threat-intel Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Palo Alto Unit 42 researchers have identified a new supply chain threat: "phantom squatting," where large language models (LLMs) hallucinate web domains that adversaries can then register to intercept traffic generated b… Palo Alto Unit 42 · Jul 1, 2026 High USllmaisupply chain
threat-intel Phishers Gain Persistence at EU, Asia Hospitality Orgs Phishing campaigns targeting hospitality organizations in Europe and Asia are utilizing malicious zip files containing disguised image files to install persistent malware. These attacks, observed by Microsoft and Trend M… Dark Reading · Jun 30, 2026 High GBJPphishingpersistencesocial engineering
threat-intel What the Numbers Say About FIFA 2026 Cyber Risk This report from Check Point Research reveals a significant pre-emptive cyber threat landscape surrounding the FIFA World Cup 2026, with attackers already establishing infrastructure months in advance. The primary target… The Hacker News · Jun 30, 2026 High RUemailspoofingfraud
threat-intel 236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers A report by Infoblox has identified over 236,000 websites utilizing the DCloud Uni-App framework, many of which are being exploited for cryptocurrency scams, phishing attacks, and wallet draining operations. These sites,… The Hacker News · Jun 29, 2026 High ARUSGBscamphishingcrypto
threat-intel Inside the inbox: Why cybercriminals want to break into your email account Cybercriminals are increasingly targeting email accounts due to the wealth of personal and business information contained within them, including access to other accounts and potential blackmail material. Phishing attacks… WeLiveSecurity · Jun 29, 2026 High phishingsocial engineeringbec
phishing ISC Stormcast For Monday, June 29th, 2026 https://isc.sans.edu/podcastdetail/9986, (Mon, Jun 29th) The SANS Internet Storm Center's June 29th, 2026 Stormcast reported a heightened level of online threats, primarily focusing on phishing campaigns and malicious email activity. The report highlighted an increase in obser… SANS Internet Storm Center · Jun 29, 2026 Medium phishingemailthreat intelligence
threat-intel FBI: Russian hackers now target Signal backup recovery keys The FBI and CISA are warning about a phishing campaign orchestrated by Russian Intelligence Services (RIS) targeting Signal users. Attackers are now specifically seeking Signal Backup Recovery Keys to gain access to vict… BleepingComputer · Jun 26, 2026 High USRUUKphishingsignalrecovery key
threat-intel FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys The FBI and CISA have issued an updated advisory warning about Russian intelligence actors targeting Signal users, expanding their tactics to include obtaining Signal Backup Recovery Keys. This allows attackers to fully… The Hacker News · Jun 26, 2026 High USRUNEsignalphishingrecovery key
phishing Cybersecurity firms targeted by fraudulent OpenAI organization invites Cybersecurity firms are being targeted by a sophisticated phishing campaign where attackers create fraudulent OpenAI organizations, mimicking legitimate companies and inviting employees to join them. These invitations, a… BleepingComputer · Jun 26, 2026 Medium phishingopenaicredential_harvesting
threat-intel In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs This week’s cybersecurity news includes a Russian government operation utilizing Cellebrite software to target an opposition activist, a Scattered Spider group breach of Transport for London, and a significant data leak… SecurityWeek · Jun 26, 2026 High RUUKINaicyberespionagesupply chain
apt Turla group adds more malware to Russia’s espionage efforts against Ukraine The Turla group, a long-standing Russian cyber-espionage team, has expanded its operations against Ukraine by deploying a new malware strain called StockStay. This malware, developed since December 2022, targets Ukrainia… The Record · Jun 26, 2026 High UKITNEcyberespionagerussiaukraine
phishing Russian Intelligence Services Continue to Target Commercial Messaging Applications The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have issued a new PSA highlighting ongoing cyberattacks by Russian Intelligence Services (RIS) targeting commercial messaging applications. These at… CISA Advisories · Jun 26, 2026 Medium RUphishingcredential theftrussian intelligence
threat-intel Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant A phishing campaign targeting hotels and hospitality organizations is underway, utilizing deceptive ZIP files containing Node.js implants to gain access to front-desk machines. The campaign, discovered by Microsoft, empl… The Hacker News · Jun 26, 2026 High GBJPDKphishingnode.jston
threat-intel Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets Russia-linked APT Turla has been deploying a new .NET backdoor, dubbed StockStay, to conduct ongoing cyber espionage against Ukrainian government and military organizations, as well as entities with interests in Italian… SecurityWeek · Jun 26, 2026 High CVE-2025-8088UKRUITespionagebackdoorphishing
threat-intel SMB cyber readiness: the road to resilience starts here A recent ESET report reveals that while small and medium-sized businesses (SMBs) are increasingly confident in their cybersecurity budgets and preparedness, a significant number still struggle with implementing effective… WeLiveSecurity · Jun 26, 2026 Medium cybersecuritysmbphishing
phishing Bluekit phishing kit adopts browser-in-the-middle for login theft Bluekit, a phishing-as-a-service platform, has evolved by incorporating browser-in-the-middle (BitM) capabilities, allowing it to steal login credentials more effectively. The platform utilizes the rrweb JavaScript libra… BleepingComputer · Jun 25, 2026 High USphishingbitmbrowser-in-the-middle
threat-intel Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools This Securelist article details Kaspersky's 2026 threat analysis for small and medium-sized businesses (SMBs), highlighting a significant increase in cyberattacks disguised as artificial intelligence (AI) tools, particul… Securelist · Jun 25, 2026 High USaismbmalware
malware Malicious Edge extension abuses Native Messaging as bridge to malware A malicious Microsoft Edge extension, ‘Edgecution,’ was used in a ransomware attack by exploiting Native Messaging to bypass browser security sandboxes and deploy a Python-based backdoor. The attack, linked to the Payout… BleepingComputer · Jun 24, 2026 High USbrowser extensionnative messagingransomware
threat-intel ISC Stormcast For Wednesday, June 24th, 2026 https://isc.sans.edu/podcastdetail/9984, (Wed, Jun 24th) The SANS Internet Storm Center's Stormcast for June 24th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The broadcast detailed ongoing campaigns involving phishing attack… SANS Internet Storm Center · Jun 24, 2026 Medium phishingmalwarethreat-intelligence
threat-intel Scattered Spider Hackers Plead Guilty on Day 1 of Trial Two key members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, have pleaded guilty to criminal charges related to attacks against Transport for London and other organizations. The group, led by… Krebs on Security · Jun 23, 2026 High UKUSGBphishingransomwaresim swapping