threat-intel Claude Flaw Automatically Sends Malicious Prompts to AI Agents A vulnerability, dubbed ‘PromptFiction,’ has been discovered in Anthropic’s Claude Desktop application, allowing attackers to automatically submit malicious prompts to the AI assistant with a single click, bypassing the… Dark Reading · Jul 15, 2026 High prompt-injectionai-securityuri-scheme
threat-intel Dutch police dismantle global crypto investment scam, arrest alleged mastermind Dutch police have dismantled a global cryptocurrency investment scam involving over 700 employees operating from dozens of call centers across multiple countries. The operation, led by a ‘well-known hacker’ with Israeli… The Record · Jul 15, 2026 High NEPOBEcryptocurrencyfraudscam
threat-intel Windows Bind Link Attacks Can Hide Malware From EDR Tools Researchers at Bitdefender have demonstrated three techniques leveraging Windows’ bind links to evade Endpoint Detection and Response (EDR) tools. These techniques – file-binding, process-binding, and silo-binding – allo… SecurityWeek · Jul 15, 2026 High bind linksedr evasionwindows security
threat-intel LAPD sidelines relationship with license-plate reader company Flock Safety The Los Angeles Police Department (LAPD) is pausing its relationship with Flock Safety, an ALPR camera company, due to concerns about data privacy, security, and control. The decision follows an inspector general’s audit… The Record · Jul 15, 2026 Medium alprsurveillanceprivacy
threat-intel Virtual Event Today: Cloud & Data Security Summit This article announces a virtual cybersecurity summit focused on cloud and data security strategies, tools, and best practices for July 15th. The event will feature interactive sessions and demonstrations to help attende… SecurityWeek · Jul 15, 2026 Info cloud securitycybersecurityvirtual event
threat-intel Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers The CISA, NSA, and international partners have jointly released guidance to help software companies and online services establish effective Coordinated Vulnerability Disclosure (CVD) programs. This program focuses on col… CISA Advisories · Jul 15, 2026 Info vulnerabilitycvdsecurity
threat-intel US Charges Russian Individuals and Firms for Running Cybercrime Services The US Justice Department has charged three Russian nationals and two companies – ML.Cloud and Media Land – with operating cybercrime services that facilitated attacks against numerous US entities, resulting in tens of m… SecurityWeek · Jul 15, 2026 High CNNLFIcybercrimehostingservicesrussian
threat-intel SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough. Traditional SASE security models are failing due to the shift to modern internet protocols and the rise of AI-powered workflows. Employees are now routinely sharing sensitive data with AI tools, bypassing traditional ne… The Hacker News · Jul 15, 2026 High aillmsaas
threat-intel New Webinar: Closing the Approval Gap in AI-Era Ad Tech This article discusses the ‘Approval Gap’ in ad tech, where approved marketing tags can lead to a cascade of third- and fourth-party scripts that security teams haven't vetted. AI is accelerating this issue by increasing… The Hacker News · Jul 15, 2026 Medium ad techprivacycompliance
threat-intel A Video Screen That Is Also a Camera Researchers at ETH Zurich have developed a novel ‘Fourier pixel’ that can both capture and emit light, mimicking a telescreen from Orwell’s *1984*. This technology has significant implications for surveillance and data c… Schneier on Security · Jul 15, 2026 Info surveillancedisplaylight field
threat-intel White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative The White House has launched Gold Eagle, a new initiative designed to streamline vulnerability detection and remediation across government and industry. This program leverages AI, specifically Anthropic's Mythos, to proa… SecurityWeek · Jul 15, 2026 Medium vulnerabilityaicybersecurity
threat-intel OkoBot: new sophisticated malware framework targets cryptocurrency users OkoBot is a sophisticated and evolving malware framework developed by threat actors since 2025, primarily targeting cryptocurrency users. The framework utilizes a layered approach, starting with a PowerShell downloader (… Securelist · Jul 15, 2026 High ransomwarecryptocurrencybrowser
threat-intel ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell This Patch Tuesday saw significant security updates released by Siemens, Schneider Electric, Rockwell Automation, ABB, and Mitsubishi Electric to address a range of vulnerabilities in their industrial control systems (IC… SecurityWeek · Jul 15, 2026 High GEicspatch tuesdayvulnerability
threat-intel Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits Nigeria is experiencing a significant rise in cybercrime losses despite a decrease in reported incidents, driven by increasingly sophisticated schemes and a growing digital economy. The country is actively developing cyb… Dark Reading · Jul 15, 2026 High NGcybercrimecybersecurityfraud
threat-intel SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits SonicWall has issued an urgent patch warning due to two newly exploited zero-day vulnerabilities in its SMA1000 secure remote access appliances. Threat actors are actively leveraging these flaws, and CISA has added them… SecurityWeek · Jul 15, 2026 Critical CVE-2026-15409CVE-2026-15410zero-dayssrfcode_injection
threat-intel ISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Jul 15, 2026 Medium phishingvulnerabilityemail
threat-intel Recent DShield SIEM Update, (Tue, Jul 14th) The DShield SIEM, a honeypot monitoring system, received a recent update incorporating new features and improved logging capabilities. Specifically, the system now collects TTY logs and integrates Suricata alerts, provid… SANS Internet Storm Center · Jul 15, 2026 Medium honeypotthreat-detectionlog-analysis
threat-intel Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal Cribl, a telemetry processing platform, has acquired CardinalOps to bolster its security operations capabilities. This acquisition will allow Cribl customers to map their existing detection rules and security controls to… Dark Reading · Jul 15, 2026 Medium mitre attckdetection engineeringsecurity operations
threat-intel Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes Microsoft's July 2026 Patch Tuesday update is the largest in the program's history, containing 622 unique CVEs, including three zero-day vulnerabilities. The sheer volume of updates presents a significant prioritization… Dark Reading · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch-tuesdayzero-dayvulnerability
threat-intel Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Microsoft released its largest Patch Tuesday update to date, encompassing 622 security updates, with two of these fixes already being actively exploited by attackers. These vulnerabilities, affecting SharePoint Server an… The Hacker News · Jul 14, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-50661zero-dayprivilege escalationremote code execution