threat-intel Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices Canadian spy agency, CSIS, utilized a novel court-ordered warrant to neutralize two foreign-run botnets operating within Canada. The operation targeted infected servers, SOHO routers, and IoT devices like Ring doorbells… The Hacker News · Jun 22, 2026 High CAUSbotnetiotcybersecurity
threat-intel AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network A new malware family, dubbed AryStinger, is exploiting vulnerabilities in older Realtek RTL819X routers to create a reconnaissance network. Approximately 4,300 routers, primarily D-Link models, have been infected, scanni… The Hacker News · Jun 22, 2026 Medium CVE-2013-3307CVE-2016-5681CVE-2025-11837KRCNSEreconnaissanceproxyiot
apt Operation Escaneo Signals Shift in LatAm Threat Landscape Operation Escaneo, a coordinated cyber campaign led by the MexicanMafia/PanchoVilla threat actor, represents a significant shift in the threat landscape of Latin America. The campaign, spanning 2025-2026, targeted critic… Dark Reading · Jun 18, 2026 High CVE-2022-42475CVE-2023-27997CVE-2024-21762MXECPTlatin americareconnaissancedata exfiltration
threat-intel Close Encounters of the Human Kind This article from Cisco Talos details a novel approach to reverse engineering that leverages AI agents alongside traditional tools like the VB6 disassembler. The key innovation is exposing the disassembler's parsed data… Cisco Talos · Jun 18, 2026 High GBFRUSreverse engineeringaiautomation
threat-intel Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model This article details a technique developed by Cisco Talos for automating reverse engineering of VB6 binaries using AI agents. The approach leverages the COM object model of VBdec, allowing external scripting tools like C… Cisco Talos · Jun 18, 2026 Medium reverse-engineeringaicom
threat-intel The Behavior of Coordinated SSH Brute Force Attacks over the last three months [Guest Diary], (Wed, Jun 17th) This report details a three-month analysis of coordinated SSH brute-force attacks conducted using a honeypot system, highlighting a correlation between attack activity and geopolitical events, law enforcement actions, an… SANS Internet Storm Center · Jun 18, 2026 High USIRILsshbrute-forcehoneypot
threat-intel Why Account Takeovers Are Rising and How to Stop Them This article discusses the rising trend of account takeover attacks, driven by increased complexity in organizational identity management due to hybrid work, BYOD, and expanded cloud services. Attackers are leveraging cr… BleepingComputer · Jun 17, 2026 High USaccount takeovercredential theftmfa fatigue
threat-intel Tenet Security Emerges From Stealth With $6 Million Seed Funding Tenet Security, a new cybersecurity firm originating in Israel, has secured $6 million in seed funding to address the emerging threat of "agentic behavior" in AI agents. The company’s technology focuses on real-time dete… SecurityWeek · Jun 17, 2026 High ISUSaiautonomous agentsagentjacking
threat-intel Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure The Athena coalition, comprised of numerous tech and fintech firms, has been established to proactively identify and mitigate vulnerabilities in open-source software (OSS) before public disclosure. This initiative addres… SecurityWeek · Jun 16, 2026 High ossvulnerabilityai
vulnerability Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw A vulnerability (CVE-2026-20262) in Cisco Catalyst SD-WAN Manager has been actively exploited in the wild, allowing authenticated attackers to overwrite files on affected systems. The flaw stems from inadequate input val… The Hacker News · Jun 16, 2026 High CVE-2026-20262CVE-2026-20245CVE-2026-20182USsd-wancvefile-upload
vulnerability Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks Cisco has released a security update to address a critical zero-day vulnerability (CVE-2026-20262) in its SD-WAN vManage software, allowing attackers to gain root privileges. The flaw stems from improper input validation… BleepingComputer · Jun 15, 2026 Critical CVE-2026-20262CVE-2026-20133CVE-2026-20128zero-dayroot privilegefile upload
apt Chinese hackers hijack auth flow, spy on isolated network for a decade Chinese cyber espionage group Velvet Ant conducted a decade-long operation, gaining persistent access to a large organization’s isolated critical infrastructure network by hijacking its authentication flow. The attackers… BleepingComputer · Jun 13, 2026 Critical CHespionageauthenticationpersistence
vulnerability Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication A critical vulnerability (CVE-2026-20253) has been identified in Splunk Enterprise versions below 10.2.4 and 10.0.7, allowing unauthenticated users to execute arbitrary code and potentially gain remote access. The flaw s… The Hacker News · Jun 13, 2026 Critical CVE-2026-20253USremote code executionauthenticationpostgresql
threat-intel A tale of two eras This article is a reflective piece by a cybersecurity analyst reminiscing about early technology and highlighting a critical shift in the threat landscape. The author uses a personal anecdote about a childhood discovery… Cisco Talos · Jun 11, 2026 High USaivulnerabilitycybersecurity
threat-intel China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance A China-linked botnet, dubbed JDY, has significantly expanded its operations, now comprising over 1,500 compromised SOHO and IoT devices. Initially a component of the KV-botnet, the JDY botnet is being used for large-sca… The Hacker News · Jun 10, 2026 High CVE-2026-35616USBRDEiotreconnaissancebotnet
threat-intel China-linked JDY botnet expands targeting of U.S. military networks A Chinese-linked botnet, JDY, has significantly expanded its targeting of U.S. military networks and associated infrastructure. The botnet, previously associated with Volt Typhoon, utilizes reconnaissance techniques like… BleepingComputer · Jun 10, 2026 High CVE-2026-35616USbotnetreconnaissanceapt
vulnerability CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation CISA has added three newly exploited vulnerabilities to its KEV catalog, impacting Cisco, Google Chrome, and Arista Networks. These vulnerabilities – one in Cisco SD-WAN Manager, another in Chrome’s V8 engine, and a thir… The Hacker News · Jun 10, 2026 High CVE-2026-20245CVE-2026-11645CVE-2026-7473cvesd-wanchrome
threat-intel Cybersecurity M&A Roundup: 26 Deals Announced in May 2026 In May 2026, several cybersecurity firms announced a significant wave of mergers and acquisitions, primarily focused on expanding capabilities in areas like AI-powered security, zero trust architectures, and endpoint pro… SecurityWeek · Jun 8, 2026 High ISUKUSm&aai securityzero trust
threat-intel Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse Meta has reported that approximately 20,000 Instagram accounts were compromised due to abuse of its AI-powered account recovery tool, High Touch Support (HTS). Hackers exploited a vulnerability in the tool to reset passw… SecurityWeek · Jun 8, 2026 High aiaccount recoverypassword reset
vulnerability Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available A high-severity vulnerability, CVE-2026-20245, in Cisco Catalyst SD-WAN Manager has been actively exploited by threat actors. The flaw, stemming from insufficient input validation, allows authenticated attackers to execu… The Hacker News · Jun 6, 2026 Critical CVE-2026-20245CVE-2026-20182CVE-2026-20127sd-wancvezero-day