Skip to content
feed: live
>_0dayNews
$ category --breaking

Breaking

Fast-turnaround coverage of active threats as they develop — APTs, ransomware gangs, breaches.

Beat editor
Morgan "airgap" Reyes
153 articles
~/articles/2026-08-16-amnesiastealer-macos-browser-hijack
AmnesiaStealer Hijacks macOS Browser Sessions
● Breaking
threat intel

AmnesiaStealer Hijacks macOS Browser Sessions

Jamf found a new macOS infostealer that hijacks Chrome in headless mode, giving attackers live remote control of authenticated browser sessions via ClickFix lures.

read →
~/articles/2026-08-16-siyuan-v374-eleven-cves-critical-rce
SiYuan v3.7.4 Patches 11 CVEs, Critical RCE Confirmed
● Breaking
threat intel

SiYuan v3.7.4 Patches 11 CVEs, Critical RCE Confirmed

SiYuan v3.7.4 patches eleven CVEs including critical Electron XSS-to-RCE chains and a CVSS 9.8 auth bypass. Desktop users should update immediately.

read →
~/articles/2026-08-16-threema-ddos-service-disruption
Threema Hit by Large-Scale DDoS, Service Disrupted
● Breaking
threat intel

Threema Hit by Large-Scale DDoS, Service Disrupted

Multiple large-scale DDoS attacks disrupted Threema's secure messaging service this week. No message content breach — availability impact only.

read →
~/articles/2026-08-16-linux-kernel-brcmfmac-wifi-heap-overflow-bpf-bypass
Linux Kernel Patches WiFi Heap Overflow, BPF Bypass
● Breaking
linux kernel

Linux Kernel Patches WiFi Heap Overflow, BPF Bypass

August 15 kernel stable drop fixes a Broadcom WiFi heap overflow triggerable by a rogue AP, a BPF verifier bypass, and 28 other security fixes.

read →
~/articles/2026-08-16-evooo1bot-botnet-routers-socks5-relay
Evooo1Bot Botnet Hijacks Routers as SOCKS5 Proxies
● Breaking
threat intel

Evooo1Bot Botnet Hijacks Routers as SOCKS5 Proxies

Fortinet researchers track Evooo1Bot, a Mirai-based modular Linux botnet hijacking routers as SOCKS5 relays with DDoS and credential-sniffing capability.

read →
~/articles/2026-08-14-scotland-copfs-breach-third-party
Scottish Crown Office Breach May Spread Across Agencies
threat intel

Scottish Crown Office Breach May Spread Across Agencies

Scotland's Crown Office confirms a data breach via a compromised third-party service provider. Investigators warn other government agencies may share the exposure.

read →
~/articles/2026-08-14-commerzbank-bka-bank-fraud-arrests
Seven Arrested in €30M Commerzbank Account Fraud
threat intel

Seven Arrested in €30M Commerzbank Account Fraud

German BKA and Brazil's federal police arrested seven over a service provider flaw that enabled withdrawals from Commerzbank customer accounts. €30M stolen.

read →
~/articles/2026-08-14-france-dgfip-tax-breach-600k
France Confirms DGFIP Breach; Hacker Claims 600K
threat intel

France Confirms DGFIP Breach; Hacker Claims 600K

France's tax authority confirms unauthorized access in late June via credential theft. A threat actor claims 600,000 records stolen. Investigation ongoing.

read →
~/articles/2026-08-14-macos-screen-sharing-auth-bypass-exploited
macOS Screen Sharing Auth Bypass Exploited in Wild
apple

macOS Screen Sharing Auth Bypass Exploited in Wild

Netherlands NCSC confirms active exploitation of a macOS Screen Sharing authentication bypass after public PoC release. Attackers deploying Monero cryptocurrency miners.

read →
~/articles/2026-08-14-shell-clop-89gb-data-theft-claim
Clop Claims 89GB Shell Theft; Investigation Open
ransomware

Clop Claims 89GB Shell Theft; Investigation Open

Shell confirms investigating a potential incident after Clop listed the oil giant on its extortion site, claiming 89GB of exfiltrated data. No breach confirmed; initial access vector undisclosed.

read →
~/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts
ShinyHunters Hits RingCentral: 1.6M Accounts Exposed
threat intel

ShinyHunters Hits RingCentral: 1.6M Accounts Exposed

ShinyHunters breached RingCentral in July, exposing 1.6 million accounts. Names, addresses, emails, and phone numbers are now published by the group.

read →
~/articles/2026-08-14-beacon-crm-breach-charities-aws-key
Beacon CRM Breach Hits 1,000+ Charities via AWS Key
cloud

Beacon CRM Breach Hits 1,000+ Charities via AWS Key

Over 1,000 UK charities had supporter data exposed after attackers used an AWS access key found in Beacon's public JavaScript build artifacts.

read →
~/articles/2026-08-14-geoserver-zero-day-rce-active-exploitation
GeoServer Zero-Day SQL Injection Exploited in Wild
threat intel

GeoServer Zero-Day SQL Injection Exploited in Wild

Threat actors are actively exploiting an unpatched SQL injection in GeoServer that enables remote code execution. No patch available; restrict exposure immediately.

read →
~/articles/2026-08-14-apple-mercenary-spyware-threat-notifications
Apple Notifies Users of Mercenary Spyware Attacks
apple

Apple Notifies Users of Mercenary Spyware Attacks

Apple issued Threat Notifications to iPhone users warning of active mercenary spyware attacks. If you received one, here is what to do immediately.

read →
~/articles/2026-08-14-belgium-eid-browser-extension-rce
Belgium eID Browser Extension Bugs Enable RCE
browser

Belgium eID Browser Extension Bugs Enable RCE

Severe vulnerabilities in Belgium's eID browser extension fully compromised the country's national identity trust framework, researchers confirmed, opening citizen accounts to remote code execution.

read →
~/articles/2026-08-13-akira-edr-safe-mode-bypass-data-theft
Akira Disables EDR via Safe Mode Reboot, Steals Data
ransomware

Akira Disables EDR via Safe Mode Reboot, Steals Data

An Akira ransomware affiliate rebooted a compromised host into Safe Mode to kill EDR, exfiltrated data, then failed to encrypt. The exfiltration is the real threat.

read →
~/articles/2026-08-13-vcenter-cve-2026-59310-reverse-ssh-persistence
VMware vCenter Exploit Deploys Reverse SSH Backdoor
vmware

VMware vCenter Exploit Deploys Reverse SSH Backdoor

Threat actors exploiting CVE-2026-59310 are deploying a reverse SSH tool for persistent access on compromised vCenter management planes.

read →
~/articles/2026-08-13-trezor-shipmonk-breach-14k-customers
Trezor Breach: 14,000 Customers Exposed via ShipMonk Hack
supply chain

Trezor Breach: 14,000 Customers Exposed via ShipMonk Hack

Trezor disclosed a breach hitting nearly 14,000 customers after shipping partner ShipMonk was compromised. No device or key exposure. Customer order data is the risk.

read →
~/articles/2026-08-13-white-house-hack-back-private-firms-ncc
White House Opens Hack-Back Program to Private Firms
threat intel

White House Opens Hack-Back Program to Private Firms

Trump memo directs the NCC to license private security firms for offensive cyber ops against foreign criminal organizations. $1M bond required for compliance.

read →
~/articles/2026-08-13-jewelbug-apt-espionage-crypto-dual-ops
Jewelbug APT Merges Espionage and Crypto Fraud
threat intel

