threat-intel New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework A new threat cluster, OP-512, is targeting Microsoft IIS servers with a custom web shell framework, exhibiting sophisticated evasion techniques and centralized management capabilities. ReliaQuest has linked the activity… The Hacker News · Jun 5, 2026 High CNiisweb shellespionage
threat-intel FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins A wave of fraudulent activity targeting FIFA World Cup 2026 fans is underway, involving fake websites, banking malware, and stolen login credentials. The operation, spearheaded by the Chinese-speaking group ‘GHOST STADIU… The Hacker News · Jun 5, 2026 High USCAMXfraudphishingmalware
threat-intel PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network PCPJack, a threat actor initially linked to TeamPCP, has established a covert SMTP email relay network by hijacking 230 cloud servers across AWS, Google Cloud, and Azure. The operation involved converting business server… The Hacker News · Jun 5, 2026 High USUKDEsmtp relaycloud proxyc2
threat-intel China Uses Dual-Method Cyberattack on Czech Orgs This article details a dual-method cyberattack targeting organizations in the Czech Republic and Taiwan, orchestrated by Chinese nation-state threat actors. The campaign, dubbed "Operation Dragon Weave," utilizes a spear… Dark Reading · Jun 2, 2026 High CZCNTWspear-phishingrustazure
threat-intel Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit An unknown threat actor exploited CVE-2026-39987 in Marimo to gain initial access, subsequently using a large language model (LLM) agent to conduct post-exploitation activities, including stealing credentials and exfiltr… The Hacker News · May 29, 2026 High CVE-2026-39987CNllmpost-exploitationcredential theft
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
threat-intel Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans A Chinese-speaking fraud gang, dubbed GHOST STADIUM, is impersonating FIFA's official website to steal credentials and payment details from fans seeking tickets for the 2026 World Cup. The operation, involving over 300 f… The Record · May 28, 2026 High CNUSCAfraudphishingworld cup
vulnerability Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter This advisory details a critical vulnerability in the Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter, specifically version 7.03T.07. The device contains hardcoded administrative cr… CISA Advisories · May 28, 2026 Critical CVE-2026-7786CNfirmwarecredentialsiot
vulnerability Gitea Vulnerability Exposes Private Container Images without Authentication A significant vulnerability (CVE-2026-27771) has been identified in Gitea, a popular open-source Git repository hosting platform. The flaw allows unauthorized access to private container images, exposing sensitive data w… The Hacker News · May 27, 2026 High CVE-2026-27771CNUSDEcontainergitvulnerability
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
ransomware Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks A critical vulnerability (CVE-2026-26980) in Ghost CMS is being exploited to hijack over 700 websites, primarily through ClickFix attacks. Threat actors are leveraging this SQL injection flaw to steal admin API keys and… The Hacker News · May 25, 2026 Critical CVE-2026-26980CNsql injectionclickfixjavascript
threat-intel Content Delivery Exploit Opens Websites to Brand Hijacking This article details a new exploit, dubbed "Underminr," that leverages vulnerabilities in Internet infrastructure to allow attackers to hijack websites and conceal malicious activity. The technique, a successor to domain… Dark Reading · May 21, 2026 High USEUCNcdndnsdomain fronting
threat-intel Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks Microsoft disrupted a malware-signing-as-a-service (MSaaS) operation, dubbed OpFauxSign, led by the threat actor Fox Tempest, which was using its Artifact Signing system to distribute malware and ransomware. The operatio… The Hacker News · May 20, 2026 High USFRINmsaascode-signingmalware
vulnerability Kieback & Peter DDC Building Controllers This CISA advisory details a cross-site scripting (XSS) vulnerability affecting several versions of Kieback & Peter’s DDC Building Controllers. The vulnerability, CVE-2026-4293, allows an attacker to execute JavaScript c… CISA Advisories · May 19, 2026 Medium CVE-2026-4293AUATCNxssbuilding automationot
malware From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat This report details the discovery of a commodity BadIIS malware variant, identified by its "demo.pdb" strings, being utilized by multiple Chinese-speaking cybercrime groups operating under a MaaS model. Developed by an a… Cisco Talos · May 19, 2026 Medium CNUSGBseomalware-as-a-serviceiis
threat-intel [Guest Diary] New Malware Libraries means New Signatures, (Fri, May 15th) This SANS Internet Storm Center diary details a new observation of the long-running mdrfckr campaign, a Shellbot associated with the Outlaw/Dota group. The key finding is the identification of a previously undocumented v… SANS Internet Storm Center · May 15, 2026 Medium USCNshellbotlibsshmdrfckr
threat-intel A rigged game: ScarCruft compromises gaming platform in a supply-chain attack A North Korean-aligned APT group, ScarCruft (also known as APT37 or Reaper), conducted a supply-chain attack targeting a video game platform used by ethnic Koreans in the Yanbian region of China. The attackers injected a… WeLiveSecurity · May 5, 2026 High CNKPsupply-chainnorth-koreaespionage