threat-intel ToxicPanda Banking Trojan Matures into Enterprise Threat ToxicPanda, a banking Trojan, has evolved into a more sophisticated enterprise threat, expanding its reach beyond individual banking apps to compromise entire Android devices and potentially access corporate resources. T… Dark Reading · 6d ago High LAITPObankingmobileenterprise
threat-intel ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More This week saw a surge in high-impact cyberattacks and vulnerabilities, highlighting the increasing sophistication and speed of threat actors. AI is now being weaponized to craft exploit scripts targeting Siemens PLCs, wh… The Hacker News · 6d ago High CVE-2026-19478CVE-2021-27101CVE-2023-34362UNRUvulnerabilitysupply-chainransomware
threat-intel The Vulnerability Gap: Why Discovery Is Outrunning Repair The increasing speed of AI-powered vulnerability discovery is outpacing the ability of open-source software maintainers to address those vulnerabilities, creating a significant gap in the cybersecurity landscape. This is… Dark Reading · 6d ago High vulnerabilityaiopen-source
threat-intel Hired for One Job, Judged on Another: The CISO’s Real Problem CISOs often struggle to demonstrate their value to a board of directors, who tend to prioritize cost, growth, and customer trust over technical security achievements. Instead of focusing on preventing breaches (which is… SecurityWeek · 6d ago Medium cisosecurity-strategybusiness-alignment
ransomware Gunra ransomware: what you need to know The Gunra ransomware gang is aggressively targeting organizations across multiple sectors, leveraging unpatched VPNs and firewalls to gain access and deploy their ransomware. They are demanding payments to decrypt stolen… Graham Cluley · 6d ago High vpnfirewallransomware
data-breach Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts Dutch regulators have fined Uber nearly $1 billion for using automated software to suspend driver accounts without human review, violating EU data privacy regulations. This is the fourth time the authority has penalized… SecurityWeek · 6d ago Medium dataprivacygdprautomation
threat-intel WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords Two new malware families, WordlistLoader and SynkLoader, are being used to deliver the Amatera Stealer via ClickFix phishing campaigns. WordlistLoader reconstructs shellcode for Amatera, utilizing techniques to evade det… The Hacker News · 6d ago High phishingransomwaremalware
threat-intel AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones AliExpress is accused of using a deceptive audio trick to silently collect shoppers' biometric data, including fingerprints, potentially compromising user privacy. This technique involved playing a brief audio clip that… The Register · 6d ago Medium privacybiometricsdata-collection
threat-intel Hackers infect Android car systems to build proxy botnet Hackers are exploiting vulnerabilities in Chinese automotive software provider DoFun's Android car head units to build a proxy botnet. The malware, initially delivered through a legitimate system application (TWCore), al… The Record · 6d ago High CHGEandroidbotnetproxy
vulnerability 91 Vulnerabilities Patched in Spring Application Framework Broadcom released a massive update addressing 91 vulnerabilities within the Spring application framework. Many of these flaws, including a critical Remote Code Execution (RCE) vulnerability, could be exploited for variou… SecurityWeek · 6d ago High CVE-2026-59270CVE-2026-59285CVE-2026-59318springvulnerabilityrce
threat-intel Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt AI coding tools are accelerating the influx of open-source packages into organizations’ software stacks, leading to a growing backlog of security vulnerabilities and remediation debt. A recent study of 300 enterprise le… The Hacker News · 6d ago Medium aiopen-sourcevulnerability
vulnerability Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account A critical vulnerability (CVE-2026-18963) in Keycloak allows unauthenticated attackers to force a password reset and take over any user account, including administrative accounts. Red Hat and Keycloak have released patch… The Hacker News · 6d ago Critical CVE-2026-18963CVE-2026-15571password-resetauthenticationkeycloak
threat-intel Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor A cyber espionage campaign, dubbed Operation QUICSILVER, targeting Myanmar's government and IT sector is being conducted by a China-linked threat actor. The campaign uses a graduation ceremony lure to deliver a Go backdo… The Hacker News · 6d ago High MYMOPAcyber espionagebackdoorkernel-mode
threat-intel The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk A growing number of enterprise users are quietly adopting a wide range of AI tools – both corporate and personal – creating a significant security blind spot for IT and security teams. While organizations are attempting… The Hacker News · 6d ago High shadow aiai securityprompt injection
threat-intel Venezuelan Gets Record Federal Prison Term for ATM Jackpotting A Venezuelan national has been sentenced to a record 96 months in prison for his involvement in a sophisticated ATM jackpotting scheme, linked to the Venezuelan terrorist organization Tren de Aragua. The scheme resulted… SecurityWeek · 6d ago High VEatmjackpottingcybercrime
threat-intel Criminal Deception in Silicon Valley This research examines how Silicon Valley entrepreneurs use deceptive tactics – ‘façades’ – to mislead investors and project a false image of success while their ventures are actually struggling. The study, analyzing cou… Schneier on Security · 6d ago Medium frauddeceptioninvestor
threat-intel Security vets rally around $4 paper password books for sale in Australia This article is a collection of snippets from The Register, covering a range of cybersecurity and technology news. It highlights a vulnerability impacting Joomla websites through exploited extensions, a Microsoft SharePo… The Register · 6d ago Medium CHvulnerabilityphishingransomware
threat-intel Personal Information Exposed in Apollo Global Data Breach Apollo Global Management suffered a data breach due to a social engineering attack, exposing sensitive personal information like names, contact details, and Social Security numbers. The attack was attributed to the UNC66… SecurityWeek · 6d ago High vishingsocial engineeringdata breach
threat-intel Rethinking Application Security for the AI Era The speed at which attackers can now exploit vulnerabilities – thanks to advancements in AI – is dramatically increasing, shrinking the window from vulnerability disclosure to exploit from months to hours. This necessita… SecurityWeek · 6d ago High aivulnerabilitypatching
threat-intel Iran-Linked Hackers Shut Down UK Power Plant for Four Days Iranian-linked hackers successfully shut down a British power plant for four days, raising significant concerns about the escalating cyber threat landscape and the vulnerability of UK critical infrastructure. The inciden… SecurityWeek · 6d ago High UKIRUSirancyberattackcritical infrastructure