threat-intel China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa A China-linked cybercrime group, TA4922, has broadened its phishing attacks to include organizations in the UK, Germany, Italy, and South Africa. The group utilizes a constantly evolving arsenal of malware, including Val… The Hacker News · Jun 4, 2026 Medium UKGEITphishingratcredential theft
threat-intel Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting This article details Cisco Talos' approach to threat hunting, which differs from traditional alert-based detection. Instead of waiting for alerts, Talos analysts formulate hypotheses about adversary behavior based on tel… Cisco Talos · Jun 4, 2026 High USthreat huntingaicorrelation
threat-intel Chinese Cybercrime Group in Spotlight for Record Campaign Pace A Chinese cybercrime group, TA4922, is experiencing a record surge in campaign activity, utilizing sophisticated social engineering tactics to target organizations globally. The group’s primary objectives involve data th… SecurityWeek · Jun 4, 2026 High GBDEITsocial engineeringcredential phishingremote access
threat-intel Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months An unknown attacker gained unauthorized access to the Outlook mailbox of a senior executive at a major stock exchange for over five months, copying the inbox in small batches and utilizing cloud services like Dropbox and… The Hacker News · Jun 4, 2026 High USespionagemailboxcloud
apt Pakistan Spies on Afghan Finance Ministry With Xeno RAT A Pakistani advanced persistent threat (APT) group, identified as SideCopy and linked to the Transparent Tribe (APT 36), has been conducting espionage against Afghanistan's finance ministry since at least May 2025. The g… Dark Reading · Jun 4, 2026 High AFPKspear-phishingremote-accesspashto
threat-intel Chinese hackers use new Atlas RAT malware in European cyberattacks A Chinese cybercrime group, tracked as TA4922, is expanding its operations with the deployment of new malware, including the Atlas RAT and RomulusLoader, targeting organizations across Europe and Southeast Asia. The grou… BleepingComputer · Jun 3, 2026 High CHGEITphishingremote access trojanmalware loader
threat-intel Cyber Insurance Rates Are Dropping, but Exclusions Widen Cyber insurance premiums are decreasing, driven by insurers refining their risk models and offering discounts for robust security practices. However, this positive trend is counterbalanced by a significant increase in co… Dark Reading · Jun 3, 2026 Medium UKcyber insurancesocial engineeringexclusions
threat-intel Global Stock Exchange Hit by Monthslong Email Campaign A global stock exchange was targeted by a sophisticated threat actor who gained near-continuous access to a senior executive’s Microsoft Outlook mailbox over a five-month period. The attacker utilized legitimate Windows… Dark Reading · Jun 3, 2026 High UKemail espionagelateral movementdata exfiltration
malware ISC Stormcast For Wednesday, June 3rd, 2026 https://isc.sans.edu/podcastdetail/9956, (Wed, Jun 3rd) The SANS Internet Storm Center's Stormcast for June 3rd, 2026 highlighted a concerning increase in malicious activity across the internet landscape. The broadcast detailed several ongoing threats, including observed phis… SANS Internet Storm Center · Jun 3, 2026 High phishingransomwaremalware
threat-intel Trump Signs Executive Order That Invites Vetting of Top AI Models for National Security Risks President Trump signed an executive order establishing a framework for the federal government to vet the national security risks of advanced AI systems, primarily focusing on models developed by companies like Anthropic… SecurityWeek · Jun 2, 2026 Medium artificial intelligenceai securitynational security
threat-intel Why the browser is now the front line for AI security This BleepingComputer article highlights the escalating threat of AI-powered phishing attacks, primarily targeting the browser environment. Adversaries are leveraging AI to rapidly create and deploy phishing kits, automa… BleepingComputer · Jun 2, 2026 High USaiphishingbrowser
phishing ISC Stormcast For Monday, June 1st, 2026 https://isc.sans.edu/podcastdetail/9952, (Mon, Jun 1st) The SANS Internet Storm Center's June 1st, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observe… SANS Internet Storm Center · Jun 1, 2026 Medium phishingemailthreat intelligence
threat-intel What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks This article highlights a growing security risk stemming from the rise of ‘vibe coding’ – AI-driven application development platforms that allow employees to rapidly build and deploy applications. Over 2,000 of these pub… The Hacker News · May 29, 2026 High aishadow-itvibe-coding
supply-chain Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets A malicious NuGet package, 'Sicoob.Sdk,' disguised as a C# SDK for Sicoob, Brazil's largest cooperative financial system, was discovered to be stealing client IDs and PFX certificates. This allowed unauthorized access to… The Hacker News · May 29, 2026 High BRsupply-chaincredentialsbanking
malware BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model An advanced Android remote access Trojan, BTMOB RAT, is spreading across Brazil and Latin America through a malware-as-a-service (MaaS) model. Delivered via a no-code interface, it allows cybercriminals to create malicio… Dark Reading · May 28, 2026 High BRARandroidratmaas
threat-intel Ransomware Actors Show Up In Person to Steal Law Firm Data The Silent Ransom Group (SRG), also known as Luna Moth and UNC3753, is targeting law firms through sophisticated social engineering tactics, including impersonating IT personnel and conducting in-person visits to gain ac… Dark Reading · May 27, 2026 High RUsocial engineeringdata theftlaw firms
malware Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users Two separate malware campaigns are targeting Windows and Android users across Latin America and Europe, primarily focusing on banking trojans. The first campaign utilizes the Grandoreiro malware, an actively evolving ban… The Hacker News · May 27, 2026 High PTBRESbanking trojanandroid malwaredll side-loading
threat-intel ISC Stormcast For Wednesday, May 27th, 2026 https://isc.sans.edu/podcastdetail/9946, (Wed, May 27th) The SANS Internet Storm Center's Stormcast for May 27th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The broadcast detailed ongoing campaigns involving phishing attacks… SANS Internet Storm Center · May 27, 2026 Medium phishingmalwareemail
threat-intel How Varonis Atlas integrates Claude Compliance API for AI governance Varonis has announced an integration between its Atlas AI Security Platform and the Claude Compliance API, allowing for enhanced monitoring and governance of activity within Claude Enterprise and Claude Platform. This in… BleepingComputer · May 26, 2026 Medium aillmcompliance
malware Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms The Lazarus Group, a North Korean threat actor, has deployed a new memory-only remote access trojan (RAT) called RemotePE to target financial and cryptocurrency firms. This multi-stage attack chain utilizes several loade… The Hacker News · May 25, 2026 High KPremote access trojannorth koreasocial engineering