threat-intel GigaWiper Combines Multiple Malware for System-Level Sabotage Microsoft has identified a sophisticated malware strain called GigaWiper, a Go-based backdoor combining multiple destructive capabilities – including a physical disk wiper, ransomware-like encryption, and persistent C&C… SecurityWeek · Jul 10, 2026 High IRbackdoorransomwarewipe
threat-intel "Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th) This phishing email campaign uses a clever technique to evade AI-based email security filters. The attacker employs a large, padded HTML attachment containing a credential-stealing page. The padding itself – a massive bl… SANS Internet Storm Center · Jul 10, 2026 High phishingai evasioncontent classification
threat-intel ISC Stormcast For Friday, July 10th, 2026 https://isc.sans.edu/podcastdetail/10002, (Fri, Jul 10th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in widely used communication… SANS Internet Storm Center · Jul 10, 2026 High phishingvulnerabilityslack
vulnerability Microsoft Reins in RoguePlanet Zero-Day Threat A disgruntled security researcher, known as "Nightmare-Eclipse," published a proof-of-concept exploit (RoguePlanet) for a Windows Defender vulnerability, leading Microsoft to issue an out-of-band patch. The vulnerability… Dark Reading · Jul 9, 2026 High CVE-2026-50656CVE-2026-33825zero-dayprivilege-escalationmicrosoft
threat-intel AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready This article discusses the growing risk posed by AI agents in software development environments and highlights that most organizations are unprepared to manage this new type of identity. Unlike traditional service accoun… Dark Reading · Jul 9, 2026 High aiidentitygovernance
threat-intel New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware Microsoft has uncovered a sophisticated Windows backdoor, dubbed GigaWiper, that combines destructive capabilities with remote control functionality. GigaWiper operates by bundling three separate tools – a disk wiper, a… The Hacker News · Jul 9, 2026 High IRISUKransomwarebackdoordata destruction
threat-intel ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories This week's ThreatsDay highlights a diverse range of cyber threats, from global fraud operations and ransomware tool overlaps to sophisticated social engineering attacks and vulnerabilities in popular software. Key event… The Hacker News · Jul 9, 2026 High CVE-2026-9181CVE-2025-49760CVE-2025-59200CHTAESsocial engineeringphishingransomware
threat-intel As Global Conflicts Go Digital, Businesses Need Wartime Gameplans As global conflicts become increasingly digital, businesses across various sectors are becoming increasingly vulnerable targets for nation-states engaged in warfare. The case of Intellect Services, a Ukrainian tax softwa… Dark Reading · Jul 9, 2026 High UKIRUNcyberwarfarenation-stategeopolitics
vulnerability 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google A 15-year-old Linux kernel vulnerability, dubbed ‘GhostLock,’ has been exploited to earn a security researcher $92,000. The flaw allows for local privilege escalation and container escapes, highlighting the long-term ris… SecurityWeek · Jul 9, 2026 High CVE-2026-43499linuxkernelvulnerability
vulnerability Microsoft Patches Defender ‘RoguePlanet’ Vulnerability Microsoft has released a patch to address a Defender vulnerability, dubbed RoguePlanet, which could allow an attacker to escalate privileges. The vulnerability was initially identified by Nightmare Eclipse (Chaotic Eclip… SecurityWeek · Jul 9, 2026 High CVE-2026-50656CVE-2026-41091CVE-2026-45498vulnerabilitypatchdefender
threat-intel 'GodDamn' Ransomware Uses BYOVD to Smite US Companies The ransomware group Hyadina, operating under the name "GodDamn," is leveraging a Microsoft-approved, malicious kernel driver – dubbed "PoisonX" – to infiltrate US organizations and deploy its ransomware. They utilize a… Dark Reading · Jul 9, 2026 High RUransomwaredriverbyovd
vulnerability Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges Microsoft has patched a critical vulnerability, RoguePlanet, within its Defender antivirus software that could allow attackers to gain SYSTEM-level privileges. This flaw, discovered by Chaotic Eclipse, allows for arbitra… The Hacker News · Jul 9, 2026 Critical CVE-2026-50656CVE-2026-33825CVE-2026-45498vulnerabilityprivilege escalationantivirus
threat-intel GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents Researchers at Wiz discovered a vulnerability (GhostApproval) in six AI coding assistants – Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf – that allows malicious repositor… The Hacker News · Jul 9, 2026 High CVE-2026-12957symlinkaicode injection
threat-intel New Ghost Phishing Wave Is Breaking Traditional Email Security A new phishing technique called ‘ghost phishing’ is emerging, where malicious links appear harmless during initial email inspection but execute a more damaging attack within the victim’s browser. The EvilTokens campaign,… The Hacker News · Jul 8, 2026 High USEUphishingghost phishingmicrosoft 365
threat-intel DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts A Microsoft 365 device code phishing campaign, leveraging collaboration-themed lures, has been observed targeting M365 accounts. The campaign, utilizing a reusable tooling layer called DEBULL, bypasses multi-factor authe… The Hacker News · Jul 7, 2026 High HRTRdevice-codephishingmicrosoft
threat-intel CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker This article profiles Tarah Wheeler, CISO at TPO Group and previously holding leadership roles at Red Queen Technologies and EFF. It highlights her unique background, blending her passion for social science and writing w… SecurityWeek · Jul 7, 2026 Medium CHRUNOsocial sciencehuman behaviorpolicy
threat-intel Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations Iranian hackers, linked to Iran's Ministry of Intelligence and Security (MOIS) and operating under the moniker Cavern Manticore, are utilizing a new, modular command-and-control (C2) framework called ‘Cavern’ to target I… The Hacker News · Jul 6, 2026 High CVE-2025-52691CVE-2025-68613CVE-2025-9316ISIRc2command and controldotnet
threat-intel When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website A sophisticated phishing campaign leveraging the Microsoft Identity Platform's Device Authorization Grant protocol is being used to compromise user accounts. Attackers are crafting emails that appear to be from legitimat… Securelist · Jul 6, 2026 High phishingdevice-code-phishingmicrosoft
ransomware New Avalon Malware Framework Packs CrownX Ransomware Capabilities Researchers at Blackpoint Cyber discovered Avalon, a new modular malware framework used to deploy the CrownX ransomware. The framework utilizes a multi-stage phishing campaign to bypass security controls and performs cre… The Hacker News · Jul 3, 2026 High CVE-2025-3248USphishingcredential theftlateral movement
threat-intel Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer Armored Likho, a previously undocumented threat actor, has been actively targeting government agencies and the power sector in Russia, Brazil, and Kazakhstan with a sophisticated campaign utilizing tools like BusySnake S… The Hacker News · Jul 3, 2026 High CVE-2025-9491RUBRKZspear-phishingremote access trojaninformation stealer