threat-intel ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories This week’s security news is a mixed bag, encompassing a range of threats from sophisticated ransomware attacks to deceptive software distribution and widespread surveillance techniques. A new ransomware family, Spirals,… The Hacker News · Jul 16, 2026 High CVE-2026-46817CVE-2023-4346CVE-2026-35273NESPPOransomwareinfostealerbrandjacking
threat-intel Sandworm hackers have a CAPTCHA trick for Ukrainians Sandworm, a hacking group linked to Russia's military intelligence, is using a sophisticated CAPTCHA trick to trick Ukrainian targets into installing malware on their computers. The group employs a 'ClickFix' technique,… The Record · Jul 16, 2026 High RUsocial engineeringmalware distributionransomware
threat-intel New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands A new modular malware, TELEPUZ, is spreading via ClickFix lures and is being developed by a solo developer or small team. The malware steals data, runs commands, and evades detection through various techniques, including… The Hacker News · Jul 16, 2026 High BRINclickfixpastejackingmalware-as-a-service
threat-intel Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack Two members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, have been sentenced to over five years in prison for their role in a 2024 attack against Transport for London (TfL). The attack caused… The Record · Jul 16, 2026 High UNcybercrimeransomwaredata breach
threat-intel Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers This episode of Smashing Security explores a series of unusual events, primarily focusing on a deep dive into a massive leak of internal communications from the Conti ransomware gang. The podcast details how the chats, f… Graham Cluley · Jul 16, 2026 Medium INransomwareremote-controle-rickshaw
threat-intel Identity Attacks Overtake Exploits as Top Ransomware Cause Ransomware attacks are increasingly being delivered through identity-based attacks, specifically malicious emails and phishing, rather than exploiting vulnerabilities in software. Despite widespread deployment of MFA (97… Dark Reading · Jul 15, 2026 High ransomwarephishingmfa
threat-intel Guten Tag, Bonjour, Hola to Our European Cyber Defenders! Dark Reading is launching a new section, DR Global Europe, to provide region-specific cybersecurity intelligence tailored for professionals in the EU and UK. This expansion addresses unique cyber threats facing Europe, i… Dark Reading · Jul 15, 2026 High RUUKSPcybersecurityddosransomware
threat-intel OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps OkoBot, a malware framework, has been actively targeting hardware wallet users since April 2025, primarily through phishing attacks leveraging a module called SeedHunter. SeedHunter intercepts the wallet's desktop softwa… The Hacker News · Jul 15, 2026 High BRVNCAphishingmalwarehardware wallet
threat-intel Windows Bind Link Attacks Can Hide Malware From EDR Tools Researchers at Bitdefender have demonstrated three techniques leveraging Windows’ bind links to evade Endpoint Detection and Response (EDR) tools. These techniques – file-binding, process-binding, and silo-binding – allo… SecurityWeek · Jul 15, 2026 High bind linksedr evasionwindows security
threat-intel OkoBot: new sophisticated malware framework targets cryptocurrency users OkoBot is a sophisticated and evolving malware framework developed by threat actors since 2025, primarily targeting cryptocurrency users. The framework utilizes a layered approach, starting with a PowerShell downloader (… Securelist · Jul 15, 2026 High ransomwarecryptocurrencybrowser
threat-intel US unseals indictment against alleged operators of Russian bulletproof hosting service The U.S. government has unsealed an indictment against three Russians linked to a Russian-based bulletproof hosting service, Media Land and ML Cloud, which provided infrastructure and tech support to cybercriminal groups… The Record · Jul 14, 2026 High USRUNLbulletproof hostingcybercrimeransomware
threat-intel Synopsys Finds No Evidence of Data Breach Following Bosch Hack Claims A cybercrime group claiming to have hacked Synopsys and Bosch is demanding a ransom for stolen data, but Synopsys denies the claims and has found no evidence of a data breach. Bosch declined to comment, offering a standa… SecurityWeek · Jul 14, 2026 Medium DEcybercrimeextortiondata breach
threat-intel ClickFix's Mushrooming Ecosystem Demands New Defense Tactics ClickFix, initially a social engineering attack vector, has evolved into a sophisticated malware-as-a-service (MaaS) ecosystem, outpacing traditional security defenses. Attackers are now utilizing a range of malware, inc… Dark Reading · Jul 14, 2026 High social engineeringmalware-as-a-serviceyara
threat-intel U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support The U.S. Treasury Department has sanctioned a VPN service provider, First VPN Service (1VPNS), and its administrator, Dmytro Rashevskyi, for enabling ransomware groups to carry out attacks against U.S. companies and inst… The Hacker News · Jul 14, 2026 High CVE-2018-0171CVE-2008-4128RUUKUNvpnransomwarecyber espionage
threat-intel The ransomware negotiator who was working for the other side A Florida man, Angelo John Martino III, was sentenced to 70 months in prison for secretly providing ransomware negotiation details and actively deploying BlackCat ransomware alongside two colleagues. He exploited his rol… Graham Cluley · Jul 14, 2026 Critical USransomwarenegotiationinsider threat
threat-intel VPN service favored by ransomware groups is sanctioned by US The U.S. government has sanctioned a VPN service, First VPN, and its administrator, citing their role in enabling ransomware attacks against critical U.S. infrastructure. The sanctions target not only the VPN providers b… The Record · Jul 13, 2026 High USUKBEvpnransomwarecybercrime
threat-intel GigaWiper Lets Threat Actors Choose Their Own Destructive Attack GigaWiper is a novel, modular malware that combines backdoor and wiper capabilities, allowing attackers to choose how to destroy a targeted system while minimizing their operational footprint. Initially identified as a G… Dark Reading · Jul 13, 2026 High IRRUVEwiperbackdoormodular
ransomware Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence Two major ransomware figures have been brought to justice in separate U.S. court cases. Karen Vardanyan, a Ryuk ransomware operator, pleaded guilty to conspiracy and computer fraud, while Angelo Martino, a ransomware neg… The Record · Jul 10, 2026 High FRUKUNransomwarenegotiatorextortion
threat-intel Cybercriminals Flock to Healthcare Businesses as Attacks Surge Cyberattacks on healthcare businesses, including service providers supporting hospitals, have surged dramatically, nearly doubling in the past year and significantly outpacing attacks on hospitals themselves. This trend… Dark Reading · Jul 10, 2026 High USGEransomwarecyberattackhealthcare
threat-intel In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops Multiple cybersecurity incidents and threats are unfolding, including a ransomware affiliate pleading guilty in the US, a subscription-based remote access trojan (QuimaRAT) being actively sold on the dark web, and a Cana… SecurityWeek · Jul 10, 2026 High ARCAUSransomwaredata breachremote access trojan