threat-intel ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories This week's "ThreatsDay" bulletin highlights a diverse range of security threats, from malware targeting PLCs with Iranian involvement to AI-generated vulnerabilities and deceptive apps. Key concerns include a GitHub sup… The Hacker News · Jul 23, 2026 High IRmalwarethreat intelligencesupply-chain
threat-intel Fake Bahrain Alert App Deploys Android Surveillance Malware A malicious Android application, dubbed ‘BH Alert,’ is being distributed through fake Google Play sites mimicking Bahraini government entities to deliver a four-stage surveillance platform. The app leverages users' trust… Dark Reading · Jul 22, 2026 High BHKUandroidspywaremalware
threat-intel New Kimsuky campaign compromised South Korean software vendors A new campaign by North Korean threat actor Kimsuky (APT43) targeted South Korean software vendors in 2025 and 2026, ultimately compromising their customers. The group leveraged social engineering and exploiting remote c… The Record · Jul 22, 2026 High KRnorth koreaapt43social engineering
threat-intel GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft A Chinese cybercrime group, known as CylindricalCanine (a sub-group of GoldenEyeDog), has been linked to a significant security breach at DigiCert, a code-signing certificate provider. The attackers exploited a vulnerabi… The Hacker News · Jul 17, 2026 High CNcode-signingphishingmalware
threat-intel New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage A previously undocumented Go-based malware, GoSerpent, has been actively targeting government and diplomatic entities in Southeast Asia since 2021, with a renewed surge in activity in 2026. Developed by the threat actor… The Hacker News · Jul 17, 2026 High BAAPmalwareespionagedata theft
threat-intel GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration A sophisticated, evolving threat actor, potentially linked to TetrisPhantom, has been targeting government and diplomatic entities in Southeast Asia since late 2025 with a campaign utilizing tools like GoSerpent, Stowawa… Securelist · Jul 16, 2026 High VNTHproxyremote accessdata exfiltration
ransomware GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses The GodDamn ransomware family, a rebrand of Beast ransomware (originally based on Monster), is utilizing a newly discovered malicious driver called PoisonX to disable endpoint defenses and gain access to systems. Threat… The Hacker News · Jul 9, 2026 High ransomwarepoisonxbyovd
threat-intel Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data Researchers at Noma Security discovered a vulnerability, dubbed ‘GitLost,’ in GitHub Agentic Workflows that allows attackers to trick AI agents into leaking private repository content simply by posting a malicious issue… The Hacker News · Jul 7, 2026 High prompt injectionai agentgithub
apt Armored Likho APT Targeting Government, Electric Power Entities The Armored Likho APT group is actively targeting government and electric power entities across multiple countries, including Russia, Brazil, and Kazakhstan. The group utilizes a diverse toolkit of malware, including RAT… SecurityWeek · Jul 6, 2026 High RUBRKZaptspear-phishingrat
threat-intel Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT A China-nexus threat actor is conducting a targeted phishing campaign against Indian taxpayers and tax professionals, leveraging fake tax filing utilities to deploy a remote access trojan (DcRAT). The campaign, dubbed Op… The Hacker News · Jul 6, 2026 High CHINphishingremote access trojantax
threat-intel Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer Armored Likho, a previously undocumented threat actor, has been actively targeting government agencies and the power sector in Russia, Brazil, and Kazakhstan with a sophisticated campaign utilizing tools like BusySnake S… The Hacker News · Jul 3, 2026 High CVE-2025-9491RUBRKZspear-phishingremote access trojaninformation stealer
threat-intel FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations A large-scale credential theft campaign, dubbed FortiBleed, has been linked to both the INC and Lynx ransomware groups, utilizing stolen Fortinet credentials for follow-on intrusions. The operation involved extensive sca… The Hacker News · Jul 2, 2026 High CVE-2026-35616USLAAScredential theftransomwarefortinet
ransomware The Gentlemen are knocking: сustom backdoors and evolving tactics This report details the activities of "The Gentlemen," a ransomware-as-a-service (RaaS) group that has been aggressively targeting large corporations and critical infrastructure since early 2026. The group employs sophis… Securelist · Jun 29, 2026 High USransomware-as-a-servicereconnaissancelateral movement
ransomware New Prinz Eugen ransomware prioritizes recent files for encryption A new ransomware variant, Prinz Eugen, is targeting organizations with a focus on encrypting recently modified files to maximize disruption. The group employs a hands-on-keyboard approach, utilizing legitimate RMM tools… BleepingComputer · Jun 20, 2026 High GBransomwarerdpencryption
malware 152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic A network of 152 Chrome extensions, collectively installed over 105,000 times, has been discovered distributing a potentially unwanted program (PUP) that generates fake traffic and logs user data. These extensions, masqu… The Hacker News · Jun 15, 2026 High TRadwarefake trafficprivacy
threat-intel Credit card theft campaign abuses Stripe to host stolen payment info A Magecart campaign is exploiting Stripe's infrastructure to steal credit card data from online stores. The attackers leverage Google Tag Manager to deliver the malicious code, bypassing standard security measures. This… BleepingComputer · Jun 4, 2026 High magecartcredit card theftstripe
ransomware AI-built ransomware toolkit automates EDR evasion, AD discovery A threat actor is utilizing an AI-powered ransomware toolkit to automate Active Directory discovery and evade Endpoint Detection and Response (EDR) solutions. The toolkit, developed with assistance from AI agents like Cu… BleepingComputer · Jun 2, 2026 High RUaiedr evasionactive directory
threat-intel New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks A new, Russian-linked cyber threat group, dubbed GREYVIBE, has been targeting Ukraine and related entities since August 2025 with a range of sophisticated attacks. The group utilizes multiple attack vectors, including ph… The Hacker News · May 29, 2026 High RUrussianaigenai
threat-intel Ransomware Actors Show Up In Person to Steal Law Firm Data The Silent Ransom Group (SRG), also known as Luna Moth and UNC3753, is targeting law firms through sophisticated social engineering tactics, including impersonating IT personnel and conducting in-person visits to gain ac… Dark Reading · May 27, 2026 High RUsocial engineeringdata theftlaw firms
threat-intel KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike A zero-day vulnerability in Digital Knowledge KnowledgeDeliver LMS was exploited to deploy the Godzilla web shell and establish Cobalt Strike Beacon access. The flaw, stemming from hard-coded ASP.NET machine keys, allowe… The Hacker News · May 26, 2026 Critical CVE-2026-5426JPzero-daydeserializationasp.net