ransomware Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk Recent breaches targeting educational institutions, including ransomware attacks on Oracle E-Business Suite and Instructure's Canvas platform, highlight the vulnerability of the sector due to legacy technology, understaf… Dark Reading · Jun 27, 2026 High USthird-party riskransomwareeducation
threat-intel Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools This Securelist article details Kaspersky's 2026 threat analysis for small and medium-sized businesses (SMBs), highlighting a significant increase in cyberattacks disguised as artificial intelligence (AI) tools, particul… Securelist · Jun 25, 2026 High USaismbmalware
malware New macOS ClickFix attack silently mounts DMGs to push infostealer A new macOS ClickFix campaign is using Terminal commands to silently deploy the Atomic macOS Stealer (AMOS) infostealer, targeting users through fake CAPTCHA pages. The malware steals sensitive data like browser credenti… BleepingComputer · Jun 23, 2026 High USmacosclickfixinfostealer
threat-intel ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories This week’s ThreatDay Bulletin highlights several concerning security incidents, including browser extension abuse, macOS malware attacks, AI-powered malware delivery, and a global phishing campaign targeting travel book… The Hacker News · Jun 18, 2026 High CVE-2026-20127CVE-2026-49975USCNJPbrowser extensionsmacos malwareai abuse
threat-intel US Cracks Down on Anthropic AI Models Amid Abuse Concerns Anthropic has suspended access to its Fable 5 and Mythos 5 AI models following a US government export control directive, aimed at preventing foreign nationals from utilizing them. This action stems from growing concerns… Dark Reading · Jun 15, 2026 High CHRUUKaicybersecuritythreat intelligence
vulnerability Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure A critical vulnerability (CVE-2026-10520) in Ivanti Sentry was exploited within 24 hours of its disclosure, highlighting the speed at which attackers can react to newly released vulnerabilities. The flaw, an OS command i… Dark Reading · Jun 11, 2026 Critical CVE-2026-10520CVE-2026-10523CVE-2026-1340vulnerabilitycommand injectionroot access
malware OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month The OnyxC2 stealer, offered as a "Malware-as-a-Service" (MaaS) product for $250-$500 per month, is a sophisticated tool designed for enterprise-level credential theft. Developed by BlackFog, it boasts a wide range of tar… SecurityWeek · Jun 11, 2026 High USstealercredential theftmalware-as-a-service
threat-intel The Invisible Battlefield: How Cyber War Is Reshaping Everyday Life This article, authored by former National Cyber Director Chris Inglis, highlights the evolving nature of cyber warfare, arguing that it’s no longer a technical issue confined to IT departments but a central arena for nat… Dark Reading · Jun 9, 2026 High UScybersecuritycyberwarfarecritical infrastructure
threat-intel Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse Meta has reported that approximately 20,000 Instagram accounts were compromised due to abuse of its AI-powered account recovery tool, High Touch Support (HTS). Hackers exploited a vulnerability in the tool to reset passw… SecurityWeek · Jun 8, 2026 High aiaccount recoverypassword reset
threat-intel Raising the Cybersecurity Stakes: Ante up for the Agentic Era This article discusses the emerging "agentic era" in cybersecurity, driven by the increasing use of AI-powered tools and agents by both attackers and defenders. The rapid evolution of AI is creating a significant securit… SecurityWeek · May 28, 2026 High USaiagenticautomation
malware BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model An advanced Android remote access Trojan, BTMOB RAT, is spreading across Brazil and Latin America through a malware-as-a-service (MaaS) model. Delivered via a no-code interface, it allows cybercriminals to create malicio… Dark Reading · May 28, 2026 High BRARandroidratmaas
threat-intel GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure CrowdStrike, in collaboration with Google and Shadowserver Foundation, successfully disrupted the command-and-control infrastructure of the GlassWorm malware campaign, which targeted software developers through compromis… The Hacker News · May 27, 2026 High RUCIsupply chaindeveloperc2
threat-intel Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Dutch authorities have seized over 800 servers and arrested two individuals – Andrey Nesterenko and Youssef Zinad – operating MIRhosting and WorkTitans, respectively, for facilitating cyberattacks and disinformation camp… Krebs on Security · May 25, 2026 High NLDKRUcyberattackddossanctions
phishing FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks The FBI has issued a warning about Kali365, a Telegram-based phishing-as-a-service platform, following its use in April attacks targeting Microsoft 365 accounts. This service lowers the barrier to entry for cybercriminal… The Record · May 22, 2026 High USphishingoauthmfa
threat-intel Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks The Verizon 2026 Data Breach Investigations Report (DBIR) reveals a significant increase in social engineering attacks targeting the healthcare sector, driven by the adoption of generative AI. While ransomware and vendor… Dark Reading · May 22, 2026 High social engineeringaigenai
vulnerability Ubiquiti patches three max severity UniFi OS vulnerabilities Ubiquiti Networks has released security patches for three critical vulnerabilities within its UniFi OS operating system, addressing potential remote exploitation risks. These flaws include improper access control, path t… BleepingComputer · May 22, 2026 Critical CVE-2026-34908CVE-2026-34909CVE-2026-34910UScommand injectionaccess controlpath traversal
threat-intel Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise As the 2026 FIFA World Cup approaches, scammers are exploiting fans’ desire for tickets and merchandise by creating convincing fake websites mimicking FIFA’s official channels. These sites use tactics like typosquatting… WeLiveSecurity · May 22, 2026 High phishingsocial engineeringdomain spoofing
threat-intel Police seize “First VPN” service used in ransomware, data theft attacks Law enforcement agencies, in a coordinated international effort led by France and the Netherlands, have taken down the ‘First VPN’ service, a virtual private network used extensively by ransomware and data theft groups.… BleepingComputer · May 21, 2026 High UKFRNEvpncybercrimeransomware
threat-intel Europe dismantles VPN service used by cybercriminals to hide ransomware attacks European law enforcement agencies successfully dismantled First VPN, a virtual private network (VPN) service heavily utilized by cybercriminals to mask their activities, including ransomware attacks and fraud schemes. Th… The Record · May 20, 2026 High FRNLUAvpncybercrimeransomware
threat-intel AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop This SecurityWeek article highlights a significant shift in app security driven by the rapid adoption of AI by cybercriminals. The report from Digital.ai indicates a dramatic increase in attacks against apps, moving from… SecurityWeek · May 20, 2026 High USGBaiagentic aiapp security