threat-intel Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations Iranian hackers, linked to Iran's Ministry of Intelligence and Security (MOIS) and operating under the moniker Cavern Manticore, are utilizing a new, modular command-and-control (C2) framework called ‘Cavern’ to target I… The Hacker News · Jul 6, 2026 High CVE-2025-52691CVE-2025-68613CVE-2025-9316ISIRc2command and controldotnet
malware Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery This report details a concerning trend in malware delivery – the evolution of ClickFix, a technique where users are tricked into running malicious code by hand. Researchers have uncovered a new API-driven approach to gen… The Hacker News · Jul 1, 2026 High RUIRNOmalwarepayloadapi
threat-intel Iran, Russia, China Target Water Systems for Sabotage A DomainTools report details ongoing nation-state targeting of water systems by Iran, Russia, and China, primarily through exploiting weak passwords, exposed PLCs, and HMI vulnerabilities. The motivations behind these at… Dark Reading · Jun 29, 2026 High IRRUCHcritical infrastructurenation-statewater systems
threat-intel The Behavior of Coordinated SSH Brute Force Attacks over the last three months [Guest Diary], (Wed, Jun 17th) This report details a three-month analysis of coordinated SSH brute-force attacks conducted using a honeypot system, highlighting a correlation between attack activity and geopolitical events, law enforcement actions, an… SANS Internet Storm Center · Jun 18, 2026 High USIRILsshbrute-forcehoneypot
threat-intel The Onboarding Password Mistake That Creates Unnecessary Risk This article discusses the significant security risks associated with using temporary onboarding passwords, highlighting how they are frequently shared insecurely and remain active for extended periods. The practice crea… The Hacker News · Jun 15, 2026 High USIRonboardingcredentialssecurity
threat-intel Major US surveillance program poised to lapse after legislative deadlock This article reports on a looming lapse in the US surveillance program, Section 702 of the FISA, due to legislative deadlock in Congress. The program, which allows intelligence agencies to collect communications of forei… The Record · Jun 12, 2026 High USIRCHfisasurveillanceintelligence
threat-intel Iranian Cyber Group Handala Claims Cal Water Hack The Iranian cyber threat actor Handala has claimed responsibility for a data breach targeting California Water Service (Cal Water), resulting in the theft of 5GB of data including customer information and credentials. Th… SecurityWeek · Jun 12, 2026 High USIRirandata breachcyber espionage
threat-intel Infostealers Turn Millions of Devices Into Credential Theft Machines This report details a significant increase in the use of infostealers as a primary method for attackers to steal credentials and gain unauthorized access to networks. Over 11.1 million devices were infected in 2025, resu… SecurityWeek · Jun 10, 2026 High IRinfostealerscredentialsmalware-as-a-service
threat-intel Cybercriminals: the 'auditors' you never hired This article explores the psychological phenomenon of ‘normalcy bias’ – our tendency to underestimate risk and assume things will always go as they have in the past – and how it contributes to a persistent rise in cybera… WeLiveSecurity · Jun 9, 2026 High UKIRcognitive biasnormalcy biascybersecurity
threat-intel Iran Signed a Ceasefire — Its Hackers Didn't This Dark Reading article discusses the ongoing cyber warfare between Iran and the United States, highlighting a significant loophole in international conflict rules. Following a ceasefire extension, U.S. agencies warned… Dark Reading · Jun 8, 2026 High IRUSIScyberwarfarecritical infrastructureiran
threat-intel In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA This week’s cybersecurity news highlights a range of threats, including AI-powered attacks targeting computing power, ongoing Grandoreiro banking trojan campaigns, and a self-propagating ransomware group utilizing obfusc… SecurityWeek · Jun 5, 2026 High IRUSairansomwaresupply chain
threat-intel ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories This bulletin highlights several ongoing cyber threats, including a high-severity SSRF vulnerability in Cisco Unified Communications Manager, a large-scale spyware operation targeting Russian officials by foreign intelli… The Hacker News · Jun 4, 2026 High CVE-2026-20230CVE-2022-0492CVE-2019-5736RUIRUSssrfspywarekeylogger
threat-intel Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts Hackers exploited Meta’s AI support bot on Instagram to gain unauthorized access to accounts, including those belonging to the Obama White House and the U.S. Space Force. The tactic involved tricking the bot into resetti… Krebs on Security · Jun 1, 2026 High IRaichatbotsocial engineering
threat-intel 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface This analysis from Palo Alto Unit 42 assesses the significant cyber threat landscape surrounding the 2026 FIFA World Cup, highlighting the expanded attack surface created by the event's scale and complexity. The report i… Palo Alto Unit 42 · May 28, 2026 High USIRRUmega-eventcybersecuritythreat intelligence
threat-intel ESET APT Activity Report Q4 2025–Q1 2026 ESET’s Q4 2025 – Q1 2026 APT Activity Report highlights a period of intense geopolitical activity driving advanced cyber espionage. China-aligned actors were mobilized to monitor maritime and energy developments, while I… WeLiveSecurity · May 28, 2026 High CHIRPOaptcyber espionagegeopolitics
threat-intel UK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About Russia British intelligence chief Anne Keast-Butler warned of the escalating threat posed by Russia’s cyber activities, particularly the weaponization of artificial intelligence, and emphasized the urgent need for increased cyb… SecurityWeek · May 27, 2026 High UKRUCHartificial intelligencecybersecurityrussia
apt Iranian intelligence service behind hack of LA transit system, researchers say Iranian intelligence service operatives, known as Ababil of Minab, were responsible for a significant cyberattack targeting the Los Angeles County Metropolitan Transportation Authority (LACMTA). The group, linked to the… The Record · May 27, 2026 High IRISTUirancyberattackcritical infrastructure
threat-intel Iranian APT Targets Aviation, Software Companies With Updated Tools The Iranian APT group, known as Nimbus Manticore, has been aggressively updating its tactics and tools to target aviation and software companies globally. The group, linked to Charming Kitten and the IRGC, is employing… SecurityWeek · May 26, 2026 High AEIRSAaptphishingappdomain
malware Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning Iranian state-sponsored threat actor Nimbus Manticore (UNC1549) has launched a new campaign utilizing the MiniFast backdoor, developed with potential AI assistance, to target organizations in the aviation and software se… The Hacker News · May 26, 2026 High SAAUIRphishingbackdoorappdomain hijacking
threat-intel Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns This report from Palo Alto Unit 42 details ongoing espionage campaigns conducted by the Iran-nexus APT group Screening Serpens (UNC1549). The group, active since 2022, targeted entities in the U.S., Israel, the UAE, and… Palo Alto Unit 42 · May 22, 2026 High USIRILaptespionagesocial engineering