threat-intel In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting This report details several significant cybersecurity events across multiple sectors, including a Canadian hacker’s imprisonment for a Texas GOP cyberattack, a large KDDI data breach impacting 14 million users, and the d… SecurityWeek · Jul 3, 2026 High CAJAUNzero-dayhacktivismdata breach
threat-intel Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer Armored Likho, a previously undocumented threat actor, has been actively targeting government agencies and the power sector in Russia, Brazil, and Kazakhstan with a sophisticated campaign utilizing tools like BusySnake S… The Hacker News · Jul 3, 2026 High CVE-2025-9491RUBRKZspear-phishingremote access trojaninformation stealer
threat-intel Chinese LLMs Broaden the Gap Between Attackers & Defenders This article reports on the emergence of new Chinese AI models, GLM 5.2 and Tulongfeng (Dragon Saber), which are demonstrating strong performance in vulnerability discovery, rivaling leading US models like Opus and GPT-5… Dark Reading · Jul 3, 2026 High CHUSaivulnerabilitychina
threat-intel Cyber readiness for SMBs: Getting the basics right This article highlights the ongoing importance of traditional cybersecurity threats for small and medium-sized businesses (SMBs), despite growing concerns about AI-powered attacks. The primary risks remain phishing, unpa… WeLiveSecurity · Jul 3, 2026 Medium USphishingvulnerabilityai
threat-intel European Parliament Member Investigating Spyware Was Hacked With Pegasus A report by Citizen Lab revealed that former European Parliament member Stelios Kouloglou was repeatedly hacked with the Pegasus spyware while investigating the use of commercial surveillance tools, including Pegasus. Th… The Hacker News · Jul 3, 2026 High UKGRRUspywarepegasusapple
threat-intel Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign The Securelist report details a new cyber espionage campaign conducted by the Armored Likho (Eagle Werewolf) APT group, targeting government agencies and the electric power sector globally. The group utilizes a sophistic… Securelist · Jul 3, 2026 High RUBRKZaptphishinginfostealer
threat-intel Spyware found on phone of European Parliament member probing it A former European Parliament member, Stelios Kouloglou, was repeatedly targeted with Pegasus spyware while investigating the misuse of commercial spyware. Citizen Lab researchers discovered the infections occurred during… The Record · Jul 3, 2026 High GRDERUspywarepegasuseuropean parliament
threat-intel Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs A recent Australian Institute of Criminology survey revealed a decrease in overall cybercrime incidents and financial losses experienced by Australians in 2025 compared to 2024. However, this positive trend was largely d… Dark Reading · Jul 2, 2026 Medium AUsmbcybercrimeaustralia
threat-intel How We Added WebAuthn to a Browser-Based RDP Client This Palo Alto Unit 42 article details the development of a browser-based RDP client that supports WebAuthn redirection, allowing users to utilize security keys like YubiKeys during remote sessions. The team overcame sig… Palo Alto Unit 42 · Jul 2, 2026 Medium webauthnrdpbrowser
threat-intel Launch of UK's National Cyber Action Plan delayed amid Labour leadership crisis The UK’s National Cyber Action Plan, intended to bolster the nation’s defenses against cyber threats, has been delayed again due to ongoing political instability within the Labour Party following Prime Minister Keir Star… The Record · Jul 2, 2026 High UKcybersecurityukpolitical delay
threat-intel Apple Reverses Age-Old Patch Policy to Keep Up With AI Apple is shifting its security patching strategy to a more frequent, independent release model in response to the accelerating pace of AI-driven attacks. Historically, Apple bundled security updates with major OS release… Dark Reading · Jul 2, 2026 High USaizero-daypatching
threat-intel FBI Seizes NetNut Proxy Platform, Popa Botnet The FBI, in collaboration with industry partners including Google and Lumen, has seized hundreds of domains associated with NetNut, a residential proxy service operated by Alarum Technologies, following findings linking… Krebs on Security · Jul 2, 2026 High USproxybotnetresidential proxy
threat-intel Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices Google, in collaboration with the FBI and Lumen, has significantly reduced the size of the NetNut residential proxy network, which utilizes millions of home devices worldwide as relays for internet traffic. This network,… The Hacker News · Jul 2, 2026 High ISCHproxyresidentialbotnet
threat-intel Catan and Mouse This Cisco Talos Threat Source newsletter highlights the emergence of ARToken, a sophisticated phishing-as-a-service (PhaaS) platform with capabilities previously undocumented. The platform, similar to EvilTokens, offers… Cisco Talos · Jul 2, 2026 High CVE-2026-48558USphishingbecai
threat-intel Supreme Court decision threatens EU-US data transfer agreement A Supreme Court ruling questioning the independence of the U.S. Federal Trade Commission (FTC) poses a significant threat to the EU-U.S. Data Privacy Framework (DPF), a key agreement enabling data transfers between the t… The Record · Jul 2, 2026 High USEUdataprotectionprivacyeu-us
threat-intel ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories This week’s security news highlights several vulnerabilities and ongoing threats across various sectors. A phishing campaign targeting small businesses globally with ransomware, a root escape vulnerability in Claude Cowo… The Hacker News · Jul 2, 2026 High CVE-2026-33825CHUNGEphishingransomwaresandbox
threat-intel How to Conduct a Successful Audit of AI-Driven Software Development This SecurityWeek article discusses the need for a new type of audit – an ‘agentic development lifecycle’ (ADLC) audit – to address the security risks introduced by AI-driven software development, particularly large lang… SecurityWeek · Jul 2, 2026 Medium aillmsoftware security
threat-intel ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API The ToddyCat APT group is utilizing a new malware, Umbrij, to gain unauthorized access to Gmail accounts via the Google API. Umbrij leverages the OAuth 2.0 protocol to obtain access tokens, allowing attackers to control… The Hacker News · Jul 2, 2026 High RUoauthgoogle apiheadless browser
threat-intel Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. This article reports on a significant investment by IBM and Red Hat into Project Lightwell, a new service designed to address the growing challenge of securing open-source software supply chains. Driven by Anthropic's My… Dark Reading · Jul 2, 2026 High USaivulnerabilityopen source
threat-intel Gardyn IoT Hub This advisory details a vulnerability within the Gardyn IoT Hub, specifically versions prior to 2.12.2026, that allows unauthenticated users to potentially gain control of connected devices. The vulnerability stems from… CISA Advisories · Jul 2, 2026 Critical CVE-2026-13768CVE-2026-55726CVE-2026-54477USiotvulnerabilitycommand execution