threat-intel ISC Stormcast For Thursday, July 9th, 2026 https://isc.sans.edu/podcastdetail/10000, (Thu, Jul 9th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging a newly discovered phishing technique that bypasses traditional email security filters. The c… SANS Internet Storm Center · Jul 9, 2026 Critical USphishingzero-dayransomware
threat-intel _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th) A self-propagating bot, originating from Belarus (as claimed by its creator), has been scanning for open ports and attempting brute-force login attempts on various servers worldwide. The bot’s purpose is to raise awarene… SANS Internet Storm Center · Jul 9, 2026 Medium BYscanbrute-forcessh
threat-intel Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself A 15-year-old in Japan used an AI chatbot to automatically cancel nearly 47,000 anime streaming subscriptions within hours. Simultaneously, researchers have documented the first fully autonomous, agentic AI-driven ransom… Graham Cluley · Jul 8, 2026 High JPairansomwarecyberattack
threat-intel Mexico's New Cyber Plan Faces Its First Real Test Mexico's National Cybersecurity Plan, designed to bolster the country's digital defenses ahead of the 2026 FIFA World Cup, is facing an early test. Despite the plan's goals – including establishing a National Cybersecuri… Dark Reading · Jul 8, 2026 High MEUNCAcybersecuritylatin americacyberattack
threat-intel Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours A lone attacker successfully breached a large Amazon Web Services (AWS) environment in 72 hours using AI to accelerate reconnaissance, tool development, and command structure, ultimately extorting a global enterprise. Th… Dark Reading · Jul 8, 2026 High aicloudransomware
threat-intel Greek victims file lawsuit against Intellexa over Predator spyware Greek victims are suing Intellexa, the manufacturer of Predator spyware, seeking €7.6 million in compensation for privacy violations and data breaches. The spyware was allegedly used by the Greek government and intellige… The Record · Jul 8, 2026 High GRsurveillancespywareprivacy
threat-intel Cash App owner to pay $45 million to settle allegations of lax security Block, Inc. (Cash App's parent company) will pay $45 million to settle allegations of misleading users about Cash App's security and failing to adequately protect them from fraud. The settlement stems from a lack of prop… The Record · Jul 8, 2026 Medium securityfraudmisleading
threat-intel AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers Sophos researchers discovered that AI coding assistants like Claude Code, Cursor, and OpenAI Codex are triggering traditional endpoint security rules designed to detect malicious activity. These agents, while harmless in… The Hacker News · Jul 8, 2026 Medium aicoding assistantendpoint security
threat-intel Taiwan charges two businessmen over alleged role in Chinese espionage campaign Taiwanese authorities have charged two businessmen for allegedly facilitating a Chinese espionage campaign targeting Taiwanese politicians, academics, journalists, and civil society groups. The suspects operated a compan… The Record · Jul 8, 2026 High CHTAespionagephishingcybercrime
threat-intel Accenture Confirms Data Breach After Hacker Claims Source Code Theft Accenture has confirmed a data breach following claims from a hacker that 35 gigabytes of data, including sensitive credentials and source code, was stolen. The incident involved a threat actor attempting to sell the all… SecurityWeek · Jul 8, 2026 Medium data breachcredential theftsource code
threat-intel China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors A China-linked advanced persistent threat group, UAT-7810, has expanded its arsenal with new backdoors, including LongLeash, DogLeash, and JarLeash, as part of a long-running espionage campaign. The group primarily targe… SecurityWeek · Jul 8, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717CNbackdooraptespionage
threat-intel New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware Researchers at Tel Aviv University have identified a new attack method called ‘HalluSquatting’ that leverages AI coding assistants’ tendency to fabricate names. Attackers register fake software package names that AIs com… The Hacker News · Jul 8, 2026 Medium ISaihallucinationprompt injection
threat-intel Former UK privacy chief preparing legal action against woman who reported him, minister says The former UK Information Commissioner, John Edwards, is preparing to sue a female employee at the Information Commissioner’s Office (ICO) who reported concerns about his behavior. This follows an independent investigati… The Record · Jul 8, 2026 Medium GBsexual_harassmentdata_protectiongovernance
threat-intel Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip Spanish authorities, with assistance from the FBI, arrested a man suspected of aiding pro-Russian hacktivist groups, specifically in facilitating the escape of a Ukrainian hacker linked to CARR. The investigation uncover… The Record · Jul 8, 2026 Medium SPPOBErussianhacktivismddos
threat-intel EU unveils cyber plan to reduce reliance on foreign AI systems The European Commission has unveiled a cybersecurity and AI action plan aimed at reducing the EU’s reliance on foreign AI systems, particularly concerning access to ‘frontier’ AI models. The plan focuses on ensuring cybe… The Record · Jul 8, 2026 Medium EUUKaicybersecurityfrontier ai
threat-intel New Ghost Phishing Wave Is Breaking Traditional Email Security A new phishing technique called ‘ghost phishing’ is emerging, where malicious links appear harmless during initial email inspection but execute a more damaging attack within the victim’s browser. The EvilTokens campaign,… The Hacker News · Jul 8, 2026 High USEUphishingghost phishingmicrosoft 365
threat-intel SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users A new banking fraud operation, tracked as REF6045, is targeting Mexican banks, fintech companies, and cryptocurrency exchanges using a malware toolset called SCMBANKER. The operation leverages fake CAPTCHA verification p… The Hacker News · Jul 8, 2026 High MXbankingmalwarephishing
threat-intel Felons, Fraudsters Flog Offensive Cybersecurity Startup IRIS C2, a cybersecurity startup operating under the Calvexa Group LLC, is aggressively pursuing zero-day vulnerabilities and offensive security capabilities, attracting researchers and exploit developers with lucrative… Krebs on Security · Jul 8, 2026 High UNcybercrimedisinformationvulnerability research
threat-intel GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures A vulnerability has been discovered in GitHub's signature verification process. Attackers can rewrite signed Git commits, creating new commits with the same content but a different hash, while still appearing as "Verifie… The Hacker News · Jul 8, 2026 High gitsignaturevulnerability
threat-intel The Verification Step Is the New ATO Battleground in 2026 The traditional methods of account takeover (ATO) – relying on stolen passwords – are becoming less effective due to the increasing adoption of passkeys and phishing-resistant authentication. Attackers are now shifting t… The Hacker News · Jul 8, 2026 High UNpasskeysgenerative aiaccount takeover