threat-intel Linux Process Name Masquerading, (Wed, Jun 24th) This SANS Internet Storm Center diary details a technique used by attackers, specifically the Velvet Ant Chinese group, to mask process names in Linux systems. Attackers modify the ‘comm’ and ‘cmdline’ entries in the /pr… SANS Internet Storm Center · Jun 24, 2026 Medium CHprocess_namemasqueradinglinux
vulnerability In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum This week’s cybersecurity news highlights several significant vulnerabilities and attacks across various platforms and industries. A critical phpBB flaw enabled session hijacking, while vulnerabilities in Chrome extensio… SecurityWeek · Jun 19, 2026 High CVE-2025-20701CHISsession hijackingchrome extensionssupply chain attack
threat-intel Close Encounters of the Human Kind This article from Cisco Talos details a novel approach to reverse engineering that leverages AI agents alongside traditional tools like the VB6 disassembler. The key innovation is exposing the disassembler's parsed data… Cisco Talos · Jun 18, 2026 High GBFRUSreverse engineeringaiautomation
threat-intel Google to use UK and EU user IP addresses for ad personalization Google plans to begin using IP addresses from August 3, 2026, across the EEA, UK, and Switzerland for ad measurement and personalization. This shift is driven by regulatory changes regarding personal data, particularly u… BleepingComputer · Jun 17, 2026 Medium GBEUCHprivacygdprconsent
threat-intel Hostile states behind three-quarters of attacks on Britain's critical infrastructure, cyber chief warns This article reports that the UK’s cyber chief, Richard Horne, has shifted the government’s approach to cybersecurity, framing it as a ‘contest’ against hostile state actors rather than a ‘risk’ to be managed. He reveale… The Record · Jun 17, 2026 High CHUKstate-sponsoredcritical infrastructurecyber conflict
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
threat-intel Security Community Slams US Ban on Exporting Mythos, Fable The US government recently imposed an export control order restricting access to Anthropic's Claude Fable 5 and Mythos 5 large language models (LLMs) for foreign nationals, citing national security concerns, particularly… Dark Reading · Jun 16, 2026 High USCHllmaiexport control
threat-intel Cybersecurity Executives Urge the Trump Administration to Ease Restrictions on Anthropic AI Models A coalition of cybersecurity executives and experts is urging the Trump administration to reverse its restrictions on Anthropic’s AI models, specifically Fable 5 and Mythos 5. The group argues that limiting access to the… SecurityWeek · Jun 16, 2026 Medium CHUNaiartificial intelligencecybersecurity
threat-intel FishMonger’s arsenal upgraded: SprySOCKS for Windows ESET researchers have discovered two new, undocumented Windows variants of FishMonger's SprySOCKS backdoor, operated by the Chinese threat actor I-SOON (believed to be part of the Winnti Group). These variants, WIN_DRV a… WeLiveSecurity · Jun 16, 2026 High CHHOTAwindowsbackdoorkernel driver
threat-intel Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails A China-linked espionage group, UNC6508, gained access to North American medical, academic, and military research networks via a backdoor on REDCap servers, stealing sensitive research and defense emails. The attackers e… The Hacker News · Jun 15, 2026 High CHUSCAespionageredcapgoogle workspace
threat-intel China-Nexus Actor Spied on US Researchers Undetected for a Year Google’s Threat Intelligence Group (GTIG) discovered and disrupted a year-long espionage campaign by the China-Nexus threat actor, UNC6508, targeting US academic, medical, and military research institutions. The actor ut… Dark Reading · Jun 15, 2026 High CHUScyber espionageintel gatheringcredential theft
threat-intel Chinese hackers breach REDCap servers, steal medical research A Chinese espionage campaign, attributed to UNC6508, targeted a North American medical research institution by exploiting vulnerabilities in the REDCap platform. The attackers deployed the custom malware, ‘Infinitered,’… BleepingComputer · Jun 15, 2026 High CHUSCAespionagecredential_theftredcap
threat-intel ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More This week’s cybersecurity recap highlights several active exploits and attacks, including a Chrome 0-day being actively leveraged, a ShinyHunters gang exploiting a PeopleSoft zero-day for lateral movement and data exfilt… The Hacker News · Jun 15, 2026 High CVE-2026-11645CVE-2026-2441CVE-2026-3909UNCHzero-dayphishingsupply-chain
threat-intel US Cracks Down on Anthropic AI Models Amid Abuse Concerns Anthropic has suspended access to its Fable 5 and Mythos 5 AI models following a US government export control directive, aimed at preventing foreign nationals from utilizing them. This action stems from growing concerns… Dark Reading · Jun 15, 2026 High CHRUUKaicybersecuritythreat intelligence
phishing FBI disrupts massive AI-powered phishing service using a million URLs The FBI, in collaboration with Google and Black Lotus Labs, successfully disrupted a large-scale Chinese phishing-as-a-service operation called Outsider Enterprise. This operation utilized AI to generate and distribute p… BleepingComputer · Jun 14, 2026 High CHphishingaisms
apt Chinese hackers hijack auth flow, spy on isolated network for a decade Chinese cyber espionage group Velvet Ant conducted a decade-long operation, gaining persistent access to a large organization’s isolated critical infrastructure network by hijacking its authentication flow. The attackers… BleepingComputer · Jun 13, 2026 Critical CHespionageauthenticationpersistence
phishing Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing Google has filed a lawsuit against a Chinese cybercrime network, Outsider, for using its Gemini AI agent to conduct massive smishing attacks targeting Americans. The network operates a phishing-as-a-service (PhaaS) platf… The Hacker News · Jun 12, 2026 High CHUSaiphishingsmishing
threat-intel Major US surveillance program poised to lapse after legislative deadlock This article reports on a looming lapse in the US surveillance program, Section 702 of the FISA, due to legislative deadlock in Congress. The program, which allows intelligence agencies to collect communications of forei… The Record · Jun 12, 2026 High USIRCHfisasurveillanceintelligence
threat-intel ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories This week’s threat intelligence bulletin highlights several concerning developments, including a large-scale leak of identity records facilitated by infostealers, the emergence of a sophisticated MaaS RAT named SilabRAT… The Hacker News · Jun 11, 2026 High CVE-2026-49494USCHNOinfostealersmaas ratcredential theft
data-breach Coupang hit with record $409 million data breach fine in Korea Coupang, a major South Korean e-commerce company, has been hit with a record $409 million fine by the Personal Information Protection Commission (PIPC) due to a massive data breach affecting over 37 million customers. Th… BleepingComputer · Jun 11, 2026 High SOCHdata breachauthenticationdata security