threat-intel GreyVibe hackers use ChatGPT, Gemini to power cyberattacks GreyVibe, a threat actor likely linked to Russia, has been conducting cyber espionage campaigns targeting Ukrainian organizations since August 2025, utilizing a diverse range of custom malware and AI-generated lures. The… BleepingComputer · May 28, 2026 High RUUKaiphishingmalware
threat-intel Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks Google has launched an AI-powered cybersecurity platform, AI Threat Defense, designed to proactively combat increasingly sophisticated cyberattacks leveraging artificial intelligence. This platform utilizes AI to identif… SecurityWeek · May 28, 2026 High GBaicybersecuritythreat detection
malware BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model An advanced Android remote access Trojan, BTMOB RAT, is spreading across Brazil and Latin America through a malware-as-a-service (MaaS) model. Delivered via a no-code interface, it allows cybercriminals to create malicio… Dark Reading · May 28, 2026 High BRARandroidratmaas
threat-intel JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware A previously undocumented threat actor, dubbed JINX-0164, is targeting cryptocurrency firms through sophisticated social engineering tactics and bespoke macOS malware to steal digital assets. The campaign involves luring… The Hacker News · May 28, 2026 High KPmacossocial engineeringcryptocurrency
threat-intel Out of the Crypt: The Evolving Cyber Extortion Economy This report from Palo Alto Unit 42 highlights a significant shift in the cyber extortion landscape, moving away from ransomware-based pressure towards pure data theft and extortion. The trend is driven by factors like ad… Palo Alto Unit 42 · May 27, 2026 High USdata theftextortionsupply chain
threat-intel Ransomware Actors Show Up In Person to Steal Law Firm Data The Silent Ransom Group (SRG), also known as Luna Moth and UNC3753, is targeting law firms through sophisticated social engineering tactics, including impersonating IT personnel and conducting in-person visits to gain ac… Dark Reading · May 27, 2026 High RUsocial engineeringdata theftlaw firms
supply-chain Glassworm botnet disrupted after resilient C2 infrastructure takedown The Glassworm botnet, a supply-chain threat targeting developers, has been significantly disrupted following a coordinated takedown of its resilient command-and-control infrastructure. The botnet utilized a complex archi… BleepingComputer · May 27, 2026 High supply-chainbotnetc2
threat-intel GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure CrowdStrike, in collaboration with Google and Shadowserver Foundation, successfully disrupted the command-and-control infrastructure of the GlassWorm malware campaign, which targeted software developers through compromis… The Hacker News · May 27, 2026 High RUCIsupply chaindeveloperc2
threat-intel 5 Steps to Managing Shadow AI Tools Without Slowing Down Employees This article discusses the growing ‘shadow AI’ gap – where employees use unapproved AI tools connected to corporate data without IT oversight. With 69% of organizations acknowledging this issue, it highlights the disconn… The Hacker News · May 27, 2026 Medium aishadow aioauth
supply-chain ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems The ‘SymJack’ attack leverages AI coding agents as a supply chain delivery mechanism, exploiting developer trust in automation to inject malicious code into CI pipelines. Attackers gain control by compromising coding age… SecurityWeek · May 27, 2026 High USaicoding agentssupply chain
threat-intel GlassWorm Botnet Disrupted The GlassWorm botnet, a persistent threat targeting open-source software developers, has been disrupted by a coordinated effort between CrowdStrike, Google, and the Shadowserver Foundation. The botnet utilized a multi-la… SecurityWeek · May 27, 2026 High RUbotnetopen sourcedeveloper
threat-intel Iranian APT Targets Aviation, Software Companies With Updated Tools The Iranian APT group, known as Nimbus Manticore, has been aggressively updating its tactics and tools to target aviation and software companies globally. The group, linked to Charming Kitten and the IRGC, is employing… SecurityWeek · May 26, 2026 High AEIRSAaptphishingappdomain
threat-intel Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images This article reports on the development of DockSec, an open-source tool designed to address the challenge of vulnerability detection in Docker images. The tool utilizes an LLM to correlate findings from multiple vulnerab… SecurityWeek · May 26, 2026 Medium dockervulnerabilityai
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
data-breach 7-Eleven data breach exposes personal information of 185,000 people 7-Eleven experienced a data breach following a cyberattack by the ShinyHunters extortion gang, exposing the personal information of over 185,000 individuals. The attackers gained access to 7-Eleven’s systems, primarily a… BleepingComputer · May 26, 2026 High DEdata breachsalesforceextortion
threat-intel Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects Anthropic’s Claude Mythos AI model has identified a massive number of vulnerabilities – estimated between 6,200 and 23,000 – across over 1,000 open-source software projects. Many of these vulnerabilities, particularly t… SecurityWeek · May 25, 2026 Critical UKaivulnerabilityopen source
threat-intel Why the Supreme Court's Chatrie case could change the meaning of privacy in America The Supreme Court is considering a case, *Chatrie v. Google*, concerning the legality of geofence warrants, which allow law enforcement to obtain location history data from tech companies like Google. This case, the firs… The Record · May 22, 2026 Medium USgeofencingprivacyfourth amendment
malware Cross-Platform NPM Stealer, (Fri, May 22nd) A cross-platform Node.js stealer has been discovered targeting Windows, macOS, and Linux systems. The malware, obfuscated to avoid detection, extracts sensitive data from various browsers and applications, including Chro… SANS Internet Storm Center · May 22, 2026 High USstealerobfuscatedbrowser
threat-intel Google API Keys Remain Active After Deletion This article details a significant vulnerability in Google Cloud Platform (GCP) API key deletion processes. Researcher Joe Leon of Aikido Security discovered that API keys can remain active for up to 23 minutes after del… Dark Reading · May 21, 2026 High USSGapi keysgcpauthentication
vulnerability Google accidentally exposed details of unfixed Chromium flaw Google inadvertently exposed details of a persistent vulnerability in Chromium, allowing for remote code execution on devices. The flaw, initially reported in December 2022, remained unfixed for over two years, leading t… BleepingComputer · May 21, 2026 High remote-code-executionbrowservulnerability