threat-intel Device Code Phishing Up 1,500% in 2026; Vishing Doubles Device code phishing and vishing are experiencing a dramatic surge, driven by state-sponsored and cybercriminal groups, and are proving highly effective at bypassing traditional security measures. CrowdStrike reports a 1… Dark Reading · Aug 4, 2026 High USRUEUphishingvishingdevice-code-phishing
threat-intel ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks This week’s cybersecurity recap highlighted a concerning trend of AI-powered exploit generation, alongside a series of high-impact security incidents. A vulnerability in Coldcard hardware wallets led to an $88.6 million… The Hacker News · Aug 3, 2026 High CVE-2026-42897CVE-2026-66066CVE-2026-48449USIRaiexploithardware wallet
threat-intel Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict Multiple US water systems, including those in Georgia and Michigan, are experiencing cyberattacks, potentially linked to the ongoing US-Iran conflict. These attacks are targeting critical infrastructure, raising serious… The Register · Aug 3, 2026 High IRUScyberattackcritical infrastructurewater systems
threat-intel Une cyberattaque vise plus de 30 réseaux d’eau A coordinated cyberattack targeting over 30 water systems in Minnesota is currently under investigation. Authorities are sharing cyber intelligence and indicators of compromise with affected water providers to identify c… ZATAZ · Aug 3, 2026 High UScyberattackcritical infrastructurecybersecurity
vulnerability Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks The INC Ransomware group has been aggressively exploiting two vulnerabilities in SonicWall’s SMA1000 secure remote access appliances to deploy ransomware, targeting organizations across multiple countries. These vulnerab… SecurityWeek · Aug 3, 2026 High CVE-2026-15409CVE-2026-15410USAUUAvulnerabilityransomwarezero-day
threat-intel Pass the Passkey: A Novel Attack Surface in Passwordless Authentication This report details a new attack vector, dubbed ‘Pass-ta-key,’ that allows malware running on a compromised endpoint to bypass traditional security measures and gain unauthorized access to passkey-protected accounts. Res… Palo Alto Unit 42 · Aug 3, 2026 High USpasskeyauthenticationmalware
threat-intel Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware A sophisticated campaign, dubbed CaptiveCrunch, is leveraging hijacked hotel Wi-Fi networks to deliver surveillance malware – specifically CornFlake, a remote access trojan – to unsuspecting guests. The attacks are orche… The Hacker News · Aug 1, 2026 High USUKcaptive portaldns redirectionremote access trojan
threat-intel CISA warns of spike in attacks on water systems as Minnesota incidents probed The CISA is warning of a significant increase in cyberattacks targeting water systems, particularly in Minnesota, with potential links to Iran. Attacks involve modifying passwords, disconnecting PLCs, and causing boil wa… The Record · Jul 31, 2026 High IRUScritical infrastructurecyberattackiran
threat-intel Interpol Leverages Global System to Curtail Fraud Payments Interpol has launched I-GRIP, a global system connecting law enforcement agencies and financial institutions to rapidly intercept fraudulent payments and curb transnational criminal activity. The system, operational sinc… Dark Reading · Jul 31, 2026 High SITIUSfraudcryptocurrencycybercrime
threat-intel EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels The European Union is establishing a new team in Brussels to combat the misuse of AI, particularly concerning deepfakes, illicit imagery, and cyber threats. This initiative is part of a broader strategy to assert tech so… SecurityWeek · Jul 31, 2026 Medium EUUSCHaideepfakeregulation
threat-intel You were onto something with “It’s the Climb,” Miley This week's Threat Source newsletter highlights a significant spike in authentication abuse and sophisticated phishing tactics, driven by attackers leveraging QR codes and advanced platforms like ARToken to bypass multi-… Cisco Talos · Jul 30, 2026 High USphishingauthenticationransomware
threat-intel US and Allies Update SBOM Guidance The US government, alongside 13 allied nations, has released updated guidance on Software Bill of Materials (SBOMs) to enhance software supply chain security and transparency. This revised guidance builds upon previous e… SecurityWeek · Jul 30, 2026 Info USAUsbomsupply chainsoftware security
threat-intel Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation Russian threat actors, linked to Laundry Bear (TA488), are exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain persistent access to email accounts within U.S. and European government entities and… The Hacker News · Jul 30, 2026 High CVE-2026-42897CVE-2025-66376USEUxsscredential theftpersistence
threat-intel Laundry Bear’s webmail hackers had more in store after February, report says Laundry Bear, a Russian state-linked APT group, has been aggressively exploiting vulnerabilities in both Zimbra Collaboration Suite’s webmail platform and Microsoft Outlook Web Access (OWA) to steal emails and credential… The Record · Jul 29, 2026 High CVE-2026-42897NLUSRUaptvulnerabilityzero-day
threat-intel US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security The U.S. Federal Communications Commission is implementing a ban on new imports of foreign-made humanoid robots and power inverters, primarily targeting China due to national security concerns. This move follows a series… SecurityWeek · Jul 29, 2026 High CHUSchinaroboticsnational security
threat-intel US, Australia Release OT Isolation Guidance for Critical Infrastructure The US cybersecurity agency CISA and Australia’s ACSC have jointly released guidance, ‘CI Fortify,’ to help critical infrastructure organizations isolate vital Operational Technology (OT) systems and supporting networks.… SecurityWeek · Jul 29, 2026 Medium USAUcritical infrastructureot securitycyber resilience
threat-intel MCP gets an enterprise makeover This article covers a range of cybersecurity and technology news, including a vulnerability impacting Joomla extensions, a Microsoft SharePoint zero-day exploit, and a Russian phishing campaign mimicking Signal support.… The Register · Jul 28, 2026 Medium USIRRUvulnerabilityphishingransomware
threat-intel AI-found bugs aren't proving any easier to exploit despite the hype Recent research indicates that AI-powered models, particularly those mimicking Claude, are being exploited to bypass security measures. Researchers have found that Chinese AI models can convincingly impersonate Claude, h… The Register · Jul 28, 2026 Medium CHIRUSaiimpersonationphishing
threat-intel 24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login A significant vulnerability, CVE-2013-4786, has been exposed due to a 20-year-old flaw in the IPMI 2.0 specification, resulting in over 36,000 internet-exposed BMCs revealing password hashes. This allows attackers to con… The Hacker News · Jul 28, 2026 High CVE-2013-4786USGECHbmcipmipassword cracking
threat-intel Suitable AI : 15 176 comptes exposés via GraphQL A hacker claims to have breached Suitable AI, a recruitment platform utilizing AI, exposing data of 15,176 candidates and potentially compromising administrator accounts. The breach stemmed from vulnerabilities in Suitab… ZATAZ · Jul 28, 2026 Medium INUSgraphqlvulnerabilitydata breach