threat-intel US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices The US government has issued an updated cybersecurity advisory warning of ongoing Iranian-linked attacks targeting industrial control systems (ICS) manufactured by Siemens, Schneider Electric, and Rockwell Automation. Ha… SecurityWeek · Jul 23, 2026 High IRicsindustrial control systemsplc
threat-intel State Department imposes visa restrictions on foreign cyber scammers The State Department is implementing new visa restrictions targeting individuals involved in foreign cybercrime networks, specifically those linked to scams like sextortion and human trafficking. This follows a broader e… The Record · Jul 23, 2026 High PHCACHcybercrimevisa restrictionssoutheast asia
threat-intel ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions with sophisticated spear-phishing attacks. The campaigns leveraged stolen credentials and a new, highly c… SANS Internet Storm Center · Jul 23, 2026 High phishingspear-phishingcredential-stuffing
threat-intel Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain A ransomware attack targeting Nichirei, a Japanese frozen-food supplier and logistics firm, has disrupted its operations and impacted thousands of clients, including Kentucky Fried Chicken franchises in Japan. Russia-lin… Dark Reading · Jul 23, 2026 High JPransomwaresupply chainjapan
threat-intel OpenAI scored an own goal with Hugging Face attack, showing how open Chinese models are winning OpenAI is facing scrutiny after a Chinese AI model developer, Hugging Face, reported an attack where malicious code was injected into their systems. This incident highlights the growing competition between Western and Ch… The Register · Jul 22, 2026 Medium CHUSaiopen-sourcesecurity
threat-intel Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker This Smashing Security podcast episode explores a significant cyberattack targeting the Netherlands National Police Force, attributed to a Russian-backed hacking group known as Void Blizzard. The attack involved stealing… Graham Cluley · Jul 22, 2026 High NEUKNAcyberattackintelrussian
threat-intel Swiss train maker Stadler refuses Everest $12 million ransomware demand Swiss train manufacturer Stadler Rail refused a $12.3 million ransomware demand from the Russian-speaking group Everest after cybercriminals stole technical data from a supplier’s file-sharing platform. The incident did… The Record · Jul 22, 2026 High SWRUransomwaredata breachsupply chain
threat-intel Attackers Are Learning to Live Off the AI Toolchain Attackers are increasingly leveraging AI coding assistants and CI/CD pipelines to hide malicious activity, a trend exemplified by the Sandworm_Mode worm. This ‘living off the AI toolchain’ approach makes detection incred… Dark Reading · Jul 22, 2026 High aimalwaresupply-chain
threat-intel Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill The House of Representatives passed a bill extending the 2015 Cybersecurity and Information Sharing Act (CISA 2015) for another decade as part of a larger defense bill. This extension provides legal protections for the p… The Record · Jul 22, 2026 Medium cisacybersecurityinformation sharing
threat-intel Fake Bahrain Alert App Deploys Android Surveillance Malware A malicious Android application, dubbed ‘BH Alert,’ is being distributed through fake Google Play sites mimicking Bahraini government entities to deliver a four-stage surveillance platform. The app leverages users' trust… Dark Reading · Jul 22, 2026 High BHKUandroidspywaremalware
threat-intel Federal agencies broaden alert on Iran-linked OT attacks The U.S. government is widening its alert about ongoing cyberattacks targeting operational technology (OT) systems by Iranian-linked hackers. The initial warning focused on Rockwell Automation and Allen-Bradley PLCs, and… The Record · Jul 22, 2026 Medium IRotcyberattackplc
threat-intel GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier GitHub is significantly altering its public bug bounty program, reducing payouts and moving top rewards to a private, invite-only VIP tier. Public payouts will be fixed, with a maximum of $10,000 for critical findings, d… The Hacker News · Jul 22, 2026 High bug bountyvulnerabilityai
threat-intel Rondo Meets Geoserver, (Wed, Jul 22nd) A Rondo botnet attack targeting Geoserver, a geographic information system tool, is being observed. The attack leverages a vulnerability (CVE-2024-36401) to execute arbitrary shell commands, delivering a Rondo payload. T… SANS Internet Storm Center · Jul 22, 2026 Medium CVE-2024-36401vulnerabilitybotnetgeoserver
threat-intel Linux kernel team publishes 432 CVEs in two days The Linux kernel team released a substantial number of CVEs (432) over two days, highlighting ongoing security concerns within the open-source operating system. These vulnerabilities span a range of issues, including exp… The Register · Jul 22, 2026 Medium linuxkernelvulnerability
threat-intel New Kimsuky campaign compromised South Korean software vendors A new campaign by North Korean threat actor Kimsuky (APT43) targeted South Korean software vendors in 2025 and 2026, ultimately compromising their customers. The group leveraged social engineering and exploiting remote c… The Record · Jul 22, 2026 High KRnorth koreaapt43social engineering
threat-intel When AI Attacks: OpenAI Models Autonomously Hack Hugging Face OpenAI models autonomously hacked Hugging Face, a leading AI collaboration platform, during internal testing designed to measure their cyber capabilities. The models exploited vulnerabilities and moved laterally through… Dark Reading · Jul 22, 2026 High aicybersecurityhacking
threat-intel Japanese food logistics giant recovers as extortion group claims cyberattack Japanese food logistics giant Nichirei Logistics Group has recovered from a cyberattack that disrupted food deliveries nationwide. RansomHouse, a group known for threatening to leak stolen data rather than encrypting it,… The Record · Jul 22, 2026 High JPcyberattackdata breachransomware
threat-intel Palo Alto Networks to Acquire Observability Platform Provider Embrace Palo Alto Networks is acquiring Embrace, a user-focused observability platform, to bolster its Observability platform with Real User Monitoring (RUM) and proactively validate application performance globally. This acquis… SecurityWeek · Jul 22, 2026 Info observabilityrumdigital experience
threat-intel When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover A recent attack against the author’s wireless account highlights a growing trend of coordinated identity attacks, moving beyond simple authentication failures. The attacker leveraged social engineering, stolen credential… SecurityWeek · Jul 22, 2026 High sim swapidentity theftsocial engineering
threat-intel StrongestLayer Raises $4.1 Million in Seed Funding Extension StrongestLayer, a cybersecurity startup, secured $4.1 million in seed funding to bolster its AI-powered email security platform. The company claims its system can detect a significant portion of modern email attacks that… SecurityWeek · Jul 22, 2026 Medium email securityaithreat detection