ransomware Amadey, StealC malware operations disrupted in Operation Endgame action Operation Endgame, a coordinated law enforcement effort involving Microsoft, Europol, and international partners, successfully disrupted infrastructure used by the Amadey and StealC malware operations. The operation resu… BleepingComputer · Jun 24, 2026 High USCADKmalware-as-a-servicecredential theftransomware
threat-intel Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed This SecurityWeek article highlights the critical importance of accurate context for agentic AI systems, particularly in security applications. The piece explains that agentic AI, relying on speed and automation, can mak… SecurityWeek · Jun 24, 2026 High USGBagentic aillmcontext
supply-chain OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat This report details a significant supply chain attack leveraging OpenClaw’s Skill Marketplace, highlighting the emerging threat of AI agentic software. Malicious skills, including infostealers and evasion techniques, wer… Palo Alto Unit 42 · Jun 23, 2026 High USaiagenticsupply chain
threat-intel ISC Stormcast For Tuesday, June 23rd, 2026 https://isc.sans.edu/podcastdetail/9982, (Tue, Jun 23rd) The SANS Internet Storm Center's Stormcast for June 23rd, 2026, reported a heightened level of online threats and potential disruptions. The broadcast highlighted several ongoing campaigns and emerging vulnerabilities th… SANS Internet Storm Center · Jun 23, 2026 Medium stormcastthreat intelligencephishing
threat-intel A Glimpse into the “Search Your Target” Market for Stolen Credentials This report details a growing underground market where threat actors are offering ‘search your target’ services, leveraging massive collections of stolen credentials. Researchers analyzed 470 forum posts revealing a serv… BleepingComputer · Jun 22, 2026 High UScredential theftinfostealerunderground market
phishing ISC Stormcast For Monday, June 22nd, 2026 https://isc.sans.edu/podcastdetail/9980, (Mon, Jun 22nd) The SANS Internet Storm Center's June 22nd, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observ… SANS Internet Storm Center · Jun 22, 2026 Medium phishingemailthreat
supply-chain Microsoft links Mastra AI supply chain attack to North Korean hackers Microsoft has attributed a recent supply chain attack targeting over 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. The attack involved compromising an npm maintainer account… BleepingComputer · Jun 20, 2026 High KPsupply-chainnpmcryptocurrency
threat-intel Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way This article highlights a growing security risk within organizations due to the widespread adoption of AI agents. Traditional identity security models, built around controlling employee and service accounts, are being by… BleepingComputer · Jun 19, 2026 High aiartificial intelligenceidentity management
threat-intel Forget Data Leakage: Shadow AI's Real Threat Is Access Control This article highlights a shift in the security landscape surrounding AI, moving beyond simple data leakage concerns to a more critical issue of access control. Employees are increasingly deploying custom AI agents acros… The Hacker News · Jun 19, 2026 High USaishadow itaccess control
threat-intel 5 reasons Microsoft 365 backup isn’t enough for business data protection This article highlights the limitations of relying solely on Microsoft 365’s built-in backup and retention policies for business data protection. It argues that organizations need a third-party solution to adequately add… BleepingComputer · Jun 18, 2026 High ransomwarebackupdata protection
threat-intel No Exploits Required This article discusses the limitations of relying solely on exploiting vulnerabilities in cybersecurity, arguing that defenders often struggle due to the inherent complexity and interconnectedness of modern networks. The… SecurityWeek · Jun 18, 2026 Medium network securitycybersecurityzero-trust
threat-intel ISC Stormcast For Thursday, June 18th, 2026 https://isc.sans.edu/podcastdetail/9978, (Thu, Jun 18th) The SANS Internet Storm Center's June 18th, 2026 Stormcast reported a heightened level of online threats and unusual network activity across various sectors. The broadcast highlighted several emerging trends, including i… SANS Internet Storm Center · Jun 18, 2026 Medium phishingdnsthreat-monitoring
threat-intel Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline A junior hacker, identified as ‘Poisson,’ infiltrated a French automotive business by exploiting vulnerabilities and establishing persistent access after his command-and-control server was taken down. He utilized OpenSSH… The Hacker News · Jun 17, 2026 Medium FRDEpersistenceremote-accessssh
malware Rokarolla Android Trojan Levels Up to Full Device Control, Persistence The Rokarolla Android Trojan has evolved to offer full device control and persistence, moving beyond typical banking Trojan capabilities. Distributed through fake Chrome and TikTok downloads, the malware steals credentia… Dark Reading · Jun 16, 2026 High USandroidbanking trojandevice control
threat-intel North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels North Korean threat actors, operating under the UNK_DeadDrop campaign, are employing a sophisticated phishing technique targeting developers across numerous sectors, including finance and cryptocurrency, using malicious… The Hacker News · Jun 15, 2026 High USGBAUdevelopergithubvscode
threat-intel ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More This week’s cybersecurity recap highlights several active exploits and attacks, including a Chrome 0-day being actively leveraged, a ShinyHunters gang exploiting a PeopleSoft zero-day for lateral movement and data exfilt… The Hacker News · Jun 15, 2026 High CVE-2026-11645CVE-2026-2441CVE-2026-3909UNCHzero-dayphishingsupply-chain
threat-intel EvilTokens: A phishing attack that doesn’t steal your password EvilTokens is a sophisticated phishing-as-a-service (PaaS) kit that bypasses traditional phishing defenses by leveraging the OAuth 2.0 device authorization grant flow. Attackers use convincing lures – often mimicking leg… WeLiveSecurity · Jun 15, 2026 High phishingoath2device-code
phishing Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts A coordinated phishing campaign, spearheaded by the now-disrupted Sniper Dz platform, targeted users in the Middle East and North Africa (MENA) through deceptive Facebook offers. The campaign leveraged browser notificati… The Hacker News · Jun 15, 2026 High DZALAEphishingsocial engineeringbrowser notifications
phishing ISC Stormcast For Monday, June 15th, 2026 https://isc.sans.edu/podcastdetail/9972, (Mon, Jun 15th) The SANS Internet Storm Center's June 15th, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observ… SANS Internet Storm Center · Jun 15, 2026 Medium phishingbotnetddos
threat-intel ISC Stormcast For Friday, June 12th, 2026 https://isc.sans.edu/podcastdetail/9970, (Fri, Jun 12th) The SANS Internet Storm Center's June 12th, 2026 Stormcast reported a heightened level of online threats and unusual network activity across various sectors. The broadcast highlighted several emerging trends, including i… SANS Internet Storm Center · Jun 12, 2026 Medium phishingdnsvulnerability