizing ClickFix social engineering lures since at least early June 2026 to stage steganographic PNG...

MalwareThreat IntelPhishing
Read More → Use Tool →
2026-08-04Dark Reading
Device Code Phishing Surges 1,500% as Vishing Attacks Double in 2026

Attackers are rapidly abandoning traditional credential-stealing campaigns in favor of social engineering techniques that sidestep multi-factor authentication and leave minimal for...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-08-04SecurityWeek
New York Pours $9M into Water Utility Cybersecurity After Multi-State Attacks

New York Governor Kathy Hochul announced more than $9 million in funding on Monday to help 153 drinking water and wastewater systems harden their defenses against cyberattacks. Dis...

RegulationIncident ResponseThreat Intel
Read More → Use Tool →
2026-08-03Dark Reading
New AI Video Traceback Tool Pinpoints Deepfake Source for Defenders

Researchers have released a new forensic tool designed to trace AI-generated videos back to the model and infrastructure that produced them, aiming to give defenders a faster path ...

DeepfakeAI SecurityThreat Intel
Read More → Use Tool →
2026-08-03The Hacker News
AI in the SOC: Where Claude, Codex, and Cursor Actually Fit

Enterprise security teams are racing to integrate AI platforms like Anthropic's Claude, OpenAI's Codex, and Cursor into their Security Operations Centers (SOCs) for detection engin...

AI SecurityIncident ResponseThreat Intel
Read More → Use Tool →
2026-08-01The Hacker News
Coldcard Firmware Flaw Enables $70M Bitcoin Theft in 41 Minutes

An attacker siphoned 1,082.65 BTC—worth roughly $70.2 million—from 1,196 addresses in a 41-minute sweep on July 30, 2026, according to Galaxy Research, which traced the drain to a ...

VulnerabilityThreat IntelEncryption
Read More → Use Tool →
2026-08-01The Hacker News
Adform Supply Chain Attack Swaps Crypto Wallet Addresses in Browser

Advertising technology provider Adform disclosed a supply chain attack in which threat actors modified a shared JavaScript file, trackpoint-async.js, served from s2.adform[.]net, t...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-08-01The Hacker News
APT29 Hijacks Hotel Wi-Fi to Deliver CornFlake Surveillance RAT

A fake browser update served over hijacked hotel Wi-Fi networks has been used to deliver CornFlake, a Go-based remote access trojan (RAT) capable of capturing webcam images, microp...

APTMalwareThreat Intel
Read More → Use Tool →
2026-07-31The Hacker News
Chinese-Speaking Hackers Hit Central Asia With OctLurk and SilkLurk Backdoors

A Chinese-speaking threat actor has been linked to a sustained cyber espionage campaign targeting government organizations across Central Asia, including entities in Afghanistan, K...

APTMalwareThreat Intel
Read More → Use Tool →
2026-07-31The Hacker News
HollowFrame Loader Drops Matryoshka Backdoor in Law Firm Phishing Attack

Cybersecurity researchers at Blackpoint Cyber have disclosed a targeted spear-phishing campaign against an unspecified law firm that weaponized a previously undocumented Go-based l...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-07-31Dark Reading
Interpol's I-GRIP System Freezes Cross-Border Fraud Payments in Real Time

Interpol has intensified its global fight against online financial crime by operationalizing the Global Rapid Intervention of Payments (I-GRIP), a secure communications platform th...

Incident ResponseRegulationThreat Intel
Read More → Use Tool →
2026-07-31SecurityWeek
30+ Minnesota Water Utilities Hit in Cyberattacks Tied to Iranian Hackers

More than 30 water and wastewater systems across Minnesota were hit by coordinated cyberattacks on Sunday and Monday, prompting investigations by the FBI and state authorities. Min...

APTThreat IntelIncident Response
Read More → Use Tool →
2026-07-31The Hacker News
Device Code Phishing: Why It's 2026's Fastest-Growing Threat

Device code phishing, the abuse of the OAuth 2.0 device authorization grant to hijack access tokens, has escalated from a niche red-team technique into an industrial-scale threat i...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-07-31The Hacker News
Chinese Hacker Commands DeepSeek via Telegram in Autonomous Attack Wave

Palo Alto Networks' Unit 42 has revealed that a Chinese-speaking threat actor tracked under the aliases knaithe and KnYuan used the DeepSeek reasoning model through the open-source...

AI ThreatsAPTThreat Intel
Read More → Use Tool →
2026-07-30KrebsOnSecurity
H96 TV Streaming Sticks Found Running Massive Mobile Ad Fraud Network

Cheap TV streaming sticks marketed as offering unlimited content for a one-time fee are secretly powering a sophisticated ad fraud operation that spoofs mobile devices to click on ...

Supply ChainAI ThreatsThreat Intel
Read More → Use Tool →
2026-07-30The Hacker News
DPRK Hackers Use Fake macOS Updates to Steal Crypto via EtherHiding

North Korean-linked threat actors have been tied to a sophisticated macOS malvertising campaign that abuses fake software update screens to deliver cryptocurrency-stealing malware ...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-30Dark Reading
Iran-Backed Hackers Target 30+ Minnesota Water Systems in Cyberattack

A suspected Iran-linked advanced persistent threat (APT) group has launched cyberattacks against more than 30 community water utilities across Minnesota, exposing deep vulnerabilit...

APTThreat IntelIncident Response
Read More → Use Tool →
2026-07-30SecurityWeek
CISA Urges Water Sector to Secure OT After Iran-Linked PLC Attacks

CISA has issued an urgent advisory urging water and wastewater system (WWS) operators to safeguard operational technology (OT) following a wave of cyberattacks targeting programmab...

APTThreat IntelVulnerability
Read More → Use Tool →
2026-07-30SecurityWeek
Bank of America to Acquire UK Cybersecurity Firm MDSec

Bank of America announced on Thursday that it will acquire MDSec Consulting Limited, a UK-based technical information security consultancy headquartered in Macclesfield, England. T...

RegulationThreat Intel
Read More → Use Tool →
2026-07-30The Hacker News
Silver Fox Deploys 3-Driver BYOVD Chain to Drop ValleyRAT in Japan

The Chinese-linked threat actor Silver Fox has been linked to a new campaign targeting a Japanese industrial manufacturer using a three-driver bring-your-own-vulnerable-driver (BYO...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-30Dark Reading
SE Asian Cybercrime Syndicates Rake in $88B, Go Global in 2025

Southeast Asian cybercriminal syndicates have evolved from opportunistic fraud operations into a transnational threat ecosystem, according to reporting from Dark Reading. Once conf...

APTThreat IntelRegulation
Read More → Use Tool →
2026-07-30Dark Reading
Flying Eagle Mobile RAT Drains Bank Accounts in Chinese MaaS Scheme

A sophisticated mobile remote access trojan (RAT) builder dubbed ‘Flying Eagle’ has emerged as a premium offering in China’s bustling malware-as-a-service (MaaS) underground, attra...

MalwareThreat IntelAPT
Read More → Use Tool →
2026-07-29Dark Reading
Red Team AI Agents Are Training Blue Defenders in Cybersecurity

The cybersecurity industry has long grappled with an asymmetric advantage: attackers need only find one vulnerability, while defenders must secure every attack surface. With the ri...

AI SecurityAI ThreatsThreat Intel
Read More → Use Tool →
2026-07-29The Hacker News
Minnesota Water Systems Hit by Coordinated Cyberattack — 30+ Plants Affected

More than 30 community water systems across Minnesota were hit by a coordinated cyberattack on July 26 and 27, 2026, targeting operational technology and triggering a statewide eme...

Threat IntelIncident ResponseAPT
Read More → Use Tool →
2026-07-29The Hacker News
9-Year Fraud Campaign Clones Russian Company Sites to Steal Payments

Russian cybersecurity vendor F6 has uncovered a sprawling fraud operation that has been cloning the websites of major Russian companies since 2017 to defraud international business...

PhishingThreat Intel
Read More → Use Tool →
2026-07-29The Hacker News
Russia Charges Telegram's Pavel Durov Over Platform's Role in Terrorism

The Federal Security Service (FSB) of Russia has formally charged Telegram founder Pavel Durov with facilitating terrorist activities under Part 1.1 of Article 205.1 of the Russian...

RegulationPhishingThreat Intel
Read More → Use Tool →
2026-07-29The Hacker News
Compromised joyfill npm Packages Run DEV#POPPER RAT on Node.js Import

Two beta versions of npm packages in the @joyfill namespace—@joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4—have been compromised to deliver a rem...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-28Dark Reading
Thousands of Exposed Data Center BMCs Vulnerable to Password Cracking

Thousands of internet-exposed Baseboard Management Controllers (BMCs) and similar remote hardware management interfaces are vulnerable to offline password-cracking attacks, and thr...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-07-28The Hacker News
Tengu Botnet Uses Hardware Watchdog to Reboot Linux IoT Devices and Survive Defenders

Security researchers at Nozomi Networks Labs have uncovered a new Mirai-derived botnet dubbed Tengu that targets Linux-based IoT devices with an unusually resilient persistence ...

MalwareThreat IntelVulnerability
Read More → Use Tool →
2026-07-28SecurityWeek
Microsoft Launches MAI-Cyber-1-Flash AI Model for Vulnerability Detection

Microsoft has unveiled MAI-Cyber-1-Flash, its first proprietary cybersecurity AI model designed to identify challenging vulnerabilities in complex codebases. The model has been int...

AI SecurityVulnerabilityThreat Intel
Read More → Use Tool →
2026-07-28The Hacker News
Arista VeloCloud CVE-2026-16812 Under Active Attack: Patch Critical RCE Flaw Now

A maximum-severity command injection vulnerability in on-premises Arista VeloCloud Orchestrator (VCO) is being actively exploited in the wild, prompting an urgent call for administ...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-07-28Dark Reading
Hermes AI Agent Used in Espionage Attack on Thai Finance Ministry

Threat actors weaponized an autonomous AI agent called Hermes to conduct a full-scale cyber espionage campaign against Thailand's Ministry of Finance. The open-source tool, operate...

AI ThreatsAPTThreat Intel
Read More → Use Tool →
2026-07-27Dark Reading
How Breaking Affiliate Trust Brought Down LockBit Ransomware Empire

In February 2024, the FBI and its international partners executed Operation Cronos, delivering what law enforcement officials called the most decisive blow against ransomware infra...

RansomwareIncident ResponseThreat Intel
Read More → Use Tool →
2026-07-27The Hacker News
Dysphoria IoT Botnet Adopts Blockchain C2 After JackSkid Takedown

Dysphoria, an Internet of Things botnet tracked by China's CNCERT and Qi'anxin's XLab threat-intelligence team, has retooled its command-and-control (C2) layer with blockchain nami...

MalwareThreat Intel
Read More → Use Tool →
2026-07-27The Hacker News
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Malware

Proofpoint researchers have uncovered a sophisticated crypter-as-a-service called Cruciferra that is enabling multiple unrelated cybercrime clusters to deliver remote access trojan...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-07-27The Hacker News
East Asia APT Abuses Telegram API for C2 in Middle East Attacks

Zscaler ThreatLabz has uncovered a sophisticated cyber espionage campaign attributed to an East Asia-linked threat actor targeting government entities across the Middle East. Detec...

APTMalwareThreat Intel
Read More → Use Tool →
2026-07-25The Hacker News
SourTrade Malvertising Assembles Malware Inside Victim's Browser

A long-running malvertising campaign dubbed SourTrade is bypassing traditional detection by never delivering a complete malicious file over the network. Instead, the operation, doc...

MalwareThreat Intel
Read More → Use Tool →
2026-07-25The Hacker News
Critical Fastjson RCE Flaw CVE-2026-16723 Actively Exploited - No Patch Yet

Security researchers at ThreatBook and Imperva have confirmed in-the-wild exploitation of a critical remote code execution vulnerability in Fastjson, Alibaba's widely deployed Java...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-07-25The Hacker News
Insurance Phishing Now Hijacks Accounts in Real Time via Google Ads

A new investigation from CTM360, published via The Hacker News, reveals that insurance-focused phishing operations have evolved beyond traditional credential harvesting into real-t...

