threat-intel ISC Stormcast For Friday, July 10th, 2026 https://isc.sans.edu/podcastdetail/10002, (Fri, Jul 10th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in widely used communication… SANS Internet Storm Center · Jul 10, 2026 High phishingvulnerabilityslack
threat-intel As Global Conflicts Go Digital, Businesses Need Wartime Gameplans As global conflicts become increasingly digital, businesses across various sectors are becoming increasingly vulnerable targets for nation-states engaged in warfare. The case of Intellect Services, a Ukrainian tax softwa… Dark Reading · Jul 9, 2026 High UKIRUNcyberwarfarenation-stategeopolitics
threat-intel UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge The UK government is launching a multi-faceted cybersecurity initiative, Cyber Shield, focused on leveraging agentic AI to bolster national cyber defenses against increasingly rapid AI-powered attacks. Simultaneously, th… SecurityWeek · Jul 9, 2026 High UKaicybersecuritynational security
vulnerability 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google A 15-year-old Linux kernel vulnerability, dubbed ‘GhostLock,’ has been exploited to earn a security researcher $92,000. The flaw allows for local privilege escalation and container escapes, highlighting the long-term ris… SecurityWeek · Jul 9, 2026 High CVE-2026-43499linuxkernelvulnerability
threat-intel Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images Meta has launched Muse Image, an AI tool that allows users to generate images using their public Instagram content. The feature is being rolled out gradually and users can opt-out of having their content used by the AI.… The Hacker News · Jul 9, 2026 Medium aiinstagrammeta
threat-intel Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself A 15-year-old in Japan used an AI chatbot to automatically cancel nearly 47,000 anime streaming subscriptions within hours. Simultaneously, researchers have documented the first fully autonomous, agentic AI-driven ransom… Graham Cluley · Jul 8, 2026 High JPairansomwarecyberattack
threat-intel Mexico's New Cyber Plan Faces Its First Real Test Mexico's National Cybersecurity Plan, designed to bolster the country's digital defenses ahead of the 2026 FIFA World Cup, is facing an early test. Despite the plan's goals – including establishing a National Cybersecuri… Dark Reading · Jul 8, 2026 High MEUNCAcybersecuritylatin americacyberattack
threat-intel EU unveils cyber plan to reduce reliance on foreign AI systems The European Commission has unveiled a cybersecurity and AI action plan aimed at reducing the EU’s reliance on foreign AI systems, particularly concerning access to ‘frontier’ AI models. The plan focuses on ensuring cybe… The Record · Jul 8, 2026 Medium EUUKaicybersecurityfrontier ai
threat-intel New Ghost Phishing Wave Is Breaking Traditional Email Security A new phishing technique called ‘ghost phishing’ is emerging, where malicious links appear harmless during initial email inspection but execute a more damaging attack within the victim’s browser. The EvilTokens campaign,… The Hacker News · Jul 8, 2026 High USEUphishingghost phishingmicrosoft 365
threat-intel The Verification Step Is the New ATO Battleground in 2026 The traditional methods of account takeover (ATO) – relying on stolen passwords – are becoming less effective due to the increasing adoption of passkeys and phishing-resistant authentication. Attackers are now shifting t… The Hacker News · Jul 8, 2026 High UNpasskeysgenerative aiaccount takeover
threat-intel State IDs for AI Agents: Will Estonia Set a Precedent? Estonia is planning to assign official government ID numbers to AI agents to regulate their use within government systems. This initiative, part of Eesti.AI, aims to enable organizations and individuals to utilize AI for… Dark Reading · Jul 8, 2026 Medium EEairegulationdigitalization
policy Supreme Court allows Texas app law requiring age verification to take effect The Supreme Court has allowed a Texas law requiring age verification for apps to take effect while a lower court considers its constitutionality. This law mandates that app developers and stores use age verification tool… The Record · Jul 7, 2026 Info USprivacyregulationfirst amendment
threat-intel Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker U.S. prosecutors have linked an alleged Scattered Spider hacker, Peter Stokes, to a luxury jewelry retailer breach through a persistent Windows device ID. Stokes, a dual U.S.-Estonian citizen, was extradited from Finland… The Hacker News · Jul 7, 2026 High ESFIUNdevice-idhackerintrusion
threat-intel Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants A critical session isolation vulnerability, dubbed WriteOut, has been discovered in Writer, an AI platform, allowing attackers to steal session tokens and gain control of user accounts across multiple organizations. The… The Hacker News · Jul 7, 2026 Critical session-hijackingtenant-isolationai
threat-intel UK cyber pledge draws only a handful of top firms despite ministerial appeal Despite a strong push from the UK government, only a small number of companies – around 15 out of 350 – signed the Cyber Resilience Pledge. The pledge, designed to improve cybersecurity across the UK economy, requires co… The Record · Jul 7, 2026 Medium UKcybersecuritycyber resiliencevoluntary pledge
threat-intel Canadian spy agency reports hacking three criminal groups in 2025 The Canadian Communications Security Establishment (CSE) conducted several authorized cyber operations targeting foreign criminal groups in 2025. These operations aimed to disrupt extremist groups spreading violent ideol… The Record · Jul 6, 2026 Medium CAcybersecuritynational securitycyber espionage
threat-intel Japanese teen arrested over cyberattack that disrupted anime streaming service A 15-year-old Japanese student was arrested for a cyberattack that disrupted an anime streaming service, Bandai Channel. The suspect exploited a vulnerability in the service’s servers and used ChatGPT to automate the fra… The Record · Jul 6, 2026 Medium JPcyberattackvulnerabilitychatgpt
threat-intel The Shift Toward Business-Aligned Risk Management This article discusses the shift towards business-aligned risk management within organizations. Traditional risk assessments, often relying on CVSS scores, can be ineffective without connecting them to tangible business… SecurityWeek · Jul 6, 2026 Medium risk managementcybersecurityvulnerability
threat-intel ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More This week’s security recap highlighted several concerning trends, including a disruption of the NetNut residential proxy network used for botnet operations, a fake Proof-of-Concept (PoC) malware targeting vulnerability r… The Hacker News · Jul 6, 2026 High CVE-2026-48276CVE-2026-48283CVE-2026-48277USESSPbotnetproxymalware
threat-intel Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages A vulnerability in Opera GX allowed malicious websites to silently install browser add-ons that could steal data from visited pages. Researchers demonstrated how a malicious iframe could install a mod, which then injecte… The Hacker News · Jul 6, 2026 High browsercssdata-theft