threat-intel Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant A phishing campaign targeting hotels and hospitality organizations is underway, utilizing deceptive ZIP files containing Node.js implants to gain access to front-desk machines. The campaign, discovered by Microsoft, empl… The Hacker News · Jun 26, 2026 High GBJPDKphishingnode.jston
threat-intel Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup This Smashing Security podcast episode discusses a potential security risk at FIFA where a hacker could have used a ‘rickroll’ tactic to disrupt the World Cup. The conversation highlights a Black Kite report detailing a… Graham Cluley · Jun 24, 2026 High UKNLSEransomwaresupply chainrickroll
ransomware Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered A coordinated international law enforcement operation, involving Bitdefender, Bitsight, ESET, Microsoft, and Europol, successfully disrupted the Amadey and StealC malware networks, recovering 27 million stolen credential… The Hacker News · Jun 24, 2026 High NLCADEmaascredential theftransomware
ransomware Amadey, StealC malware operations disrupted in Operation Endgame action Operation Endgame, a coordinated law enforcement effort involving Microsoft, Europol, and international partners, successfully disrupted infrastructure used by the Amadey and StealC malware operations. The operation resu… BleepingComputer · Jun 24, 2026 High USCADKmalware-as-a-servicecredential theftransomware
threat-intel SocGholish Takedown Highlights Malicious TDS Threats A coordinated international law enforcement operation, part of Operation Endgame, successfully disrupted SocGholish, a decade-old malware framework used as an initial-access broker by cybercriminal groups like Evil Corp.… Dark Reading · Jun 23, 2026 High NLtdssmalwareaffiliate
threat-intel Russian Initial Access Broker Behind FortiBleed Campaign A Russian initial access broker (IAB) is targeting over 430,000 FortiGate firewalls globally as part of the FortiBleed campaign, harvesting credentials and selling access to other malicious actors. The campaign utilizes… SecurityWeek · Jun 23, 2026 High USGBNLcredential harvestingfirewallsupply chain
threat-intel Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites An international law enforcement operation, dubbed Operation Endgame, successfully disrupted SocGholish’s infrastructure and removed malware from nearly 15,000 WordPress websites. The takedown, involving agencies from mu… The Hacker News · Jun 19, 2026 High NLCADEbotnetwordpressmalware
threat-intel Close Encounters of the Human Kind This article from Cisco Talos details a novel approach to reverse engineering that leverages AI agents alongside traditional tools like the VB6 disassembler. The key innovation is exposing the disassembler's parsed data… Cisco Talos · Jun 18, 2026 High GBFRUSreverse engineeringaiautomation
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
threat-intel North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels North Korean threat actors, operating under the UNK_DeadDrop campaign, are employing a sophisticated phishing technique targeting developers across numerous sectors, including finance and cryptocurrency, using malicious… The Hacker News · Jun 15, 2026 High USGBAUdevelopergithubvscode
data-breach Police arrest man following hack of Ajax football club A 35-year-old man has been arrested in the Netherlands following a significant security breach at Ajax football club. The incident exposed the personal data of approximately 300,000 supporters due to a vulnerability in t… Graham Cluley · May 29, 2026 High NLdata-leakmobile-appfan-data
threat-intel Dutch Raid Fails to Dent Russian Bulletproof Host A Dutch law enforcement operation targeting THE.Hosting, a bulletproof hosting network linked to Russian cybercrime, resulted in the seizure of 800 servers and arrests of two operators but failed to significantly disrupt… Dark Reading · May 28, 2026 High NLRUDKbulletproof hostingcybercrimesanctions evasion
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel Dutch authorities arrest men suspected of providing infrastructure for Russian cyber operations Dutch authorities have arrested two IT entrepreneurs suspected of providing hosting infrastructure used in pro-Russian cyberattacks and disinformation campaigns. The investigation, led by the FIOD, uncovered a network in… The Record · May 25, 2026 High NLMDRUcyberattackdisinformationsanctions
threat-intel Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Dutch authorities have seized over 800 servers and arrested two individuals – Andrey Nesterenko and Youssef Zinad – operating MIRhosting and WorkTitans, respectively, for facilitating cyberattacks and disinformation camp… Krebs on Security · May 25, 2026 High NLDKRUcyberattackddossanctions
threat-intel First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups A global operation, dubbed Operation Saffron, led by France and the Netherlands, successfully dismantled the First VPN service, a virtual private network specifically designed for criminal use. The service was utilized b… The Hacker News · May 22, 2026 High USFRNLvpnransomwareanonymity
threat-intel Europe dismantles VPN service used by cybercriminals to hide ransomware attacks European law enforcement agencies successfully dismantled First VPN, a virtual private network (VPN) service heavily utilized by cybercriminals to mask their activities, including ransomware attacks and fraud schemes. Th… The Record · May 20, 2026 High FRNLUAvpncybercrimeransomware