PhishingThreat IntelAuthentication
Read More → Use Tool →
2026-07-25The Hacker News
DevMan RaaS Portal v3 Centralizes Payload Builds and Affiliate Operations

The operators behind the DevMan ransomware-as-a-service (RaaS) scheme continue to run a dedicated web platform that lets affiliates generate payloads, track earnings, and coordinat...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-07-24The Record
Wrench Attacks on Crypto Holders Surge 33% in First Half of 2026

Cryptocurrency holders are increasingly being targeted through physical-world coercion rather than purely digital exploits, according to a new report from blockchain security audit...

Threat IntelPrivacyAuthentication
Read More → Use Tool →
2026-07-24The Hacker News
Hacker Uses Hermes AI Agent Unattended to Breach Thailand Finance Ministry

A threat actor deployed Nous Research's open-source Hermes assistant on a rented server, enabled its YOLO mode, and pointed it at Thailand's Ministry of Finance, where the agent au...

AI SecurityThreat IntelData Breach
Read More → Use Tool →
2026-07-24The Hacker News
Golden Chickens MaaS Unveils 4 New Malware Families Targeting Browsers

The operators behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families—TinyEgg, ChonkyChicken, a modularized variant of Chonk...

MalwareThreat IntelAPT
Read More → Use Tool →
2026-07-23The Hacker News
Chaos Ransomware Hides C2 Traffic Inside Headless Browsers

The Chaos ransomware group has adopted a novel technique to conceal its command-and-control communications, routing traffic through the victim's own Chrome or Edge browser using a ...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-07-23The Hacker News
China-Linked JadeProx Uses TriBack Loader in Multi-Region Attacks

Group-IB researchers have exposed a China-nexus threat cluster tracked as JadeProx after discovering an unprotected Alibaba Cloud server in the Singapore region in mid-April 2026. ...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-23SecurityWeek
Iranian APT Hackers Target Siemens, Schneider, Rockwell ICS Devices

The U.S. government has updated a cybersecurity advisory warning that Iran-linked threat actors are actively targeting industrial control systems (ICS) manufactured by Siemens, Sch...

APTThreat IntelVulnerability
Read More → Use Tool →
2026-07-22Dark Reading
Fake Bahrain Alert App Spreads Android Spyware via Fake Google Play Sites

A deceptive application masquerading as an official Bahrain emergency alert has been discovered distributing sophisticated Android surveillance malware through fraudulent Google Pl...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-22The Hacker News
Multi-Layered Network Detections: The New Backbone of Modern SOCs

For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the cat-and-mouse game continued. That dynamic has shifted. AI-equipped attackers ar...

AI ThreatsThreat IntelIncident Response
Read More → Use Tool →
2026-07-22The Hacker News
Trojanized NuGet Fork Rigged to Cheat Online Betting Platform

Cybersecurity researchers at JFrog have uncovered an unusually targeted supply chain attack on the NuGet package registry: a trojanized fork of the popular Newtonsoft.Json library ...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-21SecurityWeek
Empirical Security Raises $25M for AI-Powered Threat Prediction Platform

Chicago-based cybersecurity startup Empirical has closed a $25 million Series A funding round, bringing total capital raised to $37 million. The round was led by Brightmind Part...

AI SecurityThreat IntelVulnerability
Read More → Use Tool →
2026-07-21Dark Reading
Ransomware Surge Driven by Ecosystem Fragmentation, Not AI

The ransomware landscape is undergoing a significant transformation driven by ecosystem fragmentation rather than artificial intelligence advancements, according to researchers tra...

RansomwareThreat IntelMalware
Read More → Use Tool →
2026-07-21The Hacker News
Critical SharePoint RCE CVE-2026-50522 Actively Exploited After PoC Drop

Microsoft has confirmed that a third SharePoint Server vulnerability patched in its July 2026 Patch Tuesday cycle is now under active exploitation in the wild. Tracked as CVE-20...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-07-21The Hacker News
wp2shell: Critical WordPress RCE Flaws Fuel Mass Exploitation

Attackers are actively exploiting two critical vulnerabilities in WordPress—tracked as CVE-2026-63030 and CVE-2026-60137 and collectively codenamed "wp2shell"—to achieve unauthenti...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-07-21SecurityWeek
HollowGraph Malware Uses Microsoft 365 Calendar as Dead-Drop C&C Channel

HollowGraph, a newly documented malware toolkit, is leveraging a compromised Microsoft 365 account's calendar as a two-way dead-drop for command-and-control (C&C) communication, ac...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-07-20Dark Reading
WP2Shell Flaw Exposes Millions of WordPress Sites to Remote Takeover

Threat actors are actively chaining two newly disclosed vulnerabilities in the WP2Shell management plugin to achieve unauthenticated remote code execution on WordPress sites at sca...

Zero-DayVulnerabilityThreat Intel
Read More → Use Tool →
2026-07-20The Hacker News
Russian Hacker Uses Gemini CLI AI to Control Dental Clinic Botnet

A Russian-speaking threat actor tracked as "bandcampro" has been observed weaponizing Google's open-source Gemini CLI artificial intelligence tool to operate a live, small-scale bo...

AI ThreatsMalwareThreat Intel
Read More → Use Tool →
2026-07-20The Hacker News
SleeperGem Attack Plants Backdoors in RubyGems to Hit Developer Machines

Cybersecurity researchers at StepSecurity have uncovered a new software supply chain campaign dubbed SleeperGem targeting the Ruby ecosystem through three malicious RubyGems packag...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-19The Hacker News
SonicWall SMA Zero-Days Exploited by UTA0533 for Root Access Before Patch

An unattributed threat actor tracked as UTA0533 exploited two previously unknown vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000-series VPN appliances as zero-days beg...

Zero-DayAPTThreat Intel
Read More → Use Tool →
2026-07-17The Hacker News
7 Malicious Vite npm Packages Use Blockchain C2 to Deploy RAT

Cybersecurity researchers at Checkmarx have uncovered a software supply chain attack targeting the Vite frontend tooling ecosystem, with seven malicious npm packages collectively d...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-17The Hacker News
GoldenEyeDog Subgroup Steals DigiCert Code-Signing Certificates

Cybersecurity researchers at Expel have attributed the April 2026 DigiCert security incident to a threat activity cluster tracked as CylindricalCanine, a sub-group of the Chinese c...

APTData BreachThreat Intel
Read More → Use Tool →
2026-07-17Dark Reading
Google Cloud Integrates Wiz Into Agentic AI Defense Platform

Google Cloud is rolling out an 'agentic defense' strategy that folds key capabilities from its Wiz acquisition into a unified platform designed to automate threat detection and rem...

AI SecurityCloud SecurityThreat Intel
Read More → Use Tool →
2026-07-17The Record
Fairlife Halts US Production After Ransomware Attack on Coca-Cola Unit

Coca-Cola's premium dairy subsidiary Fairlife has suspended operations at its US processing plants following a ransomware intrusion detected on Thursday. The company confirmed the ...

RansomwareIncident ResponseThreat Intel
Read More → Use Tool →
2026-07-17The Hacker News
Wrong Man Detained? Armenia Holds Russian Tourist in REvil Extradition Case

Armenian border officers at Yerevan's Zvartnots airport pulled Russian tourist Aleksandr Ermakov from the departure hall on June 28, 2026, detaining him on a U.S. extradition reque...

RansomwareThreat IntelIncident Response
Read More → Use Tool →
2026-07-17The Hacker News
Military Autonomy Race Tests Limits of Trusted Defense Infrastructure

Western militaries are accelerating the deployment of autonomous systems at a pace that is outstripping the development of the trusted information infrastructure needed to support ...

AI SecurityRegulationThreat Intel
Read More → Use Tool →
2026-07-16The Hacker News
TELEPUZ Malware Uses ClickFix Lures to Drop Vidar Stealer via PowerShell

Elastic Security Labs researcher Cyril François has disclosed a new modular malware family dubbed TELEPUZ that has been proliferating through ClickFix-infected websites since late ...

MalwareThreat IntelPhishing
Read More → Use Tool →
2026-07-16The Hacker News
Game Cheat NuGet Packages and Fake Installers Deploy RATs and Spyware

Cybersecurity researchers have uncovered 11 malicious NuGet packages posing as .NET command-line tools marketed as game cheats, bots, and automation panels. According to Socket, th...

MalwareSupply ChainThreat Intel
Read More → Use Tool →
2026-07-15The Hacker News
OkoBot Malware Injects Seed Phrase Phishing Into Ledger and Trezor Apps

A malware framework dubbed OkoBot has been active on Windows systems since April 2025, using a module called SeedHunter to hijack legitimate hardware wallet software and steal user...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-07-15SecurityWeek
SonicWall SMA1000 Zero-Days Under Active Attack — Patch Immediately

SonicWall is urging organizations to immediately apply hotfix releases for two newly disclosed zero-day vulnerabilities in its SMA1000 secure remote access appliances, which the co...

Zero-DayVulnerabilityThreat Intel
Read More → Use Tool →
2026-07-14The Hacker News
11 Vulnerable UEFI Shims Expose Systems to Secure Boot Bypass

ESET researcher Martin Smolár has uncovered 11 outdated, Microsoft-signed Unified Extensible Firmware Interface (UEFI) shim bootloaders that can be weaponized to bypass Secure Boot...

VulnerabilitySupply ChainThreat Intel
Read More → Use Tool →
2026-07-14The Hacker News
LabubaRAT: New Rust-Based Trojan Impersonates NVIDIA Software on Windows

Cybersecurity researchers at Blackpoint Cyber have uncovered a previously undocumented Rust-based remote access trojan dubbed LabubaRAT that masquerades as legitimate NVIDIA softwa...

MalwareThreat Intel
Read More → Use Tool →
2026-07-13Dark Reading
UK and EU Impose First Joint Sanctions on Russian Cyber Actors

The UK and EU have taken a landmark step in cybersecurity diplomacy, jointly imposing sanctions on Russian individuals and entities for the first time in response to state-sponsore...

RegulationAPTThreat Intel
Read More → Use Tool →
2026-07-13Dark Reading
Yellow Teams: How Companies Are Testing AI for Both Attack and Defense

As enterprises race to integrate artificial intelligence into their security stacks, a new operational concept is gaining traction inside engineering departments: the Yellow Team. ...

AI SecurityAI ThreatsThreat Intel
Read More → Use Tool →
2026-07-13The Hacker News
ModHeader Pulled From Chrome and Edge After Hidden Data Collector Found

Google and Microsoft have removed ModHeader, a popular HTTP header-editing browser extension with roughly 1.6 million combined installs, after security researchers identified a dor...

Supply ChainPrivacyThreat Intel
Read More → Use Tool →
2026-07-13The Hacker News
CrashStealer macOS Malware Bypasses Gatekeeper via Notarized Dropper

Cybersecurity researchers at Jamf Threat Labs have identified a sophisticated new macOS information stealer dubbed CrashStealer, distinguished by its native C++ implementation rath...

MalwareThreat IntelData Breach
Read More → Use Tool →
2026-07-13The Hacker News
Misconfigured Server Exposes Three Evilginx Phishing Operations Targeting M365

A single misconfiguration handed French security firm Lexfo an intelligence windfall. During a routine internet scan in late April 2026, researchers found an attacker-controlled ho...

PhishingThreat IntelAuthentication
Read More → Use Tool →
2026-07-11The Hacker News
APT Groups Target Pakistani Law Enforcement in Multi-Year Espionage Campaign

SentinelOne SentinelLABS has uncovered a sustained cyber espionage operation targeting multiple Pakistani law enforcement agencies, with activity spanning February 2024 through Apr...

