data-breach Hackers steal Lidl customer data from external service provider Lidl, a major European supermarket chain, suffered a data breach after attackers gained access to customer data stored by an external IT service provider. The stolen information included personal details like names, emai… The Record · Jul 13, 2026 Medium DEBENLdata breachcustomer dataretail
threat-intel VPN service favored by ransomware groups is sanctioned by US The U.S. government has sanctioned a VPN service, First VPN, and its administrator, citing their role in enabling ransomware attacks against critical U.S. infrastructure. The sanctions target not only the VPN providers b… The Record · Jul 13, 2026 High USUKBEvpnransomwarecybercrime
threat-intel Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 In June 2026, a significant number of cybersecurity M&A deals were announced, highlighting the industry's ongoing consolidation and investment in advanced security technologies. Several key acquisitions focused on areas… SecurityWeek · Jul 13, 2026 High ISBECAmergers and acquisitionscybersecurityidentity management
ransomware No Manners Here: The Ruthless Rise of The Gentlemen Ransomware The Gentlemen, a rapidly growing Ransomware-as-a-Service (RaaS) program, has significantly increased its victim count in 2026, becoming the second most active RaaS program globally. Leveraging a 90% affiliate payout stru… Palo Alto Unit 42 · Jul 10, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073USCAGBransomware-as-a-serviceracksedge-device-attack
threat-intel Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip Spanish authorities, with assistance from the FBI, arrested a man suspected of aiding pro-Russian hacktivist groups, specifically in facilitating the escape of a Ukrainian hacker linked to CARR. The investigation uncover… The Record · Jul 8, 2026 Medium SPPOBErussianhacktivismddos
threat-intel European Parliament Member Investigating Spyware Was Hacked With Pegasus A report by Citizen Lab revealed that former European Parliament member Stelios Kouloglou was repeatedly hacked with the Pegasus spyware while investigating the use of commercial surveillance tools, including Pegasus. Th… The Hacker News · Jul 3, 2026 High UKGRRUspywarepegasusapple
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
threat-intel Critical Windows Netlogon RCE flaw now exploited in attacks A critical Remote Code Execution (RCE) vulnerability (CVE-2026-41089) in Windows Netlogon is now being actively exploited in attacks, according to Belgium's national cybersecurity authority, the Centre for Cybersecurity… BleepingComputer · Jun 1, 2026 Critical CVE-2026-41089CVE-2026-45585CVE-2026-33825BErcenetlogonwindows
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups A global operation, dubbed Operation Saffron, led by France and the Netherlands, successfully dismantled the First VPN service, a virtual private network specifically designed for criminal use. The service was utilized b… The Hacker News · May 22, 2026 High USFRNLvpnransomwareanonymity
phishing Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware The Ghostwriter threat actor, linked to Belarus, has been conducting a phishing campaign targeting Ukrainian government entities since the spring of 2026. This campaign utilizes lures related to the Prometheus online lea… The Hacker News · May 22, 2026 High UKBERUphishingmalwarecobalt strike
threat-intel China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts. A China-aligned Advanced Persistent Threat (APT) group known as Webworm has shifted its focus from Asia to targeting European governmental organizations, specifically in Belgium, Italy, Serbia, Spain, Poland, and South A… Dark Reading · May 22, 2026 High CHBEITaptdiscordmicrosoft graph
threat-intel Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API A China-aligned threat actor known as Webworm has expanded its arsenal with two new backdoors, EchoCreep and GraphWorm, utilizing Discord and the Microsoft Graph API for command-and-control communications. The group, act… The Hacker News · May 20, 2026 High CHRUGEdiscordmicrosoft graphrat
threat-intel Webworm: New burrowing techniques This blog post details the evolving tactics of Webworm, a China-aligned APT group, particularly their activity in 2025. Webworm has shifted away from traditional backdoors in favor of more sophisticated techniques, inclu… WeLiveSecurity · May 20, 2026 High CVE-2017-7692BEITSEdiscordmicrosoft graph apic&c
threat-intel Microsoft Exchange Zero-Day Under Attack, No Patch Available A zero-day vulnerability (CVE-2026-42897) affecting Microsoft Exchange Outlook Web Access (OWA) is under active exploitation, allowing attackers to compromise mailboxes through cross-site scripting (XSS). Despite Microso… Dark Reading · May 18, 2026 High CVE-2026-42897BEzero-dayxssexchange