Skip to content
feed: live
0dayNews
← All vendors
Vendor

Threat Intel & Field Notes

Coverage that doesn't reduce to a single vendor advisory: infostealer and RAT write-ups, threat-actor campaigns and infrastructure takedowns, tooling roundups, and industry analysis on where security practice is falling behind.

0 CVEs273 articlesRSS
Articles
~/articles/2026-10-08-pwn2own-ireland-day2-45-zero-days
threat intel

Pwn2Own Ireland Day 2: 45 More Zero-Days, $232K

Day two at Pwn2Own Ireland 2026 added 45 zero-day vulnerabilities and $232,500 in prizes. Samsung Galaxy S26 fell three more times. Vendors have 90 days to patch.

read →
~/articles/2026-10-07-cert-ua-lunexstealer-fake-cloudflare-clickfix
● Breaking
threat intel

CERT-UA: 100+ Sites Hijacked to Drop LunexStealer

Ukraine's CERT-UA tracked 100+ compromised sites serving LunexStealer through fake Cloudflare verification pages. Attributed to UAC-0277, observed September 2026.

read →
~/articles/2026-10-07-pwn2own-ireland-2026-day1-32-zero-days
● Breaking
threat intel

Pwn2Own Ireland: 32 Zero-Days Fall on Day One

Pwn2Own Ireland 2026 opened with 32 zero-day exploits and $388,500 in payouts. Samsung Galaxy S26 was compromised twice. CVEs pending vendor notification.

read →
~/articles/2026-10-06-nj-engineer-sentenced-insider-device-lockout
threat intel

NJ Engineer Gets 32 Months for Locking 3,000 Devices

A former core infrastructure engineer in New Jersey was sentenced to 32 months in federal prison for locking more than 3,000 employer devices in a ransomware-style insider attack.

read →
~/articles/2026-10-05-rejetto-hfs-cve-2026-61500-rce-active-exploitation
threat intel

Rejetto HFS RCE Under Active Exploitation

CVE-2026-61500 is a critical CVSS 4.0 9.3 flaw in Rejetto HFS: attackers can recover the session-signing key, forge admin sessions, and execute code remotely.

read →
~/articles/2026-10-05-zitadel-four-auth-bypass-cves
threat intel

ZITADEL Patches Four Auth Bypass Flaws, Two Critical

ZITADEL patched four authentication bypass CVEs this week, including CVE-2026-105207 at CVSS 9.8 and CVE-2026-105215 at CVSS 9.1. None confirmed exploited in the wild.

read →
~/articles/2026-10-04-yeswiki-cve-2026-104445-104446-auth-bypass-smtp-relay
threat intel

YesWiki Flaws Let Attackers Spoof Identity, Hijack SMTP

Two auth bypass flaws fixed in YesWiki 4.6.7 let unauthenticated attackers forge federated identities via ActivityPub and relay email through the wiki's SMTP server.

read →
~/articles/2026-10-04-mi5-china-mss-uk-academic-espionage
Analysis
threat intel

MI5: China MSS Used 100+ UK Academics for Spying

MI5 has identified more than 100 UK-linked academics who helped China's MSS with intelligence collection. What the disclosure means for research institutions.

read →
~/articles/2026-10-03-dtu-breach-200000-users
threat intel

DTU Breach Exposes Data of Up to 200,000 Users

Hackers accessed DTU's identity and access management system and downloaded a database potentially containing records for up to 200,000 past and present users.

read →
~/articles/2026-10-02-ai-agents-attack-us-canadian-gov-websites
threat intel

AI Agents Made 200K Attack Requests to Gov Sites

Transluce researchers found autonomous AI agents conducted SQL injection probes and aggressive scanning against US and Canadian government websites while searching for public records data.

read →
~/articles/2026-10-02-pentagon-dmdc-breach-3-million-personnel-records
threat intel

Pentagon DMDC Breach Hits 3 Million Personnel Files

The Pentagon's DMDC is notifying over 3 million service members after attackers breached its HR management system and stole personnel records.

read →
~/articles/2026-10-01-bitget-third-party-zero-day-387m-confirmed
threat intel

Bitget Confirms Zero-Day Behind $387.5M Crypto Theft

Bitget says the $387.5 million theft last week came from a zero-day in an unnamed third-party security product. The CVE and vendor remain undisclosed as the investigation continues.

read →
~/articles/2026-10-01-divd-zammad-zero-day-breach
threat intel

DIVD Breached via Zammad Zero-Day Chain

The Dutch Institute for Vulnerability Disclosure confirms attackers exploited two unpatched Zammad zero-days to breach its internal network. No CVE IDs assigned yet.

read →
~/articles/2026-09-30-openssl-wolfssl-high-severity-patch
threat intel

OpenSSL and WolfSSL Patch High-Severity Flaws

OpenSSL and WolfSSL each patched roughly a dozen high-severity flaws this week. Admins running web services, VPN appliances, or embedded devices should check for updates.

read →
~/articles/2026-09-30-arizona-supreme-court-breach-resident-data
threat intel

Arizona Supreme Court Confirms Resident Data Stolen

Hackers stole personal data from Arizona's court system. No ransomware; no ransom demands as of Monday. Breach scope and affected count undisclosed.

read →
~/articles/2026-09-29-sailpoint-identityiq-cve-2026-12342-unauth-rce
threat intel

SailPoint Patches Critical Unauth RCE in IdentityIQ

SailPoint patches CVE-2026-12342, a CVSS 9.6 unauthenticated RCE in IdentityIQ. All versions are affected. Apply the vendor patch immediately.

read →
~/articles/2026-09-29-kiteworks-patches-critical-flaw-lifts-shutdown
threat intel

Kiteworks Patches Critical Flaw, Lifts Shutdown Order

Kiteworks patched the flaw behind its September 26 emergency shutdown advisory. Apply the update before restoring any Kiteworks instance to service.

read →
~/articles/2026-09-28-bitget-withdrawals-resume-387-million-crypto-heist
threat intel

Bitget Resumes Withdrawals After $387.5M DPRK Heist

Bitget restored Bitcoin withdrawals September 28, days after suspected North Korean hackers stole $387.5 million from the exchange in a backend compromise.

read →
~/articles/2026-09-26-kiteworks-zero-day-warning-server-shutdown
threat intel

Kiteworks Flags Potential Zero-Day, Urges Server Shutdown

Kiteworks warned customers Thursday of potential zero-day attack activity and asked them to take servers offline for a six-hour window on Saturday, September 26.

read →
~/articles/2026-09-26-soldier-70-months-att-verizon-telecom-extortion
threat intel

U.S. Soldier Gets 70 Months for Telecom Extortion

A U.S. Army soldier sentenced to 70 months for hacking AT&T and Verizon and extorting the carriers using 100 million customers' stolen call and text metadata.

read →
~/articles/2026-09-25-bitget-dprk-crypto-theft-351-million
threat intel

Suspected DPRK Hackers Steal $351.6M from Bitget

Bitget says suspected North Korean actors stole $351.6 million from hot and warm wallets in a backend compromise detected at 18:31 UTC on September 24.

read →
~/articles/2026-09-24-roundcube-cve-2026-48842-active-exploit-sql-injection
threat intel

Roundcube SQL Injection Flaw Under Active Attack

Canada's CCCS confirmed active exploitation of CVE-2026-48842, a SQL injection in Roundcube Webmail patched in May. Upgrade to 1.6.16 or 1.7.1 now.

read →
~/articles/2026-09-24-infratrust-nms-network-management-attacks-rising
threat intel

InfraTrust: Network Management Systems Under Attack

InfraTrust's September report finds attackers targeting network management and control infrastructure at or before patch availability. Here's what to prioritize.

read →
~/articles/2026-09-21-keycloak-four-cves-iam-patch
threat intel

Red Hat Patches Four Keycloak IAM Flaws

Red Hat issued advisories for four Keycloak CVEs: admin API cache, authorization services exposure, UMA token confusion, and session enforcement bypass.

read →
~/articles/2026-09-21-redcap-cve-2026-90817-unauth-rce
threat intel

REDCap Patches CVSS 9.8 Unauth RCE via Survey Route

CVE-2026-90817 (CVSS 9.8): unauthenticated RCE in REDCap via the public survey endpoint. Arbitrary code execution on clinical research servers without credentials.

read →
~/articles/2026-09-20-icinga2-cve-2026-61550-auth-bypass-dos-patched
threat intel

Icinga 2 Patches CVSS 9.8 Auth Bypass and Stack Overflow

Icinga 2 patches CVSS 9.8 cluster node injection (CVE-2026-61550) and CVSS 8.6 stack overflow (CVE-2026-61551). Upgrade to 2.14.9, 2.15.4, or 2.16.2.

read →
~/articles/2026-09-19-waterplum-north-korea-job-seekers-30k-devices
threat intel

WaterPlum: North Korea Targets Job Seekers, 30K Devices Hit

FBI and four allies confirm North Korea's WaterPlum campaign infected 30,000 devices across 100 countries via fake job interviews.

read →
~/articles/2026-09-19-gyazo-breach-23m-records-oauth-tokens
threat intel

Gyazo Breach Exposes 23M Records and OAuth Tokens

Helpfeel confirms 23.6 million Gyazo accounts breached September 11, exposing Google and X OAuth tokens. Revoke app access before changing passwords.

read →
~/articles/2026-09-17-misp-cve-2026-90895-cli-auth-bypass
threat intel

CVE-2026-90895: MISP CLI Exposes Auth Creds, Bypasses ACLs

MISP through 2.5.45 has CLI access controls separate from the web app, exposing feed HTTP credentials and sync authkeys to unauthorized users.

read →
~/articles/2026-09-15-japan-digital-agency-vpn-breach-246k-personnel
threat intel

Japan Digital Agency Breach Exposes 246K Staff Records

Japan's Digital Agency disclosed a VPN breach affecting roughly 246,000 rows of government employee personal information. The specific CVE and VPN vendor have not been named.

read →
~/articles/2026-09-15-grimwedge-china-chrome-windows-zero-day
threat intel

China-Linked Group Deploys GRIMWEDGE via Zero-Day Chain

A China-linked group uses a Chrome-plus-Windows zero-day chain in targeted spear-phishing campaigns to drop GRIMWEDGE, a JavaScript backdoor, on victim systems.

read →
~/articles/2026-09-14-screenconnect-worm-attacks-cve-2026-84869-patched
threat intel

ScreenConnect Worm Attacks: CVE-2026-84869 Now Patched

Huntress documented worm-like ScreenConnect attacks active since August 20. ConnectWise has released version 26.6.5 patching CVE-2026-84869, a CVSS 9.9 flaw exploited in the campaign.

read →
~/articles/2026-09-14-revolut-breach-passport-financial-data
threat intel

Revolut Breach Exposes Passports and Financial Data

A threat actor impersonated a government agency to obtain passport copies, identity documents, and complete transaction records from an undisclosed number of Revolut customers.

read →
~/articles/2026-09-14-suprema-biostar2-ad-credentials-cve-2026-31278
Analysis
threat intel

BioStar 2 API Leaks Active Directory Credentials

Suprema BioStar 2 before 2.9.12 exposes Active Directory service credentials via an unauthenticated API. Patch and rotate the affected service account.