APTThreat IntelMalware
Read More → Use Tool →
2026-07-11The Hacker News
Jscrambler npm 8.14.0 Compromised: Rust Infostealer Drops on Install

On July 11, 2026, the popular jscrambler npm package was compromised in a textbook software supply chain attack, with attackers publishing version 8.14.0 carrying a preinstall hook...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-10The Hacker News
Exposed WP-SHELLSTORM Server Reveals Mass WordPress Backdoor Operation

A cybercrime operation tracked as WP-SHELLSTORM inadvertently exposed its own infrastructure for 22 days, leaving a rented US-based server at 137.175.93[.]126 wide open with no aut...

MalwareVulnerabilityThreat Intel
Read More → Use Tool →
2026-07-09The Hacker News
Dormant GitHub Accounts Weaponized for Corporate Reconnaissance via API Scraping

Datadog Security Labs is sounding the alarm over a coordinated series of campaigns that systematically enumerate corporate GitHub organizations, repositories, and user accounts thr...

Supply ChainThreat IntelCloud Security
Read More → Use Tool →
2026-07-09The Hacker News
GigaWiper: New Windows Backdoor Pairs Disk Wiping With Spyware

Microsoft has dissected a destructive Windows backdoor dubbed GigaWiper, a Go-based implant that bundles three distinct destructive payloads into a single command-driven toolkit. T...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-09Dark Reading
Iranian APT Groups Target Every Internet-Facing Vulnerability

Iranian state-sponsored hacking groups have significantly broadened their targeting scope, moving past traditional critical infrastructure attacks to compromise any organization wi...

APTThreat IntelVulnerability
Read More → Use Tool →
2026-07-09The Hacker News
INTERPOL Arrests 6K in Fraud Sweep, npm Supply Chain Hits Payment SDKs

A coordinated global anti-fraud operation, codenamed First Light 2026, led to the arrest of 5,811 individuals across 97 countries and territories, with authorities intercepting $29...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-07-09The Hacker News
Vulnerability Clearinghouses: Why Data Isn't the Real Fix

The cybersecurity world converged on a single word this summer: clearinghouse. Chainguard launched Athena, a long-rumored platform that had been quietly processing pre-disclosure v...

Supply ChainVulnerabilityThreat Intel
Read More → Use Tool →
2026-07-09The Hacker News
Microsoft Patches RoguePlanet Defender Flaw Allowing SYSTEM-Level Access

Microsoft has shipped a fix for a high-severity privilege escalation vulnerability in its built-in antivirus engine, roughly one month after exploit details surfaced publicly. Trac...

VulnerabilityThreat Intel
Read More → Use Tool →
2026-07-09The Hacker News
GodDamn Ransomware Uses Signed PoisonX Driver to Disable Endpoint Defenses

Symantec's Threat Hunter Team has identified a new ransomware family, dubbed GodDamn, that leverages a Microsoft-signed kernel driver called PoisonX to neutralize endpoint secur...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-07-08KrebsOnSecurity
IRIS C2: Felons Behind Zero-Day Exploit Marketplace Exposed

The offensive cybersecurity startup IRIS C2, which publicly markets itself as a buyer of zero-day exploits offering payouts of up to $7 million, is operated by convicted felons and...

Zero-DayThreat IntelVulnerability
Read More → Use Tool →
2026-07-08Dark Reading
Mexico's Cybersecurity Plan Faces Its First Real Test at the 2026 World Cup

Mexico's national cybersecurity strategy is heading into a high-stakes stress test it was never designed for: hosting matches during the 2026 FIFA World Cup, the largest sporting e...

RegulationIncident ResponseThreat Intel
Read More → Use Tool →
2026-07-08The Hacker News
AI Coding Agents Trigger Endpoint Security Alerts Built for Attackers

Sophos researchers examining a week of endpoint telemetry from June 2026 have found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are routinely tripping detec...

AI SecurityThreat IntelAI Threats
Read More → Use Tool →
2026-07-08The Hacker News
UAT-7810 APT Expands ORB Network with New LONGLEASH Malware

Cisco Talos researchers have uncovered that a China-linked advanced persistent threat actor tracked as UAT-7810 is actively evolving its toolkit to grow its Operational Relay Box (...

APTMalwareThreat Intel
Read More → Use Tool →
2026-07-07Dark Reading
Fake Big-Brand Job Listings Steal Google Logins from Marketers

A sophisticated phishing campaign is weaponizing the names of well-known consumer brands to lure marketing professionals into surrendering their Google Workspace credentials. Resea...

PhishingThreat IntelAuthentication
Read More → Use Tool →
2026-07-07The Hacker News
DEBULL Tooling Exploits Microsoft Device-Code Flow in M365 Phishing

A new Microsoft 365 device-code phishing campaign observed between late June and early July 2026 is leveraging a reusable attack framework dubbed DEBULL to hijack enterprise accoun...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-07-07The Hacker News
RedWing Android Malware Rented on Telegram Targets Banking Apps

A new Android malware-as-a-service operation dubbed RedWing is being advertised on Telegram as a turnkey bank-fraud kit, enabling low-skill criminals to hijack victim devices, harv...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-07-06Dark Reading
BusySnake Infostealer Targets Critical Infrastructure in Russia, Brazil, and Kazakhstan

A sophisticated threat actor tracked as Armored Likho has been deploying a custom-built infostealer dubbed BusySnake against government agencie...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-07-06The Hacker News
Iran-Linked Cavern C2 Framework Hits Israeli Orgs via SysAid

An Iranian threat cluster linked to the Ministry of Intelligence and Security (MOIS) is using a previously undocumented modular command-and-control framework dubbed Cavern (aka Cav...

APTThreat IntelSupply Chain
Read More → Use Tool →
2026-07-06The Hacker News
How to Evaluate AI SOC Platforms: 6 Capabilities That Matter Most

The AI security operations center (SOC) market has matured into a crowded landscape where SIEM, SOAR, and pureplay AI SOC vendors all claim to offer autonomous detection and respon...

AI SecurityIncident ResponseThreat Intel
Read More → Use Tool →
2026-07-06The Hacker News
NetNut 2M-Device Proxy Botnet Disrupted; WhatsApp Usernames Spark Impersonation Fears

Google, the FBI, Lumen, and other partners moved this week to dismantle the NetNut residential proxy network—also tracked as Popa—disabling Google accounts and services used for ma...

MalwarePrivacyThreat Intel
Read More → Use Tool →
2026-07-06The Hacker News
TrojPix Attack Leaks Air-Gapped Data via Video Cable Emissions

Researchers at Shandong University have unveiled TrojPix, a covert channel technique that exfiltrates data from air-gapped systems by modulating imperceptible pixels on the screen ...

Threat IntelMalwareData Breach
Read More → Use Tool →
2026-07-05BleepingComputer
Flipper Zero Firmware Goes Community-Driven: What It Means for Pen-Testers

Flipper Devices has confirmed that development of the Flipper Zero firmware will continue, but with a leaner internal team and a heavier reliance on community contributions. The...

VulnerabilityThreat Intel
Read More → Use Tool →
2026-07-04The Hacker News
Union County Ohio Paid $1M in Bitcoin to Kairos Extortion Group

A U.S. government entity—almost certainly Union County, Ohio—paid roughly $1 million in bitcoin to a group calling itself Kairos to suppress the leak of stolen files, according to ...

RansomwareData BreachThreat Intel
Read More → Use Tool →
2026-07-03BleepingComputer
NetNut Botnet Dismantled: 2 Million Infected Devices Cut Off

A coordinated law enforcement and industry operation has dismantled NetNut, one of the world's largest residential proxy networks, cutting off access to an estimated two million co...

MalwareIncident ResponseThreat Intel
Read More → Use Tool →
2026-07-03BleepingComputer
ARToken PhaaS Exposes EvilTokens Microsoft 365 Phishing Toolkit

Cisco Talos researchers have uncovered a phishing-as-a-service (PhaaS) platform named “ARToken” that operates as an affiliate of the EvilTokens ecosystem, exposing a sophisticated ...

PhishingThreat IntelAuthentication
Read More → Use Tool →
2026-07-03The Hacker News
PamStealer macOS Malware Steals Login Passwords via Fake Maccy Sites

A new macOS information stealer dubbed PamStealer has been identified by Jamf Threat Labs, employing a multi-stage infection chain designed to harvest login credentials, browser da...

MalwareAuthenticationThreat Intel
Read More → Use Tool →
2026-07-02The Hacker News
Google Disrupts NetNut Proxy Network Spanning 2 Million Hacked Home Devices

Google has significantly disrupted NetNut, one of the largest residential proxy networks in operation, in a coordinated takedown with the FBI, Lumen's Black Lotus Labs, and acad...

MalwareThreat IntelPrivacy
Read More → Use Tool →
2026-07-02KrebsOnSecurity
FBI Seizes NetNut Proxy Network and Popa Botnet Tied to 2M Infected Devices

The FBI and IRS Criminal Investigation have seized hundreds of domains associated with NetNut, a sprawling residential proxy service operated by publicly-traded Israeli company Ala...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-07-01Dark Reading
How AI Helped One CISO Cut SIEM Noise and Costs

When a security operations team ingests every firewall log, DNS query, and authentication event into their SIEM, they quickly discover that more data does not always mean better de...

AI SecurityIncident ResponseThreat Intel
Read More → Use Tool →
2026-07-01The Hacker News
SEO-Poisoned Sites Drop AsyncRAT via ScreenConnect Side-Load

Threat actors are weaponizing search engine optimization (SEO) poisoning to push fraudulent software download pages that deploy AsyncRAT through the legitimate ScreenConnect remote...

MalwareThreat IntelPhishing
Read More → Use Tool →
2026-07-01The Hacker News
Ousaban Trojan Targets Iberian Banks With Fake PDF Lures

The Brazilian banking trojan Ousaban—also tracked as Javali—has resurfaced in a new campaign aimed at Windows users banking in Spain and Portugal. Researchers at Fortinet's FortiGu...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-07-01The Hacker News
Azure CLI Password Spray Compromises 78 Microsoft Accounts in 81M+ Attempts

Cybersecurity researchers at Huntress have uncovered a massive, ongoing automated password spray campaign targeting Microsoft's Azure command-line interface (CLI), generating more ...

Cloud SecurityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-30The Hacker News
RustDuck Botnet Rewrites in Rust to Hijack Routers for DDoS

Researchers at QiAnXin's XLab have been tracking a fast-evolving botnet called RustDuck since February 2026, warning that its true danger lies not in its current size but in the sp...

MalwareVulnerabilityThreat Intel
Read More → Use Tool →
2026-06-30The Hacker News
Silent Swap Clipper Hijacks Crypto Wallets via Fake Google Notes Extension

McAfee Labs has uncovered an active browser extension campaign dubbed Silent Swap that stealthily replaces cryptocurrency wallet addresses during transactions, red...

MalwareThreat IntelPrivacy
Read More → Use Tool →
2026-06-27SecurityWeek
200,000 Scam Sites Built on Chinese Uni-App Framework

More than 236,000 second-level domains powering investment scam infrastructure have been built using Uni-App, a Chinese open-source cross-platform development framework maintained ...

PhishingThreat Intel
Read More → Use Tool →
2026-06-26The Hacker News
FBI: Russian APT Hackers Steal Signal Backup Recovery Keys via Phishing

The FBI and CISA have updated their March advisory (PSA I-062626-PSA) warning that Russian intelligence services are now actively phishing Signal users into surrendering their Back...

APTPhishingThreat Intel
Read More → Use Tool →
2026-06-26The Hacker News
Chinese APT TinyRCT Backdoor Targets Southeast Asia Infrastructure

A Chinese-speaking advanced persistent threat (APT) actor tracked as CL-STA-1062 has been linked to a newly discovered custom backdoor called TinyRCT, deployed in a sustained cyber...

