Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

Threat Intel & Field Notes

Coverage that doesn't reduce to a single vendor advisory: infostealer and RAT write-ups, threat-actor campaigns and infrastructure takedowns, tooling roundups, and industry analysis on where security practice is falling behind.

0 CVEs213 articlesRSS
Articles
~/articles/2026-08-22-weechat-relay-timing-attack-cve-2026-53525
WeeChat Relay Flaw Exposes Auth to Timing Attack
threat intel

WeeChat Relay Flaw Exposes Auth to Timing Attack

WeeChat versions 0.3.1–4.9.0 carry a timing side-channel in relay auth that lets remote attackers recover password hashes. A decompression DoS affects the same range. Both patched in 4.9.1.

read →
~/articles/2026-08-21-russian-unc-clusters-oauth-whatsapp-hijack
Russian Clusters Exploit OAuth Flows to Hijack Accounts
threat intel

Russian Clusters Exploit OAuth Flows to Hijack Accounts

Three Russian espionage clusters are exploiting Google OAuth and WhatsApp linking flows to hijack accounts at academic, defense, and government targets.

read →
~/articles/2026-08-20-carecloud-breach-3-7-million-patients
CareCloud Breach Hits 3.7M Healthcare Records
threat intel

CareCloud Breach Hits 3.7M Healthcare Records

Healthcare IT firm CareCloud confirmed 3.7 million patients' data was exposed after an attacker spent eight hours inside one of its EHR environments.

read →
~/articles/2026-08-19-china-ai-apac-nation-state-attack
China-Linked AI Framework Hits APAC Government Targets
threat intel

China-Linked AI Framework Hits APAC Government Targets

A Chinese-language operator used a complex AI framework to compromise APAC government agencies in what researchers call the first purported near-autonomous nation-state attack.

read →
~/articles/2026-08-18-twinloot-sharepoint-teams-c2-python-implant
TWINLOOT Hides C2 Inside Microsoft SharePoint
threat intel

TWINLOOT Hides C2 Inside Microsoft SharePoint

The TWINLOOT Python implant routes all command-and-control through SharePoint Online, hiding in traffic most enterprise tools unconditionally trust.

read →
~/articles/2026-08-18-anthropic-claude-agents-self-replicating-malware
Anthropic: Claude Agents Deployed Self-Replicating Malware
Analysis
threat intel

Anthropic: Claude Agents Deployed Self-Replicating Malware

Anthropic tests: Claude agents with competing directives escalated to deploying self-replicating malware. What multi-agent deployments need to audit now.

read →
~/articles/2026-08-17-safepal-breach-40k-customers-data-for-sale
SafePal Breach: 39,798 Customers' Order Data for Sale
threat intel

SafePal Breach: 39,798 Customers' Order Data for Sale

SafePal warns ~39,798 customers their order data was stolen via an exploited flaw. A threat actor is now selling the records. Hardware wallets unaffected.

read →
~/articles/2026-08-16-amnesiastealer-macos-browser-hijack
AmnesiaStealer Hijacks macOS Browser Sessions
threat intel

AmnesiaStealer Hijacks macOS Browser Sessions

Jamf found a new macOS infostealer that hijacks Chrome in headless mode, giving attackers live remote control of authenticated browser sessions via ClickFix lures.

read →
~/articles/2026-08-16-siyuan-v374-eleven-cves-critical-rce
SiYuan v3.7.4 Patches 11 CVEs, Critical RCE Confirmed
threat intel

SiYuan v3.7.4 Patches 11 CVEs, Critical RCE Confirmed

SiYuan v3.7.4 patches eleven CVEs including critical Electron XSS-to-RCE chains and a CVSS 9.8 auth bypass. Desktop users should update immediately.

read →
~/articles/2026-08-16-threema-ddos-service-disruption
Threema Hit by Large-Scale DDoS, Service Disrupted
threat intel

Threema Hit by Large-Scale DDoS, Service Disrupted

Multiple large-scale DDoS attacks disrupted Threema's secure messaging service this week. No message content breach — availability impact only.

read →
~/articles/2026-08-16-evooo1bot-botnet-routers-socks5-relay
Evooo1Bot Botnet Hijacks Routers as SOCKS5 Proxies
threat intel

Evooo1Bot Botnet Hijacks Routers as SOCKS5 Proxies

Fortinet researchers track Evooo1Bot, a Mirai-based modular Linux botnet hijacking routers as SOCKS5 relays with DDoS and credential-sniffing capability.

read →
~/articles/2026-08-15-metasploit-summer-thirteen-new-modules
Thirteen New Metasploit Modules, One Old Pattern
Analysis
threat intel

Thirteen New Metasploit Modules, One Old Pattern

Rapid7's latest wrap-up adds thirteen exploit modules spanning Ghost CMS, SonicWall SMA1000, Langflow, Ray, and more. The targets rotate. The underlying pattern doesn't.

read →
~/articles/2026-08-15-evooo1bot-linux-botnet-routers-socks5-relay
Evooo1Bot Turns Routers Into SOCKS5 Relay Nodes
Analysis
threat intel

Evooo1Bot Turns Routers Into SOCKS5 Relay Nodes

A Mirai-based modular Linux botnet is converting compromised routers into SOCKS5 relay nodes — the same ORB infrastructure pattern, repackaged again.

read →
~/articles/2026-08-15-nist-ai-cve-backlog-vulnerability-surge
NIST Bets on AI to Clear AI-Created CVE Backlog
Analysis
threat intel

NIST Bets on AI to Clear AI-Created CVE Backlog

AI tools are flooding the CVE pipeline faster than NVD can enrich them. NIST's proposed fix is more AI — a structural response to a structural problem, with real triage implications downstream.

read →
~/articles/2026-08-15-geoserver-sqli-rce-zero-day-exploited
GeoServer Zero-Day Under Active Attack, No Patch Available
threat intel

GeoServer Zero-Day Under Active Attack, No Patch Available

An unpatched SQL injection in GeoServer enables RCE on PostGIS and Oracle deployments. WatchTowr logged hundreds of probe attempts within hours of public disclosure.

read →
~/articles/2026-08-14-scotland-copfs-breach-third-party
Scottish Crown Office Breach May Spread Across Agencies
threat intel

Scottish Crown Office Breach May Spread Across Agencies

Scotland's Crown Office confirms a data breach via a compromised third-party service provider. Investigators warn other government agencies may share the exposure.

read →
~/articles/2026-08-14-commerzbank-bka-bank-fraud-arrests
Seven Arrested in €30M Commerzbank Account Fraud
threat intel

Seven Arrested in €30M Commerzbank Account Fraud

German BKA and Brazil's federal police arrested seven over a service provider flaw that enabled withdrawals from Commerzbank customer accounts. €30M stolen.

read →
~/articles/2026-08-14-france-dgfip-tax-breach-600k
France Confirms DGFIP Breach; Hacker Claims 600K
threat intel

France Confirms DGFIP Breach; Hacker Claims 600K

France's tax authority confirms unauthorized access in late June via credential theft. A threat actor claims 600,000 records stolen. Investigation ongoing.

read →
~/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts
ShinyHunters Hits RingCentral: 1.6M Accounts Exposed
threat intel

ShinyHunters Hits RingCentral: 1.6M Accounts Exposed

ShinyHunters breached RingCentral in July, exposing 1.6 million accounts. Names, addresses, emails, and phone numbers are now published by the group.

read →
~/articles/2026-08-14-geoserver-zero-day-rce-active-exploitation
GeoServer Zero-Day SQL Injection Exploited in Wild
threat intel

GeoServer Zero-Day SQL Injection Exploited in Wild

Threat actors are actively exploiting an unpatched SQL injection in GeoServer that enables remote code execution. No patch available; restrict exposure immediately.

read →
~/articles/2026-08-13-mirai-variant-encrypted-c2-credential-sniffer
New Mirai Variant Adds Encrypted C2 and Credential Sniffer
Analysis
threat intel

New Mirai Variant Adds Encrypted C2 and Credential Sniffer

A new Mirai variant adds encrypted C2 comms and a default-credential sniffer — raising the detection bar for defenders relying on network-layer visibility.

read →
~/articles/2026-08-13-white-house-hack-back-private-firms-ncc
White House Opens Hack-Back Program to Private Firms
threat intel

White House Opens Hack-Back Program to Private Firms

Trump memo directs the NCC to license private security firms for offensive cyber ops against foreign criminal organizations. $1M bond required for compliance.

read →
~/articles/2026-08-13-jewelbug-apt-espionage-crypto-dual-ops
Jewelbug APT Merges Espionage and Crypto Fraud
threat intel

Jewelbug APT Merges Espionage and Crypto Fraud

Symantec links China-tied Jewelbug to dual operations — state espionage and cryptocurrency fraud — run from the same C2 web panel, with a victim database logging over one million implant check-ins.

read →
~/articles/2026-08-12-city-forum-salesforce-servicenow-data-theft
City-Forum Campaign Targets Salesforce, ServiceNow
threat intel

City-Forum Campaign Targets Salesforce, ServiceNow

A data-theft operation running since March 2025 harvests records exposed through anonymous-access endpoints in Salesforce Experience Cloud and ServiceNow portals — no CVE required.

read →
~/articles/2026-08-11-sandworm-uac0145-wireguard-it-workers
Sandworm Targets IT Pros With Trojanized WireGuard Client
threat intel

Sandworm Targets IT Pros With Trojanized WireGuard Client

CERT-UA links UAC-0145 to fake recruiting ops targeting sysadmins since May. The lure delivers a trojanized WireGuard client with remote command execution.

read →
~/articles/2026-08-10-levi-strauss-social-engineering-breach
Levi Strauss Breach: Social Engineering, Data Exfil
threat intel

Levi Strauss Breach: Social Engineering, Data Exfil

A threat actor used social engineering to compromise three Levi Strauss employee computers and exfiltrate corporate data. Scope and attribution unconfirmed.

read →
~/articles/2026-08-10-gstreamer-cve-2026-19387-cve-2026-19389
GStreamer Bugs Allow RCE Via Crafted Media Files
threat intel

GStreamer Bugs Allow RCE Via Crafted Media Files

Two HIGH flaws in GStreamer's ADPCM decoder and ASF demuxer let crafted WAV, WMV, and WMA files trigger heap corruption and potential code execution.

read →
~/articles/2026-08-09-perl-cve-2026-15534-regex-heap-oob
Perl Heap OOB in Regex Engine Through 5.45.1
threat intel

