threat-intel North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels North Korean threat actors, operating under the UNK_DeadDrop campaign, are employing a sophisticated phishing technique targeting developers across numerous sectors, including finance and cryptocurrency, using malicious… The Hacker News · Jun 15, 2026 High USGBAUdevelopergithubvscode
threat-intel China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance A China-linked botnet, dubbed JDY, has significantly expanded its operations, now comprising over 1,500 compromised SOHO and IoT devices. Initially a component of the KV-botnet, the JDY botnet is being used for large-sca… The Hacker News · Jun 10, 2026 High CVE-2026-35616USBRDEiotreconnaissancebotnet
vulnerability Gogs patches critical zero-day enabling remote code execution A critical zero-day vulnerability in Gogs, a remote collaboration platform, has been identified, allowing authenticated attackers to execute remote code and access private repositories. The flaw, present in versions up t… BleepingComputer · Jun 8, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPremote-code-executionzero-dayauthentication
malware C0XMO botnet spreads via DD-WRT router flaw, kills rival malware A new botnet, C0XMO, leveraging a DD-WRT router vulnerability (CVE-2021-27137) is spreading across various device architectures, including routers, DVRs, and Android devices. This botnet, developed by the Gafgyt group, i… BleepingComputer · Jun 7, 2026 High CVE-2021-27137DEJPddosbotnetexploit
threat-intel PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network PCPJack, a threat actor initially linked to TeamPCP, has established a covert SMTP email relay network by hijacking 230 cloud servers across AWS, Google Cloud, and Azure. The operation involved converting business server… The Hacker News · Jun 5, 2026 High USUKDEsmtp relaycloud proxyc2
threat-intel Chinese Cybercrime Group in Spotlight for Record Campaign Pace A Chinese cybercrime group, TA4922, is experiencing a record surge in campaign activity, utilizing sophisticated social engineering tactics to target organizations globally. The group’s primary objectives involve data th… SecurityWeek · Jun 4, 2026 High GBDEITsocial engineeringcredential phishingremote access
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike A zero-day vulnerability in Digital Knowledge KnowledgeDeliver LMS was exploited to deploy the Godzilla web shell and establish Cobalt Strike Beacon access. The flaw, stemming from hard-coded ASP.NET machine keys, allowe… The Hacker News · May 26, 2026 Critical CVE-2026-5426JPzero-daydeserializationasp.net
threat-intel A cunning predator: How Silver Fox preys on Japanese firms this tax season A targeted spearphishing campaign, dubbed ‘Silver Fox’, is actively exploiting the Japanese tax filing season to compromise businesses. The campaign utilizes convincing lures related to tax compliance, salary adjustments… WeLiveSecurity · Mar 27, 2026 High JPspearphishingjapantax season