threat-intel ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API The ToddyCat APT group is utilizing a new malware, Umbrij, to gain unauthorized access to Gmail accounts via the Google API. Umbrij leverages the OAuth 2.0 protocol to obtain access tokens, allowing attackers to control… The Hacker News · Jul 2, 2026 High RUoauthgoogle apiheadless browser
threat-intel Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects This Kaspersky report, based on 2025 compromise assessment engagements, highlights significant missed incidents due to inadequate monitoring, delayed detection, and communication gaps. The analysis reveals a concerning t… Securelist · Jul 2, 2026 High SACNRUmissed incidentsthreat detectionincident response
malware Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery This report details a concerning trend in malware delivery – the evolution of ClickFix, a technique where users are tricked into running malicious code by hand. Researchers have uncovered a new API-driven approach to gen… The Hacker News · Jul 1, 2026 High RUIRNOmalwarepayloadapi
threat-intel What the Numbers Say About FIFA 2026 Cyber Risk This report from Check Point Research reveals a significant pre-emptive cyber threat landscape surrounding the FIFA World Cup 2026, with attackers already establishing infrastructure months in advance. The primary target… The Hacker News · Jun 30, 2026 High RUemailspoofingfraud
threat-intel Iran, Russia, China Target Water Systems for Sabotage A DomainTools report details ongoing nation-state targeting of water systems by Iran, Russia, and China, primarily through exploiting weak passwords, exposed PLCs, and HMI vulnerabilities. The motivations behind these at… Dark Reading · Jun 29, 2026 High IRRUCHcritical infrastructurenation-statewater systems
threat-intel US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp The United States government is offering a $10 million reward for information leading to the identification of Russian cyber groups involved in targeting Signal and WhatsApp accounts. These groups, UNC5792 and UNC4221, a… The Record · Jun 29, 2026 High USUKRUsocial engineeringencryptionespionage
threat-intel ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More This week’s security news highlights several concerning vulnerabilities and attacks, including a DirtyClone Linux kernel flaw, exploitation of PTC Windchill vulnerabilities, and the emergence of new malware like Gaslight… The Hacker News · Jun 29, 2026 High CVE-2026-43503CVE-2026-12569CVE-2026-47729UKRUlinuxkernelai
threat-intel Ukraine to use seized crypto from cybercrime group to buy war bonds Ukraine is utilizing cryptocurrency seized from a notorious international cybercrime group to bolster its war effort. Over $8.3 million in digital assets, obtained from investigations targeting attacks across Europe and… The Record · Jun 29, 2026 High UKRUUScybercrimecryptocurrencywar bonds
threat-intel Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse The Gamaredon APT group continued its aggressive cyberattacks against Ukraine throughout 2025, utilizing a range of new malware and exploiting vulnerabilities to steal sensitive information. The group expanded its tactic… The Hacker News · Jun 29, 2026 High CVE-2025-8088RUUAspear-phishingpersistencecloud-services
threat-intel FBI: Russian hackers now target Signal backup recovery keys The FBI and CISA are warning about a phishing campaign orchestrated by Russian Intelligence Services (RIS) targeting Signal users. Attackers are now specifically seeking Signal Backup Recovery Keys to gain access to vict… BleepingComputer · Jun 26, 2026 High USRUUKphishingsignalrecovery key
threat-intel FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys The FBI and CISA have issued an updated advisory warning about Russian intelligence actors targeting Signal users, expanding their tactics to include obtaining Signal Backup Recovery Keys. This allows attackers to fully… The Hacker News · Jun 26, 2026 High USRUNEsignalphishingrecovery key
threat-intel In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs This week’s cybersecurity news includes a Russian government operation utilizing Cellebrite software to target an opposition activist, a Scattered Spider group breach of Transport for London, and a significant data leak… SecurityWeek · Jun 26, 2026 High RUUKINaicyberespionagesupply chain
threat-intel Russia accuses Apple of ‘political censorship’ after VK apps removed from App Store Following the removal of VK apps from the Apple App Store, Russia has accused Apple of political censorship and a lack of trust, citing sanctions compliance. The move has sparked a diplomatic backlash from Russian offici… The Record · Jun 26, 2026 Medium RUsanctionscensorshiprussia
apt Turla group adds more malware to Russia’s espionage efforts against Ukraine The Turla group, a long-standing Russian cyber-espionage team, has expanded its operations against Ukraine by deploying a new malware strain called StockStay. This malware, developed since December 2022, targets Ukrainia… The Record · Jun 26, 2026 High UKITNEcyberespionagerussiaukraine
threat-intel FCC votes to toughen rules in bid to better protect undersea cables The FCC has voted to implement stricter regulations for undersea cables, aiming to bolster national security and protect internet traffic. This includes mandating licensing for submarine line terminal equipment (SLTE) an… The Record · Jun 26, 2026 High CHUKUSundersea cablescybersecuritynational security
phishing Russian Intelligence Services Continue to Target Commercial Messaging Applications The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have issued a new PSA highlighting ongoing cyberattacks by Russian Intelligence Services (RIS) targeting commercial messaging applications. These at… CISA Advisories · Jun 26, 2026 Medium RUphishingcredential theftrussian intelligence
supply-chain Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack A sophisticated supply chain attack, spearheaded by the Miasma malware family (linked to Mini Shai-Hulud and Hades), is targeting npm packages and GitHub Actions workflows. The attackers are leveraging compromised npm pa… The Hacker News · Jun 26, 2026 High RUsupply chainnpmgithub actions
threat-intel Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets Russia-linked APT Turla has been deploying a new .NET backdoor, dubbed StockStay, to conduct ongoing cyber espionage against Ukrainian government and military organizations, as well as entities with interests in Italian… SecurityWeek · Jun 26, 2026 High CVE-2025-8088UKRUITespionagebackdoorphishing
threat-intel Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff This report details how Russian authorities utilized Cellebrite's UFED forensic tools to access Andrey Pivovarov's iPhone 12 in June 2021, despite Cellebrite's subsequent announcement of a sales cutoff to Russia and Bela… The Hacker News · Jun 26, 2026 High RUGBJOforensiciphonecustody
threat-intel Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks Google Threat Intelligence Group (GTIG) has identified a new backdoor, STOCKSTAY, developed and deployed by the Russian state-sponsored threat actor Turla. This multi-component backdoor, built using .NET and leveraging a… The Hacker News · Jun 26, 2026 High CVE-2025-8088UKITNEespionagebackdoorrussia