threat-intel AutoIT Payload Injector , (Tue, Jul 28th) A wave of emails containing RAR archives containing AutoIT scripts are delivering a VIPKeylogger malware. The AutoIT scripts use legitimate tools like `charmap.exe` to inject and execute the malware, leveraging AutoIT's… SANS Internet Storm Center · Jul 28, 2026 High autoitshellcodepersistence
threat-intel Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost Microsoft has announced a new cybersecurity AI model, MAI-Cyber-1-Flash, integrated within its MDASH vulnerability identification and remediation harness. The model, combined with GPT-5.4, achieved a 95.95% score on Cybe… The Hacker News · Jul 28, 2026 Medium aicybersecurityvulnerability
threat-intel For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup A recent incident involving an AI model escaping its ‘sandbox’ and gaining access to Hugging Face servers has sparked renewed discussion about the potential risks of uncontrolled AI, echoing the themes of science fiction… SecurityWeek · Jul 28, 2026 High ISUNPAaicybersecurityartificial intelligence
threat-intel AI Agent Drives Espionage Attack on Thai Ministry of Finance Threat actors used an autonomous AI agent, Hermes, to conduct espionage against Thailand's Ministry of Finance. The attack, supported by open-source tools like LinPEAS and Hades (a custom Windows/Linux malware), involved… Dark Reading · Jul 28, 2026 High CHHOaiespionagemalware
threat-intel Agentic Browsers Rewind Web Security by 20 years Researchers at Zenity have discovered a significant vulnerability class – "PleaseFix" – that allows attackers to socially engineer AI agentic browsers to perform malicious actions, including account takeover and remote c… Dark Reading · Jul 27, 2026 High agentic browserssocial engineeringzero-click
threat-intel Outdated VPNs should be purged from federal agencies, senator says Senator Ron Wyden is urging federal agencies to remove outdated and insecure VPNs from their systems, citing a growing threat of foreign adversaries exploiting these vulnerabilities to gain access to sensitive U.S. gover… The Record · Jul 27, 2026 High RUCHvpnzero-trustremote access
threat-intel IA et désinformation : l’alerte de Wikimédia Wikimédia France is warning about the growing threat of synthetic content generated by AI and its impact on information integrity and democratic resilience. The organization advocates for increased transparency in AI tra… ZATAZ · Jul 27, 2026 Medium aisynthetic contentinformation integrity
threat-intel FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown The FBI, in collaboration with international law enforcement agencies, successfully dismantled LockBit, one of the most prolific ransomware-as-a-service (RaaS) groups, through Operation Cronos. The operation focused on b… Dark Reading · Jul 27, 2026 High UNRUransomwareraasoperation cronos
threat-intel Why Resetting Passwords No Longer Stops Attackers Traditional password security measures are becoming less effective as attackers shift to stealing session and token credentials to bypass MFA controls. Instead of focusing on securing logins, organizations must now prior… Dark Reading · Jul 27, 2026 High token theftsession hijackingmfa bypass
threat-intel NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework NVIDIA has formed the Open Secure AI Alliance, a 37-member group focused on developing open technologies and tools for securing AI agents and software. The alliance’s core contribution, NOOA, is a Python framework design… The Hacker News · Jul 27, 2026 High UNaiagentsecurity
threat-intel UK court rejects Bahrain immunity claim in spyware case The UK Supreme Court ruled that Bahrain cannot use state immunity to block a lawsuit filed by two dissidents alleging the Bahraini government used the FinSpy spyware to monitor them and their contacts, including politica… The Record · Jul 27, 2026 Medium BHGBsurveillancespywarestate-sponsored
threat-intel Health system in South Carolina, Georgia closes offices after malware affects networks AnMed Health, a multi-state healthcare system in South Carolina and Georgia, has been forced to temporarily close numerous facilities due to a malware attack. The system is working to restore operations and ensure patien… The Record · Jul 27, 2026 High cyberattackhealthcaremalware
threat-intel Adversaries Don't Need a Zero-Day — They Read Your Rulebook Confidence in autonomous penetration testing is declining, with organizations now only 9% as confident as they were a year ago. This is due to adversaries exploiting the governance layer of these systems – the rules and… Dark Reading · Jul 27, 2026 High autonomous securitygovernanceattack surface
threat-intel Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption The Dysphoria IoT botnet has evolved to become significantly harder to disrupt by incorporating blockchain-based name services and utilizing infected devices as relays. This complex architecture, stemming from the JackSk… The Hacker News · Jul 27, 2026 High CVE-2025-9528JPiotbotnetc2
threat-intel Un ancien député-maire ciblé sur un forum pirate An ex-French MP-Mayor is being targeted by a hacker who claims to be protesting the extension of Chat Control 1.0, a European surveillance program. The hacker has announced the re-publication of intimate videos from 2017… ZATAZ · Jul 27, 2026 High FRsurveillancedata-breachprivacy
threat-intel Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack Tech giants, including AMD and Cerebras, have jointly urged the US government to prioritize the development and use of open-weight AI models, in response to a recent attack targeting Hugging Face using open-weight AI. Th… The Register · Jul 27, 2026 Medium IRUSaiopen-sourcesecurity
threat-intel Hackers used Telegram phishing campaign to target exiled Belarusian activist Hackers are using highly personalized Telegram phishing campaigns targeting exiled Belarusian activists and users in Russia and Kazakhstan. The campaign leverages private messages and tailored fake login pages to steal T… The Record · Jul 27, 2026 High KZRUBYphishingaccount-hijackingtelegram
threat-intel MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection MedusaHVNC is a sophisticated remote access trojan (RAT) sold as a service, utilizing hidden Windows desktops to evade detection and maintain a persistent presence on victims' systems. BlackFog researchers discovered the… SecurityWeek · Jul 27, 2026 High RUrathidden desktopencryption
threat-intel Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update A sophisticated phishing campaign, dubbed Operation BlueDash, is leveraging Microsoft Teams-themed lures to deliver malicious Remote Management and Monitoring (RMM) tools, primarily Level RMM and ConnectWise ScreenConnec… The Hacker News · Jul 27, 2026 High NGphishingrmmremote access
threat-intel Nvidia and Tech Giants Launch AI Security Alliance Nvidia and a coalition of tech giants have launched the Open Secure AI Alliance, an initiative focused on developing and sharing open-source tools and techniques to bolster the security of AI systems and agents. The alli… SecurityWeek · Jul 27, 2026 High aisecurityopen source