phishing ISC Stormcast For Thursday, July 2nd, 2026 https://isc.sans.edu/podcastdetail/9992, (Thu, Jul 2nd) The SANS Internet Storm Center's July 2nd, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing and malicious email campaigns. The broadcast highlighted several emerging trends and… SANS Internet Storm Center · Jul 2, 2026 Medium phishingemailthreat-intelligence
vulnerability Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack? This article discusses a security vulnerability discovered in Fortinet’s FortiBleed, a tool designed to securely dispose of sensitive data. A researcher identified a flaw allowing unauthorized access to sensitive data, h… Graham Cluley · Jul 1, 2026 High vulnerabilityfortinetsecurity
phishing Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS This article details a concerning trend in phishing attacks where threat actors are leveraging user-agent data to dynamically adapt their campaigns to the specific device and operating system of the victim. Attackers are… Dark Reading · Jul 1, 2026 High USphishinguser-agentmalware
ransomware Teen suspect in Scattered Spider hacks is extradited to US A 19-year-old man, Peter Stokes, with dual citizenship, has been extradited to the United States to face charges related to his involvement with the Scattered Spider cybercrime group. The investigation centers around a r… The Record · Jul 1, 2026 High USESFIphishingsocial engineeringransomware
threat-intel And the Winner in Dominant Malware Delivery? ClickFix ClickFix, a social engineering technique where attackers trick users into executing malicious commands via error messages, has become the dominant method for malware delivery, according to a recent ReliaQuest analysis. T… Dark Reading · Jul 1, 2026 High USsocial engineeringmalware deliveryobfuscation
threat-intel Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters An unpatched vulnerability in Argo CD's repo-server component allows unauthenticated attackers to take over Kubernetes clusters by exploiting a lack of authentication and network policies. Synacktiv discovered the flaw i… The Hacker News · Jul 1, 2026 Critical CVE-2024-31989CVE-2025-55190CVE-2026-42880kubernetesargo cdnetwork policy
threat-intel 19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges This article reports the extradition of a 19-year-old, Peter Stokes, known as "Bouquet," from Finland to the United States to face charges related to computer intrusion, fraud, and conspiracy as part of the Scattered Spi… The Hacker News · Jul 1, 2026 High USFIUKsocial engineeringphishinghelp desk
Microsoft Adds New Teams Controls to Block Unauthorized AI Bots From Meetings Microsoft's new Teams admin policy requires organizer approval for external AI bots, giving organizations greater visibility and control over automated participants in sensitive meetings. The post Microsoft Adds New Team… SecurityWeek · Jul 1, 2026
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT. Kaspersky said the activity is part of a "massive, multi-domain, multi-language" campaign that distribute… The Hacker News · Jul 1, 2026
malware VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer A new multi-stage malware attack chain, dubbed VEIL#DROP, is utilizing social engineering and Blogger pages to deliver the PureLogs stealer. The attack begins with a deceptive JavaScript file, leveraging Google's infrast… The Hacker News · Jul 1, 2026 High USspear-phishingbloggerpurelogs
threat-intel When Too Much Security Data Became the Risk This article details how Vensure Employer Solutions, an HR services provider, struggled with the exponential growth of telemetry data flowing into its SIEM environment due to rapid acquisitions and expansion. The overwhe… Dark Reading · Jul 1, 2026 Medium telemetrysiemdata-overload
malware Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures The Ousaban banking trojan, originating in Brazil and previously tracked as Javali, is targeting Windows users in Spain and Portugal with a phishing campaign utilizing fake PDF lures. The trojan, which has evolved over t… The Hacker News · Jul 1, 2026 High PTESbanking trojanphishinggeofencing
vulnerability Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic Adobe has released critical security patches for vulnerabilities in both ColdFusion and Adobe Campaign Classic, addressing flaws with CVSS scores of up to 10.0. These vulnerabilities could allow for remote code execution… The Hacker News · Jul 1, 2026 Critical CVE-2026-48276CVE-2026-48283CVE-2026-48277adobevulnerabilitycode execution
threat-intel 'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat This article details a new supply chain threat dubbed "Phantom Squatting," where large language models (LLMs) are hallucinating non-existent web domains linked to legitimate brands. Cybercriminals are exploiting this by… Dark Reading · Jul 1, 2026 High USllmsupply chainai
threat-intel Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands A critical vulnerability, dubbed DuneSlide, has been discovered in Cursor, an AI code editor used by over half of the Fortune 500, allowing attackers to bypass the editor's sandbox and execute arbitrary commands on a dev… The Hacker News · Jul 1, 2026 Critical CVE-2026-50548CVE-2026-50549CVE-2025-54135prompt-injectionsandboxai-code-editor
vulnerability Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts A critical remote code execution (RCE) vulnerability, CVE-2026-8037, in Progress Kemp LoadMaster is currently being actively exploited. The flaw allows unauthenticated attackers to execute arbitrary commands on vulnerabl… The Hacker News · Jul 1, 2026 Critical CVE-2026-8037CVE-2024-1212rcecommand injectionload balancer
threat-intel US lifts export controls on Anthropic’s frontier cybersecurity AI models The U.S. government has lifted export controls on Anthropic’s Fable 5 and Mythos 5 cybersecurity AI models following a ‘jailbreak’ exploit discovered in Fable 5. This marks the first instance of export controls being app… The Record · Jul 1, 2026 Medium USCHaijailbreakexport controls
data-breach Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches Multiple Japanese companies, including an insurer, brewer, manufacturer, and telecom provider, have recently disclosed significant cyber breaches impacting customer data and operational systems. The attacks range from a… The Record · Jul 1, 2026 High JASICAdata breachransomwarecyberattack
threat-intel Safe Events Start With Threat Intel and Digital Security This article discusses the importance of threat intelligence and digital security in protecting major events like sporting competitions and celebrations. It highlights how attackers often begin preparing well in advance,… Dark Reading · Jul 1, 2026 High ATUSevent securitythreat intelligencecybersecurity
ransomware AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android A new type of ransomware, dubbed ‘InfernoGrabber v9.0’, has emerged utilizing AI-generated code to exploit vulnerabilities in Chromium-based browsers on Windows and Android. The malware, created using the DeepSeek AI mod… The Hacker News · Jul 1, 2026 High CVE-2023-4863USairansomwarebrowser