threat-intel DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts The DevMan ransomware-as-a-service (RaaS) operation has significantly upgraded its affiliate portal, transitioning from a chat-based system to a centralized platform for managing victims, payouts, and team operations. PRODAFT cybersecurity researchers have identified five distinct roles within the DevMan structure, hig… The Hacker News · Jul 25, 2026 High USCISEransomwareraasdevman
threat-intel Europe's Multilingual Reality Exposes AI Security Gaps Europe faces a unique security challenge due to its multilingual landscape and the resulting inconsistencies in AI safety and security across numerous languages. While many AI models can process text in dozens of languag… Dark Reading · Jul 24, 2026 High EUGESPaisecuritymultilingual
threat-intel ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing ClickLock Stealer, a new macOS malware, bypasses macOS security through social engineering and aggressive process killing to steal sensitive data, including browser data, cryptocurrency wallets, and password manager info… SecurityWeek · Jul 16, 2026 High DEFRITmacossocial engineeringprocess killing
ransomware No Manners Here: The Ruthless Rise of The Gentlemen Ransomware The Gentlemen, a rapidly growing Ransomware-as-a-Service (RaaS) program, has significantly increased its victim count in 2026, becoming the second most active RaaS program globally. Leveraging a 90% affiliate payout stru… Palo Alto Unit 42 · Jul 10, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073USCAGBransomware-as-a-serviceracksedge-device-attack
threat-intel Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup This Smashing Security podcast episode discusses a potential security risk at FIFA where a hacker could have used a ‘rickroll’ tactic to disrupt the World Cup. The conversation highlights a Black Kite report detailing a… Graham Cluley · Jun 24, 2026 High UKNLSEransomwaresupply chainrickroll
threat-intel AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network A new malware family, dubbed AryStinger, is exploiting vulnerabilities in older Realtek RTL819X routers to create a reconnaissance network. Approximately 4,300 routers, primarily D-Link models, have been infected, scanni… The Hacker News · Jun 22, 2026 Medium CVE-2013-3307CVE-2016-5681CVE-2025-11837KRCNSEreconnaissanceproxyiot
malware AryStinger botnet infected thousands of D-Link routers worldwide A new botnet, named AryStinger, has been discovered compromising over 4,000 outdated D-Link routers worldwide, turning them into proxies for malicious traffic. The malware utilizes multiple vulnerabilities to perform sca… BleepingComputer · Jun 21, 2026 High CVE-2013-3307CVE-2016-5681CVE-2025-11837KRCNSErouterbotnetdns
threat-intel Bulgaria allowed surveillance tech firm to sell products to repressive regimes, report says A report by Human Rights Watch revealed that Bulgaria allowed a surveillance technology firm, Circles, to sell its products – including Pixcell, Landmark, and Voice Over Location Enabler software – to repressive regimes… The Record · Jun 18, 2026 High BUELUAsurveillancespywareexport control
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
malware Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content A new malware campaign, dubbed Weedhack, is targeting Minecraft players through YouTube and malicious websites, distributing a MaaS (Malware-as-a-Service) tool. The campaign, active since January 2026, utilizes SEO poiso… The Hacker News · Jun 3, 2026 High USDEINminecraftmalwareyoutube
threat-intel Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say As a result of sanctions and the ongoing war in Ukraine, Russian intelligence agencies are intensifying their efforts to steal Western technology and defense secrets. This includes targeting advanced machine tools, resea… SecurityWeek · May 30, 2026 High RUSEFIsanctionsespionagecyberattack
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups A global operation, dubbed Operation Saffron, led by France and the Netherlands, successfully dismantled the First VPN service, a virtual private network specifically designed for criminal use. The service was utilized b… The Hacker News · May 22, 2026 High USFRNLvpnransomwareanonymity
threat-intel China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts. A China-aligned Advanced Persistent Threat (APT) group known as Webworm has shifted its focus from Asia to targeting European governmental organizations, specifically in Belgium, Italy, Serbia, Spain, Poland, and South A… Dark Reading · May 22, 2026 High CHBEITaptdiscordmicrosoft graph
threat-intel Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API A China-aligned threat actor known as Webworm has expanded its arsenal with two new backdoors, EchoCreep and GraphWorm, utilizing Discord and the Microsoft Graph API for command-and-control communications. The group, act… The Hacker News · May 20, 2026 High CHRUGEdiscordmicrosoft graphrat
threat-intel Webworm: New burrowing techniques This blog post details the evolving tactics of Webworm, a China-aligned APT group, particularly their activity in 2025. Webworm has shifted away from traditional backdoors in favor of more sophisticated techniques, inclu… WeLiveSecurity · May 20, 2026 High CVE-2017-7692BEITSEdiscordmicrosoft graph apic&c