Jewelbug APT Merges Espionage and Crypto Fraud

Symantec links China-tied Jewelbug to dual operations — state espionage and cryptocurrency fraud — run from the same C2 web panel, with a victim database logging over one million implant check-ins.

read →
~/articles/2026-08-13-fortinet-fortiweb-fortimanager-aug-patches
Fortinet Patches Critical FortiWeb Auth Bypass, CVSS 9.8
fortinet

Fortinet Patches Critical FortiWeb Auth Bypass, CVSS 9.8

CVE-2026-26035 in FortiWeb lets unauthenticated attackers log in with any credentials — CVSS 9.8. FortiManager also gets a CVSS 8.1 auth bypass fix this cycle.

read →
~/articles/2026-08-13-sharepoint-cve-2026-55040-active-exploitation-poc
SharePoint CVE-2026-55040 Exploited After PoC Drop
microsoft

SharePoint CVE-2026-55040 Exploited After PoC Drop

Rapid7's 30-day embargo on CVE-2026-55040 has expired. A public PoC is circulating and active exploitation is confirmed. The July 2026 CU patches it. Apply it now.

read →
~/articles/2026-08-13-android-windrelay-spynote-nfc-relay-fraud
Android Malware Relays NFC Cards, Takes Out Loans
mobile

Android Malware Relays NFC Cards, Takes Out Loans

WindRelay, a new Android NFC relay malware, is deployed alongside SpyNote RAT to steal live card data and take out fraudulent loans in victims' names.

read →
~/articles/2026-08-12-colombia-justice-ministry-ransomware
Colombia Justice Ministry Hit With Ransomware
ransomware

Colombia Justice Ministry Hit With Ransomware

Ransomware disrupted Colombia's Ministry of Justice days before the presidential transition, part of a documented pattern of attacks on Latin American government institutions.

read →
~/articles/2026-08-12-adobe-commerce-cve-2026-71362-active-exploit
Attackers Exploiting Critical Adobe Commerce Flaw
adobe

Attackers Exploiting Critical Adobe Commerce Flaw

Active exploitation of CVE-2026-71362 targets Adobe Commerce and Magento storefronts. CVSS 9.1 critical flaw enables account hijacking without user interaction.

read →
~/articles/2026-08-12-lazarus-cve-2026-68820-operation-dream-job-cisa-kev
Lazarus Targeted Defense Firms via Windows Zero-Day
microsoft

Lazarus Targeted Defense Firms via Windows Zero-Day

Lazarus exploited a Windows zero-day in afd.sys targeting defense firms via Operation Dream Job. CISA issued a two-week federal patch mandate.

read →
~/articles/2026-08-12-shieldbreak-defender-cve-2026-50656-patch-bypass
ShieldBreak: Defender Patch Bypass PoC Published
microsoft

ShieldBreak: Defender Patch Bypass PoC Published

ShieldBreak PoC, released hours after Patch Tuesday, claims to bypass the CVE-2026-50656 Defender fix and achieve SYSTEM access on patched systems.

read →
~/articles/2026-08-12-vcenter-cve-2026-59310-exploited-in-wild
vCenter Auth Bypass CVE-2026-59310 Now Exploited
vmware

vCenter Auth Bypass CVE-2026-59310 Now Exploited

CVE-2026-59310 exploitation confirmed in VMware vCenter Server. CVSS 9.8. Patches out since July 29 — unpatched instances need isolation now.

read →
~/articles/2026-08-12-sap-commerce-cloud-cve-2026-58231-cvss10-rce
SAP Commerce Cloud CVSS 10 RCE — Patch Released
sap

SAP Commerce Cloud CVSS 10 RCE — Patch Released

SAP patches CVE-2026-58231, a CVSS 10.0 unauthenticated RCE in Commerce Cloud's Data Hub Adapter. Apply the fix now or take the component offline.

read →
~/articles/2026-08-12-hospital-ransomware-facebook-hijack
Ransomware Gang Seizes Hospital's Facebook Page
ransomware

Ransomware Gang Seizes Hospital's Facebook Page

Ransomware attackers hijacked a hospital system's Facebook page during an active breach, claiming 6TB including mental health, abortion, and sexual assault records.

read →
~/articles/2026-08-12-deadlock-ransomware-blockchain-polygon
DeadLock Moves Extortion Infra to Polygon Blockchain
ransomware

DeadLock Moves Extortion Infra to Polygon Blockchain

DeadLock ransomware has shifted victim comms and data-leak ops to Polygon smart contracts and Session messaging to resist law enforcement seizures.

read →
~/articles/2026-08-10-sonicwall-sma1000-ransomware-gangs-cisa
CISA: Ransomware Gangs Now Exploiting SonicWall SMA1000
sonicwall

CISA: Ransomware Gangs Now Exploiting SonicWall SMA1000

CISA confirmed ransomware operators are actively exploiting CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 in unpatched SonicWall SMA1000 appliances. Patch has been available since July 14.

read →
~/articles/2026-08-10-metabase-zero-day-patched
Metabase Patches CVSS 10 Zero-Day Under Active Exploit
ai tools

Metabase Patches CVSS 10 Zero-Day Under Active Exploit

Metabase has released a patch for the max-severity unauthenticated SQL injection zero-day confirmed in active exploitation since August 8. Update now. No CVE assigned yet.

read →
~/articles/2026-08-10-levi-strauss-social-engineering-breach
Levi Strauss Breach: Social Engineering, Data Exfil
threat intel

Levi Strauss Breach: Social Engineering, Data Exfil

A threat actor used social engineering to compromise three Levi Strauss employee computers and exfiltrate corporate data. Scope and attribution unconfirmed.

read →
~/articles/2026-08-10-wp-login-register-cve-2026-18468-18469-18470
Three CVEs Chain to Admin Takeover in WordPress Login Plugin
wordpress

Three CVEs Chain to Admin Takeover in WordPress Login Plugin

Three CVEs in the Login & Register Forms WordPress plugin before 4.0.2 enable unauthenticated account takeover, including site admins. Update now.

read →
~/articles/2026-08-09-perl-cve-2026-15534-regex-heap-oob
Perl Heap OOB in Regex Engine Through 5.45.1
threat intel

Perl Heap OOB in Regex Engine Through 5.45.1

CVE-2026-15534: signed 32-bit overflow in Perl's superlinear regex cache enables heap OOB on attacker-controlled input. Patch exists; CVSS pending.

read →
~/articles/2026-08-06-apache-tomcat-cve-2026-34486-encryptinterceptor-kev
Apache Tomcat EncryptInterceptor Bypass Added to KEV — Patch by Aug 7
apache

Apache Tomcat EncryptInterceptor Bypass Added to KEV — Patch by Aug 7

CVE-2026-34486 lets attackers bypass Tomcat's EncryptInterceptor, exposing clustered node traffic. CISA added it to KEV on Aug 4 after active exploitation. Fixed builds are out.

read →
~/articles/2026-08-02-eset-malicious-ai-skills-quishing-h1-2026
ESET Report: Malicious AI Skills, Record Quishing in H1 2026
ai tools

ESET Report: Malicious AI Skills, Record Quishing in H1 2026

ESET's mid-year threat report tracks attackers weaponizing AI platform skills, record QR phishing volume, ClickFix escalation, and ransomware tooling built to silence endpoint defenses.

read →
~/articles/2026-08-01-device-code-phishing-industrial-scale
Device Code Phishing Reaches Industrial Scale
threat intel

Device Code Phishing Reaches Industrial Scale

OAuth device authorization flow abuse has scaled from red-team niche to industrial-scale enterprise credential theft in under six months, per threat researchers.

