threat-intel Major US surveillance program poised to lapse after legislative deadlock This article reports on a looming lapse in the US surveillance program, Section 702 of the FISA, due to legislative deadlock in Congress. The program, which allows intelligence agencies to collect communications of forei… The Record · Jun 12, 2026 High USIRCHfisasurveillanceintelligence
ransomware Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs Europol, in collaboration with international law enforcement, successfully disrupted AudiA6, a cryptocurrency laundering service used extensively by ransomware gangs and cybercriminals. The operation, resulting in the ar… The Hacker News · Jun 12, 2026 High UKRUGEcryptocurrencyransomwaremoney laundering
ransomware The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm The Gentlemen ransomware group, initially operating as the affiliate-focused Phantom Mantis, has evolved into an independent RaaS operation led by the cybercriminal LARVA-368 (aka hastalamuerte). The group, responsible… The Hacker News · Jun 11, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073RUTHUKransomware-as-a-servicedouble extortionaffiliate program
ransomware Authorities dismantle 'AudiA6' ransomware crypto-laundering service Law enforcement agencies have successfully dismantled the ‘AudiA6’ cryptocurrency service, which was used to launder over $380 million generated from ransomware attacks and other cybercriminal activities. The operation,… BleepingComputer · Jun 11, 2026 High POUKGEcryptocurrencyransomwaremoney laundering
threat-intel Who Runs the Ransomware Group ‘The Gentlemen?’ The Gentlemen, a prolific ransomware group, is being led by a Russian individual known as Zeta88/Hastalamuerte. Extensive investigation by Check Point and Intel 471 has revealed that this administrator, whose real identi… Krebs on Security · Jun 10, 2026 High RUransomwarerandsomware-as-a-servicerussian cybercrime
threat-intel Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs Russian threat actors, including Shadow-Earth-066 (UAC-0226) and Earth Dahu (Primitive Bear, Shuckworm), are continuing to exploit a long-standing vulnerability (CVE-2025-8088) in WinRAR to conduct data theft and cyber e… Dark Reading · Jun 9, 2026 High CVE-2025-8088CVE-2023-38831RUUAwinrarvulnerabilitycyberespionage
threat-intel Hackers pose as women seeking romance to spy on Russian soldiers A previously unknown cyber espionage group, SiribClone, has been targeting Russian military personnel by impersonating women seeking romantic relationships. The group’s primary goal is to gather battlefield intelligence… The Record · Jun 9, 2026 High RUespionagesocial-engineeringmobile-malware
threat-intel WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine A vulnerability in WinRAR, first identified in July 2025, is being exploited by Russia-aligned cyber groups to deploy malware targeting Ukrainian organizations. The attackers, including Earth Dahu and SHADOW-EARTH-066, a… The Hacker News · Jun 9, 2026 High CVE-2025-8088RUUAwinrarexploitukraine
supply-chain Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer A new supply chain attack, dubbed Hades, is leveraging the Miasma campaign to compromise 37 PyPI packages, including those used in bioinformatics and computational biology. The attack utilizes a malicious setup.pth file… The Hacker News · Jun 9, 2026 High RUsupply-chainpythoncredential-stealing
threat-intel Armenia’s pro-Europe party wins election despite Russia-linked disinformation Armenia’s parliamentary election saw the pro-Europe Civil Contract party secure a significant victory, despite a large-scale disinformation campaign orchestrated by Russia-linked actors. This campaign utilized tactics su… The Record · Jun 8, 2026 Medium RUAMUSdisinformationinfluence_operationcyberattack
threat-intel Russia upgrades rules for its digital spy system to better track citizens online Russia has updated its SORM (System for Operative Investigative Activities) digital surveillance system to enhance its capabilities for tracking citizens online. The updated regulations expand the data accessible through… The Record · Jun 8, 2026 High RUsurveillancedigital privacyinternet monitoring
threat-intel From cause to cash: a cross-border look at hacktivist activity This Securelist article details a cross-border hacktivist campaign led by groups including 4BID, with a broadened geographic scope impacting organizations in Kazakhstan, the UAE, Syria, and Egypt. The campaign utilized t… Securelist · Jun 8, 2026 High CVE-2023-44976KZAESYproxyshellransomwarehacktivism
threat-intel Apple removes Russia’s state-backed messaging app Max from its store Apple removed the state-backed Russian messaging app Max from its App Store, citing sanctions regulations. This action has drawn criticism from Russian officials who view it as an unfriendly move and has impacted the app… The Record · Jun 4, 2026 Medium RUsanctionsrussiamessaging
threat-intel Reporting from Vegas: Networking, AI, and good boys This Cisco Talos Threat Source newsletter highlights the ongoing challenges of managing data at scale in an AI-driven world, particularly during large technology conferences like Cisco Live. It details Talos’ expansion o… Cisco Talos · Jun 4, 2026 High USRUaithreat huntingc2
threat-intel ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories This bulletin highlights several ongoing cyber threats, including a high-severity SSRF vulnerability in Cisco Unified Communications Manager, a large-scale spyware operation targeting Russian officials by foreign intelli… The Hacker News · Jun 4, 2026 High CVE-2026-20230CVE-2022-0492CVE-2019-5736RUIRUSssrfspywarekeylogger
malware Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS A sophisticated operation is impersonating popular open-source and freeware tools like Ghidra and dnSpy to lure users to malicious websites via a Traffic Distribution System (TDS). This TDS then delivers malware, includi… The Hacker News · Jun 4, 2026 High TRPLBRtdsmalware-as-a-serviceclick interception
threat-intel New cyber force would cost up to $11 billion to start, commission says This article reports on a commission’s recommendation for the U.S. to establish a dedicated cyber warfare force, estimated to cost up to $11 billion and staffed by approximately 30,000 personnel. The proposal stems from… The Record · Jun 3, 2026 High UNRUCHcybersecuritymilitarydefense
threat-intel FBI-Flagged Phishing Kit Kali365 Expands Its Reach The Kali365 phishing-as-a-service platform, initially focused on compromising Microsoft 365 accounts via MFA bypass, has significantly expanded its capabilities and target list. It now actively targets platforms like AWS… Dark Reading · Jun 2, 2026 High USRUphishingdevice-codemfa
ransomware AI-built ransomware toolkit automates EDR evasion, AD discovery A threat actor is utilizing an AI-powered ransomware toolkit to automate Active Directory discovery and evade Endpoint Detection and Response (EDR) solutions. The toolkit, developed with assistance from AI agents like Cu… BleepingComputer · Jun 2, 2026 High RUaiedr evasionactive directory
threat-intel Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine The Gamaredon group is exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy a multi-stage malware campaign targeting Ukraine. This campaign utilizes GammaWorm and GammaSteel, designed for data theft and persistenc… The Hacker News · Jun 2, 2026 High CVE-2025-8088CVE-2026-21509RUUAwinrarmalwarevulnerability