phishing Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware The Ghostwriter threat actor, linked to Belarus, has been conducting a phishing campaign targeting Ukrainian government entities since the spring of 2026. This campaign utilizes lures related to the Prometheus online lea… The Hacker News · May 22, 2026 High UKBERUphishingmalwarecobalt strike
malware Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor A new Linux malware, dubbed Showboat, has been used in a campaign targeting a telecommunications provider in the Middle East since at least 2022. The malware, developed by a China-linked threat actor group known as Calyp… The Hacker News · May 21, 2026 High CVE-2021-26855AFAZCHlinuxsocks5c2
threat-intel Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API A China-aligned threat actor known as Webworm has expanded its arsenal with two new backdoors, EchoCreep and GraphWorm, utilizing Discord and the Microsoft Graph API for command-and-control communications. The group, act… The Hacker News · May 20, 2026 High CHRUGEdiscordmicrosoft graphrat
supply-chain Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer A compromised version of the Nx Console VS Code extension (version 18.95.0) was used to steal developer credentials through a supply chain attack. The extension, initially introduced by a developer whose machine was comp… The Hacker News · May 19, 2026 High RUUSsupply chaincredential theftvscode
threat-intel Inside Department 4: Russia’s secret school for hackers A new investigation has revealed a secret faculty within Bauman Moscow State Technical University, known as ‘Department 4,’ which has been training students to become hackers for Russian military intelligence, the GRU. T… Graham Cluley · May 8, 2026 High RUUSrussian hackingspywaregru
threat-intel Websites with an undefined trust level: avoiding the trap This Securelist article discusses the growing threat of websites with an "undefined trust level," which are not traditional phishing sites but still pose significant risks to users. These sites, often mimicking legitimat… Securelist · May 6, 2026 Medium AFLARUscamfraudonline scams
threat-intel NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later This Dark Reading Confidential episode features a retrospective discussion with Chris Inglis, former NSA Deputy Director during the Edward Snowden affair, 13 years after the events. The conversation focuses on the misund… Dark Reading · Apr 28, 2026 Low USRUnsasnowdenmetadata
malware 108 malicious Chrome extensions caught stealing Google and Telegram data from 20,000 users A coordinated campaign involving 108 malicious Chrome extensions has been discovered, stealing data from approximately 20,000 users. The extensions, disguised as legitimate add-ons for popular apps like Telegram and YouT… Graham Cluley · Apr 15, 2026 High RUbrowser extensionsdata theftcredentials
threat-intel Russia Hacked Routers to Steal Microsoft Office Tokens Russian military intelligence, operating under the ‘Forest Blizzard’ (APT28/Fancy Bear) moniker, has been conducting a sophisticated cyber espionage campaign targeting over 18,000 routers globally. The attackers exploite… Krebs on Security · Apr 7, 2026 High USUKRUdns hijackingauthentication tokensmicrosoft office
ransomware Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab German authorities have identified ‘UNKN,’ the elusive figure behind the notorious GandCrab and REvil ransomware gangs, as 31-year-old Russian national Daniil Maksimovich Shchukin. Shchukin, alongside Anatoly Sergeevitsc… Krebs on Security · Apr 6, 2026 Critical DERUransomwareextortioncybercrime