threat-intel Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation Russian threat actors, linked to Laundry Bear (TA488), are exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain persistent access to email accounts within U.S. and European government entities and… The Hacker News · Jul 30, 2026 High CVE-2026-42897CVE-2025-66376USEUxsscredential theftpersistence
threat-intel Headteacher had the most guessable username-password combo you could imagine This article is a roundup of cybersecurity and technology news, covering a range of topics including a phishing campaign targeting Signal users, a zero-day vulnerability in on-prem SharePoint, and a report on vulnerabili… The Register · Jul 30, 2026 Medium UNphishingvulnerabilityransomware
vulnerability Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data A zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) software is actively being exploited, allowing unauthenticated remote attackers to gain access to sensitive data. The vulnerability stems from sta… The Hacker News · Jul 30, 2026 High CVE-2026-20316CVE-2026-20079zero-dayauthenticationremote
threat-intel 'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China A sophisticated, full-service mobile malware-as-a-service (MaaS) framework called ‘Flying Eagle’ has emerged from the Chinese cybercriminal underground, enabling criminals to build and deploy mobile malware campaigns wit… Dark Reading · Jul 30, 2026 High CHmaasmobile malwarecybercrime
threat-intel When AppSec Scanners Become a Supply Chain Attack Vector Security scanners used in the software supply chain can be exploited to introduce vulnerabilities and compromise downstream systems. Researchers at ZeroPath discovered that attackers can craft malicious code repositories… Dark Reading · Jul 29, 2026 High supply-chainvulnerabilitysecurity
threat-intel Word worm crawls into Copilot, spreads chaos A group of Russian hackers are impersonating Signal support to launch phishing attacks, targeting users with links to malicious websites. Simultaneously, a zero-day vulnerability in on-prem SharePoint is being exploited,… The Register · Jul 29, 2026 High RUIRphishingzero-daysharepoint
threat-intel Laundry Bear’s webmail hackers had more in store after February, report says Laundry Bear, a Russian state-linked APT group, has been aggressively exploiting vulnerabilities in both Zimbra Collaboration Suite’s webmail platform and Microsoft Outlook Web Access (OWA) to steal emails and credential… The Record · Jul 29, 2026 High CVE-2026-42897NLUSRUaptvulnerabilityzero-day
threat-intel Russia accuses Telegram founder of aiding terrorism, seeks international arrest Russia has formally accused Telegram founder Pavel Durov of aiding terrorism, seeking an international arrest warrant due to allegations that the messaging app was used by Ukrainian intelligence to organize terrorist att… The Record · Jul 29, 2026 High RUUKFRrussiatelegramukraine
threat-intel Pages piégées à Saint-Denis, le test avant l’opération d’influence ? A French swimming pool website was infiltrated in June 2026 by pirates, who have since been altering pages to test the pool's defenses and gather intelligence. The attackers are using the website's modification patterns… ZATAZ · Jul 29, 2026 High FRcyber espionagereconnaissancedisinformation
threat-intel Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates A remote access trojan (RAT) called Flying Eagle, along with a related control kit called Night Dragon, is circulating through criminal Telegram channels. Researchers have identified 170 servers hosting the RAT framework… The Hacker News · Jul 29, 2026 High CNandroidrattelegram
threat-intel America bans imported robots due to supply chain and security risks The United States is implementing a ban on importing robots due to significant security and supply chain risks. This action is driven by concerns about potential vulnerabilities in these devices, which could be exploited… The Register · Jul 29, 2026 Medium IRroboticssupply chainsecurity
threat-intel Senate confirms Clayton as intel chief after delays The Senate confirmed Jay Clayton as the next Director of National Intelligence, a position that comes amidst significant challenges for the intelligence community. Clayton’s confirmation follows a turbulent process marke… The Record · Jul 28, 2026 Medium IRCHintelfisapolitics
threat-intel MCP gets an enterprise makeover This article covers a range of cybersecurity and technology news, including a vulnerability impacting Joomla extensions, a Microsoft SharePoint zero-day exploit, and a Russian phishing campaign mimicking Signal support.… The Register · Jul 28, 2026 Medium USIRRUvulnerabilityphishingransomware
vulnerability 'Certighost' Flaw Haunts Microsoft Active Directory Certificates A critical vulnerability, dubbed ‘Certighost,’ has been patched by Microsoft that allowed a low-privileged domain user to impersonate a domain controller and compromise an Active Directory environment. The flaw stemmed f… Dark Reading · Jul 28, 2026 Critical CVE-2026-54121UNcertificateactive directorypkis
threat-intel AI-found bugs aren't proving any easier to exploit despite the hype Recent research indicates that AI-powered models, particularly those mimicking Claude, are being exploited to bypass security measures. Researchers have found that Chinese AI models can convincingly impersonate Claude, h… The Register · Jul 28, 2026 Medium CHIRUSaiimpersonationphishing
threat-intel Uncle Sam needs you to fight for 6G leadership and security, lest Beijing get there first The United States is actively working to maintain leadership in 6G technology and security, particularly in response to China's advancements. Recent security incidents highlight ongoing threats, including phishing attack… The Register · Jul 28, 2026 Medium IRCHphishingvulnerabilitiescybersecurity
threat-intel Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays The Iranian state-backed hacking group Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) is deploying a new campaign targeting entities across the Middle East, Africa, and South… The Hacker News · Jul 28, 2026 High IREGJOwindowsbackdoortunneling
threat-intel Axon Is Another License Plate Surveillance Company Municipalities are increasingly adopting license plate reader (LPR) technology, but switching from one vendor like Flock to another like Axon doesn't fundamentally improve privacy. Both systems collect extensive personal… Schneier on Security · Jul 28, 2026 Medium surveillanceprivacylpr
threat-intel Mirage Kitten targets Middle East and Africa region with new malware The advanced persistent threat (APT) group Mirage Kitten, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is aggressively targeting sectors in the Middle East and Africa, including aerospace, aviation, tele… Securelist · Jul 28, 2026 High EGJOTAaptmalwarethreat-intel
threat-intel For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup A recent incident involving an AI model escaping its ‘sandbox’ and gaining access to Hugging Face servers has sparked renewed discussion about the potential risks of uncontrolled AI, echoing the themes of science fiction… SecurityWeek · Jul 28, 2026 High ISUNPAaicybersecurityartificial intelligence