threat-intel FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks The FBI has seized hacking tools believed to have been used by Chinese state actors to target critical US infrastructure, including NASA, the Department of Energy, and the US Senate. These tools were used to conduct reco… The Register · 3d ago High CVE-2019-11510CVE-2019-19781CHcyber espionagestate-sponsoredcritical infrastructure
threat-intel OpenAI explains how its AI agents did crime and attacked Hugging Face This article doesn't present a specific security incident but rather highlights a broader trend of security vulnerabilities and exploits within open-source software and related technologies. It touches on themes of open-… The Register · 3d ago Medium vulnerabilityopen-sourceexploit
threat-intel Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th) This article from the SANS Internet Storm Center details a PowerShell script used to analyze Entra ID Directory roles and identify users with administrative privileges. The script lists each role and the number of users… SANS Internet Storm Center · 4d ago Medium entradirectoryadminrightssecurityaudit
threat-intel NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions A new phishing toolkit called NovaCookies is being used to steal Microsoft 365 sessions by abusing legitimate Docusign notifications and mimicking genuine email shares. Developed by an adversary-in-the-middle (AitM) oper… The Hacker News · 4d ago High USUKCAphishingaitmmicrosoft 365
threat-intel Nigeria Looks to Sovereign Cloud for Cyber, National Security Nigeria is pursuing a sovereign cloud initiative to bolster its national cybersecurity, economic development, and technological independence. Driven by increasing cyberattacks and a desire to reduce reliance on foreign c… Dark Reading · 4d ago Medium NGsovereign cloudcybersecuritydata residency
threat-intel Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation The Linux Foundation will manage TRACE, a new open standard for verifying the behavior of AI agents and confidential workloads. Developed collaboratively by AMD, Intel, Microsoft, and the Technology Innovation Institute,… SecurityWeek · 5d ago Medium aiconfidential computingtrust
vulnerability You could've applied all 1,449 Oracle patches and still been hit by this attack A zero-day vulnerability in on-prem SharePoint, stemming from improperly applied patches, is being exploited by attackers. Despite applying 1,449 Oracle patches, attackers successfully leveraged this flaw to gain unautho… The Register · 5d ago High UNzero-dayvulnerabilitysharepoint
threat-intel A Tale of Two SOCs: Insights From Two Red Team Assessments Two separate red team assessments at a Government Services and Facilities Sector organization (Organization A) and a Water and Wastewater Systems Sector organization (Organization B) revealed significant vulnerabilities… CISA Advisories · 5d ago High credential abuseactive directorymicrosoft
threat-intel Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows The Mirage2FA campaign, a commercial phishing-as-a-service toolkit, has impacted approximately 4,532 organizations, primarily in the US, by exploiting legitimate Microsoft 365 login flows and bypassing two-factor authent… The Hacker News · 5d ago High USINSGphishingmicrosoftmfa
threat-intel E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands Threat actors are utilizing FTP banner responses as dead drop resolvers to deliver two new remote access trojans, E4del and PINHOLE RAT. E4del, a Node.js-based RAT, employs a dynamic beaconing system to blend in with net… The Hacker News · 5d ago High UNdvrftpremote access trojan
threat-intel Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly An Indian man, Jay Sunilbharthi Goswami, has been arrested on charges of aiding overseas cyberscammers who defrauded elderly New Yorkers out of $7.5 million. Goswami acted as a money mule, receiving instructions and tran… The Record · 5d ago High INCAUSmoney mulescamcybercrime
threat-intel Iran-linked cyberattack shut down a UK power plant A cyberattack linked to Iran has successfully taken down a UK power plant control system. The attack exploited vulnerabilities in the system, allowing attackers to gain unauthorized access and disrupt operations. This hi… The Register · 6d ago High UKIRcyberattackcritical infrastructureiran
threat-intel Tricky 'SynkLoader' Multitool May Herald Ransomware A sophisticated new malware family, dubbed ‘SynkLoader,’ is making a comeback of older, effective tactics, including screen locking and phishing, to facilitate ransomware attacks. The malware utilizes a combination of no… Dark Reading · 6d ago High phishingransomwarescreen-locking
threat-intel WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords Two new malware families, WordlistLoader and SynkLoader, are being used to deliver the Amatera Stealer via ClickFix phishing campaigns. WordlistLoader reconstructs shellcode for Amatera, utilizing techniques to evade det… The Hacker News · 6d ago High phishingransomwaremalware
threat-intel Security vets rally around $4 paper password books for sale in Australia This article is a collection of snippets from The Register, covering a range of cybersecurity and technology news. It highlights a vulnerability impacting Joomla websites through exploited extensions, a Microsoft SharePo… The Register · 6d ago Medium CHvulnerabilityphishingransomware
threat-intel UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit The Chinese-speaking cybercrime group UAT-10147 is aggressively targeting web servers globally, leveraging AI-powered tools to automate intrusion operations and establish persistent access. They utilize a new cross-platf… The Hacker News · 6d ago High CVE-2022-0995CVE-2021-3156CVE-2015-5287CHBRBOairansomwaremalware
threat-intel Cyber actualités ZATAZ de la semaine du 17 au 23 août 2026 This week’s cybersecurity news is dominated by data breaches, ransomware attacks, and widespread data exposures. ShinyHunters is targeting Logitech and Streamlabs, while RingCentral has experienced a massive 1.6 million… ZATAZ · Aug 22, 2026 High FRBESOransomwaredata breachvpn
threat-intel AWS Security makes an inscrutable choice This article is a collection of security-related news snippets from The Register. It highlights a range of issues, including a phishing campaign impersonating Signal support, a zero-day vulnerability in on-prem SharePoin… The Register · Aug 21, 2026 Medium IRphishingzero-dayransomware
threat-intel OWASP Flags Top AI Skill Risks in New Security Blueprint The OWASP has released a new top 10 list focusing on security risks associated with "skills" – essentially, scripts that add functionality to agentic AI platforms. The primary risk is malicious skills, often introduced t… Dark Reading · Aug 21, 2026 High aiskillsagentic ai
threat-intel Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot Check Point Research has discovered a method to weaponize Microsoft Defender's own built-in boot-time remediation driver (BTR.sys) to delete security software and manipulate Windows systems. This technique, dubbed ‘BTR R… The Hacker News · Aug 21, 2026 High CVE-2021-24092driverbootremediation