threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
supply-chain GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say A supply-chain worm, dubbed Shai-Hulud, is exploiting design flaws in GitHub to infect hundreds of software packages and developer accounts worldwide. The vulnerabilities, initially flagged by Deep Specter Research, were… The Record · Jun 16, 2026 High GBFRsupply chainvulnerabilitygithub
malware Fileless Phantom Stealer Targets Browser Credentials A new fileless malware, Phantom Stealer, is being deployed through targeted phishing campaigns against banks and high-value organizations. The malware focuses on stealing browser credentials and session cookies, utilizin… Dark Reading · Jun 16, 2026 High GBDEFRcredential theftbrowser securityfileless malware
threat-intel UK to require ID or face scan before you can make social media accounts The UK government is implementing new regulations to restrict social media access for under-16s, requiring platforms to verify users' ages through ID uploads or facial scans. This follows a model established in Australia… BleepingComputer · Jun 16, 2026 Medium GBage-verificationsocial-mediaprivacy
threat-intel Can CISOs Trust Their Applications? TrustCloud Wants to Replace the Questionnaire This article discusses the challenges CISOs face when assessing the trust and security of their enterprise applications, highlighting the manual and time-consuming nature of traditional questionnaire-based approaches. Tr… SecurityWeek · Jun 16, 2026 Medium GBautomationaiapplication security
threat-intel North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels North Korean threat actors, operating under the UNK_DeadDrop campaign, are employing a sophisticated phishing technique targeting developers across numerous sectors, including finance and cryptocurrency, using malicious… The Hacker News · Jun 15, 2026 High USGBAUdevelopergithubvscode
vulnerability ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities The ShinyHunters extortion group exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft to gain unauthorized access to university systems, resulting in data theft and a demand for payment. Mandiant iden… The Hacker News · Jun 11, 2026 High CVE-2026-35273GBUSzero-dayexploitationuniversity
threat-intel AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS. The rapid advancement of AI, particularly through tools like Anthropic's Claude Mythos Preview, has dramatically reduced the time it takes to discover and exploit vulnerabilities in software. This has collapsed the tradi… The Hacker News · Jun 11, 2026 High USGBaivulnerabilityexploitation
ransomware Why schools remain one of cybercriminals’ favourite targets Schools continue to be a prime target for cyberattacks, particularly ransomware, as evidenced by recent incidents at Evanston Township High School and Powys County Council. These attacks disrupt operations and compromise… Graham Cluley · Jun 10, 2026 High USGBschoolsransomwarecyberattack
malware Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models Researchers at the University of Toronto have developed a novel AI-driven computer worm that operates autonomously by leveraging locally hosted, open-weight large language models. The worm dynamically generates attack st… The Hacker News · Jun 9, 2026 Critical CVE-2026-39987CVE-2026-31431CVE-2026-43284GBaiwormllm
threat-intel Exposed Fuel Tank Gauges Under Attack in the US Internet-exposed fuel tank gauges in the United States are being targeted by cyberattacks, posing a significant risk to gas stations and industrial facilities. The Cybersecurity and Infrastructure Security Agency (CISA)… Dark Reading · Jun 5, 2026 High USCAAUindustrial control systemscybersecuritytank gauges
threat-intel Chinese Cybercrime Group in Spotlight for Record Campaign Pace A Chinese cybercrime group, TA4922, is experiencing a record surge in campaign activity, utilizing sophisticated social engineering tactics to target organizations globally. The group’s primary objectives involve data th… SecurityWeek · Jun 4, 2026 High GBDEITsocial engineeringcredential phishingremote access
malware Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS A sophisticated operation is impersonating popular open-source and freeware tools like Ghidra and dnSpy to lure users to malicious websites via a Traffic Distribution System (TDS). This TDS then delivers malware, includi… The Hacker News · Jun 4, 2026 High TRPLBRtdsmalware-as-a-serviceclick interception
threat-intel Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say As a result of sanctions and the ongoing war in Ukraine, Russian intelligence agencies are intensifying their efforts to steal Western technology and defense secrets. This includes targeting advanced machine tools, resea… SecurityWeek · May 30, 2026 High RUSEFIsanctionsespionagecyberattack
threat-intel 'The Com' Cyberattacks Support Violence & Sexploitation This report details the activities of 'The Com,' a decentralized cybercriminal collective primarily composed of North American teenagers, many linked to groups like ShinyHunters, Lapsus$, and Scattered Spider. The group… Dark Reading · May 29, 2026 Critical USGBcybercrimechild exploitationhacktivism
threat-intel Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks Google has launched an AI-powered cybersecurity platform, AI Threat Defense, designed to proactively combat increasingly sophisticated cyberattacks leveraging artificial intelligence. This platform utilizes AI to identif… SecurityWeek · May 28, 2026 High GBaicybersecuritythreat detection
vulnerability Gitea Vulnerability Exposes Private Container Images without Authentication A significant vulnerability (CVE-2026-27771) has been identified in Gitea, a popular open-source Git repository hosting platform. The flaw allows unauthorized access to private container images, exposing sensitive data w… The Hacker News · May 27, 2026 High CVE-2026-27771CNUSDEcontainergitvulnerability
phishing FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required The FBI has issued a warning about Kali365, a phishing-as-a-service kit that allows attackers to compromise Microsoft 365 accounts without needing passwords, even when MFA is enabled. This kit leverages device code flow,… Graham Cluley · May 26, 2026 High USCAGBmfadevice-code-flowphishing
threat-intel MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries The MuddyWater hacking group, backed by Iran, has been conducting a sophisticated espionage campaign targeting organizations across nine countries on four continents during Q1 2026. The campaign utilizes DLL side-loading… The Hacker News · May 26, 2026 High KRSAAEdll-side-loadingcredential-stealingreconnaissance
threat-intel Iranian APT Targets Aviation, Software Companies With Updated Tools The Iranian APT group, known as Nimbus Manticore, has been aggressively updating its tactics and tools to target aviation and software companies globally. The group, linked to Charming Kitten and the IRGC, is employing… SecurityWeek · May 26, 2026 High AEIRSAaptphishingappdomain