threat-intel ATF Confirms Cyber Incident After Ransomware Group Claims Attack The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) suffered a cybersecurity incident, confirmed by the agency itself, and attributed to the Qilin ransomware group. While the incident didn't impact the agency's core systems, it led to a ‘major incident’ designation and an ongoing investigation. The Qilin grou… SecurityWeek · 2d ago Medium ransomwarezero-daydouble-extortion
threat-intel ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories This week’s ThreatsDay bulletin highlights a diverse range of cyber threats, including a 296,000-device IoT botnet, social engineering attacks targeting security teams, and a growing number of credential-stealing malware… The Hacker News · 3d ago High CVE-2026-55040CVE-2026-63520RUsocial engineeringphishingcredential theft
threat-intel ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited ReliaQuest was targeted by the ShinyHunters group through a sophisticated phishing campaign mimicking security employees to gain access to an Okta dashboard. While the attackers gained temporary view-only access, they we… SecurityWeek · 6d ago Medium phishingsocial engineeringokta
threat-intel Russian snoops add OAuth abuse to targeted phishing campaigns Google has identified three distinct groups of Russian cyber-spies – UNC6293, UNC7005, and UNC5976 – that are aggressively targeting individuals in academia, defense, government, and think tanks across Europe and the US.… The Register · Aug 21, 2026 High RUUKWEphishingoathsocial engineering
threat-intel Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts Three distinct clusters of suspected Russian cyber espionage groups – UNC6293, UNC7005, and UNC5976 – are leveraging legitimate authentication flows to target individuals in academia, aerospace/defense, governments, and… The Hacker News · Aug 20, 2026 High UKARRUoauthapp passworddevice linking
threat-intel Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says Russian state-sponsored hackers, linked to the Midnight Blizzard group (part of APT29), are compromising hotel Wi-Fi networks worldwide to steal traveler login credentials and install espionage malware. The campaign uses… The Record · Aug 3, 2026 High RUUKSAhotel wifiespionagecaptive portal
threat-intel Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware A sophisticated campaign, dubbed CaptiveCrunch, is leveraging hijacked hotel Wi-Fi networks to deliver surveillance malware – specifically CornFlake, a remote access trojan – to unsuspecting guests. The attacks are orche… The Hacker News · Aug 1, 2026 High USUKcaptive portaldns redirectionremote access trojan
vulnerability PTC Windchill Vulnerability Exploited in Ransomware Campaign A critical remote code execution vulnerability in PTC's Windchill and FlexPLM PLM platforms has been exploited by a Cl0p ransomware affiliate in a targeted campaign. The attackers are leveraging a chain of vulnerabilitie… SecurityWeek · Jul 27, 2026 Critical CVE-2026-12569rcevulnerabilityransomware
threat-intel Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials A threat actor is exploiting vulnerabilities in public Wi-Fi gateways, particularly at hotels and conference centers, to steal corporate credentials, including Microsoft 365 accounts, and is leveraging tactics similar to… SecurityWeek · Jul 27, 2026 High USINSAdnscaptive portalcredential theft
threat-intel And the Winner in Dominant Malware Delivery? ClickFix ClickFix, a social engineering technique where attackers trick users into executing malicious commands via error messages, has become the dominant method for malware delivery, according to a recent ReliaQuest analysis. T… Dark Reading · Jul 1, 2026 High USsocial engineeringmalware deliveryobfuscation
threat-intel New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new stealthy backdoor, Mistic (MLTBackdoor), linked to the KongTuke IAB has been used in financially motivated attacks targeting organizations across insurance, education, IT, and professional services since April 2026… The Hacker News · Jun 25, 2026 High USbackdoorremote access trojanclickfix
supply-chain Klue OAuth breach victim list grows as Icarus hackers claim attack A security breach at Klue, a market intelligence platform, has resulted in the theft of OAuth tokens used to connect to customer Salesforce environments. The attack, attributed to the ‘Icarus’ extortion group, impacted m… BleepingComputer · Jun 19, 2026 High USoauthsalesforcedata breach
supply-chain Cybersecurity Firms Impacted by Klue Supply Chain Attack A supply chain attack targeting the Klue market intelligence platform resulted in the unauthorized harvesting of customer data from various integrations, including Salesforce and HubSpot. The attack, attributed to a new… SecurityWeek · Jun 19, 2026 High supply-chainoauthcrm
threat-intel Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data Salesforce disabled the Klue Battlecards app integration following a security incident where the Icarus extortion group exploited compromised credentials to access customer data via Salesforce. The attackers leveraged a… The Hacker News · Jun 19, 2026 High USoauthcredentialdata-exfiltration
threat-intel Salesforce Data Thefts Continue via Klue App Compromise A series of data thefts targeting Salesforce instances have been linked to a new threat actor group, Icarus, following a compromise of Klue's Battlecards app. The attacks leveraged compromised OAuth tokens and Python scr… Dark Reading · Jun 18, 2026 High USoauthsaasdata exfiltration
data-breach Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks A recent breach at Klue, a market intelligence platform, allowed the "Icarus" threat actor to steal Salesforce CRM data from multiple organizations, triggering an ongoing extortion campaign. The attackers leveraged stole… BleepingComputer · Jun 18, 2026 High USoauthsalesforcedata theft
threat-intel ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More This week’s security news highlights a series of attacks and vulnerabilities, including a supply chain attack targeting Microsoft GitHub repositories via the Miasma Worm, a zero-day exploit in Android, and ongoing cyberc… The Hacker News · Jun 8, 2026 High CVE-2025-48595CVE-2026-28318CVE-2026-39210CHUSGEsupply-chainzero-daycybercrime
threat-intel New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework A new threat cluster, OP-512, is targeting Microsoft IIS servers with a custom web shell framework, exhibiting sophisticated evasion techniques and centralized management capabilities. ReliaQuest has linked the activity… The Hacker News · Jun 5, 2026 High CNiisweb shellespionage
threat-intel Securing AI Agents Before They Go Rogue Is Next to Impossible This article highlights the significant security challenges posed by high-autonomy AI agents, particularly those with broad permissions and access to sensitive data. Gartner research VP Dennis Xu warns that securing thes… Dark Reading · Jun 2, 2026 High aiagentsecurity
threat-intel Hackers bypass SonicWall VPN MFA due to incomplete patching Hackers exploited a vulnerability (CVE-2024-12802) in SonicWall Gen6 SSL-VPN appliances to bypass multi-factor authentication and deploy ransomware tools. The attackers gained access to networks within 30-60 minutes, lev… BleepingComputer · May 20, 2026 High CVE-2024-12802USvpnmfacredential theft