threat-intel PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network PCPJack, a threat actor initially linked to TeamPCP, has established a covert SMTP email relay network by hijacking 230 cloud servers across AWS, Google Cloud, and Azure. The operation involved converting business server… The Hacker News · Jun 5, 2026 High USUKDEsmtp relaycloud proxyc2
threat-intel Reporting from Vegas: Networking, AI, and good boys This Cisco Talos Threat Source newsletter highlights the ongoing challenges of managing data at scale in an AI-driven world, particularly during large technology conferences like Cisco Live. It details Talos’ expansion o… Cisco Talos · Jun 4, 2026 High USRUaithreat huntingc2
threat-intel Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process A security researcher, Ammar Askar, released a GitHub token-stealing exploit for Microsoft's VS Code, citing frustration with the company's vulnerability disclosure process. This follows a recent breach of GitHub reposit… The Record · Jun 4, 2026 High githubvulnerabilitydisclosure
threat-intel Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months An unknown attacker gained unauthorized access to the Outlook mailbox of a senior executive at a major stock exchange for over five months, copying the inbox in small batches and utilizing cloud services like Dropbox and… The Hacker News · Jun 4, 2026 High USespionagemailboxcloud
threat-intel DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets The U.S. Department of Justice, in collaboration with numerous international law enforcement agencies and private sector companies, disrupted a network of cybercrime groups operating out of Southeast Asia that were defra… The Hacker News · Jun 4, 2026 High USTHAUcryptocurrencyfraudscam
apt Pakistan Spies on Afghan Finance Ministry With Xeno RAT A Pakistani advanced persistent threat (APT) group, identified as SideCopy and linked to the Transparent Tribe (APT 36), has been conducting espionage against Afghanistan's finance ministry since at least May 2025. The g… Dark Reading · Jun 4, 2026 High AFPKspear-phishingremote-accesspashto
threat-intel Chinese hackers use new Atlas RAT malware in European cyberattacks A Chinese cybercrime group, tracked as TA4922, is expanding its operations with the deployment of new malware, including the Atlas RAT and RomulusLoader, targeting organizations across Europe and Southeast Asia. The grou… BleepingComputer · Jun 3, 2026 High CHGEITphishingremote access trojanmalware loader
threat-intel Tropical Blend: Cyber & Politics Ramp Up Across Latin America This report details a surge in cyber espionage activities targeting Latin American nations, primarily driven by China-linked Advanced Persistent Threat (APT) groups. These groups, including FamousSparrow and NegativeGlim… Dark Reading · Jun 3, 2026 High CHVEPAaptcyber espionagelatin america
ddos New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute A new denial-of-service (DoS) attack, dubbed ‘HTTP/2 Bomb,’ has been identified that can cripple web servers within seconds by exploiting vulnerabilities in default HTTP/2 configurations of popular web servers like Nginx… BleepingComputer · Jun 3, 2026 High CVE-2026-49975doshttp2compression
threat-intel Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover A coding error in several Microsoft 365 Android applications, specifically Excel, Word, PowerPoint, OneNote, Loop, and Microsoft 365 Copilot, exposed user accounts to potential compromise. The issue stemmed from a disabl… Dark Reading · Jun 3, 2026 High CVE-2026-41100CVE-2026-41101CVE-2026-41102authenticationtokensandroid
vulnerability Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag A vulnerability in Microsoft 365 Android apps allowed unauthorized apps to steal user account tokens, potentially granting access to sensitive data like emails and calendar information. The flaw, discovered by Enclave, s… The Hacker News · Jun 3, 2026 High CVE-2026-41100CVE-2026-41101CVE-2026-41102androidtokenspoofing
threat-intel ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds A new ‘HTTP/2 Bomb’ exploit has been discovered that leverages existing vulnerabilities in HTTP/2 implementations to cause widespread denial-of-service attacks against web servers. The exploit combines compression and fl… SecurityWeek · Jun 3, 2026 High CVE-2016-6581CVE-2025-53020CVE-2016-8740USdoshttp2compression
threat-intel Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash This article reports on a controversy between Microsoft and a security researcher, known as Nightmare Eclipse, regarding the disclosure of several zero-day vulnerabilities affecting Microsoft products. Microsoft initiall… SecurityWeek · Jun 3, 2026 High CVE-2026-41091CVE-2026-45498CVE-2026-33825USzero-dayvulnerability disclosurelegal action
ddos New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare Researchers have identified a new HTTP/2 bomb vulnerability affecting web servers like NGINX, Apache, and IIS, allowing for remote denial-of-service attacks. The exploit leverages header compression and connection manage… The Hacker News · Jun 3, 2026 High CVE-2016-6581CVE-2025-53020CVE-2016-8740http2compressiondos
vulnerability VS Code zero-day lets hackers steal GitHub tokens in one click A researcher, Ammar Askar, has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link. The vulne… BleepingComputer · Jun 3, 2026 High zero-daygithubvscode
threat-intel Microsoft's Coreutils project brings Linux commands to Windows Microsoft has released Coreutils for Windows, a project bringing commonly used Linux command-line utilities to Windows as native applications. Based on the uutils open-source project, this aims to simplify development wo… BleepingComputer · Jun 2, 2026 Low linuxwindowscommand-line
threat-intel FBI-Flagged Phishing Kit Kali365 Expands Its Reach The Kali365 phishing-as-a-service platform, initially focused on compromising Microsoft 365 accounts via MFA bypass, has significantly expanded its capabilities and target list. It now actively targets platforms like AWS… Dark Reading · Jun 2, 2026 High USRUphishingdevice-codemfa
threat-intel DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks A sophisticated cybercriminal operation, dubbed DriveSurge, has been hijacking thousands of legitimate websites to distribute malware, primarily through ClickFix and FakeUpdate attacks. The operation utilizes a traffic d… Dark Reading · Jun 2, 2026 High USmalwaretraffic distributionclickfix
ransomware AI-built ransomware toolkit automates EDR evasion, AD discovery A threat actor is utilizing an AI-powered ransomware toolkit to automate Active Directory discovery and evade Endpoint Detection and Response (EDR) solutions. The toolkit, developed with assistance from AI agents like Cu… BleepingComputer · Jun 2, 2026 High RUaiedr evasionactive directory
threat-intel China Uses Dual-Method Cyberattack on Czech Orgs This article details a dual-method cyberattack targeting organizations in the Czech Republic and Taiwan, orchestrated by Chinese nation-state threat actors. The campaign, dubbed "Operation Dragon Weave," utilizes a spear… Dark Reading · Jun 2, 2026 High CZCNTWspear-phishingrustazure