threat-intel Japanese teen arrested over cyberattack that disrupted anime streaming service A 15-year-old Japanese student was arrested for a cyberattack that disrupted an anime streaming service, Bandai Channel. The suspect exploited a vulnerability in the service’s servers and used ChatGPT to automate the fra… The Record · Jul 6, 2026 Medium JPcyberattackvulnerabilitychatgpt
threat-intel JadePuffer: The First Complete LLM-Driven Ransomware Attack Sysdig researchers have identified ‘JadePuffer,’ the first documented case of a fully autonomous ransomware operation driven by a large language model (LLM). The attack leveraged a Langflow vulnerability to gain initial… Dark Reading · Jul 6, 2026 High CVE-2025-3248airansomwarellm
threat-intel Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure Threat actors have been actively probing a critical vulnerability in Gitea Docker images, exploiting a wildcard configuration that allows unauthenticated access to elevated user accounts. The vulnerability, discovered 13… The Hacker News · Jul 6, 2026 Critical CVE-2026-20896dockervulnerabilityauthentication
threat-intel The Shift Toward Business-Aligned Risk Management This article discusses the shift towards business-aligned risk management within organizations. Traditional risk assessments, often relying on CVSS scores, can be ineffective without connecting them to tangible business… SecurityWeek · Jul 6, 2026 Medium risk managementcybersecurityvulnerability
threat-intel RCS and DNS: The NAPTR Record, (Mon, Jul 6th) This article details the observation of NAPTR records being utilized in RCS (Rich Communication Services) communications, specifically within Verizon’s network. NAPTR records, defined in RFC 2915, are typically used to r… SANS Internet Storm Center · Jul 6, 2026 Medium USrcsdnsnaptr
threat-intel Ukrainian media outlets now among 'priority targets' for Russian hackers Ukrainian media outlets are increasingly becoming priority targets for Russian hackers as part of a broader campaign to undermine public trust and spread propaganda amid Russia’s ongoing invasion of Ukraine. Recent attac… The Record · Jul 6, 2026 High UKRUcyberattacksukrainerussia
threat-intel ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More This week’s security recap highlighted several concerning trends, including a disruption of the NetNut residential proxy network used for botnet operations, a fake Proof-of-Concept (PoC) malware targeting vulnerability r… The Hacker News · Jul 6, 2026 High CVE-2026-48276CVE-2026-48283CVE-2026-48277USESSPbotnetproxymalware
threat-intel Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability A proof-of-concept exploit for a Linux kernel vulnerability, dubbed ‘Bad Epoll,’ has been released, allowing unprivileged processes to gain root access on various devices. The vulnerability stems from a race condition wi… SecurityWeek · Jul 6, 2026 High CVE-2026-46242CVE-2026-43074linuxkernelvulnerability
threat-intel ISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. Specifically, the report… SANS Internet Storm Center · Jul 6, 2026 High icsotindustrial control systems
threat-intel How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions This article discusses the evolving landscape of AI-powered Security Operations Centers (SOCs). It differentiates between ‘bolt-on’ AI solutions, which simply summarize alerts within a traditional SIEM, and true AI SOC p… The Hacker News · Jul 6, 2026 Medium aisocsecurity
threat-intel Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments Threat actors are exploiting prompt injection vulnerabilities in AI agents to trick them into making cryptocurrency payments and promoting fraudulent platforms. Zscaler identified two campaigns utilizing SEO poisoning an… SecurityWeek · Jul 6, 2026 Medium prompt-injectionaicybersecurity
threat-intel Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT A China-nexus threat actor is conducting a targeted phishing campaign against Indian taxpayers and tax professionals, leveraging fake tax filing utilities to deploy a remote access trojan (DcRAT). The campaign, dubbed Op… The Hacker News · Jul 6, 2026 High CHINphishingremote access trojantax
threat-intel France to Stop Certifying Non-Quantum-Safe Encryption France’s cybersecurity agency, ANSSI, is implementing a significant shift in encryption standards. Starting in 2027, they will no longer certify security products that don't offer quantum-resistant encryption, effectivel… Schneier on Security · Jul 6, 2026 Medium FRencryptionquantumcybersecurity
threat-intel When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website A sophisticated phishing campaign leveraging the Microsoft Identity Platform's Device Authorization Grant protocol is being used to compromise user accounts. Attackers are crafting emails that appear to be from legitimat… Securelist · Jul 6, 2026 High phishingdevice-code-phishingmicrosoft
threat-intel New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions Researchers at Shandong University have developed a new technique called TrojPix that allows data to be exfiltrated from air-gapped systems by subtly modulating pixels on a screen and transmitting them as a radio signal.… The Hacker News · Jul 6, 2026 Medium air-gapdata exfiltrationpixel modulation
threat-intel New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS A new Java-based remote access trojan (RAT) called QuimaRAT, offered as a malware-as-a-service (MaaS), has been released by a threat actor. The tool is cross-platform, supporting Windows, Linux, and macOS, and is adverti… The Hacker News · Jul 6, 2026 High javaratmalware-as-a-service
threat-intel Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages A vulnerability in Opera GX allowed malicious websites to silently install browser add-ons that could steal data from visited pages. Researchers demonstrated how a malicious iframe could install a mod, which then injecte… The Hacker News · Jul 6, 2026 High browsercssdata-theft
threat-intel SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing Researchers at the Hong Kong University of Science and Technology have developed a method to bypass AI coding agent scanners by using self-extracting packing and character substitution to disguise malicious skills. Their… The Hacker News · Jul 6, 2026 High aiskillsmalware
threat-intel U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case A U.S. government entity reportedly paid $1 million to the group known as Kairos to prevent the leak of stolen data following a data breach at Union County, Ohio. Kairos, however, operated solely through data theft extor… The Hacker News · Jul 4, 2026 High USRUdatatheftextortionnegotiation
threat-intel North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign North Korean threat actors, linked to the Contagious Interview campaign, have been publishing 108 malicious packages and extensions across platforms like npm, Packagist, and Go, as part of the PolinRider operation. This… The Hacker News · Jul 4, 2026 High KPnorth koreangithubmalware