ransomware The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm The Gentlemen ransomware group, initially operating as the affiliate-focused Phantom Mantis, has evolved into an independent RaaS operation led by the cybercriminal LARVA-368 (aka hastalamuerte). The group, responsible… The Hacker News · Jun 11, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073RUTHUKransomware-as-a-servicedouble extortionaffiliate program
threat-intel ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories This week’s threat intelligence bulletin highlights several concerning developments, including a large-scale leak of identity records facilitated by infostealers, the emergence of a sophisticated MaaS RAT named SilabRAT… The Hacker News · Jun 11, 2026 High CVE-2026-49494USCHNOinfostealersmaas ratcredential theft
threat-intel ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More This week’s security news highlights a series of attacks and vulnerabilities, including a supply chain attack targeting Microsoft GitHub repositories via the Miasma Worm, a zero-day exploit in Android, and ongoing cyberc… The Hacker News · Jun 8, 2026 High CVE-2025-48595CVE-2026-28318CVE-2026-39210CHUSGEsupply-chainzero-daycybercrime
threat-intel China's TA4922 Expands Cybercrime Attacks Globally China's TA4922 cybercrime group has significantly expanded its operations globally, targeting a diverse range of countries and employing a wider array of tactics and techniques than previously observed. Initially focused… Dark Reading · Jun 4, 2026 High CHJATAphishingratmalware
threat-intel Chinese Cybercrime Group in Spotlight for Record Campaign Pace A Chinese cybercrime group, TA4922, is experiencing a record surge in campaign activity, utilizing sophisticated social engineering tactics to target organizations globally. The group’s primary objectives involve data th… SecurityWeek · Jun 4, 2026 High GBDEITsocial engineeringcredential phishingremote access
malware Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content A new malware campaign, dubbed Weedhack, is targeting Minecraft players through YouTube and malicious websites, distributing a MaaS (Malware-as-a-Service) tool. The campaign, active since January 2026, utilizes SEO poiso… The Hacker News · Jun 3, 2026 High USDEINminecraftmalwareyoutube
malware Over 116,000 Mincraft systems infected in WeedHack malware campaign A large-scale malware campaign, dubbed WeedHack, has infected over 116,000 Minecraft systems since January, primarily through malicious mods and clients promoted via YouTube and SEO poisoning. The malware operates as a M… BleepingComputer · Jun 2, 2026 High USDEINminecraftmalwaremaas
malware Over 116,000 Minecraft systems infected in WeedHack malware campaign A large-scale malware campaign, dubbed WeedHack, has infected over 116,000 Minecraft systems since January, primarily through malicious mods and clients promoted on YouTube and via SEO poisoning. The operation is a malwa… BleepingComputer · Jun 2, 2026 Medium USDEINminecraftmalwaremaas
threat-intel AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It. This article discusses the accelerating pace of vulnerability exploitation driven by the use of AI by both attackers and defenders. The traditional approach of simply ‘patching faster’ is no longer sufficient due to the… The Hacker News · Jun 2, 2026 High INaivulnerabilityexploitation
threat-intel China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan A new cyber espionage campaign, dubbed Operation Dragon Weave, is targeting government, research, and financial institutions in the Czech Republic and Taiwan using spear-phishing emails and a Rust-based loader to deploy… The Hacker News · Jun 1, 2026 High CZTWINspear-phishingc2azure
threat-intel Asia's Cyber Insurance Market Shows Signs of Life The Asian cyber insurance market has historically lagged behind other regions due to low penetration rates, particularly among larger organizations and small businesses. However, a recent report indicates a potential shi… Dark Reading · May 29, 2026 High CHJASIcyberinsuranceransomwareapac
vulnerability CP Plus 8 Ch. Network Video Recorder A cross-site scripting (XSS) vulnerability has been identified in CP Plus 8 Ch. Network Video Recorder devices (CP-UNR-108F1 Hardware V1.0, CP-UNR-108F1 Web V3.2.7.128806, and CP-UNR-108F1 System V4.001.00AT009.0.R). Att… CISA Advisories · May 28, 2026 High CVE-2026-6824INNPAExsscwe-79firmware
threat-intel CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks CERT-In has mandated a 12-hour patching window for critical internet-facing vulnerabilities, driven by the increasing use of AI by threat actors to automate attacks. This response is intended to address the accelerated a… The Hacker News · May 26, 2026 High INaicybersecurityvulnerability
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel Two Americans plead guilty to assisting India-based tech support scam centers Two American men, Adam Young and Harrison Gevirtz, have pleaded guilty to assisting India-based tech support scam centers. They operated a U.S.-based tech firm, C.A. Cloud Attribution, providing services like call routin… The Record · May 21, 2026 High USINTNscamfraudtelemarketing
threat-intel Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks This article details the discovery of "Showboat" (kworker), a Linux post-exploitation framework being shared among Chinese Advanced Persistent Threat (APT) groups, primarily Calypso and Red Lamassu. The malware has been… Dark Reading · May 21, 2026 Medium CHAFUKaptlinuxspyware
threat-intel Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks Microsoft disrupted a malware-signing-as-a-service (MSaaS) operation, dubbed OpFauxSign, led by the threat actor Fox Tempest, which was using its Artifact Signing system to distribute malware and ransomware. The operatio… The Hacker News · May 20, 2026 High USFRINmsaascode-signingmalware
threat-intel [GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th) This article, a guest diary by an ISC intern, details an investigation into a fraudulent marketplace operation. The author discovered a website using SEO poisoning to lure victims into purchasing goods from a fake market… SANS Internet Storm Center · May 13, 2026 High INseo poisoningfraudmarketplace
malware Fake call logs, real payments: How CallPhantom tricks Android users This report details a widespread Android scam, dubbed CallPhantom, where fraudulent apps masquerading as call log retrieval services tricked users into paying for randomly generated data. Twenty-eight apps, collectively… WeLiveSecurity · May 7, 2026 Medium INscamfraudandroid