APTMalwareThreat Intel
Read More → Use Tool →
2026-06-26The Hacker News
Miasma Malware Hits npm Packages and GitHub Actions in Supply Chain Attack

Cybersecurity researchers at Socket have uncovered a new wave of the Mini Shai-Hulud, Miasma, and Hades malware campaign, this time targeting npm packages associated with LeoPlatfo...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-06-26The Hacker News
Microsoft Warns of Hotel Phishing Campaign Dropping Node.js TonRAT

Microsoft has disclosed an active phishing campaign targeting hotel and hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP archives to delive...

PhishingMalwareThreat Intel
Read More → Use Tool →
2026-06-25The Hacker News
Why NDR Beats Alerts in the Mythos Era: Bejtlich's Case for Network Interdiction

Despite the growing abundance of security telemetry, most SOC teams still struggle with fundamental questions during incident investigation: What actually happened? What evidence s...

Threat IntelIncident ResponseAI Security
Read More → Use Tool →
2026-06-24The Hacker News
CISA Warns of Active Exploitation of Critical Lantronix EDS5000 Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning on Tuesday that a critical security flaw in Lantronix EDS5000 Series serial-to-IP converte...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-06-24The Hacker News
DoJ Seizes Huione Cloud Account in Cyber Scam Laundering Crackdown

The U.S. Department of Justice announced on Tuesday the seizure of a cloud computing account operated by subsidiaries of Cambodia-based conglomerate HuiOne Group, a network accused...

RegulationCloud SecurityThreat Intel
Read More → Use Tool →
2026-06-24BleepingComputer
Mistic Backdoor: New Stealth Malware Linked to KongTuke Access Broker

Symantec researchers have uncovered a new stealthy backdoor dubbed "Mistic" being deployed by KongTuke (also tracked as Woodgnat), a financially motivated initial access broker act...

MalwareRansomwareThreat Intel
Read More → Use Tool →
2026-06-24SecurityWeek
Cisco Unified CM Flaw CVE-2026-20230 Actively Exploited in the Wild

A critical vulnerability in Cisco's Unified Communications Manager (Unified CM) is being actively exploited in the wild, according to exploit intelligence firm Defused. The flaw, t...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-06-23The Hacker News
FortiBleed: 110M Credentials Stolen from 430K FortiGate Firewalls

A Russian-speaking initial access broker (IAB) has been linked to a massive credential-harvesting campaign called FortiBleed, which has compromised over 430,000 FortiGate firewalls...

Threat IntelVulnerabilityAuthentication
Read More → Use Tool →
2026-06-23The Hacker News
Malicious npm Packages Impersonate PostCSS Tools to Deploy Windows RAT

Cybersecurity researchers at JFrog have uncovered three malicious npm packages designed to deliver a Windows-based remote access trojan (RAT) to developers who install them. Publis...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-06-23The Hacker News
WhatsApp VBScript Campaign Drops ManageEngine RMM via Fake Documents

Security researchers at Kaspersky have uncovered an active social engineering campaign abusing WhatsApp Direct Messages to distribute heavily obfuscated VBScript files disguised as...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-22The Hacker News
OXLOADER Malware Uses Google Ads to Spread CastleStealer Infostealer

Elastic Security Labs has uncovered a new campaign, tracked as REF8372, that delivers the CastleStealer information-stealing malware through a previously undocumented loader called...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-20The Hacker News
Hackers Exploit Gravity SMTP Flaw to Steal API Keys from WordPress Sites

Threat actors are actively exploiting a recently patched information disclosure vulnerability in the Gravity SMTP WordPress plugin, installed on roughly 100,000 websites. Tracked a...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-06-19BleepingComputer
Hackers Exploit Gravity SMTP Flaw Exposing API Keys on 100K WordPress Sites

Threat actors are actively exploiting an unauthenticated information disclosure vulnerability in the Gravity SMTP WordPress plugin, which is installed on over 100,000 websites. Tra...

VulnerabilityThreat Intel
Read More → Use Tool →
2026-06-19The Hacker News
Operation Endgame Disrupts SocGholish: 106 Servers Down, 15K WordPress Sites Cleaned

In a significant blow against one of the web's most persistent malware distribution networks, Dutch law enforcement, working alongside the FBI, the Royal Canadian Mounted Police, a...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-06-19The Hacker News
CISA Warns: FortiBleed Campaign Hits 86,644 FortiGate Devices Globally

CISA has issued an urgent advisory urging Fortinet customers to secure their FortiGate appliances against an ongoing malicious campaign dubbed FortiBleed, which has already comprom...

Data BreachAuthenticationThreat Intel
Read More → Use Tool →
2026-06-19The Hacker News
From Assistive to Agentic: How AI Is Redefining Enterprise Threat Management

The average enterprise security team juggles 40 or more security tools, generating massive amounts of internal telemetry and asset data. Yet these tools operate in silos, producing...

AI SecurityThreat IntelIncident Response
Read More → Use Tool →
2026-06-18KrebsOnSecurity
Popa Botnet: 1.4M Hacked Android TV Boxes Linked to Israeli Firm NetNut

Security researchers from Qurium, HUMAN Security, and XLAB have concluded that the massive Popa botnet is operated by NetNut, a residential proxy service run by publicly-traded Isr...

MalwareThreat IntelPrivacy
Read More → Use Tool →
2026-06-18BleepingComputer
Gentlemen Ransomware Uses 8 EDR Killer Variants to Disable Defenses

The Gentlemen ransomware-as-a-service (RaaS) operation is actively maintaining a sophisticated suite of endpoint detection and response (EDR) killers to help its affiliates evade d...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-06-18The Hacker News
SearchJack Chrome Extensions Hit 758K Users as macOS ClickFix Spreads RAT

A cluster of 23 deceptive Chrome browser extensions has been uncovered routing user searches through monetization middleware before delivering results, exposing roughly 758,000 aff...

Threat IntelMalwarePhishingPrivacyCloud Security
Read More → Use Tool →
2026-06-18The Hacker News
Microsoft Uncovers Windows Clipper Malware Using USB LNK Worm and Tor C2

Microsoft's Defender Security Research Team has disclosed details of a sophisticated Windows-based cryptocurrency clipper campaign that has been active since February 2026. The mal...

MalwareThreat Intel
Read More → Use Tool →
2026-06-18The Hacker News
INC Ransomware Hits 830+ Victims Since 2023 — RaaS Giant Reshapes Cybercrime

INC Ransomware has cemented its position as one of the most prolific ransomware-as-a-service (RaaS) operations in 2026, claiming more than 830 victims since its emergence in August...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-06-17Dark Reading
INC Ransomware Targets Healthcare with Pressure-Driven Tactics

INC Ransomware has emerged as one of the most operationally disciplined ransomware groups active in 2024-2025, achieving consistent success not through novel exploit chains or zero...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-06-17The Hacker News
Junior Hacker Used Tailscale to Survive Havoc C2 Takedown

A French-speaking threat actor tracked as "Poisson" compromised a small French automotive business and demonstrated a persistence technique that survived the loss of his command-an...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-06-17The Hacker News
Adversarial Exposure Validation: From Visibility to Confident Prioritization

Security teams today are drowning in findings but starving for context. Vulnerability scanners, CSPM tools, endpoint detection platforms, attack surface monitors, SAST scanners, an...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-06-17BleepingComputer
FortiBleed Leak Exposes 73,000 Fortinet VPN Credentials Worldwide

A newly discovered data leak dubbed "FortiBleed" has exposed a massive trove of Fortinet and FortiGate VPN credentials spanning 73,932 firewall URLs across 194 countries. Security ...

Data BreachVulnerabilityThreat Intel
Read More → Use Tool →
2026-06-17BleepingComputer
Account Takeover Attacks Surge: How Attackers Bypass MFA in 2026

Organizations now manage thousands of human and non-human identities spread across cloud services, SaaS applications, endpoints, and remote environments. As hybrid work, BYOD polic...

AuthenticationPhishingThreat Intel
Read More → Use Tool →
2026-06-17The Hacker News
Top 10 Attack Surface Exposures of 2026: 60% of Organizations at Risk

A new analysis of 3,000 organizational attack surfaces reveals that unnecessary internet-facing services remain the weakest link in enterprise defense. Intruder's 2026 Attack Surfa...

VulnerabilityThreat IntelAuthentication
Read More → Use Tool →
2026-06-16The Hacker News
ClickFix Attacks Deploy New Loaders: BabaDeda, Potemkin, and Lorem Ipsum

Cybersecurity researchers from Morphisec, BlueVoyant, and Huntress have independently identified a wave of ClickFix social engineering campaigns distributing three new malware load...

MalwareThreat IntelPhishing
Read More → Use Tool →
2026-06-16The Hacker News
Rokarolla Android Trojan Targets 217 Banking and Crypto Apps With 137 Commands

Security researchers at Zimperium's zLabs have uncovered a new Android banking trojan dubbed Rokarolla, named after its command-and-control infrastructure. The malware targets 217 ...

MalwareThreat IntelAuthentication
Read More → Use Tool →
2026-06-16BleepingComputer
GhostTree Attack Uses Recursive Windows Junctions to Hide Malware from EDR

A newly disclosed technique dubbed GhostTree exploits a little-known feature of the Windows NTFS file system to conceal malware from security scanners. By creating recursive direct...

MalwareVulnerabilityThreat Intel
Read More → Use Tool →
2026-06-16The Hacker News
94% of Security Incidents Now Involve Anonymized Infrastructure, Survey Finds

Security teams are drowning in IP data but starving for context, according to a new industry study from Spur Intelligence. The survey of more than 200 security practitioners found ...

Threat IntelPrivacyIncident Response
Read More → Use Tool →
2026-06-16The Hacker News
Attackers Exploit Three Fortinet FortiSandbox Flaws, Including One Patched Last Week

Threat intelligence firm Defused Cyber has reported active in-the-wild exploitation of three critical vulnerabilities in Fortinet FortiSandbox appliances over the past 24 hours. Th...

VulnerabilityThreat IntelAI Threats
Read More → Use Tool →
2026-06-16The Hacker News
China-Linked SprySOCKS Backdoor Targets Windows with Kernel Driver Stealth

Cybersecurity researchers at ESET have uncovered two previously undocumented Windows variants of SprySOCKS, a backdoor long believed to operate exclusively on Linux systems. Intern...

APTMalwareThreat Intel
Read More → Use Tool →
2026-06-15The Hacker News
China-Linked Hackers Abuse Google Workspace Rules to Steal Defense Emails

A China-linked espionage group tracked as UNC6508 maintained undetected access to North American medical, academic, and military research networks for over a year, quietly siphonin...

APTCloud SecurityThreat Intel
Read More → Use Tool →
2026-06-15The Hacker News
152 Chrome Wallpaper Extensions Exposed as Adware with 105K Installs

Cybersecurity researchers at Socket have uncovered a sprawling network of 152 Google Chrome extensions posing as live wallpaper and new tab add-ons that covertly distribute a poten...

MalwarePrivacyThreat Intel
Read More → Use Tool →
2026-06-15The Hacker News
Sniper Dz PhaaS Platform Targets MENA Users with Fake Facebook Lures

Cybersecurity researchers at Group-IB have exposed a sprawling social engineering campaign operated through Sniper Dz, a turnkey phishing-as-a-service (PhaaS) platform dismantled l...

PhishingThreat IntelMalware
Read More → Use Tool →
2026-06-15The Hacker News
Palo Alto Networks PAN-OS GlobalProtect VPN Flaw Actively Exploited

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a high-severity authentication bypass vulnerability (CVSS 7.8) affecting the GlobalProtect VPN portal and gat...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-13BleepingComputer
Operation Highland: Velvet Ant APT Spied on Air-Gapped Network for 10 Years

The Chinese state-linked espionage group "Velvet Ant" maintained undetected access to a large organization's critical infrastructure for an extraordinary 10 years, according to res...

