threat-intel APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations APT28-linked threat actors, tracked as BlueDelta, have been deploying a new backdoor named HOOKEDGE to target European government and diplomatic organizations since late 2025. HOOKEDGE, a lightweight Windows batch script, is delivered via macro-enabled Word documents and utilizes webhook[.]site for command-and-control,… The Hacker News · 2d ago High ROSPTUapt28hookedgewebhook
threat-intel CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six previously exploited vulnerabilities to its KEV catalog, including flaws in Citrix NetScaler, Linux, and Microsoft SQL Server. These vulnerab… The Hacker News · 3d ago High CVE-2019-1068CVE-2026-8452CVE-2022-0995SWGEHOkevexploitationvulnerability
threat-intel China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware China's 'SilkParasite' operation, utilizing AI-assisted malware, has been targeting government institutions across Central Asia for nearly a year. Threat researchers at Bitdefender identified seven previously unseen malw… The Record · Aug 20, 2026 High CHKAKYaiespionagemalware
threat-intel SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs A previously unreported cyber espionage campaign, dubbed SilkParasite, is targeting government bodies in Central Asia, utilizing a set of five new remote access tool (RAT) families. The operation, linked to China, employ… The Hacker News · Aug 19, 2026 High CHKATAcyber espionagedll sideloadingremote access tool
threat-intel US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them The US Department of Justice has charged 17 Iranian hackers associated with the Mabna Institute, a company operating on behalf of the Islamic Revolutionary Guard Corps (IRGC). These hackers targeted over 100,000 professo… SecurityWeek · Aug 19, 2026 High IRAUCAcybercrimehackingdata theft
threat-intel Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware A Chinese-nexus advanced persistent threat (APT) group, suspected to be operating from China, exploited a newly patched VMware vCenter vulnerability (CVE-2026-59310) to deploy Babuk-derived ransomware. The attack involve… The Hacker News · Aug 17, 2026 High CVE-2026-59310CVE-2026-59309CHGEIRaptvulnerabilityransomware
threat-intel Global Threat Campaign Hits Critical VMware vCenter Flaw A single threat actor has been aggressively exploiting a critical vulnerability (CVE-2026-59310) in VMware vCenter, initiating a global threat campaign that began shortly after public disclosure. The vulnerability, a dir… Dark Reading · Aug 13, 2026 High USFRIRvulnerabilityexploitreverse_ssh
vulnerability Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access Threat actors are actively exploiting a recently patched critical vulnerability (CVE-2026-59310) in Broadcom VMware vCenter to gain persistent remote access. QUIRSO discovered a campaign involving 361 unique victim IP ad… The Hacker News · Aug 12, 2026 High CVE-2026-59310CVE-2026-59309GEUNTUvulnerabilityexploitreverse_ssh
ransomware DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt The DeadLock ransomware group is utilizing a sophisticated, blockchain-backed infrastructure to enhance operational resilience and evade takedown efforts. They leverage decentralized proxy servers managed via Polygon sma… The Hacker News · Aug 11, 2026 High ITSPPOransomwareblockchainsmart contracts
threat-intel Coruna, DarkSword iOS Exploits Proliferate Globally Sophisticated iPhone exploit chains, DarkSword and Coruna, are rapidly spreading beyond nation-state actors and into the hands of organized cybercrime groups. These advanced tools, initially developed for surveillance an… Dark Reading · Aug 10, 2026 High CVE-2025-31277CVE-2025-43529CVE-2026-20700CHMASAexploitioscybercrime
threat-intel Un pirate plaide coupable après 165 piratages A Canadian man, Connor Riley Moucka, has pleaded guilty to a massive cloud-based hacking and extortion scheme targeting over 165 organizations. Between February and October 2024, his group exploited stolen credentials to… ZATAZ · Aug 8, 2026 High CAUNSPcloud-securitycredential-theftextortion
threat-intel L’ingérence informationnelle teste le terrain électoral français This article examines a sophisticated disinformation campaign targeting French political figures, likely orchestrated by external actors. The campaign employs tactics such as impersonating media outlets, creating fake we… ZATAZ · Aug 7, 2026 Medium FRRUCHdisinformationinfluencefake news
threat-intel Canadian Man Pleads Guilty in Snowflake Extortions A 26-year-old Canadian man, known online as ‘Judische’ and ‘Waifu,’ has pleaded guilty to computer fraud and conspiracy to hack and extort over 165 Snowflake customers, including major companies like TicketMaster and Nei… Krebs on Security · Aug 6, 2026 High CASOTUcybercrimedata breachextortion
threat-intel Canadian man pleads guilty to Snowflake hacks that led to 165 breaches A Canadian man, Connor Riley Moucka, has pleaded guilty to hacking Snowflake and orchestrating data breaches affecting over 165 companies, including major names like AT&T and Ticketmaster. He and his co-conspirators stol… The Record · Aug 5, 2026 High CATUUNdata breachcybercrimelogin credentials
threat-intel Titan automatise le chantage aux données The TITAN group is claiming to have developed a ransomware-as-a-service platform leveraging artificial intelligence to automate extortion efforts. The tool analyzes stolen data, identifies sensitive information, maps rel… ZATAZ · Jul 24, 2026 High TUFRransomwareartificial intelligencedata extortion
threat-intel Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks CERT-UA has warned of a new phishing campaign led by the UAC-0099 threat cluster (linked to Russia) utilizing a malicious Notepad++ plugin to deliver the MATCHBOIL.V2 malware. The campaign begins with a phishing email co… The Hacker News · Jul 24, 2026 High CVE-2025-66376CVE-2026-8496CVE-2025-49113RUUKALphishingmalwarevulnerability
ransomware Europe Evolves Into Ransomware's Favorite Region Ransomware attacks in Europe have dramatically increased, representing a significant shift from previous trends. Black Kite researchers report a 55% rise in ransomware attacks across the continent through the first four… Dark Reading · Jun 25, 2026 High UKGEFRransomwaresupply-chainai
vulnerability CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution CISA has added a critical vulnerability, CVE-2026-48907, to its Known Exploited Vulnerabilities catalog affecting the Widget Factory Joomla Content Editor (JCE) due to improper access control. This flaw allows for PHP co… The Hacker News · Jun 17, 2026 Critical CVE-2026-48907TUjoomlaphpcode execution
policy UK to ban social media access for children under 16 The UK government is planning to ban social media access for individuals under 16, mirroring a similar measure implemented in Australia. This initiative aims to protect children online by restricting access to user-to-us… The Record · Jun 16, 2026 Medium UKAUSPsocial mediachildrenonline safety
apt Iranian intelligence service behind hack of LA transit system, researchers say Iranian intelligence service operatives, known as Ababil of Minab, were responsible for a significant cyberattack targeting the Los Angeles County Metropolitan Transportation Authority (LACMTA). The group, linked to the… The Record · May 27, 2026 High IRISTUirancyberattackcritical infrastructure