threat-intel Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors, known as LAUNDRY BEAR, has been aggressively targeting Western organizations using the Zimbra Collaboration Suite (ZCS) since July 2025, seeking to gather sensitive inform… CISA Advisories · Jul 23, 2026 High CVE-2025-66376MOPOSPphishingsupply-chainmalware
policy French Parliament greenlights social media ban for under-15s France has become the first European nation to enact a ban on social media access for children under 15, a move driven by concerns about child welfare and prompted by similar legislation in other countries. The law will… The Record · Jul 22, 2026 Info FRAUTRsocial mediachild safetyregulation
threat-intel EU Financial Institutions Leak Data Through Cookie Trackers European financial institutions are inadvertently exposing customer data to third-party advertising and analytics platforms through tracking pixels, even when users haven't consented to tracking. Jscrambler’s research re… Dark Reading · Jul 22, 2026 High FRPOSPdata-breachprivacygdpr
threat-intel Une usurpation cible les services communication An impersonation campaign is targeting businesses by mimicking Damien Bancal and ZATAZ to gain access to internal contacts and initiate a social engineering operation. The attacker uses a fabricated email chain to map ou… ZATAZ · Jul 21, 2026 Medium FRsocial_engineeringimpersonationcybercrime
threat-intel Fuite revendiquée au Rassemblement national ? A pirate claims to have compromised the website of the French far-right party, Rassemblement National (formerly Front National), and is offering a recent SQL dump for sale. The dump, allegedly containing 95 tables, inclu… ZATAZ · Jul 21, 2026 High FRdata breachsql dumpwordpress
threat-intel ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing ClickLock Stealer, a new macOS malware, bypasses macOS security through social engineering and aggressive process killing to steal sensitive data, including browser data, cryptocurrency wallets, and password manager info… SecurityWeek · Jul 16, 2026 High DEFRITmacossocial engineeringprocess killing
threat-intel Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife The UK is intensifying its push for tech sovereignty, driven by concerns over reliance on US tech companies, particularly in the rapidly developing field of AI. Recent restrictions on AI models from Anthropic and OpenAI… Dark Reading · Jul 15, 2026 High UKUSCHtech-sovereigntyaicybersecurity
threat-intel Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 In June 2026, a significant number of cybersecurity M&A deals were announced, highlighting the industry's ongoing consolidation and investment in advanced security technologies. Several key acquisitions focused on areas… SecurityWeek · Jul 13, 2026 High ISBECAmergers and acquisitionscybersecurityidentity management
threat-intel EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign The European Union has imposed sanctions on Russian intelligence officers and entities involved in a long-running cyber espionage campaign targeting European governments and critical infrastructure. This campaign, spanni… SecurityWeek · Jul 13, 2026 High FRDEPLcyber espionagecritical infrastructurerussian threat
threat-intel Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 A security firm, Lexfo, uncovered three separate phishing operations targeting Microsoft 365, all leveraging modified versions of the Evilginx proxy. These campaigns utilized a combination of traditional proxying and a n… The Hacker News · Jul 13, 2026 High EGFRNOphishingevilginxdevice-code
threat-intel Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions Russia’s FSB, specifically its Center 16 signals intelligence arm, has been formally blamed for a cyberattack that threatened to cut heating to half a million people in Poland last winter. Following this attribution, the… The Record · Jul 12, 2026 High RUPOFRcyberattackcybercrimeespionage
ransomware No Manners Here: The Ruthless Rise of The Gentlemen Ransomware The Gentlemen, a rapidly growing Ransomware-as-a-Service (RaaS) program, has significantly increased its victim count in 2026, becoming the second most active RaaS program globally. Leveraging a 90% affiliate payout stru… Palo Alto Unit 42 · Jul 10, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073USCAGBransomware-as-a-serviceracksedge-device-attack
ransomware Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence Two major ransomware figures have been brought to justice in separate U.S. court cases. Karen Vardanyan, a Ryuk ransomware operator, pleaded guilty to conspiracy and computer fraud, while Angelo Martino, a ransomware neg… The Record · Jul 10, 2026 High FRUKUNransomwarenegotiatorextortion
threat-intel EU takes member states to court over unimplemented cybersecurity law The European Commission has filed legal action against Ireland, Spain, France, and the Netherlands for failing to implement the NIS2 Directive, a cybersecurity law designed to improve security for critical infrastructure… The Record · Jul 9, 2026 Medium IEESFRcybersecurityeu lawcritical infrastructure
threat-intel France to Stop Certifying Non-Quantum-Safe Encryption France’s cybersecurity agency, ANSSI, is implementing a significant shift in encryption standards. Starting in 2027, they will no longer certify security products that don't offer quantum-resistant encryption, effectivel… Schneier on Security · Jul 6, 2026 Medium FRencryptionquantumcybersecurity
ransomware Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials The Anubis ransomware group, a rebranded version of Sphinx, is actively exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to gain initial access to victim networks. They leverage legitimate RMM tools like Scree… The Hacker News · Jul 2, 2026 High CVE-2025-5777USUKAUcitrixbleedransomware-as-a-servicecredential theft
threat-intel Attackers Hijack Exposed AI Endpoints to Power Offensive Ops Researchers at Zenity discovered attackers are exploiting exposed AI endpoints, specifically Ollama and LiteLLM, to power offensive operations. Attackers leverage these AI agents – such as Strix and HexStrike AI – withou… Dark Reading · Jun 30, 2026 High FRaillmendpoint
vulnerability Schneider Electric EcoStruxure IT Data Center Expert This report details a vulnerability discovered in Schneider Electric’s EcoStruxure IT Data Center Expert software, specifically versions up to 9.1.1. The vulnerability, classified as CWE-611, is an Improper Restriction o… CISA Advisories · Jun 30, 2026 Medium CVE-2026-8045FRxmlcwe-611data center
vulnerability Schneider Electric EasyLogic T150 and Saitel DP RTU This advisory details vulnerabilities in Schneider Electric's EasyLogic T150 and Saitel DP RTU devices, specifically versions through 11.06.37. These vulnerabilities, classified as CWE-522 and CWE-732, allow for unauthor… CISA Advisories · Jun 30, 2026 Medium CVE-2026-9650CVE-2026-9651FRcredentialsfirmwareiot
threat-intel FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys The FBI and CISA have issued an updated advisory warning about Russian intelligence actors targeting Signal users, expanding their tactics to include obtaining Signal Backup Recovery Keys. This allows attackers to fully… The Hacker News · Jun 26, 2026 High USRUNEsignalphishingrecovery key