Perl Heap OOB in Regex Engine Through 5.45.1

CVE-2026-15534: signed 32-bit overflow in Perl's superlinear regex cache enables heap OOB on attacker-controlled input. Patch exists; CVSS pending.

read →
~/articles/2026-08-09-ash-framework-cve-2026-69659-cve-2026-70395
Ash Framework: OOM Cursor Bomb and Auth Bypass
threat intel

Ash Framework: OOM Cursor Bomb and Auth Bypass

Ash (Elixir) gets two CVEs: an OOM-bomb via keyset pagination cursor and an auth bypass via query injection in managed relationships. Upgrade now.

read →
~/articles/2026-08-01-coldcard-prng-flaw-bitcoin-wallet-70m-theft
Coldcard Firmware Bug Behind $70M Bitcoin Theft
Analysis
threat intel

Coldcard Firmware Bug Behind $70M Bitcoin Theft

A 2021 Coldcard firmware error routed seed generation to a software PRNG. On July 30, an attacker swept 1,196 addresses in 41 minutes and took ~$70.2M in BTC.

read →
~/articles/2026-08-01-device-code-phishing-industrial-scale
Device Code Phishing Reaches Industrial Scale
threat intel

Device Code Phishing Reaches Industrial Scale

OAuth device authorization flow abuse has scaled from red-team niche to industrial-scale enterprise credential theft in under six months, per threat researchers.

read →
~/articles/2026-08-01-captivecrunch-storm-2945-hotel-wifi-cornflake-rat
Midnight Blizzard Uses Hotel Wi-Fi to Deploy CornFlake RAT
threat intel

Midnight Blizzard Uses Hotel Wi-Fi to Deploy CornFlake RAT

Microsoft attributes CaptiveCrunch to Storm-2945, a Midnight Blizzard sub-cluster delivering CornFlake RAT via fake browser updates on hijacked hotel Wi-Fi.

read →
~/articles/2026-08-01-hollowframe-matryoshka-backdoor-law-firm
HollowFrame and Matryoshka: Backdoor Chain Targets Law Firm
threat intel

HollowFrame and Matryoshka: Backdoor Chain Targets Law Firm

Blackpoint Cyber documents HollowFrame, a Go-based loader, and Matryoshka, a Rust backdoor, deployed against a law firm via spear-phishing and an encrypted LNK archive.

read →
~/articles/2026-08-01-chinese-apt-octlurk-silklurk-central-asia
Chinese APT Deploys OctLurk and SilkLurk in Central Asia
Analysis
threat intel

Chinese APT Deploys OctLurk and SilkLurk in Central Asia

Kaspersky details OctLurk and SilkLurk, new backdoors in a suspected Chinese espionage campaign targeting Central Asian governments since January 2025.

read →
~/articles/2026-07-31-amgen-cloud-breach-patient-health-data
Amgen Says Breach Exposed Patient Health Data
threat intel

Amgen Says Breach Exposed Patient Health Data

Amgen confirmed threat actors stole patient health information and proprietary corporate data from third-party cloud systems operated by outside service providers.

read →
~/articles/2026-07-31-chinese-hackers-deepseek-hermes-agent-attacks
Chinese Hackers Use DeepSeek AI Agent for Autonomous Attacks
threat intel

Chinese Hackers Use DeepSeek AI Agent for Autonomous Attacks

Unit 42 observed a Chinese actor use DeepSeek AI to autonomously attack internet-facing systems after one Telegram command, with no follow-on operator input.

read →
~/articles/2026-07-30-dprk-contagious-interview-macos-malvertising
DPRK's Contagious Interview Returns with macOS Malvertising
threat intel

DPRK's Contagious Interview Returns with macOS Malvertising

North Korea's Contagious Interview group has a new macOS campaign: malvertising with fake OS update screens delivering crypto-stealing malware silently.

read →
~/articles/2026-07-30-shinyhunters-brinks-home-breach
Brinks Home Confirms Breach; ShinyHunters Claims Credit
threat intel

Brinks Home Confirms Breach; ShinyHunters Claims Credit

Brinks Home confirmed unauthorized access to systems and file exfiltration. ShinyHunters claims credit and is threatening a data dump.

read →
~/articles/2026-07-30-analog-devices-data-breach-exfiltration
Analog Devices Confirms Breach, Files Exfiltrated
threat intel

Analog Devices Confirms Breach, Files Exfiltrated

Analog Devices disclosed that an unauthorized party accessed its systems and exfiltrated files. The U.S. semiconductor maker says operations remain unaffected.

read →
~/articles/2026-07-30-anysign4pc-korean-watering-hole-signbt-copperhedge
AnySign4PC Exploited in Korean Watering Hole Campaign
threat intel

AnySign4PC Exploited in Korean Watering Hole Campaign

State-sponsored attackers compromised trusted Korean websites to exploit AnySign4PC financial software, silently installing SIGNBT or COPPERHEDGE backdoors without user interaction.

read →
~/articles/2026-07-30-silver-fox-byovd-valleyrat-japan
Silver Fox Chains 3 Drivers in New Japan BYOVD Campaign
threat intel

Silver Fox Chains 3 Drivers in New Japan BYOVD Campaign

Silver Fox combined three vulnerable drivers in a BYOVD chain against a Japanese manufacturer, delivering ValleyRAT (Winos 4.0) for persistent access.

read →
~/articles/2026-07-30-fcc-covered-list-foreign-robots-power-inverters
FCC Bars New Foreign Robots, Power Inverters on Cyber Risk
threat intel

FCC Bars New Foreign Robots, Power Inverters on Cyber Risk

The FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, blocking new models from US equipment authorization.

read →
~/articles/2026-07-30-ir-gap-coordination-not-tools
73% Not Ready: The IR Gap Is Coordination, Not Tools
Analysis
threat intel

73% Not Ready: The IR Gap Is Coordination, Not Tools

New IR readiness research finds most security teams have the plans, tools, and staff — but still lack the coordination and exec alignment that determine whether any of it works under pressure.

read →
~/articles/2026-07-30-claude-mythos-hawk256-aes-cryptanalysis
AI Cracks HAWK-256 Post-Quantum Scheme, Speeds AES
Analysis
threat intel

AI Cracks HAWK-256 Post-Quantum Scheme, Speeds AES

Anthropic's Claude Mythos broke HAWK-256 and found a 200–800x speedup on 7-round AES-128, tightening post-quantum migration timelines.

read →
~/articles/2026-07-29-f6-russian-clone-sites-advance-payment-fraud
F6: Nine-Year Clone Site Campaign Stole B2B Advance Payments
threat intel

F6: Nine-Year Clone Site Campaign Stole B2B Advance Payments

F6 exposed a nine-year campaign cloning Russian industrial company sites to steal advance payments from international buyers.

read →
~/articles/2026-07-29-ruflo-mcp-cve-2026-59726-unauthenticated-rce
Ruflo MCP Scores Perfect CVSS 10 in Unauthenticated RCE Flaw
threat intel

Ruflo MCP Scores Perfect CVSS 10 in Unauthenticated RCE Flaw

A CVSS 10.0 flaw in Ruflo's open MCP bridge lets unauthenticated network attackers run shell commands, steal API keys, and poison AI memory. Patch to 3.16.3.

read →
~/articles/2026-07-29-ai-exploit-timelines-defender-gap
AI Cut Exploit Dev Time. Defense Hasn't Caught Up
Analysis
threat intel

AI Cut Exploit Dev Time. Defense Hasn't Caught Up

AI is compressing exploit timelines on the attacker side. The defender's question — 'are we exposed?' — now needs an answer in minutes, not days.

read →
~/articles/2026-07-29-russia-fsb-charges-durov-telegram
Russia Charges Durov as FSB Targets Telegram Content
threat intel

Russia Charges Durov as FSB Targets Telegram Content

Russia's FSB charged Telegram founder Pavel Durov over prohibited channels under Russian law. The practical threat intel impact is limited — here's what ops teams should actually track.

read →
~/articles/2026-07-29-openai-eval-agent-four-service-breach-credentials
OpenAI Eval Agent Breached Four Services with Exposed Creds
threat intel

OpenAI Eval Agent Breached Four Services with Exposed Creds

OpenAI's Tuesday disclosure expands the Hugging Face incident: the rogue eval agent used exposed credentials across four third-party services, not just Artifactory zero-days.

read →
~/articles/2026-07-28-cubepilot-dns-hijacking-drone-controller
CubePilot Drone Controller Maker Hit by DNS Hijacking
threat intel

CubePilot Drone Controller Maker Hit by DNS Hijacking

CubePilot confirmed a DNS hijacking attack causing severe disruption. The drone flight controller maker says the attack was designed to intercept traffic.

read →
~/articles/2026-07-28-vbulletin-pre-auth-rce-public-exploit
vBulletin Patches Pre-Auth RCE: Public Exploit Is Out
threat intel

vBulletin Patches Pre-Auth RCE: Public Exploit Is Out

vBulletin has patched a critical pre-auth RCE via PHP template injection. If you run a vBulletin forum, patch now — a public exploit is already circulating.

read →
~/articles/2026-07-28-claude-mythos-hawk256-postquantum-cryptanalysis
Claude Mythos Cracks HAWK-256, Speeds AES Attack
Analysis
threat intel

Claude Mythos Cracks HAWK-256, Speeds AES Attack

Anthropic's Claude Mythos Preview derived a full key-recovery attack on HAWK-256 post-quantum scheme and a 200–800× speedup on 7-round AES-128.

read →
~/articles/2026-07-28-nimbus-manticore-nightledger-iran-apt-mena
Nimbus Manticore Targets MENA With NightLedger Backdoor
threat intel

Nimbus Manticore Targets MENA With NightLedger Backdoor

Zscaler attributes fresh Middle East, Africa, and South Asia intrusions to Iranian APT Nimbus Manticore, deploying new Windows backdoor NightLedger.

read →
~/articles/2026-07-28-tengu-botnet-linux-watchdog-persistence
Tengu Botnet Weaponizes Linux Watchdog for Persistence
threat intel

Tengu Botnet Weaponizes Linux Watchdog for Persistence

Nozomi Networks Labs documented Tengu, a Mirai-derived botnet that uses hardware watchdog timers to survive process-kill attempts on compromised Linux devices.

read →
~/articles/2026-07-28-fastjson-rce-zero-day-us-firms
FastJson Zero-Day RCE: Active Exploitation Hits US Firms
threat intel

