threat-intel Threat landscape for industrial automation systems. Q2 2026 In Q2 2026, the percentage of ICS computers blocked by malicious objects continued to decline, hitting a low of 19.15%, the lowest since 2022. East Asia and Africa saw significant increases in threat percentages across various categories, including malicious scripts, phishing pages, and email threats. Biometrics consi… Securelist · 3d ago High RUCHAFicsindustrial automationcybersecurity
threat-intel Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler Iranian state-sponsored hacking group Nimbus Manticore (linked to Charming Kitten) has expanded its toolset with a TWOSTROKE-like backdoor and SSH tunneling utility, furthering its espionage activities targeting defense,… The Hacker News · 4d ago High IRMIEUsshbackdoorc2
threat-intel China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud The China-linked threat actor Jewelbug, operating as a ‘hack-for-hire’ group, is engaged in both sophisticated government espionage targeting nations across the Middle East, Southeast Asia, and South Asia, and cryptocurr… The Hacker News · Aug 14, 2026 High CHMISOespionagecryptocurrencyhack-for-hire
threat-intel 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft The ‘Jewelbug’ APT group, operating out of China, balances state-sponsored espionage and cryptocurrency theft, targeting governments, military organizations, and corporations globally. They utilize a custom command-and-c… Dark Reading · Aug 13, 2026 High CHMISOcyber espionagecryptocurrency theftnation-state
threat-intel Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA The Gunra ransomware gang, leveraging leaked Conti code and exploiting vulnerabilities in Fortinet products, is expanding its operations through a RaaS affiliate program and successfully bypassing defenses, including MFA… Dark Reading · Aug 11, 2026 High CVE-2024-55591CVE-2025-24472SOBRCAransomwareraasfortinet
threat-intel Device Code Phishing Up 1,500% in 2026; Vishing Doubles Device code phishing and vishing are experiencing a dramatic surge, driven by state-sponsored and cybercriminal groups, and are proving highly effective at bypassing traditional security measures. CrowdStrike reports a 1… Dark Reading · Aug 4, 2026 High USRUEUphishingvishingdevice-code-phishing
threat-intel Chinese hackers target telcos with new Linux, Windows malware A Chinese cyber-espionage group, known as Calypso (Red Lamassu), has been targeting telecommunications providers globally since mid-2022 with a dual-pronged malware campaign utilizing Showboat (Linux) and JMFBackdoor (Wi… BleepingComputer · May 21, 2026 High CHMIASlinuxwindowsespionage
threat-intel Why geopolitical turmoil is a gift for scammers, and how to stay safe Geopolitical turmoil is being exploited by scammers to increase the success of their fraudulent schemes. The article details a range of scams – from fake charities and romance fraud to investment scams and sensational fa… WeLiveSecurity · May 15, 2026 Medium IRMIscamsfraudcybercrime