vulnerability Microsoft smashes Patch Tuesday record for second successive month Microsoft released a massive Patch Tuesday update, exceeding 600 security vulnerabilities – the largest in the program's history. This surge in vulnerabilities, driven in part by AI-assisted discovery, has led to a signi… The Record · Jul 15, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-55040UNpatch tuesdayvulnerabilityexploit
threat-intel U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support The U.S. Treasury Department has sanctioned a VPN service provider, First VPN Service (1VPNS), and its administrator, Dmytro Rashevskyi, for enabling ransomware groups to carry out attacks against U.S. companies and inst… The Hacker News · Jul 14, 2026 High CVE-2018-0171CVE-2008-4128RUUKUNvpnransomwarecyber espionage
threat-intel Weak Security Continues to Fuel Russian Cyberattacks The UK and EU have jointly sanctioned Russian individuals and entities involved in cyberattacks and disinformation campaigns, coinciding with a US cybersecurity advisory highlighting ongoing Russian state-sponsored attac… Dark Reading · Jul 13, 2026 High UKEUUNrouter securityciscosnmp
threat-intel Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft Forg365, a new PhaaS operation, is targeting Microsoft 365 accounts using a sophisticated combination of device code phishing, AitM tactics, and AI-assisted lure creation. The platform allows even inexperienced operators… The Hacker News · Jul 13, 2026 High UNRUphishingaitmdevice code
threat-intel Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 In June 2026, a significant number of cybersecurity M&A deals were announced, highlighting the industry's ongoing consolidation and investment in advanced security technologies. Several key acquisitions focused on areas… SecurityWeek · Jul 13, 2026 High ISBECAmergers and acquisitionscybersecurityidentity management
threat-intel AI Data Centers and the Concentration of Wealth This article argues that focusing solely on opposition to AI data centers in the US is a misguided approach, as it obscures the larger issue of corporate AI dominance and the concentration of wealth within the industry.… Schneier on Security · Jul 13, 2026 High CHUNaidata centerscorporate power
threat-intel Jen Ellis: Connecting Cyber Community With Political Machinery This article chronicles the career of Jen Ellis, a cybersecurity advocate who rose to prominence after witnessing the legal troubles faced by security researcher HD Moore. Initially spurred by a deep sense of injustice a… Dark Reading · Jul 10, 2026 High UNpolicycybersecurityresearch
ransomware Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence Two major ransomware figures have been brought to justice in separate U.S. court cases. Karen Vardanyan, a Ryuk ransomware operator, pleaded guilty to conspiracy and computer fraud, while Angelo Martino, a ransomware neg… The Record · Jul 10, 2026 High FRUKUNransomwarenegotiatorextortion
threat-intel More Countries Jump on the Social Media Ban Wagon More countries are implementing social media bans for minors, driven by concerns about mental health and safety. However, companies are struggling to comply while minimizing user disruption and avoiding intrusive data co… Dark Reading · Jul 10, 2026 Medium AUUNsocial mediaage verificationprivacy
threat-intel New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware Microsoft has uncovered a sophisticated Windows backdoor, dubbed GigaWiper, that combines destructive capabilities with remote control functionality. GigaWiper operates by bundling three separate tools – a disk wiper, a… The Hacker News · Jul 9, 2026 High IRISUKransomwarebackdoordata destruction
threat-intel ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories This week's ThreatsDay highlights a diverse range of cyber threats, from global fraud operations and ransomware tool overlaps to sophisticated social engineering attacks and vulnerabilities in popular software. Key event… The Hacker News · Jul 9, 2026 High CVE-2026-9181CVE-2025-49760CVE-2025-59200CHTAESsocial engineeringphishingransomware
threat-intel As Global Conflicts Go Digital, Businesses Need Wartime Gameplans As global conflicts become increasingly digital, businesses across various sectors are becoming increasingly vulnerable targets for nation-states engaged in warfare. The case of Intellect Services, a Ukrainian tax softwa… Dark Reading · Jul 9, 2026 High UKIRUNcyberwarfarenation-stategeopolitics
threat-intel Mexico's New Cyber Plan Faces Its First Real Test Mexico's National Cybersecurity Plan, designed to bolster the country's digital defenses ahead of the 2026 FIFA World Cup, is facing an early test. Despite the plan's goals – including establishing a National Cybersecuri… Dark Reading · Jul 8, 2026 High MEUNCAcybersecuritylatin americacyberattack
vulnerability Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS Ubiquiti Networks has released security updates to address a series of critical vulnerabilities affecting its UniFi network management products, including UniFi Connect, Talk, Access, Protect, and OS. These flaws could a… The Hacker News · Jul 8, 2026 High CVE-2026-50746CVE-2026-50747CVE-2026-50748UNRUvulnerabilitynetwork securitycommand injection
threat-intel Felons, Fraudsters Flog Offensive Cybersecurity Startup IRIS C2, a cybersecurity startup operating under the Calvexa Group LLC, is aggressively pursuing zero-day vulnerabilities and offensive security capabilities, attracting researchers and exploit developers with lucrative… Krebs on Security · Jul 8, 2026 High UNcybercrimedisinformationvulnerability research
threat-intel The Verification Step Is the New ATO Battleground in 2026 The traditional methods of account takeover (ATO) – relying on stolen passwords – are becoming less effective due to the increasing adoption of passkeys and phishing-resistant authentication. Attackers are now shifting t… The Hacker News · Jul 8, 2026 High UNpasskeysgenerative aiaccount takeover
threat-intel Cybersecurity and the Gap Between Skill and Ability A joint statement from the Five Eyes intelligence alliance warned of escalating cyber risks due to the increasing capabilities of AI models, particularly their ability to autonomously carry out cyberattacks. The statemen… Schneier on Security · Jul 8, 2026 High UNCAAUaicybersecuritythreat intelligence
threat-intel Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker U.S. prosecutors have linked an alleged Scattered Spider hacker, Peter Stokes, to a luxury jewelry retailer breach through a persistent Windows device ID. Stokes, a dual U.S.-Estonian citizen, was extradited from Finland… The Hacker News · Jul 7, 2026 High ESFIUNdevice-idhackerintrusion
threat-intel CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker This article profiles Tarah Wheeler, CISO at TPO Group and previously holding leadership roles at Red Queen Technologies and EFF. It highlights her unique background, blending her passion for social science and writing w… SecurityWeek · Jul 7, 2026 Medium CHRUNOsocial sciencehuman behaviorpolicy
threat-intel Threat landscape for industrial automation systems. Q1 2026 In Q1 2026, the effectiveness of blocking malicious objects on industrial control systems (ICS) decreased significantly, reaching 19.6%, a three-year low. Growth in blocked threats was most pronounced in Southern Europe… Securelist · Jul 7, 2026 Medium UNRUSOicsindustrial control systemsmalware