threat-intel PaperCut warns of hackers using printer management software flaw in attacks PaperCut, a popular printer management software provider, has warned customers of a serious vulnerability being actively exploited by cybercriminals. The vulnerability, affecting their PaperCut NG and MF software, has led to confirmed customer incidents and prompted the company to release multiple patches. Organization… The Record · 2d ago Critical CVE-2026-82078CVE-2026-81578IRvulnerabilityprintercybersecurity
threat-intel Red Flags That Expose Fake North Korean IT Workers North Korean operatives are increasingly sophisticated in their attempts to infiltrate organizations by posing as IT workers, often leveraging stolen or fabricated identities and VPNs to mask their locations. Huntress In… Dark Reading · 4d ago High CHNEnorth koreanvpnproxy
threat-intel Is Cyber Facing an Affordability Crisis? The cybersecurity industry is facing an ‘affordability crisis’ driven by rapidly rising breach costs and defense spending, disproportionately impacting small and medium-sized businesses (SMBs) who often lack the resource… Dark Reading · 5d ago High cybersecurityaffordabilitysmb
threat-intel CISOs Break Their Silence in 'Declassified' Docuseries Red Mirror Studios, led by Danielle Lewan and Clint Howard II, is releasing an 11-episode docuseries titled "Declassified" featuring 11 cybersecurity CISOs sharing their real-world breach-response stories and personal st… Dark Reading · Aug 18, 2026 High cybersecuritycisosburnout
threat-intel The Coordination Gap: How Attackers Are Outpacing Law Enforcement The fight against cybercrime is increasingly losing ground due to attackers’ growing coordination and adaptability, outpacing law enforcement’s ability to respond effectively. Carole House, a cybersecurity strategist, ar… Dark Reading · Aug 6, 2026 High cybercrimethreat intelligenceransomware
threat-intel Black Hat USA 2026 – Summary of Vendor Announcements (Part 2) This document summarizes key vendor announcements from the 2026 Black Hat conference, focusing on advancements in cybersecurity products and services. Several companies are leveraging AI to enhance their security offerin… SecurityWeek · Aug 4, 2026 High aivulnerability remediationthreat hunting
threat-intel DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts The DevMan ransomware-as-a-service (RaaS) operation has significantly upgraded its affiliate portal, transitioning from a chat-based system to a centralized platform for managing victims, payouts, and team operations. PR… The Hacker News · Jul 25, 2026 High USCISEransomwareraasdevman
threat-intel Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths For a year, attackers leveraging the ShinyHunters group gained access to Salesforce environments not through exploiting vulnerabilities, but by exploiting trust placed in connected apps and vendors. They achieved this th… The Hacker News · Jul 14, 2026 High USoathconnected appsvendor compromise
threat-intel Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory A threat actor leveraged an AI-generated PowerShell script to aggressively map an Active Directory environment, culminating in data exfiltration and a detailed inventory report. The attack chain, utilizing tools like s5c… The Hacker News · Jul 13, 2026 High aipowershellactive directory
threat-intel Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs A recent Australian Institute of Criminology survey revealed a decrease in overall cybercrime incidents and financial losses experienced by Australians in 2025 compared to 2024. However, this positive trend was largely d… Dark Reading · Jul 2, 2026 Medium AUsmbcybercrimeaustralia
threat-intel Massive Password Spray Campaign Targeting Azure CLI A massive password spray campaign targeting Microsoft 365 environments, specifically the Azure CLI, was observed by Huntress. The attacks, originating from AS32167 and linked to LSHIY LLC, resulted in the compromise of o… SecurityWeek · Jul 1, 2026 High CHHOUScredential spraymfaoauth ropc
threat-intel New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new stealthy backdoor, Mistic (MLTBackdoor), linked to the KongTuke IAB has been used in financially motivated attacks targeting organizations across insurance, education, IT, and professional services since April 2026… The Hacker News · Jun 25, 2026 High USbackdoorremote access trojanclickfix
data-breach Scope of Salesforce Attacks Expands as Icarus Leaks Data A series of attacks originating from the Icarus extortion group have expanded the scope of breaches affecting Salesforce customers. Initially targeting Klue’s OAuth tokens, attackers leveraged this access to steal custom… Dark Reading · Jun 23, 2026 High USsalesforceoauthdata breach
threat-intel CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd) This report details a significant ongoing cyber threat targeting SonicWall firewalls exploiting CVE-2024-40766, a critical access control vulnerability. Ransomware groups, notably Akira and Fog, have been actively levera… SANS Internet Storm Center · Jun 23, 2026 Critical CVE-2024-40766CVE-2024-12802USGBvpncredential theftransomware
supply-chain Klue OAuth breach victim list grows as Icarus hackers claim attack A security breach at Klue, a market intelligence platform, has resulted in the theft of OAuth tokens used to connect to customer Salesforce environments. The attack, attributed to the ‘Icarus’ extortion group, impacted m… BleepingComputer · Jun 19, 2026 High USoauthsalesforcedata breach
ransomware The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes The Gentlemen ransomware-as-a-service (RaaS) operation is utilizing a sophisticated suite of EDR-terminating tools, centered around the GentleKiller framework, to disable security defenses before deploying ransomware. Th… The Hacker News · Jun 19, 2026 High RUSOWEransomware-as-a-serviceedr-killingbyovd
supply-chain Cybersecurity Firms Impacted by Klue Supply Chain Attack A supply chain attack targeting the Klue market intelligence platform resulted in the unauthorized harvesting of customer data from various integrations, including Salesforce and HubSpot. The attack, attributed to a new… SecurityWeek · Jun 19, 2026 High supply-chainoauthcrm
threat-intel Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data Salesforce disabled the Klue Battlecards app integration following a security incident where the Icarus extortion group exploited compromised credentials to access customer data via Salesforce. The attackers leveraged a… The Hacker News · Jun 19, 2026 High USoauthcredentialdata-exfiltration
threat-intel Salesforce Data Thefts Continue via Klue App Compromise A series of data thefts targeting Salesforce instances have been linked to a new threat actor group, Icarus, following a compromise of Klue's Battlecards app. The attacks leveraged compromised OAuth tokens and Python scr… Dark Reading · Jun 18, 2026 High USoauthsaasdata exfiltration
data-breach Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks A recent breach at Klue, a market intelligence platform, allowed the "Icarus" threat actor to steal Salesforce CRM data from multiple organizations, triggering an ongoing extortion campaign. The attackers leveraged stole… BleepingComputer · Jun 18, 2026 High USoauthsalesforcedata theft