APTAuthenticationThreat Intel
Read More → Use Tool →
2026-06-12BleepingComputer
400+ Arch Linux AUR Packages Compromised to Push eBPF Rootkit and Infostealer

More than 400 packages in the Arch User Repository (AUR) have been compromised to distribute a Linux rootkit and infostealer malware designed to harvest developer credentials, acce...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-06-12BleepingComputer
Early Supply-Chain Attack Warning Signs Hidden in Dark Web Forums

Supply-chain attacks rarely appear under their real name in underground forums. Long before a malicious package, compromised update, or breached vendor makes headlines, the precurs...

Supply ChainThreat IntelData Breach
Read More → Use Tool →
2026-06-12The Record
FISA Section 702 Lapses After Congress Fails to Renew Surveillance Powers

Section 702 of the Foreign Intelligence Surveillance Act (FISA) expired at midnight Friday after Congress and the White House failed to reach a deal to renew the controversial spy ...

PrivacyRegulationThreat Intel
Read More → Use Tool →
2026-06-12The Hacker News
MDR Is Failing: 60% of Alerts Unreviewed as AI Attacks Outpace Defenders

For the past decade, Managed Detection and Response (MDR) filled a critical gap in enterprise security by providing outsourced 24/7 alert triage for teams that couldn't staff round...

AI ThreatsIncident ResponseThreat Intel
Read More → Use Tool →
2026-06-12The Hacker News
INTERPOL Dismantles Sniper Dz Phishing Platform, Arrests 201

An INTERPOL-coordinated operation codenamed "Operation Ramz" has successfully disrupted Sniper Dz, a decade-old phishing-as-a-service (PhaaS) platform responsible for harvesting ov...

PhishingThreat IntelIncident Response
Read More → Use Tool →
2026-06-12The Hacker News
Europol Shuts Down AudiA6 Crypto Laundering Ring Used by Ransomware Gangs

Europol has announced the takedown of AudiA6, an industrial-scale cryptocurrency laundering service that processed more than €336 million (~$389 million) in illicit funds since lau...

RansomwareThreat IntelIncident Response
Read More → Use Tool →
2026-06-12Dark Reading
Phishing Attacks Drop 20% as Hackers Leverage AI for Smarter Scams

Phishing attack volume has declined by approximately 20% over the past reporting period, according to new data highlighted by Dark Reading, but the decline tells a misl...

PhishingAI ThreatsThreat Intel
Read More → Use Tool →
2026-06-11The Hacker News
The Gentlemen Ransomware Tied to 478 Victims, Uses AI and Worm Spreading

A new deep-dive into The Gentlemen ransomware operation reveals that the financially motivated threat group has claimed 478 victims since emerging in March 2025, and now operates a...

RansomwareMalwareThreat Intel
Read More → Use Tool →
2026-06-11The Hacker News
3.3B Stolen Credentials, $5K SilabRAT, North Korean APTs Dominate Week

The latest threat intelligence roundup reveals a staggering expansion of the identity-based attack economy, with Flashpoint reporting that infostealer infections on more than 11.1 ...

MalwareThreat IntelAPT
Read More → Use Tool →
2026-06-11BleepingComputer
Europol Dismantles AudiA6 Crypto-Laundering Hub Tied to Ransomware Gangs

Law enforcement agencies across 11 countries have jointly dismantled "AudiA6," a cryptocurrency laundering service that processed more than $380 million in illicit proceeds for ran...

RansomwareThreat IntelIncident Response
Read More → Use Tool →
2026-06-11The Hacker News
OceanLotus APT Targets Vietnam with SPECTRALVIPER in FireAnt Supply Chain Attack

Vietnam-aligned threat actor OceanLotus has been linked to two parallel cyber-espionage campaigns targeting domestic entities, leveraging its signature SPECTRALVIPER backdoor in a ...

APTSupply ChainThreat Intel
Read More → Use Tool →
2026-06-11The Hacker News
AI Compressed Time-to-Exploit to 24 Hours: Why CISOs Are Switching to BAS

For three decades, vulnerability management depended on a buffer: the months between disclosure and weaponization. Triage by severity, schedule remediation, validate, and move on. ...

AI ThreatsVulnerabilityThreat Intel
Read More → Use Tool →
2026-06-11Dark Reading
Chinese and North Korean APT Groups Expand After Asia-Pacific Success

State-sponsored threat actors from China and North Korea are scaling up cyber operations across the Asia-Pacific region, leveraging tactical gains to pursue higher-value targets in...

APTThreat Intel
Read More → Use Tool →
2026-06-10The Hacker News
China-Linked JDY Botnet Grows to 1,500+ Devices for Mass Reconnaissance

Cybersecurity researchers at Lumen's Black Lotus Labs have identified a significant resurgence of JDY, a covert China-linked botnet that has expanded to over 1,500 compromised smal...

APTThreat IntelMalware
Read More → Use Tool →
2026-06-10The Hacker News
Automated Pentest Blind Spots: What Your Security Report Is Missing

A clean penetration test report may look reassuring, but security leaders should read it as a warning sign, not a victory lap. According to Autumn Stambaugh and Can Yüceel of Picus...

VulnerabilityCloud SecurityThreat Intel
Read More → Use Tool →
2026-06-09The Hacker News
Russia-Linked APTs Still Exploiting Patched WinRAR Flaw to Target Ukraine

Two Russia-aligned cyber-espionage campaigns have continued weaponizing CVE-2025-8088, a path-traversal vulnerability in WinRAR patched in July 2025, to compromise Ukrainian organi...

APTVulnerabilityThreat Intel
Read More → Use Tool →
2026-06-09The Hacker News
The Hidden Security Risk: Work Between Tools Slows Response

Despite record investment in SIEM platforms, firewalls, IAM systems, and AI-driven detection, enterprise network security teams are still struggling with the same fundamental probl...

Incident ResponseAI SecurityThreat Intel
Read More → Use Tool →
2026-06-09The Hacker News
Hades PyPI Attack Poisons 19 Packages with Bun-Powered Credential Stealer

A new supply chain offensive dubbed Hades has compromised 19 packages in the Python Package Index (PyPI), deploying 37 malicious wheel artifacts that silently install a Bun-based c...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-06-08BleepingComputer
NFCShare Android Malware Steals Card Data via Fake Bank App Updates on GitHub

New variants of the NFCShare Android malware are spreading through a phishing campaign that impersonates legitimate banking apps, with malicious APKs hosted on public GitHub reposi...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-07BleepingComputer
C0XMO Botnet Exploits DD-WRT Flaw to Wipe Rival Malware

Fortinet researchers have uncovered a new variant of the Gafgyt botnet, dubbed C0XMO, which exploits a long-known buffer overflow vulnerability in DD-WRT router firmware (CVE-2021-...

MalwareVulnerabilityThreat Intel
Read More → Use Tool →
2026-06-07BleepingComputer
Silent Ransom Group Targets Law Firms With Fake IT Support Calls

The Silent Ransom Group, tracked by Mandiant as UNC3753 (also known as Luna Moth and Chatty Spider), is actively targeting U.S. law firms and professional services organizations wi...

PhishingThreat IntelData Breach
Read More → Use Tool →
2026-06-06BleepingComputer
Critical Everest Forms Pro Flaw Actively Exploited to Hijack WordPress Sites

Hackers are actively exploiting a critical unauthenticated remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin to seize full control of vulnerable w...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-05BleepingComputer
CISA Warns: SolarWinds Serv-U Flaw Actively Exploited to Crash Servers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that threat actors are actively exploiting a recently patched high-severity vulnerability in SolarWin...

VulnerabilityIncident ResponseThreat Intel
Read More → Use Tool →
2026-06-05The Hacker News
Asin Android Spyware Targets Arabic Users via Fake News, PDF, and War Map Apps

ESET researchers have uncovered a new Android spyware strain dubbed "Asin" that has been actively targeting Arabic-speaking users through a series of malicious apps disguised as le...

MalwareThreat IntelPrivacy
Read More → Use Tool →
2026-06-05The Hacker News
Hackers Exploit Critical Everest Forms Pro RCE Flaw to Hijack WordPress Sites

Threat actors are actively weaponizing a critical remote code execution vulnerability in the Everest Forms Pro WordPress plugin, putting an estimated 4,000 active installations at ...

VulnerabilityThreat IntelMalware
Read More → Use Tool →
2026-06-05The Hacker News
FIFA World Cup 2026 Scams: 4,300 Phishing Domains Exposed Before Kickoff

Cybersecurity researchers and the FBI are sounding the alarm on a massive wave of FIFA-themed fraud targeting World Cup 2026 fans, just days before the June 11 opening match. With ...

PhishingMalwareThreat Intel
Read More → Use Tool →
2026-06-05The Hacker News
PCPJack Hijacks 230 Cloud Servers to Build Covert SMTP Relay Network

The threat actor tracked as PCPJack has compromised at least 230 cloud servers across Amazon Web Services (AWS), Google Cloud Platform, and Microsoft Azure, converting them into a ...

Cloud SecurityThreat IntelMalware
Read More → Use Tool →
2026-06-04The Hacker News
Cisco Unified CM SSRF Flaw (CVE-2026-20230): PoC Public, Full Patch Months Away

Cisco has released a patch for a server-side request forgery (SSRF) vulnerability in Unified Communications Manager (Unified CM) and its Session Management Edition that allows an u...

VulnerabilityThreat IntelAuthentication
Read More → Use Tool →
2026-06-04The Hacker News
Fake Open-Source Tool Sites Poison Google Results to Deliver Malware

Cybersecurity researchers at Check Point have uncovered a large-scale SEO poisoning operation that impersonates popular open-source and freeware projects to distribute malware thro...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-04The Hacker News
APT Spied on Stock Exchange Exec's Outlook Mailbox for 5 Months

Unknown attackers maintained undetected access to the Outlook mailbox of a senior executive at a major global stock exchange for at least five months, systematically exfiltrating c...

APTThreat IntelData Breach
Read More → Use Tool →
2026-06-04Dark Reading
Pakistan Deploys Xeno RAT to Spy on Afghan Finance Ministry

A state-sponsored cyber-espionage campaign attributed to Pakistan-linked threat actors has been uncovered targeting Afghanistan's Ministry of Finance, leveraging the open-source Xe...

APTMalwareThreat Intel
Read More → Use Tool →
2026-06-03The Hacker News
Google DoubleClick Abused to Deliver DesckVB RAT in Malspam Campaign

Cybersecurity researchers at Huntress have uncovered a sophisticated malspam campaign that exploits Google's DoubleClick domain to bypass security filters and deliver a remote acce...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-06-03The Hacker News
Beyond the Zero-Day: Map Your Network the Way Attackers Do

Assume the breach. Zero-days continue to ship faster than patches, and AI-assisted exploit development has rendered the "patch everything in time" strategy obsolete for most organi...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-06-03BleepingComputer
CISA Warns of Active Attacks Exploiting Android and Linux Kernel Flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two high-severity vulnerabilities—one in the Android Framework and another in the Linux kernel—to its Kno...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-06-03The Hacker News
Unpatched Windows Search URI Flaw Lets Attackers Steal NTLMv2 Hashes

Cybersecurity researchers at Huntress have disclosed an unpatched vulnerability in the Windows "search:" URI handler that can be weaponized to leak a user's NTLMv2 hash to a remote...

VulnerabilityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-03The Hacker News
Weedhack MaaS Targets Minecraft Users via YouTube SEO Poisoning

Cybersecurity researchers at McAfee Labs have uncovered a malware-as-a-service (MaaS) campaign dubbed Weedhack that has been actively targeting Minecraft players since January 2026...

MalwareThreat IntelSupply Chain
Read More → Use Tool →
2026-06-02BleepingComputer
WeedHack Malware Hits 116,000+ Minecraft Systems in Global Infostealer Campaign

A large-scale malware-as-a-service operation dubbed WeedHack has infected more than 116,464 systems since January 2026 by targeting Minecraft players with trojanized mods, clients,...

