threat-intel ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories This week’s ThreatsDay bulletin highlights a diverse range of cyber threats, including a 296,000-device IoT botnet, social engineering attacks targeting security teams, and a growing number of credential-stealing malware families. Notable threats include a fake login page and productivity app used for phishing, a Pytho… The Hacker News · 3d ago High CVE-2026-55040CVE-2026-63520RUsocial engineeringphishingcredential theft
threat-intel Android Malware Hijacks Update System for Car Head Units Threat actors, linked to the BadBox click-fraud botnet, are exploiting legitimate update mechanisms in car head units to spread malware. This marks the first known instance of malware targeting automotive infotainment sy… Dark Reading · 4d ago High CHandroidbotnetmalware
threat-intel FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations The FBI has disrupted a Chinese-linked hacking infrastructure, QScan and QTRouter, operated by the group QTFY, which has been targeting U.S. critical infrastructure since 2018. These tools were used to steal data and con… The Hacker News · 4d ago High CVE-2024-8190CVE-2024-8963CVE-2024-9380CHcyber espionageiotproxy
threat-intel US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate The U.S. Department of Justice and FBI have taken down Chinese hacking tools – QScan and QTRouter – used by China’s Ministry of State Security and People’s Liberation Army to target U.S. agencies, including the Federal R… The Record · 4d ago High CHchinaiotcyberattack
threat-intel CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks CISA has revealed that over 100 internet-exposed water systems were targeted in July cyberattacks, primarily linked to Iranian threat actors. The agency is urging water and wastewater utilities to significantly reduce th… SecurityWeek · 4d ago High IRUSiototcyberattack
threat-intel Hackers infect Android car systems to build proxy botnet Hackers are exploiting vulnerabilities in Chinese automotive software provider DoFun's Android car head units to build a proxy botnet. The malware, initially delivered through a legitimate system application (TWCore), al… The Record · 6d ago High CHGEandroidbotnetproxy
threat-intel The invisible passenger in your car Researchers at Securelist discovered a new Android malware campaign targeting automotive head units, orchestrated by the MoYu Group, a group linked to the BADBOX botnet. The malware, delivered through legitimate system u… Securelist · Aug 21, 2026 High androidiotbotnet
threat-intel Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 In July 2026, a significant wave of cybersecurity mergers and acquisitions occurred, with 21 deals announced. These transactions involved companies like Bank of America acquiring MDSec Consulting, Barracuda Networks acqu… SecurityWeek · Aug 13, 2026 Medium UNISTEmergersacquisitionscybersecurity
vulnerability Haiwell IoT Cloud HMI Gateway A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway, version 3.40.1.12. Exploitation could allow an attacker to execute arbitrary OS commands with root privileges, posin… CISA Advisories · Aug 13, 2026 Critical CVE-2026-19188cwe-78iotcommand injection
threat-intel Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th) This report details an experiment using a Large Language Model (Gemma4) to analyze malware hashes uploaded to the DShield sensor. The LLM was used to identify potential threats and recommend actions, focusing on a patter… SANS Internet Storm Center · Aug 13, 2026 High ailarge language modeldshield
threat-intel Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing A new version of the Kimwolf/AISURU Android and IoT botnet, Kimwolf v7, has been discovered by Palo Alto Networks Unit 42. This version significantly improves its operational resilience and DDoS attack capabilities by ut… The Hacker News · Aug 11, 2026 High botnetddosadb
threat-intel A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices Researchers at the University of Birmingham and Fuzzware discovered a vulnerability in cellular IoT devices that allows a malicious SIM card to execute commands on the device. The vulnerability stems from a SIM card's ab… The Hacker News · Aug 11, 2026 High CVE-2025-48618CVE-2026-57550CVE-2021-31698UNiotcellularsim card
threat-intel IT threat evolution in Q2 2026. Non-mobile statistics In Q2 2026, Kaspersky products blocked a massive 399.3 million attacks originating from online resources, highlighting a continued surge in ransomware activity and botnet attacks. The Qilin ransomware group dominated, ac… Securelist · Aug 10, 2026 High CVE-2026-33825CVE-2026-50751CVE-2026-50752NEGEUNransomwarebotnetsupply chain
threat-intel Water Sector Cyberattacks Reportedly Hit at Least 12 States A growing number of US states, including Minnesota, Michigan, and Georgia, are experiencing cyberattacks targeting water and wastewater facilities. The FBI has linked these attacks to Iran, specifically targeting interne… SecurityWeek · Aug 5, 2026 High IRicsiotcyberattack
vulnerability TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover Researchers at Forescout discovered 15 vulnerabilities in TP-Link’s Omada networking ecosystem’s zero-touch provisioning (ZTP) system, allowing attackers to potentially take over entire networks by chaining together thes… SecurityWeek · Aug 4, 2026 High CVE-2025-7850CVE-2025-7851ztpnetworkvulnerability
threat-intel ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks This week’s cybersecurity recap highlighted a concerning trend of AI-powered exploit generation, alongside a series of high-impact security incidents. A vulnerability in Coldcard hardware wallets led to an $88.6 million… The Hacker News · Aug 3, 2026 High CVE-2026-42897CVE-2026-66066CVE-2026-48449USIRaiexploithardware wallet
threat-intel US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States A coordinated cyberattack targeting the water and wastewater sector in the United States has expanded beyond Minnesota to at least seven states, with Iran suspected as the primary actor. The attacks are focused on operat… SecurityWeek · Aug 3, 2026 High IRUNAUotcyberattackiran
threat-intel Read This Before You Buy That TV Streaming Stick A security firm, Bitsight, uncovered a complex and widespread ad fraud network centered around H96 streaming devices. These devices, often sold by major retailers, are secretly used to generate revenue by masquerading as… Krebs on Security · Jul 30, 2026 High CHHOSIiotproxyad fraud
threat-intel Voiture connectée : quelles données guident l’entretien ? This article discusses the increasing collection of data by connected vehicles, particularly regarding climate control systems, and how this data can be used to predict maintenance needs. However, it also highlights the… ZATAZ · Jul 30, 2026 Medium data-privacyconnected-carsvehicle-security
threat-intel Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks Dozens of water utilities in Minnesota were targeted in a coordinated cyberattack on their operational technology (OT) systems. While services remained operational, attackers disrupted automated control functions, leadin… SecurityWeek · Jul 29, 2026 High IRiotindustrial control systemscyberattack