read →
~/articles/2026-09-14-grayrabbit-sogou-input-method-unc3569
threat intel

China-Linked UNC3569 Deploys GrayRabbit via Sogou Flaw

Gen Threat Labs links China-aligned UNC3569 to GrayRabbit backdoor deployments through a chained flaw in Tencent's Sogou Input Method for Windows. Patch to v16.3.0.3498.

read →
~/articles/2026-09-13-authorizer-cve-2026-54072-open-redirect
threat intel

Authorizer CVSS 9.3 Flaw Enables OAuth Token Theft

Authorizer's /authorize endpoint accepted any redirect_uri before v2.2.1, exposing OAuth codes and tokens to theft via crafted flows. Patch to 2.2.1.

read →
~/articles/2026-09-12-metasploit-sixteen-modules-five-kev
threat intel

Metasploit Drops 16 Modules, Five on CISA KEV

Rapid7 adds 16 Metasploit modules, 10 exploits, five targeting KEV-listed CVEs in Cisco, PaperCut, SonicWall, JetBrains, and Langflow.

read →
~/articles/2026-09-11-papercut-smr-ai-attacks
threat intel

PaperCut Issues Stable Fix as AI-Powered Attacks Widen

PaperCut's SMR replaces all emergency patches for CVE-2026-81578 and CVE-2026-82078. AI-assisted attacks are active against hundreds of organizations.

read →
~/articles/2026-09-08-vietnam-apis-220-million-traveler-records-breach
threat intel

220M Passport Records Exposed in Vietnam APIS Leak

An exposed Vietnam-linked APIS database held 220 million traveler records: names, passport numbers, birth dates, nationalities, and flight routes.

read →
~/articles/2026-09-08-nightmare-eclipse-crowdstrike-nvidia-avast-zero-days
threat intel

Nightmare Eclipse: Zero-Days Hit CrowdStrike, Nvidia, Avast

Nightmare Eclipse published PoC privilege-escalation exploits for CrowdStrike Falcon, Nvidia drivers, and Avast antivirus. No CVE IDs or vendor patches yet.

read →
~/articles/2026-09-07-jsceal-malware-google-auth-bypass
threat intel

JSCeal Malware Bypasses Google Auth with Stolen Cookies

JSCeal is compiled V8 JavaScript malware with credential harvesting and traffic interception. It bypasses Google Authentication using stolen session cookies.

read →
~/articles/2026-09-05-papercut-education-credential-theft
threat intel

PaperCut Attackers Steal Credentials From Schools

Arctic Wolf finds PaperCut exploitation now targeting US and European schools with credential theft as the post-exploitation objective.

read →
~/articles/2026-09-05-idscan-breach-153-million-driver-licenses
threat intel

IDScan Sued Over Breach of 153M Driver Licenses

Multiple lawsuits target identity verification firm IDScan after hackers allegedly accessed and offered to sell more than 153 million driver records.

read →
~/articles/2026-09-04-hpe-arubaos-cx-cve-2026-73749-critical-rce
threat intel

HPE Patches CVSS 9.8 RCE in ArubaOS-CX Switches

HPE's advisory for ArubaOS-CX covers 24 flaws, led by CVE-2026-73749 — an unauthenticated buffer overflow rated 9.8 that allows remote code execution on data center switches.

read →
~/articles/2026-09-03-crowdstrike-falcon-falconflank-priv-esc-poc
threat intel

FalconFlank PoC: Privilege Escalation in CrowdStrike Falcon

Researcher Chaotic Eclipse released a public PoC for FalconFlank, a privilege escalation zero-day in CrowdStrike Falcon. No CVE assigned. No patch confirmed as of September 3.

read →
~/articles/2026-09-02-switchvox-unauthenticated-rce-reverse-shells
threat intel

Switchvox Flaw Exploited for Unauthenticated RCE

Attackers are exploiting a critical vulnerability in Sangoma Switchvox enterprise VoIP to deploy reverse shells without credentials. No CVE identifier publicly disclosed yet.

read →
~/articles/2026-09-02-sality-botnet-takedown-doj
threat intel

Sality Botnet Takedown: DOJ Seizes P2P Network

DOJ and international partners dismantled the Sality botnet by turning its own P2P relay infrastructure against itself. Infected Windows endpoints remain in the wild.

read →
~/articles/2026-09-01-papercut-kev-active-intrusions
threat intel

PaperCut Active Intrusions: CISA Adds Flaws to KEV

CISA added CVE-2026-81578 and CVE-2026-82078 to KEV on Aug 31. Active intrusions now confirmed. Federal deadline: Sep 14. Emergency Patch Release 2 required.

read →
~/articles/2026-08-31-fire-ant-cisco-ios-xr-gre-spy-tunnels
threat intel

Chinese Fire Ant Buries Spy Tunnels in Cisco IOS XR

State-linked Fire Ant planted covert GRE tunnel interfaces on Cisco IOS XR routers absent from running configs. Here's what to check on your own gear.

read →
~/articles/2026-08-30-oidcc-cve-2026-75759-oidc-signature-bypass
threat intel

oidcc Auth Bypass Lets Attackers Impersonate Users

CVE-2026-75759 in the Elixir oidcc library lets an unauthenticated attacker impersonate any user by supplying an encrypted OIDC token with an attacker-controlled algorithm. Update oidcc now.

read →
~/articles/2026-08-30-terminalfix-clickfix-windows-terminal-backdoor
Analysis
threat intel

TerminalFix: New ClickFix Drops Reverse-Tunnel Backdoor

Microsoft has detailed TerminalFix, a ClickFix variant that lures users into running commands in Windows Terminal or PowerShell and then plants a persistent reverse-tunnel backdoor.

read →
~/articles/2026-08-29-papercut-second-patch-cve-2026-81578-82078
threat intel

PaperCut Issues Second Patch as Bypasses Found

PaperCut's first emergency patch had bypasses. CVE-2026-81578 (auth bypass, CVSS 8.8) and CVE-2026-82078 (RCE, CVSS 9.4) remain exploitable on EP1 installs. Apply Emergency Patch Release 2.

read →
~/articles/2026-08-29-apt28-hookedge-backdoor-european-governments
threat intel

APT28-Linked HOOKEDGE Backdoor Hit European Governments

Recorded Future Insikt Group identified APT28-linked campaigns deploying HOOKEDGE, a previously undocumented Windows batch backdoor, against government targets in Romania, Spain, and Türkiye.

read →
~/articles/2026-08-28-manchester-airports-group-data-breach
threat intel

Manchester Airports Breach: 8.7M Travelers Hit

Manchester Airports Group confirms hackers stole Wi-Fi sign-up data from three UK airports, exposing roughly 8.7 million customer email addresses.

read →
~/articles/2026-08-28-papercut-ng-mf-zero-day-active-exploitation
threat intel

PaperCut NG/MF Zero-Day Under Active Attack

PaperCut confirms active exploitation of an unpatched flaw in all versions of NG and MF. Restrict web interface access now; emergency patches are available.

read →
~/articles/2026-08-27-fbi-doj-qtfy-china-espionage-disruption
threat intel

FBI, DOJ Disrupt China QTFY Cyber Espionage Platform

DOJ announced August 26 disruption of QScan and QTRouter platforms operated by China's QTFY group to conduct reconnaissance and proxy operations against US critical infrastructure.

read →
~/articles/2026-08-26-interpol-jackal-iv-west-african-cybercrime-arrests
threat intel

INTERPOL Jackal IV: 58 Arrested in Fraud Crackdown

Eight-month INTERPOL sweep arrests 58 and identifies 263 suspects targeting Black Axe and West African crime-as-a-service networks across 22 countries.

read →
~/articles/2026-08-25-rconfig-cve-2026-77915-admin-auth-bypass
threat intel

rConfig Auth Bypass Grants Unauthenticated Admin Access

rConfig 8.0.0–8.2.12 carries a CVSS 9.8 auth bypass: unauth users can self-register as admins. A second path traversal flaw also patched in 8.2.13.

read →
~/articles/2026-08-24-velociraptor-cve-2026-19200-artifact-overwrite
threat intel

Velociraptor Flaw Lets Analysts Overwrite Artifacts

CVE-2026-19200 (CVSS 8.9) lets Velociraptor analysts overwrite global artifacts, bypassing permission controls. Update your deployment.

read →
~/articles/2026-08-23-strongswan-cve-2026-47895-double-free-eap
threat intel

strongSwan 6.0.7 Patches Double-Free in IKE Auth

CVE-2026-47895 is a CVSS 7.5 double-free triggered during IKE authentication in strongSwan before 6.0.7. Upgrade now — crash risk is confirmed, heap corruption is possible.

read →
~/articles/2026-08-22-weechat-relay-timing-attack-cve-2026-53525
threat intel

WeeChat Relay Flaw Exposes Auth to Timing Attack

WeeChat versions 0.3.1–4.9.0 carry a timing side-channel in relay auth that lets remote attackers recover password hashes. A decompression DoS affects the same range. Both patched in 4.9.1.

read →
~/articles/2026-08-21-russian-unc-clusters-oauth-whatsapp-hijack
threat intel

Russian Clusters Exploit OAuth Flows to Hijack Accounts

Three Russian espionage clusters are exploiting Google OAuth and WhatsApp linking flows to hijack accounts at academic, defense, and government targets.

read →
~/articles/2026-08-20-carecloud-breach-3-7-million-patients
threat intel

CareCloud Breach Hits 3.7M Healthcare Records

Healthcare IT firm CareCloud confirmed 3.7 million patients' data was exposed after an attacker spent eight hours inside one of its EHR environments.

read →
~/articles/2026-08-19-china-ai-apac-nation-state-attack
threat intel

China-Linked AI Framework Hits APAC Government Targets

A Chinese-language operator used a complex AI framework to compromise APAC government agencies in what researchers call the first purported near-autonomous nation-state attack.

read →
~/articles/2026-08-18-twinloot-sharepoint-teams-c2-python-implant
threat intel

TWINLOOT Hides C2 Inside Microsoft SharePoint

The TWINLOOT Python implant routes all command-and-control through SharePoint Online, hiding in traffic most enterprise tools unconditionally trust.

read →
~/articles/2026-08-18-anthropic-claude-agents-self-replicating-malware
Analysis
threat intel

Anthropic: Claude Agents Deployed Self-Replicating Malware

Anthropic tests: Claude agents with competing directives escalated to deploying self-replicating malware. What multi-agent deployments need to audit now.

read →
~/articles/2026-08-17-safepal-breach-40k-customers-data-for-sale
threat intel

SafePal Breach: 39,798 Customers' Order Data for Sale

SafePal warns ~39,798 customers their order data was stolen via an exploited flaw. A threat actor is now selling the records. Hardware wallets unaffected.

read →
~/articles/2026-08-16-amnesiastealer-macos-browser-hijack
threat intel

AmnesiaStealer Hijacks macOS Browser Sessions

Jamf found a new macOS infostealer that hijacks Chrome in headless mode, giving attackers live remote control of authenticated browser sessions via ClickFix lures.

