threat-intel In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops Multiple cybersecurity incidents and threats are unfolding, including a ransomware affiliate pleading guilty in the US, a subscription-based remote access trojan (QuimaRAT) being actively sold on the dark web, and a Cana… SecurityWeek · Jul 10, 2026 High ARCAUSransomwaredata breachremote access trojan
threat-intel Fresh ATM Crypto Software Bugs: Jackpot or Bust? A researcher, Matt Burch, discovered nine vulnerabilities in CryptoPro Secure Disk, a full-disk encryption solution used by ATM manufacturer Diebold Nixdorf. These vulnerabilities could allow attackers to bypass encrypti… Dark Reading · Jul 10, 2026 High USatmencryptionjackpotting
threat-intel AI Surveillance and Social Progress This article explores the growing threat of AI-powered surveillance systems, particularly in China, and their potential to significantly erode personal freedoms and democratic progress. The author argues that these syste… Schneier on Security · Jul 10, 2026 High CHUSGEsurveillanceaifacial recognition
threat-intel Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks A former ransomware negotiator, Angelo Martino, has been sentenced to 70 months in prison for betraying five victims and providing BlackCat ransomware operators with confidential information, allowing them to demand high… The Hacker News · Jul 10, 2026 High USransomwarenegotiatorcollusion
threat-intel ISC Stormcast For Thursday, July 9th, 2026 https://isc.sans.edu/podcastdetail/10000, (Thu, Jul 9th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging a newly discovered phishing technique that bypasses traditional email security filters. The c… SANS Internet Storm Center · Jul 9, 2026 Critical USphishingzero-dayransomware
malware Vidar Infostealer Hammers SMBs via Malvertising Campaign A financially motivated operation is using malvertising to deliver a two-for-one malware payload – the Vidar infostealer and XMRig cryptominer – to consumers and SMBs globally. The campaign employs sophisticated evasion… Dark Reading · Jul 8, 2026 High USEUmalvertisingmaascryptomining
threat-intel New Ghost Phishing Wave Is Breaking Traditional Email Security A new phishing technique called ‘ghost phishing’ is emerging, where malicious links appear harmless during initial email inspection but execute a more damaging attack within the victim’s browser. The EvilTokens campaign,… The Hacker News · Jul 8, 2026 High USEUphishingghost phishingmicrosoft 365
threat-intel Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation A financially motivated campaign utilizing Vidar stealer and XMRig cryptocurrency miner has been active since April 2026, targeting consumers and small- and medium-sized businesses globally, primarily in the U.S. and EU.… Palo Alto Unit 42 · Jul 7, 2026 High USDEmalvertisingdll hijackinganti-forensic
phishing Big Brand Jobs Scam Targets Marketing Pros' Google Accounts A sophisticated phishing campaign is targeting marketing professionals by impersonating major brands like Coca-Cola, Louis Vuitton, and McKinsey & Company to steal their Google credentials. The campaign utilizes nested r… Dark Reading · Jul 7, 2026 Medium USphishingcredential theftnested redirects
data-breach County Government Reportedly Paid $1 Million to Cyber Extortion Group A small county government in Ohio reportedly paid $1 million to the Kairos cyber extortion group to prevent the release of stolen data following a brute-force attack in May 2025. The attackers, Kairos, demanded $3 millio… SecurityWeek · Jul 7, 2026 High USdata breachransomwaregovernment
policy Supreme Court allows Texas app law requiring age verification to take effect The Supreme Court has allowed a Texas law requiring age verification for apps to take effect while a lower court considers its constitutionality. This law mandates that app developers and stores use age verification tool… The Record · Jul 7, 2026 Info USprivacyregulationfirst amendment
threat-intel CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws The US Cybersecurity and Infrastructure Security Agency (CISA) is leveraging Anthropic’s AI model, Mythos, to proactively scan federal government software for security vulnerabilities. This initiative is part of a broade… SecurityWeek · Jul 7, 2026 Medium USaiintelligencevulnerability
threat-intel Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities A China-aligned threat actor cluster, tracked as UNC5174 and linked to ShadowPad, has been exploiting vulnerabilities in Roundcube webmail software at U.S. and Canadian universities. The campaign leverages CVE-2024-42009… The Hacker News · Jul 7, 2026 High CVE-2024-42009CVE-2025-49113CHUSCAroundcubexsscve-2024-42009
threat-intel RCS and DNS: The NAPTR Record, (Mon, Jul 6th) This article details the observation of NAPTR records being utilized in RCS (Rich Communication Services) communications, specifically within Verizon’s network. NAPTR records, defined in RFC 2915, are typically used to r… SANS Internet Storm Center · Jul 6, 2026 Medium USrcsdnsnaptr
threat-intel ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More This week’s security recap highlighted several concerning trends, including a disruption of the NetNut residential proxy network used for botnet operations, a fake Proof-of-Concept (PoC) malware targeting vulnerability r… The Hacker News · Jul 6, 2026 High CVE-2026-48276CVE-2026-48283CVE-2026-48277USESSPbotnetproxymalware
threat-intel U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case A U.S. government entity reportedly paid $1 million to the group known as Kairos to prevent the leak of stolen data following a data breach at Union County, Ohio. Kairos, however, operated solely through data theft extor… The Hacker News · Jul 4, 2026 High USRUdatatheftextortionnegotiation
vulnerability New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android A newly discovered Linux kernel vulnerability, dubbed "Bad Epoll" (CVE-2026-46242), allows unprivileged users to gain root access on systems, including Android devices. The flaw, a "use-after-free" bug, was identified by… The Hacker News · Jul 3, 2026 High CVE-2026-46242CVE-2026-43074CVE-2026-31431USUKlinuxkernelepoll
ransomware New Avalon Malware Framework Packs CrownX Ransomware Capabilities Researchers at Blackpoint Cyber discovered Avalon, a new modular malware framework used to deploy the CrownX ransomware. The framework utilizes a multi-stage phishing campaign to bypass security controls and performs cre… The Hacker News · Jul 3, 2026 High CVE-2025-3248USphishingcredential theftlateral movement
threat-intel Chinese LLMs Broaden the Gap Between Attackers & Defenders This article reports on the emergence of new Chinese AI models, GLM 5.2 and Tulongfeng (Dragon Saber), which are demonstrating strong performance in vulnerability discovery, rivaling leading US models like Opus and GPT-5… Dark Reading · Jul 3, 2026 High CHUSaivulnerabilitychina
threat-intel Cyber readiness for SMBs: Getting the basics right This article highlights the ongoing importance of traditional cybersecurity threats for small and medium-sized businesses (SMBs), despite growing concerns about AI-powered attacks. The primary risks remain phishing, unpa… WeLiveSecurity · Jul 3, 2026 Medium USphishingvulnerabilityai