MalwareThreat Intel
Read More → Use Tool →
2026-06-02The Hacker News
Google June 2026 Android Update Fixes 124 Flaws, One Actively Exploited

Google has rolled out its June 2026 Android security bulletin, addressing 124 vulnerabilities across the mobile operating system, including a high-severity privilege escalation fla...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-06-02The Hacker News
Russian Gamaredon APT Exploits WinRAR Flaw to Deploy GammaWorm Against Ukraine

Russian state-sponsored hacking group Gamaredon, officially linked to the Federal Security Service (FSB), has been exploiting a WinRAR path traversal vulnerability (CVE-2025-8088) ...

APTMalwareThreat Intel
Read More → Use Tool →
2026-06-02The Hacker News
CISA Adds Oracle WebLogic CVE-2024-21182 to KEV Catalog Amid Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Oracle WebLogic Server flaw, tracked as CVE-2024-21182, to its Known Exploited Vulnerabil...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-06-02The Hacker News
Why EDR Alone Fails and How Teams Build Real Cyber Resilience

Endpoint detection and response (EDR) has become a default investment for mid-sized organizations, yet owning an advanced platform does not automatically translate into operational...

Incident ResponseAI ThreatsThreat Intel
Read More → Use Tool →
2026-06-01The Hacker News
Miasma Attack Compromises Red Hat npm Packages, Steals Credentials

A new supply chain attack campaign dubbed "Miasma" has compromised multiple @redhat-cloud-services npm packages to steal credentials and secrets from developer machines, ultimately...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-06-01The Hacker News
Dragon Weave Campaign: China-Aligned APT Targets Czech Republic & Taiwan

Seqrite Labs has uncovered a sophisticated cyber espionage operation dubbed Operation Dragon Weave, targeting government officials, research institutions, and financial services in...

APTThreat IntelPhishing
Read More → Use Tool →
2026-06-01BleepingComputer
WordPress Malware Hides in Steam Profiles: 2,000 Sites Hit

Security researchers at GoDaddy have uncovered a sophisticated WordPress malware campaign that leverages Steam Community profile comments to conceal command-and-control (C2) commun...

MalwareThreat Intel
Read More → Use Tool →
2026-05-31The Hacker News
Dutch Police Takedown 17M Device Botnet Linked to Asocks Proxy Service

Dutch authorities have successfully dismantled a massive botnet infrastructure responsible for enslaving approximately 17 million compromised devices, including computers, tablets,...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2026-05-26The Hacker News
MuddyWater APT Targets 9 Countries in DLL Side-Loading Espionage Campaign

The Iranian threat actor MuddyWater has been linked to a sophisticated cyber espionage campaign that compromised at least nine organizations across nine countries on four continent...

APTThreat IntelMalware
Read More → Use Tool →
2026-05-26The Hacker News
MFA Prompt Bombing: Push-Based 2FA Exploitation Explained

Multi-factor authentication (MFA) was designed to close a critical gap in identity security by requiring a second factor beyond passwords. However, attackers have developed a techn...

AuthenticationPhishingThreat Intel
Read More → Use Tool →
2026-05-26The Hacker News
KnowledgeDeliver LMS Zero-Day Used to Deploy Godzilla & Cobalt Strike

A critical high-severity vulnerability (CVE-2026-5426, CVSS 7.5) in Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) widely used in Japan, was actively exploi...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-05-25The Hacker News
Ghost CMS CVE-2026-26980 Exploited: 700+ Sites Hit in ClickFix Attacks

Threat actors are actively exploiting a critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980, CVSS 9.4) to compromise over 700 websites across multiple sectors includi...

VulnerabilityMalwareThreat Intel
Read More → Use Tool →
2026-05-25The Hacker News
Agentic AI Transforms Network Detection & Response

Network Detection and Response (NDR) has long carried a reputation for being noisy and overwhelming security operations center (SOC) teams with alert fatigue. However, the emergenc...

AI SecurityThreat IntelIncident Response
Read More → Use Tool →
2026-05-23The Record
CISA Launches Form for Researchers to Report Exploited Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a new nomination form enabling security researchers, vendors, and industry partners to submit vulnerabiliti...

VulnerabilityThreat IntelBug Bounty
Read More → Use Tool →
2026-05-22The Hacker News
Operation Saffron Takes Down First VPN Used by 25 Ransomware Groups

Authorities in Europe and North America have successfully dismantled First VPN, a criminal VPN service specifically designed to anonymize ransomware operations and other cyberattac...

RansomwareThreat IntelPrivacy
Read More → Use Tool →
2026-05-21KrebsOnSecurity
Kimwolf Botnet Operator 'Dort' Arrested in Canada, Charged in US

Jacob Butler, known in cybercrime circles as "Dort," has been arrested in Canada and faces criminal charges in both the United States and Canada for allegedly operating the Kimw...

MalwareThreat Intel
Read More → Use Tool →
2026-05-21The Hacker News
Showboat Linux Malware Targets Middle East Telecom with SOCKS5 Backdoor

Cybersecurity researchers from Lumen Technologies Black Lotus Labs have uncovered a sophisticated Linux malware campaign targeting a telecommunications provider in the Middle East ...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-05-21The Hacker News
Microsoft Defender Zero-Days Actively Exploited; Added to CISA KEV

Microsoft has disclosed two actively exploited vulnerabilities in Microsoft Defender—a privilege escalation flaw and a denial-of-service bug—both now under active exploitation in t...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-05-20BleepingComputer
Ukraine Nabs 18-Year-Old Hacker Behind 28K Account Thefts

Ukrainian cyberpolice, working in coordination with U.S. law enforcement, have identified an 18-year-old male from Odesa suspected of orchestrating an infostealer malware operation...

MalwareData BreachThreat Intel
Read More → Use Tool →
2026-05-18The Hacker News
INTERPOL Operation Ramz: 201 Arrests in MENA Cybercrime Crackdown

INTERPOL's Operation Ramz has concluded with a significant blow to cybercriminal operations across the Middle East and North Africa (MENA) region. The coordinated crackdown, spanni...

PhishingThreat IntelIncident Response
Read More → Use Tool →
2026-05-18The Hacker News
Reduce Phishing Exposure Before Business Disruption Hits

Phishing attacks continue to evolve beyond simple credential harvesting, creating multi-stage risks that can compromise email systems, SaaS applications, cloud platforms, and inter...

PhishingThreat IntelIncident Response
Read More → Use Tool →
2026-05-18The Hacker News
Developer Workstations Now Critical Supply Chain Attack Targets

In a concentrated 48-hour window, threat actors launched coordinated attacks against npm, PyPI, and Docker Hub, marking a significant escalation in software supply chain aggression...

Supply ChainThreat IntelAuthentication
Read More → Use Tool →
2026-05-17The Hacker News
NGINX CVE-2026-42945 Actively Exploited - Critical RCE Risk

A critical heap buffer overflow vulnerability in NGINX's ngx_http_rewrite_module, tracked as CVE-2026-42945 with a CVSS score of 9.2, is now under active exploitation mere days aft...

Zero-DayVulnerabilityThreat Intel
Read More → Use Tool →
2026-05-16SecurityWeek
Critical NGINX Heap Overflow PoC Published – CVE-2026-42945

Technical details and proof-of-concept (PoC) exploit code targeting a newly patched critical-severity vulnerability in NGINX are now publicly available. Tracked as CVE-2026-42945 w...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-05-15The Hacker News
Living-Off-the-Land Attacks: 84% of Breaches Exploit Trusted Tools

Bitdefender's analysis of 700,000 high-severity incidents reveals that legitimate-tool abuse now accounts for 84% of attacks, fundamentally reshaping how organizations must approac...

Threat IntelVulnerability
Read More → Use Tool →
2026-05-15The Hacker News
CISA Adds Critical Cisco SD-WAN Flaw CVE-2026-20182 to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20182, a critical authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-05-11The Hacker News
Purple Teaming Fails: Attackers Exploit CVEs in 10 Hours, Defenders Can't Keep Up

The cybersecurity industry’s beloved “purple team” concept is broken by design. According to data from CISA KEV, VulnCheck KEV, and ExploitDB, the mean time from ...

VulnerabilityThreat IntelIncident Response
Read More → Use Tool →
2026-05-10BleepingComputer
German Police Shut Down Relaunched Crimenetwork Marketplace, Arrest Admin

German law‑enforcement agencies, led by the Federal Criminal Police Office (BKA) and the Hessian State Criminal Police Office (LKA Hessen) in close coordination with Europol’s Euro...

PrivacyEncryptionThreat Intel
Read More → Use Tool →
2026-05-09BleepingComputer
JDownloader Site Hacked, Distributing Python RAT via Fake Installers

The official website for JDownloader, a widely used open‑source download manager, was compromised earlier this week. Attackers altered the download links for both Windows and Linux...

MalwareSupply ChainThreat Intel
Read More → Use Tool →
2026-05-08SecurityWeek
Train Hacker Arrested, PamDOORa Backdoor, New CISA Director Frontrunner

U.S. authorities have apprehended a suspect allegedly responsible for compromising rail signaling systems, marking a rare enforcement action against attacks on transportation netwo...

Threat IntelVulnerabilitySupply Chain
Read More → Use Tool →
2026-05-08SecurityWeek
Polish Agency Reports ICS Breaches at Five Water Treatment Plants

Poland's Computer Security Incident Response Team (CERT Polska) has disclosed a series of intrusion campaigns targeting Industrial Control Systems (ICS) at five municipal water tre...

VulnerabilityThreat Intel
Read More → Use Tool →
2026-05-08SecurityWeek
RansomHouse Ransomware Breach: Trellix Internal Services Exposed

RansomHouse, a known ransomware operation, has claimed responsibility for a breach at Trellix, a prominent cybersecurity vendor. The group posted several screenshots on a dark‑web ...

RansomwareData BreachThreat Intel
Read More → Use Tool →
2026-05-08The Record
Kingdom Market Admin Sentenced to 16 Years for Dark Web Drug Platform

A Slovakian national, Alan Bill, 33, was sentenced on Thursday to 16 years (192 months) in federal prison after pleading guilty to conspiracy to distribute controlled substances. B...

Threat IntelRegulation
Read More → Use Tool →
2026-05-08The Record
Pro-Ukraine BO Team, Head Mare Hackers Collaborate on Russian Attacks

Kaspersky researchers have uncovered a convergence between the pro‑Ukraine hacktivist group BO Team and the advanced threat actor Head Mare, revealing that the two have begun shari...

APTThreat IntelMalware
Read More → Use Tool →
2026-05-08The Hacker News
Patient Zero Webinar: Preventing Stealth Breaches Through Threat Intel

The Hacker News recently highlighted an emerging cybersecurity threat model dubbed "Patient Zero" that organizations increasingly struggle to detect. A specialized webinar hosted b...

PhishingThreat IntelData Breach
Read More → Use Tool →
2026-05-08The Hacker News
25M Alerts Expose Hidden Low-Severity Threat Gaps in Enterprise SOC

A recent analysis of more than 25 million security alerts collected from a dozen global security operations centers (SOCs) over a six‑month period reveals that low‑severity events ...

Threat IntelIncident ResponseVulnerability
Read More → Use Tool →
2026-05-08The Hacker News
Linux PamDOORa Backdoor Exploits PAM to Steal SSH Credentials

Cybersecurity researchers have disclosed a previously unknown Linux backdoor called PamDOORa that is being actively advertised on the Russian cybercrime forum Rehub for $1,600 by a...

MalwareThreat IntelAuthentication
Read More → Use Tool →
2026-05-08The Hacker News
Dirty Frag: New Linux Kernel Exploit Grants Root Access

Security researchers have disclosed a critical unpatched local privilege escalation (LPE) vulnerability in the Linux kernel, tracked as CVE-2026-3157, dubbed 'Dirty Frag.' The flaw...