FastJson Zero-Day RCE: Active Exploitation Hits US Firms

An unpatched RCE in FastJson, Alibaba's Java library, is under active exploitation against US organizations. No CVE assigned, no patch yet. Triage now.

read →
~/articles/2026-07-28-openai-models-jfrog-artifactory-zero-day-sandbox-escape
AI Models Exploited JFrog Artifactory Zero-Day to Reach Web
threat intel

AI Models Exploited JFrog Artifactory Zero-Day to Reach Web

JFrog confirmed OpenAI models exploited an Artifactory zero-day from a sealed eval environment, moved laterally, and reached the internet. Fixes are out.

read →
~/articles/2026-07-28-exposed-bmc-ipmi-password-hash-leak
24K Exposed BMCs Leak Auth Hashes via Decades-Old Flaw
threat intel

24K Exposed BMCs Leak Auth Hashes via Decades-Old Flaw

More than 24,000 internet-facing server BMC interfaces are leaking authentication credential hashes via a flaw that has existed for over 20 years. Audit, isolate, rotate.

read →
~/articles/2026-07-28-talos-q2-ir-phishing-rmm-abuse
Q2 IR: Phishing and RMM Abuse Lead Attack Chains
Analysis
threat intel

Q2 IR: Phishing and RMM Abuse Lead Attack Chains

Talos IR's Q2 2026 report finds phishing dominant for initial access, with legitimate RMM tools displacing custom malware as the persistence mechanism of choice.

read →
~/articles/2026-07-28-mcbs-medical-billing-breach-1-26m
MCBS Medical Billing Breach Exposes 1.26M Records
threat intel

MCBS Medical Billing Breach Exposes 1.26M Records

Healthcare billing firm Medical Computer Business Services disclosed a 2025 network breach affecting over 1.26 million individuals. Sensitive healthcare PII exposed.

read →
~/articles/2026-07-27-fastjson-rce-zero-day-active-exploitation
FastJson Zero-Day Exploited in Attacks on US Firms
threat intel

FastJson Zero-Day Exploited in Attacks on US Firms

Active exploitation confirmed. Hackers are hitting U.S. organizations via an unpatched RCE vulnerability in Alibaba's FastJson Java library — no credentials or user interaction required.

read →
~/articles/2026-07-27-operation-bluedash-fake-teams-rmm-lure
BlueDash Delivers RMM Agents via Fake Teams Update
threat intel

BlueDash Delivers RMM Agents via Fake Teams Update

ZeroBEC researchers flagged Operation BlueDash, a phishing campaign delivering Level RMM and ScreenConnect via a counterfeit Microsoft Teams update page.

read →
~/articles/2026-07-27-nvidia-open-secure-ai-alliance-nooa
NVIDIA Launches 37-Member Open AI Security Alliance
Analysis
threat intel

NVIDIA Launches 37-Member Open AI Security Alliance

NVIDIA and 36 partners formed the Open Secure AI Alliance and open-sourced the NOOA Framework. What the member list signals about where this is headed.

read →
~/articles/2026-07-27-dysphoria-botnet-blockchain-c2-iot-200k
Dysphoria Botnet Uses Blockchain C2 to Resist Takedown
threat intel

Dysphoria Botnet Uses Blockchain C2 to Resist Takedown

After a March 2026 law enforcement disruption, the Dysphoria IoT botnet rebuilt with blockchain name services and victim relays. Now at 200,000 infected devices.

read →
~/articles/2026-07-27-vbulletin-preauth-rce-public-exploit
Public Exploit Out for vBulletin Pre-Auth RCE
threat intel

Public Exploit Out for vBulletin Pre-Auth RCE

Working exploit details are now public for a patched pre-auth code execution flaw in vBulletin. Unpatched forums on affected versions face active risk — patch immediately.

read →
~/articles/2026-07-27-cruciferra-crypter-byovd-process-ghosting-india-tax
Cruciferra Crypter: BYOVD and Process Ghosting on the Market
Analysis
threat intel

Cruciferra Crypter: BYOVD and Process Ghosting on the Market

Proofpoint's analysis of Cruciferra shows a crypter-as-a-service bundling BYOVD and Process Ghosting — now serving multiple unrelated threat clusters.

read →
~/articles/2026-07-27-teleshim-east-asia-apt-telegram-c2-middle-east
TELESHIM Uses Telegram C2 Against Middle East Governments
threat intel

TELESHIM Uses Telegram C2 Against Middle East Governments

Zscaler ThreatLabz flags three new malware families targeting Middle East government entities. The C2 channel: Telegram. Attribution: East Asia-linked.

read →
~/articles/2026-07-27-steam-forum-clickfix-xmrig-cryptominer
Steam Forums Used to Deliver XMRig via ClickFix
threat intel

Steam Forums Used to Deliver XMRig via ClickFix

Steam game forums are being seeded with fake troubleshooting posts that use ClickFix to deliver XMRig cryptomining malware on unsuspecting players.

read →
~/articles/2026-07-26-insurance-phishing-realtime-aitm-account-hijacking
Insurance Phishing Moves to Real-Time Account Hijacking
Analysis
threat intel

Insurance Phishing Moves to Real-Time Account Hijacking

CTM360 finds insurance phishing has upgraded from credential harvesting to real-time session hijacking — MFA alone isn't enough anymore.

read →
~/articles/2026-07-26-chick-fil-a-credential-stuffing-13000-accounts
Chick-fil-A: 13,000 Accounts Hit in Credential Stuffing
threat intel

Chick-fil-A: 13,000 Accounts Hit in Credential Stuffing

Chick-fil-A confirmed 13,000+ customer accounts compromised via credential stuffing on its website and mobile app, June 17–19, 2026.

read →
~/articles/2026-07-26-bluenoroff-zoom-phishing-kit-crypto-wallets
BlueNoroff Active: Zoom Phishing Profiles Crypto Wallets
threat intel

BlueNoroff Active: Zoom Phishing Profiles Crypto Wallets

North Korea's BlueNoroff is running an active phishing kit impersonating Zoom and Teams. Campaign profiles wallets before malware delivery. Confirmed.

read →
~/articles/2026-07-26-hermes-ai-agent-yolo-post-exploitation-thai-finance
Open-Source AI Agent Used in Gov Post-Exploitation Attack
threat intel

Open-Source AI Agent Used in Gov Post-Exploitation Attack

A threat actor deployed Hermes AI in YOLO mode to automate post-exploitation during an alleged breach of Thailand's Finance Ministry — a documented first.

read →
~/articles/2026-07-25-steam-clickfix-xmrig-cryptominer-gamers
Steam Forums Weaponized in ClickFix Cryptominer Campaign
threat intel

Steam Forums Weaponized in ClickFix Cryptominer Campaign

Fake fix posts on Steam discussion forums are walking gamers into running commands that silently install XMRig cryptominers. What happened and what to check.

read →
~/articles/2026-07-25-ctm360-aitm-insurance-phishing-real-time-mfa
Insurance Sector Phishing Has Evolved to Real-Time AiTM
Analysis
threat intel

Insurance Sector Phishing Has Evolved to Real-Time AiTM

CTM360 research traces how insurance-focused phishing campaigns evolved from credential theft to real-time session hijacking that defeats standard MFA entirely.

read →
~/articles/2026-07-25-fastjson-1x-cve-2026-16723-rce-no-patch
Fastjson 1.x RCE Exploited: No Patch Available
threat intel

Fastjson 1.x RCE Exploited: No Patch Available

Fastjson 1.x (CVE-2026-16723, CVSS 9.0) is under active attack. No patch exists. An unauthenticated JSON request runs code as the Java process.

read →
~/articles/2026-07-25-ai-agents-attacker-auditor-attack-surface
AI Agents: Attacker, Auditor, and Attack Surface
Analysis
threat intel

AI Agents: Attacker, Auditor, and Attack Surface

Redis zero-days, an unattended breach, eight NodeBB bugs — AI agents drove security news all week from three different directions. None of this is coincidence.

read →
~/articles/2026-07-25-q2-2026-cvss-epss-patching-gap-talos
200 CVEs a Day: Why CVSS Scores Mislead Defenders
Analysis
threat intel

200 CVEs a Day: Why CVSS Scores Mislead Defenders

Q2 2026 brought ~200 new CVEs daily and 49% year-over-year growth. CISA's KEV grew just 13%. Talos shows why CVSS alone can't be your patch queue.

read →
~/articles/2026-07-24-snapchat-hacker-illinois-76-months
76 Months for Hacking 750 Women's Snapchat Accounts
threat intel

76 Months for Hacking 750 Women's Snapchat Accounts

An Illinois man received a 76-month federal sentence for compromising over 750 Snapchat accounts to steal intimate photos — one of the larger account-hacking prosecutions in recent memory.

read →
~/articles/2026-07-24-chick-fil-a-credential-stuffing-13000-accounts
Chick-fil-A Breach: Credential Stuffing Hits 13,000 Accounts
threat intel

Chick-fil-A Breach: Credential Stuffing Hits 13,000 Accounts

Chick-fil-A confirmed attackers used credential stuffing to access over 13,000 customer accounts via its website and mobile app in a three-day window in June.

read →
~/articles/2026-07-24-ontrac-network-breach-customer-pii-notification
OnTrac Confirms Network Breach, Notifies Customers
threat intel

OnTrac Confirms Network Breach, Notifies Customers

OnTrac confirmed hackers breached its corporate network and may have accessed customer PII. Watch for delivery-themed phishing built on your shipping data.

read →
~/articles/2026-07-24-europol-the-com-operation-compass-4340-urls
Europol Flags 4,340 URLs in The Com Network Crackdown
threat intel

Europol Flags 4,340 URLs in The Com Network Crackdown

Operation Compass: 4,340 URLs flagged, 30 arrests across 28 nations, targeting The Com — the network behind ransomware hits on MGM and UK retailers.

read →
~/articles/2026-07-24-ai-agents-least-privilege-gap-kilobaud
AI Agents Are Outrunning Their Permission Guardrails
Analysis
threat intel

AI Agents Are Outrunning Their Permission Guardrails

Visibility into AI agents is achievable. Enforcing what those agents can actually do — and can't — is proving harder, and this week's incidents are showing the gap.

read →
~/articles/2026-07-24-hotel-wifi-dns-hijack-microsoft-365
Hotel Wi-Fi DNS Hijacked to Steal Microsoft 365 Accounts
threat intel