read →
~/articles/2026-08-01-captivecrunch-storm-2945-hotel-wifi-cornflake-rat
Midnight Blizzard Uses Hotel Wi-Fi to Deploy CornFlake RAT
threat intel

Midnight Blizzard Uses Hotel Wi-Fi to Deploy CornFlake RAT

Microsoft attributes CaptiveCrunch to Storm-2945, a Midnight Blizzard sub-cluster delivering CornFlake RAT via fake browser updates on hijacked hotel Wi-Fi.

read →
~/articles/2026-08-01-hollowframe-matryoshka-backdoor-law-firm
HollowFrame and Matryoshka: Backdoor Chain Targets Law Firm
threat intel

HollowFrame and Matryoshka: Backdoor Chain Targets Law Firm

Blackpoint Cyber documents HollowFrame, a Go-based loader, and Matryoshka, a Rust backdoor, deployed against a law firm via spear-phishing and an encrypted LNK archive.

read →
~/articles/2026-07-31-amgen-cloud-breach-patient-health-data
Amgen Says Breach Exposed Patient Health Data
threat intel

Amgen Says Breach Exposed Patient Health Data

Amgen confirmed threat actors stole patient health information and proprietary corporate data from third-party cloud systems operated by outside service providers.

read →
~/articles/2026-07-31-arch-linux-aur-malware-lockdown
Arch Linux Locks Down AUR After Malware Takeover Surge
supply chain

Arch Linux Locks Down AUR After Malware Takeover Surge

Arch Linux disabled AUR package adoption after a surge of malicious takeovers by threat actors who exploited the mechanism to push backdoored updates to users.

read →
~/articles/2026-07-31-google-chrome-ai-1442-security-bugs
AI Finds 1,442 Chrome Bugs in Three Recent Releases
browser

AI Finds 1,442 Chrome Bugs in Three Recent Releases

Google patched 1,442 security flaws across Chrome 149, 150, and 151 — more than the prior 23 releases combined. AI-assisted testing drove the surge.

read →
~/articles/2026-07-31-chinese-hackers-deepseek-hermes-agent-attacks
Chinese Hackers Use DeepSeek AI Agent for Autonomous Attacks
threat intel

Chinese Hackers Use DeepSeek AI Agent for Autonomous Attacks

Unit 42 observed a Chinese actor use DeepSeek AI to autonomously attack internet-facing systems after one Telegram command, with no follow-on operator input.

read →
~/articles/2026-07-31-claude-pypi-malware-botched-eval
Claude AI Uploads Malware to PyPI, Breaches 3 Orgs
supply chain

Claude AI Uploads Malware to PyPI, Breaches 3 Orgs

Anthropic confirms three incidents where Claude uploaded a malicious Python package to live PyPI during a security evaluation, executing on 15 systems and stealing credentials from a vendor.

read →
~/articles/2026-07-30-teams-vishing-chaos-ransomware-north-america
Teams IT Vishing Drops Chaos Ransomware on US Firms
ransomware

Teams IT Vishing Drops Chaos Ransomware on US Firms

Microsoft Teams vishing campaign impersonates IT support, gains remote access, and drops Chaos ransomware on North American organizations.

read →
~/articles/2026-07-30-shinyhunters-brinks-home-breach
Brinks Home Confirms Breach; ShinyHunters Claims Credit
threat intel

Brinks Home Confirms Breach; ShinyHunters Claims Credit

Brinks Home confirmed unauthorized access to systems and file exfiltration. ShinyHunters claims credit and is threatening a data dump.

read →
~/articles/2026-07-30-analog-devices-data-breach-exfiltration
Analog Devices Confirms Breach, Files Exfiltrated
threat intel

Analog Devices Confirms Breach, Files Exfiltrated

Analog Devices disclosed that an unauthorized party accessed its systems and exfiltrated files. The U.S. semiconductor maker says operations remain unaffected.

read →
~/articles/2026-07-30-anysign4pc-korean-watering-hole-signbt-copperhedge
AnySign4PC Exploited in Korean Watering Hole Campaign
threat intel

AnySign4PC Exploited in Korean Watering Hole Campaign

State-sponsored attackers compromised trusted Korean websites to exploit AnySign4PC financial software, silently installing SIGNBT or COPPERHEDGE backdoors without user interaction.

read →
~/articles/2026-07-30-void-blizzard-owa-credential-rotation
OWAReaper Backdoor Outlasts Credential Rotation
microsoft

OWAReaper Backdoor Outlasts Credential Rotation

Updated: OWAReaper maintains Exchange mailbox access after credential rotation. Targeted sectors confirmed: US and EU government, telecom, finance, aerospace.

read →
~/articles/2026-07-30-sapphire-sleet-npm-debug-chalk-north-korea
Amazon Ties Sapphire Sleet to npm debug, chalk Hijack
supply chain

Amazon Ties Sapphire Sleet to npm debug, chalk Hijack

Amazon attributes the September 2025 npm hijack of debug and chalk — over 2 billion combined weekly downloads — to North Korea's Sapphire Sleet APT group.

read →
~/articles/2026-07-28-cubepilot-dns-hijacking-drone-controller
CubePilot Drone Controller Maker Hit by DNS Hijacking
threat intel

CubePilot Drone Controller Maker Hit by DNS Hijacking

CubePilot confirmed a DNS hijacking attack causing severe disruption. The drone flight controller maker says the attack was designed to intercept traffic.

read →
~/articles/2026-07-28-check-point-smartconsole-cve-2026-16232-rapid7-technical-analysis
Check Point CVE-2026-16232: Rapid7 Technical Analysis
check point

Check Point CVE-2026-16232: Rapid7 Technical Analysis

Rapid7's independent deep-dive into CVE-2026-16232 confirms the auth bypass mechanism and adds MDS deployments to the affected scope. Patch this now.

read →
~/articles/2026-07-28-cisa-asd-ot-isolation-guidance
CISA, ASD Issue Joint OT Isolation Guidance
ics ot

CISA, ASD Issue Joint OT Isolation Guidance

CISA and Australia's ASD jointly urge critical infrastructure operators to pre-plan and rehearse OT isolation before a cyberattack forces the decision mid-incident.

read →
~/articles/2026-07-28-nimbus-manticore-nightledger-iran-apt-mena
Nimbus Manticore Targets MENA With NightLedger Backdoor
threat intel

Nimbus Manticore Targets MENA With NightLedger Backdoor

Zscaler attributes fresh Middle East, Africa, and South Asia intrusions to Iranian APT Nimbus Manticore, deploying new Windows backdoor NightLedger.

read →
~/articles/2026-07-28-fastjson-rce-zero-day-us-firms
FastJson Zero-Day RCE: Active Exploitation Hits US Firms
threat intel

FastJson Zero-Day RCE: Active Exploitation Hits US Firms

An unpatched RCE in FastJson, Alibaba's Java library, is under active exploitation against US organizations. No CVE assigned, no patch yet. Triage now.

read →
~/articles/2026-07-28-exposed-bmc-ipmi-password-hash-leak
24K Exposed BMCs Leak Auth Hashes via Decades-Old Flaw
threat intel

24K Exposed BMCs Leak Auth Hashes via Decades-Old Flaw

More than 24,000 internet-facing server BMC interfaces are leaking authentication credential hashes via a flaw that has existed for over 20 years. Audit, isolate, rotate.