Zero-DayVulnerabilityThreat Intel
Read More → Use Tool →
2026-05-08BleepingComputer
Why More Analysts Won’t Solve Your SOC Alert Problem

Modern threat actors launch campaigns that generate thousands of alerts per hour, leaving security operations centers (SOCs) drowning in data. Even with a larger team of analysts, ...

AI SecurityIncident ResponseThreat Intel
Read More → Use Tool →
2026-05-07The Hacker News
Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation – Admin Access

Ivanti has released a critical advisory warning of a high‑severity flaw in its Endpoint Manager Mobile (EPMM) product, tracked as CVE‑2026‑6973 and rated 7.2 on the CVSS scale. The...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-05-07The Hacker News
Day Zero Readiness: Closing Operational Gaps in Incident Response

Organizations often believe that securing a retainer with a reputable incident response (IR) firm or pre‑approving an external provider is sufficient to survive a cyber crisis. Whi...

Incident ResponseThreat IntelZero-Day
Read More → Use Tool →
2026-05-07BleepingComputer
Australia Warns of ClickFix Attacks Spreading Vidar Stealer

The Australian Cyber Security Centre (ACSC) has issued a high‑priority advisory warning that a sophisticated malware campaign is actively using the ClickFix social‑engineering tech...

MalwarePhishingThreat Intel
Read More → Use Tool →
2026-05-07Dark Reading
PCPJack Malware Exploits Parquet Files to Steal Cloud Secrets

Security researchers at Unit 42 have uncovered a new cloud‑targeting malware family they are calling PCPJack, which has quietly replaced the earlier TeamPCP implant. PCPJack distin...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-05-07BleepingComputer
California Man Gets 6.5 Years for $230M Crypto Heist, Money Laundering

Ethan J. Rivera, a 20‑year‑old from Los Angeles, California, was sentenced on Friday to 78 months (6.5 years) in federal prison for his role in a sophisticated criminal operation t...

Threat IntelPrivacyEncryption
Read More → Use Tool →
2026-05-07Dark Reading
AI-Driven Cyberattack Targets SCADA Systems, Foiled by Login Screen

Security researchers at Mandiant and Dragos have documented what they are calling the world's first fully AI-integrated cyberattack campaign targeting operational technology (OT) i...

AI ThreatsVulnerabilityThreat Intel
Read More → Use Tool →
2026-05-06The Hacker News
New Mirai Botnet 'xlabs_v1' Exploits ADB for IoT DDoS Attacks

Cybersecurity researchers have identified a new Mirai-variant botnet designated as xlabs_v1 that actively exploits the Android Debug Bridge (ADB) interface to compromise internet-c...

MalwareVulnerabilityThreat Intel
Read More → Use Tool →
2026-05-06The Hacker News
Hacker News Opens Cybersecurity Stars Awards 2026 Submissions

The Hacker News (THN) has officially opened the call for entries for the Cybersecurity Stars Awards 2026, an initiative designed to shine a spotlight on the behind‑the‑scenes work ...

Bug BountyThreat IntelIncident Response
Read More → Use Tool →
2026-05-06BleepingComputer
Google Ads Abused in GoDaddy ManageWP Login Phishing Scam

A sophisticated phishing campaign is leveraging Google’s sponsored search ads to mimic the login page of ManageWP, GoDaddy’s platform for centrally managing large fleets of WordPre...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-05-06BleepingComputer
Ransomware Targets Backup Systems Before Encryption: Acronis

Acronis researchers have documented a systematic shift in ransomware operations: before triggering encryption, threat actors now deliberately cripple backup infrastructure. Their 2...

RansomwareIncident ResponseThreat Intel
Read More → Use Tool →
2026-05-06BleepingComputer
Webinar: Fix Triage, Enrichment & Coordination to Stop Incident Escalation

hackmyip.com will host a live webinar titled "Why Network Incidents Escalate and How to Fix Response Gaps" on March 15, 2025 at 2:00 PM EST. The session will feature Alex Rivera, s...

Incident ResponseThreat Intel
Read More → Use Tool →
2026-05-05The Hacker News
China-Linked UAT-8302 Hits South America Governments with Shared APT Malware

Security researchers have linked a newly tracked China‑nexus threat cluster, designated UAT‑8302, to a wave of cyber‑espionage operations targeting government agencies in South Ame...

APTMalwareThreat Intel
Read More → Use Tool →
2026-05-05The Hacker News
Microsoft Exposes Credential Theft Phishing Targeting 35K Users in 26 Countries

Microsoft’s Threat Intelligence Center (MSTIC) has released details of a large‑scale credential‑harvesting operation that successfully targeted roughly 35,000 users in 26 countries...

PhishingThreat IntelAPT
Read More → Use Tool →
2026-05-05Dark Reading
Trellix Source Code Breach Exposes Security Product Vulnerabilities

Trellix, a prominent cybersecurity company formed from the merger of McAfee Enterprise and FireEye, has confirmed a significant source code breach affecting multiple security produ...

Supply ChainData BreachThreat Intel
Read More → Use Tool →
2026-05-05Dark Reading
Berkeley CLTC Provides Cybersecurity Tools for Under-Resourced Entities

The UC Berkeley Center for Long-Term Cybersecurity (CLTC) has launched a dedicated research hub designed to bridge the cybersecurity gap for schools, local governments, and non‑pro...

Threat IntelIncident ResponseVulnerability
Read More → Use Tool →
2026-05-05Dark Reading
USB Pen Test: Steve Stasiukonis' Viral Social Engineering Experiment

In 2004, penetration tester Steve Stasiukonis of the security firm “SecureX” conducted a USB drop experiment at a regional credit union in the Pacific Northwest. Armed with a batch...

VulnerabilityPhishingThreat Intel
Read More → Use Tool →
2026-05-05BleepingComputer
Instructure Breach: Hacker Claims 280M Records from 8,800 Schools

Education technology provider Instructure has disclosed a significant data breach after a threat actor operating under the alias 'CSAMKing' claimed to have stolen approximately 280...

Data BreachPrivacyThreat Intel
Read More → Use Tool →
2026-05-05BleepingComputer
DAEMON Tools Backdoor Attack: Supply Chain Compromise

On April 8, 2026, Disc Soft Ltd. confirmed that the official DAEMON Tools Pro installer (version 8.0.0.0634) had been trojanized and was being distributed through its website. The ...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-05-05BleepingComputer
Student Arrested for Hacking Taiwan High-Speed Rail, Triggering Emergency Brakes

On 12 March 2026, Taiwanese authorities arrested a 23‑year‑old university student for allegedly compromising the TETRA (Terrestrial Trunked Radio) communication network that underp...

VulnerabilityIncident ResponseThreat Intel
Read More → Use Tool →
2026-05-05BleepingComputer
Latvian Gets 8.5 Years for Karakurt Ransomware Negotiator Role

A Latvian national was sentenced on Friday to 8.5 years in a U.S. federal prison after being extradited to face charges related to his work as a "cold case" negotiator for the Russ...

RansomwareThreat Intel
Read More → Use Tool →
2026-05-04The Hacker News
Global Police Bust: 276 Arrested, 9 Crypto Scam Centers Dismantled, $701M Seized

An international law enforcement coalition dubbed 'Operation Crypto Shield,' led by the FBI, Europol, and China's Ministry of Public Security, has achieved a landmark victory again...

PhishingThreat IntelIncident Response
Read More → Use Tool →
2026-05-04Dark Reading
Cybercriminal Syndicates Exploit Supply Chain to Boost Physical Cargo Theft

Physical cargo theft is no longer the domain of opportunistic street gangs; it has morphed into a high‑tech enterprise orchestrated by transnational cybercriminal syndicates. Accor...

Supply ChainAPTThreat Intel
Read More → Use Tool →
2026-05-04Dark Reading
RMM Tools Exploited in Stealthy Phishing Campaign Targeting 80+ Orgs

Security researchers at Volexity have uncovered a sophisticated phishing campaign leveraging legitimate remote monitoring and management (RMM) tools to maintain persistent access w...

PhishingMalwareThreat Intel
Read More → Use Tool →
2026-05-04Dark Reading
How Dark Reading Launched Cybersecurity Media Without Print in 2006

Twenty years ago, Dark Reading entered the cybersecurity media landscape without the traditional safety net of a print edition, proving that compelling content and editorial expert...

Threat Intel
Read More → Use Tool →
2026-05-04BleepingComputer
Zero-Day CVE-2026-22679 in Weaver E-Cology Exploited Since March

Security researchers have identified a critical remote‑code‑execution flaw in Weaver E‑cology, a widely deployed office‑automation platform. The vulnerability, tracked as CVE‑2026‑...

Zero-DayVulnerabilityThreat Intel
Read More → Use Tool →
2026-05-04BleepingComputer
Kaspersky: Amazon SES Phishing Evades Email Security

Kaspersky researchers identified a surge in phishing campaigns leveraging Amazon Simple Email Service (SES). Attackers abuse the trusted infrastructure by sending emails via verifi...

PhishingCloud SecurityThreat Intel
Read More → Use Tool →
2026-05-04BleepingComputer
Trellix Data Breach Exposes Source Code - What You Need to Know

Cybersecurity firm Trellix has disclosed a significant data breach after threat actors gained unauthorized access to a portion of its source code repository. The incident, discover...

Data BreachSupply ChainThreat Intel
Read More → Use Tool →
2026-05-04BleepingComputer
Amazon SES Phishing Surge: Evading Standard Security Filters

Amazon Simple Email Service (SES), the cloud‑based email sending platform offered by Amazon Web Services, is increasingly being weaponized by threat actors to distribute phishing e...

PhishingCloud SecurityThreat Intel
Read More → Use Tool →
2026-05-04BleepingComputer
Credit Union Loan Fraud: Stolen Identity Verification Exposed

Fraudsters are not breaking into credit unions with zero‑days or ransomware; they are exploiting the normal loan origination workflow. Flare’s threat‑intelligence team uncovered a ...

AuthenticationThreat IntelPrivacy
Read More → Use Tool →
2026-05-04BleepingComputer
CISA Warns: Copy Fail Linux Flaw Exploited for Root Access

CISA warned Monday that threat actors have begun actively exploiting a newly disclosed Linux kernel vulnerability dubbed “Copy Fail,” just one day after Theori security researchers...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-05-03BleepingComputer
Instructure Data Breach: ShinyHunters Claim 4.5M Records Stolen

Instructure, the educational technology company behind the popular Canvas learning‑management system, confirmed on March 5 2026 that unauthorized actors had accessed its internal n...

Data BreachThreat IntelPrivacy
Read More → Use Tool →
2026-05-02BleepingComputer
ConsentFix v3: Automated OAuth Abuse Targets Azure

Security researchers have flagged a new iteration of the consent‑phishing tool known as ConsentFix, now labeled v3, which dramatically expands the scale and automation of attacks a...

Cloud SecurityAuthenticationThreat Intel
Read More → Use Tool →
2026-05-01The Hacker News
Vishing & SSO Abuse Power Rapid SaaS Extortion Attacks

Cybersecurity researchers have identified two distinct cybercrime groups orchestrating rapid, high‑impact extortion campaigns that operate almost entirely within Software‑as‑a‑Serv...

PhishingCloud SecurityThreat Intel
Read More → Use Tool →
2026-05-01The Hacker News
China-Linked Hackers Target Asian Governments, NATO State, Activists

Cybersecurity researchers have uncovered a sophisticated espionage operation linked to Chinese state actors, targeting a broad spectrum of victims across Asia and a NATO member sta...

APTThreat IntelMalware
Read More → Use Tool →
2026-05-01The Hacker News
Top 5 Sales Challenges Costing MSPs Cybersecurity Revenue

Managed security services are on a steep ascent, with the market expected to swell from $38.31 billion in 2025 to $69.16 billion by 2030, making cybersecurity the fastest‑growing s...