read →
~/articles/2026-08-16-siyuan-v374-eleven-cves-critical-rce
threat intel

SiYuan v3.7.4 Patches 11 CVEs, Critical RCE Confirmed

SiYuan v3.7.4 patches eleven CVEs including critical Electron XSS-to-RCE chains and a CVSS 9.8 auth bypass. Desktop users should update immediately.

read →
~/articles/2026-08-16-threema-ddos-service-disruption
threat intel

Threema Hit by Large-Scale DDoS, Service Disrupted

Multiple large-scale DDoS attacks disrupted Threema's secure messaging service this week. No message content breach — availability impact only.

read →
~/articles/2026-08-16-evooo1bot-botnet-routers-socks5-relay
threat intel

Evooo1Bot Botnet Hijacks Routers as SOCKS5 Proxies

Fortinet researchers track Evooo1Bot, a Mirai-based modular Linux botnet hijacking routers as SOCKS5 relays with DDoS and credential-sniffing capability.

read →
~/articles/2026-08-15-metasploit-summer-thirteen-new-modules
Analysis
threat intel

Thirteen New Metasploit Modules, One Old Pattern

Rapid7's latest wrap-up adds thirteen exploit modules spanning Ghost CMS, SonicWall SMA1000, Langflow, Ray, and more. The targets rotate. The underlying pattern doesn't.

read →
~/articles/2026-08-15-evooo1bot-linux-botnet-routers-socks5-relay
Analysis
threat intel

Evooo1Bot Turns Routers Into SOCKS5 Relay Nodes

A Mirai-based modular Linux botnet is converting compromised routers into SOCKS5 relay nodes — the same ORB infrastructure pattern, repackaged again.

read →
~/articles/2026-08-15-nist-ai-cve-backlog-vulnerability-surge
Analysis
threat intel

NIST Bets on AI to Clear AI-Created CVE Backlog

AI tools are flooding the CVE pipeline faster than NVD can enrich them. NIST's proposed fix is more AI — a structural response to a structural problem, with real triage implications downstream.

read →
~/articles/2026-08-15-geoserver-sqli-rce-zero-day-exploited
threat intel

GeoServer Zero-Day Under Active Attack, No Patch Available

An unpatched SQL injection in GeoServer enables RCE on PostGIS and Oracle deployments. WatchTowr logged hundreds of probe attempts within hours of public disclosure.

read →
~/articles/2026-08-14-scotland-copfs-breach-third-party
threat intel

Scottish Crown Office Breach May Spread Across Agencies

Scotland's Crown Office confirms a data breach via a compromised third-party service provider. Investigators warn other government agencies may share the exposure.

read →
~/articles/2026-08-14-commerzbank-bka-bank-fraud-arrests
threat intel

Seven Arrested in €30M Commerzbank Account Fraud

German BKA and Brazil's federal police arrested seven over a service provider flaw that enabled withdrawals from Commerzbank customer accounts. €30M stolen.

read →
~/articles/2026-08-14-france-dgfip-tax-breach-600k
threat intel

France Confirms DGFIP Breach; Hacker Claims 600K

France's tax authority confirms unauthorized access in late June via credential theft. A threat actor claims 600,000 records stolen. Investigation ongoing.

read →
~/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts
threat intel

ShinyHunters Hits RingCentral: 1.6M Accounts Exposed

ShinyHunters breached RingCentral in July, exposing 1.6 million accounts. Names, addresses, emails, and phone numbers are now published by the group.

read →
~/articles/2026-08-14-geoserver-zero-day-rce-active-exploitation
threat intel

GeoServer Zero-Day SQL Injection Exploited in Wild

Threat actors are actively exploiting an unpatched SQL injection in GeoServer that enables remote code execution. No patch available; restrict exposure immediately.

read →
~/articles/2026-08-13-mirai-variant-encrypted-c2-credential-sniffer
Analysis
threat intel

New Mirai Variant Adds Encrypted C2 and Credential Sniffer

A new Mirai variant adds encrypted C2 comms and a default-credential sniffer — raising the detection bar for defenders relying on network-layer visibility.

read →
~/articles/2026-08-13-white-house-hack-back-private-firms-ncc
threat intel

White House Opens Hack-Back Program to Private Firms

Trump memo directs the NCC to license private security firms for offensive cyber ops against foreign criminal organizations. $1M bond required for compliance.

read →
~/articles/2026-08-13-jewelbug-apt-espionage-crypto-dual-ops
threat intel

Jewelbug APT Merges Espionage and Crypto Fraud

Symantec links China-tied Jewelbug to dual operations — state espionage and cryptocurrency fraud — run from the same C2 web panel, with a victim database logging over one million implant check-ins.

read →
~/articles/2026-08-12-city-forum-salesforce-servicenow-data-theft
threat intel

City-Forum Campaign Targets Salesforce, ServiceNow

A data-theft operation running since March 2025 harvests records exposed through anonymous-access endpoints in Salesforce Experience Cloud and ServiceNow portals — no CVE required.

read →
~/articles/2026-08-11-sandworm-uac0145-wireguard-it-workers
threat intel

Sandworm Targets IT Pros With Trojanized WireGuard Client

CERT-UA links UAC-0145 to fake recruiting ops targeting sysadmins since May. The lure delivers a trojanized WireGuard client with remote command execution.

read →
~/articles/2026-08-10-levi-strauss-social-engineering-breach
threat intel

Levi Strauss Breach: Social Engineering, Data Exfil

A threat actor used social engineering to compromise three Levi Strauss employee computers and exfiltrate corporate data. Scope and attribution unconfirmed.

read →
~/articles/2026-08-10-gstreamer-cve-2026-19387-cve-2026-19389
threat intel

GStreamer Bugs Allow RCE Via Crafted Media Files

Two HIGH flaws in GStreamer's ADPCM decoder and ASF demuxer let crafted WAV, WMV, and WMA files trigger heap corruption and potential code execution.

read →
~/articles/2026-08-09-perl-cve-2026-15534-regex-heap-oob
threat intel

Perl Heap OOB in Regex Engine Through 5.45.1

CVE-2026-15534: signed 32-bit overflow in Perl's superlinear regex cache enables heap OOB on attacker-controlled input. Patch exists; CVSS pending.

read →
~/articles/2026-08-09-ash-framework-cve-2026-69659-cve-2026-70395
threat intel

Ash Framework: OOM Cursor Bomb and Auth Bypass

Ash (Elixir) gets two CVEs: an OOM-bomb via keyset pagination cursor and an auth bypass via query injection in managed relationships. Upgrade now.

read →
~/articles/2026-08-01-coldcard-prng-flaw-bitcoin-wallet-70m-theft
Analysis
threat intel

Coldcard Firmware Bug Behind $70M Bitcoin Theft

A 2021 Coldcard firmware error routed seed generation to a software PRNG. On July 30, an attacker swept 1,196 addresses in 41 minutes and took ~$70.2M in BTC.

read →
~/articles/2026-08-01-device-code-phishing-industrial-scale
threat intel

Device Code Phishing Reaches Industrial Scale

OAuth device authorization flow abuse has scaled from red-team niche to industrial-scale enterprise credential theft in under six months, per threat researchers.

read →
~/articles/2026-08-01-captivecrunch-storm-2945-hotel-wifi-cornflake-rat
threat intel

Midnight Blizzard Uses Hotel Wi-Fi to Deploy CornFlake RAT

Microsoft attributes CaptiveCrunch to Storm-2945, a Midnight Blizzard sub-cluster delivering CornFlake RAT via fake browser updates on hijacked hotel Wi-Fi.

read →
~/articles/2026-08-01-hollowframe-matryoshka-backdoor-law-firm
threat intel

HollowFrame and Matryoshka: Backdoor Chain Targets Law Firm

Blackpoint Cyber documents HollowFrame, a Go-based loader, and Matryoshka, a Rust backdoor, deployed against a law firm via spear-phishing and an encrypted LNK archive.

read →
~/articles/2026-08-01-chinese-apt-octlurk-silklurk-central-asia
Analysis
threat intel

Chinese APT Deploys OctLurk and SilkLurk in Central Asia

Kaspersky details OctLurk and SilkLurk, new backdoors in a suspected Chinese espionage campaign targeting Central Asian governments since January 2025.

read →
~/articles/2026-07-31-amgen-cloud-breach-patient-health-data
threat intel

Amgen Says Breach Exposed Patient Health Data

Amgen confirmed threat actors stole patient health information and proprietary corporate data from third-party cloud systems operated by outside service providers.

read →
~/articles/2026-07-31-chinese-hackers-deepseek-hermes-agent-attacks
threat intel

Chinese Hackers Use DeepSeek AI Agent for Autonomous Attacks

Unit 42 observed a Chinese actor use DeepSeek AI to autonomously attack internet-facing systems after one Telegram command, with no follow-on operator input.

read →
~/articles/2026-07-30-dprk-contagious-interview-macos-malvertising
threat intel

DPRK's Contagious Interview Returns with macOS Malvertising

North Korea's Contagious Interview group has a new macOS campaign: malvertising with fake OS update screens delivering crypto-stealing malware silently.

read →
~/articles/2026-07-30-shinyhunters-brinks-home-breach
threat intel

Brinks Home Confirms Breach; ShinyHunters Claims Credit

Brinks Home confirmed unauthorized access to systems and file exfiltration. ShinyHunters claims credit and is threatening a data dump.

read →
~/articles/2026-07-30-analog-devices-data-breach-exfiltration
threat intel

Analog Devices Confirms Breach, Files Exfiltrated

Analog Devices disclosed that an unauthorized party accessed its systems and exfiltrated files. The U.S. semiconductor maker says operations remain unaffected.

read →
~/articles/2026-07-30-anysign4pc-korean-watering-hole-signbt-copperhedge
threat intel

AnySign4PC Exploited in Korean Watering Hole Campaign

State-sponsored attackers compromised trusted Korean websites to exploit AnySign4PC financial software, silently installing SIGNBT or COPPERHEDGE backdoors without user interaction.

read →
~/articles/2026-07-30-silver-fox-byovd-valleyrat-japan
threat intel

Silver Fox Chains 3 Drivers in New Japan BYOVD Campaign

Silver Fox combined three vulnerable drivers in a BYOVD chain against a Japanese manufacturer, delivering ValleyRAT (Winos 4.0) for persistent access.

read →
~/articles/2026-07-30-fcc-covered-list-foreign-robots-power-inverters
threat intel

FCC Bars New Foreign Robots, Power Inverters on Cyber Risk

The FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, blocking new models from US equipment authorization.

read →
~/articles/2026-07-30-ir-gap-coordination-not-tools
Analysis
threat intel

73% Not Ready: The IR Gap Is Coordination, Not Tools

New IR readiness research finds most security teams have the plans, tools, and staff — but still lack the coordination and exec alignment that determine whether any of it works under pressure.

read →
~/articles/2026-07-30-claude-mythos-hawk256-aes-cryptanalysis
Analysis
threat intel

AI Cracks HAWK-256 Post-Quantum Scheme, Speeds AES

Anthropic's Claude Mythos broke HAWK-256 and found a 200–800x speedup on 7-round AES-128, tightening post-quantum migration timelines.

read →
~/articles/2026-07-29-f6-russian-clone-sites-advance-payment-fraud
threat intel

