threat-intel CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six previously exploited vulnerabilities to its KEV catalog, including flaws in Citrix NetScaler, Linux, and Microsoft SQL Server. These vulnerabilities are actively being exploited, with telemetry showing attacks originating from various countr… The Hacker News · 3d ago High CVE-2019-1068CVE-2026-8452CVE-2022-0995SWGEHOkevexploitationvulnerability
threat-intel DYSPHOR1A, nouveau groupe de ransomware maître chanteur A new ransomware group, DYSPHOR1A, operating in conjunction with Normal Hunters, is leveraging a data extortion model – leaking and selling stolen data to pressure victims into paying to have the information removed. The… ZATAZ · Aug 21, 2026 High MYTHINdata-breachransomwareextortion
threat-intel Ghost Tap : une fraude NFC signalée depuis Pattaya This article details a case in Pattaya, Thailand, where a reader of ZATAZ discovered a NFC-based banking fraud. The incident highlights a technique called ‘Ghost Tap,’ where a compromised device relays NFC communications… ZATAZ · Aug 13, 2026 Medium THnfcfraudrelay
ransomware Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks The Gunra ransomware group, linked to state-sponsored actors, is aggressively targeting critical infrastructure and organizations globally, leveraging vulnerabilities in Fortinet and Schneider Electric appliances to gain… The Hacker News · Aug 11, 2026 High CVE-2024-5559CVE-2025-24472SOBRSPransomwarevulnerabilitysupply-chain
Des cibles françaises au cœur d’une plateforme cybercriminelle A ZATAZ investigation has uncovered a list of French organizations targeted by a cybercriminal group, Krybit, who are aggressively recruiting affiliates through a platform offering a lucrative 80% revenue split. The grou… ZATAZ · Aug 7, 2026 FRMXUSransomwarerecruitmentcybercrime
threat-intel India’s Bank of Baroda confirms cyber incident after hackers claim data theft India’s Bank of Baroda has confirmed a cybersecurity incident where an employee’s email account was compromised, leading to claims of stolen banking data and internal records being leaked on the dark web. The incident fo… The Record · Jul 28, 2026 Medium INTHcyberattackdata breachdark web
threat-intel Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry A Thai Ministry of Finance employee installed the Hermes AI assistant, a tool designed for mail management and task automation, on a rented server. The agent, left running unattended, autonomously scanned the ministry's… The Hacker News · Jul 24, 2026 High CVE-2026-31431CVE-2026-43284CVE-2026-43500THHOaiunattendeddefault
threat-intel GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration A sophisticated, evolving threat actor, potentially linked to TetrisPhantom, has been targeting government and diplomatic entities in Southeast Asia since late 2025 with a campaign utilizing tools like GoSerpent, Stowawa… Securelist · Jul 16, 2026 High VNTHproxyremote accessdata exfiltration
threat-intel Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor A long-dormant Chinese-linked malware, Daxin, resurfaced in Taiwan after over a decade, alongside a new backdoor called Stupig. Daxin, a kernel-mode rootkit, has been used in targeted attacks since 2013, and its ability… The Hacker News · Jul 16, 2026 High CHAFTHcyber espionagekernel-modecommand and control
threat-intel China-Linked Group Targets Southeast Asia Critical Systems A China-linked cyber threat group, CL-STA-1062 (formerly UAT-7237), has been targeting critical infrastructure providers in Southeast Asia over the past year, deploying a new backdoor tool called TinyRCT. The group has s… Dark Reading · Jul 1, 2026 High CNMYTHchinaaptbackdoor
threat-intel Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries Google is implementing a new Android developer verification system, starting September 30, 2026, in Brazil, Indonesia, Singapore, and Thailand, to combat app scams and malware. This will block installations of apps from… The Hacker News · Jun 22, 2026 Medium BRIDSGapp scamsdeveloper verificationopen source
threat-intel CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices CISA has issued a warning to Fortinet customers regarding FortiBleed, a campaign targeting 86,644 FortiGate devices globally. The attack, attributed to Russian-speaking threat actors, leverages a two-step approach involv… The Hacker News · Jun 19, 2026 High USINMEcredential_stuffingdefault_credentialspassword_reuse
threat-intel CISA warns Fortinet users to secure devices after FortiBleed leak CISA has issued a warning to Fortinet customers regarding the "FortiBleed" data leak, which exposed nearly 74,000 firewall and VPN credentials. Threat actors are exploiting these compromised credentials to target interne… BleepingComputer · Jun 19, 2026 High USRUCNcredentialsvpnfirewall
threat-intel ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories This week’s ThreatDay Bulletin highlights several concerning security incidents, including browser extension abuse, macOS malware attacks, AI-powered malware delivery, and a global phishing campaign targeting travel book… The Hacker News · Jun 18, 2026 High CVE-2026-20127CVE-2026-49975USCNJPbrowser extensionsmacos malwareai abuse
ransomware Killing me gently: Inside Gentlemen’s EDR killer framework The Gentlemen ransomware-as-a-service (RaaS) gang has emerged as a significant and technically agile threat, distinguished by its proactive development and maintenance of a comprehensive suite of Endpoint Detection and R… WeLiveSecurity · Jun 18, 2026 High THBRFRransomwareedrrd
data-breach FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. A significant data leak, dubbed "FortiBleed," has exposed approximately 73,932 Fortinet VPN credentials for firewall URLs across numerous organizations worldwide. The leak, discovered by Bob Diachenko, reveals a multi-op… BleepingComputer · Jun 17, 2026 High USGBJPvpncredentialsbreach
threat-intel SprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detection A new Windows variant of the SprySOCKS Linux backdoor, developed by the nation-state threat actor FishMonger (also known as Earth Lusca and Aquatic Panda), has been discovered targeting government organizations in Hondur… Dark Reading · Jun 16, 2026 High HNTWTHkernel-driveraptbackdoor
threat-intel China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Researchers have identified new Windows variants of the SprySOCKS backdoor, initially linked to the Chinese state-sponsored threat actor Earth Lusca (also known as Aquatic Panda). These variants, designated WIN_DRV and W… The Hacker News · Jun 16, 2026 High CVE-2023-24932CNTWHUbackdoorwindowsstealth
threat-intel Windows version of SprySOCKS Linux malware used to attack govt orgs Windows variants of the SprySOCKS Linux malware, previously linked to the Earth Lusca threat actor, have been used to target government organizations in Taiwan, Thailand, Pakistan, and Honduras. These variants offer adva… BleepingComputer · Jun 16, 2026 High CVE-2023-24932TWTHPKlinuxstealthbackdoor
threat-intel FishMonger’s arsenal upgraded: SprySOCKS for Windows ESET researchers have discovered two new, undocumented Windows variants of FishMonger's SprySOCKS backdoor, operated by the Chinese threat actor I-SOON (believed to be part of the Winnti Group). These variants, WIN_DRV a… WeLiveSecurity · Jun 16, 2026 High CHHOTAwindowsbackdoorkernel driver