Cloud SecurityThreat Intel
Read More → Use Tool →
2026-05-01Dark Reading
North Korean APTs Dominate 2026 Crypto Theft, AI in the Mix

North Korean advanced persistent threat (APT) groups have consolidated their dominance over the cryptocurrency threat landscape in 2026, accounting for an estimated 76 % of all dig...

APTAI ThreatsThreat Intel
Read More → Use Tool →
2026-05-01Dark Reading
Dark Reading Celebrates 20 Years of Cybersecurity Coverage

Dark Reading marks its 20th anniversary this month, reflecting on two decades of delivering timely cybersecurity news, analysis, and insights to professionals worldwide. Launched o...

Threat IntelPrivacyRegulation
Read More → Use Tool →
2026-05-01BleepingComputer
Criminal IP and Securonix ThreatQ Team Up to Boost Threat Intel

Criminal IP, a provider of exposure‑based threat intelligence, announced a partnership with Securonix to embed its rich contextual data directly into the Securonix ThreatQ platform...

Threat IntelIncident Response
Read More → Use Tool →
2026-05-01BleepingComputer
Former Employees Sentenced 4 Years for BlackCat Ransomware Attacks

A federal court has sentenced two former cybersecurity incident response professionals to four years in prison each for their roles in conducting BlackCat (ALPHV) ransomware attack...

RansomwareIncident ResponseThreat Intel
Read More → Use Tool →
2026-04-30The Hacker News
DEEP#DOOR Python Backdoor Steals Browser and Cloud Credentials

Security researchers at SentinelOne and WithSecure have uncovered a sophisticated Python-based backdoor named DEEP#DOOR that leverages legitimate tunneling services to establish co...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-04-30KrebsOnSecurity
Brazilian Anti-DDoS Firm Exposed as Botnet Operator

A Brazilian technology firm that markets itself as a specialist in mitigating distributed denial-of-service (DDoS) attacks has been uncovered as the operator of a botnet responsibl...

Supply ChainThreat IntelMalware
Read More → Use Tool →
2026-04-29The Hacker News
SAP npm Packages Compromised in Credential-Stealing Supply Chain Attack

Cybersecurity researchers at Aikido Security have uncovered a new supply chain attack campaign that has compromised several npm packages associated with SAP software. The malicious...

Supply ChainMalwareThreat Intel
Read More → Use Tool →
2026-04-29The Hacker News
AI-Powered Kill Chain Automation Shifts Threat Landscape in 2026

In February 2026, a joint research team from SentinelLabs and the University of Calgary published a report revealing a paradigm shift in cyber‑attack tradecraft. The analysts, led ...

AI ThreatsAI SecurityThreat Intel
Read More → Use Tool →
2026-04-29The Hacker News
Exposure Management Platforms: Key Features and Common Pitfalls

Security teams across industries are increasingly discovering that traditional vulnerability management approaches fail to accurately represent organizational risk. Despite closing...

VulnerabilityThreat IntelCloud Security
Read More → Use Tool →
2026-04-29The Hacker News
CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical security flaws—one affecting ConnectWise ScreenConnect and the other targeting Microsoft Win...

VulnerabilityZero-DayThreat Intel
Read More → Use Tool →
2026-04-28Dark Reading
Chris Inglis Reflects on NSA Failures 13 Years After Snowden Leaks

Chris Inglis, who served as NSA Deputy Director from 2011 to 2014 under Director Keith Alexander, has broken his silence on the agency's missteps during the Edward Snowden affair, ...

PrivacyThreat IntelRegulation
Read More → Use Tool →
2026-04-28Dark Reading
Feuding Ransomware Groups 0APT and KryBit Expose Each Other's Operations

The ransomware ecosystem was rocked in early 2026 when two prominent ransomware‑as‑a‑service (RaaS) operations, 0APT and KryBit, turned on each other, spilling a treasure trove of ...

RansomwareAPTThreat Intel
Read More → Use Tool →
2026-04-28Dark Reading
Vidar Infostealer Dominates Market After Law Enforcement Takedowns

Vidar has emerged as the dominant infostealer in the cybercriminal ecosystem, filling the vacuum left by last year's coordinated law enforcement operations against Lumma Stealer an...

MalwareThreat IntelData Breach
Read More → Use Tool →
2026-04-28The Hacker News
Brazilian LofyGang Returns with Minecraft LofyStealer Campaign

After a three‑year absence, the Brazilian cybercrime group LofyGang has resurfaced with a new campaign targeting Minecraft players. The outfit is deploying a freshly coded stealer ...

MalwareThreat Intel
Read More → Use Tool →
2026-04-28The Hacker News
China's Silk Typhoon Hacker Extradited to US Over COVID Research Cyberattacks

A Chinese national linked to the Silk Typhoon advanced persistent threat (APT) group has been handed over to U.S. authorities after being arrested in Italy in July 2025. Xu Zewei, ...

APTThreat IntelIncident Response
Read More → Use Tool →
2026-04-27Dark Reading
Fast16: 20-Year-Old Malware That Predates Stuxnet Found

Researchers at SentinelOne, led by senior threat analyst Alexei Markov, uncovered a previously unknown malware framework they have dubbed "Fast16", dating back to the late 1990s an...

MalwareAPTThreat Intel
Read More → Use Tool →
2026-04-27The Hacker News
Checkmarx Data Leaked on Dark Web After Supply Chain Attack

Checkmarx has confirmed that the data stolen during the March 23 supply‑chain intrusion has been publicly posted on a Tor‑based dark‑web leak site. The company’s incident response ...

Supply ChainData BreachThreat Intel
Read More → Use Tool →
2026-04-27The Hacker News
PhantomCore Exploits TrueConf Flaws to Target Russian Networks

A pro‑Ukrainian hacktivist collective known as PhantomCore has been conducting aggressive intrusions against Russian organizations since September 2025, focusing on servers that ru...

VulnerabilityAPTThreat Intel
Read More → Use Tool →
2026-04-27The Hacker News
73 Fake VS Code Extensions Spread GlassWorm v2 Malware

Security researchers have identified 73 malicious Visual Studio Code extensions hosted on the Open VSX registry that are distributing an updated variant of the GlassWorm informatio...

MalwareSupply ChainThreat Intel
Read More → Use Tool →
2026-04-27The Hacker News
Fake CAPTCHA IRSF Scam: 120 Keitaro Campaigns Fuel Global SMS and Crypto Fraud

Security researchers at Group-IB have uncovered a large-scale smishing operation that combines fake CAPTCHA verification pages with International Revenue Share Fraud (IRSF) and cry...

PhishingThreat IntelPrivacy
Read More → Use Tool →
2026-04-25The Hacker News
CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, signaling a...

VulnerabilityRegulationThreat Intel
Read More → Use Tool →
2026-04-24Dark Reading
US Charges 29 in Myanmar Investment Fraud Ring, Seizes 500+ Domains

The US Department of Justice has announced the indictment of 29 individuals linked to a cyber fraud syndicate operating from Myanmar, charging them with conspiracy to commit wire f...

PhishingThreat IntelPrivacy
Read More → Use Tool →
2026-04-24Dark Reading
AI Phishing Surges: Hackers Shift to 1-to-1 Personalized Attacks

In the past six months, a surge of AI‑powered phishing campaigns has reshaped the threat landscape, according to an analysis published by Dark Reading. Threat actors are moving awa...

PhishingAI ThreatsThreat Intel
Read More → Use Tool →
2026-04-24Dark Reading
Tropic Trooper APT Targets Home Routers and Japanese Entities

Tropic Trooper, the Chinese state‑sponsored threat group also tracked as KeyBoy and Pirate Panda, has broadened its operational scope with a fresh wave of attacks aimed at consumer...

APTVulnerabilityThreat Intel
Read More → Use Tool →
2026-04-23Dark Reading
China-Backed Hackers Industrializing Botnets for Covert Attacks

China's state-sponsored threat actors are increasingly leveraging automated botnets comprised of compromised IoT devices, routers, and servers to conduct large-scale cyber operatio...

APTMalwareThreat Intel
Read More → Use Tool →
2026-04-23Dark Reading
Africa Cyberattack Volume Falls 22% as Hackers Target Latin America

According to the latest Dark Reading analysis, the weekly number of cyberattacks directed at African organizations dropped by 22 % over the past year, falling from roughly 5,400 in...

Threat IntelAPTRansomware
Read More → Use Tool →
2026-04-23The Hacker News
China-Linked GopherWhisper Infiltrates 12 Mongolian Gov Systems

A previously undocumented China‑aligned advanced persistent threat (APT) group, tracked as GopherWhisper, has successfully compromised at least twelve Mongolian government institut...

APTMalwareThreat Intel
Read More → Use Tool →
2026-04-22Dark Reading
The Gentlemen Ransomware Gang Surges in Sophistication and Speed

Security researchers at multiple threat intelligence firms have observed a significant acceleration in The Gentlemen ransomware group's operational tempo and technical capabilities...

RansomwareThreat IntelMalware
Read More → Use Tool →
2026-04-21Dark Reading
Chinese APT Targets Indian Banks, Korean Policy in New Cyber Campaign

A newly identified Chinese advanced persistent threat (APT) group has launched a coordinated cyber‑espionage campaign against major Indian financial institutions and South Korean p...

APTThreat IntelMalware
Read More → Use Tool →
2026-04-17Dark Reading
NIST's NVD Cuts Spark Rise of Private CVE Enrichment

NIST's National Vulnerability Database (NVD) has historically been the primary source of enriched CVE data, attaching CVSS v3.1 vector strings, severity ratings, affected product C...

VulnerabilityRegulationThreat Intel
Read More → Use Tool →
2026-04-17Dark Reading
Tycoon 2FA Phishers Switch to Device Code Phishing Attacks

Tycoon, a well‑known phishing collective that has long abused two‑factor authentication (2FA) bypass tricks, has quietly shifted to a new attack vector: OAuth 2.0 device‑code phish...

PhishingAuthenticationThreat Intel
Read More → Use Tool →
2026-04-14Ars Technica
UK Government Mythos AI Tests Cut Cybersecurity Hype, Identify Real Threats

The UK Cabinet Office’s Emerging Technology Cybersecurity Division (ETCD), in close collaboration with the National Cyber Security Centre (NCSC), has publicly released results from...

AI SecurityThreat Intel
Read More → Use Tool →
2026-04-06KrebsOnSecurity
Germany Doxes 'UNKN', Head of REvil & GandCrab Ransomware Gangs

German authorities have publicly exposed the identity of the notorious hacker known as "UNKN", linking the alias to 31‑year‑old Russian national Daniil Maksimov. Maksimov is allege...

RansomwareThreat IntelPrivacy
Read More → Use Tool →
2026-03-23KrebsOnSecurity
CanisterWorm Worm Targets Iran via Cloud Services, Wipes Data

Security researchers at SecureSphere Labs have uncovered a new file‑wiping worm they have named CanisterWorm, attributed to a financially motivated threat actor tracked under the a...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-03-20KrebsOnSecurity
Feds Dismantle Four IoT Botnets Behind Massive DDoS Attacks

The U.S. Department of Justice, together with the Royal Canadian Mounted Police (RCMP) and the German Federal Criminal Police Office (BKA), has dismantled the command‑and‑control (...

MalwareThreat IntelIncident Response
Read More → Use Tool →
2022-08-30Threatpost
Watering Hole Attacks Spread ScanBox Keylogger via APT TA423

Security researchers have uncovered a sophisticated watering‑hole campaign attributed to the advanced persistent threat group TA423, which leverages compromised websites to deliver...

APTMalwareThreat Intel
Read More → Use Tool →
2022-08-29Threatpost
0ktapus Phishing Attacks Compromised 130 Firms, Bypassed MFA

A coordinated phishing operation attributed to the threat group 0ktapus has ensnared more than 130 organizations across multiple industries, according to researchers at Threatpost....

PhishingThreat IntelAuthentication
Read More → Use Tool →