threat-intel Ukrainian software developer faces 12 years in Swiss ransomware trial A Ukrainian software developer is facing a 12-year prison sentence in Switzerland for his alleged involvement in a ransomware operation targeting companies including Stadler Rail and Crealogix, resulting in over 130 mill… The Record · Aug 17, 2026 High SWRUUKransomwarecybercrimeinvestigation
threat-intel Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes Ukraine’s military intelligence, in collaboration with hacker groups, reportedly launched a cyberattack against Russia’s largest e-commerce platform, Wildberries, coinciding with drone strikes targeting the company’s inf… The Record · Aug 17, 2026 High UARUcyberwardroneecommerce
threat-intel Crook hawks millions of records allegedly plundered from corporate Azure tenants A group of Russian threat actors are exploiting vulnerabilities in Microsoft's on-prem SharePoint to steal corporate data. The attackers are impersonating Signal support to carry out phishing attacks, leveraging a zero-d… The Register · Aug 17, 2026 High RUzero-dayphishingdata breach
threat-intel Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do This article covers a range of cybersecurity and technology news, including a warning about autonomous AI attacks posing a significant risk to critical infrastructure, a report on Russian phishing campaigns mimicking Sig… The Register · Aug 16, 2026 Medium IRRUcyberattackphishingransomware
threat-intel Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware Threat actors are spending heavily – nearly $7 million – on expired domains to build a criminal enterprise focused on illegal sports streaming, online gambling promotion, and malware infrastructure. These ‘dropcatch’ dom… The Hacker News · Aug 14, 2026 High VIRUAUdropcatchexpired domainsmalware
threat-intel Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth The HoneyMyte threat actor (aka Mustang Panda) has updated its CoolClient backdoor with a new, signed Windows kernel-mode rootkit, significantly enhancing its stealth capabilities. This rootkit, implemented through a dri… The Hacker News · Aug 14, 2026 High MYMOPArootkitkernel-modestealth
threat-intel Who’s Tracking You? Use This New Service to Find Out DecryptAds is a new service designed to expose the complex ecosystem of adtech companies tracking users online. By scraping data from files like ads.txt, app-ads.txt, and sellers.json, it reveals a network of data broker… Krebs on Security · Aug 14, 2026 High CHRUUAadtechdata-brokermalvertising
threat-intel China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud The China-linked threat actor Jewelbug, operating as a ‘hack-for-hire’ group, is engaged in both sophisticated government espionage targeting nations across the Middle East, Southeast Asia, and South Asia, and cryptocurr… The Hacker News · Aug 14, 2026 High CHMISOespionagecryptocurrencyhack-for-hire
threat-intel Germany moves to give spy agencies hacking and sabotage powers Germany is poised to significantly expand the powers of its intelligence agencies, allowing them to conduct cyber operations, sabotage supply chains, and spread disinformation within the country. This legislation, a majo… The Record · Aug 13, 2026 High GERUcybersecurityintelligencesurveillance
threat-intel Armored Likho expands its cyber-espionage toolkit The Armored Likho group (also known as Eagle Werewolf) has significantly expanded its cyber-espionage toolkit with the introduction of the ‘Still Toolkit,’ a new set of tools designed for advanced surveillance and data t… Securelist · Aug 13, 2026 High RUcyber espionagetelegramaudio surveillance
threat-intel 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One A massive collection of 737 Chrome VPN and proxy extensions are being used to route user traffic through a single SOCKS5 proxy infrastructure, primarily targeting Russian-speaking users seeking access to blocked content.… The Hacker News · Aug 12, 2026 High RUvpnproxychrome
threat-intel WhatsApp Unveils New Scam Alert Feature WhatsApp is rolling out a limited beta feature called Scam Alert, designed to identify potentially scam messages on users' devices *before* they are sent. The feature uses on-device machine learning, doesn't send message… SecurityWeek · Aug 12, 2026 Medium GERUmachine learningencryptionprivacy
threat-intel Akira ransomware scum blocked victim's security tools – and broke their own encryptor Russian threat actors are impersonating Signal support to conduct phishing attacks, targeting users to steal their information. This follows a trend of Iranian propaganda sites being taken down by the US, and a marketing… The Register · Aug 12, 2026 Medium IRRUphishingthreat intelligencesocial engineering
threat-intel Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands Russian state-sponsored threat actors, linked to the Sandworm group, are using fake recruitment campaigns to trick IT professionals in Ukraine into installing malware. They impersonate IT companies like Sopra Steria Bulg… The Hacker News · Aug 11, 2026 High RUUKsocial engineeringvpnrecruitment
ransomware DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt The DeadLock ransomware group is utilizing a sophisticated, blockchain-backed infrastructure to enhance operational resilience and evade takedown efforts. They leverage decentralized proxy servers managed via Polygon sma… The Hacker News · Aug 11, 2026 High ITSPPOransomwareblockchainsmart contracts
threat-intel Deepfake hiccup unmasks suspected digital certificate fraudster This article discusses a potential digital certificate fraud scheme linked to deepfake technology, where Russian actors are impersonating Signal support to launch phishing attacks. The vulnerability stems from flaws in J… The Register · Aug 11, 2026 Medium RUdeepfakephishingjoomla
threat-intel Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G This article discusses a security vulnerability where malicious actors are exploiting SIM cards to disable phones, steal data, and potentially downgrade connections to 2G, enabling more sophisticated phishing attacks. Th… The Register · Aug 11, 2026 High CVE-2025-48618CHRUsim cardphishingtelecom security
threat-intel Poland uncovers second heat plant cyberattack that went hidden for months Poland’s CERT Polska uncovered a cyberattack targeting a combined heat and power plant that went undetected for months, highlighting a previously unknown attack vector involving private cellular networks. The attack, occ… The Record · Aug 10, 2026 High PORUcyberattackindustrial control systemsprivate cellular network
threat-intel Russian military hackers pose as recruiters to target Ukrainian IT workers Russian military hackers, linked to the Sandworm group (APT44/Seashell Blizzard), are impersonating IT recruiters to target Ukrainian IT workers and install malicious software. The operation involves using legitimate job… The Record · Aug 10, 2026 High UKRUrecruitmentvpnwireguard
threat-intel New Zealand sanctions Russian hackers, propaganda groups over Ukraine war New Zealand has expanded its sanctions against Russia, targeting 33 individuals and entities involved in cyber activities supporting Russia's war in Ukraine. These include hackers, propaganda groups, and technology compa… The Record · Aug 10, 2026 High RUUKCAcyberattacksrussiasanctions