threat-intel Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects This Kaspersky report, based on 2025 compromise assessment engagements, highlights significant missed incidents due to inadequate monitoring, delayed detection, and communication gaps. The analysis reveals a concerning t… Securelist · Jul 2, 2026 High SACNRUmissed incidentsthreat detectionincident response
phishing Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS This article details a concerning trend in phishing attacks where threat actors are leveraging user-agent data to dynamically adapt their campaigns to the specific device and operating system of the victim. Attackers are… Dark Reading · Jul 1, 2026 High USphishinguser-agentmalware
threat-intel And the Winner in Dominant Malware Delivery? ClickFix ClickFix, a social engineering technique where attackers trick users into executing malicious commands via error messages, has become the dominant method for malware delivery, according to a recent ReliaQuest analysis. T… Dark Reading · Jul 1, 2026 High USsocial engineeringmalware deliveryobfuscation
threat-intel Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters An unpatched vulnerability in Argo CD's repo-server component allows unauthenticated attackers to take over Kubernetes clusters by exploiting a lack of authentication and network policies. Synacktiv discovered the flaw i… The Hacker News · Jul 1, 2026 Critical CVE-2024-31989CVE-2025-55190CVE-2026-42880kubernetesargo cdnetwork policy
malware VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer A new multi-stage malware attack chain, dubbed VEIL#DROP, is utilizing social engineering and Blogger pages to deliver the PureLogs stealer. The attack begins with a deceptive JavaScript file, leveraging Google's infrast… The Hacker News · Jul 1, 2026 High USspear-phishingbloggerpurelogs
threat-intel 'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat This article details a new supply chain threat dubbed "Phantom Squatting," where large language models (LLMs) are hallucinating non-existent web domains linked to legitimate brands. Cybercriminals are exploiting this by… Dark Reading · Jul 1, 2026 High USllmsupply chainai
threat-intel Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands A critical vulnerability, dubbed DuneSlide, has been discovered in Cursor, an AI code editor used by over half of the Fortune 500, allowing attackers to bypass the editor's sandbox and execute arbitrary commands on a dev… The Hacker News · Jul 1, 2026 Critical CVE-2026-50548CVE-2026-50549CVE-2025-54135prompt-injectionsandboxai-code-editor
threat-intel US lifts export controls on Anthropic’s frontier cybersecurity AI models The U.S. government has lifted export controls on Anthropic’s Fable 5 and Mythos 5 cybersecurity AI models following a ‘jailbreak’ exploit discovered in Fable 5. This marks the first instance of export controls being app… The Record · Jul 1, 2026 Medium USCHaijailbreakexport controls
threat-intel Safe Events Start With Threat Intel and Digital Security This article discusses the importance of threat intelligence and digital security in protecting major events like sporting competitions and celebrations. It highlights how attackers often begin preparing well in advance,… Dark Reading · Jul 1, 2026 High ATUSevent securitythreat intelligencecybersecurity
ransomware AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android A new type of ransomware, dubbed ‘InfernoGrabber v9.0’, has emerged utilizing AI-generated code to exploit vulnerabilities in Chromium-based browsers on Windows and Android. The malware, created using the DeepSeek AI mod… The Hacker News · Jul 1, 2026 High CVE-2023-4863USairansomwarebrowser
malware The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign A large-scale cyber campaign utilized the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware onto compromised systems. Threat actors disguised installers of popular software like OBS Studio and DNS Ju… Securelist · Jul 1, 2026 High GDremote accessdll sideloadingpersistence
threat-intel Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls Anthropic has restored access to Claude Fable 5 following the U.S. Commerce Department’s lifting of export controls triggered by a jailbreak vulnerability discovered in the model. The controls, implemented in June, restr… The Hacker News · Jul 1, 2026 High USjailbreakaisecurity
threat-intel Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts A massive, automated password spray attack targeting Microsoft's Azure CLI compromised at least 78 Microsoft accounts across 64 organizations. The attack leveraged a deprecated OAuth flow (ROPC) to bypass Conditional Acc… The Hacker News · Jul 1, 2026 High USCNpassword sprayropcconditional access
threat-intel Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Palo Alto Unit 42 researchers have identified a new supply chain threat: "phantom squatting," where large language models (LLMs) hallucinate web domains that adversaries can then register to intercept traffic generated b… Palo Alto Unit 42 · Jul 1, 2026 High USllmaisupply chain
threat-intel Attackers Hijack Exposed AI Endpoints to Power Offensive Ops Researchers at Zenity discovered attackers are exploiting exposed AI endpoints, specifically Ollama and LiteLLM, to power offensive operations. Attackers leverage these AI agents – such as Strix and HexStrike AI – withou… Dark Reading · Jun 30, 2026 High FRaillmendpoint
threat-intel Phishers Gain Persistence at EU, Asia Hospitality Orgs Phishing campaigns targeting hospitality organizations in Europe and Asia are utilizing malicious zip files containing disguised image files to install persistent malware. These attacks, observed by Microsoft and Trend M… Dark Reading · Jun 30, 2026 High GBJPphishingpersistencesocial engineering
threat-intel Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data This report details a new security vulnerability impacting AI agent-based systems, specifically leveraging the Model Context Protocol (MCP). Attackers can inject malicious instructions into tool descriptions used by AI a… The Hacker News · Jun 30, 2026 High N/aiagentsupply-chain
malware RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS A new botnet, RustDuck, is leveraging Rust programming to hijack routers, IP cameras, and servers for DDoS attacks. Developed by QiAnXin's XLab, the botnet utilizes a two-stage approach, exploiting vulnerabilities in dev… The Hacker News · Jun 30, 2026 High CVE-2017-17215CVE-2025-29635CVE-2024-1781CNddosbotnetrust
ransomware Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints A critical Remote Code Execution (RCE) vulnerability (CVE-2026-33017) in Langflow is being exploited by threat actors to deploy a Monero cryptocurrency miner on exposed AI application endpoints. The campaign, active from… The Hacker News · Jun 30, 2026 Critical CVE-2026-33017CVE-2025-3248NOrcemoneroai
threat-intel GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks A research report by Adversa AI has revealed a significant security vulnerability in ten popular open-source AI coding agents, including GuardFall, which allows attackers to bypass safety checks and execute shell command… The Hacker News · Jun 30, 2026 High aishellsecurity