threat-intel Inc Ransomware Exploits SonicWall SMA Zero-Days A major ransomware group, Inc, has been exploiting two zero-day vulnerabilities in SonicWall SMA appliances to gain remote code execution and escalate privileges, allowing them to infiltrate enterprise networks, steal cr… Dark Reading · Jul 17, 2026 High CVE-2026-15409CVE-2026-15410zero-dayransomwarevulnerability
ransomware Anubis ransomware: what you need to know The Anubis ransomware, delivered as a service, is targeting healthcare organizations, but its reach extends beyond this sector. This RaaS operation is causing significant disruption and data loss for affected entities, h… Graham Cluley · Jul 16, 2026 High ransomwareraashealthcare
threat-intel Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack Two members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, have been sentenced to over five years in prison for their role in a 2024 attack against Transport for London (TfL). The attack caused… The Record · Jul 16, 2026 High UNcybercrimeransomwaredata breach
threat-intel Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers This episode of Smashing Security explores a series of unusual events, primarily focusing on a deep dive into a massive leak of internal communications from the Conti ransomware gang. The podcast details how the chats, f… Graham Cluley · Jul 16, 2026 Medium INransomwareremote-controle-rickshaw
vulnerability Cursor IDE Auto-Executes Malicious Code in Poisoned Repos A security vulnerability in Cursor IDE allows attackers to automatically execute malicious code embedded in poisoned Git repositories. Researchers at Mindgard discovered the flaw in December, but Cursor has not addressed… Dark Reading · Jul 14, 2026 High gitrepositorymalware
threat-intel GigaWiper Lets Threat Actors Choose Their Own Destructive Attack GigaWiper is a novel, modular malware that combines backdoor and wiper capabilities, allowing attackers to choose how to destroy a targeted system while minimizing their operational footprint. Initially identified as a G… Dark Reading · Jul 13, 2026 High IRRUVEwiperbackdoormodular
threat-intel Cybercriminals Flock to Healthcare Businesses as Attacks Surge Cyberattacks on healthcare businesses, including service providers supporting hospitals, have surged dramatically, nearly doubling in the past year and significantly outpacing attacks on hospitals themselves. This trend… Dark Reading · Jul 10, 2026 High USGEransomwarecyberattackhealthcare
threat-intel Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks A former ransomware negotiator, Angelo Martino, has been sentenced to 70 months in prison for betraying five victims and providing BlackCat ransomware operators with confidential information, allowing them to demand high… The Hacker News · Jul 10, 2026 High USransomwarenegotiatorcollusion
threat-intel CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its KEV catalog, including flaws in Adobe ColdFusion, JoomShaper SP Page Builder, and Langflow. These… The Hacker News · Jul 8, 2026 High CVE-2026-48282CVE-2026-56290CVE-2026-55255INvulnerabilityrceidror
threat-intel Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks An Iran-linked APT group, known as Cavern Manticore, is utilizing a sophisticated, AI-assisted modular command-and-control framework to target organizations in Israel, particularly government entities and IT providers. T… SecurityWeek · Jul 7, 2026 High ILaptcommand and controllateral movement
threat-intel Cyber readiness for SMBs: Getting the basics right This article highlights the ongoing importance of traditional cybersecurity threats for small and medium-sized businesses (SMBs), despite growing concerns about AI-powered attacks. The primary risks remain phishing, unpa… WeLiveSecurity · Jul 3, 2026 Medium USphishingvulnerabilityai
threat-intel Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs A recent Australian Institute of Criminology survey revealed a decrease in overall cybercrime incidents and financial losses experienced by Australians in 2025 compared to 2024. However, this positive trend was largely d… Dark Reading · Jul 2, 2026 Medium AUsmbcybercrimeaustralia
ransomware FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs The FortiBleed operation, initially focused on stealing credentials from thousands of Fortinet FortiGate firewalls, has expanded to involve ransomware-as-a-service (RaaS) gangs Inc Ransom and Lynx. SOCRadar researchers d… Dark Reading · Jul 2, 2026 High USGBcredential theftransomware-as-a-servicezero-day
ransomware Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials The Anubis ransomware group, a rebranded version of Sphinx, is actively exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to gain initial access to victim networks. They leverage legitimate RMM tools like Scree… The Hacker News · Jul 2, 2026 High CVE-2025-5777USUKAUcitrixbleedransomware-as-a-servicecredential theft
ransomware Ransomware Thugs Masquerade as Interpol to Entice Small Biz A new ransomware campaign is targeting small businesses globally, impersonating Interpol to lure victims into downloading malware. The campaign utilizes basic social engineering techniques, delivering a rudimentary ranso… Dark Reading · Jul 2, 2026 Medium USEUSAsocial engineeringphishingsmall business
data-breach Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches Multiple Japanese companies, including an insurer, brewer, manufacturer, and telecom provider, have recently disclosed significant cyber breaches impacting customer data and operational systems. The attacks range from a… The Record · Jul 1, 2026 High JASICAdata breachransomwarecyberattack
threat-intel 2026 FIFA World Cup Faces Surge in Cyber Threats The 2026 FIFA World Cup is facing a surge in cyber threats across the US, Canada, and Mexico, driven by a complex threat landscape including financial and nation-state actors. These threats primarily involve social engin… Dark Reading · Jun 24, 2026 High USCAMXcybercrimesocial engineeringfraud
threat-intel CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd) This report details a significant ongoing cyber threat targeting SonicWall firewalls exploiting CVE-2024-40766, a critical access control vulnerability. Ransomware groups, notably Akira and Fog, have been actively levera… SANS Internet Storm Center · Jun 23, 2026 Critical CVE-2024-40766CVE-2024-12802USGBvpncredential theftransomware
ransomware Australian sugar producer works to restore operations as ransomware group claims attack Mackay Sugar, a major Australian sugar producer, experienced a significant disruption due to a ransomware attack claimed by the Gentlemen group. The attack impacted their operations, halting sugar production in Queenslan… The Record · Jun 18, 2026 High AUransomwareaustraliasugar
threat-intel 5 reasons Microsoft 365 backup isn’t enough for business data protection This article highlights the limitations of relying solely on Microsoft 365’s built-in backup and retention policies for business data protection. It argues that organizations need a third-party solution to adequately add… BleepingComputer · Jun 18, 2026 High ransomwarebackupdata protection