threat-intel 2026 FIFA World Cup Faces Surge in Cyber Threats The 2026 FIFA World Cup is facing a surge in cyber threats across the US, Canada, and Mexico, driven by a complex threat landscape including financial and nation-state actors. These threats primarily involve social engin… Dark Reading · Jun 24, 2026 High USCAMXcybercrimesocial engineeringfraud
threat-intel Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement A coordinated international effort, led by Microsoft and Europol, successfully dismantled a significant cybercrime-as-a-service infrastructure used by multiple threat actors. The operation resulted in the seizure of subs… The Record · Jun 24, 2026 High RUcybercrime-as-a-servicesupply chaininfostealer
threat-intel Do CISOs Need a Code of Ethics? This article discusses the potential need for a code of ethics for Chief Information Security Officers (CISOs) due to concerns about self-dealing and prioritizing personal gain over organizational security. Robert "RSnak… Dark Reading · Jun 24, 2026 Medium cisoethicsvendor influence
threat-intel When Information Becomes the Attack Surface – Understanding AI Agent Traps This article discusses a new security risk related to AI agents – "traps" – where malicious information can be injected into the data sources an agent uses, leading it to make incorrect decisions or take unintended actio… SecurityWeek · Jun 24, 2026 High aiagentsecurity
threat-intel More Malicious OpenClaw Skills Threaten AI Supply Chain A recent investigation by Palo Alto Networks' Unit 42 revealed five malicious skills hidden within OpenClaw's ClawHub marketplace, a platform for AI agent skills. These skills, including infostealers, detection evasion t… Dark Reading · Jun 24, 2026 High USaisupply chaininfostealer
threat-intel Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk This article discusses the limitations of current vulnerability triage methods (SBOMs, VEX, and CVSS) in addressing supply chain attacks, particularly in the context of increasingly complex AI-driven systems. The author,… SecurityWeek · Jun 24, 2026 High supply chainaiautonomous robots
threat-intel Securing the service desk: Why social engineering attacks keep succeeding This article highlights the ongoing success of social engineering attacks against corporate service desks, particularly by groups like Scattered Spider and the Silent Ransom Group. Attackers exploit the trust and helpful… BleepingComputer · Jun 24, 2026 High UKsocial engineeringservice deskcredential theft
threat-intel ESET takes part in Operation Endgame to disrupt Amadey and Stealc ESET, in collaboration with Microsoft DCU and other partners, successfully disrupted the Amadey and Stealc botnets as part of Operation Endgame. These botnets, sold as a service on darknet forums, utilize a MaaS model wh… WeLiveSecurity · Jun 24, 2026 High maasbotnetdarknet
threat-intel Apple's MacOS Gap Lets Users Disable Security Tools This article details a macOS security vulnerability discovered by XM Cyber that allows standard users to disable enterprise security tools like CrowdStrike Falcon EDR and Kandji MDM without administrator privileges. The… Dark Reading · Jun 24, 2026 High CVE-2026-39118USmacosxpccdhash
threat-intel Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed This SecurityWeek article highlights the critical importance of accurate context for agentic AI systems, particularly in security applications. The piece explains that agentic AI, relying on speed and automation, can mak… SecurityWeek · Jun 24, 2026 High USGBagentic aillmcontext
threat-intel Dawn of the Apex Agentic Adversary This article discusses a significant shift in cybersecurity driven by the emergence of "agentic" AI models capable of rapidly discovering and exploiting vulnerabilities at speeds far exceeding human capabilities. The ris… The Hacker News · Jun 24, 2026 Critical aiautomationcybersecurity
threat-intel Stealthy Mistic backdoor linked to ransomware access broker KongTuke A new stealthy backdoor, dubbed Mistic, has been identified as a tool used by the initial access broker KongTuke to facilitate ransomware attacks against organizations in the insurance, education, IT, and professional se… BleepingComputer · Jun 24, 2026 High USbackdoorinitial accessransomware
threat-intel StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader A new malware family, named SharkLoader, has been identified as part of a broader campaign targeting organizations globally, including diplomatic entities, government organizations, and software development companies. Th… Securelist · Jun 24, 2026 Medium CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikeexploitloader
threat-intel DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering The U.S. Department of Justice seized a cloud computing account belonging to HuiOne Group subsidiaries, following an investigation into their role in facilitating cryptocurrency-based cyber scams and money laundering ope… The Hacker News · Jun 24, 2026 Critical CACHUScryptocurrencyfraudmoney laundering
threat-intel Linux Process Name Masquerading, (Wed, Jun 24th) This SANS Internet Storm Center diary details a technique used by attackers, specifically the Velvet Ant Chinese group, to mask process names in Linux systems. Attackers modify the ‘comm’ and ‘cmdline’ entries in the /pr… SANS Internet Storm Center · Jun 24, 2026 Medium CHprocess_namemasqueradinglinux
threat-intel Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says Anthropic’s Mythos AI model identified vulnerabilities within several U.S. government computer systems during a testing exercise conducted in collaboration with intelligence agencies. While the model quickly detected wea… SecurityWeek · Jun 24, 2026 High UNaivulnerabilitysecurity
threat-intel ISC Stormcast For Wednesday, June 24th, 2026 https://isc.sans.edu/podcastdetail/9984, (Wed, Jun 24th) The SANS Internet Storm Center's Stormcast for June 24th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The broadcast detailed ongoing campaigns involving phishing attack… SANS Internet Storm Center · Jun 24, 2026 Medium phishingmalwarethreat-intelligence
threat-intel Windows 11 KB5095093 update rolls out new Point-in-Time restore feature This article reports on the release of Microsoft's KB5095093 preview cumulative update for Windows 11, introducing a new Point-in-Time Restore feature. The update focuses on enhancing system reliability and usability, al… BleepingComputer · Jun 23, 2026 Low windows 11point-in-time restorefeature update
threat-intel Five Eyes agencies sound alarm about AI’s threat to cybersecurity Five Eyes intelligence agencies are issuing a stark warning about the rapidly escalating threat posed by artificial intelligence (AI) to cybersecurity. They believe AI will dramatically accelerate both offensive and defe… The Record · Jun 23, 2026 High USUKCAaicybersecuritythreat intelligence
threat-intel FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation A Russian-speaking threat actor, dubbed FortiBleed, is conducting a large-scale credential harvesting operation targeting over 430,000 FortiGate firewalls globally. The campaign, active since February 2026, utilizes a Go… The Hacker News · Jun 23, 2026 High USINRUcredential harvestingfirewallactive directory