vulnerability PaperCut Releases Emergency Patch for Exploited Zero-Day PaperCut has released an emergency patch for a zero-day vulnerability being actively exploited in its print management solutions. The vulnerability, currently unassigned a CVE, is linked to malware delivery and log deletion attempts, with approximately 1,000 instances exposed globally. The company urges immediate actio… SecurityWeek · 2d ago High USCAEUzero-dayvulnerabilitypatch
threat-intel Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler Iranian state-sponsored hacking group Nimbus Manticore (linked to Charming Kitten) has expanded its toolset with a TWOSTROKE-like backdoor and SSH tunneling utility, furthering its espionage activities targeting defense,… The Hacker News · 4d ago High IRMIEUsshbackdoorc2
threat-intel ShinyHunters menace Logitech et Streamlabs The ShinyHunters group is aggressively targeting numerous companies, including Logitech and Streamlabs, using a coordinated extortion campaign. They claim to have compromised vast amounts of sensitive data – including pe… ZATAZ · Aug 22, 2026 High SWEUdata breachextortioncyber extortion
threat-intel 'Grandoreiro' Malware Resurfaces With Mexico Campaign The Grandoreiro banking Trojan, a 12-year-old malware initially developed in Brazil, has resurfaced with a new campaign targeting users in Mexico and expanding its reach to North America and Europe. Operators are utilizi… Dark Reading · Aug 20, 2026 High BRSPMEbanking trojanmalwareanti-analysis
supply-chain Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations A supply-chain attack linked to Aqua Security's Trivy scanner has resulted in the release of two malicious LiteLLM packages containing credential-stealing code. CloudSEK identified over 2,500 organizations potentially ex… The Hacker News · Aug 12, 2026 High CVE-2026-33634USEUsupply chaincredential theftpypi
threat-intel Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA The Gunra ransomware gang, leveraging leaked Conti code and exploiting vulnerabilities in Fortinet products, is expanding its operations through a RaaS affiliate program and successfully bypassing defenses, including MFA… Dark Reading · Aug 11, 2026 High CVE-2024-55591CVE-2025-24472SOBRCAransomwareraasfortinet
threat-intel Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails A widespread phishing campaign, leveraging adversary-in-the-middle (AitM) techniques and residential proxies, is targeting organizations across various sectors in the U.S., Canada, and Europe. The campaign, linked to the… The Hacker News · Aug 7, 2026 High USCAEUaitmphishingmicrosoft 365
threat-intel Device Code Phishing Up 1,500% in 2026; Vishing Doubles Device code phishing and vishing are experiencing a dramatic surge, driven by state-sponsored and cybercriminal groups, and are proving highly effective at bypassing traditional security measures. CrowdStrike reports a 1… Dark Reading · Aug 4, 2026 High USRUEUphishingvishingdevice-code-phishing
threat-intel EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels The European Union is establishing a new team in Brussels to combat the misuse of AI, particularly concerning deepfakes, illicit imagery, and cyber threats. This initiative is part of a broader strategy to assert tech so… SecurityWeek · Jul 31, 2026 Medium EUUSCHaideepfakeregulation
threat-intel Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation Russian threat actors, linked to Laundry Bear (TA488), are exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain persistent access to email accounts within U.S. and European government entities and… The Hacker News · Jul 30, 2026 High CVE-2026-42897CVE-2025-66376USEUxsscredential theftpersistence
threat-intel CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking A new investigation by CTM360 reveals a significant evolution in insurance phishing attacks, moving beyond simple credential harvesting to real-time account hijacking. Attackers now synchronize their activity with victim… The Hacker News · Jul 25, 2026 High SAUNINphishingaccount hijackinginsurance
threat-intel Europe's Multilingual Reality Exposes AI Security Gaps Europe faces a unique security challenge due to its multilingual landscape and the resulting inconsistencies in AI safety and security across numerous languages. While many AI models can process text in dozens of languag… Dark Reading · Jul 24, 2026 High EUGESPaisecuritymultilingual
threat-intel International alert spotlights Russia-linked attacks on Zimbra webmail Russian state-aligned hackers, operating under the APT group Laundry Bear, are targeting governmental and commercial organizations globally through zero-click phishing campaigns exploiting a vulnerability in Zimbra webma… The Record · Jul 23, 2026 High CVE-2025-66376UKRUNEzero-clickphishingzimbra
threat-intel Ransomware Is Accelerating, But It's Not Because of AI Ransomware activity is surging, with a 25% increase in incidents between April 2025 and March 2026, driven by a fragmented ecosystem and the emergence of numerous new groups. Black Kite researchers found that many victim… Dark Reading · Jul 21, 2026 High USEUransomwarevulnerabilitysupply-chain
threat-intel Begun, the Patch Wars have Cisco Talos has identified a sophisticated, financially motivated Russian-speaking adversary, UAT-11795, actively targeting users in the U.S. and Europe since June 2025. This campaign utilizes trojanized software install… Cisco Talos · Jul 16, 2026 High UNRUEUsupply-chainaptzero-day
threat-intel New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password A new macOS infostealer, dubbed ClickLock Stealer, is actively targeting users by forcing them to enter their passwords repeatedly through a loop of killing apps. The malware, a copy of GSocket, uses a deceptive Cloudfla… The Hacker News · Jul 16, 2026 High EUmacosinfostealerpassword
threat-intel U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support The U.S. Treasury Department has sanctioned a VPN service provider, First VPN Service (1VPNS), and its administrator, Dmytro Rashevskyi, for enabling ransomware groups to carry out attacks against U.S. companies and inst… The Hacker News · Jul 14, 2026 High CVE-2018-0171CVE-2008-4128RUUKUNvpnransomwarecyber espionage
threat-intel Weak Security Continues to Fuel Russian Cyberattacks The UK and EU have jointly sanctioned Russian individuals and entities involved in cyberattacks and disinformation campaigns, coinciding with a US cybersecurity advisory highlighting ongoing Russian state-sponsored attac… Dark Reading · Jul 13, 2026 High UKEUUNrouter securityciscosnmp
malware Vidar Infostealer Hammers SMBs via Malvertising Campaign A financially motivated operation is using malvertising to deliver a two-for-one malware payload – the Vidar infostealer and XMRig cryptominer – to consumers and SMBs globally. The campaign employs sophisticated evasion… Dark Reading · Jul 8, 2026 High USEUmalvertisingmaascryptomining
threat-intel EU unveils cyber plan to reduce reliance on foreign AI systems The European Commission has unveiled a cybersecurity and AI action plan aimed at reducing the EU’s reliance on foreign AI systems, particularly concerning access to ‘frontier’ AI models. The plan focuses on ensuring cybe… The Record · Jul 8, 2026 Medium EUUKaicybersecurityfrontier ai