Des cibles françaises au cœur d’une plateforme cybercriminelle A ZATAZ investigation has uncovered a list of French organizations targeted by a cybercriminal group, Krybit, who are aggressively recruiting affiliates through a platform offering a lucrative 80% revenue split. The group, known for ransomware operations, is actively seeking partners to expand its reach and utilize a d… ZATAZ · Aug 7, 2026 FRMXUSransomwarerecruitmentcybercrime
ransomware No Manners Here: The Ruthless Rise of The Gentlemen Ransomware The Gentlemen, a rapidly growing Ransomware-as-a-Service (RaaS) program, has significantly increased its victim count in 2026, becoming the second most active RaaS program globally. Leveraging a 90% affiliate payout stru… Palo Alto Unit 42 · Jul 10, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073USCAGBransomware-as-a-serviceracksedge-device-attack
ransomware Ransomware Thugs Masquerade as Interpol to Entice Small Biz A new ransomware campaign is targeting small businesses globally, impersonating Interpol to lure victims into downloading malware. The campaign utilizes basic social engineering techniques, delivering a rudimentary ranso… Dark Reading · Jul 2, 2026 Medium USEUSAsocial engineeringphishingsmall business
threat-intel CISA warns Fortinet users to secure devices after FortiBleed leak CISA has issued a warning to Fortinet customers regarding the "FortiBleed" data leak, which exposed nearly 74,000 firewall and VPN credentials. Threat actors are exploiting these compromised credentials to target interne… BleepingComputer · Jun 19, 2026 High USRUCNcredentialsvpnfirewall
threat-intel Telegram admits it couldn't police exam-leak channels, India tells court India's government blocked Telegram access following reports of leaked exam materials for the NEET-UG 2026 medical entrance exam, leading to disruptions for users globally. Telegram initially admitted limitations in proa… BleepingComputer · Jun 18, 2026 Medium INAEexamleakregulatory
data-breach FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. A significant data leak, dubbed "FortiBleed," has exposed approximately 73,932 Fortinet VPN credentials for firewall URLs across numerous organizations worldwide. The leak, discovered by Bob Diachenko, reveals a multi-op… BleepingComputer · Jun 17, 2026 High USGBJPvpncredentialsbreach
threat-intel India's Telegram ban hit the UAE too. Here's how to get around it Following the ban of Telegram in India due to leaked exam materials from the NEET medical entrance exam, the platform experienced disruptions in access for users globally, notably in the UAE, attributed to a BGP hijackin… BleepingComputer · Jun 17, 2026 High INAEbgproutingexam fraud
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
phishing Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts A coordinated phishing campaign, spearheaded by the now-disrupted Sniper Dz platform, targeted users in the Middle East and North Africa (MENA) through deceptive Facebook offers. The campaign leveraged browser notificati… The Hacker News · Jun 15, 2026 High DZALAEphishingsocial engineeringbrowser notifications
phishing INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator INTERPOL, in collaboration with authorities across 13 MENA countries, successfully dismantled the decade-long Sniper Dz phishing-as-a-service (PhaaS) platform, resulting in the arrest of its administrator, Guedz. The ope… The Hacker News · Jun 12, 2026 High ALAEDZphishing-as-a-servicecredential theftsocial engineering
threat-intel From cause to cash: a cross-border look at hacktivist activity This Securelist article details a cross-border hacktivist campaign led by groups including 4BID, with a broadened geographic scope impacting organizations in Kazakhstan, the UAE, Syria, and Egypt. The campaign utilized t… Securelist · Jun 8, 2026 High CVE-2023-44976KZAESYproxyshellransomwarehacktivism
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
vulnerability CP Plus 8 Ch. Network Video Recorder A cross-site scripting (XSS) vulnerability has been identified in CP Plus 8 Ch. Network Video Recorder devices (CP-UNR-108F1 Hardware V1.0, CP-UNR-108F1 Web V3.2.7.128806, and CP-UNR-108F1 System V4.001.00AT009.0.R). Att… CISA Advisories · May 28, 2026 High CVE-2026-6824INNPAExsscwe-79firmware
threat-intel MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries The MuddyWater hacking group, backed by Iran, has been conducting a sophisticated espionage campaign targeting organizations across nine countries on four continents during Q1 2026. The campaign utilizes DLL side-loading… The Hacker News · May 26, 2026 High KRSAAEdll-side-loadingcredential-stealingreconnaissance
threat-intel Iranian APT Targets Aviation, Software Companies With Updated Tools The Iranian APT group, known as Nimbus Manticore, has been aggressively updating its tactics and tools to target aviation and software companies globally. The group, linked to Charming Kitten and the IRGC, is employing… SecurityWeek · May 26, 2026 High AEIRSAaptphishingappdomain
threat-intel Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns This report from Palo Alto Unit 42 details ongoing espionage campaigns conducted by the Iran-nexus APT group Screening Serpens (UNC1549). The group, active since 2022, targeted entities in the U.S., Israel, the UAE, and… Palo Alto Unit 42 · May 22, 2026 High USIRILaptespionagesocial engineering
threat-intel Interpol's 'Operation Ramz' Pioneers Cross-Region Collabs in Middle East Interpol’s ‘Operation Ramz’ was a five-month collaborative law enforcement effort involving 13 countries in the Middle East and North Africa (MENA) region to combat cybercrime. The operation resulted in the identificatio… Dark Reading · May 20, 2026 High AEEGIQcybercrimeregionalcollaboration
vulnerability Kieback & Peter DDC Building Controllers This CISA advisory details a cross-site scripting (XSS) vulnerability affecting several versions of Kieback & Peter’s DDC Building Controllers. The vulnerability, CVE-2026-4293, allows an attacker to execute JavaScript c… CISA Advisories · May 19, 2026 Medium CVE-2026-4293AUATCNxssbuilding automationot
threat-intel INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests INTERPOL’s Operation Ramz was a coordinated international effort involving 13 MENA countries to combat cybercrime, resulting in 201 arrests and the disruption of phishing and malware operations. The operation targeted in… The Hacker News · May 18, 2026 High AEALBHcybercrimephishingmalware
threat-intel Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition A 19-year-old teenager, identified as "Bouquet," has been arrested in Finland and faces US extradition charges for allegedly being a member of the Scattered Spider cybercrime group. The investigation revealed the group’s… Graham Cluley · May 4, 2026 High USGBFIsocial engineeringphishingmfa