vulnerability CitrixBleed-ing Again? NetScaler Vulnerability Under Attack A vulnerability in Citrix's NetScaler products has quickly been exploited by attackers following the release of a proof-of-concept exploit. The flaw allows attackers to potentially gain unauthorized access to systems, hi… Dark Reading · Jul 6, 2026 High memory-disclosurecitrixvulnerability
threat-intel Canadian spy agency reports hacking three criminal groups in 2025 The Canadian Communications Security Establishment (CSE) conducted several authorized cyber operations targeting foreign criminal groups in 2025. These operations aimed to disrupt extremist groups spreading violent ideol… The Record · Jul 6, 2026 Medium CAcybersecuritynational securitycyber espionage
threat-intel Attackers vote themselves $20 million in BONK cryptocurrency Attackers exploited a governance mechanism within the decentralized finance project overseeing BONK cryptocurrency, draining $20 million worth of the token. This was achieved through a malicious governance proposal, leve… The Record · Jul 6, 2026 High KRdaogovernancecryptocurrency
threat-intel Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks Securonix researchers identified a complex malware delivery framework called ‘Veil#Drop’ that utilizes compromised websites, specifically Blogspot, to deploy information-stealing malware. The framework employs multiple l… SecurityWeek · Jul 6, 2026 High malwareinformation stealerevasion
threat-intel Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations Iranian hackers, linked to Iran's Ministry of Intelligence and Security (MOIS) and operating under the moniker Cavern Manticore, are utilizing a new, modular command-and-control (C2) framework called ‘Cavern’ to target I… The Hacker News · Jul 6, 2026 High CVE-2025-52691CVE-2025-68613CVE-2025-9316ISIRc2command and controldotnet
data-breach Major medical device manufacturer notifies nearly 4 million of breach Medtronic, a leading medical device manufacturer, has notified nearly 4 million individuals that their data may have been compromised in a cyberattack. The breach was linked to the ShinyHunters cybercrime group and resul… The Record · Jul 6, 2026 High data breachcybersecuritymedical devices
threat-intel 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems A 16-year-old use-after-free vulnerability in Linux's KVM hypervisor, dubbed ‘Januscape’ (CVE-2026-53359), allows guest virtual machines to corrupt the host kernel's shadow-page state. Researcher Hyunwoo Kim discovered t… The Hacker News · Jul 6, 2026 High CVE-2026-53359CVE-2026-43284CVE-2026-43500use-after-freeshadow pagenested virtualization
threat-intel Japanese teen arrested over cyberattack that disrupted anime streaming service A 15-year-old Japanese student was arrested for a cyberattack that disrupted an anime streaming service, Bandai Channel. The suspect exploited a vulnerability in the service’s servers and used ChatGPT to automate the fra… The Record · Jul 6, 2026 Medium JPcyberattackvulnerabilitychatgpt
threat-intel JadePuffer: The First Complete LLM-Driven Ransomware Attack Sysdig researchers have identified ‘JadePuffer,’ the first documented case of a fully autonomous ransomware operation driven by a large language model (LLM). The attack leveraged a Langflow vulnerability to gain initial… Dark Reading · Jul 6, 2026 High CVE-2025-3248airansomwarellm
threat-intel Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure Threat actors have been actively probing a critical vulnerability in Gitea Docker images, exploiting a wildcard configuration that allows unauthenticated access to elevated user accounts. The vulnerability, discovered 13… The Hacker News · Jul 6, 2026 Critical CVE-2026-20896dockervulnerabilityauthentication
threat-intel The Shift Toward Business-Aligned Risk Management This article discusses the shift towards business-aligned risk management within organizations. Traditional risk assessments, often relying on CVSS scores, can be ineffective without connecting them to tangible business… SecurityWeek · Jul 6, 2026 Medium risk managementcybersecurityvulnerability
apt Armored Likho APT Targeting Government, Electric Power Entities The Armored Likho APT group is actively targeting government and electric power entities across multiple countries, including Russia, Brazil, and Kazakhstan. The group utilizes a diverse toolkit of malware, including RAT… SecurityWeek · Jul 6, 2026 High RUBRKZaptspear-phishingrat
threat-intel RCS and DNS: The NAPTR Record, (Mon, Jul 6th) This article details the observation of NAPTR records being utilized in RCS (Rich Communication Services) communications, specifically within Verizon’s network. NAPTR records, defined in RFC 2915, are typically used to r… SANS Internet Storm Center · Jul 6, 2026 Medium USrcsdnsnaptr
threat-intel Ukrainian media outlets now among 'priority targets' for Russian hackers Ukrainian media outlets are increasingly becoming priority targets for Russian hackers as part of a broader campaign to undermine public trust and spread propaganda amid Russia’s ongoing invasion of Ukraine. Recent attac… The Record · Jul 6, 2026 High UKRUcyberattacksukrainerussia
supply-chain North Korean Hackers Target Open Source Developers in Supply Chain Attacks North Korean hackers, linked to the Contagious Interview operation, are engaging in a sophisticated supply chain attack targeting open-source developers. They are leveraging compromised GitHub repositories and malicious… SecurityWeek · Jul 6, 2026 High KRsupply-chaingithubopen-source
threat-intel ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More This week’s security recap highlighted several concerning trends, including a disruption of the NetNut residential proxy network used for botnet operations, a fake Proof-of-Concept (PoC) malware targeting vulnerability r… The Hacker News · Jul 6, 2026 High CVE-2026-48276CVE-2026-48283CVE-2026-48277USESSPbotnetproxymalware
threat-intel Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability A proof-of-concept exploit for a Linux kernel vulnerability, dubbed ‘Bad Epoll,’ has been released, allowing unprivileged processes to gain root access on various devices. The vulnerability stems from a race condition wi… SecurityWeek · Jul 6, 2026 High CVE-2026-46242CVE-2026-43074linuxkernelvulnerability
threat-intel ISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. Specifically, the report… SANS Internet Storm Center · Jul 6, 2026 High icsotindustrial control systems
threat-intel How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions This article discusses the evolving landscape of AI-powered Security Operations Centers (SOCs). It differentiates between ‘bolt-on’ AI solutions, which simply summarize alerts within a traditional SIEM, and true AI SOC p… The Hacker News · Jul 6, 2026 Medium aisocsecurity
threat-intel Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments Threat actors are exploiting prompt injection vulnerabilities in AI agents to trick them into making cryptocurrency payments and promoting fraudulent platforms. Zscaler identified two campaigns utilizing SEO poisoning an… SecurityWeek · Jul 6, 2026 Medium prompt-injectionaicybersecurity