threat-intel APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations APT28-linked threat actors, tracked as BlueDelta, have been deploying a new backdoor named HOOKEDGE to target European government and diplomatic organizations since late 2025. HOOKEDGE, a lightweight Windows batch script, is delivered via macro-enabled Word documents and utilizes webhook[.]site for command-and-control,… The Hacker News · 2d ago High ROSPTUapt28hookedgewebhook
threat-intel Interpol's Jackal IV Disrupts West African Crime Infrastructure Interpol's Jackal IV operation successfully disrupted West African crime infrastructure networks involved in various cybercrime activities, including business email compromise, romance scams, and money laundering. The op… Dark Reading · 4d ago High ARAUCAcybercrimefraudmoney laundering
threat-intel INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown INTERPOL’s fourth iteration of Operation Jackal has resulted in the arrest of 58 individuals and the identification of 263 suspects globally, targeting West African organized crime groups involved in cyber fraud, includi… The Hacker News · 4d ago High AUARBEcybercrimefraudmoney laundering
threat-intel 58 arrested in international cybercrime crackdown Interpol and law enforcement agencies across 22 countries concluded Operation Jackal IV, resulting in the arrest of 58 individuals involved in a coordinated cybercrime operation. The operation targeted a crime-as-a-servi… The Record · 4d ago High ARITROcybercrimeromance scamsmoney laundering
threat-intel Fake IRS letters target cryptocurrency holders Scammers are impersonating the IRS to trick cryptocurrency holders into visiting fake websites designed to steal their personal information and digital assets. The IRS does not operate a Digital Asset Compliance Portal,… Graham Cluley · Aug 4, 2026 High HOROphishingcryptocurrencyfraud
threat-intel Beelzebub Raises $3.4 Million for Hacker-Trapping Platform Beelzebub, an Italian cybersecurity startup, has raised €3.4 million in seed funding to combat AI-powered cyberattacks. Their platform uses a combination of red and blue teaming, deception technology, and AI analysis to… SecurityWeek · Jul 27, 2026 Medium ITSAROaicybersecuritythreat intelligence
threat-intel Europe's Multilingual Reality Exposes AI Security Gaps Europe faces a unique security challenge due to its multilingual landscape and the resulting inconsistencies in AI safety and security across numerous languages. While many AI models can process text in dozens of languag… Dark Reading · Jul 24, 2026 High EUGESPaisecuritymultilingual
threat-intel Romania races to restore land registry after cyberattack disrupts property market A major cyberattack disrupted Romania's land registry system, causing a standstill in property transactions and delaying a planned increase in property taxes. The attack, attributed to a threat actor named ByteToBreach,… The Record · Jul 20, 2026 High ROcyberattackland registryproperty
threat-intel ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories This week’s security news is a mixed bag, encompassing a range of threats from sophisticated ransomware attacks to deceptive software distribution and widespread surveillance techniques. A new ransomware family, Spirals,… The Hacker News · Jul 16, 2026 High CVE-2026-46817CVE-2023-4346CVE-2026-35273NESPPOransomwareinfostealerbrandjacking
threat-intel ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing ClickLock Stealer, a new macOS malware, bypasses macOS security through social engineering and aggressive process killing to steal sensitive data, including browser data, cryptocurrency wallets, and password manager info… SecurityWeek · Jul 16, 2026 High DEFRITmacossocial engineeringprocess killing
threat-intel UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign A sophisticated, Russian-speaking threat actor, UAT-11795, has been conducting a financially motivated campaign targeting users in the U.S. and Europe since June 2025. The campaign utilizes a novel combination of tools,… Cisco Talos · Jul 16, 2026 High USGEROclickfixsocial engineeringc2
threat-intel EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign The European Union has imposed sanctions on Russian intelligence officers and entities involved in a long-running cyber espionage campaign targeting European governments and critical infrastructure. This campaign, spanni… SecurityWeek · Jul 13, 2026 High FRDEPLcyber espionagecritical infrastructurerussian threat
threat-intel Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions Russia’s FSB, specifically its Center 16 signals intelligence arm, has been formally blamed for a cyberattack that threatened to cut heating to half a million people in Poland last winter. Following this attribution, the… The Record · Jul 12, 2026 High RUPOFRcyberattackcybercrimeespionage
ransomware No Manners Here: The Ruthless Rise of The Gentlemen Ransomware The Gentlemen, a rapidly growing Ransomware-as-a-Service (RaaS) program, has significantly increased its victim count in 2026, becoming the second most active RaaS program globally. Leveraging a 90% affiliate payout stru… Palo Alto Unit 42 · Jul 10, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073USCAGBransomware-as-a-serviceracksedge-device-attack
ransomware Europe Evolves Into Ransomware's Favorite Region Ransomware attacks in Europe have dramatically increased, representing a significant shift from previous trends. Black Kite researchers report a 55% rise in ransomware attacks across the continent through the first four… Dark Reading · Jun 25, 2026 High UKGEFRransomwaresupply-chainai
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
threat-intel ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More This Hacker News bulletin details several recent cyber threats, including a massive C2 infrastructure footprint discovered in the Middle East dominated by IoT botnets, a privilege escalation vulnerability in Azure Backup… The Hacker News · May 28, 2026 High CVE-2026-8398SAROUSc2supply-chainprivilege-escalation
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups A global operation, dubbed Operation Saffron, led by France and the Netherlands, successfully dismantled the First VPN service, a virtual private network specifically designed for criminal use. The service was utilized b… The Hacker News · May 22, 2026 High USFRNLvpnransomwareanonymity