threat-intel Apple removes Russia’s state-backed messaging app Max from its store Apple removed the state-backed Russian messaging app Max from its App Store, citing sanctions regulations. This action has drawn criticism from Russian officials who view it as an unfriendly move and has impacted the app… The Record · Jun 4, 2026 Medium RUsanctionsrussiamessaging
vulnerability CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability, CVE-2026-45247, affecting the Mirasvit Cache Warmer Magento extension to its KEV catalog. This flaw allows for remote c… The Hacker News · Jun 4, 2026 Critical CVE-2026-45247USUKFRphpobjectdeserialization
ddos New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute A new denial-of-service (DoS) attack, dubbed ‘HTTP/2 Bomb,’ has been identified that can cripple web servers within seconds by exploiting vulnerabilities in default HTTP/2 configurations of popular web servers like Nginx… BleepingComputer · Jun 3, 2026 High CVE-2026-49975doshttp2compression
threat-intel ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds A new ‘HTTP/2 Bomb’ exploit has been discovered that leverages existing vulnerabilities in HTTP/2 implementations to cause widespread denial-of-service attacks against web servers. The exploit combines compression and fl… SecurityWeek · Jun 3, 2026 High CVE-2016-6581CVE-2025-53020CVE-2016-8740USdoshttp2compression
ddos New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare Researchers have identified a new HTTP/2 bomb vulnerability affecting web servers like NGINX, Apache, and IIS, allowing for remote denial-of-service attacks. The exploit leverages header compression and connection manage… The Hacker News · Jun 3, 2026 High CVE-2016-6581CVE-2025-53020CVE-2016-8740http2compressiondos
ransomware AI-built ransomware toolkit automates EDR evasion, AD discovery A threat actor is utilizing an AI-powered ransomware toolkit to automate Active Directory discovery and evade Endpoint Detection and Response (EDR) solutions. The toolkit, developed with assistance from AI agents like Cu… BleepingComputer · Jun 2, 2026 High RUaiedr evasionactive directory
threat-intel Russia claims foreign spy agencies hacked officials' phones Russia's FSB has accused foreign intelligence agencies of conducting a large-scale espionage operation targeting senior Russian officials through the use of malware installed on their mobile devices. The agency alleges t… The Record · Jun 2, 2026 High RUUNEUespionagesurveillanceforeign interference
ddos From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market This article reports on the increasing commercialization of Distributed Denial-of-Service (DDoS) attacks, now offered as a ‘DDoS-as-a-Service’ (DDoSaaS) model. The trend shows a shift from fragmented, DIY attack methods… BleepingComputer · May 29, 2026 High USddosbotnetcloudflare
threat-intel GreyVibe hackers use ChatGPT, Gemini to power cyberattacks GreyVibe, a threat actor likely linked to Russia, has been conducting cyber espionage campaigns targeting Ukrainian organizations since August 2025, utilizing a diverse range of custom malware and AI-generated lures. The… BleepingComputer · May 28, 2026 High RUUKaiphishingmalware
ddos Canadian man arrested, charged for running KimWolf DDos botnet A Canadian man, Jacob Butler, has been arrested and charged with operating the KimWolf DDoS botnet, a significant online threat that disrupted numerous websites. Law enforcement agencies, in a coordinated international e… The Record · May 22, 2026 High CAUSGEddosbotnetcybercrime
threat-intel In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking This week’s cybersecurity news highlights several incidents, including Iranian hackers targeting US gas station tank monitor systems, a CISA contractor exposing sensitive credentials, a Huawei router vulnerability causin… SecurityWeek · May 22, 2026 High CVE-2024-9643CVE-2026-45401USLUiotcritical infrastructuresupply-chain
threat-intel Belarus-linked hackers use fake training certificates to target Ukrainian officials A Belarus-linked hacking group, GhostWriter (UNC1151/Storm-0257), is conducting a new espionage campaign targeting Ukrainian government officials. The operation utilizes sophisticated phishing emails disguised as trainin… The Record · May 21, 2026 High UABYphishingmalwareespionage
threat-intel Content Delivery Exploit Opens Websites to Brand Hijacking This article details a new exploit, dubbed "Underminr," that leverages vulnerabilities in Internet infrastructure to allow attackers to hijack websites and conceal malicious activity. The technique, a successor to domain… Dark Reading · May 21, 2026 High USEUCNcdndnsdomain fronting
threat-intel Cyber Pioneers Ponder Past as Prologue This Dark Reading article reflects on the platform's 20-year history, featuring insights from prominent cybersecurity leaders who contributed to its content. Robert Hansen discusses his early work on robot scraping and A… Dark Reading · May 15, 2026 High aivulnerabilitybug bounties