threat-intel Russia conducting daily attacks on UK 'from seabed to cyberspace,' spy chief warns GCHQ Director Anne Keast-Butler warned of daily, sophisticated cyberattacks originating from Russia targeting the UK and Europe, spanning undersea cables to cyberspace. These attacks are focused on critical infrastructur… The Record · May 28, 2026 High UKRUCHcyberattackhybrid warfareintelligence
threat-intel ESET APT Activity Report Q4 2025–Q1 2026 ESET’s Q4 2025 – Q1 2026 APT Activity Report highlights a period of intense geopolitical activity driving advanced cyber espionage. China-aligned actors were mobilized to monitor maritime and energy developments, while I… WeLiveSecurity · May 28, 2026 High CHIRPOaptcyber espionagegeopolitics
threat-intel UK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About Russia British intelligence chief Anne Keast-Butler warned of the escalating threat posed by Russia’s cyber activities, particularly the weaponization of artificial intelligence, and emphasized the urgent need for increased cyb… SecurityWeek · May 27, 2026 High UKRUCHartificial intelligencecybersecurityrussia
vulnerability Microsoft Issues Out-of-Band SharePoint Patch Microsoft has released an out-of-band security patch to address a critical remote code execution vulnerability (CVE-2026-45659) in SharePoint Server. The flaw allows authenticated attackers to execute code without elevat… Dark Reading · May 26, 2026 Critical CVE-2026-45659CHremote code executionsharepointzero-day
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups A global operation, dubbed Operation Saffron, led by France and the Netherlands, successfully dismantled the First VPN service, a virtual private network specifically designed for criminal use. The service was utilized b… The Hacker News · May 22, 2026 High USFRNLvpnransomwareanonymity
threat-intel China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts. A China-aligned Advanced Persistent Threat (APT) group known as Webworm has shifted its focus from Asia to targeting European governmental organizations, specifically in Belgium, Italy, Serbia, Spain, Poland, and South A… Dark Reading · May 22, 2026 High CHBEITaptdiscordmicrosoft graph
malware The art of being ungovernable This analysis focuses on a Cisco Talos report detailing the emergence of a sophisticated, multi-year-old BadIIS malware variant being utilized by Chinese-speaking cybercrime groups as part of a malware-as-a-service (MaaS… Cisco Talos · May 21, 2026 High CHmalware-as-a-serviceseo fraudtraffic hijacking
malware Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor A new Linux malware, dubbed Showboat, has been used in a campaign targeting a telecommunications provider in the Middle East since at least 2022. The malware, developed by a China-linked threat actor group known as Calyp… The Hacker News · May 21, 2026 High CVE-2021-26855AFAZCHlinuxsocks5c2
threat-intel Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks This article details the discovery of "Showboat" (kworker), a Linux post-exploitation framework being shared among Chinese Advanced Persistent Threat (APT) groups, primarily Calypso and Red Lamassu. The malware has been… Dark Reading · May 21, 2026 Medium CHAFUKaptlinuxspyware
threat-intel Chinese hackers target telcos with new Linux, Windows malware A Chinese cyber-espionage group, known as Calypso (Red Lamassu), has been targeting telecommunications providers globally since mid-2022 with a dual-pronged malware campaign utilizing Showboat (Linux) and JMFBackdoor (Wi… BleepingComputer · May 21, 2026 High CHMIASlinuxwindowsespionage
vulnerability ABB B&R Automation Runtime This CISA advisory details vulnerabilities within ABB B&R Automation Runtime versions prior to 6.4. Specifically, the System Diagnostic Manager (SDM) component is susceptible to reflected cross-site scripting (XSS) and i… CISA Advisories · May 21, 2026 High CVE-2025-3449CVE-2025-3448CVE-2025-11498CHxsscsvsdm
vulnerability ABB B&R Automation Studio ABB has issued a security advisory regarding vulnerabilities in its B&R Automation Studio software. The issues, stemming from SQLite versions, could lead to memory corruption and heap buffer overflows, potentially allowi… CISA Advisories · May 21, 2026 High CVE-2025-6965CVE-2025-3277CVE-2023-7104CHsqliteheap-overflowmemory-corruption
threat-intel ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories This week's threat intelligence report highlights a diverse range of security incidents and vulnerabilities, including a significant Pwn2Own competition with substantial rewards, warnings about the risks of deploying age… The Hacker News · May 21, 2026 High CVE-2026-45793CVE-2026-8631UKUSCHzero-dayai securitysocial engineering
threat-intel Texas, Florida top list of states reporting millions of dollars lost through crypto ATMs A recent FBI report reveals a significant surge in financial losses linked to cryptocurrency ATMs across the United States, totaling $388 million in 2025. Texas and Florida topped the list of states experiencing these lo… The Record · May 20, 2026 High CHNEAUcryptocurrencyscamsfraud
threat-intel Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API A China-aligned threat actor known as Webworm has expanded its arsenal with two new backdoors, EchoCreep and GraphWorm, utilizing Discord and the Microsoft Graph API for command-and-control communications. The group, act… The Hacker News · May 20, 2026 High CHRUGEdiscordmicrosoft graphrat
vulnerability ZKTeco CCTV Cameras A vulnerability has been identified in ZKTeco CCTV cameras, specifically models utilizing the SSC335-GC2063-Face-0b77 Solution firmware, allowing unauthorized access to camera credentials and configuration information. T… CISA Advisories · May 19, 2026 Medium CVE-2026-8598CHcctvcameraauthentication
threat-intel The quest for greater tech independence The article explores the growing trend of nations, particularly in Europe, seeking greater tech sovereignty – the ability to independently control their digital infrastructure and technology supply chains – driven by con… WeLiveSecurity · May 19, 2026 High EUCHUStech sovereigntydigital independencesupply chain
apt Alleged Silk Typhoon hacker extradited to the United States to face charges A Chinese national, Xu Zewei, has been extradited to the United States to face charges related to his alleged involvement with the Hafnium hacking group, also known as Silk Typhoon. He is accused of attempting to steal c… Graham Cluley · Apr 29, 2026 Critical CHUSstate-sponsoredcyber espionageexchange server