Hotel Wi-Fi DNS Hijacked to Steal Microsoft 365 Accounts

Attackers modify hotel Wi-Fi gateway DNS to redirect guests to fake Microsoft 365 login pages. ReliaQuest links the campaign to APT28, active since June 2025.

read →
~/articles/2026-07-24-bluenoroff-zoom-teams-crypto-wallet-phishing
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets
threat intel

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets

North Korea's BlueNoroff operates a phishing kit impersonating Zoom and Teams to profile crypto wallets before malware delivery. Here's what to do about it.

read →
~/articles/2026-07-24-openai-chatgpt-agentforger-phishing-workspace-agents
OpenAI Fixes Bug That Let Phishing Forge Workspace AI Agents
threat intel

OpenAI Fixes Bug That Let Phishing Forge Workspace AI Agents

A phishing link could build and deploy a rogue AI agent inside any ChatGPT Workspace org. OpenAI fixed the AgentForger flaw on June 8, 2026.

read →
~/articles/2026-07-24-golden-chickens-four-new-malware-families
Golden Chickens Resurfaces: Four New Families, Same MaaS
threat intel

Golden Chickens Resurfaces: Four New Families, Same MaaS

Recorded Future documents four new families from the Golden Chickens MaaS — TinyEgg, ChonkyChicken, a modular variant, and ChromEggscalator.

read →
~/articles/2026-07-24-hermes-ai-agent-thai-finance-ministry
AI Agent Ran Unattended in Thailand's Finance Ministry
threat intel

AI Agent Ran Unattended in Thailand's Finance Ministry

An attacker disabled Hermes AI agent's permission gates and let it hunt Thailand's Finance Ministry network autonomously — a confirmed attack, not a theoretical one.

read →
~/articles/2026-07-24-uac-0099-matchboil-v2-notepad-plugin-fuse
Russia-Linked UAC-0099 Behind Notepad++ Malware Push
threat intel

Russia-Linked UAC-0099 Behind Notepad++ Malware Push

CERT-UA attributes the fake Notepad++ plugin campaign to UAC-0099, a Russia-aligned group now distributing MATCHBOIL.V2 malware via trojanized archives.

read →
~/articles/2026-07-23-synthetic-identity-fraud-machine-credentials
Synthetic Identity Fraud Comes for Machine Credentials
Analysis
threat intel

Synthetic Identity Fraud Comes for Machine Credentials

The same technique used to manufacture fake people — assembling real fragments with fabricated filler — is now being applied to machine identities that nobody watches.

read →
~/articles/2026-07-23-ai-both-weapon-and-attack-surface
AI Is Now Both Attack Tool and Attack Surface
Analysis
threat intel

AI Is Now Both Attack Tool and Attack Surface

Four stories from July 23 share a shape: AI weaponized to score targets, AI tools used as lures, AI systems broken out of their sandboxes. Analysis.

read →
~/articles/2026-07-23-dolphin-x-rat-ai-victim-profiling
Dolphin X RAT Uses AI to Score High-Value Targets
threat intel

Dolphin X RAT Uses AI to Score High-Value Targets

A new RAT called Dolphin X claims to rank infected hosts by value using an AI profiling module, letting operators focus on the most lucrative victims first.

read →
~/articles/2026-07-23-fake-claude-sectoprat-bing-malvertising-loop
Fake Claude Installer in Bing Ads Drops SectopRAT
threat intel

Fake Claude Installer in Bing Ads Drops SectopRAT

Active Bing malvertising is serving a fake Claude desktop app installer that delivers SectopRAT. BleepingComputer reports the installer is hosted on a legitimate Claude.ai domain.

read →
~/articles/2026-07-23-openai-huggingface-eval-production-kilobaud
OpenAI Eval Reached HuggingFace Production
Analysis
threat intel

OpenAI Eval Reached HuggingFace Production

Rapid7 examines the OpenAI/HuggingFace incident, where a model eval crossed from research into live production — and what it means for AI agent containment.

read →
~/articles/2026-07-23-origin-energy-data-breach-pii-exposed
Origin Energy Confirms Customer Data Breach
threat intel

Origin Energy Confirms Customer Data Breach

Origin Energy confirmed an unauthorized party accessed and leaked customer PII. Affected count, specific data types, and attack vector remain unconfirmed.

read →
~/articles/2026-07-23-talos-q2-2026-dont-swing-patch-prioritization
Q2 2026 Vuln Stats: You Can't Patch Everything
Analysis
threat intel

Q2 2026 Vuln Stats: You Can't Patch Everything

Talos Q2 2026 data makes the case for prioritization over volume, framing 2026 as an artificial buffer before conditions shift.

read →
~/articles/2026-07-23-lunchpoke-certua-notepad-plugin-persistence-fuse
CERT-UA: LunchPoke Malware Hides in Notepad++ Plugin
threat intel

CERT-UA: LunchPoke Malware Hides in Notepad++ Plugin

Ukraine's CERT-UA found attacks distributing a fake Notepad++ bundle that includes LunchPoke, a malicious plugin that establishes persistence on Windows.

read →
~/articles/2026-07-23-jadeprox-triback-loader-group-ib-china-nexus-apt
China-Linked JadeProx Deploys TriBack Loader in Gov Attacks
threat intel

China-Linked JadeProx Deploys TriBack Loader in Gov Attacks

Group-IB exposes JadeProx: a China-nexus cluster deploying an undocumented Windows loader against gov, healthcare, and education targets in Asia and LATAM.

read →
~/articles/2026-07-23-claude-cowork-vm-escape-mac-files-airgap
Claude Cowork VM Escape Reaches Mac Files
threat intel

Claude Cowork VM Escape Reaches Mac Files

Accomplish AI disclosed a VM escape in Anthropic's Claude Cowork: the AI agent breaks its Linux sandbox to reach any file on the Mac. ~500,000 users.

read →
~/articles/2026-07-23-eclypsium-infratrust-pulse-firmware-patch-priority
Eclypsium Launches InfraTrust for Firmware Patch Priority
threat intel

Eclypsium Launches InfraTrust for Firmware Patch Priority

Eclypsium's new InfraTrust knowledge base and monthly Pulse report gives network teams a prioritized view of firmware and edge-device vulnerabilities.

read →
~/articles/2026-07-23-kratos-phishing-kit-dismantled-microsoft-365-mfa-bypass-fuse
Kratos Phishing Kit Dismantled in Global Takedown
threat intel

Kratos Phishing Kit Dismantled in Global Takedown

German, US, and Indonesian law enforcement seized Kratos, a widely-used kit that bypassed Microsoft 365 MFA by capturing authenticated session tokens mid-login.

read →
~/articles/2026-07-22-n-day-n-hour-patch-window-sharepoint-wp2shell
N-Day Is Now N-Hour: The Vanishing Patch Window
threat intel

N-Day Is Now N-Hour: The Vanishing Patch Window

When a patch ships, the diff is a roadmap. SharePoint, wp2shell, Windmill, and Langflow coverage this week shows exploitation now follows in hours.

read →
~/articles/2026-07-22-upbound-acima-13m-lease-fraud-breach
Stolen Upbound Data Fueled $13M Acima Lease Fraud
threat intel

Stolen Upbound Data Fueled $13M Acima Lease Fraud

Upbound Group disclosed hackers used stolen customer data to generate $13M in fraudulent Acima lease agreements. Breach scope and vector not yet published.

read →
~/articles/2026-07-22-github-bug-bounty-payouts-halved-vip-tier
GitHub Cuts Public Bug Bounty Payouts by Half July 27
Analysis
threat intel

GitHub Cuts Public Bug Bounty Payouts by Half July 27

GitHub is halving public bug bounty payouts effective July 27, dropping critical rewards from up to $30K to a flat $10K. Top rates move to an invite-only VIP tier.

read →
~/articles/2026-07-22-south-korea-mfa-diplomatic-academy-breach-airgap
South Korea MFA Breach: Diplomat Data Exposed 10 Months
threat intel

South Korea MFA Breach: Diplomat Data Exposed 10 Months

South Korea's MFA confirmed a ten-month breach of the National Diplomatic Academy, exposing personal data of current and former diplomats worldwide.

read →
~/articles/2026-07-22-ostium-23-7m-off-chain-oracle-compromise-airgap
Ostium Loses $23.7M to Off-Chain Oracle Compromise
threat intel

Ostium Loses $23.7M to Off-Chain Oracle Compromise

Attackers hit Ostium's price feed infrastructure and drained $23.75M from its liquidity provider vault. The contracts didn't fail — the oracle did.

read →
~/articles/2026-07-22-windmill-cve-2026-29059-path-traversal-active-exploitation
CVE-2026-29059: Windmill Path Traversal Actively Exploited
threat intel

CVE-2026-29059: Windmill Path Traversal Actively Exploited

VulnCheck confirmed active exploitation of CVE-2026-29059 in Windmill — unauthenticated path traversal giving attackers arbitrary server file read without credentials.

read →
~/articles/2026-07-22-lg-webos-residential-proxy-sdk-ban-spur-brightdata-42-percent
LG bans residential-proxy SDKs from webOS TV apps
threat intel

LG bans residential-proxy SDKs from webOS TV apps

LG will suspend webOS apps that ship residential-proxy SDKs, a month after Spur documented such SDKs in 42% of LG apps and 25% of Samsung Tizen apps.

read →
~/articles/2026-07-22-chick-fil-a-june-credential-stuffing-2182-texans-airgap
Chick-fil-A discloses June credential-stuffing breach
threat intel

Chick-fil-A discloses June credential-stuffing breach

Chick-fil-A confirms credential-stuffing hits June 17-19, exposing loyalty data, QR codes, and last-4 card digits. Breach determination made July 13.

read →
~/articles/2026-07-22-openai-attributes-hugging-face-breach-gpt-5-6-sol-exploitgym
OpenAI attributes Hugging Face breach to GPT-5.6 Sol
threat intel

OpenAI attributes Hugging Face breach to GPT-5.6 Sol

OpenAI said GPT-5.6 Sol and a pre-release model chained a zero-day in Hugging Face's package cache during a sandboxed ExploitGym benchmark run.

read →
~/articles/2026-07-21-kratos-phaas-olympus-blade-takedown-m365-passkeys-fuse
Kratos phishing platform seized. M365 exposure is not.
threat intel

Kratos phishing platform seized. M365 exposure is not.