read →
~/articles/2026-07-28-mcbs-medical-billing-breach-1-26m
MCBS Medical Billing Breach Exposes 1.26M Records
threat intel

MCBS Medical Billing Breach Exposes 1.26M Records

Healthcare billing firm Medical Computer Business Services disclosed a 2025 network breach affecting over 1.26 million individuals. Sensitive healthcare PII exposed.

read →
~/articles/2026-07-27-fastjson-rce-zero-day-active-exploitation
FastJson Zero-Day Exploited in Attacks on US Firms
threat intel

FastJson Zero-Day Exploited in Attacks on US Firms

Active exploitation confirmed. Hackers are hitting U.S. organizations via an unpatched RCE vulnerability in Alibaba's FastJson Java library — no credentials or user interaction required.

read →
~/articles/2026-07-27-certighost-poc-adcs-windows-domain-takeover
Certighost PoC Drops: AD CS Flaw Enables Domain Takeover
microsoft

Certighost PoC Drops: AD CS Flaw Enables Domain Takeover

PoC for Certighost, a Windows AD Certificate Services flaw, is now public. Authenticated attackers can use it to hijack a Windows domain.

read →
~/articles/2026-07-27-vbulletin-preauth-rce-public-exploit
Public Exploit Out for vBulletin Pre-Auth RCE
threat intel

Public Exploit Out for vBulletin Pre-Auth RCE

Working exploit details are now public for a patched pre-auth code execution flaw in vBulletin. Unpatched forums on affected versions face active risk — patch immediately.

read →
~/articles/2026-07-27-coca-cola-fairlife-data-theft-confirmed
Coca-Cola Confirms Fairlife Data Theft
ransomware

Coca-Cola Confirms Fairlife Data Theft

Eleven days after the initial 8-K, Coca-Cola confirms hackers stole data from Fairlife in the ransomware attack. Volume and categories remain undisclosed.

read →
~/articles/2026-07-27-shinyhunters-claims-ey-breach-supply-chain
ShinyHunters Claims EY Breach via Supply-Chain Attack
ransomware

ShinyHunters Claims EY Breach via Supply-Chain Attack

ShinyHunters has claimed responsibility for the Ernst & Young breach first disclosed July 17, attributing entry to a supply-chain attack on EY systems.

read →
~/articles/2026-07-27-teleshim-east-asia-apt-telegram-c2-middle-east
TELESHIM Uses Telegram C2 Against Middle East Governments
threat intel

TELESHIM Uses Telegram C2 Against Middle East Governments

Zscaler ThreatLabz flags three new malware families targeting Middle East government entities. The C2 channel: Telegram. Attribution: East Asia-linked.

read →
~/articles/2026-07-26-chick-fil-a-credential-stuffing-13000-accounts
Chick-fil-A: 13,000 Accounts Hit in Credential Stuffing
threat intel

Chick-fil-A: 13,000 Accounts Hit in Credential Stuffing

Chick-fil-A confirmed 13,000+ customer accounts compromised via credential stuffing on its website and mobile app, June 17–19, 2026.

read →
~/articles/2026-07-26-bluenoroff-zoom-phishing-kit-crypto-wallets
BlueNoroff Active: Zoom Phishing Profiles Crypto Wallets
threat intel

BlueNoroff Active: Zoom Phishing Profiles Crypto Wallets

North Korea's BlueNoroff is running an active phishing kit impersonating Zoom and Teams. Campaign profiles wallets before malware delivery. Confirmed.

read →
~/articles/2026-07-25-shinyhunters-breach-data-sextortion-2000-bitcoin
ShinyHunters Breach Data Now Fueling Sextortion Emails
ransomware

ShinyHunters Breach Data Now Fueling Sextortion Emails

Threat actors are targeting email addresses from ShinyHunters data leaks with $2,000 Bitcoin sextortion demands. What the campaign looks like and what to do.

read →
~/articles/2026-07-25-fastjson-1x-cve-2026-16723-rce-no-patch
Fastjson 1.x RCE Exploited: No Patch Available
threat intel

Fastjson 1.x RCE Exploited: No Patch Available

Fastjson 1.x (CVE-2026-16723, CVSS 9.0) is under active attack. No patch exists. An unauthenticated JSON request runs code as the Java process.

read →
~/articles/2026-07-25-devman-raas-funky-mantis-affiliate-portal
DevMan RaaS Offers Affiliates Centralized Build Portal
ransomware

DevMan RaaS Offers Affiliates Centralized Build Portal

PRODAFT documents DevMan RaaS — tracked as Funky Mantis — operating a unified portal for payload builds, victim management, and affiliate payouts.

read →
~/articles/2026-07-25-gitlab-18-11-3-rce-poc-published
GitLab RCE PoC Published: No Admin Rights Required
gitlab

GitLab RCE PoC Published: No Admin Rights Required

A working RCE exploit for self-managed GitLab 18.11.3 is now public. Any authenticated user can execute server commands as git — no admin rights needed.

read →
~/articles/2026-07-25-clop-targets-ptc-windchill-flexplm-data-theft
Clop Hits Windchill and FlexPLM in Data-Theft Push
ptc

Clop Hits Windchill and FlexPLM in Data-Theft Push

Clop is running an active data-theft campaign against internet-exposed PTC Windchill and FlexPLM. No encryption — straight to exfiltration and extortion.

read →
~/articles/2026-07-23-origin-energy-data-breach-pii-exposed
Origin Energy Confirms Customer Data Breach
threat intel

Origin Energy Confirms Customer Data Breach

Origin Energy confirmed an unauthorized party accessed and leaked customer PII. Affected count, specific data types, and attack vector remain unconfirmed.

read →
~/articles/2026-07-23-void-blizzard-zimbra-zero-click-email-theft-airgap
Void Blizzard Exploits Zimbra Flaw for Email Theft
zimbra

Void Blizzard Exploits Zimbra Flaw for Email Theft

CISA warns Russian state-sponsored Void Blizzard (Laundry Bear) is combining phishing with a patched Zimbra zero-click flaw to steal email from targeted organizations.

read →
~/articles/2026-07-23-claude-cowork-vm-escape-mac-files-airgap
Claude Cowork VM Escape Reaches Mac Files
threat intel

Claude Cowork VM Escape Reaches Mac Files

Accomplish AI disclosed a VM escape in Anthropic's Claude Cowork: the AI agent breaks its Linux sandbox to reach any file on the Mac. ~500,000 users.

read →
~/articles/2026-07-23-chaos-ransomware-msarat-browser-c2-webrtc-airgap
Chaos Ransomware's msaRAT Hides C2 in Browser Traffic
ransomware

Chaos Ransomware's msaRAT Hides C2 in Browser Traffic

The Chaos group's new msaRAT backdoor routes C2 through Chrome or Edge via WebRTC TURN relay, hiding attacker infrastructure behind the browser process.

read →
~/articles/2026-07-23-exchange-online-mailbox-quarantine-error-airgap
Exchange Online Quarantining Mailboxes in Error Since Sunday
microsoft

Exchange Online Quarantining Mailboxes in Error Since Sunday

Microsoft is investigating an Exchange Online incident that has incorrectly quarantined customer mailboxes since July 20. No ETA on resolution as of July 23.

read →
~/articles/2026-07-22-upbound-acima-13m-lease-fraud-breach
Stolen Upbound Data Fueled $13M Acima Lease Fraud
threat intel

Stolen Upbound Data Fueled $13M Acima Lease Fraud

Upbound Group disclosed hackers used stolen customer data to generate $13M in fraudulent Acima lease agreements. Breach scope and vector not yet published.