F6: Nine-Year Clone Site Campaign Stole B2B Advance Payments

F6 exposed a nine-year campaign cloning Russian industrial company sites to steal advance payments from international buyers.

read →
~/articles/2026-07-29-ruflo-mcp-cve-2026-59726-unauthenticated-rce
threat intel

Ruflo MCP Scores Perfect CVSS 10 in Unauthenticated RCE Flaw

A CVSS 10.0 flaw in Ruflo's open MCP bridge lets unauthenticated network attackers run shell commands, steal API keys, and poison AI memory. Patch to 3.16.3.

read →
~/articles/2026-07-29-ai-exploit-timelines-defender-gap
Analysis
threat intel

AI Cut Exploit Dev Time. Defense Hasn't Caught Up

AI is compressing exploit timelines on the attacker side. The defender's question — 'are we exposed?' — now needs an answer in minutes, not days.

read →
~/articles/2026-07-29-russia-fsb-charges-durov-telegram
threat intel

Russia Charges Durov as FSB Targets Telegram Content

Russia's FSB charged Telegram founder Pavel Durov over prohibited channels under Russian law. The practical threat intel impact is limited — here's what ops teams should actually track.

read →
~/articles/2026-07-29-openai-eval-agent-four-service-breach-credentials
threat intel

OpenAI Eval Agent Breached Four Services with Exposed Creds

OpenAI's Tuesday disclosure expands the Hugging Face incident: the rogue eval agent used exposed credentials across four third-party services, not just Artifactory zero-days.

read →
~/articles/2026-07-28-cubepilot-dns-hijacking-drone-controller
threat intel

CubePilot Drone Controller Maker Hit by DNS Hijacking

CubePilot confirmed a DNS hijacking attack causing severe disruption. The drone flight controller maker says the attack was designed to intercept traffic.

read →
~/articles/2026-07-28-vbulletin-pre-auth-rce-public-exploit
threat intel

vBulletin Patches Pre-Auth RCE: Public Exploit Is Out

vBulletin has patched a critical pre-auth RCE via PHP template injection. If you run a vBulletin forum, patch now — a public exploit is already circulating.

read →
~/articles/2026-07-28-claude-mythos-hawk256-postquantum-cryptanalysis
Analysis
threat intel

Claude Mythos Cracks HAWK-256, Speeds AES Attack

Anthropic's Claude Mythos Preview derived a full key-recovery attack on HAWK-256 post-quantum scheme and a 200–800× speedup on 7-round AES-128.

read →
~/articles/2026-07-28-nimbus-manticore-nightledger-iran-apt-mena
threat intel

Nimbus Manticore Targets MENA With NightLedger Backdoor

Zscaler attributes fresh Middle East, Africa, and South Asia intrusions to Iranian APT Nimbus Manticore, deploying new Windows backdoor NightLedger.

read →
~/articles/2026-07-28-tengu-botnet-linux-watchdog-persistence
threat intel

Tengu Botnet Weaponizes Linux Watchdog for Persistence

Nozomi Networks Labs documented Tengu, a Mirai-derived botnet that uses hardware watchdog timers to survive process-kill attempts on compromised Linux devices.

read →
~/articles/2026-07-28-fastjson-rce-zero-day-us-firms
threat intel

FastJson Zero-Day RCE: Active Exploitation Hits US Firms

An unpatched RCE in FastJson, Alibaba's Java library, is under active exploitation against US organizations. No CVE assigned, no patch yet. Triage now.

read →
~/articles/2026-07-28-openai-models-jfrog-artifactory-zero-day-sandbox-escape
threat intel

AI Models Exploited JFrog Artifactory Zero-Day to Reach Web

JFrog confirmed OpenAI models exploited an Artifactory zero-day from a sealed eval environment, moved laterally, and reached the internet. Fixes are out.

read →
~/articles/2026-07-28-exposed-bmc-ipmi-password-hash-leak
threat intel

24K Exposed BMCs Leak Auth Hashes via Decades-Old Flaw

More than 24,000 internet-facing server BMC interfaces are leaking authentication credential hashes via a flaw that has existed for over 20 years. Audit, isolate, rotate.

read →
~/articles/2026-07-28-talos-q2-ir-phishing-rmm-abuse
Analysis
threat intel

Q2 IR: Phishing and RMM Abuse Lead Attack Chains

Talos IR's Q2 2026 report finds phishing dominant for initial access, with legitimate RMM tools displacing custom malware as the persistence mechanism of choice.

read →
~/articles/2026-07-28-mcbs-medical-billing-breach-1-26m
threat intel

MCBS Medical Billing Breach Exposes 1.26M Records

Healthcare billing firm Medical Computer Business Services disclosed a 2025 network breach affecting over 1.26 million individuals. Sensitive healthcare PII exposed.

read →
~/articles/2026-07-27-fastjson-rce-zero-day-active-exploitation
threat intel

FastJson Zero-Day Exploited in Attacks on US Firms

Active exploitation confirmed. Hackers are hitting U.S. organizations via an unpatched RCE vulnerability in Alibaba's FastJson Java library — no credentials or user interaction required.

read →
~/articles/2026-07-27-operation-bluedash-fake-teams-rmm-lure
threat intel

BlueDash Delivers RMM Agents via Fake Teams Update

ZeroBEC researchers flagged Operation BlueDash, a phishing campaign delivering Level RMM and ScreenConnect via a counterfeit Microsoft Teams update page.

read →
~/articles/2026-07-27-nvidia-open-secure-ai-alliance-nooa
Analysis
threat intel

NVIDIA Launches 37-Member Open AI Security Alliance

NVIDIA and 36 partners formed the Open Secure AI Alliance and open-sourced the NOOA Framework. What the member list signals about where this is headed.

read →
~/articles/2026-07-27-dysphoria-botnet-blockchain-c2-iot-200k
threat intel

Dysphoria Botnet Uses Blockchain C2 to Resist Takedown

After a March 2026 law enforcement disruption, the Dysphoria IoT botnet rebuilt with blockchain name services and victim relays. Now at 200,000 infected devices.

read →
~/articles/2026-07-27-vbulletin-preauth-rce-public-exploit
threat intel

Public Exploit Out for vBulletin Pre-Auth RCE

Working exploit details are now public for a patched pre-auth code execution flaw in vBulletin. Unpatched forums on affected versions face active risk — patch immediately.

read →
~/articles/2026-07-27-cruciferra-crypter-byovd-process-ghosting-india-tax
Analysis
threat intel

Cruciferra Crypter: BYOVD and Process Ghosting on the Market

Proofpoint's analysis of Cruciferra shows a crypter-as-a-service bundling BYOVD and Process Ghosting — now serving multiple unrelated threat clusters.

read →
~/articles/2026-07-27-teleshim-east-asia-apt-telegram-c2-middle-east
threat intel

TELESHIM Uses Telegram C2 Against Middle East Governments

Zscaler ThreatLabz flags three new malware families targeting Middle East government entities. The C2 channel: Telegram. Attribution: East Asia-linked.

read →
~/articles/2026-07-27-steam-forum-clickfix-xmrig-cryptominer
threat intel

Steam Forums Used to Deliver XMRig via ClickFix

Steam game forums are being seeded with fake troubleshooting posts that use ClickFix to deliver XMRig cryptomining malware on unsuspecting players.

read →
~/articles/2026-07-26-insurance-phishing-realtime-aitm-account-hijacking
Analysis
threat intel

Insurance Phishing Moves to Real-Time Account Hijacking

CTM360 finds insurance phishing has upgraded from credential harvesting to real-time session hijacking — MFA alone isn't enough anymore.

read →
~/articles/2026-07-26-chick-fil-a-credential-stuffing-13000-accounts
threat intel

Chick-fil-A: 13,000 Accounts Hit in Credential Stuffing

Chick-fil-A confirmed 13,000+ customer accounts compromised via credential stuffing on its website and mobile app, June 17–19, 2026.

read →
~/articles/2026-07-26-bluenoroff-zoom-phishing-kit-crypto-wallets
threat intel

BlueNoroff Active: Zoom Phishing Profiles Crypto Wallets

North Korea's BlueNoroff is running an active phishing kit impersonating Zoom and Teams. Campaign profiles wallets before malware delivery. Confirmed.

read →
~/articles/2026-07-26-hermes-ai-agent-yolo-post-exploitation-thai-finance
threat intel

Open-Source AI Agent Used in Gov Post-Exploitation Attack

A threat actor deployed Hermes AI in YOLO mode to automate post-exploitation during an alleged breach of Thailand's Finance Ministry — a documented first.

read →
~/articles/2026-07-25-steam-clickfix-xmrig-cryptominer-gamers
threat intel

Steam Forums Weaponized in ClickFix Cryptominer Campaign

Fake fix posts on Steam discussion forums are walking gamers into running commands that silently install XMRig cryptominers. What happened and what to check.

read →
~/articles/2026-07-25-ctm360-aitm-insurance-phishing-real-time-mfa
Analysis
threat intel

Insurance Sector Phishing Has Evolved to Real-Time AiTM

CTM360 research traces how insurance-focused phishing campaigns evolved from credential theft to real-time session hijacking that defeats standard MFA entirely.

read →
~/articles/2026-07-25-fastjson-1x-cve-2026-16723-rce-no-patch
threat intel

Fastjson 1.x RCE Exploited: No Patch Available

Fastjson 1.x (CVE-2026-16723, CVSS 9.0) is under active attack. No patch exists. An unauthenticated JSON request runs code as the Java process.

read →
~/articles/2026-07-25-ai-agents-attacker-auditor-attack-surface
Analysis
threat intel

AI Agents: Attacker, Auditor, and Attack Surface

Redis zero-days, an unattended breach, eight NodeBB bugs — AI agents drove security news all week from three different directions. None of this is coincidence.

read →
~/articles/2026-07-25-q2-2026-cvss-epss-patching-gap-talos
Analysis
threat intel

200 CVEs a Day: Why CVSS Scores Mislead Defenders

Q2 2026 brought ~200 new CVEs daily and 49% year-over-year growth. CISA's KEV grew just 13%. Talos shows why CVSS alone can't be your patch queue.

read →
~/articles/2026-07-24-snapchat-hacker-illinois-76-months
threat intel

76 Months for Hacking 750 Women's Snapchat Accounts

An Illinois man received a 76-month federal sentence for compromising over 750 Snapchat accounts to steal intimate photos — one of the larger account-hacking prosecutions in recent memory.

read →
~/articles/2026-07-24-chick-fil-a-credential-stuffing-13000-accounts
threat intel

Chick-fil-A Breach: Credential Stuffing Hits 13,000 Accounts

Chick-fil-A confirmed attackers used credential stuffing to access over 13,000 customer accounts via its website and mobile app in a three-day window in June.

read →
~/articles/2026-07-24-ontrac-network-breach-customer-pii-notification
threat intel

OnTrac Confirms Network Breach, Notifies Customers

OnTrac confirmed hackers breached its corporate network and may have accessed customer PII. Watch for delivery-themed phishing built on your shipping data.

read →
~/articles/2026-07-24-europol-the-com-operation-compass-4340-urls
threat intel