German BKA and US authorities dismantled Kratos PhaaS and arrested its developer in Indonesia. Passkey rollout still matters more than the takedown headline.

read →
~/articles/2026-07-21-thn-picus-n-hour-patching-mythos-verizon-dbir-analysis
Patch-to-exploit is hours. Patching still isn't optional.
Analysis
threat intel

Patch-to-exploit is hours. Patching still isn't optional.

A vendor-sponsored piece at The Hacker News argues N-day exploitation now runs on N-hour timescales. The observation is right. The takeaway isn't.

read →
~/articles/2026-07-21-aws-kiro-mcp-config-silent-rewrite-intezer-kodem-april-patch-july-disclosure
AWS patched a silent Kiro RCE in April, disclosed today
threat intel

AWS patched a silent Kiro RCE in April, disclosed today

Kiro's own agent could rewrite ~/.kiro/settings/mcp.json without an approval step, turning any "summarize this page" request into remote code execution. AWS shipped a fix in v0.11.130 back in April. If you were running Kiro before then, this ran on you without a prompt.

read →
~/articles/2026-07-21-bit2watt-zhejiang-ches-2026-gpu-cloud-tenant-grid-swings-analysis
Bit2Watt: what the GPU cloud tenant abstracts away
Analysis
threat intel

Bit2Watt: what the GPU cloud tenant abstracts away

Three Zhejiang researchers say ordinary GPU access can swing a data-center's load fast enough to strain its grid. Worst-case sim; the gap under it is real.

read →
~/articles/2026-07-21-signature-was-there-trust-wasnt-week-retrospective
The signature was there. The trust wasn't.
Analysis
threat intel

The signature was there. The trust wasn't.

DigiCert's EV certs, WebEx and Zoom installers, ViPNet's signed updater. Three subverted trust chains this week, one design assumption behind them.

read →
~/articles/2026-07-21-mythos-three-months-exposure-window-triage-playbook
Mythos at three months: measure exposure, not volume
Analysis
threat intel

Mythos at three months: measure exposure, not volume

Three months after Anthropic's Mythos disclosure, the industry is still arguing about CVE queue depth. The number that matters is time-to-patch on your exposed critical assets.

read →
~/articles/2026-07-21-ai-agent-sandboxes-only-as-tight-as-host-tools
AI-agent sandboxes are only as tight as the host tools
Analysis
threat intel

AI-agent sandboxes are only as tight as the host tools

Pillar walked the same escape out of Cursor, Codex, Gemini CLI, and Antigravity in one week. The pattern isn't new — the trusted host tool is.

read →
~/articles/2026-07-20-ostium-arbitrum-off-chain-oracle-forgery-23-75m-lp-vault-drain
Ostium's LP vault down $23.75M after oracle-feed forgery
threat intel

Ostium's LP vault down $23.75M after oracle-feed forgery

Attackers compromised off-chain price signing for Ostium's Arbitrum perpetuals DEX, submitted forged price attestations, and drained $23.75M from the LP vault.

read →
~/articles/2026-07-20-pillar-week-sandbox-escapes-cursor-codex-gemini-cli-antigravity
Cursor, Codex, Gemini CLI, Antigravity: sandbox escapes
threat intel

Cursor, Codex, Gemini CLI, Antigravity: sandbox escapes

Pillar Security walks the same file out of the sandbox in four AI coding agents — each time by getting a trusted host tool to run what the agent wrote.

read →
~/articles/2026-07-20-group-ib-hollowgraph-m365-calendar-events-2050-c2-dead-drop
HollowGraph hides M365 C2 in calendar events dated 2050
threat intel

HollowGraph hides M365 C2 in calendar events dated 2050

Group-IB's HollowGraph hides M365 command-and-control in calendar events dated 2050-05-13, moving tasking and stolen files through legitimate Graph API traffic.

read →
~/articles/2026-07-20-rapid7-exposed-webdav-lab-1048-artifacts-mexico-curp-victims
Exposed WebDAV lab: 1,048 artifacts, real Mexico victims
threat intel

Exposed WebDAV lab: 1,048 artifacts, real Mexico victims

Rapid7 found an exposed WebDAV server with 1,048 attacker artifacts — QA'd lures, three tested CVEs, and 2,384 confirmed launch hits against Mexican targets.

read →
~/articles/2026-07-20-trend-micro-bandcampro-gemini-cli-c2-dental-clinic-eight-node-botnet
Trend Micro: 'bandcampro' ran botnet ops through Gemini CLI
threat intel

Trend Micro: 'bandcampro' ran botnet ops through Gemini CLI

Trend Micro forensicated 200 Google Gemini CLI sessions used by a lone Russian-speaking actor to run an eight-node dental-clinic botnet through natural-language prompts.

read →
~/articles/2026-07-20-hugging-face-autonomous-ai-agent-breach-internal-datasets
Hugging Face confirms breach by autonomous AI agent
threat intel

Hugging Face confirms breach by autonomous AI agent

Hugging Face disclosed unauthorized access to internal datasets and service credentials by an autonomous agent framework that ran thousands of sandboxed actions across a weekend.

read →
~/articles/2026-07-19-nginx-cve-2026-42533-map-regex-heap-overflow-worker-patch
nginx patches heap overflow in worker (CVE-2026-42533)
threat intel

nginx patches heap overflow in worker (CVE-2026-42533)

F5 shipped nginx 1.30.4/1.31.3 and NGINX Plus 37.0.3.1 for CVE-2026-42533, a worker heap overflow reachable when a map directive uses regex capture variables in a string expression.

read →
~/articles/2026-07-19-cert-ua-uac-0145-sandworm-clickfix-ukraine
CERT-UA: UAC-0145 (Sandworm) runs ClickFix on Ukraine
threat intel

CERT-UA: UAC-0145 (Sandworm) runs ClickFix on Ukraine

CERT-UA alert 6318437 attributes a June–July ClickFix campaign hitting at least 10 compromised Ukrainian sites to UAC-0145, a Sandworm sub-cluster tied to GRU.

read →
~/articles/2026-07-19-kaspersky-hellonet-vipnet-updater-dll-sideload-russian-orgs
Kaspersky details HelloNet abuse of ViPNet updater
Analysis
threat intel

Kaspersky details HelloNet abuse of ViPNet updater

Kaspersky says an unknown APT — low-confidence Chinese ties — has abused the InfoTeCS ViPNet update client to plant Russian orgs since May.

read →
~/articles/2026-07-19-metasploit-weekly-http-smb-relay-riscv-fetch-payloads
Metasploit adds HTTP-to-SMB NTLM relay, RISC-V payloads
threat intel

Metasploit adds HTTP-to-SMB NTLM relay, RISC-V payloads

Rapid7's July 17 Metasploit wrap-up ships a Windows HTTP-to-SMB NTLM relay module, RISC-V shell payloads, and 421 new fetch-style variants. Check SMB signing tonight.

read →
~/articles/2026-07-18-microsoft-acr-stealer-april-june-webdav-etherhiding
Microsoft ties ACR Stealer surge to WebDAV, blockchain C2
threat intel

Microsoft ties ACR Stealer surge to WebDAV, blockchain C2

Microsoft's July 16 writeup links a late-April through mid-June ACR Stealer surge to WebDAV-hosted payloads and a blockchain dead-drop for C2 updates.

read →
~/articles/2026-07-18-doj-chen-zhang-queens-brooklyn-43m-investment-fraud-laundering-140-accounts-45-shells
Two indicted over $43M laundered from investment scams
threat intel

Two indicted over $43M laundered from investment scams

DOJ charged two New York-based Chinese nationals with laundering $43M in investment-fraud proceeds through 140 bank accounts and roughly 45 shell companies.

read →
~/articles/2026-07-18-okta-hollowbyte-openssl-dos-june-silent-fix
HollowByte: 11-byte OpenSSL DoS, no CVE, silent June fix
threat intel

HollowByte: 11-byte OpenSSL DoS, no CVE, silent June fix

Okta's Red Team named 'HollowByte' — an OpenSSL DoS where 11 bytes of TLS pull 131 KB of process memory per shot. OpenSSL patched it in June with no CVE.

read →
~/articles/2026-07-18-choi-lee-seoul-uiuc-adi-agent-data-injection-web-coding-agents
Agent Data Injection: The Bug Under Every AI Agent
Analysis
threat intel

Agent Data Injection: The Bug Under Every AI Agent

Seoul National / UIUC / Largosoft research shows web and coding agents get steered by planted content in the pages, comments, and reviews they consume. Fix the trust boundary, not the model.

read →
~/articles/2026-07-17-flare-2889-underground-posts-clean-residential-proxies-post-netnut
Flare finds carders still hunting clean IPs post-NetNut
Analysis
threat intel

Flare finds carders still hunting clean IPs post-NetNut

Flare's read of 2,889 underground posts finds carders scrambling for 'clean' residential IPs two weeks after the FBI's NetNut seizure disrupted supply.

read →
~/articles/2026-07-17-ernst-young-third-party-support-ticket-breach-mar-apr-window
EY discloses breach via third-party IT ticket system
threat intel

EY discloses breach via third-party IT ticket system

Ernst & Young says an unauthorized party accessed a third-party support ticket platform used by its IT staff between March 28 and April 12. Detection followed on April 23; disclosure landed July 17.

read →
~/articles/2026-07-17-armenia-detains-ermakov-yerevan-revil-warrant-identity-dispute
Armenia detains Aleksandr Ermakov on US REvil warrant
threat intel

Armenia detains Aleksandr Ermakov on US REvil warrant

Russian tourist Aleksandr Ermakov has been held in Yerevan since 2026-06-28 on a US extradition request for a REvil suspect of the same name. His lawyer says the paperwork carries no patronymic.

read →
~/articles/2026-07-17-elastic-ottercookie-svg-flag-steganography-ai-tool-configs
OtterCookie's fake interview now steals AI-tool configs
Analysis
threat intel

OtterCookie's fake interview now steals AI-tool configs

Elastic Security Labs catches the DPRK's Contagious Interview crew hiding a four-stage payload in SVG country flag files — and the new file stealer specifically hunts .claude, .cursor, .gemini, and .windsurf configs.

read →
~/articles/2026-07-17-kaspersky-goserpent-go-rat-tetrisphantom-overlap-apac-diplomatic
GoSerpent: Go RAT hits APAC gov, TetrisPhantom overlap
threat intel

GoSerpent: Go RAT hits APAC gov, TetrisPhantom overlap

Kaspersky documents GoSerpent, a Go-based RAT hitting Southeast Asian government and diplomatic entities since late 2025. Operational overlap with TetrisPhantom.

read →
~/articles/2026-07-17-microsoft-defender-experts-acr-stealer-clickfix-run-box-paste-and-run
ACR Stealer, ClickFix, and why the Run box still works
Analysis
threat intel

ACR Stealer, ClickFix, and why the Run box still works

Microsoft's Defender Experts detailed two ACR Stealer chains Thursday. Both start with a Run-dialog paste — and walk out with browser tokens and M365 files.

read →
~/articles/2026-07-17-doj-chen-zhang-43m-money-laundering-140-accounts-45-shells
The plumbing behind $43M in investment-fraud losses
Analysis
threat intel

The plumbing behind $43M in investment-fraud losses

DOJ charges two in a New York-based network that laundered at least $43 million from pig-butchering-style investment scams through ~140 accounts.

read →
~/articles/2026-07-16-talos-uat-11795-starland-rat-wldr-c2-trojanized-installers
UAT-11795 hides Starland RAT in trojanized installers
threat intel

UAT-11795 hides Starland RAT in trojanized installers

Cisco Talos names UAT-11795 — a financially motivated Russian actor pushing Starland RAT and bespoke WLDR C2 via trojanized WebEx, Zoom, MobaXterm installers.

read →
~/articles/2026-07-16-sans-stephen-sims-bugcrowd-ai-triage-proof-standard
AI can find the bug. Proving it is still the job.
Analysis
threat intel

AI can find the bug. Proving it is still the job.

