threat-intel Justices rule that cellphone location histories are protected by the Fourth Amendment The Supreme Court ruled that police use of cellphone location history data obtained from tech companies constitutes a Fourth Amendment search and requires a warrant. This decision effectively rejects the "third-party doc… The Record · Jun 29, 2026 High USfourth amendmentlocation trackingprivacy
threat-intel US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp The United States government is offering a $10 million reward for information leading to the identification of Russian cyber groups involved in targeting Signal and WhatsApp accounts. These groups, UNC5792 and UNC4221, a… The Record · Jun 29, 2026 High USUKRUsocial engineeringencryptionespionage
threat-intel Ukraine to use seized crypto from cybercrime group to buy war bonds Ukraine is utilizing cryptocurrency seized from a notorious international cybercrime group to bolster its war effort. Over $8.3 million in digital assets, obtained from investigations targeting attacks across Europe and… The Record · Jun 29, 2026 High UKRUUScybercrimecryptocurrencywar bonds
threat-intel 236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers A report by Infoblox has identified over 236,000 websites utilizing the DCloud Uni-App framework, many of which are being exploited for cryptocurrency scams, phishing attacks, and wallet draining operations. These sites,… The Hacker News · Jun 29, 2026 High ARUSGBscamphishingcrypto
threat-intel Why Post-Quantum Cryptography Starts With Credentials This article discusses the growing threat posed by quantum computing to current encryption methods, particularly public-key cryptography used to protect credentials. The article highlights the ‘Harvest Now, Decrypt Later… The Hacker News · Jun 29, 2026 High USquantum computingcryptographycredentials
threat-intel OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review This article reports on a significant shift in the release strategy of AI models ChatGPT and Anthropic’s Claude, driven by a government-led cybersecurity review initiated by the Trump administration. OpenAI is restrictin… SecurityWeek · Jun 29, 2026 High USaicybersecuritygovernment
ransomware The Gentlemen are knocking: сustom backdoors and evolving tactics This report details the activities of "The Gentlemen," a ransomware-as-a-service (RaaS) group that has been aggressively targeting large corporations and critical infrastructure since early 2026. The group employs sophis… Securelist · Jun 29, 2026 High USransomware-as-a-servicereconnaissancelateral movement
threat-intel OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards OpenAI is releasing a preview of GPT-5.6 Sol, a powerful AI model with enhanced cybersecurity capabilities, to a limited group of companies and the U.S. government. The model is designed for legitimate vulnerability rese… The Hacker News · Jun 27, 2026 High USaicybersecurityvulnerability research
ransomware Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk Recent breaches targeting educational institutions, including ransomware attacks on Oracle E-Business Suite and Instructure's Canvas platform, highlight the vulnerability of the sector due to legacy technology, understaf… Dark Reading · Jun 27, 2026 High USthird-party riskransomwareeducation
threat-intel FBI: Russian hackers now target Signal backup recovery keys The FBI and CISA are warning about a phishing campaign orchestrated by Russian Intelligence Services (RIS) targeting Signal users. Attackers are now specifically seeking Signal Backup Recovery Keys to gain access to vict… BleepingComputer · Jun 26, 2026 High USRUUKphishingsignalrecovery key
threat-intel FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys The FBI and CISA have issued an updated advisory warning about Russian intelligence actors targeting Signal users, expanding their tactics to include obtaining Signal Backup Recovery Keys. This allows attackers to fully… The Hacker News · Jun 26, 2026 High USRUNEsignalphishingrecovery key
threat-intel New Initiative Tackles Security for End-of-Life Open Source Software This article discusses a new initiative, the Open Source Sustainability Initiative (OSSI), launched by the Commonhaus Foundation to address the growing challenge of managing and securing end-of-life (EOL) open-source sof… Dark Reading · Jun 26, 2026 High USend-of-lifevulnerabilitiesopen source
vulnerability Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories A high-severity vulnerability was discovered in the Amazon Q Developer extension for Visual Studio Code, allowing attackers to steal cloud credentials through malicious code repositories. The extension’s automatic execut… SecurityWeek · Jun 26, 2026 Critical CVE-2026-12957CVE-2026-12958USaivscodecredentials
threat-intel In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs This week’s cybersecurity news includes a Russian government operation utilizing Cellebrite software to target an opposition activist, a Scattered Spider group breach of Transport for London, and a significant data leak… SecurityWeek · Jun 26, 2026 High RUUKINaicyberespionagesupply chain
threat-intel Meeting Trump's 2030 Quantum Deadline Will be Expensive, Complex This article discusses the US government's accelerated efforts to prepare for the advent of quantum computing, driven by executive orders focused on post-quantum cryptography (PQC). The government is mandating a transiti… Dark Reading · Jun 26, 2026 High USquantum computingpost-quantum cryptographypqc
threat-intel New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries A vulnerability, dubbed "pedit COW," has been discovered in the Linux kernel's traffic-control subsystem, allowing unprivileged users to gain root access by poisoning cached binaries. The exploit, demonstrated with a wor… The Hacker News · Jun 26, 2026 Critical CVE-2026-46331USGBlinuxkernelexploit
vulnerability Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk A vulnerability (CVE-2024-2658) has been identified in Schneider Electric’s Floating License Manager (FLM), specifically the FlexNet Publisher component, due to an uncontrolled search path element. This allows a local, n… Securelist · Jun 26, 2026 High CVE-2024-2658USopensslprivilege escalationindustrial control systems
threat-intel FCC votes to toughen rules in bid to better protect undersea cables The FCC has voted to implement stricter regulations for undersea cables, aiming to bolster national security and protect internet traffic. This includes mandating licensing for submarine line terminal equipment (SLTE) an… The Record · Jun 26, 2026 High CHUKUSundersea cablescybersecuritynational security
threat-intel In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw A critical vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager (CUCM) has been rapidly weaponized by attackers within 24 hours of a proof-of-concept release. The SSRF flaw allows unauthenticated remote… Dark Reading · Jun 25, 2026 Critical CVE-2026-20230USssrfprivilege escalationcisco
threat-intel Local Police Collusion Hampers Crackdown on Asian Scam Centers This article reports on the ongoing challenge of combating cybercrime, specifically online scams, centered in Southeast Asia, particularly Cambodia, Myanmar, and the Philippines. Despite international pressure and arrest… Dark Reading · Jun 25, 2026 High KHUSCNcybercrimescamcorruption