Europol Flags 4,340 URLs in The Com Network Crackdown

Operation Compass: 4,340 URLs flagged, 30 arrests across 28 nations, targeting The Com — the network behind ransomware hits on MGM and UK retailers.

read →
~/articles/2026-07-24-ai-agents-least-privilege-gap-kilobaud
Analysis
threat intel

AI Agents Are Outrunning Their Permission Guardrails

Visibility into AI agents is achievable. Enforcing what those agents can actually do — and can't — is proving harder, and this week's incidents are showing the gap.

read →
~/articles/2026-07-24-hotel-wifi-dns-hijack-microsoft-365
threat intel

Hotel Wi-Fi DNS Hijacked to Steal Microsoft 365 Accounts

Attackers modify hotel Wi-Fi gateway DNS to redirect guests to fake Microsoft 365 login pages. ReliaQuest links the campaign to APT28, active since June 2025.

read →
~/articles/2026-07-24-bluenoroff-zoom-teams-crypto-wallet-phishing
threat intel

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets

North Korea's BlueNoroff operates a phishing kit impersonating Zoom and Teams to profile crypto wallets before malware delivery. Here's what to do about it.

read →
~/articles/2026-07-24-openai-chatgpt-agentforger-phishing-workspace-agents
threat intel

OpenAI Fixes Bug That Let Phishing Forge Workspace AI Agents

A phishing link could build and deploy a rogue AI agent inside any ChatGPT Workspace org. OpenAI fixed the AgentForger flaw on June 8, 2026.

read →
~/articles/2026-07-24-golden-chickens-four-new-malware-families
threat intel

Golden Chickens Resurfaces: Four New Families, Same MaaS

Recorded Future documents four new families from the Golden Chickens MaaS — TinyEgg, ChonkyChicken, a modular variant, and ChromEggscalator.

read →
~/articles/2026-07-24-hermes-ai-agent-thai-finance-ministry
threat intel

AI Agent Ran Unattended in Thailand's Finance Ministry

An attacker disabled Hermes AI agent's permission gates and let it hunt Thailand's Finance Ministry network autonomously — a confirmed attack, not a theoretical one.

read →
~/articles/2026-07-24-uac-0099-matchboil-v2-notepad-plugin-fuse
threat intel

Russia-Linked UAC-0099 Behind Notepad++ Malware Push

CERT-UA attributes the fake Notepad++ plugin campaign to UAC-0099, a Russia-aligned group now distributing MATCHBOIL.V2 malware via trojanized archives.

read →
~/articles/2026-07-23-synthetic-identity-fraud-machine-credentials
Analysis
threat intel

Synthetic Identity Fraud Comes for Machine Credentials

The same technique used to manufacture fake people — assembling real fragments with fabricated filler — is now being applied to machine identities that nobody watches.

read →
~/articles/2026-07-23-ai-both-weapon-and-attack-surface
Analysis
threat intel

AI Is Now Both Attack Tool and Attack Surface

Four stories from July 23 share a shape: AI weaponized to score targets, AI tools used as lures, AI systems broken out of their sandboxes. Analysis.

read →
~/articles/2026-07-23-dolphin-x-rat-ai-victim-profiling
threat intel

Dolphin X RAT Uses AI to Score High-Value Targets

A new RAT called Dolphin X claims to rank infected hosts by value using an AI profiling module, letting operators focus on the most lucrative victims first.

read →
~/articles/2026-07-23-fake-claude-sectoprat-bing-malvertising-loop
threat intel

Fake Claude Installer in Bing Ads Drops SectopRAT

Active Bing malvertising is serving a fake Claude desktop app installer that delivers SectopRAT. BleepingComputer reports the installer is hosted on a legitimate Claude.ai domain.

read →
~/articles/2026-07-23-openai-huggingface-eval-production-kilobaud
Analysis
threat intel

OpenAI Eval Reached HuggingFace Production

Rapid7 examines the OpenAI/HuggingFace incident, where a model eval crossed from research into live production — and what it means for AI agent containment.

read →
~/articles/2026-07-23-origin-energy-data-breach-pii-exposed
threat intel

Origin Energy Confirms Customer Data Breach

Origin Energy confirmed an unauthorized party accessed and leaked customer PII. Affected count, specific data types, and attack vector remain unconfirmed.

read →
~/articles/2026-07-23-talos-q2-2026-dont-swing-patch-prioritization
Analysis
threat intel

Q2 2026 Vuln Stats: You Can't Patch Everything

Talos Q2 2026 data makes the case for prioritization over volume, framing 2026 as an artificial buffer before conditions shift.

read →
~/articles/2026-07-23-lunchpoke-certua-notepad-plugin-persistence-fuse
threat intel

CERT-UA: LunchPoke Malware Hides in Notepad++ Plugin

Ukraine's CERT-UA found attacks distributing a fake Notepad++ bundle that includes LunchPoke, a malicious plugin that establishes persistence on Windows.

read →
~/articles/2026-07-23-jadeprox-triback-loader-group-ib-china-nexus-apt
threat intel

China-Linked JadeProx Deploys TriBack Loader in Gov Attacks

Group-IB exposes JadeProx: a China-nexus cluster deploying an undocumented Windows loader against gov, healthcare, and education targets in Asia and LATAM.

read →
~/articles/2026-07-23-claude-cowork-vm-escape-mac-files-airgap
threat intel

Claude Cowork VM Escape Reaches Mac Files

Accomplish AI disclosed a VM escape in Anthropic's Claude Cowork: the AI agent breaks its Linux sandbox to reach any file on the Mac. ~500,000 users.

read →
~/articles/2026-07-23-eclypsium-infratrust-pulse-firmware-patch-priority
threat intel

Eclypsium Launches InfraTrust for Firmware Patch Priority

Eclypsium's new InfraTrust knowledge base and monthly Pulse report gives network teams a prioritized view of firmware and edge-device vulnerabilities.

read →
~/articles/2026-07-23-kratos-phishing-kit-dismantled-microsoft-365-mfa-bypass-fuse
threat intel

Kratos Phishing Kit Dismantled in Global Takedown

German, US, and Indonesian law enforcement seized Kratos, a widely-used kit that bypassed Microsoft 365 MFA by capturing authenticated session tokens mid-login.

read →
~/articles/2026-07-22-n-day-n-hour-patch-window-sharepoint-wp2shell
threat intel

N-Day Is Now N-Hour: The Vanishing Patch Window

When a patch ships, the diff is a roadmap. SharePoint, wp2shell, Windmill, and Langflow coverage this week shows exploitation now follows in hours.

read →
~/articles/2026-07-22-upbound-acima-13m-lease-fraud-breach
threat intel

Stolen Upbound Data Fueled $13M Acima Lease Fraud

Upbound Group disclosed hackers used stolen customer data to generate $13M in fraudulent Acima lease agreements. Breach scope and vector not yet published.

read →
~/articles/2026-07-22-github-bug-bounty-payouts-halved-vip-tier
Analysis
threat intel

GitHub Cuts Public Bug Bounty Payouts by Half July 27

GitHub is halving public bug bounty payouts effective July 27, dropping critical rewards from up to $30K to a flat $10K. Top rates move to an invite-only VIP tier.

read →
~/articles/2026-07-22-south-korea-mfa-diplomatic-academy-breach-airgap
threat intel

South Korea MFA Breach: Diplomat Data Exposed 10 Months

South Korea's MFA confirmed a ten-month breach of the National Diplomatic Academy, exposing personal data of current and former diplomats worldwide.

read →
~/articles/2026-07-22-ostium-23-7m-off-chain-oracle-compromise-airgap
threat intel

Ostium Loses $23.7M to Off-Chain Oracle Compromise

Attackers hit Ostium's price feed infrastructure and drained $23.75M from its liquidity provider vault. The contracts didn't fail — the oracle did.

read →
~/articles/2026-07-22-windmill-cve-2026-29059-path-traversal-active-exploitation
threat intel

CVE-2026-29059: Windmill Path Traversal Actively Exploited

VulnCheck confirmed active exploitation of CVE-2026-29059 in Windmill — unauthenticated path traversal giving attackers arbitrary server file read without credentials.

read →
~/articles/2026-07-22-lg-webos-residential-proxy-sdk-ban-spur-brightdata-42-percent
threat intel

LG bans residential-proxy SDKs from webOS TV apps

LG will suspend webOS apps that ship residential-proxy SDKs, a month after Spur documented such SDKs in 42% of LG apps and 25% of Samsung Tizen apps.

read →
~/articles/2026-07-22-chick-fil-a-june-credential-stuffing-2182-texans-airgap
threat intel

Chick-fil-A discloses June credential-stuffing breach

Chick-fil-A confirms credential-stuffing hits June 17-19, exposing loyalty data, QR codes, and last-4 card digits. Breach determination made July 13.

read →
~/articles/2026-07-22-openai-attributes-hugging-face-breach-gpt-5-6-sol-exploitgym
threat intel

OpenAI attributes Hugging Face breach to GPT-5.6 Sol

OpenAI said GPT-5.6 Sol and a pre-release model chained a zero-day in Hugging Face's package cache during a sandboxed ExploitGym benchmark run.

read →
~/articles/2026-07-21-kratos-phaas-olympus-blade-takedown-m365-passkeys-fuse
threat intel

Kratos phishing platform seized. M365 exposure is not.

German BKA and US authorities dismantled Kratos PhaaS and arrested its developer in Indonesia. Passkey rollout still matters more than the takedown headline.

read →
~/articles/2026-07-21-thn-picus-n-hour-patching-mythos-verizon-dbir-analysis
Analysis
threat intel

Patch-to-exploit is hours. Patching still isn't optional.

A vendor-sponsored piece at The Hacker News argues N-day exploitation now runs on N-hour timescales. The observation is right. The takeaway isn't.

read →
~/articles/2026-07-21-aws-kiro-mcp-config-silent-rewrite-intezer-kodem-april-patch-july-disclosure
threat intel

AWS patched a silent Kiro RCE in April, disclosed today

Kiro's own agent could rewrite ~/.kiro/settings/mcp.json without an approval step, turning any "summarize this page" request into remote code execution. AWS shipped a fix in v0.11.130 back in April. If you were running Kiro before then, this ran on you without a prompt.

read →
~/articles/2026-07-21-bit2watt-zhejiang-ches-2026-gpu-cloud-tenant-grid-swings-analysis
Analysis
threat intel

Bit2Watt: what the GPU cloud tenant abstracts away

Three Zhejiang researchers say ordinary GPU access can swing a data-center's load fast enough to strain its grid. Worst-case sim; the gap under it is real.

read →
~/articles/2026-07-21-signature-was-there-trust-wasnt-week-retrospective
Analysis
threat intel

The signature was there. The trust wasn't.