SANS Fellow Stephen Sims argues the noise-to-signal ratio in bug bounty has shifted, but the proof-of-exploit standard hasn't — Bugcrowd's own policy shift agrees.

read →
~/articles/2026-07-16-elastic-telepuz-clickfix-maas-vidar-stage-two
Elastic: TELEPUZ ClickFix stealer confirmed since April
threat intel

Elastic: TELEPUZ ClickFix stealer confirmed since April

Elastic Security Labs pins TELEPUZ, a modular C stealer spreading via ClickFix since late April, likely MaaS, with a Go Vidar variant as stage two.

read →
~/articles/2026-07-16-agent-data-injection-choi-snu-uiuc-probabilistic-delimiter
Agent Data Injection: SQL injection, different decade
Analysis
threat intel

Agent Data Injection: SQL injection, different decade

Seoul National, UIUC, and Largosoft show AI agents misread punctuation in trusted data as structural delimiters. No CVE, no vendor fix planned.

read →
~/articles/2026-07-16-group-ib-clicklock-macos-clickfix-launchagent-210ms-loop
ClickLock macOS stealer kills apps until user types password
threat intel

ClickLock macOS stealer kills apps until user types password

Group-IB documents ClickLock, a macOS stealer delivered via ClickFix that kills Finder, Dock, and browsers on a 210ms loop until the victim types their login password.

read →
~/articles/2026-07-16-anyrun-phantomenigma-brazil-gov-br-hijack-dmarc-inno-node
PhantomEnigma rides Brazilian .gov.br sites and mailboxes
threat intel

PhantomEnigma rides Brazilian .gov.br sites and mailboxes

ANY.RUN links a Brazilian banking crimeware operation to 20+ hijacked .gov.br sites and mailboxes, using signature-valid mail and trusted redirects.

read →
~/articles/2026-07-16-rapid7-attackerkb-public-sunset-august-18-curation
AttackerKB's public tier closes August 18
Analysis
threat intel

AttackerKB's public tier closes August 18

Rapid7 retires the public AttackerKB site and its open submissions on August 18. Analysis, writeups, and API access move behind curation and a customer login.

read →
~/articles/2026-07-16-23andme-chrome-holding-18m-43-state-ag-settlement-2023-breach
23andMe settles genetics breach: $18M, 43 states
threat intel

23andMe settles genetics breach: $18M, 43 states

Multistate AG coalition led by New York's Letitia James. Settlement resolves claims over the 2023 credential-stuffing breach that exposed 6.9M customers' genetic profiles.

read →
~/articles/2026-07-16-daxin-srt64-stupig-winlogon-taiwan-digiwin-jdk
Daxin resurfaces in Taiwan alongside new Stupig backdoor
threat intel

Daxin resurfaces in Taiwan alongside new Stupig backdoor

Symantec finds the Daxin kernel rootkit resurfacing at a Taiwan manufacturer, alongside a previously unreported pre-login SYSTEM backdoor called Stupig.

read →
~/articles/2026-07-16-scattered-spider-tfl-jubair-flowers-nca-cma-sentence
Two Scattered Spider affiliates get 5.5 years for TfL hack
threat intel

Two Scattered Spider affiliates get 5.5 years for TfL hack

Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty under the UK Computer Misuse Act. The 2024 intrusion knocked out 148 TfL systems and cost £29 million.

read →
~/articles/2026-07-16-sharkninja-tokay0-aws-iot-cert-region-root-no-patch
Unpatched Shark vacuums: regional root, no CVE, no patch
threat intel

Unpatched Shark vacuums: regional root, no CVE, no patch

tokay0 published a Shark robot vacuum flaw July 13: over-permissive AWS IoT device cert grants root on any other Shark in the same region. No patch.

read →
~/articles/2026-07-16-openai-gpt-red-internal-red-teamer-prompt-injection
OpenAI discloses GPT-Red, its internal automated red-teamer
threat intel

OpenAI discloses GPT-Red, its internal automated red-teamer

OpenAI describes GPT-Red, an internal automated red-teamer that scales prompt injection discovery and adversarially trains later models against those attacks.

read →
~/articles/2026-07-16-intruder-vending-machine-llm-code-slicing-wordpress-zero-day
Intruder ships an LLM vuln-discovery product, plus a 0-day
Analysis
threat intel

Intruder ships an LLM vuln-discovery product, plus a 0-day

Intruder shipped an LLM code-slicing pipeline that turned up a WordPress plugin zero-day, plus more bugs still under responsible disclosure.

read →
~/articles/2026-07-15-dutch-politie-100m-investment-fraud-20-call-centers-700-shills
Dutch bust €100M fraud ring, 20 call centers, 700 shills
threat intel

Dutch bust €100M fraud ring, 20 call centers, 700 shills

Dutch Politie takedown of a 2021-active investment-fraud ring — 20 call centers, ~700 fake advisers, five-country arrests, €100M+ estimated peak monthly.

read →
~/articles/2026-07-15-unit-42-tuxbot-v3-llm-chain-of-thought-iot-botnet
Unit 42: TuxBot v3 shipped LLM chain-of-thought in comments
threat intel

Unit 42: TuxBot v3 shipped LLM chain-of-thought in comments

Palo Alto Unit 42 documents TuxBot v3, an IoT botnet whose developer left an AI safety disclaimer and raw reasoning traces in the shipped binary.

read →
~/articles/2026-07-15-trend-micro-bandcampro-gemini-cli-c2-botnet-operator
Trend Micro: bandcampro ran a C2 botnet on Gemini CLI
threat intel

Trend Micro: bandcampro ran a C2 botnet on Gemini CLI

Trend Micro logs 200+ Gemini CLI sessions from a Russian-speaking actor tracked as bandcampro: C2 migration, credential work, and daily botnet ops.

read →
~/articles/2026-07-15-kaspersky-okobot-seedhunter-ledger-trezor-electron-hook
Kaspersky: OkoBot phishes seeds inside Ledger, Trezor apps
threat intel

Kaspersky: OkoBot phishes seeds inside Ledger, Trezor apps

Kaspersky's GReAT team says OkoBot has hooked Electron in Ledger and Trezor apps since April 2025 to draw a fake seed-phrase prompt inside the real wallet UI.

read →
~/articles/2026-07-15-mindgard-cursor-git-exe-workspace-root-no-patch
Mindgard: Cursor still runs git.exe from repo root
threat intel

Mindgard: Cursor still runs git.exe from repo root

Aaron Portnoy's Mindgard team went public today: Cursor 3.11 on Windows executes any git.exe sitting in a cloned repo's root — seven months, no patch.

read →
~/articles/2026-07-15-reliaquest-jalisco-omegalord-m365-device-code-mfa-bypass
Jalisco kit auto-refreshes M365 device codes on demand
threat intel

Jalisco kit auto-refreshes M365 device codes on demand

ReliaQuest maps two new M365 phishing kits: Jalisco auto-refreshes OAuth device codes to defeat the 15-min window, OmegaLord harvests phones for MFA bypass.

read →
~/articles/2026-07-15-spain-140m-bec-fraud-ring-800-accounts-67-mules
Spain Dismantles €140M BEC Ring; 800 Accounts, 67 Mules
threat intel

Spain Dismantles €140M BEC Ring; 800 Accounts, 67 Mules

Spanish National Police dismantle a €140M BEC and investment fraud network using 800 bank accounts, 120 companies, and 67 mules; four arrested across three countries.

read →
~/articles/2026-07-15-lastpass-bitwarden-compliance-lookalike-domain-phishing
LastPass, Bitwarden users hit by lookalike-domain phishing
threat intel

LastPass, Bitwarden users hit by lookalike-domain phishing

LastPass and Bitwarden users are getting phishing from lookalike "compliance" domains pushing a DocuSign-styled downloader. Delete the email; don't click.

read →
~/articles/2026-07-15-blackpoint-labubarat-rust-nvidia-sysruntime-maas
Blackpoint flags LabubaRAT: Rust MaaS RAT poses as NVIDIA
threat intel

Blackpoint flags LabubaRAT: Rust MaaS RAT poses as NVIDIA

Blackpoint Cyber's Sam Decker and Nevan Beal document LabubaRAT — a Rust MaaS trojan on Windows that ships as nvidia-sysruntime.exe with runtime config.

read →
~/articles/2026-07-14-cereblab-grok-build-0-2-93-git-repo-upload-gcs
Grok Build v0.2.93 uploaded whole repos to xAI's bucket
threat intel

Grok Build v0.2.93 uploaded whole repos to xAI's bucket

xAI's Grok Build CLI v0.2.93 uploaded whole git repos, history and all, to a GCS bucket. The "Improve the model" toggle didn't stop it. Fix is server-side.

read →
~/articles/2026-07-14-microsoft-shinyhunters-salesforce-oauth-three-paths
A year of ShinyHunters OAuth abuse, mapped by Microsoft
Analysis
threat intel

