ransomware Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks The Gunra ransomware group, linked to state-sponsored actors, is aggressively targeting critical infrastructure and organizations globally, leveraging vulnerabilities in Fortinet and Schneider Electric appliances to gain… The Hacker News · Aug 11, 2026 High CVE-2024-5559CVE-2025-24472SOBRSPransomwarevulnerabilitysupply-chain
Des cibles françaises au cœur d’une plateforme cybercriminelle A ZATAZ investigation has uncovered a list of French organizations targeted by a cybercriminal group, Krybit, who are aggressively recruiting affiliates through a platform offering a lucrative 80% revenue split. The grou… ZATAZ · Aug 7, 2026 FRMXUSransomwarerecruitmentcybercrime
threat-intel AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls An AI meeting assistant, tl;dv, is vulnerable due to a misconfiguration in its Firebase environment, allowing unauthorized access to users' video calls and meeting data. A security researcher discovered that users could… Dark Reading · Aug 4, 2026 High MAUKBRfirebaseaimeeting assistant
threat-intel Almost Half of Malware Samples Communicate Direct to IP Almost half (45.32%) of malware samples with Command & Control (C2) activity bypass DNS entirely, communicating directly to IP addresses. This behavior, known as D2IP, is prevalent across various threat types, including… Palo Alto Unit 42 · Aug 4, 2026 High BRd2ipdnsc2
threat-intel An analysis of incidents at Brazilian educational institutions This report details cyberattacks targeting educational institutions in Brazil since 2025, highlighting a trend of leveraging readily available tools and valid accounts to gain access and deploy ransomware and other malwa… Securelist · Aug 3, 2026 High BRransomwarethreat-intelinsider-threat
threat-intel EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels The European Union is establishing a new team in Brussels to combat the misuse of AI, particularly concerning deepfakes, illicit imagery, and cyber threats. This initiative is part of a broader strategy to assert tech so… SecurityWeek · Jul 31, 2026 Medium EUUSCHaideepfakeregulation
threat-intel Brazilian Banking Trojan Actively Spreading in Portugal A long-standing Brazilian banking Trojan, Lampion, is actively targeting Portuguese organizations, leveraging the shared language and cultural connection between Brazilian hackers and Portuguese businesses. The malware,… Dark Reading · Jul 23, 2026 High BRPTESbanking trojanphishinggeofencing
threat-intel ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More This week saw a flurry of vulnerabilities and attacks, including a WordPress core flaw leading to remote code execution, exploitation of zero-day vulnerabilities in SonicWall VPN appliances, and a new malware framework (… The Hacker News · Jul 20, 2026 High CVE-2026-63030CVE-2026-60137CVE-2026-15409INTÜBRvulnerabilityzero-dayransomware
threat-intel New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands A new modular malware, TELEPUZ, is spreading via ClickFix lures and is being developed by a solo developer or small team. The malware steals data, runs commands, and evades detection through various techniques, including… The Hacker News · Jul 16, 2026 High BRINclickfixpastejackingmalware-as-a-service
threat-intel 20+ Hijacked Government Websites Became an Attack Channel A sophisticated campaign, dubbed PhantomEnigma, has hijacked over 20 Brazilian government websites to deliver malware and conduct attacks against banks and public agencies. Attackers leveraged compromised .gov.br infrast… The Hacker News · Jul 16, 2026 High BRgovernmentphishingmalware
threat-intel OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps OkoBot, a malware framework, has been actively targeting hardware wallet users since April 2025, primarily through phishing attacks leveraging a module called SeedHunter. SeedHunter intercepts the wallet's desktop softwa… The Hacker News · Jul 15, 2026 High BRVNCAphishingmalwarehardware wallet
ransomware No Manners Here: The Ruthless Rise of The Gentlemen Ransomware The Gentlemen, a rapidly growing Ransomware-as-a-Service (RaaS) program, has significantly increased its victim count in 2026, becoming the second most active RaaS program globally. Leveraging a 90% affiliate payout stru… Palo Alto Unit 42 · Jul 10, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073USCAGBransomware-as-a-serviceracksedge-device-attack
threat-intel 'BusySnake' Infostealer Slithers into Critical Infrastructure Networks The threat group Armored Likho, operating under the name 'BusySnake,' has infiltrated critical infrastructure networks across Russia, Brazil, and Kazakhstan. This group is leveraging a sophisticated infostealer to steal… Dark Reading · Jul 6, 2026 High RUBRKZinfostealercritical infrastructurenation-state
apt Armored Likho APT Targeting Government, Electric Power Entities The Armored Likho APT group is actively targeting government and electric power entities across multiple countries, including Russia, Brazil, and Kazakhstan. The group utilizes a diverse toolkit of malware, including RAT… SecurityWeek · Jul 6, 2026 High RUBRKZaptspear-phishingrat
threat-intel Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer Armored Likho, a previously undocumented threat actor, has been actively targeting government agencies and the power sector in Russia, Brazil, and Kazakhstan with a sophisticated campaign utilizing tools like BusySnake S… The Hacker News · Jul 3, 2026 High CVE-2025-9491RUBRKZspear-phishingremote access trojaninformation stealer
threat-intel Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign The Securelist report details a new cyber espionage campaign conducted by the Armored Likho (Eagle Werewolf) APT group, targeting government agencies and the electric power sector globally. The group utilizes a sophistic… Securelist · Jul 3, 2026 High RUBRKZaptphishinginfostealer
malware Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses A new browser extension campaign, dubbed Silent Swap by McAfee Labs, is targeting cryptocurrency users by stealthily replacing wallet addresses during transactions. The malicious extension, disguised as a Google Notes ut… The Hacker News · Jun 30, 2026 High INUSBRclipboardwalletcrypto
malware WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool A WhatsApp-based campaign is utilizing malicious VBScript files to trick users into installing ManageEngine RMM tool software. The campaign, currently active across multiple countries, leverages deceptive document names… The Hacker News · Jun 23, 2026 Medium MYBRINsocial engineeringvbsremote access
threat-intel Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries Google is implementing a new Android developer verification system, starting September 30, 2026, in Brazil, Indonesia, Singapore, and Thailand, to combat app scams and malware. This will block installations of apps from… The Hacker News · Jun 22, 2026 Medium BRIDSGapp scamsdeveloper verificationopen source
malware A VBScript campaign distributed through WhatsApp deploying RMM software A WhatsApp-distributed malware campaign, active as of June 2026, leverages deceptive VBScript files disguised as financial documents to trick users into executing malicious code. This code ultimately installs legitimate… Securelist · Jun 22, 2026 High MYBRINsocial engineeringvbswhatsapp