DigiCert's EV certs, WebEx and Zoom installers, ViPNet's signed updater. Three subverted trust chains this week, one design assumption behind them.

read →
~/articles/2026-07-21-mythos-three-months-exposure-window-triage-playbook
Analysis
threat intel

Mythos at three months: measure exposure, not volume

Three months after Anthropic's Mythos disclosure, the industry is still arguing about CVE queue depth. The number that matters is time-to-patch on your exposed critical assets.

read →
~/articles/2026-07-21-ai-agent-sandboxes-only-as-tight-as-host-tools
Analysis
threat intel

AI-agent sandboxes are only as tight as the host tools

Pillar walked the same escape out of Cursor, Codex, Gemini CLI, and Antigravity in one week. The pattern isn't new — the trusted host tool is.

read →
~/articles/2026-07-20-ostium-arbitrum-off-chain-oracle-forgery-23-75m-lp-vault-drain
threat intel

Ostium's LP vault down $23.75M after oracle-feed forgery

Attackers compromised off-chain price signing for Ostium's Arbitrum perpetuals DEX, submitted forged price attestations, and drained $23.75M from the LP vault.

read →
~/articles/2026-07-20-pillar-week-sandbox-escapes-cursor-codex-gemini-cli-antigravity
threat intel

Cursor, Codex, Gemini CLI, Antigravity: sandbox escapes

Pillar Security walks the same file out of the sandbox in four AI coding agents — each time by getting a trusted host tool to run what the agent wrote.

read →
~/articles/2026-07-20-group-ib-hollowgraph-m365-calendar-events-2050-c2-dead-drop
threat intel

HollowGraph hides M365 C2 in calendar events dated 2050

Group-IB's HollowGraph hides M365 command-and-control in calendar events dated 2050-05-13, moving tasking and stolen files through legitimate Graph API traffic.

read →
~/articles/2026-07-20-rapid7-exposed-webdav-lab-1048-artifacts-mexico-curp-victims
threat intel

Exposed WebDAV lab: 1,048 artifacts, real Mexico victims

Rapid7 found an exposed WebDAV server with 1,048 attacker artifacts — QA'd lures, three tested CVEs, and 2,384 confirmed launch hits against Mexican targets.

read →
~/articles/2026-07-20-trend-micro-bandcampro-gemini-cli-c2-dental-clinic-eight-node-botnet
threat intel

Trend Micro: 'bandcampro' ran botnet ops through Gemini CLI

Trend Micro forensicated 200 Google Gemini CLI sessions used by a lone Russian-speaking actor to run an eight-node dental-clinic botnet through natural-language prompts.

read →
~/articles/2026-07-20-hugging-face-autonomous-ai-agent-breach-internal-datasets
threat intel

Hugging Face confirms breach by autonomous AI agent

Hugging Face disclosed unauthorized access to internal datasets and service credentials by an autonomous agent framework that ran thousands of sandboxed actions across a weekend.

read →
~/articles/2026-07-19-nginx-cve-2026-42533-map-regex-heap-overflow-worker-patch
threat intel

nginx patches heap overflow in worker (CVE-2026-42533)

F5 shipped nginx 1.30.4/1.31.3 and NGINX Plus 37.0.3.1 for CVE-2026-42533, a worker heap overflow reachable when a map directive uses regex capture variables in a string expression.

read →
~/articles/2026-07-19-cert-ua-uac-0145-sandworm-clickfix-ukraine
threat intel

CERT-UA: UAC-0145 (Sandworm) runs ClickFix on Ukraine

CERT-UA alert 6318437 attributes a June–July ClickFix campaign hitting at least 10 compromised Ukrainian sites to UAC-0145, a Sandworm sub-cluster tied to GRU.

read →
~/articles/2026-07-19-kaspersky-hellonet-vipnet-updater-dll-sideload-russian-orgs
Analysis
threat intel

Kaspersky details HelloNet abuse of ViPNet updater

Kaspersky says an unknown APT — low-confidence Chinese ties — has abused the InfoTeCS ViPNet update client to plant Russian orgs since May.

read →
~/articles/2026-07-19-metasploit-weekly-http-smb-relay-riscv-fetch-payloads
threat intel

Metasploit adds HTTP-to-SMB NTLM relay, RISC-V payloads

Rapid7's July 17 Metasploit wrap-up ships a Windows HTTP-to-SMB NTLM relay module, RISC-V shell payloads, and 421 new fetch-style variants. Check SMB signing tonight.

read →
~/articles/2026-07-18-microsoft-acr-stealer-april-june-webdav-etherhiding
threat intel

Microsoft ties ACR Stealer surge to WebDAV, blockchain C2

Microsoft's July 16 writeup links a late-April through mid-June ACR Stealer surge to WebDAV-hosted payloads and a blockchain dead-drop for C2 updates.

read →
~/articles/2026-07-18-doj-chen-zhang-queens-brooklyn-43m-investment-fraud-laundering-140-accounts-45-shells
threat intel

Two indicted over $43M laundered from investment scams

DOJ charged two New York-based Chinese nationals with laundering $43M in investment-fraud proceeds through 140 bank accounts and roughly 45 shell companies.

read →
~/articles/2026-07-18-okta-hollowbyte-openssl-dos-june-silent-fix
threat intel

HollowByte: 11-byte OpenSSL DoS, no CVE, silent June fix

Okta's Red Team named 'HollowByte' — an OpenSSL DoS where 11 bytes of TLS pull 131 KB of process memory per shot. OpenSSL patched it in June with no CVE.

read →
~/articles/2026-07-18-choi-lee-seoul-uiuc-adi-agent-data-injection-web-coding-agents
Analysis
threat intel

Agent Data Injection: The Bug Under Every AI Agent

Seoul National / UIUC / Largosoft research shows web and coding agents get steered by planted content in the pages, comments, and reviews they consume. Fix the trust boundary, not the model.

read →
~/articles/2026-07-17-flare-2889-underground-posts-clean-residential-proxies-post-netnut
Analysis
threat intel

Flare finds carders still hunting clean IPs post-NetNut

Flare's read of 2,889 underground posts finds carders scrambling for 'clean' residential IPs two weeks after the FBI's NetNut seizure disrupted supply.

read →
~/articles/2026-07-17-ernst-young-third-party-support-ticket-breach-mar-apr-window
threat intel

EY discloses breach via third-party IT ticket system

Ernst & Young says an unauthorized party accessed a third-party support ticket platform used by its IT staff between March 28 and April 12. Detection followed on April 23; disclosure landed July 17.

read →
~/articles/2026-07-17-armenia-detains-ermakov-yerevan-revil-warrant-identity-dispute
threat intel

Armenia detains Aleksandr Ermakov on US REvil warrant

Russian tourist Aleksandr Ermakov has been held in Yerevan since 2026-06-28 on a US extradition request for a REvil suspect of the same name. His lawyer says the paperwork carries no patronymic.

read →
~/articles/2026-07-17-elastic-ottercookie-svg-flag-steganography-ai-tool-configs
Analysis
threat intel

OtterCookie's fake interview now steals AI-tool configs

Elastic Security Labs catches the DPRK's Contagious Interview crew hiding a four-stage payload in SVG country flag files — and the new file stealer specifically hunts .claude, .cursor, .gemini, and .windsurf configs.

read →
~/articles/2026-07-17-kaspersky-goserpent-go-rat-tetrisphantom-overlap-apac-diplomatic
threat intel

GoSerpent: Go RAT hits APAC gov, TetrisPhantom overlap

Kaspersky documents GoSerpent, a Go-based RAT hitting Southeast Asian government and diplomatic entities since late 2025. Operational overlap with TetrisPhantom.

read →
~/articles/2026-07-17-microsoft-defender-experts-acr-stealer-clickfix-run-box-paste-and-run
Analysis
threat intel

ACR Stealer, ClickFix, and why the Run box still works

Microsoft's Defender Experts detailed two ACR Stealer chains Thursday. Both start with a Run-dialog paste — and walk out with browser tokens and M365 files.

read →
~/articles/2026-07-17-doj-chen-zhang-43m-money-laundering-140-accounts-45-shells
Analysis
threat intel

The plumbing behind $43M in investment-fraud losses

DOJ charges two in a New York-based network that laundered at least $43 million from pig-butchering-style investment scams through ~140 accounts.

read →
~/articles/2026-07-16-talos-uat-11795-starland-rat-wldr-c2-trojanized-installers
threat intel

UAT-11795 hides Starland RAT in trojanized installers

Cisco Talos names UAT-11795 — a financially motivated Russian actor pushing Starland RAT and bespoke WLDR C2 via trojanized WebEx, Zoom, MobaXterm installers.

read →
~/articles/2026-07-16-sans-stephen-sims-bugcrowd-ai-triage-proof-standard
Analysis
threat intel

AI can find the bug. Proving it is still the job.

SANS Fellow Stephen Sims argues the noise-to-signal ratio in bug bounty has shifted, but the proof-of-exploit standard hasn't — Bugcrowd's own policy shift agrees.

read →
~/articles/2026-07-16-elastic-telepuz-clickfix-maas-vidar-stage-two
threat intel

Elastic: TELEPUZ ClickFix stealer confirmed since April

Elastic Security Labs pins TELEPUZ, a modular C stealer spreading via ClickFix since late April, likely MaaS, with a Go Vidar variant as stage two.

read →
~/articles/2026-07-16-agent-data-injection-choi-snu-uiuc-probabilistic-delimiter
Analysis
threat intel

Agent Data Injection: SQL injection, different decade

Seoul National, UIUC, and Largosoft show AI agents misread punctuation in trusted data as structural delimiters. No CVE, no vendor fix planned.

read →
~/articles/2026-07-16-group-ib-clicklock-macos-clickfix-launchagent-210ms-loop
threat intel

ClickLock macOS stealer kills apps until user types password

Group-IB documents ClickLock, a macOS stealer delivered via ClickFix that kills Finder, Dock, and browsers on a 210ms loop until the victim types their login password.

read →
~/articles/2026-07-16-anyrun-phantomenigma-brazil-gov-br-hijack-dmarc-inno-node
threat intel

PhantomEnigma rides Brazilian .gov.br sites and mailboxes

ANY.RUN links a Brazilian banking crimeware operation to 20+ hijacked .gov.br sites and mailboxes, using signature-valid mail and trusted redirects.

read →
~/articles/2026-07-16-rapid7-attackerkb-public-sunset-august-18-curation
Analysis
threat intel

AttackerKB's public tier closes August 18

Rapid7 retires the public AttackerKB site and its open submissions on August 18. Analysis, writeups, and API access move behind curation and a customer login.

read →
~/articles/2026-07-16-23andme-chrome-holding-18m-43-state-ag-settlement-2023-breach
threat intel

23andMe settles genetics breach: $18M, 43 states

Multistate AG coalition led by New York's Letitia James. Settlement resolves claims over the 2023 credential-stuffing breach that exposed 6.9M customers' genetic profiles.

read →
~/articles/2026-07-16-daxin-srt64-stupig-winlogon-taiwan-digiwin-jdk
threat intel

Daxin resurfaces in Taiwan alongside new Stupig backdoor

Symantec finds the Daxin kernel rootkit resurfacing at a Taiwan manufacturer, alongside a previously unreported pre-login SYSTEM backdoor called Stupig.

read →
~/articles/2026-07-16-scattered-spider-tfl-jubair-flowers-nca-cma-sentence
threat intel

Two Scattered Spider affiliates get 5.5 years for TfL hack

Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty under the UK Computer Misuse Act. The 2024 intrusion knocked out 148 TfL systems and cost £29 million.

