threat-intel ISC Stormcast For Wednesday, July 8th, 2026 https://isc.sans.edu/podcastdetail/9998, (Wed, Jul 8th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. Specifically, the report… SANS Internet Storm Center · Jul 8, 2026 High icsotvulnerability
threat-intel Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation A financially motivated campaign utilizing Vidar stealer and XMRig cryptocurrency miner has been active since April 2026, targeting consumers and small- and medium-sized businesses globally, primarily in the U.S. and EU.… Palo Alto Unit 42 · Jul 7, 2026 High USDEmalvertisingdll hijackinganti-forensic
phishing Big Brand Jobs Scam Targets Marketing Pros' Google Accounts A sophisticated phishing campaign is targeting marketing professionals by impersonating major brands like Coca-Cola, Louis Vuitton, and McKinsey & Company to steal their Google credentials. The campaign utilizes nested r… Dark Reading · Jul 7, 2026 Medium USphishingcredential theftnested redirects
threat-intel Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft Google has patched a critical vulnerability in its Dialogflow CX AI chatbot platform, dubbed 'Rogue Agent,' which could have allowed attackers to steal data from AI agents. The flaw stemmed from a permission boundary iss… Dark Reading · Jul 7, 2026 High aichatbotcodeblocks
threat-intel More Odd DNS Records: NIMLOC, (Tue, Jul 7th) This article discusses the continued use of NIMLOC DNS records, an obsolete record type originally designed for the Nimrod routing architecture. Despite the demise of NetBIOS and the shift to modern DNS and SMB protocols… SANS Internet Storm Center · Jul 7, 2026 Info dnsnetbiosmac
data-breach County Government Reportedly Paid $1 Million to Cyber Extortion Group A small county government in Ohio reportedly paid $1 million to the Kairos cyber extortion group to prevent the release of stolen data following a brute-force attack in May 2025. The attackers, Kairos, demanded $3 millio… SecurityWeek · Jul 7, 2026 High USdata breachransomwaregovernment
threat-intel Critical Gitea Flaw Under Active Exploitation, Researchers Warn A critical vulnerability in Gitea’s reverse-proxy authentication mechanism is being actively exploited, allowing attackers to bypass authentication and gain unauthorized access to Gitea instances. The flaw, tracked as CV… SecurityWeek · Jul 7, 2026 Critical CVE-2026-20896vulnerabilityauthenticationgit
threat-intel RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service A new Android malware operation, RedWing, is being sold on Telegram as a ready-made bank fraud service. Developed by a Russian threat actor group, RedWing allows even unskilled criminals to steal banking logins and one-t… The Hacker News · Jul 7, 2026 High RUandroidmalwarefraud
vulnerability Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots A critical vulnerability, dubbed ‘Rogue Agent,’ within Google's Dialogflow CX platform allowed a malicious insider or compromised developer account to compromise multiple chatbot agents within the same Google Cloud proje… The Hacker News · Jul 7, 2026 High dialogflowcodeblockscloud run
policy Supreme Court allows Texas app law requiring age verification to take effect The Supreme Court has allowed a Texas law requiring age verification for apps to take effect while a lower court considers its constitutionality. This law mandates that app developers and stores use age verification tool… The Record · Jul 7, 2026 Info USprivacyregulationfirst amendment
threat-intel Britain plans to build autonomous AI 'Cyber Shield' to defend nation The UK’s National Cyber Security Centre (NCSC) is developing an AI-powered ‘Cyber Shield’ to bolster national cybersecurity defenses against increasingly sophisticated and rapid attacks. This initiative aims to automate… The Record · Jul 7, 2026 High UKaicybersecuritynational defense
threat-intel 'GitLost' Flaw Leaks Private Data from GitHub's Agentic Workflows A critical prompt injection vulnerability, dubbed ‘GitLost,’ has been discovered in GitHub’s Agentic Workflows, allowing unauthenticated attackers to steal private data from an organization’s repositories by crafting a G… Dark Reading · Jul 7, 2026 High prompt injectionagentic aisecurity vulnerability
threat-intel DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts A Microsoft 365 device code phishing campaign, leveraging collaboration-themed lures, has been observed targeting M365 accounts. The campaign, utilizing a reusable tooling layer called DEBULL, bypasses multi-factor authe… The Hacker News · Jul 7, 2026 High HRTRdevice-codephishingmicrosoft
data-breach Major Japanese telco says cyberattack exposed 12 million emails KDDI, a major Japanese telecommunications company, disclosed that a cyberattack exposed the email addresses and passwords of over 12 million customers due to a vulnerability in third-party software. The breach impacted a… The Record · Jul 7, 2026 Medium JPdata breachpasswordvulnerability
threat-intel Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data Researchers at Noma Security discovered a vulnerability, dubbed ‘GitLost,’ in GitHub Agentic Workflows that allows attackers to trick AI agents into leaking private repository content simply by posting a malicious issue… The Hacker News · Jul 7, 2026 High prompt injectionai agentgithub
threat-intel Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker U.S. prosecutors have linked an alleged Scattered Spider hacker, Peter Stokes, to a luxury jewelry retailer breach through a persistent Windows device ID. Stokes, a dual U.S.-Estonian citizen, was extradited from Finland… The Hacker News · Jul 7, 2026 High ESFIUNdevice-idhackerintrusion
threat-intel Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants A critical session isolation vulnerability, dubbed WriteOut, has been discovered in Writer, an AI platform, allowing attackers to steal session tokens and gain control of user accounts across multiple organizations. The… The Hacker News · Jul 7, 2026 Critical session-hijackingtenant-isolationai
threat-intel CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws The US Cybersecurity and Infrastructure Security Agency (CISA) is leveraging Anthropic’s AI model, Mythos, to proactively scan federal government software for security vulnerabilities. This initiative is part of a broade… SecurityWeek · Jul 7, 2026 Medium USaiintelligencevulnerability
threat-intel UK cyber pledge draws only a handful of top firms despite ministerial appeal Despite a strong push from the UK government, only a small number of companies – around 15 out of 350 – signed the Cyber Resilience Pledge. The pledge, designed to improve cybersecurity across the UK economy, requires co… The Record · Jul 7, 2026 Medium UKcybersecuritycyber resiliencevoluntary pledge
threat-intel Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud Two men were arrested in the Netherlands on suspicion of running a phishing operation targeting credit card details, leading to a significant increase in payment fraud within the country. The Dutch central bank reported… Graham Cluley · Jul 7, 2026 High NLEUphishingcredit card fraudcybercrime