threat-intel UAT-7810 continues building ORB networks using new malware Cisco Talos Intelligence has identified UAT-7810, a China-nexus APT group, continuing to develop and deploy malware as part of its Operational Relay Box (ORB) network. The group is actively creating new malware variants,… Cisco Talos · Jul 7, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717CHaptmalwarechina
threat-intel SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing Researchers at the Hong Kong University of Science and Technology have developed a method to bypass AI coding agent scanners by using self-extracting packing and character substitution to disguise malicious skills. Their… The Hacker News · Jul 6, 2026 High aiskillsmalware
threat-intel In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting This report details several significant cybersecurity events across multiple sectors, including a Canadian hacker’s imprisonment for a Texas GOP cyberattack, a large KDDI data breach impacting 14 million users, and the d… SecurityWeek · Jul 3, 2026 High CAJAUNzero-dayhacktivismdata breach
threat-intel Catan and Mouse This Cisco Talos Threat Source newsletter highlights the emergence of ARToken, a sophisticated phishing-as-a-service (PhaaS) platform with capabilities previously undocumented. The platform, similar to EvilTokens, offers… Cisco Talos · Jul 2, 2026 High CVE-2026-48558USphishingbecai
vulnerability New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure A newly discovered CitrixBleed-like vulnerability (CVE-2026-8451) in NetScaler ADC and Gateways was exploited within 24 hours of its public disclosure. The flaw, stemming from an out-of-bounds read issue in the XML parse… SecurityWeek · Jul 2, 2026 Critical CVE-2026-8451DEHKcitrixbleedsamlmemory disclosure
threat-intel Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. This article reports on a significant investment by IBM and Red Hat into Project Lightwell, a new service designed to address the growing challenge of securing open-source software supply chains. Driven by Anthropic's My… Dark Reading · Jul 2, 2026 High USaivulnerabilityopen source
threat-intel China-Linked Group Targets Southeast Asia Critical Systems A China-linked cyber threat group, CL-STA-1062 (formerly UAT-7237), has been targeting critical infrastructure providers in Southeast Asia over the past year, deploying a new backdoor tool called TinyRCT. The group has s… Dark Reading · Jul 1, 2026 High CNMYTHchinaaptbackdoor
malware New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks A new cyberattack campaign, dubbed StrikeShark, is utilizing a previously undocumented malware family called SharkLoader to deploy Cobalt Strike Beacon. The campaign has targeted diplomatic organizations in Indonesia and… The Hacker News · Jun 26, 2026 High CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikedll hijackingexploit
threat-intel Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions Cisco is bolstering its security offerings by acquiring Astrix Security and WideField Security, both focused on managing the growing number of non-human identities (NHIs) created by AI agents. This strategy reflects a sh… Dark Reading · Jun 26, 2026 High ainon-human identitiesidentity management
threat-intel CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Palo Alto Unit 42 has identified a sustained cyber threat campaign, CL-STA-1062, targeting government and critical infrastructure entities in Southeast Asia since at least March 2022. The group, linked to UAT-7237, utili… Palo Alto Unit 42 · Jun 25, 2026 High VNeast asiasoutheast asiabackdoor
threat-intel In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw A critical vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager (CUCM) has been rapidly weaponized by attackers within 24 hours of a proof-of-concept release. The SSRF flaw allows unauthenticated remote… Dark Reading · Jun 25, 2026 Critical CVE-2026-20230USssrfprivilege escalationcisco
threat-intel Beyond IOCs: AI-enabled threat intelligence This article from Cisco Talos discusses the potential of large language models (LLMs) to revolutionize threat intelligence management. Currently, the industry relies heavily on indicators of compromise (IOCs) and struggl… Cisco Talos · Jun 25, 2026 Medium UKaillmcom
threat-intel Introduction to COM usage by Windows threats This Cisco Talos report details the increasing use of the Component Object Model (COM) by malware actors for malicious activities within Windows environments. COM's capabilities for inter-process communication, automatio… Cisco Talos · Jun 25, 2026 Medium comwindowslateral movement
threat-intel Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access A zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN was exploited by an unknown threat actor, gaining root access to a communications service provider’s network. The attack involved anti-forensic technique… The Hacker News · Jun 25, 2026 Critical CVE-2026-20245CVE-2026-20127CVE-2026-20182zero-daysd-wanroot access
vulnerability Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access A Mandiant report details how attackers exploited a zero-day vulnerability (CVE-2026-20245) in Cisco SD-WAN Manager, Controller, and Validator software to gain root access on targeted devices. The attackers initially gai… BleepingComputer · Jun 24, 2026 High CVE-2026-20245CVE-2026-20127CVE-2026-20182USzero-dayprivilege escalationroot access
vulnerability Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure Attackers exploited a critical vulnerability in Cisco Catalyst SD-WAN Controller (CVE-2026-20245) approximately two months before Cisco publicly disclosed it. The vulnerability, stemming from insufficient input validatio… Dark Reading · Jun 24, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127USsd-wanprivilege escalationzero-day
vulnerability Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs Critical vulnerabilities were discovered in Ubiquiti UniFi devices, specifically CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, allowing for unauthorized access and command injection. While patches were released in… SecurityWeek · Jun 24, 2026 Critical CVE-2026-34908CVE-2026-34909CVE-2026-34910USvulnerabilitycommand injectionauthentication
threat-intel StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader A new malware family, named SharkLoader, has been identified as part of a broader campaign targeting organizations globally, including diplomatic entities, government organizations, and software development companies. Th… Securelist · Jun 24, 2026 Medium CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikeexploitloader
vulnerability Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks A high-severity Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-20230, in Cisco Unified Communications Manager is currently being actively exploited by threat actors. This allows attackers to gain root privile… BleepingComputer · Jun 23, 2026 High CVE-2026-20230ssrfcve-2026-20230root
threat-intel Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents This article details an experiment conducted by AIR Security to demonstrate the vulnerabilities within current skill-scanning methods for AI agent skills within popular marketplaces. The firm created a seemingly harmless… The Hacker News · Jun 23, 2026 Medium USaiagentskills