threat-intel ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More This week saw a flurry of vulnerabilities and attacks, including a WordPress core flaw leading to remote code execution, exploitation of zero-day vulnerabilities in SonicWall VPN appliances, and a new malware framework (… The Hacker News · Jul 20, 2026 High CVE-2026-63030CVE-2026-60137CVE-2026-15409INTÜBRvulnerabilityzero-dayransomware
threat-intel Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs A Russian-speaking threat actor, “bandcampro,” leveraged Google Gemini CLI to orchestrate a botnet and conduct various cybercrime activities, including dental clinic control and cryptocurrency fraud. The actor utilized t… The Hacker News · Jul 20, 2026 High USCARUaicybercrimebotnet
threat-intel Senator calls on Rubio, Blanche to push back against Canadian surveillance legislation Senator Ron Wyden is urging the Trump administration to push back against Canadian legislation that could force U.S. tech companies to create backdoors and share user data, potentially compromising U.S. national security… The Record · Jul 16, 2026 High CAUSsurveillanceprivacyencryption
threat-intel OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps OkoBot, a malware framework, has been actively targeting hardware wallet users since April 2025, primarily through phishing attacks leveraging a module called SeedHunter. SeedHunter intercepts the wallet's desktop softwa… The Hacker News · Jul 15, 2026 High BRVNCAphishingmalwarehardware wallet
threat-intel US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers Russian state-sponsored APT actors are actively targeting routers worldwide to compromise critical infrastructure. These attacks involve exploiting vulnerabilities and leveraging SNMP to steal device configurations and t… SecurityWeek · Jul 14, 2026 High CVE-2008-4128CVE-2018-0171USAUCAsnmpciscorouter
threat-intel Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 In June 2026, a significant number of cybersecurity M&A deals were announced, highlighting the industry's ongoing consolidation and investment in advanced security technologies. Several key acquisitions focused on areas… SecurityWeek · Jul 13, 2026 High ISBECAmergers and acquisitionscybersecurityidentity management
ransomware No Manners Here: The Ruthless Rise of The Gentlemen Ransomware The Gentlemen, a rapidly growing Ransomware-as-a-Service (RaaS) program, has significantly increased its victim count in 2026, becoming the second most active RaaS program globally. Leveraging a 90% affiliate payout stru… Palo Alto Unit 42 · Jul 10, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073USCAGBransomware-as-a-serviceracksedge-device-attack
threat-intel In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops Multiple cybersecurity incidents and threats are unfolding, including a ransomware affiliate pleading guilty in the US, a subscription-based remote access trojan (QuimaRAT) being actively sold on the dark web, and a Cana… SecurityWeek · Jul 10, 2026 High ARCAUSransomwaredata breachremote access trojan
ransomware Mount Royal University Confirms Data Stolen in Ransomware Attack Mount Royal University in Canada suffered a ransomware attack that resulted in the theft of employee and student data. The attackers, identified as CMD Organization, exfiltrated over 10 terabytes of information and are d… SecurityWeek · Jul 9, 2026 High CAransomwaredata breachtor
threat-intel Mexico's New Cyber Plan Faces Its First Real Test Mexico's National Cybersecurity Plan, designed to bolster the country's digital defenses ahead of the 2026 FIFA World Cup, is facing an early test. Despite the plan's goals – including establishing a National Cybersecuri… Dark Reading · Jul 8, 2026 High MEUNCAcybersecuritylatin americacyberattack
threat-intel Cybersecurity and the Gap Between Skill and Ability A joint statement from the Five Eyes intelligence alliance warned of escalating cyber risks due to the increasing capabilities of AI models, particularly their ability to autonomously carry out cyberattacks. The statemen… Schneier on Security · Jul 8, 2026 High UNCAAUaicybersecuritythreat intelligence
vulnerability Hydro-Québec Le Circuit Electrique charging station backend Hydro-Québec has addressed vulnerabilities in its Le Circuit Electrique charging station backend, preventing potential privilege escalation and denial-of-service attacks. The issues stemmed from a lack of proper authenti… CISA Advisories · Jul 7, 2026 Medium CVE-2026-20744CVE-2026-42952CVE-2026-44383CAcwe-284cwe-307cwe-613
threat-intel Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities A China-aligned threat actor cluster, tracked as UNC5174 and linked to ShadowPad, has been exploiting vulnerabilities in Roundcube webmail software at U.S. and Canadian universities. The campaign leverages CVE-2024-42009… The Hacker News · Jul 7, 2026 High CVE-2024-42009CVE-2025-49113CHUSCAroundcubexsscve-2024-42009
threat-intel Canadian spy agency reports hacking three criminal groups in 2025 The Canadian Communications Security Establishment (CSE) conducted several authorized cyber operations targeting foreign criminal groups in 2025. These operations aimed to disrupt extremist groups spreading violent ideol… The Record · Jul 6, 2026 Medium CAcybersecuritynational securitycyber espionage
threat-intel In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting This report details several significant cybersecurity events across multiple sectors, including a Canadian hacker’s imprisonment for a Texas GOP cyberattack, a large KDDI data breach impacting 14 million users, and the d… SecurityWeek · Jul 3, 2026 High CAJAUNzero-dayhacktivismdata breach
ransomware Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials The Anubis ransomware group, a rebranded version of Sphinx, is actively exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to gain initial access to victim networks. They leverage legitimate RMM tools like Scree… The Hacker News · Jul 2, 2026 High CVE-2025-5777USUKAUcitrixbleedransomware-as-a-servicecredential theft
data-breach Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches Multiple Japanese companies, including an insurer, brewer, manufacturer, and telecom provider, have recently disclosed significant cyber breaches impacting customer data and operational systems. The attacks range from a… The Record · Jul 1, 2026 High JASICAdata breachransomwarecyberattack
threat-intel This month in security with Tony Anscombe – June 2026 edition This month’s security roundup highlights a critical CISA policy demanding rapid patching of vulnerabilities for federal agencies, a targeted cyberattack campaign against US-based Automatic Tank Gauges (ATGs), a surge in… WeLiveSecurity · Jun 30, 2026 Medium USUKCAvulnerabilitycyberattacksocial media
threat-intel Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat This article details the unconventional career path of Chris Thompson, a former IBM X-Force Red head and now CEO of RemoteThreat, tracing his journey from a teenage game hacker to a respected security professional. Thomp… SecurityWeek · Jun 30, 2026 Medium UKCAhackerred teamingai
vulnerability Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth A critical vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster allows unauthenticated attackers to execute arbitrary commands as root by manipulating API requests. The flaw stems from a lack of proper sanitization… The Hacker News · Jun 30, 2026 Critical CVE-2026-8037CVE-2026-33691CVE-2024-1212CAcommand-injectionrootapi