threat-intel ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories This week's "ThreatsDay" bulletin highlights a diverse range of security threats, from malware targeting PLCs with Iranian involvement to AI-generated vulnerabilities and deceptive apps. Key concerns include a GitHub sup… The Hacker News · Jul 23, 2026 High IRmalwarethreat intelligencesupply-chain
threat-intel Iran-linked crews are probing more flavors of US industrial kit Iranian-linked actors are actively probing and exploiting vulnerabilities in various US-based industrial hardware and software, including AMD systems and Joomla extensions. This activity highlights a broader trend of sta… The Register · Jul 23, 2026 High IRstate-sponsoredvulnerabilitycyberattack
threat-intel HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 A sophisticated espionage implant, dubbed HollowGraph, is using a hijacked Microsoft 365 calendar as its command and control channel to steal data and deliver instructions. The malware, linked to the Iranian threat group… The Hacker News · Jul 20, 2026 High ISIRespionagecommand-and-controlmicrosoft 365
threat-intel Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure Iran's cyber operations, primarily conducted through groups like Handala and Ababil of Minab, are increasingly targeting a broader range of organizations beyond critical infrastructure. These groups, often described as h… Dark Reading · Jul 9, 2026 Medium CVE-2021-22681IRhacktivismcyber espionagevulnerability exploitation
threat-intel As Global Conflicts Go Digital, Businesses Need Wartime Gameplans As global conflicts become increasingly digital, businesses across various sectors are becoming increasingly vulnerable targets for nation-states engaged in warfare. The case of Intellect Services, a Ukrainian tax softwa… Dark Reading · Jul 9, 2026 High UKIRUNcyberwarfarenation-stategeopolitics
threat-intel Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations Iranian hackers, linked to Iran's Ministry of Intelligence and Security (MOIS) and operating under the moniker Cavern Manticore, are utilizing a new, modular command-and-control (C2) framework called ‘Cavern’ to target I… The Hacker News · Jul 6, 2026 High CVE-2025-52691CVE-2025-68613CVE-2025-9316ISIRc2command and controldotnet
threat-intel The Onboarding Password Mistake That Creates Unnecessary Risk This article discusses the significant security risks associated with using temporary onboarding passwords, highlighting how they are frequently shared insecurely and remain active for extended periods. The practice crea… The Hacker News · Jun 15, 2026 High USIRonboardingcredentialssecurity
threat-intel Infostealers Turn Millions of Devices Into Credential Theft Machines This report details a significant increase in the use of infostealers as a primary method for attackers to steal credentials and gain unauthorized access to networks. Over 11.1 million devices were infected in 2025, resu… SecurityWeek · Jun 10, 2026 High IRinfostealerscredentialsmalware-as-a-service
threat-intel Iran Signed a Ceasefire — Its Hackers Didn't This Dark Reading article discusses the ongoing cyber warfare between Iran and the United States, highlighting a significant loophole in international conflict rules. Following a ceasefire extension, U.S. agencies warned… Dark Reading · Jun 8, 2026 High IRUSIScyberwarfarecritical infrastructureiran
threat-intel Over 900 US gas station tank gauge systems exposed to attacks Over 900 US gas station tank gauge systems are vulnerable to ongoing attacks due to internet exposure and security flaws. Threat actors are exploiting these systems to potentially alter settings and cause operational dis… BleepingComputer · Jun 5, 2026 High USatgindustrial control systemscybersecurity
threat-intel In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking This week’s cybersecurity news highlights several incidents, including Iranian hackers targeting US gas station tank monitor systems, a CISA contractor exposing sensitive credentials, a Huawei router vulnerability causin… SecurityWeek · May 22, 2026 High CVE-2024-9643CVE-2026-45401USLUiotcritical infrastructuresupply-chain
threat-intel Real-World ICS Security Tales From the Trenches This article details real-world incidents involving industrial control systems (ICS) security vulnerabilities, highlighting the challenges of securing OT environments beyond traditional IT security practices. Two separat… SecurityWeek · May 20, 2026 High IRUSicsotlateral movement
threat-intel Fuel Tank Breaches Expand Scope of Iran's Cyber Offensive This article reports on a cyber offensive by Iran targeting fuel tank systems in the United States, exploiting insecure automatic tank gauge (ATG) systems exposed online. The attacks, which involved manipulating displaye… Dark Reading · May 18, 2026 High USIRcyberattackcritical infrastructuregeopolitics