threat-intel Fresh ATM Crypto Software Bugs: Jackpot or Bust? A researcher, Matt Burch, discovered nine vulnerabilities in CryptoPro Secure Disk, a full-disk encryption solution used by ATM manufacturer Diebold Nixdorf. These vulnerabilities could allow attackers to bypass encrypti… Dark Reading · Jul 10, 2026 High USatmencryptionjackpotting
threat-intel Third US Security Expert Sentenced to Prison for Helping Ransomware Gang A former cybersecurity expert, Angelo Martino, was sentenced to 70 months in prison for aiding a ransomware gang, BlackCat/Alphv, by providing confidential information to maximize ransom payments. Two other cybersecurity… SecurityWeek · Jul 10, 2026 Critical ransomwareinsider threatcybercrime
threat-intel GigaWiper Combines Multiple Malware for System-Level Sabotage Microsoft has identified a sophisticated malware strain called GigaWiper, a Go-based backdoor combining multiple destructive capabilities – including a physical disk wiper, ransomware-like encryption, and persistent C&C… SecurityWeek · Jul 10, 2026 High IRbackdoorransomwarewipe
threat-intel Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks A former ransomware negotiator, Angelo Martino, has been sentenced to 70 months in prison for betraying five victims and providing BlackCat ransomware operators with confidential information, allowing them to demand high… The Hacker News · Jul 10, 2026 High USransomwarenegotiatorcollusion
supply-chain Network of 200 GitHub Repositories Used for Malware Infection A threat actor, linked to previous activity associated with the ‘ischhfd83’ email address, has created a network of over 200 GitHub repositories delivering Windows malware through a Go module disguised as a DNS scanning… SecurityWeek · Jul 10, 2026 High supply chaingithubmalware
threat-intel New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware Microsoft has uncovered a sophisticated Windows backdoor, dubbed GigaWiper, that combines destructive capabilities with remote control functionality. GigaWiper operates by bundling three separate tools – a disk wiper, a… The Hacker News · Jul 9, 2026 High IRISUKransomwarebackdoordata destruction
threat-intel ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories This week's ThreatsDay highlights a diverse range of cyber threats, from global fraud operations and ransomware tool overlaps to sophisticated social engineering attacks and vulnerabilities in popular software. Key event… The Hacker News · Jul 9, 2026 High CVE-2026-9181CVE-2025-49760CVE-2025-59200CHTAESsocial engineeringphishingransomware
threat-intel Latvian forestry company still restoring systems weeks after ransomware attack A Latvian state-owned forestry company, LVM, is still recovering from a ransomware attack that disrupted its systems for weeks. The attack, attributed to a foreign, financially motivated ransomware group, led to the leak… The Record · Jul 9, 2026 High LVransomwarecyberattackdata breach
ransomware GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses The GodDamn ransomware family, a rebrand of Beast ransomware (originally based on Monster), is utilizing a newly discovered malicious driver called PoisonX to disable endpoint defenses and gain access to systems. Threat… The Hacker News · Jul 9, 2026 High ransomwarepoisonxbyovd
ransomware Mount Royal University Confirms Data Stolen in Ransomware Attack Mount Royal University in Canada suffered a ransomware attack that resulted in the theft of employee and student data. The attackers, identified as CMD Organization, exfiltrated over 10 terabytes of information and are d… SecurityWeek · Jul 9, 2026 High CAransomwaredata breachtor
threat-intel 'GodDamn' Ransomware Uses BYOVD to Smite US Companies The ransomware group Hyadina, operating under the name "GodDamn," is leveraging a Microsoft-approved, malicious kernel driver – dubbed "PoisonX" – to infiltrate US organizations and deploy its ransomware. They utilize a… Dark Reading · Jul 9, 2026 High RUransomwaredriverbyovd
threat-intel ISC Stormcast For Thursday, July 9th, 2026 https://isc.sans.edu/podcastdetail/10000, (Thu, Jul 9th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging a newly discovered phishing technique that bypasses traditional email security filters. The c… SANS Internet Storm Center · Jul 9, 2026 Critical USphishingzero-dayransomware
threat-intel Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself A 15-year-old in Japan used an AI chatbot to automatically cancel nearly 47,000 anime streaming subscriptions within hours. Simultaneously, researchers have documented the first fully autonomous, agentic AI-driven ransom… Graham Cluley · Jul 8, 2026 High JPairansomwarecyberattack
threat-intel Mexico's New Cyber Plan Faces Its First Real Test Mexico's National Cybersecurity Plan, designed to bolster the country's digital defenses ahead of the 2026 FIFA World Cup, is facing an early test. Despite the plan's goals – including establishing a National Cybersecuri… Dark Reading · Jul 8, 2026 High MEUNCAcybersecuritylatin americacyberattack
threat-intel Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours A lone attacker successfully breached a large Amazon Web Services (AWS) environment in 72 hours using AI to accelerate reconnaissance, tool development, and command structure, ultimately extorting a global enterprise. Th… Dark Reading · Jul 8, 2026 High aicloudransomware
malware Vidar Infostealer Hammers SMBs via Malvertising Campaign A financially motivated operation is using malvertising to deliver a two-for-one malware payload – the Vidar infostealer and XMRig cryptominer – to consumers and SMBs globally. The campaign employs sophisticated evasion… Dark Reading · Jul 8, 2026 High USEUmalvertisingmaascryptomining
threat-intel SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users A new banking fraud operation, tracked as REF6045, is targeting Mexican banks, fintech companies, and cryptocurrency exchanges using a malware toolset called SCMBANKER. The operation leverages fake CAPTCHA verification p… The Hacker News · Jul 8, 2026 High MXbankingmalwarephishing
threat-intel ESET Threat Report H1 2026 The first half of 2026 demonstrates attackers’ increasing reliance on adapting existing techniques, leveraging AI to enhance their efficiency and expand the attack surface. This includes AI-powered malware, sophisticate… WeLiveSecurity · Jul 8, 2026 Medium aisocial engineeringransomware
threat-intel CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its KEV catalog, including flaws in Adobe ColdFusion, JoomShaper SP Page Builder, and Langflow. These… The Hacker News · Jul 8, 2026 High CVE-2026-48282CVE-2026-56290CVE-2026-55255INvulnerabilityrceidror
data-breach County Government Reportedly Paid $1 Million to Cyber Extortion Group A small county government in Ohio reportedly paid $1 million to the Kairos cyber extortion group to prevent the release of stolen data following a brute-force attack in May 2025. The attackers, Kairos, demanded $3 millio… SecurityWeek · Jul 7, 2026 High USdata breachransomwaregovernment