threat-intel New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic A China-linked cybercrime group, Silver Fox, is using a new Rust-based remote access trojan called MODBEACON to target technology, education, and state-owned enterprises in Asia. The trojan utilizes gRPC streaming for en… The Hacker News · Jul 10, 2026 High CNrustgrpcc2
threat-intel China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors A China-linked advanced persistent threat group, UAT-7810, has expanded its arsenal with new backdoors, including LongLeash, DogLeash, and JarLeash, as part of a long-running espionage campaign. The group primarily targe… SecurityWeek · Jul 8, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717CNbackdooraptespionage
threat-intel Google Is Suing Chinese Scammers Who Are Using Gemini Google is taking legal action against a Chinese group, Outsider Enterprise, who were leveraging Google's Gemini AI to create sophisticated phishing campaigns. The group utilized Telegram to offer ‘phishing-as-a-service,’… Schneier on Security · Jul 7, 2026 Medium CNphishingaigemini
threat-intel Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects This Kaspersky report, based on 2025 compromise assessment engagements, highlights significant missed incidents due to inadequate monitoring, delayed detection, and communication gaps. The analysis reveals a concerning t… Securelist · Jul 2, 2026 High SACNRUmissed incidentsthreat detectionincident response
threat-intel Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts A massive, automated password spray attack targeting Microsoft's Azure CLI compromised at least 78 Microsoft accounts across 64 organizations. The attack leveraged a deprecated OAuth flow (ROPC) to bypass Conditional Acc… The Hacker News · Jul 1, 2026 High USCNpassword sprayropcconditional access
threat-intel China-Linked Group Targets Southeast Asia Critical Systems A China-linked cyber threat group, CL-STA-1062 (formerly UAT-7237), has been targeting critical infrastructure providers in Southeast Asia over the past year, deploying a new backdoor tool called TinyRCT. The group has s… Dark Reading · Jul 1, 2026 High CNMYTHchinaaptbackdoor
malware RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS A new botnet, RustDuck, is leveraging Rust programming to hijack routers, IP cameras, and servers for DDoS attacks. Developed by QiAnXin's XLab, the botnet utilizes a two-stage approach, exploiting vulnerabilities in dev… The Hacker News · Jun 30, 2026 High CVE-2017-17215CVE-2025-29635CVE-2024-1781CNddosbotnetrust
threat-intel Local Police Collusion Hampers Crackdown on Asian Scam Centers This article reports on the ongoing challenge of combating cybercrime, specifically online scams, centered in Southeast Asia, particularly Cambodia, Myanmar, and the Philippines. Despite international pressure and arrest… Dark Reading · Jun 25, 2026 High KHUSCNcybercrimescamcorruption
vulnerability Siemens Products using OpenSSL A stack-based buffer overflow vulnerability (CVE-2025-15467) has been identified in various Siemens products utilizing OpenSSL. This vulnerability allows a remote attacker to potentially cause a denial-of-service or exec… CISA Advisories · Jun 23, 2026 High CVE-2025-15467DEUSCNopensslbuffer overflowdenial of service
threat-intel AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network A new malware family, dubbed AryStinger, is exploiting vulnerabilities in older Realtek RTL819X routers to create a reconnaissance network. Approximately 4,300 routers, primarily D-Link models, have been infected, scanni… The Hacker News · Jun 22, 2026 Medium CVE-2013-3307CVE-2016-5681CVE-2025-11837KRCNSEreconnaissanceproxyiot
malware AryStinger botnet infected thousands of D-Link routers worldwide A new botnet, named AryStinger, has been discovered compromising over 4,000 outdated D-Link routers worldwide, turning them into proxies for malicious traffic. The malware utilizes multiple vulnerabilities to perform sca… BleepingComputer · Jun 21, 2026 High CVE-2013-3307CVE-2016-5681CVE-2025-11837KRCNSErouterbotnetdns
threat-intel CISA warns Fortinet users to secure devices after FortiBleed leak CISA has issued a warning to Fortinet customers regarding the "FortiBleed" data leak, which exposed nearly 74,000 firewall and VPN credentials. Threat actors are exploiting these compromised credentials to target interne… BleepingComputer · Jun 19, 2026 High USRUCNcredentialsvpnfirewall
threat-intel Close Encounters of the Human Kind This article from Cisco Talos details a novel approach to reverse engineering that leverages AI agents alongside traditional tools like the VB6 disassembler. The key innovation is exposing the disassembler's parsed data… Cisco Talos · Jun 18, 2026 High GBFRUSreverse engineeringaiautomation
threat-intel ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories This week’s ThreatDay Bulletin highlights several concerning security incidents, including browser extension abuse, macOS malware attacks, AI-powered malware delivery, and a global phishing campaign targeting travel book… The Hacker News · Jun 18, 2026 High CVE-2026-20127CVE-2026-49975USCNJPbrowser extensionsmacos malwareai abuse
threat-intel China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Researchers have identified new Windows variants of the SprySOCKS backdoor, initially linked to the Chinese state-sponsored threat actor Earth Lusca (also known as Aquatic Panda). These variants, designated WIN_DRV and W… The Hacker News · Jun 16, 2026 High CVE-2023-24932CNTWHUbackdoorwindowsstealth
threat-intel Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk A widespread campaign involving malicious wallpapers distributed through the Steam Workshop has been identified, targeting gamers primarily in China and Russia. Attackers are exploiting the Wallpaper Engine’s sharing fea… Securelist · Jun 16, 2026 High CNRUsteamwallpapermalware
threat-intel FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers The FBI has taken down thirteen websites used by Chinese intelligence operatives to target and recruit U.S. government employees with access to sensitive information. These websites impersonated consulting firms offering… SecurityWeek · Jun 11, 2026 High USCNespionagerecruitmentcybersecurity
threat-intel China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance A China-linked botnet, dubbed JDY, has significantly expanded its operations, now comprising over 1,500 compromised SOHO and IoT devices. Initially a component of the KV-botnet, the JDY botnet is being used for large-sca… The Hacker News · Jun 10, 2026 High CVE-2026-35616USBRDEiotreconnaissancebotnet
vulnerability Gogs patches critical zero-day enabling remote code execution A critical zero-day vulnerability in Gogs, a remote collaboration platform, has been identified, allowing authenticated attackers to execute remote code and access private repositories. The flaw, present in versions up t… BleepingComputer · Jun 8, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPremote-code-executionzero-dayauthentication
apt Chinese APT deploys new malware to keep access to hacked networks A Chinese Advanced Persistent Threat (APT) group, tracked as UNC5221 (VerdantBamboo), has been conducting a prolonged espionage campaign targeting organizations in the United States, primarily leveraging the Brickstorm b… BleepingComputer · Jun 5, 2026 High CNespionagebackdoorpersistence