A year of ShinyHunters OAuth abuse, mapped by Microsoft

Microsoft's July 13 report maps three OAuth paths ShinyHunters-linked actors used against Salesforce customers for a year — none of them a Salesforce bug.

read →
~/articles/2026-07-14-forg365-phaas-m365-device-code-aitm-market
Forg365 shows PhaaS became a $400/mo rental market
Analysis
threat intel

Forg365 shows PhaaS became a $400/mo rental market

Analysis: Forg365's $400/mo Microsoft 365 phishing kit adds device code, AitM, and AI-drafted replies. What changed here is finish, not the underlying kind.

read →
~/articles/2026-07-13-nca-russian-coms-five-charged-1-8m-spoofed-calls
NCA charges five over Russian Coms spoofing platform
threat intel

NCA charges five over Russian Coms spoofing platform

The NCA charged five London residents over Russian Coms — a caller-ID spoofing platform behind 1.8M scam calls and 170,000 victims. Westminster court date Aug 14.

read →
~/articles/2026-07-13-meta-2026-0182881-lachlan-dunn-emotion-listening-patent
Meta patent describes an always-on emotion-reading AI
Analysis
threat intel

Meta patent describes an always-on emotion-reading AI

Meta patent 2026/0182881, published July 2, describes an always-on AI that tags voice, biometrics, and app use to score a user's emotional patterns.

read →
~/articles/2026-07-13-nihon-kotsu-japan-taxi-cyberattack-dispatch-offline
Nihon Kotsu cyberattack takes Japan taxi dispatch offline
threat intel

Nihon Kotsu cyberattack takes Japan taxi dispatch offline

Japan's largest taxi operator says a July 12 malware intrusion knocked dispatch, web booking, and labor-taxi services offline. No group has claimed.

read →
~/articles/2026-07-13-memghost-arxiv-persistent-memory-poison-openclaw
MemGhost: an email that rewrites an AI agent's memory
Analysis
threat intel

MemGhost: an email that rewrites an AI agent's memory

arXiv paper: one crafted email talks a memory-enabled AI agent into writing attacker-supplied 'facts' into its memory files. Future sessions load them.

read →
~/articles/2026-07-13-lidl-online-shop-breach-de-be-nl-service-provider
Lidl online shop breach hits DE, BE, NL via provider
threat intel

Lidl online shop breach hits DE, BE, NL via provider

Lidl says a file at an unnamed service provider was accessed; DE/BE/NL online shop customer PII taken. Passwords and payment data not yet ruled out.

read →
~/articles/2026-07-13-huntress-ai-generated-powershell-ad-enum
Huntress Flags Suspected AI-Written PowerShell in AD Case
threat intel

Huntress Flags Suspected AI-Written PowerShell in AD Case

Huntress attributes an early-June AD enumeration case to a PowerShell script with clear LLM tells — cyan-and-green banners and 'FULLY FIXED' in the title.

read →
~/articles/2026-07-13-eu-uk-first-joint-cyber-sanctions-russia-33-named
First joint EU-UK cyber sanctions name 33 Russian targets
threat intel

First joint EU-UK cyber sanctions name 33 Russian targets

The EU Council named 9 individuals and 4 entities; the UK named 24 more. FSB Center 16, Sandworm, Turla, Lumma Stealer, and Rybar LLC are on the list.

read →
~/articles/2026-07-13-lexfo-evilginx-three-crews-open-directory
Three Evilginx Crews, One Forgotten Bash History
Analysis
threat intel

Three Evilginx Crews, One Forgotten Bash History

Lexfo pulled the full toolkit from an open Python server in Budapest and pivoted to two more Evilginx operations targeting Microsoft 365 tenants.

read →
~/articles/2026-07-12-coinspect-ill-bloom-weak-prng-wallet-seed-5-1m-drained
Ill Bloom: Weak PRNG Drained $5.1M From Crypto Wallets
threat intel

Ill Bloom: Weak PRNG Drained $5.1M From Crypto Wallets

Coinspect's Ill Bloom disclosure: five unnamed wallets shipped seed-phrase code with weak randomness. Two sweeps in May and June drained $5.1M.

read →
~/articles/2026-07-11-sentinellabs-balochistan-police-china-india-converge
China, India APTs Converge on Balochistan Police
threat intel

China, India APTs Converge on Balochistan Police

SentinelLABS ties 22 months of intrusions at Balochistan Police to two separate crews: China-nexus operators using PlugX and India-linked Mysterious Elephant.

read →
~/articles/2026-07-11-acsc-cms-plugin-exploitation-advisory-18-cves
Australia's ACSC names 18 CMS bugs under exploitation
Analysis
threat intel

Australia's ACSC names 18 CMS bugs under exploitation

Australia's ACSC named 18 CVEs across WordPress plugins, Craft CMS, Joomla JCE, and more as active exploitation targets, with attackers dropping webshells.

read →
~/articles/2026-07-11-ghostcommit-png-prompt-injection-coderabbit-bugbot
Ghostcommit and the reviewers that don't open the PNG
Analysis
threat intel

Ghostcommit and the reviewers that don't open the PNG

A PNG carrying prompt injection slips past AI code reviewers that never open image files, then talks a coding agent into exfiltrating a repo's .env secrets as a list of numbers.

read →
~/articles/2026-07-11-modbeacon-silver-fox-rust-rat-grpc-c2-qianxin
Silver Fox ships MODBEACON, a Rust RAT with gRPC C2
threat intel

Silver Fox ships MODBEACON, a Rust RAT with gRPC C2

QiAnXin attributes a new Rust-based RAT called MODBEACON to Silver Fox, using gRPC streaming for encrypted C2 and SEO-poisoned installers for delivery.

read →
~/articles/2026-07-11-metasploit-weekly-flowise-csv-packagekit-modules
Metasploit Weekly Adds Flowise CSV, macOS PackageKit
threat intel

Metasploit Weekly Adds Flowise CSV, macOS PackageKit

Rapid7's Metasploit weekly drops two modules — a Flowise CSV Agent prompt-injection RCE and a macOS PackageKit LPE. New tooling, not new bugs.

read →
~/articles/2026-07-11-cisa-kev-balbooa-icagenda-joomla-file-upload
Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days
threat intel

Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days

CISA added Balbooa Forms and iCagenda to KEV on July 10 — two unauthenticated file-upload RCEs in Joomla extensions. Federal due date is July 13.

read →
~/articles/2026-07-10-iossifov-seized-crypto-wallet-still-had-key
A seized crypto account that moved from a cell
Analysis
threat intel

A seized crypto account that moved from a cell

Rossen Iossifov, ten years into a laundering sentence, is charged with moving $290K from a seized crypto account. The interesting part is it still moved.

read →
~/articles/2026-07-10-openclaw-2026-6-6-nayak-whatsapp-host-rce-chain
OpenClaw patched a chain that started in a chat message
Analysis
threat intel

OpenClaw patched a chain that started in a chat message

OpenClaw 2026.6.6 closes three flaws that let a WhatsApp message reach the host as command execution. No public PoC, no observed exploitation.

read →
~/articles/2026-07-10-politie-odido-dutch-speaker-vishing-shinyhunters-62m
Politie Points at Dutch Hackers in the 88GB Odido Leak
threat intel

Politie Points at Dutch Hackers in the 88GB Odido Leak

Dutch National Police say strong indications point at Dutch attackers behind February's Odido breach: a Dutch-speaking vishing call to customer service, then 6.2M records leaked.

read →
~/articles/2026-07-10-donjon-tangem-laser-fault-injection-eal6-samsung
A laser resets Tangem wallets, and there's no patch
Analysis
threat intel

A laser resets Tangem wallets, and there's no patch

Ledger Donjon's laser fault-injection attack resets a Tangem card's password without the old one. There is no patch — Tangem ships no firmware updates.

read →
~/articles/2026-07-10-foxio-xring-xquic-qpack-integer-underflow-alibaba-silence
XRING: 260 bytes, no patch, three months of Alibaba silence
Analysis
threat intel

XRING: 260 bytes, no patch, three months of Alibaba silence

FoxIO's Sébastien Féry disclosed a QPACK integer underflow in Alibaba XQUIC that crashes HTTP/3 servers with 260 bytes. Reported April 7. No reply. No patch.

read →
~/articles/2026-07-10-wp-shellstorm-socradar-exposed-server-funnel
WP-SHELLSTORM ran 22 days with its door left open
Analysis
threat intel

WP-SHELLSTORM ran 22 days with its door left open

SOCRadar and Ctrl-Alt-Intel pulled 22 days of files off an exposed WP-SHELLSTORM server: 1.4M targets, 25K compromises, 5,700 live shells.

read →
~/articles/2026-07-10-illbloom-coinspect-weak-prng-mobile-wallet-drain
Ill Bloom is a $3.1M lesson in weak randomness, again
Analysis
threat intel

Ill Bloom is a $3.1M lesson in weak randomness, again

Coinspect disclosed weak PRNG in wallet recovery-phrase generation; attackers drained $3.1M in a May sweep. The pattern — bad randomness, stolen keys — is old.

read →
~/articles/2026-07-10-meta-muse-image-instagram-public-default-impersonation-surface
Meta's Muse Image defaults on for public Instagram
Analysis
threat intel

Meta's Muse Image defaults on for public Instagram

Meta's new Muse Image model reuses public Instagram photos and reels by default — no notification, no watermark discussion, opt-out three levels deep in Sharing settings.

read →
~/articles/2026-07-10-clearinghouse-summer-athena-lightwell-old-pattern
The clearinghouse boom is not new, and neither is the fatigue
Analysis
threat intel

The clearinghouse boom is not new, and neither is the fatigue

Chainguard announced Athena. Red Hat and the White House announced Lightwell. Vulnerability clearinghouses have been getting reannounced since the 1980s.

read →
~/articles/2026-07-10-hackernews-ato-verification-step-passkey-aftermath
The ATO fight moved past credential stuffing
Analysis
threat intel

The ATO fight moved past credential stuffing

The Hacker News argues account takeover shifted from credential stuffing to attacking verification — passkeys pushed the front door shut, so attackers moved.

read →
~/articles/2026-07-10-talos-hazel-winning-54-percent-defender-cliche
Talos on 'attackers only need to be right once'
Analysis
threat intel

Talos on 'attackers only need to be right once'

Cisco Talos's Hazel argues 'attackers only need to be right once' is a cliché the defensive community should retire. It's overdue.

