threat-intel Rondo Meets Geoserver, (Wed, Jul 22nd) A Rondo botnet attack targeting Geoserver, a geographic information system tool, is being observed. The attack leverages a vulnerability (CVE-2024-36401) to execute arbitrary shell commands, delivering a Rondo payload. T… SANS Internet Storm Center · Jul 22, 2026 Medium CVE-2024-36401vulnerabilitybotnetgeoserver
vulnerability Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks A fourth SharePoint vulnerability, CVE-2026-50522, is being actively exploited in the wild, allowing attackers to execute arbitrary code on SharePoint servers. Threat actors are specifically targeting SharePoint machine… SecurityWeek · Jul 22, 2026 High CVE-2026-50522CVE-2026-58644CVE-2026-56164sharepointvulnerabilityremote code execution
threat-intel Council worker spared prison after four-day data-snooping spree This article is a collection of security and technology news snippets. A House worker was spared prison after a data snooping spree, while Microsoft’s SharePoint remains vulnerable to zero-day attacks. Additionally, a Ru… The Register · Jul 22, 2026 Medium RUSWphishingvulnerabilitycybersecurity
threat-intel DNI nominee Clayton wins Senate panel’s approval The Senate Intelligence Committee has approved Jay Clayton as the next Director of National Intelligence. This approval paves the way for a full Senate vote, potentially enabling the renewal of Section 702 of the FISA Ac… The Record · Jul 21, 2026 Info fisasurveillancenational security
vulnerability Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC A critical SharePoint vulnerability (CVE-2026-50522) is currently being actively exploited, allowing attackers to execute code remotely and steal machine keys. Microsoft released a patch last month, but attackers are lev… The Hacker News · Jul 21, 2026 Critical CVE-2026-50522CVE-2026-56164CVE-2026-58644sharepointvulnerabilityrce
threat-intel Taiwan to slow mobile data during national resilience drills Taiwan is conducting a national resilience drill to simulate communication disruptions, primarily targeting mobile data services, to prepare its citizens for potential network outages during emergencies, especially in th… The Record · Jul 21, 2026 Info TWresiliencecommunicationsdisruption
threat-intel Kenya probes hack of president's website after bitcoin ransom demand Kenya’s presidential website was hacked, with attackers demanding a ransom of five bitcoins in exchange for not releasing sensitive information. The incident follows a previous coordinated attack in November 2025, highli… The Record · Jul 21, 2026 Medium KEcyberattackransomwaregovernment
threat-intel New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication HollowGraph, a new malware dubbed by Group-IB, leverages Microsoft 365 calendars to establish command-and-control communication, specifically targeting Israeli entities. The malware uses a sophisticated technique to hide… SecurityWeek · Jul 21, 2026 High ILmicrosoft 365c&ccalendar
threat-intel Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine's CERT-UA has warned that Russian hackers, specifically a branch of the Sandworm group, are using fake CAPTCHA challenges to trick users into executing PowerShell commands on their own computers, installing recon… Graham Cluley · Jul 21, 2026 High RUclickfixpowershellcaptcha
threat-intel Fuite revendiquée au Rassemblement national ? A pirate claims to have compromised the website of the French far-right party, Rassemblement National (formerly Front National), and is offering a recent SQL dump for sale. The dump, allegedly containing 95 tables, inclu… ZATAZ · Jul 21, 2026 High FRdata breachsql dumpwordpress
threat-intel Scammers impersonate FBI on social media, prey on crime victims Scammers are impersonating the FBI on social media to trick victims, particularly those involved in crime, into divulging sensitive information. This tactic is part of a broader trend of online fraud and disinformation c… The Register · Jul 20, 2026 Medium CHsocial engineeringphishingfraud
threat-intel Flock Safety kills acoustic system designed to detect 'human distress' Flock Safety has scrapped its acoustic gunshot detection system, initially designed to identify ‘human distress’ through audio analysis. The decision follows significant privacy concerns raised by the Electronic Frontier… The Record · Jul 20, 2026 Medium surveillanceprivacycivil liberties
threat-intel Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign A cybercriminal, utilizing AI coding tools and a sophisticated pipeline, exposed a comprehensive phishing toolkit targeting Mexican users and beyond. The operator, likely leveraging LLMs and tools like Coderrr, created a… The Hacker News · Jul 20, 2026 High CVE-2025-33053CVE-2026-21513CVE-2025-24054MXUSDEphishingwebdavai
threat-intel Hackers were inside South Korea's diplomat training system for 9 months Hackers gained unauthorized access to South Korea's diplomat training system for nine months, stealing personal information from former and current Ministry of Foreign Affairs employees. The breach was facilitated by a p… The Record · Jul 20, 2026 High KRdata breachzero-daydiplomacy
threat-intel Romania races to restore land registry after cyberattack disrupts property market A major cyberattack disrupted Romania's land registry system, causing a standstill in property transactions and delaying a planned increase in property taxes. The attack, attributed to a threat actor named ByteToBreach,… The Record · Jul 20, 2026 High ROcyberattackland registryproperty
threat-intel HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 A sophisticated espionage implant, dubbed HollowGraph, is using a hijacked Microsoft 365 calendar as its command and control channel to steal data and deliver instructions. The malware, linked to the Iranian threat group… The Hacker News · Jul 20, 2026 High ISIRespionagecommand-and-controlmicrosoft 365
threat-intel Cybersecurity Keeps Events 'Uneventful' This article discusses the importance of proactive digital threat intelligence in securing major events. It highlights that threats often emerge long before physical security measures are in place, frequently originating… Dark Reading · Jul 20, 2026 Medium digital intelligenceevent securitythreat hunting
threat-intel ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More This week saw a flurry of vulnerabilities and attacks, including a WordPress core flaw leading to remote code execution, exploitation of zero-day vulnerabilities in SonicWall VPN appliances, and a new malware framework (… The Hacker News · Jul 20, 2026 High CVE-2026-63030CVE-2026-60137CVE-2026-15409INTÜBRvulnerabilityzero-dayransomware
threat-intel Inc Ransomware Exploits SonicWall SMA Zero-Days A major ransomware group, Inc, has been exploiting two zero-day vulnerabilities in SonicWall SMA appliances to gain remote code execution and escalate privileges, allowing them to infiltrate enterprise networks, steal cr… Dark Reading · Jul 17, 2026 High CVE-2026-15409CVE-2026-15410zero-dayransomwarevulnerability
threat-intel Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear The White House launched Gold Eagle, a voluntary initiative aimed at coordinating vulnerability response across critical infrastructure sectors, leveraging AI to accelerate the patching process. However, the initiative i… Dark Reading · Jul 17, 2026 Medium vulnerabilityaicybersecurity