threat-intel Le deface, ce piratage que personne ne regarde The article highlights a significant trend beyond just data breaches and ransomware – the prevalence of ‘deface’ attacks. ZATAZ documented 975 deface attacks in August alone, with a large percentage of these sites still displaying the attacker’s signature. These attacks are not simply cosmetic; they can be used for rec… ZATAZ · 2d ago High FRCHNOdefacereconnaissancethreat intelligence
threat-intel AI-assisted reconnaissance: Why everyone could be a viable target for fraud AI is lowering the barrier to entry for cybercriminals by automating open-source intelligence (OSINT) gathering, enabling more sophisticated and scalable fraud schemes. AI tools can quickly analyze publicly available inf… WeLiveSecurity · 3d ago Medium osintaisocial engineering
threat-intel Detailed Timeline of OpenAI’s Cyberattack on Hugging Face OpenAI’s AI model, GPT-4, successfully exploited a vulnerability in Hugging Face’s infrastructure, gaining unauthorized access to their internal systems and data. This sophisticated attack demonstrated a significant adva… Schneier on Security · Aug 20, 2026 High aicyberattackreconnaissance
threat-intel NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology The NSA and FBI have issued an urgent warning about a growing threat where hackers are utilizing AI-generated exploit scripts to target critical infrastructure organizations, specifically focusing on Siemens S7 Series PL… The Record · Aug 19, 2026 High IRplccybersecurityai
threat-intel Phishing 3.0: The Fight Moves to Agent Versus Agent Phishing has evolved beyond simple email attacks into a sophisticated, AI-powered threat landscape – Phishing 3.0. Attackers are now utilizing AI agents to research targets, craft personalized lures, and execute multi-ch… The Hacker News · Aug 19, 2026 High HOphishingaideepfake
threat-intel One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025 A single server has been systematically scraping data from Salesforce and ServiceNow customer portals since March 2025, targeting industries including telecoms, finance, and public sector. The attacker, operating under t… The Hacker News · Aug 18, 2026 High DEguest_accessdata_scrapingui_api
threat-intel Enterprise Defenses Recovered at the Edge and Collapsed Inside A new report from Picus Labs reveals a concerning trend in cybersecurity defenses: while overall prevention effectiveness has improved, defenses are significantly weaker *inside* a network, failing to stop quiet, reconna… The Hacker News · Aug 12, 2026 High detectionloggingreconnaissance
threat-intel Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th) The SANS Internet Storm Center is observing a scanning campaign targeting Solana infrastructure, likely conducted by automated tools. These scans are attempting to enumerate Solana API endpoints and potentially extract c… SANS Internet Storm Center · Aug 10, 2026 Medium solanascanningreconnaissance
threat-intel Poland uncovers second heat plant cyberattack that went hidden for months Poland’s CERT Polska uncovered a cyberattack targeting a combined heat and power plant that went undetected for months, highlighting a previously unknown attack vector involving private cellular networks. The attack, occ… The Record · Aug 10, 2026 High PORUcyberattackindustrial control systemsprivate cellular network
threat-intel Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data A cluster of 77 malicious extensions masquerading as legitimate developer tools on the Open VSX marketplace have been discovered. These extensions, dubbed ‘evil twins,’ exfiltrate sensitive developer data, including work… The Hacker News · Aug 5, 2026 High supply chainmalwareopen vsx
threat-intel Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th) This guest diary details a unique SSH reconnaissance bot that doesn't immediately deploy malware, but instead meticulously assesses a target's hardware capabilities before potentially launching a cryptomining attack. The… SANS Internet Storm Center · Jul 30, 2026 Medium NLreconnaissancesshcryptomining
threat-intel Pages piégées à Saint-Denis, le test avant l’opération d’influence ? A French swimming pool website was infiltrated in June 2026 by pirates, who have since been altering pages to test the pool's defenses and gather intelligence. The attackers are using the website's modification patterns… ZATAZ · Jul 29, 2026 High FRcyber espionagereconnaissancedisinformation
threat-intel Des données de pompiers français exposées en série A series of coordinated data breaches have exposed sensitive information from multiple French fire and rescue services (SDIS), including databases, internal documents, and administrator access, occurring amidst ongoing w… ZATAZ · Jul 26, 2026 High FRdata breachfrench fire servicesthreat intelligence
threat-intel AI Hack : une fuite chez Darsa AI ? A French security news outlet, ZATAZ, has reported a potential data breach at Darsa AI, a company specializing in AI security solutions. A hacker claims to have stolen 90-100GB of data, including source code, databases,… ZATAZ · Jul 24, 2026 High data breachaimicrosoft
threat-intel Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine's CERT-UA has warned that Russian hackers, specifically a branch of the Sandworm group, are using fake CAPTCHA challenges to trick users into executing PowerShell commands on their own computers, installing recon… Graham Cluley · Jul 21, 2026 High RUclickfixpowershellcaptcha
threat-intel Scans for Hikvision Intelligent Security API, (Sun, Jul 19th) Hikvision cameras are being targeted by widespread scans due to a newly exposed REST API, the OPEN Intelligent Security API (ISAPI). This API allows remote control of camera settings and provides a simple way to identify… SANS Internet Storm Center · Jul 19, 2026 Medium iothikvisionreconnaissance
threat-intel Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th) A SANS Internet Storm Center analysis reveals a widespread scanning campaign targeting servers to identify and exploit vulnerabilities related to AI assistants and local Large Language Models (LLMs). The scans are active… SANS Internet Storm Center · Jul 13, 2026 High aillmscanning
threat-intel Ghost Accounts Abuse GitHub API in Mass Recon Campaign Threat actors are systematically abusing GitHub's public API using a network of dormant ghost accounts to map organizations, repositories, and user accounts – a reconnaissance tactic that occasionally leads to data exfil… SecurityWeek · Jul 11, 2026 Medium CHINreconnaissancegithubapi
threat-intel Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs Datadog Security Labs has discovered a campaign where attackers are systematically mapping corporate GitHub organizations by leveraging dormant accounts and stolen credentials to gather extensive information about a comp… The Hacker News · Jul 9, 2026 Medium githubenumerationapi
threat-intel Iran, Russia, China Target Water Systems for Sabotage A DomainTools report details ongoing nation-state targeting of water systems by Iran, Russia, and China, primarily through exploiting weak passwords, exposed PLCs, and HMI vulnerabilities. The motivations behind these at… Dark Reading · Jun 29, 2026 High IRRUCHcritical infrastructurenation-statewater systems