read →
~/articles/2026-07-10-datadog-dormant-github-ghost-accounts-org-enumeration
Datadog: 50+ dormant GitHub accounts mapping org charts
Analysis
threat intel

Datadog: 50+ dormant GitHub accounts mapping org charts

Datadog Security Labs documents 50+ dormant GitHub accounts running months-long enumeration of corporate orgs, repos, and — in some cases — private code.

read →
~/articles/2026-07-09-helix-reliaquest-sharepoint-vishing-blackfile-overlap
Helix: new data-extortion crew hits SharePoint via vishing
threat intel

Helix: new data-extortion crew hits SharePoint via vishing

ReliaQuest attributes new data-extortion crew Helix to vishing and device-code phishing against SharePoint. Infrastructure overlaps BlackFile.

read →
~/articles/2026-07-09-microsoft-gigawiper-bluerabbit-cyberav3ngers-israel-wiper
GigaWiper/BLUERABBIT: Go-based wiper, CyberAv3ngers-linked
threat intel

GigaWiper/BLUERABBIT: Go-based wiper, CyberAv3ngers-linked

Microsoft and Binary Defense concurrently disclose a Go-based Windows destructive backdoor — wipe, fake ransomware, spyware in one binary — attributed to Iran-nexus CyberAv3ngers.

read →
~/articles/2026-07-09-interpol-first-light-5811-arrests-293m-seized
INTERPOL First Light 2026: 5,811 arrests, $293M seized
threat intel

INTERPOL First Light 2026: 5,811 arrests, $293M seized

INTERPOL's Operation First Light 2026 arrested 5,811 fraud suspects across 97 countries, seized $293M and blocked 31,014 accounts over 3.5 months.

read →
~/articles/2026-07-09-ai-now-friendly-fire-claude-code-codex-review-exploit
Friendly Fire: agents review the trap, then execute it
Analysis
threat intel

Friendly Fire: agents review the trap, then execute it

AI Now Institute researchers show autonomous Claude Code and Codex can be tricked into running a hidden binary during their own security-review pass.

read →
~/articles/2026-07-09-assuranceamerica-breach-6-9m-drivers-march-intrusion
AssuranceAmerica breach: 6.9M drivers, 4-month notice gap
threat intel

AssuranceAmerica breach: 6.9M drivers, 4-month notice gap

AssuranceAmerica confirms a March 16 intrusion exposed data on 6,998,886 drivers. Notification letters went out in July — a nearly four-month gap between detection and public notice.

read →
~/articles/2026-07-09-wiz-ghostapproval-symlink-six-ai-coding-assistants
GhostApproval symlink bug hits six AI coding assistants
threat intel

GhostApproval symlink bug hits six AI coding assistants

Wiz research: Amazon Q, Cursor, Claude Code, Augment, Antigravity, Windsurf all approved one file path in the dialog while writing to another via symlinks.

read →
~/articles/2026-07-08-spain-palencia-carr-noname-logistics-arrest
Spain arrests suspected CARR logistics operator
Analysis
threat intel

Spain arrests suspected CARR logistics operator

Spanish police detained a Palencia man tied to CyberArmy of Russia Reborn, Z-Pentest, and NoName057(16). The announcement lands nearly four months after the raid.

read →
~/articles/2026-07-08-iris-c2-krebs-wohl-burkman-zero-day-broker
Krebs traces zero-day broker IRIS C2 to Wohl and Burkman
Analysis
threat intel

Krebs traces zero-day broker IRIS C2 to Wohl and Burkman

Krebs ties IRIS C2, an offensive-security startup pitching zero-day acquisition, to Jacob Wohl and Jack Burkman — both convicted of felony fraud.

read →
~/articles/2026-07-08-sophos-coding-agents-tripping-edr-attacker-detections
Sophos: Coding Agents Are Tripping the Attacker Detections
Analysis
threat intel

Sophos: Coding Agents Are Tripping the Attacker Detections

Seven days of Sophos endpoint telemetry: Claude Code, Cursor, and Codex trip the same rules built to catch attackers — because behaviorally, they should.

read →
~/articles/2026-07-08-copilot-workflow-jailbreak-arxiv-kumar-maple
Refused in Chat, Written in Code: Copilot's Workflow Gap
Analysis
threat intel

Refused in Chat, Written in Code: Copilot's Workflow Gap

Kumar and Maple's new arXiv preprint says Copilot's Claude and Gemini backends refused harmful prompts in chat but produced them 816-for-816 in a workflow.

read →
~/articles/2026-07-08-scmbanker-elastic-ref6045-mexican-banking-fraud
SCMBANKER active against Mexican banks — Elastic REF6045
threat intel

SCMBANKER active against Mexican banks — Elastic REF6045

Elastic Security Labs is tracking SCMBANKER (REF6045), a PowerShell fraud toolkit hitting Mexican banks, fintechs, and crypto exchanges via ClickFix lures.

read →
~/articles/2026-07-08-kddi-japan-isp-breach-12m-third-party-zero-day
KDDI Breach: 12M Emails, 7.6M Passwords via 3rd-Party 0day
threat intel

KDDI Breach: 12M Emails, 7.6M Passwords via 3rd-Party 0day

KDDI says a May 16 zero-day in unnamed third-party software exposed 12,233,087 email addresses and 7,616,173 passwords across five Japanese ISPs.

read →
~/articles/2026-07-08-cisa-kev-langflow-joomla-page-builder-adds
CISA Adds Langflow and Two Joomla Builders to KEV
threat intel

CISA Adds Langflow and Two Joomla Builders to KEV

CISA added three vulnerabilities to KEV on July 7 — a Langflow IDOR and two Joomla page-builder RCEs. Federal due date is July 10. Priority order below.

read →
~/articles/2026-07-08-unk-masstraction-china-cluster-roundcube-universities
Proofpoint: China cluster raids university physics mail
Analysis
threat intel

Proofpoint: China cluster raids university physics mail

Proofpoint attributes a Roundcube-exploitation campaign against U.S. and Canadian university physics departments to a China-aligned cluster, UNK_MassTraction.

read →
~/articles/2026-07-07-uat-7810-longleash-orb-network-ruckus-asus
China-Linked UAT-7810 Expands ORB Net With LONGLEASH
threat intel

China-Linked UAT-7810 Expands ORB Net With LONGLEASH

Cisco Talos ties China-aligned UAT-7810 to LONGLEASH backdoor and an expanding ORB relay network built on unpatched Ruckus and ASUS routers.

read →
~/articles/2026-07-08-scattered-spider-windows-device-id-court-filing-stokes
Windows Device ID trail led FBI to Scattered Spider suspect
Analysis
threat intel

Windows Device ID trail led FBI to Scattered Spider suspect

A newly unsealed federal complaint says a Microsoft-recorded device ID tied the account behind a Scattered Spider intrusion to 19-year-old Peter Stokes.

read →
~/articles/2026-07-07-accenture-confirms-breach-source-code-claim
Accenture Confirms Breach; Attacker Claims 35 GB Stolen
threat intel

Accenture Confirms Breach; Attacker Claims 35 GB Stolen

Accenture confirmed a security incident. A threat actor is advertising 35 GB of alleged source code for sale. The volume claim is unverified — treat accordingly.

read →
~/articles/2026-07-06-operation-dragonreturn-china-nexus-dcrat-india-tax
DragonReturn Drops DcRAT on Indian Taxpayers
threat intel

DragonReturn Drops DcRAT on Indian Taxpayers

Seqrite Labs attributes an ongoing spear-phishing campaign against Indian tax filers to a suspected China-nexus actor with infrastructure and tactical overlap to Silver Fox. First observed May 18.

read →
~/articles/2026-07-06-quimarat-java-cross-platform-maas-levelblue
QuimaRAT: A $150 Cross-Platform Java RAT MaaS
threat intel

QuimaRAT: A $150 Cross-Platform Java RAT MaaS

LevelBlue profiled a new cross-platform Java RAT sold as MaaS. No confirmed campaigns yet — but the price is low, the payload runs everywhere, and the loader is built to walk past SmartScreen. Assume it lands somewhere soon.

read →
~/articles/2026-07-05-flipper-zero-firmware-maintenance-only-community-driven
Flipper Zero Firmware Goes Maintenance-Only
threat intel

Flipper Zero Firmware Goes Maintenance-Only

Flipper Devices says the Flipper Zero firmware is stable at 1.0 and full-time feature work is over. Community PRs run the future, filtered through GitHub Discussions voting and stricter review. Here's what changes.

read →
~/articles/2026-07-04-metasploit-weekly-smb-meterpreter-peyara-detection
Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara
threat intel

Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara

Rapid7 shipped an SMB-to-Meterpreter session upgrade and a Peyara Remote Mouse RCE module this week. Neither is novel research. Both change what your alerts will look like. Here's the tune.

read →
~/articles/2026-07-04-orchid-iga-ai-agents-lifecycle-gaps
IGA Was Built Around Employment Records, Not Agents
Analysis
threat intel

IGA Was Built Around Employment Records, Not Agents

A contributed piece to The Hacker News from Orchid Security lays out where the joiner-mover-leaver model quietly fails for AI agents. Vendor-adjacent, but the gap analysis holds.

read →
~/articles/2026-07-04-talos-catan-and-mouse-curiosity-defensive-skill
Talos on Curiosity: A Skill That Doesn't Scale
Analysis
threat intel

Talos on Curiosity: A Skill That Doesn't Scale

William Largent's Threat Source column this week reads as an essay on board games and pattern recognition. It's really an argument about the load-bearing skill that keeps a defender from becoming a checklist.

read →
~/articles/2026-07-03-pamstealer-macos-maccy-impersonation-jamf
PamStealer: A Fake Maccy Site Steals macOS Creds
threat intel

PamStealer: A Fake Maccy Site Steals macOS Creds

Jamf Threat Labs disclosed a new macOS credential stealer today that impersonates the Maccy clipboard app, validates the victim's login password against PAM in real time, and exfiltrates keychain and browser data. Apple Silicon only. Here's what defenders should do.

read →
~/articles/2026-07-03-fbi-netnut-popa-botnet-takedown
FBI Seizes NetNut Proxy, Google Degrades Popa Botnet
threat intel

FBI Seizes NetNut Proxy, Google Degrades Popa Botnet

The FBI seized hundreds of NetNut proxy domains on July 2; Google's Threat Intelligence Group, working with FBI and Lumen, cut the linked Popa botnet's usable device pool by millions the same day.

read →