threat-intel Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments Threat actors are exploiting prompt injection vulnerabilities in AI agents to trick them into making cryptocurrency payments and promoting fraudulent platforms. Zscaler identified two campaigns utilizing SEO poisoning an… SecurityWeek · Jul 6, 2026 Medium prompt-injectionaicybersecurity
threat-intel Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT A China-nexus threat actor is conducting a targeted phishing campaign against Indian taxpayers and tax professionals, leveraging fake tax filing utilities to deploy a remote access trojan (DcRAT). The campaign, dubbed Op… The Hacker News · Jul 6, 2026 High CHINphishingremote access trojantax
threat-intel France to Stop Certifying Non-Quantum-Safe Encryption France’s cybersecurity agency, ANSSI, is implementing a significant shift in encryption standards. Starting in 2027, they will no longer certify security products that don't offer quantum-resistant encryption, effectivel… Schneier on Security · Jul 6, 2026 Medium FRencryptionquantumcybersecurity
threat-intel When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website A sophisticated phishing campaign leveraging the Microsoft Identity Platform's Device Authorization Grant protocol is being used to compromise user accounts. Attackers are crafting emails that appear to be from legitimat… Securelist · Jul 6, 2026 High phishingdevice-code-phishingmicrosoft
threat-intel New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions Researchers at Shandong University have developed a new technique called TrojPix that allows data to be exfiltrated from air-gapped systems by subtly modulating pixels on a screen and transmitting them as a radio signal.… The Hacker News · Jul 6, 2026 Medium air-gapdata exfiltrationpixel modulation
threat-intel New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS A new Java-based remote access trojan (RAT) called QuimaRAT, offered as a malware-as-a-service (MaaS), has been released by a threat actor. The tool is cross-platform, supporting Windows, Linux, and macOS, and is adverti… The Hacker News · Jul 6, 2026 High javaratmalware-as-a-service
threat-intel Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages A vulnerability in Opera GX allowed malicious websites to silently install browser add-ons that could steal data from visited pages. Researchers demonstrated how a malicious iframe could install a mod, which then injecte… The Hacker News · Jul 6, 2026 High browsercssdata-theft
threat-intel SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing Researchers at the Hong Kong University of Science and Technology have developed a method to bypass AI coding agent scanners by using self-extracting packing and character substitution to disguise malicious skills. Their… The Hacker News · Jul 6, 2026 High aiskillsmalware
vulnerability Multiples vulnérabilités dans Roundcube (06 juillet 2026) Multiple vulnerabilities have been discovered in Roundcube Webmail, impacting versions 1.6.x (prior to 1.6.17) and 1.7.x (prior to 1.7.2). These vulnerabilities include denial-of-service attacks, server-side request forg… CERT-FR · Jul 6, 2026 Medium CVE-2026-54432CVE-2026-54433CVE-2026-62641webmailvulnerabilityssrf
threat-intel U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case A U.S. government entity reportedly paid $1 million to the group known as Kairos to prevent the leak of stolen data following a data breach at Union County, Ohio. Kairos, however, operated solely through data theft extor… The Hacker News · Jul 4, 2026 High USRUdatatheftextortionnegotiation
threat-intel North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign North Korean threat actors, linked to the Contagious Interview campaign, have been publishing 108 malicious packages and extensions across platforms like npm, Packagist, and Go, as part of the PolinRider operation. This… The Hacker News · Jul 4, 2026 High KPnorth koreangithubmalware
vulnerability Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices This article details seven vulnerabilities discovered in the FatFs filesystem library, commonly used in embedded devices like security cameras, drones, and industrial controllers. The vulnerabilities, ranging from intege… The Hacker News · Jul 3, 2026 High CVE-2026-6682CVE-2026-6687CVE-2026-6688embeddedfilesystemfirmware
vulnerability New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android A newly discovered Linux kernel vulnerability, dubbed "Bad Epoll" (CVE-2026-46242), allows unprivileged users to gain root access on systems, including Android devices. The flaw, a "use-after-free" bug, was identified by… The Hacker News · Jul 3, 2026 High CVE-2026-46242CVE-2026-43074CVE-2026-31431USUKlinuxkernelepoll
ransomware New Avalon Malware Framework Packs CrownX Ransomware Capabilities Researchers at Blackpoint Cyber discovered Avalon, a new modular malware framework used to deploy the CrownX ransomware. The framework utilizes a multi-stage phishing campaign to bypass security controls and performs cre… The Hacker News · Jul 3, 2026 High CVE-2025-3248USphishingcredential theftlateral movement
threat-intel North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets North Korean-linked threat actors are deploying malicious npm packages that mimic Rollup polyfill tooling to steal developer secrets. These packages, including 'rollup-packages-polyfill-core' and 'rollup-runtime-polyfill… The Hacker News · Jul 3, 2026 High KPnpmthreat-actornorth korea
threat-intel In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting This report details several significant cybersecurity events across multiple sectors, including a Canadian hacker’s imprisonment for a Texas GOP cyberattack, a large KDDI data breach impacting 14 million users, and the d… SecurityWeek · Jul 3, 2026 High CAJAUNzero-dayhacktivismdata breach
threat-intel Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer Armored Likho, a previously undocumented threat actor, has been actively targeting government agencies and the power sector in Russia, Brazil, and Kazakhstan with a sophisticated campaign utilizing tools like BusySnake S… The Hacker News · Jul 3, 2026 High CVE-2025-9491RUBRKZspear-phishingremote access trojaninformation stealer
threat-intel Chinese LLMs Broaden the Gap Between Attackers & Defenders This article reports on the emergence of new Chinese AI models, GLM 5.2 and Tulongfeng (Dragon Saber), which are demonstrating strong performance in vulnerability discovery, rivaling leading US models like Opus and GPT-5… Dark Reading · Jul 3, 2026 High CHUSaivulnerabilitychina
threat-intel Cyber readiness for SMBs: Getting the basics right This article highlights the ongoing importance of traditional cybersecurity threats for small and medium-sized businesses (SMBs), despite growing concerns about AI-powered attacks. The primary risks remain phishing, unpa… WeLiveSecurity · Jul 3, 2026 Medium USphishingvulnerabilityai
Flock Cameras Can Surveil Cars Without License Plates This is from a 2024 company presentation : Officers can also tap into data showing a car’s decals, bumper stickers, back and top racks—along with temporary and unique state tags. Flock calls it a “Vehicle Fingerprint” an… Schneier on Security · Jul 3, 2026 High