threat-intel FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations The FBI has disrupted a Chinese-linked hacking infrastructure, QScan and QTRouter, operated by the group QTFY, which has been targeting U.S. critical infrastructure since 2018. These tools were used to steal data and conduct reconnaissance, with the goal of obfuscating the origin of attacks and blending in with legitim… The Hacker News · 4d ago High CVE-2024-8190CVE-2024-8963CVE-2024-9380CHcyber espionageiotproxy
threat-intel North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring North Korean IT workers are increasingly infiltrating government and businesses by securing jobs through traditional hiring processes. The FBI is currently investigating a case where a North Korean remote worker was hire… The Hacker News · Aug 13, 2026 High NOnorth korealazarus groupremote worker
threat-intel Black Hat USA 2026: AI is racing ahead of cybersecurity controls Black Hat USA 2026 focused heavily on the accelerating role of AI in cybersecurity, both as a threat and a tool. Experts highlighted the rapid discovery of vulnerabilities by AI systems and the need for robust oversight… WeLiveSecurity · Aug 12, 2026 Medium aicybersecurityvulnerabilities
threat-intel Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA The Gunra ransomware gang, leveraging leaked Conti code and exploiting vulnerabilities in Fortinet products, is expanding its operations through a RaaS affiliate program and successfully bypassing defenses, including MFA… Dark Reading · Aug 11, 2026 High CVE-2024-55591CVE-2025-24472SOBRCAransomwareraasfortinet
ransomware #StopRansomware: Gunra Ransomware The FBI, CISA, and other agencies have issued a joint advisory regarding the Gunra ransomware threat, a sophisticated double-extortion variant derived from the Conti ransomware. Gunra has rapidly expanded through a RaaS… CISA Advisories · Aug 10, 2026 Critical CVE-2024-55591CVE-2025-24472USREransomwaredouble extortionr0aas
threat-intel Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents Cyberattacks on water systems are expanding, now affecting at least 12 states, with Iran suspected of being behind the campaign. The attacks, primarily targeting programmable logic controllers (PLCs), have led to boil wa… The Record · Aug 5, 2026 High IRcyberattackwater systemsplcs
threat-intel Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen A popular Bitcoin hardware wallet manufacturer, Coinkite, destroyed its remaining inventory after a firmware vulnerability was exploited, leading to the theft of over $88 million in Bitcoin. The vulnerability, discovered… The Record · Aug 3, 2026 Critical bitcoinhardware walletfirmware
threat-intel CISA warns of spike in attacks on water systems as Minnesota incidents probed The CISA is warning of a significant increase in cyberattacks targeting water systems, particularly in Minnesota, with potential links to Iran. Attacks involve modifying passwords, disconnecting PLCs, and causing boil wa… The Record · Jul 31, 2026 High IRUScritical infrastructurecyberattackiran
threat-intel CI Fortify – Advice for isolating vital systems The U.S. government, through CISA and ASD’s ACSC, has released guidance for critical infrastructure organizations to isolate vital operational technology and enabling systems from other networks. This proactive measure i… CISA Advisories · Jul 28, 2026 Medium critical infrastructurecybersecurityisolation
threat-intel FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown The FBI, in collaboration with international law enforcement agencies, successfully dismantled LockBit, one of the most prolific ransomware-as-a-service (RaaS) groups, through Operation Cronos. The operation focused on b… Dark Reading · Jul 27, 2026 High UNRUransomwareraasoperation cronos
threat-intel Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors, known as LAUNDRY BEAR, has been aggressively targeting Western organizations using the Zimbra Collaboration Suite (ZCS) since July 2025, seeking to gather sensitive inform… CISA Advisories · Jul 23, 2026 High CVE-2025-66376MOPOSPphishingsupply-chainmalware
threat-intel Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting Russian state-sponsored actors are exploiting poorly configured and vulnerable networking devices, primarily routers, across critical infrastructure sectors worldwide. This joint cybersecurity advisory, released by numer… CISA Advisories · Jul 13, 2026 High CVE-2018-0171CVE-2008-4128RUsnmpcverouter
threat-intel Iran, Russia, China Target Water Systems for Sabotage A DomainTools report details ongoing nation-state targeting of water systems by Iran, Russia, and China, primarily through exploiting weak passwords, exposed PLCs, and HMI vulnerabilities. The motivations behind these at… Dark Reading · Jun 29, 2026 High IRRUCHcritical infrastructurenation-statewater systems
threat-intel FBI: Russian hackers now target Signal backup recovery keys The FBI and CISA are warning about a phishing campaign orchestrated by Russian Intelligence Services (RIS) targeting Signal users. Attackers are now specifically seeking Signal Backup Recovery Keys to gain access to vict… BleepingComputer · Jun 26, 2026 High USRUUKphishingsignalrecovery key
phishing Russian Intelligence Services Continue to Target Commercial Messaging Applications The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have issued a new PSA highlighting ongoing cyberattacks by Russian Intelligence Services (RIS) targeting commercial messaging applications. These at… CISA Advisories · Jun 26, 2026 Medium RUphishingcredential theftrussian intelligence
phishing FBI disrupts massive AI-powered phishing service using a million URLs The FBI, in collaboration with Google and Black Lotus Labs, successfully disrupted a large-scale Chinese phishing-as-a-service operation called Outsider Enterprise. This operation utilized AI to generate and distribute p… BleepingComputer · Jun 14, 2026 High CHphishingaisms
threat-intel Phishing Attack Volume Down 20%, but Risk Still Rising The volume of phishing attacks has decreased by 20% across multiple industries, despite a shift towards more sophisticated attacks utilizing AI. Threat actors are prioritizing targeted campaigns with higher conversion ra… Dark Reading · Jun 12, 2026 High CAESAUphishingaicloud
threat-intel Exposed Fuel Tank Gauges Under Attack in the US Internet-exposed fuel tank gauges in the United States are being targeted by cyberattacks, posing a significant risk to gas stations and industrial facilities. The Cybersecurity and Infrastructure Security Agency (CISA)… Dark Reading · Jun 5, 2026 High USCAAUindustrial control systemscybersecuritytank gauges
threat-intel Over 900 US gas station tank gauge systems exposed to attacks Over 900 US gas station tank gauge systems are vulnerable to ongoing attacks due to internet exposure and security flaws. Threat actors are exploiting these systems to potentially alter settings and cause operational dis… BleepingComputer · Jun 5, 2026 High USatgindustrial control systemscybersecurity
threat-intel In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA This week’s cybersecurity news highlights a range of threats, including AI-powered attacks targeting computing power, ongoing Grandoreiro banking trojan campaigns, and a self-propagating ransomware group utilizing obfusc… SecurityWeek · Jun 5, 2026 High IRUSairansomwaresupply chain