threat-intel TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor Microsoft has disclosed a new ClickFix variant, TerminalFix, that uses fake Cloudflare CAPTCHAs to trick users into executing malicious PowerShell commands via Windows Terminal or PowerShell. The campaign employs a multi-stage attack leveraging DLL sideloading, reconnaissance, and a reverse-tunnel backdoor to gain pers… The Hacker News · 15h ago High clickfixdll sideloadingreverse tunnel
threat-intel Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler Iranian state-sponsored hacking group Nimbus Manticore (linked to Charming Kitten) has expanded its toolset with a TWOSTROKE-like backdoor and SSH tunneling utility, furthering its espionage activities targeting defense,… The Hacker News · 4d ago High IRMIEUsshbackdoorc2
threat-intel Choose your fighter: Balancing competing requirements to select models for your AI SOC Cisco Talos conducted a comprehensive study to determine the best Large Language Model (LLM) for Security Operations Center (SOC) and Digital Forensics & Incident Response (DFIR) tasks, moving beyond simply identifying t… Cisco Talos · 4d ago High llmsocdfir
threat-intel Exploits and vulnerabilities in Q2 2026 Q2 2026 saw a significant surge in the number of registered vulnerabilities, largely driven by the increasing adoption of AI tools for vulnerability discovery. Researchers are now publishing exploits for vulnerabilities… Securelist · 4d ago High CVE-2018-0802CVE-2017-11882CVE-2017-0199vulnerabilitythreat-intelapt
threat-intel E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands Threat actors are utilizing FTP banner responses as dead drop resolvers to deliver two new remote access trojans, E4del and PINHOLE RAT. E4del, a Node.js-based RAT, employs a dynamic beaconing system to blend in with net… The Hacker News · 5d ago High UNdvrftpremote access trojan
threat-intel You don't want this Sleepwalker backdoor on your Windows machine A previously unknown backdoor, dubbed ‘Sleepwalker,’ has been discovered in Nvidia’s drivers for Windows machines. This backdoor allows attackers to remotely execute code on vulnerable systems, potentially leading to ful… The Register · 6d ago High backdoorvulnerabilitynvidia
threat-intel WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords Two new malware families, WordlistLoader and SynkLoader, are being used to deliver the Amatera Stealer via ClickFix phishing campaigns. WordlistLoader reconstructs shellcode for Amatera, utilizing techniques to evade det… The Hacker News · 6d ago High phishingransomwaremalware
threat-intel Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot Check Point Research has discovered a method to weaponize Microsoft Defender's own built-in boot-time remediation driver (BTR.sys) to delete security software and manipulate Windows systems. This technique, dubbed ‘BTR R… The Hacker News · Aug 21, 2026 High CVE-2021-24092driverbootremediation
vulnerability Microsoft Rolls Out 22 Fresh Security Patches Microsoft released 22 security patches addressing critical and high-severity vulnerabilities across its Azure, Entra ID, Exchange, Fabric, and Defender products. Several of these flaws, including a zero-day exploit dubbe… SecurityWeek · Aug 21, 2026 Critical CVE-2026-69502CVE-2026-69555CVE-2026-65816vulnerabilitypatchzero-day
threat-intel Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts Three distinct clusters of suspected Russian cyber espionage groups – UNC6293, UNC7005, and UNC5976 – are leveraging legitimate authentication flows to target individuals in academia, aerospace/defense, governments, and… The Hacker News · Aug 20, 2026 High UKARRUoauthapp passworddevice linking
vulnerability Multiples vulnérabilités dans Microsoft Windows (20 août 2026) Multiple vulnerabilities have been discovered in Microsoft Windows, allowing an attacker to elevate privileges and compromise data confidentiality. These vulnerabilities affect a wide range of Windows versions and server… CERT-FR · Aug 20, 2026 High CVE-2026-62727CVE-2026-69550securitypatchvulnerability
threat-intel CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities The CISA has issued an urgent warning about four actively exploited vulnerabilities affecting Microsoft, VMware, and Apple products. These flaws, including a double-free in Windows IKE and a weak authentication bypass in… SecurityWeek · Aug 19, 2026 Critical CVE-2026-33824CVE-2026-55040CVE-2026-59310CHvulnerabilitypatchingremote code execution
threat-intel ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More This week saw a surge in exploitation activity and new malware discoveries. A China-nexus APT is leveraging a newly patched VMware vulnerability to deploy a backdoor and ransomware (Babuk-derived). Simultaneously, a zero… The Hacker News · Aug 17, 2026 High CVE-2026-59310CVE-2026-65400CVE-2026-68820CHNOFRexploitvulnerabilityransomware
threat-intel Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth The HoneyMyte threat actor (aka Mustang Panda) has updated its CoolClient backdoor with a new, signed Windows kernel-mode rootkit, significantly enhancing its stealth capabilities. This rootkit, implemented through a dri… The Hacker News · Aug 14, 2026 High MYMOPArootkitkernel-modestealth
vulnerability Fortinet Patches Authentication Flaws in FortiWeb and FortiManager Fortinet has released patches for eight security vulnerabilities across its products, including critical authentication flaws in FortiWeb and FortiManager. These vulnerabilities could allow attackers to gain unauthorized… SecurityWeek · Aug 13, 2026 Critical CVE-2026-26035CVE-2026-70468CVE-2026-70465vulnerabilityauthenticationpatch
vulnerability Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ A disgruntled security researcher, Nightmare Eclipse, released a new zero-day exploit called ShieldBreak targeting Microsoft Defender, allowing users to escalate privileges on Windows 11 and Server 2025. This exploit lev… SecurityWeek · Aug 13, 2026 High CVE-2026-50656zero-daydefenderprivilege escalation
threat-intel Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor The Lazarus Group, a North Korean threat actor, is exploiting a newly patched zero-day vulnerability in Microsoft Windows' AFD.sys driver to gain SYSTEM access and deploy a backdoor called Troy. They are leveraging a sop… The Hacker News · Aug 12, 2026 High CVE-2026-68820CVE-2025-49113FRGEBRzero-daysocial engineeringphishing
vulnerability Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery Microsoft released a massive update with 62 critical and 357 important security vulnerabilities, marking a significant increase in the number of flaws discovered and highlighting the growing role of AI in vulnerability d… The Record · Aug 12, 2026 High CVE-2026-68820CVE-2026-62832vulnerabilitypatch tuesdayai
threat-intel CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign The CISA has ordered federal agencies to patch a critical Windows vulnerability being actively exploited by North Korean hackers as part of Operation ‘Dream Job’. This campaign, led by the Lazarus Group, impersonates rec… The Record · Aug 12, 2026 Critical CVE-2026-68820FRGEBRzero-daynorth koreaoperation dream job
vulnerability ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access A security researcher, Chaotic Eclipse, has released a proof-of-concept (PoC) demonstrating a patch bypass for a Microsoft Defender zero-day vulnerability, dubbed ShieldBreak. This vulnerability, CVE-2026-50656 (RoguePla… The Hacker News · Aug 12, 2026 High CVE-2026-50656CVE-2026-62832CVE-2026-68820zero-daypatch-bypassprivilege escalation