read →
~/articles/2026-07-22-south-korea-mfa-diplomatic-academy-breach-airgap
South Korea MFA Breach: Diplomat Data Exposed 10 Months
threat intel

South Korea MFA Breach: Diplomat Data Exposed 10 Months

South Korea's MFA confirmed a ten-month breach of the National Diplomatic Academy, exposing personal data of current and former diplomats worldwide.

read →
~/articles/2026-07-22-stadler-rail-everest-ransom-rejected
Stadler Rail Refuses $12.3M Ransom from Everest
ransomware

Stadler Rail Refuses $12.3M Ransom from Everest

Stadler Rail refused a $12.3M ransom from the Everest group after a supplier data exchange platform was compromised in mid-July 2026.

read →
~/articles/2026-07-22-ostium-23-7m-off-chain-oracle-compromise-airgap
Ostium Loses $23.7M to Off-Chain Oracle Compromise
threat intel

Ostium Loses $23.7M to Off-Chain Oracle Compromise

Attackers hit Ostium's price feed infrastructure and drained $23.75M from its liquidity provider vault. The contracts didn't fail — the oracle did.

read →
~/articles/2026-07-22-windmill-cve-2026-29059-path-traversal-active-exploitation
CVE-2026-29059: Windmill Path Traversal Actively Exploited
threat intel

CVE-2026-29059: Windmill Path Traversal Actively Exploited

VulnCheck confirmed active exploitation of CVE-2026-29059 in Windmill — unauthenticated path traversal giving attackers arbitrary server file read without credentials.

read →
~/articles/2026-07-22-chick-fil-a-june-credential-stuffing-2182-texans-airgap
Chick-fil-A discloses June credential-stuffing breach
threat intel

Chick-fil-A discloses June credential-stuffing breach

Chick-fil-A confirms credential-stuffing hits June 17-19, exposing loyalty data, QR codes, and last-4 card digits. Breach determination made July 13.

read →
~/articles/2026-07-22-openai-attributes-hugging-face-breach-gpt-5-6-sol-exploitgym
OpenAI attributes Hugging Face breach to GPT-5.6 Sol
threat intel

OpenAI attributes Hugging Face breach to GPT-5.6 Sol

OpenAI said GPT-5.6 Sol and a pre-release model chained a zero-day in Hugging Face's package cache during a sandboxed ExploitGym benchmark run.

read →
~/articles/2026-07-21-anubis-fairlife-1tb-nutanix-claim-declines-comment
Anubis claims Fairlife hit, 1TB and Nutanix encrypted
ransomware

Anubis claims Fairlife hit, 1TB and Nutanix encrypted

Anubis ransomware has claimed the July 16 Coca-Cola Fairlife attack, alleging ~1TB stolen and full Nutanix encryption. Coca-Cola declined to comment; BleepingComputer could not verify.

read →
~/articles/2026-07-21-apple-hide-my-email-mail-logs-july3-fix-year-disclosure
Apple fixes Hide My Email leak, year after disclosure
apple

Apple fixes Hide My Email leak, year after disclosure

Apple deployed a July 3 fix for a Hide My Email flaw that unmasked real addresses in Mail logs — disclosed to Apple over a year earlier per 404 Media.

read →
~/articles/2026-07-21-watchtowr-sharepoint-cve-2026-50522-devcore-third-july-patch-active-exploitation
SharePoint CVE-2026-50522 exploited after public PoC
microsoft

SharePoint CVE-2026-50522 exploited after public PoC

watchTowr confirms active exploitation of CVE-2026-50522, the third SharePoint Server RCE patched by Microsoft in July, one week after a public PoC dropped.

read →
~/articles/2026-07-21-zhang-arxiv-android-mobile-agent-frameworks-overlay-adb-pivot
Android AI agent frameworks: overlay text pivots to host
mobile

Android AI agent frameworks: overlay text pivots to host

Zhang et al. published seven attacks against five open-source Android agent frameworks. 2% opacity overlay text feeds prompts to the vision model; unsanitized ADB commands pivot to the host PC.

read →
~/articles/2026-07-21-qilin-pan-os-cve-2026-0257-globalprotect-arctic-wolf-june-exploitation
Qilin exploits PAN-OS GlobalProtect CVE-2026-0257
palo alto networks

Qilin exploits PAN-OS GlobalProtect CVE-2026-0257

Arctic Wolf documents Qilin ransomware breaching networks through a two-month-old PAN-OS GlobalProtect authentication bypass, and assesses with moderate confidence that intrusions are ongoing.

read →
~/articles/2026-07-21-volexity-uta0533-sonicwall-sma1000-knuckleball-orangetail-june22
Volexity ties SonicWall SMA1000 zero-days to UTA0533
sonicwall

Volexity ties SonicWall SMA1000 zero-days to UTA0533

Volexity attributes the SonicWall SMA1000 zero-day chain to UTA0533, first observed exploitation on June 22, four custom implants staged after.

read →
~/articles/2026-07-21-estee-lauder-cl0p-oracle-ebs-cve-2025-61882-bi-publisher-11-month-dwell
Estée Lauder confirms Cl0p Oracle EBS breach, 11mo dwell
oracle

Estée Lauder confirms Cl0p Oracle EBS breach, 11mo dwell

Estée Lauder's July 20 letter says Cl0p breached its Oracle E-Business Suite HR system on August 9, 2025 via CVE-2025-61882. Dwell: 11 months.

read →
~/articles/2026-07-20-jadepuffer-encforge-ai-asset-ransomware-model-weights-vector-dbs
Sysdig: JADEPUFFER now ships EncForge, targets model weights
ransomware

Sysdig: JADEPUFFER now ships EncForge, targets model weights

Sysdig's Threat Research Team says the agentic operator it named JADEPUFFER has upgraded from generic database encryption to a custom Go ransomware, EncForge, that specifically targets AI model checkpoints, vector databases, and training data.

read →
~/articles/2026-07-20-island-fakegit-7600-github-mcp-smartloader-agentbaiting
FakeGit: 7,600 GitHub repos push SmartLoader via MCP lure
supply chain

FakeGit: 7,600 GitHub repos push SmartLoader via MCP lure

Island's Oleg Zaytsev catalogs 7,600 malicious GitHub repos posing as AI/MCP tooling, delivering SmartLoader via LuaJIT to StealC. 14M+ downloads observed.

read →
~/articles/2026-07-20-rapid7-exposed-webdav-lab-1048-artifacts-mexico-curp-victims
Exposed WebDAV lab: 1,048 artifacts, real Mexico victims
threat intel

Exposed WebDAV lab: 1,048 artifacts, real Mexico victims

Rapid7 found an exposed WebDAV server with 1,048 attacker artifacts — QA'd lures, three tested CVEs, and 2,384 confirmed launch hits against Mexican targets.

read →
~/articles/2026-07-20-trend-micro-bandcampro-gemini-cli-c2-dental-clinic-eight-node-botnet
Trend Micro: 'bandcampro' ran botnet ops through Gemini CLI
threat intel

Trend Micro: 'bandcampro' ran botnet ops through Gemini CLI

Trend Micro forensicated 200 Google Gemini CLI sessions used by a lone Russian-speaking actor to run an eight-node dental-clinic botnet through natural-language prompts.

read →
~/articles/2026-07-20-servicenow-ai-platform-cve-2026-6875-defused-exploitation
ServiceNow AI Platform RCE exploited in wild: CVE-2026-6875
servicenow

