threat-intel Critical Gitea Flaw Under Active Exploitation, Researchers Warn A critical vulnerability in Gitea’s reverse-proxy authentication mechanism is being actively exploited, allowing attackers to bypass authentication and gain unauthorized access to Gitea instances. The flaw, tracked as CV… SecurityWeek · Jul 7, 2026 Critical CVE-2026-20896vulnerabilityauthenticationgit
threat-intel Britain plans to build autonomous AI 'Cyber Shield' to defend nation The UK’s National Cyber Security Centre (NCSC) is developing an AI-powered ‘Cyber Shield’ to bolster national cybersecurity defenses against increasingly sophisticated and rapid attacks. This initiative aims to automate… The Record · Jul 7, 2026 High UKaicybersecuritynational defense
threat-intel 'GitLost' Flaw Leaks Private Data from GitHub's Agentic Workflows A critical prompt injection vulnerability, dubbed ‘GitLost,’ has been discovered in GitHub’s Agentic Workflows, allowing unauthenticated attackers to steal private data from an organization’s repositories by crafting a G… Dark Reading · Jul 7, 2026 High prompt injectionagentic aisecurity vulnerability
threat-intel DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts A Microsoft 365 device code phishing campaign, leveraging collaboration-themed lures, has been observed targeting M365 accounts. The campaign, utilizing a reusable tooling layer called DEBULL, bypasses multi-factor authe… The Hacker News · Jul 7, 2026 High HRTRdevice-codephishingmicrosoft
threat-intel Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data Researchers at Noma Security discovered a vulnerability, dubbed ‘GitLost,’ in GitHub Agentic Workflows that allows attackers to trick AI agents into leaking private repository content simply by posting a malicious issue… The Hacker News · Jul 7, 2026 High prompt injectionai agentgithub
threat-intel Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud Two men were arrested in the Netherlands on suspicion of running a phishing operation targeting credit card details, leading to a significant increase in payment fraud within the country. The Dutch central bank reported… Graham Cluley · Jul 7, 2026 High NLEUphishingcredit card fraudcybercrime
threat-intel Threat landscape for industrial automation systems. Q1 2026 In Q1 2026, the effectiveness of blocking malicious objects on industrial control systems (ICS) decreased significantly, reaching 19.6%, a three-year low. Growth in blocked threats was most pronounced in Southern Europe… Securelist · Jul 7, 2026 Medium UNRUSOicsindustrial control systemsmalware
threat-intel Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure Threat actors have been actively probing a critical vulnerability in Gitea Docker images, exploiting a wildcard configuration that allows unauthenticated access to elevated user accounts. The vulnerability, discovered 13… The Hacker News · Jul 6, 2026 Critical CVE-2026-20896dockervulnerabilityauthentication
threat-intel When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website A sophisticated phishing campaign leveraging the Microsoft Identity Platform's Device Authorization Grant protocol is being used to compromise user accounts. Attackers are crafting emails that appear to be from legitimat… Securelist · Jul 6, 2026 High phishingdevice-code-phishingmicrosoft
threat-intel New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS A new Java-based remote access trojan (RAT) called QuimaRAT, offered as a malware-as-a-service (MaaS), has been released by a threat actor. The tool is cross-platform, supporting Windows, Linux, and macOS, and is adverti… The Hacker News · Jul 6, 2026 High javaratmalware-as-a-service
vulnerability New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android A newly discovered Linux kernel vulnerability, dubbed "Bad Epoll" (CVE-2026-46242), allows unprivileged users to gain root access on systems, including Android devices. The flaw, a "use-after-free" bug, was identified by… The Hacker News · Jul 3, 2026 High CVE-2026-46242CVE-2026-43074CVE-2026-31431USUKlinuxkernelepoll
threat-intel Chinese LLMs Broaden the Gap Between Attackers & Defenders This article reports on the emergence of new Chinese AI models, GLM 5.2 and Tulongfeng (Dragon Saber), which are demonstrating strong performance in vulnerability discovery, rivaling leading US models like Opus and GPT-5… Dark Reading · Jul 3, 2026 High CHUSaivulnerabilitychina
malware PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords PamStealer, a new macOS information stealer developed by Jamf Threat Labs, utilizes deceptive tactics like mimicking the Maccy clipboard manager and exploiting Pluggable Authentication Modules (PAM) to steal login creden… The Hacker News · Jul 3, 2026 High RUBYKZmacosstealercredential theft
threat-intel Spyware found on phone of European Parliament member probing it A former European Parliament member, Stelios Kouloglou, was repeatedly targeted with Pegasus spyware while investigating the misuse of commercial spyware. Citizen Lab researchers discovered the infections occurred during… The Record · Jul 3, 2026 High GRDERUspywarepegasuseuropean parliament
threat-intel Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs A recent Australian Institute of Criminology survey revealed a decrease in overall cybercrime incidents and financial losses experienced by Australians in 2025 compared to 2024. However, this positive trend was largely d… Dark Reading · Jul 2, 2026 Medium AUsmbcybercrimeaustralia
threat-intel Apple Reverses Age-Old Patch Policy to Keep Up With AI Apple is shifting its security patching strategy to a more frequent, independent release model in response to the accelerating pace of AI-driven attacks. Historically, Apple bundled security updates with major OS release… Dark Reading · Jul 2, 2026 High USaizero-daypatching
ransomware Ransomware Thugs Masquerade as Interpol to Entice Small Biz A new ransomware campaign is targeting small businesses globally, impersonating Interpol to lure victims into downloading malware. The campaign utilizes basic social engineering techniques, delivering a rudimentary ranso… Dark Reading · Jul 2, 2026 Medium USEUSAsocial engineeringphishingsmall business
threat-intel Catan and Mouse This Cisco Talos Threat Source newsletter highlights the emergence of ARToken, a sophisticated phishing-as-a-service (PhaaS) platform with capabilities previously undocumented. The platform, similar to EvilTokens, offers… Cisco Talos · Jul 2, 2026 High CVE-2026-48558USphishingbecai
threat-intel ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories This week’s security news highlights several vulnerabilities and ongoing threats across various sectors. A phishing campaign targeting small businesses globally with ransomware, a root escape vulnerability in Claude Cowo… The Hacker News · Jul 2, 2026 High CVE-2026-33825CHUNGEphishingransomwaresandbox
vulnerability New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure A newly discovered CitrixBleed-like vulnerability (CVE-2026-8451) in NetScaler ADC and Gateways was exploited within 24 hours of its public disclosure. The flaw, stemming from an out-of-bounds read issue in the XML parse… SecurityWeek · Jul 2, 2026 Critical CVE-2026-8451DEHKcitrixbleedsamlmemory disclosure