threat-intel AI Coding: Do Security Risks Outweigh Productivity Gains? AI coding tools are rapidly increasing in popularity, with 91% of organizations using two or more and 54% using three or more. While developers report productivity gains and ROI, significant security risks are associated… Dark Reading · Jul 10, 2026 High aicodingsecurity
threat-intel Third US Security Expert Sentenced to Prison for Helping Ransomware Gang A former cybersecurity expert, Angelo Martino, was sentenced to 70 months in prison for aiding a ransomware gang, BlackCat/Alphv, by providing confidential information to maximize ransom payments. Two other cybersecurity… SecurityWeek · Jul 10, 2026 Critical ransomwareinsider threatcybercrime
threat-intel China, India-Linked Hackers Both Targeted Same Pakistani Police Force Chinese and Indian cyber espionage groups have been quietly targeting Pakistani law enforcement networks for over two years, with a particular focus on the Balochistan Police. The intrusions aimed to access sensitive dat… SecurityWeek · Jul 10, 2026 High CHINPAcyberespionagebelt and roadgeopolitics
threat-intel From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale Lumen Technologies dramatically improved its exposure management program by reconciling data from over 40 disconnected systems, revealing a massive underestimation of its cyber assets – growing from approximately 17,000… The Hacker News · Jul 10, 2026 High asset-inventoryexposure-managementcyber-assets
threat-intel Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites A cybercrime crew exposed its operations – including tools, logs, and target lists – after leaving a server open for three weeks. The WP-SHELLSTORM operation, which involved planting webshells on vulnerable WordPress and… The Hacker News · Jul 10, 2026 High CVE-2026-3844CVE-2021-29441CVE-2026-3300CHwebshellvulnerabilityexploit
threat-intel Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers Okta has warned of a sophisticated vishing campaign targeting Microsoft 365 customers, primarily through impersonating legitimate Microsoft Entra ID login pages. The campaign, attributed to the O-UNC-066 threat actor gro… SecurityWeek · Jul 10, 2026 High vishingpasskeyphishing
threat-intel AI Surveillance and Social Progress This article explores the growing threat of AI-powered surveillance systems, particularly in China, and their potential to significantly erode personal freedoms and democratic progress. The author argues that these syste… Schneier on Security · Jul 10, 2026 High CHUSGEsurveillanceaifacial recognition
threat-intel Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking A University of Michigan, New Mexico, and IIT Delhi study found that 281 popular free Android VPN apps on the Google Play Store have significant security flaws, including leaking user traffic, sending data in plain text,… The Hacker News · Jul 10, 2026 High CVE-2016-6329CVE-2016-2183vpnandroidsecurity
threat-intel Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access A threat actor, linked to the O-UNC-066 group (affiliated with The Com/Scattered Spider), is using a sophisticated, operator-controlled phishing kit to trick users into enrolling fake Microsoft Entra passkeys, gaining un… The Hacker News · Jul 10, 2026 High passkeyphishingvishing
threat-intel GigaWiper Combines Multiple Malware for System-Level Sabotage Microsoft has identified a sophisticated malware strain called GigaWiper, a Go-based backdoor combining multiple destructive capabilities – including a physical disk wiper, ransomware-like encryption, and persistent C&C… SecurityWeek · Jul 10, 2026 High IRbackdoorransomwarewipe
threat-intel "Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th) This phishing email campaign uses a clever technique to evade AI-based email security filters. The attacker employs a large, padded HTML attachment containing a credential-stealing page. The padding itself – a massive bl… SANS Internet Storm Center · Jul 10, 2026 High phishingai evasioncontent classification
threat-intel Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets Attackers are exploiting a vulnerability called ‘Ill Bloom’ in several cryptocurrency wallets, allowing them to drain funds. A coordinated attack on May 27th resulted in $3.1 million being stolen from 431 wallets, with a… The Hacker News · Jul 10, 2026 High CVE-2023-39910CVE-2023-31290vulnerabilitycryptocurrencywallet
threat-intel ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism Researchers have discovered a new attack technique called ‘HalluSquatting’ that leverages AI assistants’ tendency to fabricate information to create scalable botnets. Attackers register fake repository names, and when us… SecurityWeek · Jul 10, 2026 High aiprompt injectionhallucination
threat-intel Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks A former ransomware negotiator, Angelo Martino, has been sentenced to 70 months in prison for betraying five victims and providing BlackCat ransomware operators with confidential information, allowing them to demand high… The Hacker News · Jul 10, 2026 High USransomwarenegotiatorcollusion
threat-intel ISC Stormcast For Friday, July 10th, 2026 https://isc.sans.edu/podcastdetail/10002, (Fri, Jul 10th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in widely used communication… SANS Internet Storm Center · Jul 10, 2026 High phishingvulnerabilityslack
threat-intel Dutch police trace Odido telco cyberattack to suspected local accomplice Dutch police are investigating a cyberattack against Odido, a Dutch telecom provider, that exposed the data of over 6 million customers. The attack was facilitated by a Dutch-speaking individual posing as an Odido IT emp… The Record · Jul 9, 2026 High NLcyberattackdata breachtelecom
threat-intel Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure Iran's cyber operations, primarily conducted through groups like Handala and Ababil of Minab, are increasingly targeting a broader range of organizations beyond critical infrastructure. These groups, often described as h… Dark Reading · Jul 9, 2026 Medium CVE-2021-22681IRhacktivismcyber espionagevulnerability exploitation
threat-intel AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready This article discusses the growing risk posed by AI agents in software development environments and highlights that most organizations are unprepared to manage this new type of identity. Unlike traditional service accoun… Dark Reading · Jul 9, 2026 High aiidentitygovernance
threat-intel Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs Datadog Security Labs has discovered a campaign where attackers are systematically mapping corporate GitHub organizations by leveraging dormant accounts and stolen credentials to gather extensive information about a comp… The Hacker News · Jul 9, 2026 Medium githubenumerationapi
threat-intel New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware Microsoft has uncovered a sophisticated Windows backdoor, dubbed GigaWiper, that combines destructive capabilities with remote control functionality. GigaWiper operates by bundling three separate tools – a disk wiper, a… The Hacker News · Jul 9, 2026 High IRISUKransomwarebackdoordata destruction