threat-intel FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation A Russian-speaking threat actor, dubbed FortiBleed, is conducting a large-scale credential harvesting operation targeting over 430,000 FortiGate firewalls globally. The campaign, active since February 2026, utilizes a Go… The Hacker News · Jun 23, 2026 High USINRUcredential harvestingfirewallactive directory
threat-intel Compromise kids online safety bill unveiled by House leaders, with key omission A revised version of the Kids Online Safety Act (KOSA) has been unveiled by the House Energy and Commerce Committee, aiming for bipartisan support. However, a key element – a ‘duty of care’ provision requiring platforms… The Record · Jun 23, 2026 Medium USonline safetychildren's privacyai regulation
threat-intel The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration This report details a newly discovered bucket hijacking technique impacting major cloud service providers (CSPs) like Google Cloud, AWS, and Microsoft Azure. The vulnerability exploits a shared namespace design where glo… Palo Alto Unit 42 · Jun 22, 2026 High cloud securitydata exfiltrationbucket hijacking
threat-intel Phishing Attack Volume Down 20%, but Risk Still Rising The volume of phishing attacks has decreased by 20% across multiple industries, despite a shift towards more sophisticated attacks utilizing AI. Threat actors are prioritizing targeted campaigns with higher conversion ra… Dark Reading · Jun 12, 2026 High CAESAUphishingaicloud
supply-chain The ‘Miasma’ worm source code briefly leaked on GitHub The source code for the Miasma credential-stealing worm framework, previously linked to supply-chain attacks targeting open-source ecosystems, was briefly leaked on GitHub. This leak, mirroring the earlier Shai-Hulud wor… BleepingComputer · Jun 10, 2026 High USsupply chaincredential theftopen source
threat-intel UK weakens proposed telecoms defenses against Chinese hackers after industry pushback The UK government has weakened proposed cybersecurity protections for its telecoms networks in response to pushback from telecom companies regarding the cost and practicality of implementing measures designed to counter… The Record · Jun 9, 2026 High UKCHespionagetelecomscybersecurity
threat-intel Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility This article from Palo Alto Unit 42 details how attackers are exploiting cloud logging services, specifically AWS CloudTrail and Google Cloud Logging, to evade detection and gain continuous visibility into target environ… Palo Alto Unit 42 · Jun 9, 2026 High cloud securityloggingevasion
vulnerability One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public A critical vulnerability, CVE-2026-23111, has been discovered in the Linux kernel’s nf_tables packet-filtering code, allowing unprivileged users to escalate to root access and break out of containers. The flaw, initially… The Hacker News · Jun 8, 2026 Critical CVE-2026-23111linuxkerneluse-after-free
threat-intel Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI A researcher has discovered that Bright Data, a company providing residential proxy services, is utilizing its iOS SDK embedded in free smart TV apps to turn these devices into web-scraping proxies for the AI industry. T… The Hacker News · Jun 6, 2026 Medium UZOMsmart tvresidential proxyai scraping
supply-chain IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks A sophisticated supply chain attack targeting the npm ecosystem has resulted in the deployment of both IronWorm, a Rust-based information stealer with self-replicating capabilities, and a new variant of the Miasma worm.… The Hacker News · Jun 5, 2026 High USsupply-chainnpmrust
threat-intel PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network PCPJack, a threat actor initially linked to TeamPCP, has established a covert SMTP email relay network by hijacking 230 cloud servers across AWS, Google Cloud, and Azure. The operation involved converting business server… The Hacker News · Jun 5, 2026 High USUKDEsmtp relaycloud proxyc2
threat-intel FBI-Flagged Phishing Kit Kali365 Expands Its Reach The Kali365 phishing-as-a-service platform, initially focused on compromising Microsoft 365 accounts via MFA bypass, has significantly expanded its capabilities and target list. It now actively targets platforms like AWS… Dark Reading · Jun 2, 2026 High USRUphishingdevice-codemfa
threat-intel Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine The Gamaredon group is exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy a multi-stage malware campaign targeting Ukraine. This campaign utilizes GammaWorm and GammaSteel, designed for data theft and persistenc… The Hacker News · Jun 2, 2026 High CVE-2025-8088CVE-2026-21509RUUAwinrarmalwarevulnerability
threat-intel Anthropic to Open Mythos AI to EU's ENISA This article reports that Anthropic is granting access to its Mythos AI model to the European Union’s ENISA as part of the Project Glasswing initiative. Mythos, an AI model capable of autonomously discovering and exploit… Dark Reading · Jun 1, 2026 High EUUSaivulnerabilitycybersecurity
vulnerability New CIFSwitch Linux flaw gives root on multiple distributions A newly discovered vulnerability, dubbed 'CIFSwitch,' in the Linux kernel allows attackers to escalate privileges to root by forging CIFS authentication key descriptions. The flaw, present since 2007, affects multiple Li… BleepingComputer · May 30, 2026 High CVE-2026-46243linuxkernelprivilege escalation
threat-intel Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security This Dark Reading article reflects on the evolution of the cybersecurity industry over the past 20 years, highlighting a shift from traditional perimeter defenses focused on antivirus and firewalls to a more complex land… Dark Reading · May 27, 2026 Medium cybersecuritycloud securityiot security
ddos Canadian man arrested, charged for running KimWolf DDos botnet A Canadian man, Jacob Butler, has been arrested and charged with operating the KimWolf DDoS botnet, a significant online threat that disrupted numerous websites. Law enforcement agencies, in a coordinated international e… The Record · May 22, 2026 High CAUSGEddosbotnetcybercrime
threat-intel China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts. A China-aligned Advanced Persistent Threat (APT) group known as Webworm has shifted its focus from Asia to targeting European governmental organizations, specifically in Belgium, Italy, Serbia, Spain, Poland, and South A… Dark Reading · May 22, 2026 High CHBEITaptdiscordmicrosoft graph
threat-intel FTC warns 12 major tech firms of violating Take It Down Act The Federal Trade Commission (FTC) has issued warnings to twelve major tech companies, alleging non-compliance with the newly enacted Take It Down Act (TIDA). This law mandates platforms swiftly remove non-consensual int… The Record · May 20, 2026 High image abuseonline safetyprivacy
vulnerability Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years A critical Linux kernel vulnerability, dubbed 'Copy Fail' (CVE-2026-31431), has been discovered allowing unprivileged local attackers to escalate their access to root across numerous Linux distributions since 2017. The f… Palo Alto Unit 42 · May 5, 2026 Critical CVE-2026-31431CVE-2026-314331USlinuxkernellpe