threat-intel CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six previously exploited vulnerabilities to its KEV catalog, including flaws in Citrix NetScaler, Linux, and Microsoft SQL Server. These vulnerabilities are actively being exploited, with telemetry showing attacks originating from various countr… The Hacker News · 3d ago High CVE-2019-1068CVE-2026-8452CVE-2022-0995SWGEHOkevexploitationvulnerability
threat-intel INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown INTERPOL’s fourth iteration of Operation Jackal has resulted in the arrest of 58 individuals and the identification of 263 suspects globally, targeting West African organized crime groups involved in cyber fraud, includi… The Hacker News · 4d ago High AUARBEcybercrimefraudmoney laundering
threat-intel Phishing 3.0: The Fight Moves to Agent Versus Agent Phishing has evolved beyond simple email attacks into a sophisticated, AI-powered threat landscape – Phishing 3.0. Attackers are now utilizing AI agents to research targets, craft personalized lures, and execute multi-ch… The Hacker News · Aug 19, 2026 High HOphishingaideepfake
vulnerability Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) due to a bypass in the authentication feature. Following the release of a proof-of-concept by Rapid7, attackers are lev… The Hacker News · Aug 13, 2026 Critical CVE-2026-55040HOJANEjwtauthenticationsharepoint
ransomware Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks The Gunra ransomware group, linked to state-sponsored actors, is aggressively targeting critical infrastructure and organizations globally, leveraging vulnerabilities in Fortinet and Schneider Electric appliances to gain… The Hacker News · Aug 11, 2026 High CVE-2024-5559CVE-2025-24472SOBRSPransomwarevulnerabilitysupply-chain
threat-intel US cyber ambassador nominee Cassady confirmed in Senate The Senate confirmed Adam Cassady as the next U.S. ambassador for cyber and digital policy. This appointment follows a reorganization within the State Department, leading to a restructuring of the Bureau of Cyberspace an… The Record · Aug 7, 2026 Info CHHOUScybersecuritytechnology exportschina
threat-intel Fake IRS letters target cryptocurrency holders Scammers are impersonating the IRS to trick cryptocurrency holders into visiting fake websites designed to steal their personal information and digital assets. The IRS does not operate a Digital Asset Compliance Portal,… Graham Cluley · Aug 4, 2026 High HOROphishingcryptocurrencyfraud
threat-intel Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS A Chinese threat actor is leveraging a publicly leaked version of the DarkSword exploit kit to deploy GHOSTBLADE, an information-stealing malware, targeting Apple iOS devices. Censys identified over 100 web properties us… The Hacker News · Aug 3, 2026 High HOJACHiosexploit kitmalware
threat-intel Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies A Chinese company, Zhejiang Fengwo IoT Technology Co., Ltd., is behind the ‘Fuyao’ operation, which involves shipping cheap Android TV boxes with apps that mimic phones and then use them to relay internet traffic as SOCK… The Hacker News · Jul 31, 2026 High CHHOSIandroidad fraudsocks5
threat-intel Read This Before You Buy That TV Streaming Stick A security firm, Bitsight, uncovered a complex and widespread ad fraud network centered around H96 streaming devices. These devices, often sold by major retailers, are secretly used to generate revenue by masquerading as… Krebs on Security · Jul 30, 2026 High CHHOSIiotproxyad fraud
threat-intel AI Agent Drives Espionage Attack on Thai Ministry of Finance Threat actors used an autonomous AI agent, Hermes, to conduct espionage against Thailand's Ministry of Finance. The attack, supported by open-source tools like LinPEAS and Hades (a custom Windows/Linux malware), involved… Dark Reading · Jul 28, 2026 High CHHOaiespionagemalware
threat-intel Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry A Thai Ministry of Finance employee installed the Hermes AI assistant, a tool designed for mail management and task automation, on a rented server. The agent, left running unattended, autonomously scanned the ministry's… The Hacker News · Jul 24, 2026 High CVE-2026-31431CVE-2026-43284CVE-2026-43500THHOaiunattendeddefault
threat-intel China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks A China-nexus operation, tracked by Group-IB, dubbed JadeProx, is using a new loader called TriBack Loader to target government, healthcare, and education organizations across Asia and Latin America. The operation levera… The Hacker News · Jul 23, 2026 High CVE-2018-11511CVE-2021-24139CVE-2021-31755CHHOVIloaderspear-phishingvulnerability
threat-intel Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Researchers at Simon Fraser University, the Chinese University of Hong Kong, Shandong University, and QAX have discovered a significant vulnerability in five popular open-source Android mobile agent frameworks. These age… The Hacker News · Jul 21, 2026 High CVE-2026-25592CVE-2026-26030CHHOmobile-securityprompt-injectionusb-debugging
threat-intel Massive Password Spray Campaign Targeting Azure CLI A massive password spray campaign targeting Microsoft 365 environments, specifically the Azure CLI, was observed by Huntress. The attacks, originating from AS32167 and linked to LSHIY LLC, resulted in the compromise of o… SecurityWeek · Jul 1, 2026 High CHHOUScredential spraymfaoauth ropc
threat-intel FishMonger’s arsenal upgraded: SprySOCKS for Windows ESET researchers have discovered two new, undocumented Windows variants of FishMonger's SprySOCKS backdoor, operated by the Chinese threat actor I-SOON (believed to be part of the Winnti Group). These variants, WIN_DRV a… WeLiveSecurity · Jun 16, 2026 High CHHOTAwindowsbackdoorkernel driver