ransomware Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs Europol, in collaboration with international law enforcement, successfully disrupted AudiA6, a cryptocurrency laundering service used extensively by ransomware gangs and cybercriminals. The operation, resulting in the ar… The Hacker News · Jun 12, 2026 High UKRUGEcryptocurrencyransomwaremoney laundering
threat-intel China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance A China-linked botnet, dubbed JDY, has significantly expanded its operations, now comprising over 1,500 compromised SOHO and IoT devices. Initially a component of the KV-botnet, the JDY botnet is being used for large-sca… The Hacker News · Jun 10, 2026 High CVE-2026-35616USBRDEiotreconnaissancebotnet
vulnerability Schneider Electric EcoStruxure Panel Server Schneider Electric has identified a vulnerability in its EcoStruxure Panel Server product line, specifically versions prior to 002.006.000. This vulnerability, classified as CWE-1188, allows for potential unauthorized au… CISA Advisories · Jun 9, 2026 High CVE-2026-6866FRcwe-1188firmwareauthentication
data-breach French govt messaging service breached in account hijacking attack The French government’s Tchap messaging service was breached after a compromised user account was used to gain access, leading to the theft of sensitive data including user information and over 13.5GB of files. The attac… BleepingComputer · Jun 9, 2026 High FRsocial engineeringdata theftmessaging
vulnerability Gogs patches critical zero-day enabling remote code execution A critical zero-day vulnerability in Gogs, a remote collaboration platform, has been identified, allowing authenticated attackers to execute remote code and access private repositories. The flaw, present in versions up t… BleepingComputer · Jun 8, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPremote-code-executionzero-dayauthentication
malware FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads A new macOS malvertising campaign, dubbed Operation FlutterBridge, is utilizing FlutterShell, a backdoor that spreads adware via malicious Google and YouTube ads. The campaign, traced back to the CL-CRI-1089 threat actor… The Hacker News · Jun 4, 2026 High USCAAUmalvertisingmacoswebview
malware Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS A sophisticated operation is impersonating popular open-source and freeware tools like Ghidra and dnSpy to lure users to malicious websites via a Traffic Distribution System (TDS). This TDS then delivers malware, includi… The Hacker News · Jun 4, 2026 High TRPLBRtdsmalware-as-a-serviceclick interception
vulnerability CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability, CVE-2026-45247, affecting the Mirasvit Cache Warmer Magento extension to its KEV catalog. This flaw allows for remote c… The Hacker News · Jun 4, 2026 Critical CVE-2026-45247USUKFRphpobjectdeserialization
threat-intel China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan A new cyber espionage campaign, dubbed Operation Dragon Weave, is targeting government, research, and financial institutions in the Czech Republic and Taiwan using spear-phishing emails and a Rust-based loader to deploy… The Hacker News · Jun 1, 2026 High CZTWINspear-phishingc2azure
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
threat-intel New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails Edamame Technologies has developed a new runtime security system designed to detect and mitigate ‘code drift’ in AI coding agents. This drift, caused by agents deviating from their intended purpose, can lead to security… SecurityWeek · May 28, 2026 High FRaicoding agentsruntime security
threat-intel 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface This analysis from Palo Alto Unit 42 assesses the significant cyber threat landscape surrounding the 2026 FIFA World Cup, highlighting the expanded attack surface created by the event's scale and complexity. The report i… Palo Alto Unit 42 · May 28, 2026 High USIRRUmega-eventcybersecuritythreat intelligence
vulnerability Gitea Vulnerability Exposes Private Container Images without Authentication A significant vulnerability (CVE-2026-27771) has been identified in Gitea, a popular open-source Git repository hosting platform. The flaw allows unauthorized access to private container images, exposing sensitive data w… The Hacker News · May 27, 2026 High CVE-2026-27771CNUSDEcontainergitvulnerability
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes Italian authorities disrupted a sophisticated piracy operation centered around the CINEMAGOAL app, which provided unauthorized access to streaming services like Netflix and Disney+. The operation, dubbed "Tutto Chiaro,"… BleepingComputer · May 23, 2026 Medium ITFRDEpiracystreamingauthentication
threat-intel First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups A global operation, dubbed Operation Saffron, led by France and the Netherlands, successfully dismantled the First VPN service, a virtual private network specifically designed for criminal use. The service was utilized b… The Hacker News · May 22, 2026 High USFRNLvpnransomwareanonymity
threat-intel Police seize “First VPN” service used in ransomware, data theft attacks Law enforcement agencies, in a coordinated international effort led by France and the Netherlands, have taken down the ‘First VPN’ service, a virtual private network used extensively by ransomware and data theft groups.… BleepingComputer · May 21, 2026 High UKFRNEvpncybercrimeransomware
threat-intel Europe dismantles VPN service used by cybercriminals to hide ransomware attacks European law enforcement agencies successfully dismantled First VPN, a virtual private network (VPN) service heavily utilized by cybercriminals to mask their activities, including ransomware attacks and fraud schemes. Th… The Record · May 20, 2026 High FRNLUAvpncybercrimeransomware
threat-intel Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks Microsoft disrupted a malware-signing-as-a-service (MSaaS) operation, dubbed OpFauxSign, led by the threat actor Fox Tempest, which was using its Artifact Signing system to distribute malware and ransomware. The operatio… The Hacker News · May 20, 2026 High USFRINmsaascode-signingmalware
vulnerability Kieback & Peter DDC Building Controllers This CISA advisory details a cross-site scripting (XSS) vulnerability affecting several versions of Kieback & Peter’s DDC Building Controllers. The vulnerability, CVE-2026-4293, allows an attacker to execute JavaScript c… CISA Advisories · May 19, 2026 Medium CVE-2026-4293AUATCNxssbuilding automationot