threat-intel UK cyber pledge draws only a handful of top firms despite ministerial appeal Despite a strong push from the UK government, only a small number of companies – around 15 out of 350 – signed the Cyber Resilience Pledge. The pledge, designed to improve cybersecurity across the UK economy, requires co… The Record · Jul 7, 2026 Medium UKcybersecuritycyber resiliencevoluntary pledge
threat-intel Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud Two men were arrested in the Netherlands on suspicion of running a phishing operation targeting credit card details, leading to a significant increase in payment fraud within the country. The Dutch central bank reported… Graham Cluley · Jul 7, 2026 High NLEUphishingcredit card fraudcybercrime
threat-intel Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks An Iran-linked APT group, known as Cavern Manticore, is utilizing a sophisticated, AI-assisted modular command-and-control framework to target organizations in Israel, particularly government entities and IT providers. T… SecurityWeek · Jul 7, 2026 High ILaptcommand and controllateral movement
threat-intel Labcenter Proteus 9 CISA has issued an advisory regarding critical vulnerabilities in Labcenter Proteus 9, a software used in critical infrastructure sectors such as communications, defense industrial base, and energy. These vulnerabilities… CISA Advisories · Jul 7, 2026 High CVE-2026-42953CVE-2026-49033CVE-2026-42958vulnerabilityremote code executioncritical infrastructure
threat-intel CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker This article profiles Tarah Wheeler, CISO at TPO Group and previously holding leadership roles at Red Queen Technologies and EFF. It highlights her unique background, blending her passion for social science and writing w… SecurityWeek · Jul 7, 2026 Medium CHRUNOsocial sciencehuman behaviorpolicy
threat-intel Siemens SINEC OS Siemens has released a security advisory regarding multiple vulnerabilities within its SINEC OS and related products, including the RUGGEDCOM RST2428P. These vulnerabilities, ranging from stack-based buffer overflows to… CISA Advisories · Jul 7, 2026 High CVE-2025-1352CVE-2025-1376CVE-2025-6052vulnerabilitybuffer overflowpath traversal
threat-intel What Changes When Your Software Supply Chain Includes AI Writing Your Code? The increasing use of AI tools in software development is significantly altering the landscape of software supply chain security. Traditionally, security focused on the code a team directly wrote, but now, AI-generated c… The Hacker News · Jul 7, 2026 Medium aisoftware supply chainautomation
threat-intel Google Is Suing Chinese Scammers Who Are Using Gemini Google is taking legal action against a Chinese group, Outsider Enterprise, who were leveraging Google's Gemini AI to create sophisticated phishing campaigns. The group utilized Telegram to offer ‘phishing-as-a-service,’… Schneier on Security · Jul 7, 2026 Medium CNphishingaigemini
threat-intel Threat landscape for industrial automation systems. Q1 2026 In Q1 2026, the effectiveness of blocking malicious objects on industrial control systems (ICS) decreased significantly, reaching 19.6%, a three-year low. Growth in blocked threats was most pronounced in Southern Europe… Securelist · Jul 7, 2026 Medium UNRUSOicsindustrial control systemsmalware
threat-intel UAT-7810 continues building ORB networks using new malware Cisco Talos Intelligence has identified UAT-7810, a China-nexus APT group, continuing to develop and deploy malware as part of its Operational Relay Box (ORB) network. The group is actively creating new malware variants,… Cisco Talos · Jul 7, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717CHaptmalwarechina
threat-intel Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems A long-standing Linux kernel vulnerability, dubbed Januscape (CVE-2026-53359), has been discovered that allows attackers to escape virtual machines and gain root access on the underlying host. This flaw, dormant for 16 y… SecurityWeek · Jul 7, 2026 Critical CVE-2026-53359linuxkernelvm
threat-intel Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security Keyfactor, a cybersecurity firm specializing in cryptographic security and machine identity management, has secured over $1 billion in investment to bolster its growth and address the increasing need for post-quantum cry… SecurityWeek · Jul 7, 2026 Medium machine identitiespost-quantumcryptography
threat-intel Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities A China-aligned threat actor cluster, tracked as UNC5174 and linked to ShadowPad, has been exploiting vulnerabilities in Roundcube webmail software at U.S. and Canadian universities. The campaign leverages CVE-2024-42009… The Hacker News · Jul 7, 2026 High CVE-2024-42009CVE-2025-49113CHUSCAroundcubexsscve-2024-42009
threat-intel BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA BeyondTrust has released patches to address critical security vulnerabilities in its Remote Support and Privileged Remote Access products. These flaws, if exploited, could allow unauthenticated attackers to gain unauthor… The Hacker News · Jul 7, 2026 Critical CVE-2026-40138CVE-2026-40139CVE-2026-40140vulnerabilityauthenticationremote access
threat-intel ISC Stormcast For Tuesday, July 7th, 2026 https://isc.sans.edu/podcastdetail/9996, (Tue, Jul 7th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. The report indicated a s… SANS Internet Storm Center · Jul 7, 2026 High icsotvulnerability
threat-intel 'BusySnake' Infostealer Slithers into Critical Infrastructure Networks The threat group Armored Likho, operating under the name 'BusySnake,' has infiltrated critical infrastructure networks across Russia, Brazil, and Kazakhstan. This group is leveraging a sophisticated infostealer to steal… Dark Reading · Jul 6, 2026 High RUBRKZinfostealercritical infrastructurenation-state
threat-intel Canadian spy agency reports hacking three criminal groups in 2025 The Canadian Communications Security Establishment (CSE) conducted several authorized cyber operations targeting foreign criminal groups in 2025. These operations aimed to disrupt extremist groups spreading violent ideol… The Record · Jul 6, 2026 Medium CAcybersecuritynational securitycyber espionage
threat-intel Attackers vote themselves $20 million in BONK cryptocurrency Attackers exploited a governance mechanism within the decentralized finance project overseeing BONK cryptocurrency, draining $20 million worth of the token. This was achieved through a malicious governance proposal, leve… The Record · Jul 6, 2026 High KRdaogovernancecryptocurrency
threat-intel Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks Securonix researchers identified a complex malware delivery framework called ‘Veil#Drop’ that utilizes compromised websites, specifically Blogspot, to deploy information-stealing malware. The framework employs multiple l… SecurityWeek · Jul 6, 2026 High malwareinformation stealerevasion
threat-intel Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations Iranian hackers, linked to Iran's Ministry of Intelligence and Security (MOIS) and operating under the moniker Cavern Manticore, are utilizing a new, modular command-and-control (C2) framework called ‘Cavern’ to target I… The Hacker News · Jul 6, 2026 High CVE-2025-52691CVE-2025-68613CVE-2025-9316ISIRc2command and controldotnet