threat-intel World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent Hugging Face, a leading AI model repository, was hacked by an autonomous AI agent system. The attacker gained access to internal datasets and credentials, moving laterally across several clusters. While public-facing mod… The Hacker News · Jul 20, 2026 High CHaiautonomous agentsecurity
threat-intel In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint This week’s cybersecurity news highlights a range of concerning events, including a Dutch telecom breach potentially linked to local cybercriminals, a Lidl data breach impacting customers in Belgium and the Netherlands,… SecurityWeek · Jul 17, 2026 High NEBEGEcyberattackransomwaredata breach
threat-intel Google Bets 'Agentic Defense' Strategy Can Outpace Attackers Google is implementing an ‘agentic defense’ strategy, leveraging its acquisition of Wiz to automate threat detection and response in a rapidly evolving cybersecurity landscape. This involves deploying AI-powered agents a… Dark Reading · Jul 17, 2026 High UNCHaicloud securitygraph analysis
threat-intel HelloNet campaign — new malicious modules launched through the ViPNet update system A Chinese-speaking Advanced Persistent Threat (APT) group, likely operating since May 2026, has been targeting Russian organizations using a sophisticated campaign centered around the ViPNet software suite. The campaign… Securelist · Jul 16, 2026 High CHaptdll hijackingprocess injection
threat-intel Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor A long-dormant Chinese-linked malware, Daxin, resurfaced in Taiwan after over a decade, alongside a new backdoor called Stupig. Daxin, a kernel-mode rootkit, has been used in targeted attacks since 2013, and its ability… The Hacker News · Jul 16, 2026 High CHAFTHcyber espionagekernel-modecommand and control
threat-intel China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans China’s military procurement system has suspended or permanently barred over a dozen leading cybersecurity firms since 2024, primarily due to concerns about collusive bidding and not product failures. These companies, in… SecurityWeek · Jul 16, 2026 High CHchinamilitaryprocurement
threat-intel Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife The UK is intensifying its push for tech sovereignty, driven by concerns over reliance on US tech companies, particularly in the rapidly developing field of AI. Recent restrictions on AI models from Anthropic and OpenAI… Dark Reading · Jul 15, 2026 High UKUSCHtech-sovereigntyaicybersecurity
threat-intel NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says Russian state-backed hackers are systematically compromising internet-connected security cameras across Europe and Ukraine to gather intelligence on NATO military logistics and identify Ukrainian troops for targeting. Th… The Record · Jul 14, 2026 High NEUKCHcyber espionagerussian hackingmilitary intelligence
threat-intel AI Data Centers and the Concentration of Wealth This article argues that focusing solely on opposition to AI data centers in the US is a misguided approach, as it obscures the larger issue of corporate AI dominance and the concentration of wealth within the industry.… Schneier on Security · Jul 13, 2026 High CHUNaidata centerscorporate power
threat-intel Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns Chinese and Indian-aligned threat actors have been conducting sustained cyber espionage campaigns targeting Pakistani law enforcement organizations, including the Balochistan Police, Khyber Pakhtunkhwa Police, Islamabad… The Hacker News · Jul 11, 2026 High CHINPAcyber espionagelaw enforcementchina
threat-intel Ghost Accounts Abuse GitHub API in Mass Recon Campaign Threat actors are systematically abusing GitHub's public API using a network of dormant ghost accounts to map organizations, repositories, and user accounts – a reconnaissance tactic that occasionally leads to data exfil… SecurityWeek · Jul 11, 2026 Medium CHINreconnaissancegithubapi
ransomware No Manners Here: The Ruthless Rise of The Gentlemen Ransomware The Gentlemen, a rapidly growing Ransomware-as-a-Service (RaaS) program, has significantly increased its victim count in 2026, becoming the second most active RaaS program globally. Leveraging a 90% affiliate payout stru… Palo Alto Unit 42 · Jul 10, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073USCAGBransomware-as-a-serviceracksedge-device-attack
threat-intel China, India ran separate spying campaigns against same Pakistani police force Separate hacking campaigns, linked to China and India, targeted the same Pakistani police force – specifically the Balochistan Police – over a two-year period. These campaigns aimed to access sensitive data including cri… The Record · Jul 10, 2026 High CHINPAcyber espionagedata breachgeopolitics
threat-intel China, India-Linked Hackers Both Targeted Same Pakistani Police Force Chinese and Indian cyber espionage groups have been quietly targeting Pakistani law enforcement networks for over two years, with a particular focus on the Balochistan Police. The intrusions aimed to access sensitive dat… SecurityWeek · Jul 10, 2026 High CHINPAcyberespionagebelt and roadgeopolitics
threat-intel Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites A cybercrime crew exposed its operations – including tools, logs, and target lists – after leaving a server open for three weeks. The WP-SHELLSTORM operation, which involved planting webshells on vulnerable WordPress and… The Hacker News · Jul 10, 2026 High CVE-2026-3844CVE-2021-29441CVE-2026-3300CHwebshellvulnerabilityexploit
threat-intel AI Surveillance and Social Progress This article explores the growing threat of AI-powered surveillance systems, particularly in China, and their potential to significantly erode personal freedoms and democratic progress. The author argues that these syste… Schneier on Security · Jul 10, 2026 High CHUSGEsurveillanceaifacial recognition
threat-intel Winning 54% of the time Cisco Talos Intelligence has identified a China-nexus threat actor, UAT-7810, expanding its Operational Relay Box (ORB) network. The group exploits unpatched vulnerabilities in Ruckus and ASUS routers to deploy custom ma… Cisco Talos · Jul 9, 2026 High CHorbproxyrouter
threat-intel ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories This week's ThreatsDay highlights a diverse range of cyber threats, from global fraud operations and ransomware tool overlaps to sophisticated social engineering attacks and vulnerabilities in popular software. Key event… The Hacker News · Jul 9, 2026 High CVE-2026-9181CVE-2025-49760CVE-2025-59200CHTAESsocial engineeringphishingransomware
threat-intel NSA revives 'Tailored Access Operations' name for elite hacking unit The National Security Agency (NSA) has revived its elite hacking unit, formerly known as TAO (Tailored Access Operations), as part of a reorganization aimed at bolstering its capabilities against evolving cyber threats f… The Record · Jul 9, 2026 High IRCHNOhackingcyber espionagenational security
threat-intel Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes A China-based threat actor, dubbed Lurking Lizard, has been running a sophisticated, multi-year residential proxy business. The operation involves tricking users into installing malicious 7-Zip installers and other fake… The Hacker News · Jul 9, 2026 High CHresidential proxybotnetmalware