threat-intel Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network Berlin's state government is facing an extortion attempt following a data breach of its state network. Rhysida, a threat group, is suspected of stealing 5.79 terabytes of data, including maps and geodata, and the group gained initial access through compromised credentials and exploiting vulnerabilities like Zerologon.… The Hacker News · 2d ago High CVE-2020-1472GEUKdata breachransomwaresupply-chain
threat-intel Some Malicious PE Stats, (Thu, Aug 27th) A security researcher used a Python script leveraging the pefile library to analyze a large dataset of malware samples from Malware Bazaar. By examining PE file headers, including the undocumented Rich Header and .NET CL… SANS Internet Storm Center · 2d ago Medium compilerrich headerpe file
threat-intel ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories This week’s ThreatsDay bulletin highlights a diverse range of cyber threats, including a 296,000-device IoT botnet, social engineering attacks targeting security teams, and a growing number of credential-stealing malware… The Hacker News · 3d ago High CVE-2026-55040CVE-2026-63520RUsocial engineeringphishingcredential theft
threat-intel GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address Threat actors linked to Dark Caracal have deployed a new Go-based malware framework, GoCaracal, utilizing an Ethereum smart contract to dynamically update its command-and-control (C2) address. This allows operators to ch… The Hacker News · 3d ago Medium BRECCHethereumsmart contractc2
threat-intel Dark Caracal Adds New Malware to Cyber Espionage Arsenal The Dark Caracal cyber-espionage group, linked to Lebanon, has added a new modular malware framework called GoCaracal to its arsenal. This framework, developed since 2026, is used for data theft, maintaining persistent a… Dark Reading · 4d ago High LBVEBRcyber-espionagedata theftmalware
threat-intel ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud ToxicPanda 2.0, an Android banking trojan, has significantly expanded its capabilities and targeting scope, now leveraging a new set of remote commands and a sophisticated overlay-based credential theft mechanism. Simult… The Hacker News · Aug 20, 2026 High SOUNbanking trojanandroid malwarecredential theft
threat-intel SilkParasite Threatens Central Asian Orgs With Flurry of RATs A Chinese-nexus cyber-espionage group, linked to FamousSparrow and the ShadowPad ecosystem, known as SilkParasite, is targeting government organizations across Central Asia (Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikist… Dark Reading · Aug 19, 2026 High UZTMKGchinaespionagerat
threat-intel SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs A previously unreported cyber espionage campaign, dubbed SilkParasite, is targeting government bodies in Central Asia, utilizing a set of five new remote access tool (RAT) families. The operation, linked to China, employ… The Hacker News · Aug 19, 2026 High CHKATAcyber espionagedll sideloadingremote access tool
threat-intel AI-Driven Vulnerability Surge Breaks the Traditional Patching Model Rapid7’s analysis reveals a significant shift in the cybersecurity landscape driven by AI, leading to a dramatic increase in disclosed and exploited vulnerabilities. The traditional patching model is becoming obsolete du… SecurityWeek · Aug 18, 2026 High CHRUIRaivulnerabilitiespatching
threat-intel Ukrainian software developer faces 12 years in Swiss ransomware trial A Ukrainian software developer is facing a 12-year prison sentence in Switzerland for his alleged involvement in a ransomware operation targeting companies including Stadler Rail and Crealogix, resulting in over 130 mill… The Record · Aug 17, 2026 High SWRUUKransomwarecybercrimeinvestigation
threat-intel Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic The Cavern C2 framework, used by Iranian nation-state hackers linked to the Ministry of Intelligence and Security (MOIS) and associated with groups like MuddyWater and OilRig (Lyceum), is undergoing continuous evolution.… The Hacker News · Aug 17, 2026 High IRc2dnsgoogle
vulnerability Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access Threat actors are actively exploiting a recently patched critical vulnerability (CVE-2026-59310) in Broadcom VMware vCenter to gain persistent remote access. QUIRSO discovered a campaign involving 361 unique victim IP ad… The Hacker News · Aug 12, 2026 High CVE-2026-59310CVE-2026-59309GEUNTUvulnerabilityexploitreverse_ssh
threat-intel IT threat evolution in Q2 2026. Non-mobile statistics In Q2 2026, Kaspersky products blocked a massive 399.3 million attacks originating from online resources, highlighting a continued surge in ransomware activity and botnet attacks. The Qilin ransomware group dominated, ac… Securelist · Aug 10, 2026 High CVE-2026-33825CVE-2026-50751CVE-2026-50752NEGEUNransomwarebotnetsupply chain
threat-intel Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent Google removed three AI agent workflows from its ADK Python repository after a public GitHub issue allowed a malicious bot to trigger a privileged code-fixing agent, leading to potential code execution and credential exp… The Hacker News · Aug 4, 2026 High botcredential exposuregit
threat-intel An analysis of incidents at Brazilian educational institutions This report details cyberattacks targeting educational institutions in Brazil since 2025, highlighting a trend of leveraging readily available tools and valid accounts to gain access and deploy ransomware and other malwa… Securelist · Aug 3, 2026 High BRransomwarethreat-intelinsider-threat
threat-intel DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware North Korean-linked threat actors are using a sophisticated macOS malvertising campaign to deliver crypto-stealing malware. The campaign mimics a fake software update sequence to trick users into executing a malicious co… The Hacker News · Jul 30, 2026 High KPmacosmalvertisingcrypto-stealer
threat-intel 'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China A sophisticated, full-service mobile malware-as-a-service (MaaS) framework called ‘Flying Eagle’ has emerged from the Chinese cybercriminal underground, enabling criminals to build and deploy mobile malware campaigns wit… Dark Reading · Jul 30, 2026 High CHmaasmobile malwarecybercrime
threat-intel Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates A remote access trojan (RAT) called Flying Eagle, along with a related control kit called Night Dragon, is circulating through criminal Telegram channels. Researchers have identified 170 servers hosting the RAT framework… The Hacker News · Jul 29, 2026 High CNandroidrattelegram
threat-intel DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts The DevMan ransomware-as-a-service (RaaS) operation has significantly upgraded its affiliate portal, transitioning from a chat-based system to a centralized platform for managing victims, payouts, and team operations. PR… The Hacker News · Jul 25, 2026 High USCISEransomwareraasdevman
threat-intel Golden Chickens Resurfaces With Four New Malware Families and Modular Implants The Golden Chickens malware-as-a-service (MaaS) group, tracked as TAG-195, has resurfaced with four new malware families, indicating continued development and a shift towards a more flexible, modular approach to evade de… The Hacker News · Jul 24, 2026 High malware-as-a-servicemodular malwareclickfix