threat-intel Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware North Korean APT37 group utilized a spear-phishing campaign mimicking Microsoft security alerts to deploy NarwhalRAT malware. The campaign leveraged urgency and confusion to trick victims into executing a malicious LNK f… The Hacker News · Jun 16, 2026 High NOSOspear-phishingratnorth korean
threat-intel ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories This week’s threat intelligence bulletin highlights several concerning developments, including a large-scale leak of identity records facilitated by infostealers, the emergence of a sophisticated MaaS RAT named SilabRAT… The Hacker News · Jun 11, 2026 High CVE-2026-49494USCHNOinfostealersmaas ratcredential theft
threat-intel Chinese, N. Korean Threat Groups Build on Asia-Pacific Success This article reports on the ongoing cybercrime activities of North Korean and Chinese threat groups targeting financial firms and cryptocurrency assets within the Asia-Pacific region. Despite increased international coll… Dark Reading · Jun 11, 2026 High CHNOSOcybercrimecryptocurrencynorth korea
vulnerability NAVTOR NavBox A critical vulnerability (CVE-2026-21404) has been identified in NAVTOR NavBox versions 4.16.1.20, allowing local attackers to gain unauthorized access due to hard-coded credentials within the Windows Communication Found… CISA Advisories · Jun 4, 2026 Critical CVE-2026-21404NOsoapcredentialswcf
malware Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content A new malware campaign, dubbed Weedhack, is targeting Minecraft players through YouTube and malicious websites, distributing a MaaS (Malware-as-a-Service) tool. The campaign, active since January 2026, utilizes SEO poiso… The Hacker News · Jun 3, 2026 High USDEINminecraftmalwareyoutube
supply-chain Red Hat removes tainted packages after software pipeline compromise Red Hat removed numerous software packages from its distribution pipeline after a compromised GitHub account was used to distribute credential-stealing malware. The attack, utilizing a variant of the Mini Shai-Hulud worm… The Record · Jun 2, 2026 High NOUKsupply chaingithubmalware
threat-intel Nordic CISOs Handle Rising Cyber Threats Remarkably Well A recent report by Truesec found that CISOs in Nordic countries are not experiencing a rise in severe cybersecurity incidents, despite a global increase in cyber threats. This surprising trend is attributed to improved c… Dark Reading · May 28, 2026 Medium NOcybersecuritynordicthreat intelligence
threat-intel UK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About Russia British intelligence chief Anne Keast-Butler warned of the escalating threat posed by Russia’s cyber activities, particularly the weaponization of artificial intelligence, and emphasized the urgent need for increased cyb… SecurityWeek · May 27, 2026 High UKRUCHartificial intelligencecybersecurityrussia
threat-intel The Alert Firehose Finally Meets Its Match This article discusses the evolution of Network Detection and Response (NDR) systems, particularly with the integration of agentic AI. It highlights how early NDR deployments suffered from a "noisy" alert firehose due to… The Hacker News · May 25, 2026 Medium NOndraithreat intelligence
threat-intel Smashing Security podcast #468: High-speed train hacks and homicidal lawnmowers This Smashing Security podcast episode discusses several ongoing cybersecurity incidents and investigations. The conversation touches on the ongoing Lazarus Group activities, including the upcoming ‘Cyberhack’ season, an… Graham Cluley · May 20, 2026 High NOTAnorth koreamalwarethreat intelligence
vulnerability Verizon DBIR: Enterprises Face a Dangerous Vulnerability Glut Verizon's 2026 Data Breach Investigations Report (DBIR) highlights a concerning trend: the increasing prevalence of exploits in initial breaches, rising to 31% in 2025. Organizations struggle to keep pace with the massiv… Dark Reading · May 19, 2026 High NOvulnerabilitiespatch managementai
threat-intel Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware Four npm packages have been identified as containing malicious code, including a clone of the Shai-Hulud worm. One package delivers a DDoS botnet (Phantom Bot), while the others function as infostealers, stealing sensiti… The Hacker News · May 18, 2026 High NOsupply chainnpminfostealer
threat-intel Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools This report from Palo Alto Unit 42 details how Active Directory Certificate Services (AD CS) is frequently exploited by both financially motivated ransomware groups and state-sponsored actors due to misconfigured templat… Palo Alto Unit 42 · May 11, 2026 High CVE-2022-26923NOad cscertificate issuanceprivilege escalation
threat-intel Fracturing Software Security With Frontier AI Models This report from Palo Alto Unit 42 highlights the emerging threat posed by advanced AI models, particularly "frontier AI models," which demonstrate autonomous vulnerability discovery and exploitation capabilities. The ra… Palo Alto Unit 42 · Apr 20, 2026 High UNNOaivulnerabilityzero-day