threat-intel In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions Several cybersecurity events were highlighted this week, including a reassessment of the Log4j vulnerability as ‘non-finding,’ a ransomware attack against Paylogix exposing sensitive data, and US sanctions against Iranian cyber actors. Other notable developments included a credential leak study revealing thousands of a… SecurityWeek · 1d ago High IRSONElog4jcredential leakransomware
threat-intel You Need Cyber Deception for OT Operational Technology (OT) systems present a significant challenge for cybersecurity due to the lack of traditional security telemetry and the difficulty in tracing attacker activity after they move from IT networks int… Dark Reading · 2d ago High UKcyber deceptionot securitythreat intelligence
threat-intel APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations APT28-linked threat actors, tracked as BlueDelta, have been deploying a new backdoor named HOOKEDGE to target European government and diplomatic organizations since late 2025. HOOKEDGE, a lightweight Windows batch script… The Hacker News · 2d ago High ROSPTUapt28hookedgewebhook
threat-intel Hackers target Ukrainian agency managing assets seized from sanctioned Russians Ukraine’s Asset Recovery and Management Agency (ARMA), responsible for seizing assets from sanctioned Russians, has been targeted by a cyberattack as it prepares to select a manager for IDS Ukraine, a major bottled water… The Record · Aug 18, 2026 High UKRUcyberattackrussiasanctions
threat-intel Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says Russian state-sponsored hackers, linked to the Midnight Blizzard group (part of APT29), are compromising hotel Wi-Fi networks worldwide to steal traveler login credentials and install espionage malware. The campaign uses… The Record · Aug 3, 2026 High RUUKSAhotel wifiespionagecaptive portal
threat-intel Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware A sophisticated campaign, dubbed CaptiveCrunch, is leveraging hijacked hotel Wi-Fi networks to deliver surveillance malware – specifically CornFlake, a remote access trojan – to unsuspecting guests. The attacks are orche… The Hacker News · Aug 1, 2026 High USUKcaptive portaldns redirectionremote access trojan
threat-intel Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials A threat actor is exploiting vulnerabilities in public Wi-Fi gateways, particularly at hotels and conference centers, to steal corporate credentials, including Microsoft 365 accounts, and is leveraging tactics similar to… SecurityWeek · Jul 27, 2026 High USINSAdnscaptive portalcredential theft
threat-intel Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks CERT-UA has warned of a new phishing campaign led by the UAC-0099 threat cluster (linked to Russia) utilizing a malicious Notepad++ plugin to deliver the MATCHBOIL.V2 malware. The campaign begins with a phishing email co… The Hacker News · Jul 24, 2026 High CVE-2025-66376CVE-2026-8496CVE-2025-49113RUUKALphishingmalwarevulnerability
threat-intel Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets Russian state-sponsored threat actors, dubbed ‘Laundry Bear,’ have been exploiting a zero-day vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite to target Western governments and enterprises, including US and U… Dark Reading · Jul 23, 2026 High CVE-2025-66376NLUSUAzimbraxssphishing
malware Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery This report details a concerning trend in malware delivery – the evolution of ClickFix, a technique where users are tricked into running malicious code by hand. Researchers have uncovered a new API-driven approach to gen… The Hacker News · Jul 1, 2026 High RUIRNOmalwarepayloadapi
threat-intel Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices Canadian spy agency, CSIS, utilized a novel court-ordered warrant to neutralize two foreign-run botnets operating within Canada. The operation targeted infected servers, SOHO routers, and IoT devices like Ring doorbells… The Hacker News · Jun 22, 2026 High CAUSbotnetiotcybersecurity
threat-intel Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine The Gamaredon group is exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy a multi-stage malware campaign targeting Ukraine. This campaign utilizes GammaWorm and GammaSteel, designed for data theft and persistenc… The Hacker News · Jun 2, 2026 High CVE-2025-8088CVE-2026-21509RUUAwinrarmalwarevulnerability
threat-intel Russia Hacked Routers to Steal Microsoft Office Tokens Russian military intelligence, operating under the ‘Forest Blizzard’ (APT28/Fancy Bear) moniker, has been conducting a sophisticated cyber espionage campaign targeting over 18,000 routers globally. The attackers exploite… Krebs on Security · Apr 7, 2026 High USUKRUdns hijackingauthentication tokensmicrosoft office