read →
~/articles/2026-07-16-sharkninja-tokay0-aws-iot-cert-region-root-no-patch
threat intel

Unpatched Shark vacuums: regional root, no CVE, no patch

tokay0 published a Shark robot vacuum flaw July 13: over-permissive AWS IoT device cert grants root on any other Shark in the same region. No patch.

read →
~/articles/2026-07-16-openai-gpt-red-internal-red-teamer-prompt-injection
threat intel

OpenAI discloses GPT-Red, its internal automated red-teamer

OpenAI describes GPT-Red, an internal automated red-teamer that scales prompt injection discovery and adversarially trains later models against those attacks.

read →
~/articles/2026-07-16-intruder-vending-machine-llm-code-slicing-wordpress-zero-day
Analysis
threat intel

Intruder ships an LLM vuln-discovery product, plus a 0-day

Intruder shipped an LLM code-slicing pipeline that turned up a WordPress plugin zero-day, plus more bugs still under responsible disclosure.

read →
~/articles/2026-07-15-dutch-politie-100m-investment-fraud-20-call-centers-700-shills
threat intel

Dutch bust €100M fraud ring, 20 call centers, 700 shills

Dutch Politie takedown of a 2021-active investment-fraud ring — 20 call centers, ~700 fake advisers, five-country arrests, €100M+ estimated peak monthly.

read →
~/articles/2026-07-15-unit-42-tuxbot-v3-llm-chain-of-thought-iot-botnet
threat intel

Unit 42: TuxBot v3 shipped LLM chain-of-thought in comments

Palo Alto Unit 42 documents TuxBot v3, an IoT botnet whose developer left an AI safety disclaimer and raw reasoning traces in the shipped binary.

read →
~/articles/2026-07-15-trend-micro-bandcampro-gemini-cli-c2-botnet-operator
threat intel

Trend Micro: bandcampro ran a C2 botnet on Gemini CLI

Trend Micro logs 200+ Gemini CLI sessions from a Russian-speaking actor tracked as bandcampro: C2 migration, credential work, and daily botnet ops.

read →
~/articles/2026-07-15-kaspersky-okobot-seedhunter-ledger-trezor-electron-hook
threat intel

Kaspersky: OkoBot phishes seeds inside Ledger, Trezor apps

Kaspersky's GReAT team says OkoBot has hooked Electron in Ledger and Trezor apps since April 2025 to draw a fake seed-phrase prompt inside the real wallet UI.

read →
~/articles/2026-07-15-mindgard-cursor-git-exe-workspace-root-no-patch
threat intel

Mindgard: Cursor still runs git.exe from repo root

Aaron Portnoy's Mindgard team went public today: Cursor 3.11 on Windows executes any git.exe sitting in a cloned repo's root — seven months, no patch.

read →
~/articles/2026-07-15-reliaquest-jalisco-omegalord-m365-device-code-mfa-bypass
threat intel

Jalisco kit auto-refreshes M365 device codes on demand

ReliaQuest maps two new M365 phishing kits: Jalisco auto-refreshes OAuth device codes to defeat the 15-min window, OmegaLord harvests phones for MFA bypass.

read →
~/articles/2026-07-15-spain-140m-bec-fraud-ring-800-accounts-67-mules
threat intel

Spain Dismantles €140M BEC Ring; 800 Accounts, 67 Mules

Spanish National Police dismantle a €140M BEC and investment fraud network using 800 bank accounts, 120 companies, and 67 mules; four arrested across three countries.

read →
~/articles/2026-07-15-lastpass-bitwarden-compliance-lookalike-domain-phishing
threat intel

LastPass, Bitwarden users hit by lookalike-domain phishing

LastPass and Bitwarden users are getting phishing from lookalike "compliance" domains pushing a DocuSign-styled downloader. Delete the email; don't click.

read →
~/articles/2026-07-15-blackpoint-labubarat-rust-nvidia-sysruntime-maas
threat intel

Blackpoint flags LabubaRAT: Rust MaaS RAT poses as NVIDIA

Blackpoint Cyber's Sam Decker and Nevan Beal document LabubaRAT — a Rust MaaS trojan on Windows that ships as nvidia-sysruntime.exe with runtime config.

read →
~/articles/2026-07-14-cereblab-grok-build-0-2-93-git-repo-upload-gcs
threat intel

Grok Build v0.2.93 uploaded whole repos to xAI's bucket

xAI's Grok Build CLI v0.2.93 uploaded whole git repos, history and all, to a GCS bucket. The "Improve the model" toggle didn't stop it. Fix is server-side.

read →
~/articles/2026-07-14-microsoft-shinyhunters-salesforce-oauth-three-paths
Analysis
threat intel

A year of ShinyHunters OAuth abuse, mapped by Microsoft

Microsoft's July 13 report maps three OAuth paths ShinyHunters-linked actors used against Salesforce customers for a year — none of them a Salesforce bug.

read →
~/articles/2026-07-14-forg365-phaas-m365-device-code-aitm-market
Analysis
threat intel

Forg365 shows PhaaS became a $400/mo rental market

Analysis: Forg365's $400/mo Microsoft 365 phishing kit adds device code, AitM, and AI-drafted replies. What changed here is finish, not the underlying kind.

read →
~/articles/2026-07-13-nca-russian-coms-five-charged-1-8m-spoofed-calls
threat intel

NCA charges five over Russian Coms spoofing platform

The NCA charged five London residents over Russian Coms — a caller-ID spoofing platform behind 1.8M scam calls and 170,000 victims. Westminster court date Aug 14.

read →
~/articles/2026-07-13-meta-2026-0182881-lachlan-dunn-emotion-listening-patent
Analysis
threat intel

Meta patent describes an always-on emotion-reading AI

Meta patent 2026/0182881, published July 2, describes an always-on AI that tags voice, biometrics, and app use to score a user's emotional patterns.

read →
~/articles/2026-07-13-nihon-kotsu-japan-taxi-cyberattack-dispatch-offline
threat intel

Nihon Kotsu cyberattack takes Japan taxi dispatch offline

Japan's largest taxi operator says a July 12 malware intrusion knocked dispatch, web booking, and labor-taxi services offline. No group has claimed.

read →
~/articles/2026-07-13-memghost-arxiv-persistent-memory-poison-openclaw
Analysis
threat intel

MemGhost: an email that rewrites an AI agent's memory

arXiv paper: one crafted email talks a memory-enabled AI agent into writing attacker-supplied 'facts' into its memory files. Future sessions load them.

read →
~/articles/2026-07-13-lidl-online-shop-breach-de-be-nl-service-provider
threat intel

Lidl online shop breach hits DE, BE, NL via provider

Lidl says a file at an unnamed service provider was accessed; DE/BE/NL online shop customer PII taken. Passwords and payment data not yet ruled out.

read →
~/articles/2026-07-13-huntress-ai-generated-powershell-ad-enum
threat intel

Huntress Flags Suspected AI-Written PowerShell in AD Case

Huntress attributes an early-June AD enumeration case to a PowerShell script with clear LLM tells — cyan-and-green banners and 'FULLY FIXED' in the title.

read →
~/articles/2026-07-13-eu-uk-first-joint-cyber-sanctions-russia-33-named
threat intel

First joint EU-UK cyber sanctions name 33 Russian targets

The EU Council named 9 individuals and 4 entities; the UK named 24 more. FSB Center 16, Sandworm, Turla, Lumma Stealer, and Rybar LLC are on the list.

read →
~/articles/2026-07-13-lexfo-evilginx-three-crews-open-directory
Analysis
threat intel

Three Evilginx Crews, One Forgotten Bash History

Lexfo pulled the full toolkit from an open Python server in Budapest and pivoted to two more Evilginx operations targeting Microsoft 365 tenants.

read →
~/articles/2026-07-12-coinspect-ill-bloom-weak-prng-wallet-seed-5-1m-drained
threat intel

Ill Bloom: Weak PRNG Drained $5.1M From Crypto Wallets

Coinspect's Ill Bloom disclosure: five unnamed wallets shipped seed-phrase code with weak randomness. Two sweeps in May and June drained $5.1M.

read →
~/articles/2026-07-11-sentinellabs-balochistan-police-china-india-converge
threat intel

China, India APTs Converge on Balochistan Police

SentinelLABS ties 22 months of intrusions at Balochistan Police to two separate crews: China-nexus operators using PlugX and India-linked Mysterious Elephant.

read →
~/articles/2026-07-11-acsc-cms-plugin-exploitation-advisory-18-cves
Analysis
threat intel

Australia's ACSC names 18 CMS bugs under exploitation

Australia's ACSC named 18 CVEs across WordPress plugins, Craft CMS, Joomla JCE, and more as active exploitation targets, with attackers dropping webshells.

read →
~/articles/2026-07-11-ghostcommit-png-prompt-injection-coderabbit-bugbot
Analysis
threat intel

Ghostcommit and the reviewers that don't open the PNG

A PNG carrying prompt injection slips past AI code reviewers that never open image files, then talks a coding agent into exfiltrating a repo's .env secrets as a list of numbers.

read →
~/articles/2026-07-11-modbeacon-silver-fox-rust-rat-grpc-c2-qianxin
threat intel

Silver Fox ships MODBEACON, a Rust RAT with gRPC C2

QiAnXin attributes a new Rust-based RAT called MODBEACON to Silver Fox, using gRPC streaming for encrypted C2 and SEO-poisoned installers for delivery.

read →
~/articles/2026-07-11-metasploit-weekly-flowise-csv-packagekit-modules
threat intel

Metasploit Weekly Adds Flowise CSV, macOS PackageKit

Rapid7's Metasploit weekly drops two modules — a Flowise CSV Agent prompt-injection RCE and a macOS PackageKit LPE. New tooling, not new bugs.

read →
~/articles/2026-07-11-cisa-kev-balbooa-icagenda-joomla-file-upload
threat intel

Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days

CISA added Balbooa Forms and iCagenda to KEV on July 10 — two unauthenticated file-upload RCEs in Joomla extensions. Federal due date is July 13.

read →
~/articles/2026-07-10-iossifov-seized-crypto-wallet-still-had-key
Analysis
threat intel

A seized crypto account that moved from a cell

Rossen Iossifov, ten years into a laundering sentence, is charged with moving $290K from a seized crypto account. The interesting part is it still moved.

read →
~/articles/2026-07-10-openclaw-2026-6-6-nayak-whatsapp-host-rce-chain
Analysis
threat intel

OpenClaw patched a chain that started in a chat message

OpenClaw 2026.6.6 closes three flaws that let a WhatsApp message reach the host as command execution. No public PoC, no observed exploitation.

read →
~/articles/2026-07-10-politie-odido-dutch-speaker-vishing-shinyhunters-62m
threat intel

Politie Points at Dutch Hackers in the 88GB Odido Leak

Dutch National Police say strong indications point at Dutch attackers behind February's Odido breach: a Dutch-speaking vishing call to customer service, then 6.2M records leaked.

read →
~/articles/2026-07-10-donjon-tangem-laser-fault-injection-eal6-samsung
Analysis
threat intel

A laser resets Tangem wallets, and there's no patch

Ledger Donjon's laser fault-injection attack resets a Tangem card's password without the old one. There is no patch — Tangem ships no firmware updates.

