threat-intel Former UK privacy chief preparing legal action against woman who reported him, minister says The former UK Information Commissioner, John Edwards, is preparing to sue a female employee at the Information Commissioner’s Office (ICO) who reported concerns about his behavior. This follows an independent investigati… The Record · Jul 8, 2026 Medium GBsexual_harassmentdata_protectiongovernance
threat-intel Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip Spanish authorities, with assistance from the FBI, arrested a man suspected of aiding pro-Russian hacktivist groups, specifically in facilitating the escape of a Ukrainian hacker linked to CARR. The investigation uncover… The Record · Jul 8, 2026 Medium SPPOBErussianhacktivismddos
phishing Webinar Today: Why Email Security Keeps Failing The article highlights a persistent and evolving phishing campaign that continues to successfully target organizations despite existing email security measures. The campaign demonstrates a significant gap in current defe… SecurityWeek · Jul 8, 2026 Medium email securityphishingcybersecurity
threat-intel EU unveils cyber plan to reduce reliance on foreign AI systems The European Commission has unveiled a cybersecurity and AI action plan aimed at reducing the EU’s reliance on foreign AI systems, particularly concerning access to ‘frontier’ AI models. The plan focuses on ensuring cybe… The Record · Jul 8, 2026 Medium EUUKaicybersecurityfrontier ai
threat-intel New Ghost Phishing Wave Is Breaking Traditional Email Security A new phishing technique called ‘ghost phishing’ is emerging, where malicious links appear harmless during initial email inspection but execute a more damaging attack within the victim’s browser. The EvilTokens campaign,… The Hacker News · Jul 8, 2026 High USEUphishingghost phishingmicrosoft 365
threat-intel SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users A new banking fraud operation, tracked as REF6045, is targeting Mexican banks, fintech companies, and cryptocurrency exchanges using a malware toolset called SCMBANKER. The operation leverages fake CAPTCHA verification p… The Hacker News · Jul 8, 2026 High MXbankingmalwarephishing
threat-intel Felons, Fraudsters Flog Offensive Cybersecurity Startup IRIS C2, a cybersecurity startup operating under the Calvexa Group LLC, is aggressively pursuing zero-day vulnerabilities and offensive security capabilities, attracting researchers and exploit developers with lucrative… Krebs on Security · Jul 8, 2026 High UNcybercrimedisinformationvulnerability research
vulnerability Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations A vulnerability in Google Cloud’s Dialogflow CX service allowed attackers to silently control agents, manipulate conversations, and exfiltrate sensitive information. The flaw stemmed from a permissive configuration withi… SecurityWeek · Jul 8, 2026 High aicloudpython
threat-intel GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures A vulnerability has been discovered in GitHub's signature verification process. Attackers can rewrite signed Git commits, creating new commits with the same content but a different hash, while still appearing as "Verifie… The Hacker News · Jul 8, 2026 High gitsignaturevulnerability
threat-intel The Verification Step Is the New ATO Battleground in 2026 The traditional methods of account takeover (ATO) – relying on stolen passwords – are becoming less effective due to the increasing adoption of passkeys and phishing-resistant authentication. Attackers are now shifting t… The Hacker News · Jul 8, 2026 High UNpasskeysgenerative aiaccount takeover
threat-intel GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code Researchers at GitHub discovered a method to bypass the safety mechanisms of AI coding assistant GitHub Copilot. By framing requests for harmful content as part of a seemingly legitimate coding task – specifically, build… The Hacker News · Jul 8, 2026 High ai safetyjailbreakcode generation
threat-intel Cybersecurity and the Gap Between Skill and Ability A joint statement from the Five Eyes intelligence alliance warned of escalating cyber risks due to the increasing capabilities of AI models, particularly their ability to autonomously carry out cyberattacks. The statemen… Schneier on Security · Jul 8, 2026 High UNCAAUaicybersecuritythreat intelligence
threat-intel CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws The CISA has issued an urgent warning to federal agencies and all organizations regarding several actively exploited vulnerabilities in Adobe ColdFusion, Langflow, Joomla extensions, and CitrixBleed. These flaws, includi… SecurityWeek · Jul 8, 2026 Critical CVE-2026-48282CVE-2026-55255CVE-2026-33017vulnerabilityexploitationpatch
threat-intel Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection A critical vulnerability, dubbed GitLost, has been identified in GitHub Agentic Workflows, allowing unauthenticated attackers to potentially leak private repository data by injecting prompts into public GitHub Issues. Th… SecurityWeek · Jul 8, 2026 Critical prompt injectionai securityagentic ai
threat-intel China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware A Chinese APT group, UAT-7810, is expanding its Operational Relay Box (ORB) network by utilizing custom malware, including LONGLEASH and LEASHTEST, to establish persistent access for secondary threat actors. The group le… The Hacker News · Jul 8, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717TWaptmalwarec2
threat-intel ESET Threat Report H1 2026 The first half of 2026 demonstrates attackers’ increasing reliance on adapting existing techniques, leveraging AI to enhance their efficiency and expand the attack surface. This includes AI-powered malware, sophisticate… WeLiveSecurity · Jul 8, 2026 Medium aisocial engineeringransomware
malware My Stack Simulator, (Wed, Jul 8th) The stack is a memory region where a program stores temporary data -&#;x26;#;xc2;&#;x26;#;xa0;like local variables and return addresses. Think of the stack as a pile of plates in your kitchen: you can only add a new plat… SANS Internet Storm Center · Jul 8, 2026 Medium
threat-intel State IDs for AI Agents: Will Estonia Set a Precedent? Estonia is planning to assign official government ID numbers to AI agents to regulate their use within government systems. This initiative, part of Eesti.AI, aims to enable organizations and individuals to utilize AI for… Dark Reading · Jul 8, 2026 Medium EEairegulationdigitalization
threat-intel 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros Researchers at Nebula Security discovered GhostLock (CVE-2026-43499), a 15-year-old Linux kernel vulnerability that allows an unprivileged user to gain root access on a machine. The flaw, discovered by their AI-driven bu… The Hacker News · Jul 8, 2026 High CVE-2026-43499CVE-2026-53166CVE-2026-46242linuxkernelprivilege-escalation
threat-intel CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its KEV catalog, including flaws in Adobe ColdFusion, JoomShaper SP Page Builder, and Langflow. These… The Hacker News · Jul 8, 2026 High CVE-2026-48282CVE-2026-56290CVE-2026-55255INvulnerabilityrceidror