threat-intel Anti-DDoS Firm Heaped Attacks on Brazilian ISPs A Brazilian DDoS protection firm, Huge Networks, was found to be running a botnet that launched massive DDoS attacks against Brazilian ISPs. This activity stemmed from a security breach in January 2026 that compromised t… Krebs on Security · Apr 30, 2026 High CVE-2023-1389BRUSddosbotnetdns
apt Alleged Silk Typhoon hacker extradited to the United States to face charges A Chinese national, Xu Zewei, has been extradited to the United States to face charges related to his alleged involvement with the Hafnium hacking group, also known as Silk Typhoon. He is accused of attempting to steal c… Graham Cluley · Apr 29, 2026 Critical CHUSstate-sponsoredcyber espionageexchange server
threat-intel NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later This Dark Reading Confidential episode features a retrospective discussion with Chris Inglis, former NSA Deputy Director during the Edward Snowden affair, 13 years after the events. The conversation focuses on the misund… Dark Reading · Apr 28, 2026 Low USRUnsasnowdenmetadata
threat-intel Five defender priorities from the Talos Year in Review This Cisco Talos report, part of their Year in Review, highlights five key priorities for cybersecurity defenders in the current threat landscape. The report emphasizes the increasing ease of attack due to readily availa… Cisco Talos · Apr 28, 2026 High USidentityvulnerabilityanomaly detection
threat-intel The calm before the ransom: What you see is not all there is This article highlights a common cybersecurity pitfall: organizations can become overly confident in their security posture due to a period of stability, leading to complacency and a failure to adequately assess current… WeLiveSecurity · Apr 24, 2026 High UScomplacencyrisk assessmentcybersecurity
threat-intel Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System This report details a proof-of-concept (PoC) developed by Palo Alto Unit 42 demonstrating the potential of autonomous AI agents in launching offensive attacks against cloud environments. The PoC, utilizing a multi-agent… Palo Alto Unit 42 · Apr 23, 2026 High USaiautonomouscloud
ransomware ‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty A senior member of the Scattered Spider cybercrime group, Tyler Robert Buchanan, has pleaded guilty to wire fraud conspiracy and aggravated identity theft related to a series of text-message phishing attacks conducted in… Krebs on Security · Apr 21, 2026 High UKUSSPphishingsim-swapcryptocurrency
ransomware What the ransom note won’t say This article details the ongoing issues surrounding the BlackCat ransomware gang’s affiliate, who attempted to defraud the group after carrying out a significant attack on Change Healthcare. The incident highlights the i… WeLiveSecurity · Apr 20, 2026 High USransomwarefranchisesupply chain
threat-intel Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) This report from Palo Alto Unit 42 details a significant escalation of cyber risk originating from Iran following a 47-day internet outage. Iranian threat actors, identified as CL-STA-1128 (Cyber Av3ngers), are now aggre… Palo Alto Unit 42 · Apr 17, 2026 High USIRILoticsphishing
phishing That data breach alert might be a trap This article highlights the increasing sophistication and prevalence of fake data breach notification scams, driven by factors like record-breaking data breaches and the use of AI tools. Scammers are leveraging these not… WeLiveSecurity · Apr 17, 2026 High USDEphishingsocial engineeringai
threat-intel A Deep Dive Into Attempted Exploitation of CVE-2023-33538 This report details an ongoing attempt to exploit CVE-2023-33538, a vulnerability in older TP-Link Wi-Fi router models (TL-WR940N v2/v4, TL-WR740N v1/v2, TL-WR841N v8/v10). Automated scans, utilizing Mirai-like malware p… Palo Alto Unit 42 · Apr 16, 2026 High CVE-2023-33538USiotvulnerabilitymirai
phishing AI and cryptocurrency scams are costing Americans billions, FBI reports Recent investigations by the FBI have revealed a significant surge in scams leveraging artificial intelligence and cryptocurrency, resulting in substantial financial losses for American victims. These scams are exploitin… Graham Cluley · Apr 10, 2026 High USaicryptocurrencyscams
threat-intel Recovery scammers hit you when you’re down: Here’s how to avoid a second strike This article discusses the growing problem of ‘recovery fraud,’ where scammers target individuals who have already been victims of fraud, exploiting their desperation to get their stolen funds back. These scams typically… WeLiveSecurity · Apr 10, 2026 High USfraudscamrecovery
threat-intel Russia Hacked Routers to Steal Microsoft Office Tokens Russian military intelligence, operating under the ‘Forest Blizzard’ (APT28/Fancy Bear) moniker, has been conducting a sophisticated cyber espionage campaign targeting over 18,000 routers globally. The attackers exploite… Krebs on Security · Apr 7, 2026 High USUKRUdns hijackingauthentication tokensmicrosoft office
threat-intel As breakout time accelerates, prevention-first cybersecurity takes center stage This article highlights the accelerating pace of cyberattacks, driven largely by the increasing use of AI and automation by threat actors. The ‘breakout time’ – the period between initial access and lateral movement – ha… WeLiveSecurity · Apr 7, 2026 High USaiautomationlateral movement
threat-intel RSAC 2026: AI Dominates, But Community Remains Key to Security This article reports on the RSAC 2026 conference, where artificial intelligence (AI) was a dominant theme, alongside discussions about the evolving role of human intelligence in cybersecurity. A key observation was the n… Dark Reading · Apr 2, 2026 Medium USEUaicybersecurityrsac
threat-intel Digital assets after death: Managing risks to your loved one’s digital estate This article discusses the growing problem of managing a person's digital assets after death, highlighting the significant challenges posed by the lack of legal frameworks and the vulnerability of digital accounts to fra… WeLiveSecurity · Apr 1, 2026 High USGBEUdigital estateestate planningfraud
threat-intel Virtual machines, virtually everywhere – and with real security gaps This article discusses the growing problem of virtual machine (VM) sprawl in cloud environments, particularly within multi-cloud setups utilizing AWS, Azure, and GCP. The ease with which new VMs can be provisioned, coupl… WeLiveSecurity · Mar 25, 2026 High USvm sprawlcloud securitymulti-cloud
malware EDR killers explained: Beyond the drivers This article analyzes the increasing use of "EDR killers" in modern ransomware attacks. These tools, often based on vulnerable drivers or custom scripts, are deployed by affiliates to disrupt endpoint detection and respo… WeLiveSecurity · Mar 19, 2026 High USransomwareedrdrivers