threat-intel Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone A vulnerability in Apple’s Beats Studio Buds firmware allowed nearby attackers to potentially eavesdrop on users via the device’s microphone. The flaw, tracked as CVE-2025-20701, stemmed from incorrect authorization with… The Hacker News · Jun 19, 2026 Critical CVE-2025-20701CVE-2025-20700CVE-2025-20702GEbluetoothmicrophonesecurerom
ransomware Killing me gently: Inside Gentlemen’s EDR killer framework The Gentlemen ransomware-as-a-service (RaaS) gang has emerged as a significant and technically agile threat, distinguished by its proactive development and maintenance of a comprehensive suite of Endpoint Detection and R… WeLiveSecurity · Jun 18, 2026 High THBRFRransomwareedrrd
supply-chain Early Warning Signs of Supply-Chain Attacks Live in the Dark Web This BleepingComputer article highlights the increasing threat of supply-chain attacks, which target the tools and vendors organizations rely on. The article details how early warning signs of these attacks often appear… BleepingComputer · Jun 12, 2026 High GEsupply chaingithubcredentials
ransomware Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs Europol, in collaboration with international law enforcement, successfully disrupted AudiA6, a cryptocurrency laundering service used extensively by ransomware gangs and cybercriminals. The operation, resulting in the ar… The Hacker News · Jun 12, 2026 High UKRUGEcryptocurrencyransomwaremoney laundering
ransomware The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm The Gentlemen ransomware group, initially operating as the affiliate-focused Phantom Mantis, has evolved into an independent RaaS operation led by the cybercriminal LARVA-368 (aka hastalamuerte). The group, responsible… The Hacker News · Jun 11, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073RUTHUKransomware-as-a-servicedouble extortionaffiliate program
ransomware Authorities dismantle 'AudiA6' ransomware crypto-laundering service Law enforcement agencies have successfully dismantled the ‘AudiA6’ cryptocurrency service, which was used to launder over $380 million generated from ransomware attacks and other cybercriminal activities. The operation,… BleepingComputer · Jun 11, 2026 High POUKGEcryptocurrencyransomwaremoney laundering
malware NFCShare Android malware spreads via fake banking app updates on GitHub A new variant of the NFCShare Android malware is spreading through fake updates for banking apps hosted on GitHub, targeting financial institutions across Europe. The malware leverages NFC technology to steal payment car… BleepingComputer · Jun 8, 2026 High ITSPGEnfcandroidbanking
threat-intel ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More This week’s security news highlights a series of attacks and vulnerabilities, including a supply chain attack targeting Microsoft GitHub repositories via the Miasma Worm, a zero-day exploit in Android, and ongoing cyberc… The Hacker News · Jun 8, 2026 High CVE-2025-48595CVE-2026-28318CVE-2026-39210CHUSGEsupply-chainzero-daycybercrime
threat-intel EU unveils tech sovereignty package to cut reliance on US, Chinese suppliers The European Commission has unveiled a comprehensive tech sovereignty package designed to reduce the EU’s reliance on foreign technology suppliers, particularly the US and China. This initiative includes legislation focu… The Record · Jun 5, 2026 Medium EUUSCHtech sovereigntyeuropean unionsemiconductors
threat-intel China's TA4922 Expands Cybercrime Attacks Globally China's TA4922 cybercrime group has significantly expanded its operations globally, targeting a diverse range of countries and employing a wider array of tactics and techniques than previously observed. Initially focused… Dark Reading · Jun 4, 2026 High CHJATAphishingratmalware
threat-intel China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa A China-linked cybercrime group, TA4922, has broadened its phishing attacks to include organizations in the UK, Germany, Italy, and South Africa. The group utilizes a constantly evolving arsenal of malware, including Val… The Hacker News · Jun 4, 2026 Medium UKGEITphishingratcredential theft
threat-intel Chinese hackers use new Atlas RAT malware in European cyberattacks A Chinese cybercrime group, tracked as TA4922, is expanding its operations with the deployment of new malware, including the Atlas RAT and RomulusLoader, targeting organizations across Europe and Southeast Asia. The grou… BleepingComputer · Jun 3, 2026 High CHGEITphishingremote access trojanmalware loader
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
ddos Canadian man arrested, charged for running KimWolf DDos botnet A Canadian man, Jacob Butler, has been arrested and charged with operating the KimWolf DDoS botnet, a significant online threat that disrupted numerous websites. Law enforcement agencies, in a coordinated international e… The Record · May 22, 2026 High CAUSGEddosbotnetcybercrime
malware Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor A new Linux malware, dubbed Showboat, has been used in a campaign targeting a telecommunications provider in the Middle East since at least 2022. The malware, developed by a China-linked threat actor group known as Calyp… The Hacker News · May 21, 2026 High CVE-2021-26855AFAZCHlinuxsocks5c2
threat-intel Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API A China-aligned threat actor known as Webworm has expanded its arsenal with two new backdoors, EchoCreep and GraphWorm, utilizing Discord and the Microsoft Graph API for command-and-control communications. The group, act… The Hacker News · May 20, 2026 High CHRUGEdiscordmicrosoft graphrat
vulnerability Siemens Simcenter Femap A heap-based buffer overflow vulnerability has been identified in Siemens Simcenter Femap, specifically within the Datakit library. The vulnerability, reported by TrendAI Zero Day Initiative, allows for remote code execu… CISA Advisories · May 14, 2026 High CVE-2025-12659GEheap-overflowremote-code-executionipt
threat-intel Eyes wide open: How to mitigate the security and privacy risks of smart glasses This article discusses the growing security and privacy risks associated with smart glasses, particularly due to their advanced tracking and recording capabilities combined with AI integration. The proliferation of these… WeLiveSecurity · May 11, 2026 High GEUKsurveillanceprivacyai