malware Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input A malicious Chrome extension disguised as the Perplexity AI search engine was discovered by Microsoft, intercepting user searches and address bar input. The extension secretly logged this data by routing it through an at… The Hacker News · Jun 29, 2026 High chromeextensiondata collection
threat-intel Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse The Gamaredon APT group continued its aggressive cyberattacks against Ukraine throughout 2025, utilizing a range of new malware and exploiting vulnerabilities to steal sensitive information. The group expanded its tactic… The Hacker News · Jun 29, 2026 High CVE-2025-8088RUUAspear-phishingpersistencecloud-services
ransomware The Gentlemen are knocking: сustom backdoors and evolving tactics This report details the activities of "The Gentlemen," a ransomware-as-a-service (RaaS) group that has been aggressively targeting large corporations and critical infrastructure since early 2026. The group employs sophis… Securelist · Jun 29, 2026 High USransomware-as-a-servicereconnaissancelateral movement
malware Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts Microsoft removed 119 malicious Edge extensions from its add-on store that employed steganography to hide malware, including credential theft and ad fraud capabilities. The operation, dubbed StegoAd, had been active sinc… The Hacker News · Jun 29, 2026 High CHsteganographycredential theftad fraud
threat-intel AI Decline? Confidence in Autonomous Penetration Testing Falls The confidence in fully autonomous AI systems for penetration testing has significantly declined after initial optimism. A report by Cobalt found that only 9% of organizations now rely on AI-powered testing, down from 29… Dark Reading · Jun 26, 2026 Medium aipentestingautomation
malware New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks A new cyberattack campaign, dubbed StrikeShark, is utilizing a previously undocumented malware family called SharkLoader to deploy Cobalt Strike Beacon. The campaign has targeted diplomatic organizations in Indonesia and… The Hacker News · Jun 26, 2026 High CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikedll hijackingexploit
threat-intel Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign A Chinese-speaking Advanced Persistent Threat (APT) group, CL-STA-1062, has been actively targeting government entities and critical infrastructure in Southeast Asia since 2022, utilizing a new custom backdoor called Tin… The Hacker News · Jun 26, 2026 High VNaptbackdoorsoutheast asia
threat-intel Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant A phishing campaign targeting hotels and hospitality organizations is underway, utilizing deceptive ZIP files containing Node.js implants to gain access to front-desk machines. The campaign, discovered by Microsoft, empl… The Hacker News · Jun 26, 2026 High GBJPDKphishingnode.jston
threat-intel CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Palo Alto Unit 42 has identified a sustained cyber threat campaign, CL-STA-1062, targeting government and critical infrastructure entities in Southeast Asia since at least March 2022. The group, linked to UAT-7237, utili… Palo Alto Unit 42 · Jun 25, 2026 High VNeast asiasoutheast asiabackdoor
threat-intel Microsoft quietly extends free Windows 10 ESU support to October 2027 Microsoft has unexpectedly extended the free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, pushing the end-of-support date to October 12, 2027. This decision provides users with… BleepingComputer · Jun 25, 2026 Low windows 10esusecurity updates
threat-intel ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories This article reports on several security vulnerabilities and trends, including a privacy-preserving protocol from Cloudflare, six vulnerabilities in the curl library, a critical security flaw in Hoppscotch allowing unaut… The Hacker News · Jun 25, 2026 High CVE-2026-8932CVE-2026-50160USKRsmart tvproxywareiot
threat-intel Introduction to COM usage by Windows threats This Cisco Talos report details the increasing use of the Component Object Model (COM) by malware actors for malicious activities within Windows environments. COM's capabilities for inter-process communication, automatio… Cisco Talos · Jun 25, 2026 Medium comwindowslateral movement
threat-intel New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new stealthy backdoor, Mistic (MLTBackdoor), linked to the KongTuke IAB has been used in financially motivated attacks targeting organizations across insurance, education, IT, and professional services since April 2026… The Hacker News · Jun 25, 2026 High USbackdoorremote access trojanclickfix
threat-intel Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances In 2025, the Russian-aligned threat actor Gamaredon significantly ramped up its cyberespionage operations targeting Ukraine, utilizing a sophisticated and evolving toolkit. The group, linked to the FSB, employed a combin… WeLiveSecurity · Jun 25, 2026 HighCVSS 8.8 CVE-2025-8088RUcyberespionagerussiaspearphishing
malware Malicious Edge extension abuses Native Messaging as bridge to malware A malicious Microsoft Edge extension, ‘Edgecution,’ was used in a ransomware attack by exploiting Native Messaging to bypass browser security sandboxes and deploy a Python-based backdoor. The attack, linked to the Payout… BleepingComputer · Jun 24, 2026 High USbrowser extensionnative messagingransomware
threat-intel Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement A coordinated international effort, led by Microsoft and Europol, successfully dismantled a significant cybercrime-as-a-service infrastructure used by multiple threat actors. The operation resulted in the seizure of subs… The Record · Jun 24, 2026 High RUcybercrime-as-a-servicesupply chaininfostealer
ransomware Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered A coordinated international law enforcement operation, involving Bitdefender, Bitsight, ESET, Microsoft, and Europol, successfully disrupted the Amadey and StealC malware networks, recovering 27 million stolen credential… The Hacker News · Jun 24, 2026 High NLCADEmaascredential theftransomware
ransomware Amadey, StealC malware operations disrupted in Operation Endgame action Operation Endgame, a coordinated law enforcement effort involving Microsoft, Europol, and international partners, successfully disrupted infrastructure used by the Amadey and StealC malware operations. The operation resu… BleepingComputer · Jun 24, 2026 High USCADKmalware-as-a-servicecredential theftransomware
supply-chain Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks A new vulnerability, dubbed 'Cordyceps,' has been discovered in CI/CD workflows, allowing unauthorized access and control over hundreds of GitHub repositories across major tech companies. The flaw stems from overly permi… The Hacker News · Jun 24, 2026 Critical cicdsupply chaingithub
threat-intel ESET takes part in Operation Endgame to disrupt Amadey and Stealc ESET, in collaboration with Microsoft DCU and other partners, successfully disrupted the Amadey and Stealc botnets as part of Operation Endgame. These botnets, sold as a service on darknet forums, utilize a MaaS model wh… WeLiveSecurity · Jun 24, 2026 High maasbotnetdarknet