threat-intel Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor The Lazarus Group, a North Korean threat actor, is exploiting a newly patched zero-day vulnerability in Microsoft Windows' AFD.sys driver to gain SYSTEM access and deploy a backdoor called Troy. They are leveraging a sop… The Hacker News · Aug 12, 2026 High CVE-2026-68820CVE-2025-49113FRGEBRzero-daysocial engineeringphishing
threat-intel WhatsApp Unveils New Scam Alert Feature WhatsApp is rolling out a limited beta feature called Scam Alert, designed to identify potentially scam messages on users' devices *before* they are sent. The feature uses on-device machine learning, doesn't send message… SecurityWeek · Aug 12, 2026 Medium GERUmachine learningencryptionprivacy
threat-intel CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign The CISA has ordered federal agencies to patch a critical Windows vulnerability being actively exploited by North Korean hackers as part of Operation ‘Dream Job’. This campaign, led by the Lazarus Group, impersonates rec… The Record · Aug 12, 2026 Critical CVE-2026-68820FRGEBRzero-daynorth koreaoperation dream job
threat-intel Siemens RUGGEDCOM APE1808 A CISA advisory, in collaboration with Siemens ProductCERT, highlights vulnerabilities in Siemens RUGGEDCOM APE1808 devices when used with Fortinet NGFW. These vulnerabilities, including Cross-Site Scripting and Path Tra… CISA Advisories · Aug 12, 2026 High CVE-2026-23573CVE-2026-59839GEindustrial control systemscwe-79cwe-22
vulnerability Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access Threat actors are actively exploiting a recently patched critical vulnerability (CVE-2026-59310) in Broadcom VMware vCenter to gain persistent remote access. QUIRSO discovered a campaign involving 361 unique victim IP ad… The Hacker News · Aug 12, 2026 High CVE-2026-59310CVE-2026-59309GEUNTUvulnerabilityexploitreverse_ssh
threat-intel Fresh Windows Zero-Day Exploited in North Korean Cyberattacks North Korean hackers, operating under the Lazarus Group, are exploiting a recently patched Windows zero-day vulnerability (CVE-2026-68820) to conduct targeted attacks against defense, aerospace, and aviation organization… SecurityWeek · Aug 12, 2026 High CVE-2026-68820CVE-2025-49113FRGEBRzero-daylazarus groupcyber espionage
threat-intel À vendre : les coulisses d’un empire du pari A cybersecurity news platform has uncovered a pattern of suspicious activity by a single online seller offering access to vast databases of gambling-related data, including player information, casino prospects, and crypt… ZATAZ · Aug 10, 2026 High AZGEINdata-breachthreat-intelgambling
threat-intel IT threat evolution in Q2 2026. Non-mobile statistics In Q2 2026, Kaspersky products blocked a massive 399.3 million attacks originating from online resources, highlighting a continued surge in ransomware activity and botnet attacks. The Qilin ransomware group dominated, ac… Securelist · Aug 10, 2026 High CVE-2026-33825CVE-2026-50751CVE-2026-50752NEGEUNransomwarebotnetsupply chain
threat-intel Commerce pirate : un cybercriminel vend des dizaines de téraoctets de données A cybercriminal is offering a massive stock of personal and corporate data, spanning over 25 countries and multiple sensitive categories, for sale. The offering includes over 100,000 distinct datasets, encompassing phone… ZATAZ · Aug 7, 2026 High FRGEUNdata breachcybercrimedata theft
threat-intel Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison Maksim Silnikau, the mastermind behind the Ransom Cartel ransomware operation, has been sentenced to 16 years in prison for his role in a multi-year criminal scheme targeting organizations across the US and abroad. The o… SecurityWeek · Aug 6, 2026 High BEUKRUransomwarecybercrimeextradition
threat-intel Republic of Georgia alleges foreign disinfo campaign sought to scare off Russian tourists Georgia's State Security Service is investigating a suspected disinformation campaign orchestrated from abroad and supported within Georgia, aimed at deterring Russian tourists and portraying the country as unsafe. The c… The Record · Aug 6, 2026 Medium GERUUKdisinformationrussiageorgia
threat-intel Russian businesses erase Durov-linked products after 'terrorist' designation Following Russia's designation of Telegram founder Pavel Durov as a terrorist and extremist, numerous Russian businesses are removing products associated with him, including books, films, and merchandise. Despite these e… The Record · Aug 4, 2026 High RUFRUAcensorshipduraovtelegram
threat-intel AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls An AI meeting assistant, tl;dv, is vulnerable due to a misconfiguration in its Firebase environment, allowing unauthorized access to users' video calls and meeting data. A security researcher discovered that users could… Dark Reading · Aug 4, 2026 High MAUKBRfirebaseaimeeting assistant
threat-intel CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability in N-able N-central to its KEV catalog due to active exploitation. This flaw, stemming from incomplete patching of… The Hacker News · Aug 4, 2026 High CVE-2026-18577CVE-2026-18556CVE-2025-8875GEICSWvulnerabilityremote monitoringremote management
threat-intel Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS A Chinese threat actor is leveraging a publicly leaked version of the DarkSword exploit kit to deploy GHOSTBLADE, an information-stealing malware, targeting Apple iOS devices. Censys identified over 100 web properties us… The Hacker News · Aug 3, 2026 High HOJACHiosexploit kitmalware
threat-intel Russia accuses Telegram founder of aiding terrorism, seeks international arrest Russia has formally accused Telegram founder Pavel Durov of aiding terrorism, seeking an international arrest warrant due to allegations that the messaging app was used by Ukrainian intelligence to organize terrorist att… The Record · Jul 29, 2026 High RUUKFRrussiatelegramukraine
threat-intel 24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login A significant vulnerability, CVE-2013-4786, has been exposed due to a 20-year-old flaw in the IPMI 2.0 specification, resulting in over 36,000 internet-exposed BMCs revealing password hashes. This allows attackers to con… The Hacker News · Jul 28, 2026 High CVE-2013-4786USGECHbmcipmipassword cracking
threat-intel 'Wrench' attacks against crypto holders appear to be on the rise Crypto theft is increasingly shifting from online attacks to physical coercion, known as ‘wrench’ attacks. CertiK reports a 33% year-over-year increase in these in-person attacks, with a significant rise in associated fi… The Record · Jul 24, 2026 High FRUNGEcryptophysical-securityself-custody
threat-intel In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws This week’s cybersecurity news highlights a range of threats, including a new AI-powered malware (Dolphin X), a data breach affecting Abbott, widespread internet outages in Maine, zero-day vulnerabilities in Siemens swit… SecurityWeek · Jul 24, 2026 High CVE-2025-40948CVE-2025-40947CVE-2025-40949GERUUNzero-dayvulnerabilityransomware
threat-intel Europe's Multilingual Reality Exposes AI Security Gaps Europe faces a unique security challenge due to its multilingual landscape and the resulting inconsistencies in AI safety and security across numerous languages. While many AI models can process text in dozens of languag… Dark Reading · Jul 24, 2026 High EUGESPaisecuritymultilingual