threat-intel Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine's CERT-UA has warned that Russian hackers, specifically a branch of the Sandworm group, are using fake CAPTCHA challenges to trick users into executing PowerShell commands on their own computers, installing recon… Graham Cluley · Jul 21, 2026 High RUclickfixpowershellcaptcha
threat-intel Scammers impersonate FBI on social media, prey on crime victims Scammers are impersonating the FBI on social media to trick victims, particularly those involved in crime, into divulging sensitive information. This tactic is part of a broader trend of online fraud and disinformation c… The Register · Jul 20, 2026 Medium CHsocial engineeringphishingfraud
threat-intel More than 1,000 domains illegally streaming World Cup games seized, DOJ says The Department of Justice, in collaboration with Homeland Security Investigations, has seized over 1,000 domains illegally streaming the World Cup. This operation targets a cyber gang, Los Ciberinfiltrados, involved in d… The Record · Jul 20, 2026 Medium BUPEARcybercrimepiracystreaming
threat-intel ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More This week saw a flurry of vulnerabilities and attacks, including a WordPress core flaw leading to remote code execution, exploitation of zero-day vulnerabilities in SonicWall VPN appliances, and a new malware framework (… The Hacker News · Jul 20, 2026 High CVE-2026-63030CVE-2026-60137CVE-2026-15409INTÜBRvulnerabilityzero-dayransomware
threat-intel Mythos Didn't Break Your Security Program. Your Exposure Window Could. The vulnerability landscape is exploding, with a projected 66,000 new CVEs in 2026, and many organizations struggle to remediate them due to slow mobilization processes. The gap between vulnerability disclosure and actua… The Hacker News · Jul 20, 2026 High vulnerabilitiesexposure windowattack path analysis
threat-intel UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Russian state-sponsored actors, linked to the Sandworm group and GRU, are using a ClickFix social engineering tactic to deliver malware to Ukrainian devices. They are leveraging fake CAPTCHA checks on compromised website… The Hacker News · Jul 19, 2026 High RUsocial engineeringclickfixrussia
threat-intel SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access A threat actor, identified as UTA0533, successfully exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances to gain root access. The attacker leveraged these vulnera… The Hacker News · Jul 19, 2026 High CVE-2026-15409CVE-2026-15410zero-dayvpnroot access
threat-intel Google’s Gemini lets strangers send messages from your locked Android phone Google’s Gemini AI assistant on Android 16 devices has a vulnerability that allows unauthorized users to send SMS and WhatsApp messages from a locked phone. This is achieved through a specific multi-touch gesture when Ge… Graham Cluley · Jul 17, 2026 Medium androidgeminilock screen
threat-intel Inc Ransomware Exploits SonicWall SMA Zero-Days A major ransomware group, Inc, has been exploiting two zero-day vulnerabilities in SonicWall SMA appliances to gain remote code execution and escalate privileges, allowing them to infiltrate enterprise networks, steal cr… Dark Reading · Jul 17, 2026 High CVE-2026-15409CVE-2026-15410zero-dayransomwarevulnerability
threat-intel In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint This week’s cybersecurity news highlights a range of concerning events, including a Dutch telecom breach potentially linked to local cybercriminals, a Lidl data breach impacting customers in Belgium and the Netherlands,… SecurityWeek · Jul 17, 2026 High NEBEGEcyberattackransomwaredata breach
supply-chain E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants The European Commission has ordered Google to allow rival AI assistants on Android to access device features like the microphone, camera, and screen, effectively dismantling Google's control over these functionalities. T… The Hacker News · Jul 17, 2026 High aiandroiddata-sharing
threat-intel Multiples vulnérabilités dans le noyau Linux d'Ubuntu (17 juillet 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Ubuntu. Some of these vulnerabilities allow for privilege escalation, remote denial of service, and data confidentiality compromise. The vulnerabilitie… CERT-FR · Jul 17, 2026 High CVE-2021-47117CVE-2021-47202CVE-2022-48816linuxkernelvulnerability
threat-intel Multiples vulnérabilités dans le noyau Linux de SUSE (17 juillet 2026) Multiple vulnerabilities have been discovered in the SUSE Linux kernel. These vulnerabilities can lead to privilege escalation, denial of service, and data confidentiality breaches. The affected products range from deskt… CERT-FR · Jul 17, 2026 High CVE-2023-53995CVE-2025-68324CVE-2025-71089vulnerabilitylinuxsecurity
vulnerability Multiples vulnérabilités dans Microsoft Windows (17 juillet 2026) Microsoft has announced multiple vulnerabilities across various versions of Windows, including Windows 10 and 11. These vulnerabilities could allow attackers to execute arbitrary code remotely, elevate privileges, and co… CERT-FR · Jul 17, 2026 High CVE-2026-56171CVE-2026-58598CVE-2026-58643windowsvulnerabilitypatch
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (17 juillet 2026) Multiple vulnerabilities have been discovered in Red Hat's Linux kernel. These vulnerabilities can lead to arbitrary code execution, privilege escalation, and a denial-of-service attack. Red Hat has released security adv… CERT-FR · Jul 17, 2026 High CVE-2025-38653CVE-2025-68183CVE-2025-68724linuxkernelvulnerability
threat-intel ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories This week’s security news is a mixed bag, encompassing a range of threats from sophisticated ransomware attacks to deceptive software distribution and widespread surveillance techniques. A new ransomware family, Spirals,… The Hacker News · Jul 16, 2026 High CVE-2026-46817CVE-2023-4346CVE-2026-35273NESPPOransomwareinfostealerbrandjacking
vulnerability Splunk, Zoom Patch Critical Vulnerabilities Splunk and Zoom have released patches to address several critical and high-severity vulnerabilities in their respective products. These flaws could allow attackers to steal credentials, access sensitive data, and potenti… SecurityWeek · Jul 16, 2026 High CVE-2026-20296CVE-2026-20297CVE-2026-20298vulnerabilitypatchsecurity
threat-intel Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers This episode of Smashing Security explores a series of unusual events, primarily focusing on a deep dive into a massive leak of internal communications from the Conti ransomware gang. The podcast details how the chats, f… Graham Cluley · Jul 16, 2026 Medium INransomwareremote-controle-rickshaw
vulnerability Zoom Patches Critical Windows Flaw That Could Enable Account Takeover Zoom has released critical security patches to address a series of vulnerabilities in its Windows-based products, including Zoom Workplace, Zoom VDI Client, and Zoom Rooms. These flaws could allow attackers to gain unaut… The Hacker News · Jul 16, 2026 High CVE-2026-53412CVE-2026-53411CVE-2026-53410windowsvulnerabilityaccount_takeover
vulnerability Multiples vulnérabilités dans Cisco RoomOS (16 juillet 2026) Multiple vulnerabilities have been discovered in Cisco RoomOS, potentially allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities affect older versions of the operating… CERT-FR · Jul 16, 2026 Medium CVE-2026-20150CVE-2026-20153CVE-2026-20156ciscoroomosvulnerability