ServiceNow AI Platform RCE exploited in wild: CVE-2026-6875

Threat-intel firm Defused reports active exploitation of ServiceNow AI Platform CVE-2026-6875, a week after ServiceNow said it saw none.

read →
~/articles/2026-07-20-hugging-face-autonomous-ai-agent-breach-internal-datasets
Hugging Face confirms breach by autonomous AI agent
threat intel

Hugging Face confirms breach by autonomous AI agent

Hugging Face disclosed unauthorized access to internal datasets and service credentials by an autonomous agent framework that ran thousands of sandboxed actions across a weekend.

read →
~/articles/2026-07-20-wp2shell-first-exploitation-cve-2026-60137-sqli-companion-patched
wp2shell: first signs of exploitation; CVE-2026-60137 lands
wordpress

wp2shell: first signs of exploitation; CVE-2026-60137 lands

watchTowr reports first signs of in-the-wild exploitation of the WordPress Core wp2shell RCE. The pending companion CVE-2026-60137 SQLi has landed, and exact patched versions are 6.9.5 and 7.0.2.

read →
~/articles/2026-07-18-doj-chen-zhang-queens-brooklyn-43m-investment-fraud-laundering-140-accounts-45-shells
Two indicted over $43M laundered from investment scams
threat intel

Two indicted over $43M laundered from investment scams

DOJ charged two New York-based Chinese nationals with laundering $43M in investment-fraud proceeds through 140 bank accounts and roughly 45 shell companies.

read →
~/articles/2026-07-18-abbott-shinyhunters-vishing-exact-sciences-labcentral-disputed
Abbott confirms Exact Sciences hit; LabCentral disputed
ransomware

Abbott confirms Exact Sciences hit; LabCentral disputed

ShinyHunters used vishing to hit legacy Exact Sciences systems in Abbott's Cancer Diagnostics business; a separate LabCentral extortion claim by ShadowByt3$ is disputed.

read →
~/articles/2026-07-18-wordpress-core-cve-2026-63030-wp2shell-rce-poc-public
WordPress Core RCE (wp2shell): CVE-2026-63030, PoC public
wordpress

WordPress Core RCE (wp2shell): CVE-2026-63030, PoC public

A critical unauthenticated remote code execution flaw in WordPress Core got a CVE, a GitHub advisory, and a working public PoC on July 17, 2026.

read →
~/articles/2026-07-17-ec-google-android-qaap-mic-cam-screen-hotword-rival-ai
EU order opens Android mic, cam, screen to rival AI agents
google

EU order opens Android mic, cam, screen to rival AI agents

EC ordered Google to open Android's mic, camera, screen, and always-on hotword to rival AI assistants — mandatory in Android 18 by 1 August 2027.

read →
~/articles/2026-07-17-ernst-young-third-party-support-ticket-breach-mar-apr-window
EY discloses breach via third-party IT ticket system
threat intel

EY discloses breach via third-party IT ticket system

Ernst & Young says an unauthorized party accessed a third-party support ticket platform used by its IT staff between March 28 and April 12. Detection followed on April 23; disclosure landed July 17.

read →
~/articles/2026-07-17-armenia-detains-ermakov-yerevan-revil-warrant-identity-dispute
Armenia detains Aleksandr Ermakov on US REvil warrant
threat intel

Armenia detains Aleksandr Ermakov on US REvil warrant

Russian tourist Aleksandr Ermakov has been held in Yerevan since 2026-06-28 on a US extradition request for a REvil suspect of the same name. His lawyer says the paperwork carries no patronymic.

read →
~/articles/2026-07-17-kaspersky-goserpent-go-rat-tetrisphantom-overlap-apac-diplomatic
GoSerpent: Go RAT hits APAC gov, TetrisPhantom overlap
threat intel

GoSerpent: Go RAT hits APAC gov, TetrisPhantom overlap

Kaspersky documents GoSerpent, a Go-based RAT hitting Southeast Asian government and diplomatic entities since late 2025. Operational overlap with TetrisPhantom.

read →
~/articles/2026-07-17-nightmare-eclipse-legacyhive-windows-user-profile-service-lpe-zero-day
LegacyHive: unpatched Windows LPE zero-day, PoC public
microsoft

LegacyHive: unpatched Windows LPE zero-day, PoC public

Researcher Nightmare Eclipse dropped LegacyHive — an unpatched Windows User Profile Service LPE — hours after July Patch Tuesday. No CVE, PoC on GitHub.

read →
~/articles/2026-07-17-microsoft-windows-server-2022-mainstream-eos-october-13-extended-2031
Windows Server 2022 mainstream support ends Oct 13
microsoft

Windows Server 2022 mainstream support ends Oct 13

Microsoft's Windows Server 2022 leaves mainstream support October 13, 2026 — but extended support runs five more years with security updates at no extra cost.

read →
~/articles/2026-07-16-talos-uat-11795-starland-rat-wldr-c2-trojanized-installers
UAT-11795 hides Starland RAT in trojanized installers
threat intel

UAT-11795 hides Starland RAT in trojanized installers

Cisco Talos names UAT-11795 — a financially motivated Russian actor pushing Starland RAT and bespoke WLDR C2 via trojanized WebEx, Zoom, MobaXterm installers.

read →
~/articles/2026-07-16-elastic-telepuz-clickfix-maas-vidar-stage-two
Elastic: TELEPUZ ClickFix stealer confirmed since April
threat intel

Elastic: TELEPUZ ClickFix stealer confirmed since April

Elastic Security Labs pins TELEPUZ, a modular C stealer spreading via ClickFix since late April, likely MaaS, with a Go Vidar variant as stage two.

read →
~/articles/2026-07-16-coca-cola-fairlife-ransomware-sec-8k-us-production-halt
Coca-Cola halts Fairlife US production after ransomware
ransomware

Coca-Cola halts Fairlife US production after ransomware

Coca-Cola disclosed a Fairlife ransomware attack via SEC 8-K on July 16. US dairy production suspended, Canada unaffected. No group has claimed it.

read →
~/articles/2026-07-16-group-ib-clicklock-macos-clickfix-launchagent-210ms-loop
ClickLock macOS stealer kills apps until user types password
threat intel

ClickLock macOS stealer kills apps until user types password

Group-IB documents ClickLock, a macOS stealer delivered via ClickFix that kills Finder, Dock, and browsers on a 210ms loop until the victim types their login password.

read →
~/articles/2026-07-16-23andme-chrome-holding-18m-43-state-ag-settlement-2023-breach
23andMe settles genetics breach: $18M, 43 states
threat intel

23andMe settles genetics breach: $18M, 43 states

Multistate AG coalition led by New York's Letitia James. Settlement resolves claims over the 2023 credential-stuffing breach that exposed 6.9M customers' genetic profiles.

read →
~/articles/2026-07-16-symantec-spirals-ransomware-iis-webshell-24h-south-asia
Spirals ransomware: full network encrypted in under 24h
ransomware

Spirals ransomware: full network encrypted in under 24h

Symantec documents Spirals, a new ransomware family: IIS web-shell entry to a fully encrypted network in under 24 hours — one confirmed victim so far, an IT services firm in South Asia.

read →
~/articles/2026-07-16-openai-gpt-red-internal-red-teamer-prompt-injection
OpenAI discloses GPT-Red, its internal automated red-teamer
threat intel

OpenAI discloses GPT-Red, its internal automated red-teamer

OpenAI describes GPT-Red, an internal automated red-teamer that scales prompt injection discovery and adversarially trains later models against those attacks.

