threat-intel Fake Bahrain Alert App Deploys Android Surveillance Malware A malicious Android application, dubbed ‘BH Alert,’ is being distributed through fake Google Play sites mimicking Bahraini government entities to deliver a four-stage surveillance platform. The app leverages users' trust in emergency alerts during times of heightened tension, such as following missile strikes, to insta… Dark Reading · Jul 22, 2026 High BHKUandroidspywaremalware
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
phishing INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator INTERPOL, in collaboration with authorities across 13 MENA countries, successfully dismantled the decade-long Sniper Dz phishing-as-a-service (PhaaS) platform, resulting in the arrest of its administrator, Guedz. The ope… The Hacker News · Jun 12, 2026 High ALAEDZphishing-as-a-servicecredential theftsocial engineering
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit