Des cibles françaises au cœur d’une plateforme cybercriminelle A ZATAZ investigation has uncovered a list of French organizations targeted by a cybercriminal group, Krybit, who are aggressively recruiting affiliates through a platform offering a lucrative 80% revenue split. The group, known for ransomware operations, is actively seeking partners to expand its reach and utilize a d… ZATAZ · Aug 7, 2026 FRMXUSransomwarerecruitmentcybercrime
threat-intel A new extortion cocktail: office printers, small ransoms, and BitLocker Two separate incidents – one in Colombia and another in Mexico – highlight a concerning trend of attackers leveraging misconfigured systems and built-in Microsoft tools to deploy BitLocker encryption and demand ransom pa… Securelist · Jul 21, 2026 High COMXransomwarebitlockerrdp
threat-intel Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign A cybercriminal, utilizing AI coding tools and a sophisticated pipeline, exposed a comprehensive phishing toolkit targeting Mexican users and beyond. The operator, likely leveraging LLMs and tools like Coderrr, created a… The Hacker News · Jul 20, 2026 High CVE-2025-33053CVE-2026-21513CVE-2025-24054MXUSDEphishingwebdavai
threat-intel OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps OkoBot, a malware framework, has been actively targeting hardware wallet users since April 2025, primarily through phishing attacks leveraging a module called SeedHunter. SeedHunter intercepts the wallet's desktop softwa… The Hacker News · Jul 15, 2026 High BRVNCAphishingmalwarehardware wallet
ransomware No Manners Here: The Ruthless Rise of The Gentlemen Ransomware The Gentlemen, a rapidly growing Ransomware-as-a-Service (RaaS) program, has significantly increased its victim count in 2026, becoming the second most active RaaS program globally. Leveraging a 90% affiliate payout stru… Palo Alto Unit 42 · Jul 10, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073USCAGBransomware-as-a-serviceracksedge-device-attack
threat-intel SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users A new banking fraud operation, tracked as REF6045, is targeting Mexican banks, fintech companies, and cryptocurrency exchanges using a malware toolset called SCMBANKER. The operation leverages fake CAPTCHA verification p… The Hacker News · Jul 8, 2026 High MXbankingmalwarephishing
threat-intel 2026 FIFA World Cup Faces Surge in Cyber Threats The 2026 FIFA World Cup is facing a surge in cyber threats across the US, Canada, and Mexico, driven by a complex threat landscape including financial and nation-state actors. These threats primarily involve social engin… Dark Reading · Jun 24, 2026 High USCAMXcybercrimesocial engineeringfraud
malware WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool A WhatsApp-based campaign is utilizing malicious VBScript files to trick users into installing ManageEngine RMM tool software. The campaign, currently active across multiple countries, leverages deceptive document names… The Hacker News · Jun 23, 2026 Medium MYBRINsocial engineeringvbsremote access
malware A VBScript campaign distributed through WhatsApp deploying RMM software A WhatsApp-distributed malware campaign, active as of June 2026, leverages deceptive VBScript files disguised as financial documents to trick users into executing malicious code. This code ultimately installs legitimate… Securelist · Jun 22, 2026 High MYBRINsocial engineeringvbswhatsapp
threat-intel CISA warns Fortinet users to secure devices after FortiBleed leak CISA has issued a warning to Fortinet customers regarding the "FortiBleed" data leak, which exposed nearly 74,000 firewall and VPN credentials. Threat actors are exploiting these compromised credentials to target interne… BleepingComputer · Jun 19, 2026 High USRUCNcredentialsvpnfirewall
apt Operation Escaneo Signals Shift in LatAm Threat Landscape Operation Escaneo, a coordinated cyber campaign led by the MexicanMafia/PanchoVilla threat actor, represents a significant shift in the threat landscape of Latin America. The campaign, spanning 2025-2026, targeted critic… Dark Reading · Jun 18, 2026 High CVE-2022-42475CVE-2023-27997CVE-2024-21762MXECPTlatin americareconnaissancedata exfiltration
threat-intel Close Encounters of the Human Kind This article from Cisco Talos details a novel approach to reverse engineering that leverages AI agents alongside traditional tools like the VB6 disassembler. The key innovation is exposing the disassembler's parsed data… Cisco Talos · Jun 18, 2026 High GBFRUSreverse engineeringaiautomation
data-breach FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. A significant data leak, dubbed "FortiBleed," has exposed approximately 73,932 Fortinet VPN credentials for firewall URLs across numerous organizations worldwide. The leak, discovered by Bob Diachenko, reveals a multi-op… BleepingComputer · Jun 17, 2026 High USGBJPvpncredentialsbreach
threat-intel FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins A wave of fraudulent activity targeting FIFA World Cup 2026 fans is underway, involving fake websites, banking malware, and stolen login credentials. The operation, spearheaded by the Chinese-speaking group ‘GHOST STADIU… The Hacker News · Jun 5, 2026 High USCAMXfraudphishingmalware
threat-intel Wardriving assessment across Mexico: Preparing for the 2026 World Cup Kaspersky GReAT conducted a wardriving assessment across Mexico City, Guadalajara, and Monterrey to analyze public Wi-Fi infrastructure ahead of the 2026 FIFA World Cup. The study, focused on passive observation and infr… Securelist · Jun 2, 2026 Medium MXpublic wifiwireless securityssid analysis
threat-intel Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans A Chinese-speaking fraud gang, dubbed GHOST STADIUM, is impersonating FIFA's official website to steal credentials and payment details from fans seeking tickets for the 2026 World Cup. The operation, involving over 300 f… The Record · May 28, 2026 High CNUSCAfraudphishingworld cup
malware Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users Two separate malware campaigns are targeting Windows and Android users across Latin America and Europe, primarily focusing on banking trojans. The first campaign utilizes the Grandoreiro malware, an actively evolving ban… The Hacker News · May 27, 2026 High PTBRESbanking trojanandroid malwaredll side-loading
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups A global operation, dubbed Operation Saffron, led by France and the Netherlands, successfully dismantled the First VPN service, a virtual private network specifically designed for criminal use. The service was utilized b… The Hacker News · May 22, 2026 High USFRNLvpnransomwareanonymity
threat-intel Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition A 19-year-old teenager, identified as "Bouquet," has been arrested in Finland and faces US extradition charges for allegedly being a member of the Scattered Spider cybercrime group. The investigation revealed the group’s… Graham Cluley · May 4, 2026 High USGBFIsocial engineeringphishingmfa