threat-intel Swiss train maker Stadler refuses Everest $12 million ransomware demand Swiss train manufacturer Stadler Rail refused a $12.3 million ransomware demand from the Russian-speaking group Everest after cybercriminals stole technical data from a supplier’s file-sharing platform. The incident did… The Record · Jul 22, 2026 High SWRUransomwaredata breachsupply chain
threat-intel Council worker spared prison after four-day data-snooping spree This article is a collection of security and technology news snippets. A House worker was spared prison after a data snooping spree, while Microsoft’s SharePoint remains vulnerable to zero-day attacks. Additionally, a Ru… The Register · Jul 22, 2026 Medium RUSWphishingvulnerabilitycybersecurity
threat-intel Hacker Turns AI Jailbreaks Into Offensive Attack Platform A Russian-speaking cybercriminal, known as ‘Trim,’ successfully weaponized publicly available AI language models to create a commercial offensive cybertooling platform. By developing and publishing jailbreaking technique… Dark Reading · Jul 21, 2026 High RUaijailbreakoffensive-security
threat-intel Kratos phishing-as-a-service kit loses its battle with international law enforcement International law enforcement agencies have taken down a phishing-as-a-service kit operated by Russian threat actors, who were using it to launch attacks mimicking Signal support. The kit exploited vulnerabilities in Joo… The Register · Jul 21, 2026 Medium RUphishingjoomlaopen source
threat-intel Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine's CERT-UA has warned that Russian hackers, specifically a branch of the Sandworm group, are using fake CAPTCHA challenges to trick users into executing PowerShell commands on their own computers, installing recon… Graham Cluley · Jul 21, 2026 High RUclickfixpowershellcaptcha
threat-intel Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs A Russian-speaking threat actor, “bandcampro,” leveraged Google Gemini CLI to orchestrate a botnet and conduct various cybercrime activities, including dental clinic control and cryptocurrency fraud. The actor utilized t… The Hacker News · Jul 20, 2026 High USCARUaicybercrimebotnet
threat-intel UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Russian state-sponsored actors, linked to the Sandworm group and GRU, are using a ClickFix social engineering tactic to deliver malware to Ukrainian devices. They are leveraging fake CAPTCHA checks on compromised website… The Hacker News · Jul 19, 2026 High RUsocial engineeringclickfixrussia
threat-intel Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man A Russian tourist, Aleksandr Yuryevich Ermakov, is being held in Armenia on a U.S. extradition warrant, despite his lawyers arguing he is the wrong man. The U.S. seeks Aleksandr Gennadievich Ermakov, a Russian national p… The Hacker News · Jul 17, 2026 High AUUSRUransomwareextraditionidentity-error
threat-intel Begun, the Patch Wars have Cisco Talos has identified a sophisticated, financially motivated Russian-speaking adversary, UAT-11795, actively targeting users in the U.S. and Europe since June 2025. This campaign utilizes trojanized software install… Cisco Talos · Jul 16, 2026 High UNRUEUsupply-chainaptzero-day
threat-intel ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories This week’s security news is a mixed bag, encompassing a range of threats from sophisticated ransomware attacks to deceptive software distribution and widespread surveillance techniques. A new ransomware family, Spirals,… The Hacker News · Jul 16, 2026 High CVE-2026-46817CVE-2023-4346CVE-2026-35273NESPPOransomwareinfostealerbrandjacking
threat-intel Sandworm hackers have a CAPTCHA trick for Ukrainians Sandworm, a hacking group linked to Russia's military intelligence, is using a sophisticated CAPTCHA trick to trick Ukrainian targets into installing malware on their computers. The group employs a 'ClickFix' technique,… The Record · Jul 16, 2026 High RUsocial engineeringmalware distributionransomware
threat-intel Guten Tag, Bonjour, Hola to Our European Cyber Defenders! Dark Reading is launching a new section, DR Global Europe, to provide region-specific cybersecurity intelligence tailored for professionals in the EU and UK. This expansion addresses unique cyber threats facing Europe, i… Dark Reading · Jul 15, 2026 High RUUKSPcybersecurityddosransomware
threat-intel OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps OkoBot, a malware framework, has been actively targeting hardware wallet users since April 2025, primarily through phishing attacks leveraging a module called SeedHunter. SeedHunter intercepts the wallet's desktop softwa… The Hacker News · Jul 15, 2026 High BRVNCAphishingmalwarehardware wallet
threat-intel US unseals indictment against alleged operators of Russian bulletproof hosting service The U.S. government has unsealed an indictment against three Russians linked to a Russian-based bulletproof hosting service, Media Land and ML Cloud, which provided infrastructure and tech support to cybercriminal groups… The Record · Jul 14, 2026 High USRUNLbulletproof hostingcybercrimeransomware
threat-intel NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says Russian state-backed hackers are systematically compromising internet-connected security cameras across Europe and Ukraine to gather intelligence on NATO military logistics and identify Ukrainian troops for targeting. Th… The Record · Jul 14, 2026 High NEUKCHcyber espionagerussian hackingmilitary intelligence
threat-intel U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support The U.S. Treasury Department has sanctioned a VPN service provider, First VPN Service (1VPNS), and its administrator, Dmytro Rashevskyi, for enabling ransomware groups to carry out attacks against U.S. companies and inst… The Hacker News · Jul 14, 2026 High CVE-2018-0171CVE-2008-4128RUUKUNvpnransomwarecyber espionage
threat-intel Weak Security Continues to Fuel Russian Cyberattacks The UK and EU have jointly sanctioned Russian individuals and entities involved in cyberattacks and disinformation campaigns, coinciding with a US cybersecurity advisory highlighting ongoing Russian state-sponsored attac… Dark Reading · Jul 13, 2026 High UKEUUNrouter securityciscosnmp
threat-intel Russian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breach Russian journalist Ksenia Sobchak's Telegram channels were briefly taken over by hackers who published alleged private correspondence. The hackers, operating under the group Black Mirror, claimed to have stolen over 350G… The Record · Jul 13, 2026 Medium RUUKtelegramdata breachrussian
threat-intel GigaWiper Lets Threat Actors Choose Their Own Destructive Attack GigaWiper is a novel, modular malware that combines backdoor and wiper capabilities, allowing attackers to choose how to destroy a targeted system while minimizing their operational footprint. Initially identified as a G… Dark Reading · Jul 13, 2026 High IRRUVEwiperbackdoormodular
threat-intel Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft Forg365, a new PhaaS operation, is targeting Microsoft 365 accounts using a sophisticated combination of device code phishing, AitM tactics, and AI-assisted lure creation. The platform allows even inexperienced operators… The Hacker News · Jul 13, 2026 High UNRUphishingaitmdevice code