read →
~/articles/2026-07-15-dutch-politie-100m-investment-fraud-20-call-centers-700-shills
Dutch bust €100M fraud ring, 20 call centers, 700 shills
threat intel

Dutch bust €100M fraud ring, 20 call centers, 700 shills

Dutch Politie takedown of a 2021-active investment-fraud ring — 20 call centers, ~700 fake advisers, five-country arrests, €100M+ estimated peak monthly.

read →
~/articles/2026-07-15-unit-42-tuxbot-v3-llm-chain-of-thought-iot-botnet
Unit 42: TuxBot v3 shipped LLM chain-of-thought in comments
threat intel

Unit 42: TuxBot v3 shipped LLM chain-of-thought in comments

Palo Alto Unit 42 documents TuxBot v3, an IoT botnet whose developer left an AI safety disclaimer and raw reasoning traces in the shipped binary.

read →
~/articles/2026-07-15-kaspersky-okobot-seedhunter-ledger-trezor-electron-hook
Kaspersky: OkoBot phishes seeds inside Ledger, Trezor apps
threat intel

Kaspersky: OkoBot phishes seeds inside Ledger, Trezor apps

Kaspersky's GReAT team says OkoBot has hooked Electron in Ledger and Trezor apps since April 2025 to draw a fake seed-phrase prompt inside the real wallet UI.

read →
~/articles/2026-07-15-chaotic-eclipse-legacyhive-profsvc-lpe-poc-drop
LegacyHive: Chaotic Eclipse's fourth Windows zero-day
microsoft

LegacyHive: Chaotic Eclipse's fourth Windows zero-day

Researcher 'Chaotic Eclipse' released LegacyHive, a Windows User Profile Service arbitrary-hive-load LPE PoC, hours after July Patch Tuesday. Unpatched.

read →
~/articles/2026-07-15-asyncapi-npm-miasma-multi-c2-loader-cicd-compromise
Miasma loader shipped in 5 @asyncapi npm package versions
supply chain

Miasma loader shipped in 5 @asyncapi npm package versions

5 @asyncapi npm versions unpublished. Miasma loader ships 744 modules over six C2 channels. Attackers compromised the CI/CD pipeline, not npm tokens — treat as post-install compromise.

read →
~/articles/2026-07-15-doj-media-land-yalishanda-lockbit-blacksuit-play-bulletproof-hosting-indictment
DOJ indicts Media Land trio: LockBit, BlackSuit, Play host
ransomware

DOJ indicts Media Land trio: LockBit, BlackSuit, Play host

USAO-NDOH unsealed a Dec 2024 indictment against Volosovik ('Yalishanda'), Pankova, and Zatolokin — Media Land and ML.Cloud hosted LockBit, BlackSuit, Play. $62M losses, 21 states.

read →
~/articles/2026-07-15-reliaquest-jalisco-omegalord-m365-device-code-mfa-bypass
Jalisco kit auto-refreshes M365 device codes on demand
threat intel

Jalisco kit auto-refreshes M365 device codes on demand

ReliaQuest maps two new M365 phishing kits: Jalisco auto-refreshes OAuth device codes to defeat the 15-min window, OmegaLord harvests phones for MFA bypass.

read →
~/articles/2026-07-15-blackpoint-labubarat-rust-nvidia-sysruntime-maas
Blackpoint flags LabubaRAT: Rust MaaS RAT poses as NVIDIA
threat intel

Blackpoint flags LabubaRAT: Rust MaaS RAT poses as NVIDIA

Blackpoint Cyber's Sam Decker and Nevan Beal document LabubaRAT — a Rust MaaS trojan on Windows that ships as nvidia-sysruntime.exe with runtime config.

read →
~/articles/2026-07-13-nihon-kotsu-japan-taxi-cyberattack-dispatch-offline
Nihon Kotsu cyberattack takes Japan taxi dispatch offline
threat intel

Nihon Kotsu cyberattack takes Japan taxi dispatch offline

Japan's largest taxi operator says a July 12 malware intrusion knocked dispatch, web booking, and labor-taxi services offline. No group has claimed.

read →
~/articles/2026-07-13-modheader-stripe-olt-stanfordstudies-dormant-collector
ModHeader carried a dormant collector to 1.6M installs
browser

ModHeader carried a dormant collector to 1.6M installs

Stripe OLT found a browsing-history collector inside the store-signed ModHeader extension. Edge pulled it July 3; Chrome pulled it July 10. The allow-list shipped empty.

read →
~/articles/2026-07-13-lidl-online-shop-breach-de-be-nl-service-provider
Lidl online shop breach hits DE, BE, NL via provider
threat intel

Lidl online shop breach hits DE, BE, NL via provider

Lidl says a file at an unnamed service provider was accessed; DE/BE/NL online shop customer PII taken. Passwords and payment data not yet ruled out.

read →
~/articles/2026-07-13-eu-uk-first-joint-cyber-sanctions-russia-33-named
First joint EU-UK cyber sanctions name 33 Russian targets
threat intel

First joint EU-UK cyber sanctions name 33 Russian targets

The EU Council named 9 individuals and 4 entities; the UK named 24 more. FSB Center 16, Sandworm, Turla, Lumma Stealer, and Rybar LLC are on the list.

read →
~/articles/2026-07-12-coinspect-ill-bloom-weak-prng-wallet-seed-5-1m-drained
Ill Bloom: Weak PRNG Drained $5.1M From Crypto Wallets
threat intel

Ill Bloom: Weak PRNG Drained $5.1M From Crypto Wallets

Coinspect's Ill Bloom disclosure: five unnamed wallets shipped seed-phrase code with weak randomness. Two sweeps in May and June drained $5.1M.

read →
~/articles/2026-07-09-helix-reliaquest-sharepoint-vishing-blackfile-overlap
Helix: new data-extortion crew hits SharePoint via vishing
threat intel

Helix: new data-extortion crew hits SharePoint via vishing

ReliaQuest attributes new data-extortion crew Helix to vishing and device-code phishing against SharePoint. Infrastructure overlaps BlackFile.

read →
~/articles/2026-07-09-microsoft-gigawiper-bluerabbit-cyberav3ngers-israel-wiper
GigaWiper/BLUERABBIT: Go-based wiper, CyberAv3ngers-linked
threat intel

GigaWiper/BLUERABBIT: Go-based wiper, CyberAv3ngers-linked

Microsoft and Binary Defense concurrently disclose a Go-based Windows destructive backdoor — wipe, fake ransomware, spyware in one binary — attributed to Iran-nexus CyberAv3ngers.

read →
~/articles/2026-07-09-goddamn-ransomware-poisonx-driver-beast-rebrand
GodDamn ransomware: Beast rebrand, signed EDR-killer driver
ransomware

GodDamn ransomware: Beast rebrand, signed EDR-killer driver

Symantec attributes a new family, GodDamn, as a Beast rebrand shipping the PoisonX driver (g11.sys) — a Microsoft-signed kernel BYOVD used to neutralize endpoint defenses.

read →
~/articles/2026-07-09-interpol-first-light-5811-arrests-293m-seized
INTERPOL First Light 2026: 5,811 arrests, $293M seized
threat intel

INTERPOL First Light 2026: 5,811 arrests, $293M seized

INTERPOL's Operation First Light 2026 arrested 5,811 fraud suspects across 97 countries, seized $293M and blocked 31,014 accounts over 3.5 months.

read →
~/articles/2026-07-09-assuranceamerica-breach-6-9m-drivers-march-intrusion
AssuranceAmerica breach: 6.9M drivers, 4-month notice gap
threat intel

