Des cibles françaises au cœur d’une plateforme cybercriminelle A ZATAZ investigation has uncovered a list of French organizations targeted by a cybercriminal group, Krybit, who are aggressively recruiting affiliates through a platform offering a lucrative 80% revenue split. The group, known for ransomware operations, is actively seeking partners to expand its reach and utilize a d… ZATAZ · Aug 7, 2026 FRMXUSransomwarerecruitmentcybercrime
threat-intel GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration A sophisticated, evolving threat actor, potentially linked to TetrisPhantom, has been targeting government and diplomatic entities in Southeast Asia since late 2025 with a campaign utilizing tools like GoSerpent, Stowawa… Securelist · Jul 16, 2026 High VNTHproxyremote accessdata exfiltration
threat-intel OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps OkoBot, a malware framework, has been actively targeting hardware wallet users since April 2025, primarily through phishing attacks leveraging a module called SeedHunter. SeedHunter intercepts the wallet's desktop softwa… The Hacker News · Jul 15, 2026 High BRVNCAphishingmalwarehardware wallet
threat-intel China-Linked Group Targets Southeast Asia Critical Systems A China-linked cyber threat group, CL-STA-1062 (formerly UAT-7237), has been targeting critical infrastructure providers in Southeast Asia over the past year, deploying a new backdoor tool called TinyRCT. The group has s… Dark Reading · Jul 1, 2026 High CNMYTHchinaaptbackdoor
threat-intel Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign A Chinese-speaking Advanced Persistent Threat (APT) group, CL-STA-1062, has been actively targeting government entities and critical infrastructure in Southeast Asia since 2022, utilizing a new custom backdoor called Tin… The Hacker News · Jun 26, 2026 High VNaptbackdoorsoutheast asia
threat-intel CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Palo Alto Unit 42 has identified a sustained cyber threat campaign, CL-STA-1062, targeting government and critical infrastructure entities in Southeast Asia since at least March 2022. The group, linked to UAT-7237, utili… Palo Alto Unit 42 · Jun 25, 2026 High VNeast asiasoutheast asiabackdoor
malware WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool A WhatsApp-based campaign is utilizing malicious VBScript files to trick users into installing ManageEngine RMM tool software. The campaign, currently active across multiple countries, leverages deceptive document names… The Hacker News · Jun 23, 2026 Medium MYBRINsocial engineeringvbsremote access
malware A VBScript campaign distributed through WhatsApp deploying RMM software A WhatsApp-distributed malware campaign, active as of June 2026, leverages deceptive VBScript files disguised as financial documents to trick users into executing malicious code. This code ultimately installs legitimate… Securelist · Jun 22, 2026 High MYBRINsocial engineeringvbswhatsapp
threat-intel Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites An international law enforcement operation, dubbed Operation Endgame, successfully disrupted SocGholish’s infrastructure and removed malware from nearly 15,000 WordPress websites. The takedown, involving agencies from mu… The Hacker News · Jun 19, 2026 High NLCADEbotnetwordpressmalware
threat-intel ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories This week’s ThreatDay Bulletin highlights several concerning security incidents, including browser extension abuse, macOS malware attacks, AI-powered malware delivery, and a global phishing campaign targeting travel book… The Hacker News · Jun 18, 2026 High CVE-2026-20127CVE-2026-49975USCNJPbrowser extensionsmacos malwareai abuse
data-breach FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. A significant data leak, dubbed "FortiBleed," has exposed approximately 73,932 Fortinet VPN credentials for firewall URLs across numerous organizations worldwide. The leak, discovered by Bob Diachenko, reveals a multi-op… BleepingComputer · Jun 17, 2026 High USGBJPvpncredentialsbreach
threat-intel OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack OceanLotus, a 15-year-old APT group with a history of targeting China and human rights activists, has been conducting a prolonged cyber espionage operation against Vietnamese entities, including a transport construction… The Hacker News · Jun 11, 2026 High VNsupply chainbackdoorespionage
threat-intel OceanLotus: From external espionage to domestic targeting OceanLotus, a Vietnamese-aligned cyberespionage group (formerly APT32), has shifted its focus from external espionage to domestic targeting, particularly in relation to corruption investigations in Vietnam. Since 2020, f… WeLiveSecurity · Jun 11, 2026 High VNsupply-chainespionagebackdoor
malware Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content A new malware campaign, dubbed Weedhack, is targeting Minecraft players through YouTube and malicious websites, distributing a MaaS (Malware-as-a-Service) tool. The campaign, active since January 2026, utilizes SEO poiso… The Hacker News · Jun 3, 2026 High USDEINminecraftmalwareyoutube
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa