threat-intel Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud Two men were arrested in the Netherlands on suspicion of running a phishing operation targeting credit card details, leading to a significant increase in payment fraud within the country. The Dutch central bank reported… Graham Cluley · Jul 7, 2026 High NLEUphishingcredit card fraudcybercrime
threat-intel Google Is Suing Chinese Scammers Who Are Using Gemini Google is taking legal action against a Chinese group, Outsider Enterprise, who were leveraging Google's Gemini AI to create sophisticated phishing campaigns. The group utilized Telegram to offer ‘phishing-as-a-service,’… Schneier on Security · Jul 7, 2026 Medium CNphishingaigemini
threat-intel ISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. Specifically, the report… SANS Internet Storm Center · Jul 6, 2026 High icsotindustrial control systems
threat-intel Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT A China-nexus threat actor is conducting a targeted phishing campaign against Indian taxpayers and tax professionals, leveraging fake tax filing utilities to deploy a remote access trojan (DcRAT). The campaign, dubbed Op… The Hacker News · Jul 6, 2026 High CHINphishingremote access trojantax
threat-intel When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website A sophisticated phishing campaign leveraging the Microsoft Identity Platform's Device Authorization Grant protocol is being used to compromise user accounts. Attackers are crafting emails that appear to be from legitimat… Securelist · Jul 6, 2026 High phishingdevice-code-phishingmicrosoft
ransomware New Avalon Malware Framework Packs CrownX Ransomware Capabilities Researchers at Blackpoint Cyber discovered Avalon, a new modular malware framework used to deploy the CrownX ransomware. The framework utilizes a multi-stage phishing campaign to bypass security controls and performs cre… The Hacker News · Jul 3, 2026 High CVE-2025-3248USphishingcredential theftlateral movement
threat-intel Cyber readiness for SMBs: Getting the basics right This article highlights the ongoing importance of traditional cybersecurity threats for small and medium-sized businesses (SMBs), despite growing concerns about AI-powered attacks. The primary risks remain phishing, unpa… WeLiveSecurity · Jul 3, 2026 Medium USphishingvulnerabilityai
threat-intel Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign The Securelist report details a new cyber espionage campaign conducted by the Armored Likho (Eagle Werewolf) APT group, targeting government agencies and the electric power sector globally. The group utilizes a sophistic… Securelist · Jul 3, 2026 High RUBRKZaptphishinginfostealer
ransomware Ransomware Thugs Masquerade as Interpol to Entice Small Biz A new ransomware campaign is targeting small businesses globally, impersonating Interpol to lure victims into downloading malware. The campaign utilizes basic social engineering techniques, delivering a rudimentary ranso… Dark Reading · Jul 2, 2026 Medium USEUSAsocial engineeringphishingsmall business
threat-intel Catan and Mouse This Cisco Talos Threat Source newsletter highlights the emergence of ARToken, a sophisticated phishing-as-a-service (PhaaS) platform with capabilities previously undocumented. The platform, similar to EvilTokens, offers… Cisco Talos · Jul 2, 2026 High CVE-2026-48558USphishingbecai
threat-intel ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories This week’s security news highlights several vulnerabilities and ongoing threats across various sectors. A phishing campaign targeting small businesses globally with ransomware, a root escape vulnerability in Claude Cowo… The Hacker News · Jul 2, 2026 High CVE-2026-33825CHUNGEphishingransomwaresandbox
phishing ISC Stormcast For Thursday, July 2nd, 2026 https://isc.sans.edu/podcastdetail/9992, (Thu, Jul 2nd) The SANS Internet Storm Center's July 2nd, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing and malicious email campaigns. The broadcast highlighted several emerging trends and… SANS Internet Storm Center · Jul 2, 2026 Medium phishingemailthreat-intelligence
phishing Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS This article details a concerning trend in phishing attacks where threat actors are leveraging user-agent data to dynamically adapt their campaigns to the specific device and operating system of the victim. Attackers are… Dark Reading · Jul 1, 2026 High USphishinguser-agentmalware
ransomware Teen suspect in Scattered Spider hacks is extradited to US A 19-year-old man, Peter Stokes, with dual citizenship, has been extradited to the United States to face charges related to his involvement with the Scattered Spider cybercrime group. The investigation centers around a r… The Record · Jul 1, 2026 High USESFIphishingsocial engineeringransomware
threat-intel 19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges This article reports the extradition of a 19-year-old, Peter Stokes, known as "Bouquet," from Finland to the United States to face charges related to computer intrusion, fraud, and conspiracy as part of the Scattered Spi… The Hacker News · Jul 1, 2026 High USFIUKsocial engineeringphishinghelp desk
malware Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures The Ousaban banking trojan, originating in Brazil and previously tracked as Javali, is targeting Windows users in Spain and Portugal with a phishing campaign utilizing fake PDF lures. The trojan, which has evolved over t… The Hacker News · Jul 1, 2026 High PTESbanking trojanphishinggeofencing
threat-intel 'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat This article details a new supply chain threat dubbed "Phantom Squatting," where large language models (LLMs) are hallucinating non-existent web domains linked to legitimate brands. Cybercriminals are exploiting this by… Dark Reading · Jul 1, 2026 High USllmsupply chainai
threat-intel ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Cisco Talos has identified a new phishing-as-a-service (PhaaS) platform called ARToken, which shares significant similarities with the existing EvilTokens platform operated by Sekoia and tracked by Microsoft. ARToken uti… Cisco Talos · Jul 1, 2026 High USphishingeviltokensreact
threat-intel Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware This article details a new phishing and malware tactic called "phantom squatting," where large language models (LLMs) generate non-existent domain names that attackers quickly register and use to host malicious content.… The Hacker News · Jul 1, 2026 High USUAEUllmphishingdomain squatting
phishing ISC Stormcast For Wednesday, July 1st, 2026 https://isc.sans.edu/podcastdetail/9990, (Wed, Jul 1st) The SANS Internet Storm Center's July 1st, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The broadcast highlighted several emerging tr… SANS Internet Storm Center · Jul 1, 2026 Medium phishingemailbotnet