threat-intel Frontier AI and the Future of Defense: Your Top Questions Answered This article from Palo Alto Networks Unit 42 analyzes the emerging threat posed by frontier AI models, particularly Anthropic’s Mythos, to cybersecurity. The rapid capabilities of these models – including vulnerability i… Palo Alto Unit 42 · Apr 23, 2026 High frontier aivulnerabilityexploit chaining
threat-intel It pays to be a forever student This article from Cisco Talos highlights the importance of broad knowledge beyond traditional cybersecurity for threat intelligence professionals. It emphasizes the need to understand diverse fields like economics and in… Cisco Talos · Apr 23, 2026 High CVE-2025-20333CVE-2025-20362aiphishingindustrial espionage
threat-intel Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System This report details a proof-of-concept (PoC) developed by Palo Alto Unit 42 demonstrating the potential of autonomous AI agents in launching offensive attacks against cloud environments. The PoC, utilizing a multi-agent… Palo Alto Unit 42 · Apr 23, 2026 High USaiautonomouscloud
apt GopherWhisper: A burrow full of malware ESET researchers have identified a new China-aligned Advanced Persistent Threat (APT) group, dubbed GopherWhisper, that targeted a Mongolian governmental entity. The group utilizes a diverse toolkit primarily built in Go… WeLiveSecurity · Apr 23, 2026 High MNaptchinago
threat-intel When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks This report details a novel attack technique, dubbed AirSnitch, that exploits vulnerabilities in Wi-Fi encryption protocols (WPA2 and WPA3-Enterprise) to bypass client isolation and intercept network traffic. The attack… Palo Alto Unit 42 · Apr 22, 2026 High wpa2wpa3wi-fi
ransomware ‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty A senior member of the Scattered Spider cybercrime group, Tyler Robert Buchanan, has pleaded guilty to wire fraud conspiracy and aggravated identity theft related to a series of text-message phishing attacks conducted in… Krebs on Security · Apr 21, 2026 High UKUSSPphishingsim-swapcryptocurrency
malware New NGate variant hides in a trojanized NFC payment app A new variant of the NGate malware, dubbed NGate, is targeting Android users in Brazil by abusing the legitimate HandyPay app. Threat actors used generative AI to modify HandyPay, allowing them to steal NFC data, includi… WeLiveSecurity · Apr 21, 2026 High BRnfcandroidmalware
threat-intel Fracturing Software Security With Frontier AI Models This report from Palo Alto Unit 42 highlights the emerging threat posed by advanced AI models, particularly "frontier AI models," which demonstrate autonomous vulnerability discovery and exploitation capabilities. The ra… Palo Alto Unit 42 · Apr 20, 2026 High UNNOaivulnerabilityzero-day
ransomware What the ransom note won’t say This article details the ongoing issues surrounding the BlackCat ransomware gang’s affiliate, who attempted to defraud the group after carrying out a significant attack on Change Healthcare. The incident highlights the i… WeLiveSecurity · Apr 20, 2026 High USransomwarefranchisesupply chain
threat-intel Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) This report from Palo Alto Unit 42 details a significant escalation of cyber risk originating from Iran following a 47-day internet outage. Iranian threat actors, identified as CL-STA-1128 (Cyber Av3ngers), are now aggre… Palo Alto Unit 42 · Apr 17, 2026 High USIRILoticsphishing
phishing That data breach alert might be a trap This article highlights the increasing sophistication and prevalence of fake data breach notification scams, driven by factors like record-breaking data breaches and the use of AI tools. Scammers are leveraging these not… WeLiveSecurity · Apr 17, 2026 High USDEphishingsocial engineeringai
threat-intel A Deep Dive Into Attempted Exploitation of CVE-2023-33538 This report details an ongoing attempt to exploit CVE-2023-33538, a vulnerability in older TP-Link Wi-Fi router models (TL-WR940N v2/v4, TL-WR740N v1/v2, TL-WR841N v8/v10). Automated scans, utilizing Mirai-like malware p… Palo Alto Unit 42 · Apr 16, 2026 High CVE-2023-33538USiotvulnerabilitymirai
supply-chain Supply chain dependencies: Have you checked your blind spot? This article highlights the growing risk of cyberattacks originating through supply chain vulnerabilities, particularly among small and medium-sized businesses (SMBs). It emphasizes that complex, digitized supply chains… WeLiveSecurity · Apr 16, 2026 High CVE-2019-15126CAUNsupply chaincybersecurityrisk management
threat-intel Smashing Security podcast #463: This AI company leaked its own code. It’s also built something terrifying This article discusses a concerning trend where AI companies are inadvertently leaking their own code and becoming targets for malicious actors. Tanya Janca highlights the vulnerability of software developers, particular… Graham Cluley · Apr 15, 2026 High CAsupply chaindeveloper securitycredential theft
malware 108 malicious Chrome extensions caught stealing Google and Telegram data from 20,000 users A coordinated campaign involving 108 malicious Chrome extensions has been discovered, stealing data from approximately 20,000 users. The extensions, disguised as legitimate add-ons for popular apps like Telegram and YouT… Graham Cluley · Apr 15, 2026 High RUbrowser extensionsdata theftcredentials
threat-intel Patch Tuesday, April 2026 Edition Microsoft released a substantial update, Patch Tuesday, addressing 167 vulnerabilities across its operating systems and software, including several zero-days. This update focused on critical flaws in SharePoint Server, W… Krebs on Security · Apr 14, 2026 High CVE-2026-32201CVE-2026-33825CVE-2026-34621zero-daypatch tuesdayvulnerability
phishing AI and cryptocurrency scams are costing Americans billions, FBI reports Recent investigations by the FBI have revealed a significant surge in scams leveraging artificial intelligence and cryptocurrency, resulting in substantial financial losses for American victims. These scams are exploitin… Graham Cluley · Apr 10, 2026 High USaicryptocurrencyscams
threat-intel Recovery scammers hit you when you’re down: Here’s how to avoid a second strike This article discusses the growing problem of ‘recovery fraud,’ where scammers target individuals who have already been victims of fraud, exploiting their desperation to get their stolen funds back. These scams typically… WeLiveSecurity · Apr 10, 2026 High USfraudscamrecovery
threat-intel Russia Hacked Routers to Steal Microsoft Office Tokens Russian military intelligence, operating under the ‘Forest Blizzard’ (APT28/Fancy Bear) moniker, has been conducting a sophisticated cyber espionage campaign targeting over 18,000 routers globally. The attackers exploite… Krebs on Security · Apr 7, 2026 High USUKRUdns hijackingauthentication tokensmicrosoft office
threat-intel RSAC 2026: How AI Is Reshaping Cybersecurity Faster Than Ever This Dark Reading article reports on insights gathered by Kelly Jackson Higgins, editor-in-chief of Dark Reading, following RSAC 2026. Higgins highlighted the rapid and transformative impact of artificial intelligence (A… Dark Reading · Apr 7, 2026 High aicybersecurityrsac