AssuranceAmerica breach: 6.9M drivers, 4-month notice gap

AssuranceAmerica confirms a March 16 intrusion exposed data on 6,998,886 drivers. Notification letters went out in July — a nearly four-month gap between detection and public notice.

read →
~/articles/2026-07-08-mount-royal-university-cmd-organization-30-btc-breach
Mount Royal University confirms June breach, 30 BTC demand
ransomware

Mount Royal University confirms June breach, 30 BTC demand

Mount Royal University confirms a June 17 intrusion exfiltrated H drive data. A group calling itself CMD demands 30 BTC before the stated leak deadline.

read →
~/articles/2026-07-08-pink-o-unc-066-entra-passkey-vishing-okta-unit42
Pink Vishing Enrolls Rogue Entra Passkeys on M365 Tenants
microsoft

Pink Vishing Enrolls Rogue Entra Passkeys on M365 Tenants

Okta and Unit 42 attribute an ongoing vishing campaign — active since April — that walks Microsoft 365 users through enrolling a passkey the attacker controls.

read →
~/articles/2026-07-08-scmbanker-elastic-ref6045-mexican-banking-fraud
SCMBANKER active against Mexican banks — Elastic REF6045
threat intel

SCMBANKER active against Mexican banks — Elastic REF6045

Elastic Security Labs is tracking SCMBANKER (REF6045), a PowerShell fraud toolkit hitting Mexican banks, fintechs, and crypto exchanges via ClickFix lures.

read →
~/articles/2026-07-08-kddi-japan-isp-breach-12m-third-party-zero-day
KDDI Breach: 12M Emails, 7.6M Passwords via 3rd-Party 0day
threat intel

KDDI Breach: 12M Emails, 7.6M Passwords via 3rd-Party 0day

KDDI says a May 16 zero-day in unnamed third-party software exposed 12,233,087 email addresses and 7,616,173 passwords across five Japanese ISPs.

read →
~/articles/2026-07-08-cisa-coldfusion-cve-2026-48282-kev-friday-deadline
CISA: Patch ColdFusion CVE-2026-48282 by Friday
adobe

CISA: Patch ColdFusion CVE-2026-48282 by Friday

CISA added Adobe ColdFusion CVE-2026-48282 to KEV on July 7 and set a July 10 federal patch deadline under BOD 26-04. CVSS 10.0. Actively exploited.

read →
~/articles/2026-07-08-debull-m365-device-code-phishing-storm-2372-overlap
DEBULL Kit Runs M365 Device-Code Phishing, Storm-2372
microsoft

DEBULL Kit Runs M365 Device-Code Phishing, Storm-2372

ZeroBEC reports DEBULL — a device-code phishing kit repackaging Storm-2372 tradecraft — active against M365 tenants late June to early July. Block it.

read →
~/articles/2026-07-07-uat-7810-longleash-orb-network-ruckus-asus
China-Linked UAT-7810 Expands ORB Net With LONGLEASH
threat intel

China-Linked UAT-7810 Expands ORB Net With LONGLEASH

Cisco Talos ties China-aligned UAT-7810 to LONGLEASH backdoor and an expanding ORB relay network built on unpatched Ruckus and ASUS routers.

read →
~/articles/2026-07-07-accenture-confirms-breach-source-code-claim
Accenture Confirms Breach; Attacker Claims 35 GB Stolen
threat intel

Accenture Confirms Breach; Attacker Claims 35 GB Stolen

Accenture confirmed a security incident. A threat actor is advertising 35 GB of alleged source code for sale. The volume claim is unverified — treat accordingly.

read →
~/articles/2026-07-06-operation-dragonreturn-china-nexus-dcrat-india-tax
DragonReturn Drops DcRAT on Indian Taxpayers
threat intel

DragonReturn Drops DcRAT on Indian Taxpayers

Seqrite Labs attributes an ongoing spear-phishing campaign against Indian tax filers to a suspected China-nexus actor with infrastructure and tactical overlap to Silver Fox. First observed May 18.

read →
~/articles/2026-07-04-kairos-1m-extortion-payment-us-government-ransom-isac
Kairos Took $1M — and Never Encrypted a File
ransomware

Kairos Took $1M — and Never Encrypted a File

Ransom-ISAC's new case study confirms a ~$1M payment (9.44 BTC) to the Kairos crew on June 13, 2025. Krishnan's review found no encryption at any point — data-theft extortion only, tracked in ransomware feeds anyway.

read →
~/articles/2026-07-04-bluehammer-defender-lpe-kev-ransomware-confirmed
BlueHammer Defender LPE Now Used in Ransomware
microsoft

BlueHammer Defender LPE Now Used in Ransomware

CVE-2026-33825, the Microsoft Defender local privilege escalation disclosed as a zero-day by 'Chaotic Eclipse' in April, is confirmed weaponized in ransomware. Patched. Ransomware family unnamed.

read →
~/articles/2026-07-04-avalon-crownx-modular-malware-framework
Avalon Framework Bundles Theft, Wiper, CrownX
ransomware

Avalon Framework Bundles Theft, Wiper, CrownX

Blackpoint Cyber says the previously undocumented Avalon framework combines credential theft, EDR-aware defense evasion, shadow-copy destruction, and the CrownX ransomware payload in one multi-stage phishing chain.

read →
~/articles/2026-07-03-fortibleed-inc-lynx-ransomware-attribution
FortiBleed Tied to INC and Lynx Ransomware Crews
ransomware

FortiBleed Tied to INC and Lynx Ransomware Crews

The Hacker News reports an operator behind FortiBleed's credential-theft infrastructure was seen running ransomware negotiation panels for both INC and Lynx. Not a resale ring — a pipeline.

read →
~/articles/2026-07-03-sysdig-jadepuffer-ai-agent-langflow-ransomware
Sysdig: JADEPUFFER ran a full ransomware chain from one LLM
ransomware

Sysdig: JADEPUFFER ran a full ransomware chain from one LLM

Sysdig's Threat Research Team says JADEPUFFER is the first ransomware incident it has observed where an AI agent handled entry, credential theft, lateral movement, and destruction end-to-end. Initial access was a Langflow code-execution flaw.

read →
~/articles/2026-07-03-avalon-crownx-modular-malware-framework
Blackpoint: Avalon Bundles Theft, Wiper, CrownX
ransomware

Blackpoint: Avalon Bundles Theft, Wiper, CrownX

Blackpoint Cyber documents Avalon, a previously undocumented modular framework whose ransomware payload — CrownX — arrives at the end of a legal-lure phishing chain that stages through Proton Drive, ISO, LNK, and MSBuild.

read →
~/articles/2026-07-03-anubis-ransomware-citrix-bleed-2-cve-2025-5777
Anubis Ransomware Exploits Citrix Bleed 2
ransomware

Anubis Ransomware Exploits Citrix Bleed 2

The Hacker News reports Anubis-ransomware affiliates using Citrix Bleed 2 (CVE-2025-5777) to breach NetScaler-fronted environments, then pivoting with legit RMM, BYOVD, and stolen supply-chain credentials.

read →
~/articles/2026-07-03-fbi-netnut-popa-botnet-takedown
FBI Seizes NetNut Proxy, Google Degrades Popa Botnet
threat intel

FBI Seizes NetNut Proxy, Google Degrades Popa Botnet

The FBI seized hundreds of NetNut proxy domains on July 2; Google's Threat Intelligence Group, working with FBI and Lumen, cut the linked Popa botnet's usable device pool by millions the same day.

read →