threat-intel Exploits and vulnerabilities in Q1 2026 This Securelist report analyzes vulnerability trends and exploitation activity during Q1 2026, focusing on the expansion of exploit kits targeting Microsoft Office, Windows, and Linux operating systems. The report highli… Securelist · May 7, 2026 High CVE-2018-0802CVE-2017-11882CVE-2017-0199USvulnerabilityexploitationrce
malware Fake call logs, real payments: How CallPhantom tricks Android users This report details a widespread Android scam, dubbed CallPhantom, where fraudulent apps masquerading as call log retrieval services tricked users into paying for randomly generated data. Twenty-eight apps, collectively… WeLiveSecurity · May 7, 2026 Medium INscamfraudandroid
threat-intel Smashing Security podcast #466: Meta sees everything, Copy Fail, and a deepfake gets hired This Smashing Security podcast episode discusses ongoing cybersecurity challenges, including the persistent issues of AI-related bugs, social engineering attacks, and the dangers of deepfakes. A key topic is Meta’s smart… Graham Cluley · May 6, 2026 Medium UKaiprivacydeepfake
threat-intel Insights into the clustering and reuse of phone numbers in scam emails This article details Cisco Talos’s intelligence gathering on the increasing use of phone numbers in scam email campaigns. Attackers are leveraging API-driven VoIP providers like Sinch and Twilio to operate high-volume, d… Cisco Talos · May 6, 2026 High USUKvoipscamphishing
vulnerability Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years A critical Linux kernel vulnerability, dubbed 'Copy Fail' (CVE-2026-31431), has been discovered allowing unprivileged local attackers to escalate their access to root across numerous Linux distributions since 2017. The f… Palo Alto Unit 42 · May 5, 2026 Critical CVE-2026-31431CVE-2026-314331USlinuxkernellpe
threat-intel CloudZ RAT potentially steals OTP messages using Pheno plugin Cisco Talos identified an intrusion campaign initiated in January 2026 involving the deployment of the CloudZ remote access tool (RAT) alongside a new plugin called ‘Pheno.’ This campaign leveraged the Microsoft Phone Li… Cisco Talos · May 5, 2026 High USotpphone linkcredential theft
phishing “Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security This Securelist article details a concerning trend of attackers leveraging Amazon Simple Email Service (Amazon SES) for phishing campaigns. Attackers exploit legitimate access keys to send convincing emails that bypass s… Securelist · May 4, 2026 High USphishingawsamazon ses
threat-intel Essential Data Sources for Detection Beyond the Endpoint This Unit 42 report highlights the increasing speed of cyberattacks and the limitations of relying solely on endpoint detection and response (EDR) solutions. Attackers are now moving four times faster to exfiltrate data,… Palo Alto Unit 42 · May 1, 2026 High cloud securityendpoint detectionthreat intelligence
threat-intel That AI Extension Helping You Write Emails? It’s Reading Them First Palo Alto Unit 42 has identified 18 AI-powered browser extensions posing significant security risks. These extensions, masquerading as productivity tools, are actually delivering malicious payloads such as remote access… Palo Alto Unit 42 · Apr 30, 2026 High USaibrowser extensionsgenai
threat-intel Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber This article reports on Anthropic’s release of Claude, dubbed ‘Mythos,’ an AI model capable of rapidly identifying and exploiting software vulnerabilities, including zero-day bugs, across major operating systems and web… Dark Reading · Apr 30, 2026 High aivulnerabilitycybersecurity
threat-intel Great responsibility, without great power This article from Cisco Talos discusses the importance of empathy and understanding in cybersecurity, particularly in recognizing and responding to attacker behavior. It highlights five critical priorities for defenders… Cisco Talos · Apr 30, 2026 High CVE-2026-42208identityanomalythreat-hunting
threat-intel Anti-DDoS Firm Heaped Attacks on Brazilian ISPs A Brazilian DDoS protection firm, Huge Networks, was found to be running a botnet that launched massive DDoS attacks against Brazilian ISPs. This activity stemmed from a security breach in January 2026 that compromised t… Krebs on Security · Apr 30, 2026 High CVE-2023-1389BRUSddosbotnetdns
threat-intel AI-powered honeypots: Turning the tables on malicious AI agents This article details a new approach to cybersecurity utilizing generative AI to create dynamic honeypots. By leveraging AI to simulate vulnerable systems and respond to attacker actions, defenders can actively manipulate… Cisco Talos · Apr 29, 2026 Medium CVE-2014-6271aihoneypotgenerative-ai
threat-intel Five defender priorities from the Talos Year in Review This Cisco Talos report, part of their Year in Review, highlights five key priorities for cybersecurity defenders in the current threat landscape. The report emphasizes the increasing ease of attack due to readily availa… Cisco Talos · Apr 28, 2026 High USidentityvulnerabilityanomaly detection
threat-intel Frontier AI and the Future of Defense: Your Top Questions Answered This article from Palo Alto Networks Unit 42 analyzes the emerging threat posed by frontier AI models, particularly Anthropic’s Mythos, to cybersecurity. The rapid capabilities of these models – including vulnerability i… Palo Alto Unit 42 · Apr 23, 2026 High frontier aivulnerabilityexploit chaining
malware New NGate variant hides in a trojanized NFC payment app A new variant of the NGate malware, dubbed NGate, is targeting Android users in Brazil by abusing the legitimate HandyPay app. Threat actors used generative AI to modify HandyPay, allowing them to steal NFC data, includi… WeLiveSecurity · Apr 21, 2026 High BRnfcandroidmalware
threat-intel Fracturing Software Security With Frontier AI Models This report from Palo Alto Unit 42 highlights the emerging threat posed by advanced AI models, particularly "frontier AI models," which demonstrate autonomous vulnerability discovery and exploitation capabilities. The ra… Palo Alto Unit 42 · Apr 20, 2026 High UNNOaivulnerabilityzero-day
phishing That data breach alert might be a trap This article highlights the increasing sophistication and prevalence of fake data breach notification scams, driven by factors like record-breaking data breaches and the use of AI tools. Scammers are leveraging these not… WeLiveSecurity · Apr 17, 2026 High USDEphishingsocial engineeringai
threat-intel A Deep Dive Into Attempted Exploitation of CVE-2023-33538 This report details an ongoing attempt to exploit CVE-2023-33538, a vulnerability in older TP-Link Wi-Fi router models (TL-WR940N v2/v4, TL-WR740N v1/v2, TL-WR841N v8/v10). Automated scans, utilizing Mirai-like malware p… Palo Alto Unit 42 · Apr 16, 2026 High CVE-2023-33538USiotvulnerabilitymirai
supply-chain Supply chain dependencies: Have you checked your blind spot? This article highlights the growing risk of cyberattacks originating through supply chain vulnerabilities, particularly among small and medium-sized businesses (SMBs). It emphasizes that complex, digitized supply chains… WeLiveSecurity · Apr 16, 2026 High CVE-2019-15126CAUNsupply chaincybersecurityrisk management