threat-intel UK government seeks powers to secretly block risky tech suppliers The UK government is seeking new powers to secretly block technology suppliers deemed to pose a national security risk, particularly to critical sectors like energy, water, and transport. These powers, modeled after thos… The Record · 5d ago High UKnational securitycybersecurityvendor risk
threat-intel A Tale of Two SOCs: Insights From Two Red Team Assessments Two separate red team assessments at a Government Services and Facilities Sector organization (Organization A) and a Water and Wastewater Systems Sector organization (Organization B) revealed significant vulnerabilities… CISA Advisories · 5d ago High credential abuseactive directorymicrosoft
threat-intel Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows The Mirage2FA campaign, a commercial phishing-as-a-service toolkit, has impacted approximately 4,532 organizations, primarily in the US, by exploiting legitimate Microsoft 365 login flows and bypassing two-factor authent… The Hacker News · 5d ago High USINSGphishingmicrosoftmfa
threat-intel 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Researchers at OX Security discovered a campaign utilizing 24 npm packages to host fake Cloudflare CAPTCHA pages via unpkg mirrors, redirecting users to phishing infrastructure. The threat actors are leveraging npm's inf… The Hacker News · 5d ago High npmphishingmalware
threat-intel E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands Threat actors are utilizing FTP banner responses as dead drop resolvers to deliver two new remote access trojans, E4del and PINHOLE RAT. E4del, a Node.js-based RAT, employs a dynamic beaconing system to blend in with net… The Hacker News · 5d ago High UNdvrftpremote access trojan
threat-intel First Malware Built Specifically for Car Head Units Fuels Botnet Researchers at Kaspersky have identified a new malware specifically designed for car head units, linked to the BadBox botnet. This represents a significant expansion of the BadBox threat, which has previously targeted An… SecurityWeek · 5d ago High CNbotnetmalwaresupply-chain
threat-intel Frontier AI: Vulnerability Management's Systemic Revolution This article discusses how the rapid advancements in Frontier AI models, like those developed by Anthropic, are forcing vulnerability management programs to undergo a significant transformation. Traditional vulnerability… The Hacker News · 5d ago High vulnerability managementfrontier aicybersecurity
threat-intel Black Hat State of Security Vendors Black Hat 2023 showcased a significant shift in the security vendor landscape, driven by the increasing influence of AI. Vendors are now heavily emphasizing AI-powered solutions, though a notable number continue to focus… Schneier on Security · 5d ago Medium aisecurityvendors
threat-intel The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution A recent analysis by Palo Alto Unit 42 found that while a significant number of AI-enabled malware samples exist in research and testing environments, only a small fraction (around 12) reached production endpoints across… Palo Alto Unit 42 · 5d ago Medium USCNGBaimalwarethreat intelligence
threat-intel The safety penalty: Reclaiming operational sovereignty in the age of AI As AI models become more powerful, their built-in safety mechanisms are increasingly causing friction for security teams, leading to a "safety penalty" where analysts are forced to redo work that a model refuses to compl… Cisco Talos · 5d ago High aifrontier-modelsguardrails
threat-intel Silent Patches Don’t Stop Attackers—They Blind Defenders Broadcom’s new program offering early access to CVE-only patches for Spring Framework users is exacerbating the problem of silent patching. While Broadcom continues to issue CVEs, the program effectively provides pre-ale… SecurityWeek · 5d ago High silent patchingvulnerability disclosureai-driven vulnerability
threat-intel Crooks push Mac malware through fake OpenAI Codex ads Russian threat actors are leveraging fake OpenAI Codex advertisements to distribute malware targeting macOS users. The campaign uses a malicious installer disguised as a legitimate tool, aiming to compromise systems and… The Register · 5d ago Medium RUmacphishingmalware
threat-intel US sanctions Iranian cyber actors as UK discloses power plant attack The U.S. has sanctioned several Iranian nationals linked to a hacking operation targeting U.S. critical infrastructure, following a recent cyberattack on a small power plant in the UK. This escalation highlights Iran's c… The Record · 6d ago High IRUNUKcyberattackcritical infrastructureiran
threat-intel You don't want this Sleepwalker backdoor on your Windows machine A previously unknown backdoor, dubbed ‘Sleepwalker,’ has been discovered in Nvidia’s drivers for Windows machines. This backdoor allows attackers to remotely execute code on vulnerable systems, potentially leading to ful… The Register · 6d ago High backdoorvulnerabilitynvidia
threat-intel Foul Language: WordlistLoader Disguises Malware as Ordinary Text A new malware loader called WordlistLoader is being used to deliver the Amatera infostealer, primarily through ClickFix-style campaigns. WordlistLoader disguises malicious code using lists of ordinary English words, allo… Dark Reading · 6d ago High malwareloaderinfostealer
threat-intel Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly An Indian man, Jay Sunilbharthi Goswami, has been arrested on charges of aiding overseas cyberscammers who defrauded elderly New Yorkers out of $7.5 million. Goswami acted as a money mule, receiving instructions and tran… The Record · 6d ago High INCAUSmoney mulescamcybercrime
threat-intel Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning Cybersecurity researchers at McAfee Labs have identified a campaign where malicious websites disguised as legitimate Minecraft clients are distributing the Weedhack malware. These sites, leveraging SEO poisoning and mimi… The Hacker News · 6d ago Medium seo poisoningmalwareminecraft
threat-intel ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited ReliaQuest was targeted by the ShinyHunters group through a sophisticated phishing campaign mimicking security employees to gain access to an Okta dashboard. While the attackers gained temporary view-only access, they we… SecurityWeek · 6d ago Medium phishingsocial engineeringokta
threat-intel Iran-linked cyberattack shut down a UK power plant A cyberattack linked to Iran has successfully taken down a UK power plant control system. The attack exploited vulnerabilities in the system, allowing attackers to gain unauthorized access and disrupt operations. This hi… The Register · 6d ago High UKIRcyberattackcritical infrastructureiran
threat-intel Tricky 'SynkLoader' Multitool May Herald Ransomware A sophisticated new malware family, dubbed ‘SynkLoader,’ is making a comeback of older, effective tactics, including screen locking and phishing, to facilitate ransomware attacks. The malware utilizes a combination of no… Dark Reading · 6d ago High phishingransomwarescreen-locking