vulnerability CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies regarding two critical vulnerabilities in TrueConf, a secure video conferencing platform. Threat actors, specifically the hacktivist group Head Mare, have exploited these vulnerabilities to deploy PhantomCore… SecurityWeek · Aug 21, 2026 High CVE-2026-72529CVE-2026-72530RUBYvulnerabilitypatchtrueconf
threat-intel Hackers used Telegram phishing campaign to target exiled Belarusian activist Hackers are using highly personalized Telegram phishing campaigns targeting exiled Belarusian activists and users in Russia and Kazakhstan. The campaign leverages private messages and tailored fake login pages to steal T… The Record · Jul 27, 2026 High KZRUBYphishingaccount-hijackingtelegram
threat-intel _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th) A self-propagating bot, originating from Belarus (as claimed by its creator), has been scanning for open ports and attempting brute-force login attempts on various servers worldwide. The bot’s purpose is to raise awarene… SANS Internet Storm Center · Jul 9, 2026 Medium BYscanbrute-forcessh
malware PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords PamStealer, a new macOS information stealer developed by Jamf Threat Labs, utilizes deceptive tactics like mimicking the Maccy clipboard manager and exploiting Pluggable Authentication Modules (PAM) to steal login creden… The Hacker News · Jul 3, 2026 High RUBYKZmacosstealercredential theft
threat-intel Spyware found on phone of European Parliament member probing it A former European Parliament member, Stelios Kouloglou, was repeatedly targeted with Pegasus spyware while investigating the misuse of commercial spyware. Citizen Lab researchers discovered the infections occurred during… The Record · Jul 3, 2026 High GRDERUspywarepegasuseuropean parliament
threat-intel ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures ClickFix campaigns are expanding their malware delivery tactics with new loaders, including BabaDeda Loader, Lorem Ipsum Loader, and Storage Crypter, targeting education and financial organizations. These attacks utilize… The Hacker News · Jun 16, 2026 High RUBYsocial engineeringloaderpayload
phishing Belarus-linked hackers target Gmail accounts of Polish public figures and their families A Belarus-linked hacking group, GhostWriter (UNC1151/Storm-0257), has expanded its phishing operations to target the personal Gmail accounts of Polish public figures and their families. The group’s tactics involve creati… The Record · Jun 14, 2026 High PLBYUAphishingpolandbelarus
data-breach Lithuania investigates theft of 600,000 state registry records by foreign actor Lithuania is investigating a significant data breach affecting its state registry systems, resulting in the theft of approximately 600,000 records containing personal and property information. The breach exploited compro… The Record · May 26, 2026 High LTRUBYdata breachregistrycyberattack
threat-intel Belarus-linked hackers use fake training certificates to target Ukrainian officials A Belarus-linked hacking group, GhostWriter (UNC1151/Storm-0257), is conducting a new espionage campaign targeting Ukrainian government officials. The operation utilizes sophisticated phishing emails disguised as trainin… The Record · May 21, 2026 High UABYphishingmalwareespionage
threat-intel FrostyNeighbor: Fresh mischief and digital shenanigans FrostyNeighbor, a long-running cyberespionage group allegedly linked to Belarus, is continuing its operations targeting governmental organizations in Ukraine and other Eastern European countries. The latest activity invo… WeLiveSecurity · May 14, 2026 High BYPLLTcyberespionagecobalt strikepicassoloader