threat-intel 20 Leaders Who Built the CISO Era: 2 Decades of Change This Dark Reading article reflects on the 20th anniversary of the publication, highlighting key figures who shaped the evolution of cybersecurity over the past two decades. The piece focuses on the rise of the CISO role,… Dark Reading · May 12, 2026 High UNEAcybercrimecisossecurity
threat-intel State-sponsored actors, better known as the friends you don’t want This Cisco Talos report highlights the significant differences in responding to state-sponsored cyber threats compared to conventional attacks like ransomware. It emphasizes that these actors operate within an organizati… Cisco Talos · May 12, 2026 High USUKstate-sponsoredzero trustosint
threat-intel Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools This report from Palo Alto Unit 42 details how Active Directory Certificate Services (AD CS) is frequently exploited by both financially motivated ransomware groups and state-sponsored actors due to misconfigured templat… Palo Alto Unit 42 · May 11, 2026 High CVE-2022-26923NOad cscertificate issuanceprivilege escalation
threat-intel LLMs and Text-in-Text Steganography This article discusses attempts to hide text within LLMs using techniques like phonological changes and unconventional formatting (e.g., white text on white backgrounds). The author explores the limitations of these meth… Schneier on Security · May 11, 2026 Low UKsteganographyllmstempeset
threat-intel Eyes wide open: How to mitigate the security and privacy risks of smart glasses This article discusses the growing security and privacy risks associated with smart glasses, particularly due to their advanced tracking and recording capabilities combined with AI integration. The proliferation of these… WeLiveSecurity · May 11, 2026 High GEUKsurveillanceprivacyai
threat-intel Inside Department 4: Russia’s secret school for hackers A new investigation has revealed a secret faculty within Bauman Moscow State Technical University, known as ‘Department 4,’ which has been training students to become hackers for Russian military intelligence, the GRU. T… Graham Cluley · May 8, 2026 High RUUSrussian hackingspywaregru
threat-intel Canvas Breach Disrupts Schools & Colleges Nationwide A cybercrime group, ShinyHunters, disrupted the Canvas education technology platform, impacting schools and colleges nationwide. The group defaced the login page with a ransom demand, threatening to leak data from 275 mi… Krebs on Security · May 8, 2026 High USeducationdata breachransomware
threat-intel Unplug your way to better code This article from Cisco Talos discusses a shift in threat intelligence strategy, focusing on tracking phone numbers used in sophisticated scam campaigns. Attackers are increasingly utilizing API-driven VoIP numbers for T… Cisco Talos · May 7, 2026 Medium voipscamphone numbers
threat-intel Exploits and vulnerabilities in Q1 2026 This Securelist report analyzes vulnerability trends and exploitation activity during Q1 2026, focusing on the expansion of exploit kits targeting Microsoft Office, Windows, and Linux operating systems. The report highli… Securelist · May 7, 2026 High CVE-2018-0802CVE-2017-11882CVE-2017-0199USvulnerabilityexploitationrce
threat-intel Fixing the password problem is as easy as 123456 This article highlights a persistent problem in cybersecurity: the widespread use of easily guessable passwords, particularly ‘123456’ and variations. Despite industry advice and password policies, numerous websites, inc… WeLiveSecurity · May 7, 2026 High password_securityweak_passwordsdata_breach
threat-intel Smashing Security podcast #466: Meta sees everything, Copy Fail, and a deepfake gets hired This Smashing Security podcast episode discusses ongoing cybersecurity challenges, including the persistent issues of AI-related bugs, social engineering attacks, and the dangers of deepfakes. A key topic is Meta’s smart… Graham Cluley · May 6, 2026 Medium UKaiprivacydeepfake
threat-intel From Stuxnet to ChatGPT: 20 News Events That Shaped Cyber This Dark Reading article reflects on key cybersecurity events from the past two decades, highlighting the evolution of cyber threats and their impact on businesses and critical infrastructure. The piece emphasizes how a… Dark Reading · May 6, 2026 High CVE-2017-0144CVE-2021-44228IRUSISindustrial control systemsnation-state actorsair gap
threat-intel Insights into the clustering and reuse of phone numbers in scam emails This article details Cisco Talos’s intelligence gathering on the increasing use of phone numbers in scam email campaigns. Attackers are leveraging API-driven VoIP providers like Sinch and Twilio to operate high-volume, d… Cisco Talos · May 6, 2026 High USUKvoipscamphishing
threat-intel Websites with an undefined trust level: avoiding the trap This Securelist article discusses the growing threat of websites with an "undefined trust level," which are not traditional phishing sites but still pose significant risks to users. These sites, often mimicking legitimat… Securelist · May 6, 2026 Medium AFLARUscamfraudonline scams
threat-intel How the Story of a USB Penetration Test Went Viral This Dark Reading Confidential episode recounts the viral 2006 pen test conducted by Steve Stasiukonis at a credit union, focusing on his use of rigged USB drives to observe employee behavior. The story gained traction t… Dark Reading · May 5, 2026 Medium social engineeringusbpen testing
threat-intel CloudZ RAT potentially steals OTP messages using Pheno plugin Cisco Talos identified an intrusion campaign initiated in January 2026 involving the deployment of the CloudZ remote access tool (RAT) alongside a new plugin called ‘Pheno.’ This campaign leveraged the Microsoft Phone Li… Cisco Talos · May 5, 2026 High USotpphone linkcredential theft
threat-intel A rigged game: ScarCruft compromises gaming platform in a supply-chain attack A North Korean-aligned APT group, ScarCruft (also known as APT37 or Reaper), conducted a supply-chain attack targeting a video game platform used by ethnic Koreans in the Yanbian region of China. The attackers injected a… WeLiveSecurity · May 5, 2026 High CNKPsupply-chainnorth-koreaespionage
threat-intel Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition A 19-year-old teenager, identified as "Bouquet," has been arrested in Finland and faces US extradition charges for allegedly being a member of the Scattered Spider cybercrime group. The investigation revealed the group’s… Graham Cluley · May 4, 2026 High USGBFIsocial engineeringphishingmfa
threat-intel Essential Data Sources for Detection Beyond the Endpoint This Unit 42 report highlights the increasing speed of cyberattacks and the limitations of relying solely on endpoint detection and response (EDR) solutions. Attackers are now moving four times faster to exfiltrate data,… Palo Alto Unit 42 · May 1, 2026 High cloud securityendpoint detectionthreat intelligence
threat-intel 20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage This Dark Reading article celebrates the platform’s 20th anniversary, reflecting on its role in covering the evolution of cybersecurity over the past two decades. The piece highlights key moments and figures from the ind… Dark Reading · May 1, 2026 Medium UScybersecurityhistoryindustry