threat-intel How We Added WebAuthn to a Browser-Based RDP Client This Palo Alto Unit 42 article details the development of a browser-based RDP client that supports WebAuthn redirection, allowing users to utilize security keys like YubiKeys during remote sessions. The team overcame sig… Palo Alto Unit 42 · Jul 2, 2026 Medium webauthnrdpbrowser
ransomware FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs The FortiBleed operation, initially focused on stealing credentials from thousands of Fortinet FortiGate firewalls, has expanded to involve ransomware-as-a-service (RaaS) gangs Inc Ransom and Lynx. SOCRadar researchers d… Dark Reading · Jul 2, 2026 High USGBcredential theftransomware-as-a-servicezero-day
threat-intel ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories This week’s security news highlights several vulnerabilities and ongoing threats across various sectors. A phishing campaign targeting small businesses globally with ransomware, a root escape vulnerability in Claude Cowo… The Hacker News · Jul 2, 2026 High CVE-2026-33825CHUNGEphishingransomwaresandbox
threat-intel ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API The ToddyCat APT group is utilizing a new malware, Umbrij, to gain unauthorized access to Gmail accounts via the Google API. Umbrij leverages the OAuth 2.0 protocol to obtain access tokens, allowing attackers to control… The Hacker News · Jul 2, 2026 High RUoauthgoogle apiheadless browser
data-breach Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches Multiple Japanese companies, including an insurer, brewer, manufacturer, and telecom provider, have recently disclosed significant cyber breaches impacting customer data and operational systems. The attacks range from a… The Record · Jul 1, 2026 High JASICAdata breachransomwarecyberattack
malware RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS A new botnet, RustDuck, is leveraging Rust programming to hijack routers, IP cameras, and servers for DDoS attacks. Developed by QiAnXin's XLab, the botnet utilizes a two-stage approach, exploiting vulnerabilities in dev… The Hacker News · Jun 30, 2026 High CVE-2017-17215CVE-2025-29635CVE-2024-1781CNddosbotnetrust
threat-intel This month in security with Tony Anscombe – June 2026 edition This month’s security roundup highlights a critical CISA policy demanding rapid patching of vulnerabilities for federal agencies, a targeted cyberattack campaign against US-based Automatic Tank Gauges (ATGs), a surge in… WeLiveSecurity · Jun 30, 2026 Medium USUKCAvulnerabilitycyberattacksocial media
threat-intel ToddyCat: your hidden email assistant. Part 2 This report details the tactics employed by the ToddyCat APT group, focusing on a new technique dubbed ‘Shadow Token via Remote Debug’ (STRD) to compromise Gmail accounts. The group utilized a tool named Umbrij to gain a… Securelist · Jun 30, 2026 High UScredential_accessgoogle_apioauth2
threat-intel AI Won't Wipe-Out Entry-Level Cybersecurity Jobs This Dark Reading article discusses the evolving role of entry-level cybersecurity professionals in the age of AI. Rather than eliminating these positions, AI is shifting the focus towards more strategic and analytical t… Dark Reading · Jun 26, 2026 Medium aiautomationcybersecurity
threat-intel Russia accuses Apple of ‘political censorship’ after VK apps removed from App Store Following the removal of VK apps from the Apple App Store, Russia has accused Apple of political censorship and a lack of trust, citing sanctions compliance. The move has sparked a diplomatic backlash from Russian offici… The Record · Jun 26, 2026 Medium RUsanctionscensorshiprussia
threat-intel FCC votes to toughen rules in bid to better protect undersea cables The FCC has voted to implement stricter regulations for undersea cables, aiming to bolster national security and protect internet traffic. This includes mandating licensing for submarine line terminal equipment (SLTE) an… The Record · Jun 26, 2026 High CHUKUSundersea cablescybersecuritynational security
threat-intel Surviving the Mythos Era: Richard Bejtlich on the Case for NDR This article discusses the challenges security teams face in investigating incidents due to the increasing volume of telemetry data and the accelerating pace of vulnerability discovery – often referred to as the ‘Mythos… The Hacker News · Jun 25, 2026 Medium UKnetwork detectionthreat huntingai
threat-intel Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access A zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN was exploited by an unknown threat actor, gaining root access to a communications service provider’s network. The attack involved anti-forensic technique… The Hacker News · Jun 25, 2026 Critical CVE-2026-20245CVE-2026-20127CVE-2026-20182zero-daysd-wanroot access
malware What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th) This SANS Internet Storm Center guest diary details an analysis of automated cybercrime activity observed through a honeypot, focusing on the Terrabot IoT botnet. The author, a BACS student, highlights the prevalence of… SANS Internet Storm Center · Jun 25, 2026 Medium CVE-2016-20017CVE-2018-10561CVE-2016-20016USiotbotnetscanning
threat-intel Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup This Smashing Security podcast episode discusses a potential security risk at FIFA where a hacker could have used a ‘rickroll’ tactic to disrupt the World Cup. The conversation highlights a Black Kite report detailing a… Graham Cluley · Jun 24, 2026 High UKNLSEransomwaresupply chainrickroll
vulnerability Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access A Mandiant report details how attackers exploited a zero-day vulnerability (CVE-2026-20245) in Cisco SD-WAN Manager, Controller, and Validator software to gain root access on targeted devices. The attackers initially gai… BleepingComputer · Jun 24, 2026 High CVE-2026-20245CVE-2026-20127CVE-2026-20182USzero-dayprivilege escalationroot access
vulnerability Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure Attackers exploited a critical vulnerability in Cisco Catalyst SD-WAN Controller (CVE-2026-20245) approximately two months before Cisco publicly disclosed it. The vulnerability, stemming from insufficient input validatio… Dark Reading · Jun 24, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127USsd-wanprivilege escalationzero-day
threat-intel Do CISOs Need a Code of Ethics? This article discusses the potential need for a code of ethics for Chief Information Security Officers (CISOs) due to concerns about self-dealing and prioritizing personal gain over organizational security. Robert "RSnak… Dark Reading · Jun 24, 2026 Medium cisoethicsvendor influence
threat-intel Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed This SecurityWeek article highlights the critical importance of accurate context for agentic AI systems, particularly in security applications. The piece explains that agentic AI, relying on speed and automation, can mak… SecurityWeek · Jun 24, 2026 High USGBagentic aillmcontext
threat-intel The Exploit Doesn't Exist. You Can Still Prove It Works Against You This BleepingComputer article discusses the rapidly decreasing timeframes for vulnerabilities to be exploited, driven by advancements in AI like Anthropic’s Mythos model. Traditional patching strategies are becoming inef… BleepingComputer · Jun 23, 2026 High CVE-2025-29824USaivulnerabilityexploitation