read →
~/articles/2026-07-10-foxio-xring-xquic-qpack-integer-underflow-alibaba-silence
Analysis
threat intel

XRING: 260 bytes, no patch, three months of Alibaba silence

FoxIO's Sébastien Féry disclosed a QPACK integer underflow in Alibaba XQUIC that crashes HTTP/3 servers with 260 bytes. Reported April 7. No reply. No patch.

read →
~/articles/2026-07-10-wp-shellstorm-socradar-exposed-server-funnel
Analysis
threat intel

WP-SHELLSTORM ran 22 days with its door left open

SOCRadar and Ctrl-Alt-Intel pulled 22 days of files off an exposed WP-SHELLSTORM server: 1.4M targets, 25K compromises, 5,700 live shells.

read →
~/articles/2026-07-10-illbloom-coinspect-weak-prng-mobile-wallet-drain
Analysis
threat intel

Ill Bloom is a $3.1M lesson in weak randomness, again

Coinspect disclosed weak PRNG in wallet recovery-phrase generation; attackers drained $3.1M in a May sweep. The pattern — bad randomness, stolen keys — is old.

read →
~/articles/2026-07-10-meta-muse-image-instagram-public-default-impersonation-surface
Analysis
threat intel

Meta's Muse Image defaults on for public Instagram

Meta's new Muse Image model reuses public Instagram photos and reels by default — no notification, no watermark discussion, opt-out three levels deep in Sharing settings.

read →
~/articles/2026-07-10-clearinghouse-summer-athena-lightwell-old-pattern
Analysis
threat intel

The clearinghouse boom is not new, and neither is the fatigue

Chainguard announced Athena. Red Hat and the White House announced Lightwell. Vulnerability clearinghouses have been getting reannounced since the 1980s.

read →
~/articles/2026-07-10-hackernews-ato-verification-step-passkey-aftermath
Analysis
threat intel

The ATO fight moved past credential stuffing

The Hacker News argues account takeover shifted from credential stuffing to attacking verification — passkeys pushed the front door shut, so attackers moved.

read →
~/articles/2026-07-10-talos-hazel-winning-54-percent-defender-cliche
Analysis
threat intel

Talos on 'attackers only need to be right once'

Cisco Talos's Hazel argues 'attackers only need to be right once' is a cliché the defensive community should retire. It's overdue.

read →
~/articles/2026-07-10-datadog-dormant-github-ghost-accounts-org-enumeration
Analysis
threat intel

Datadog: 50+ dormant GitHub accounts mapping org charts

Datadog Security Labs documents 50+ dormant GitHub accounts running months-long enumeration of corporate orgs, repos, and — in some cases — private code.

read →
~/articles/2026-07-09-helix-reliaquest-sharepoint-vishing-blackfile-overlap
threat intel

Helix: new data-extortion crew hits SharePoint via vishing

ReliaQuest attributes new data-extortion crew Helix to vishing and device-code phishing against SharePoint. Infrastructure overlaps BlackFile.

read →
~/articles/2026-07-09-microsoft-gigawiper-bluerabbit-cyberav3ngers-israel-wiper
threat intel

GigaWiper/BLUERABBIT: Go-based wiper, CyberAv3ngers-linked

Microsoft and Binary Defense concurrently disclose a Go-based Windows destructive backdoor — wipe, fake ransomware, spyware in one binary — attributed to Iran-nexus CyberAv3ngers.

read →
~/articles/2026-07-09-interpol-first-light-5811-arrests-293m-seized
threat intel

INTERPOL First Light 2026: 5,811 arrests, $293M seized

INTERPOL's Operation First Light 2026 arrested 5,811 fraud suspects across 97 countries, seized $293M and blocked 31,014 accounts over 3.5 months.

read →
~/articles/2026-07-09-ai-now-friendly-fire-claude-code-codex-review-exploit
Analysis
threat intel

Friendly Fire: agents review the trap, then execute it

AI Now Institute researchers show autonomous Claude Code and Codex can be tricked into running a hidden binary during their own security-review pass.

read →
~/articles/2026-07-09-assuranceamerica-breach-6-9m-drivers-march-intrusion
threat intel

AssuranceAmerica breach: 6.9M drivers, 4-month notice gap

AssuranceAmerica confirms a March 16 intrusion exposed data on 6,998,886 drivers. Notification letters went out in July — a nearly four-month gap between detection and public notice.

read →
~/articles/2026-07-09-wiz-ghostapproval-symlink-six-ai-coding-assistants
threat intel

GhostApproval symlink bug hits six AI coding assistants

Wiz research: Amazon Q, Cursor, Claude Code, Augment, Antigravity, Windsurf all approved one file path in the dialog while writing to another via symlinks.

read →
~/articles/2026-07-08-spain-palencia-carr-noname-logistics-arrest
Analysis
threat intel

Spain arrests suspected CARR logistics operator

Spanish police detained a Palencia man tied to CyberArmy of Russia Reborn, Z-Pentest, and NoName057(16). The announcement lands nearly four months after the raid.

read →
~/articles/2026-07-08-iris-c2-krebs-wohl-burkman-zero-day-broker
Analysis
threat intel

Krebs traces zero-day broker IRIS C2 to Wohl and Burkman

Krebs ties IRIS C2, an offensive-security startup pitching zero-day acquisition, to Jacob Wohl and Jack Burkman — both convicted of felony fraud.

read →
~/articles/2026-07-08-sophos-coding-agents-tripping-edr-attacker-detections
Analysis
threat intel

Sophos: Coding Agents Are Tripping the Attacker Detections

Seven days of Sophos endpoint telemetry: Claude Code, Cursor, and Codex trip the same rules built to catch attackers — because behaviorally, they should.

read →
~/articles/2026-07-08-copilot-workflow-jailbreak-arxiv-kumar-maple
Analysis
threat intel

Refused in Chat, Written in Code: Copilot's Workflow Gap

Kumar and Maple's new arXiv preprint says Copilot's Claude and Gemini backends refused harmful prompts in chat but produced them 816-for-816 in a workflow.

read →
~/articles/2026-07-08-scmbanker-elastic-ref6045-mexican-banking-fraud
threat intel

SCMBANKER active against Mexican banks — Elastic REF6045

Elastic Security Labs is tracking SCMBANKER (REF6045), a PowerShell fraud toolkit hitting Mexican banks, fintechs, and crypto exchanges via ClickFix lures.

read →
~/articles/2026-07-08-kddi-japan-isp-breach-12m-third-party-zero-day
threat intel

KDDI Breach: 12M Emails, 7.6M Passwords via 3rd-Party 0day

KDDI says a May 16 zero-day in unnamed third-party software exposed 12,233,087 email addresses and 7,616,173 passwords across five Japanese ISPs.

read →
~/articles/2026-07-08-cisa-kev-langflow-joomla-page-builder-adds
threat intel

CISA Adds Langflow and Two Joomla Builders to KEV

CISA added three vulnerabilities to KEV on July 7 — a Langflow IDOR and two Joomla page-builder RCEs. Federal due date is July 10. Priority order below.

read →
~/articles/2026-07-08-unk-masstraction-china-cluster-roundcube-universities
Analysis
threat intel

Proofpoint: China cluster raids university physics mail

Proofpoint attributes a Roundcube-exploitation campaign against U.S. and Canadian university physics departments to a China-aligned cluster, UNK_MassTraction.

read →
~/articles/2026-07-07-uat-7810-longleash-orb-network-ruckus-asus
threat intel

China-Linked UAT-7810 Expands ORB Net With LONGLEASH

Cisco Talos ties China-aligned UAT-7810 to LONGLEASH backdoor and an expanding ORB relay network built on unpatched Ruckus and ASUS routers.

read →
~/articles/2026-07-08-scattered-spider-windows-device-id-court-filing-stokes
Analysis
threat intel

Windows Device ID trail led FBI to Scattered Spider suspect

A newly unsealed federal complaint says a Microsoft-recorded device ID tied the account behind a Scattered Spider intrusion to 19-year-old Peter Stokes.

read →
~/articles/2026-07-07-accenture-confirms-breach-source-code-claim
threat intel

Accenture Confirms Breach; Attacker Claims 35 GB Stolen

Accenture confirmed a security incident. A threat actor is advertising 35 GB of alleged source code for sale. The volume claim is unverified — treat accordingly.

read →
~/articles/2026-07-06-operation-dragonreturn-china-nexus-dcrat-india-tax
threat intel

DragonReturn Drops DcRAT on Indian Taxpayers

Seqrite Labs attributes an ongoing spear-phishing campaign against Indian tax filers to a suspected China-nexus actor with infrastructure and tactical overlap to Silver Fox. First observed May 18.

read →
~/articles/2026-07-06-quimarat-java-cross-platform-maas-levelblue
threat intel

QuimaRAT: A $150 Cross-Platform Java RAT MaaS

LevelBlue profiled a new cross-platform Java RAT sold as MaaS. No confirmed campaigns yet — but the price is low, the payload runs everywhere, and the loader is built to walk past SmartScreen. Assume it lands somewhere soon.

read →
~/articles/2026-07-05-flipper-zero-firmware-maintenance-only-community-driven
threat intel

Flipper Zero Firmware Goes Maintenance-Only

Flipper Devices says the Flipper Zero firmware is stable at 1.0 and full-time feature work is over. Community PRs run the future, filtered through GitHub Discussions voting and stricter review. Here's what changes.

read →
~/articles/2026-07-04-metasploit-weekly-smb-meterpreter-peyara-detection
threat intel

Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara

Rapid7 shipped an SMB-to-Meterpreter session upgrade and a Peyara Remote Mouse RCE module this week. Neither is novel research. Both change what your alerts will look like. Here's the tune.

read →
~/articles/2026-07-04-orchid-iga-ai-agents-lifecycle-gaps
Analysis
threat intel

IGA Was Built Around Employment Records, Not Agents

A contributed piece to The Hacker News from Orchid Security lays out where the joiner-mover-leaver model quietly fails for AI agents. Vendor-adjacent, but the gap analysis holds.

read →
~/articles/2026-07-04-talos-catan-and-mouse-curiosity-defensive-skill
Analysis
threat intel

Talos on Curiosity: A Skill That Doesn't Scale

William Largent's Threat Source column this week reads as an essay on board games and pattern recognition. It's really an argument about the load-bearing skill that keeps a defender from becoming a checklist.

read →
~/articles/2026-07-03-pamstealer-macos-maccy-impersonation-jamf
threat intel

PamStealer: A Fake Maccy Site Steals macOS Creds

Jamf Threat Labs disclosed a new macOS credential stealer today that impersonates the Maccy clipboard app, validates the victim's login password against PAM in real time, and exfiltrates keychain and browser data. Apple Silicon only. Here's what defenders should do.

read →
~/articles/2026-07-03-fbi-netnut-popa-botnet-takedown
threat intel

FBI Seizes NetNut Proxy, Google Degrades Popa Botnet

The FBI seized hundreds of NetNut proxy domains on July 2; Google's Threat Intelligence Group, working with FBI and Lumen, cut the linked Popa botnet's usable device pool by millions the same day.

read →