threat-intel Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks Google has launched an AI-powered cybersecurity platform, AI Threat Defense, designed to proactively combat increasingly sophisticated cyberattacks leveraging artificial intelligence. This platform utilizes AI to identif… SecurityWeek · May 28, 2026 High GBaicybersecuritythreat detection
threat-intel Sextortionist sentenced to 33 years for targeting 145 children A Canadian man, Ramanan Pathmanathan, has been sentenced to 33 years in prison for a long-running sextortion scheme targeting over 145 children, primarily in the United States. The scheme involved blackmailing victims wi… BleepingComputer · May 28, 2026 Critical CAUSsextortionchild_exploitationonline_abuse
malware BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model An advanced Android remote access Trojan, BTMOB RAT, is spreading across Brazil and Latin America through a malware-as-a-service (MaaS) model. Delivered via a no-code interface, it allows cybercriminals to create malicio… Dark Reading · May 28, 2026 High BRARandroidratmaas
threat-intel ESET APT Activity Report Q4 2025–Q1 2026 ESET’s Q4 2025 – Q1 2026 APT Activity Report highlights a period of intense geopolitical activity driving advanced cyber espionage. China-aligned actors were mobilized to monitor maritime and energy developments, while I… WeLiveSecurity · May 28, 2026 High CHIRPOaptcyber espionagegeopolitics
threat-intel JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware A previously undocumented threat actor, dubbed JINX-0164, is targeting cryptocurrency firms through sophisticated social engineering tactics and bespoke macOS malware to steal digital assets. The campaign involves luring… The Hacker News · May 28, 2026 High KPmacossocial engineeringcryptocurrency
threat-intel Nordic CISOs Handle Rising Cyber Threats Remarkably Well A recent report by Truesec found that CISOs in Nordic countries are not experiencing a rise in severe cybersecurity incidents, despite a global increase in cyber threats. This surprising trend is attributed to improved c… Dark Reading · May 28, 2026 Medium NOcybersecuritynordicthreat intelligence
malware Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years In April 2026, a cybercrime gang has been using fake video player plugin updates to distribute a cryptocurrency miner, a tactic that has been ongoing since at least 2022. The gang leverages pirated digital libraries and… Securelist · May 28, 2026 High RUTOcryptominerstackoverflowfake update
threat-intel ISC Stormcast For Thursday, May 28th, 2026 https://isc.sans.edu/podcastdetail/9948, (Thu, May 28th) The SANS Internet Storm Center's Stormcast for May 28th, 2026 highlighted a concerning increase in observed malicious activity across the internet. The report detailed several ongoing threats, including observed phishing… SANS Internet Storm Center · May 28, 2026 Medium phishingvulnerabilitythreat intelligence
threat-intel Smashing Security podcast #469: What your Oura ring won’t tell you This podcast episode, "Smashing Security" #469, discusses cybersecurity concerns, primarily focusing on the potential vulnerabilities of wearable devices like the Oura ring and broader issues within the cybersecurity ind… Graham Cluley · May 27, 2026 Medium CARUwearablesiotmalware
threat-intel Out of the Crypt: The Evolving Cyber Extortion Economy This report from Palo Alto Unit 42 highlights a significant shift in the cyber extortion landscape, moving away from ransomware-based pressure towards pure data theft and extortion. The trend is driven by factors like ad… Palo Alto Unit 42 · May 27, 2026 High USdata theftextortionsupply chain
malware GPU mining malware spreads via SEO poisoning, AI chatbots A cryptojacking campaign utilizing SEO poisoning and AI chatbot manipulation is spreading through malicious downloads of popular system utilities. The campaign leverages a ZIP archive containing a malicious DLL and a Scr… BleepingComputer · May 27, 2026 High UScryptojackingseo poisoningai chatbots
ransomware Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th) This report details the reconstruction of an Akira ransomware attack on a mid-sized organization, focusing on the critical early stages of the intrusion. The analysis, based solely on firewall and Windows event logs, rev… SANS Internet Storm Center · May 27, 2026 High USbrute-forcecredential-stuffinglateral-movement
threat-intel Ransomware Actors Show Up In Person to Steal Law Firm Data The Silent Ransom Group (SRG), also known as Luna Moth and UNC3753, is targeting law firms through sophisticated social engineering tactics, including impersonating IT personnel and conducting in-person visits to gain ac… Dark Reading · May 27, 2026 High RUsocial engineeringdata theftlaw firms
policy Romanian national sentenced to more than 4 years for hacking Oregon government systems Dragomir was arrested in Romania in November 2024 and brought to the U.S. last year to face charges for hacking into the network belonging to Oregon’s Office of Emergency Management. The Record · May 27, 2026
threat-intel UK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About Russia British intelligence chief Anne Keast-Butler warned of the escalating threat posed by Russia’s cyber activities, particularly the weaponization of artificial intelligence, and emphasized the urgent need for increased cyb… SecurityWeek · May 27, 2026 High UKRUCHartificial intelligencecybersecurityrussia
data-breach Latin American Cybercriminals Hoover Up Government Data Recent investigations reveal a surge in cybercriminal activity targeting government agencies across Latin America, primarily driven by groups like La Pampa Leaks and the Chronus Group. These actors are stealing and monet… Dark Reading · May 27, 2026 High URMECOgovernmentdata breachlatin america
threat-intel AI-Assisted Exploit Development Outpaces Scanner Detection Research from Cogent indicates that AI-assisted exploit development is dramatically accelerating, reducing exploit creation time from 125 days to just 0.5 days using large language models. This creates significant ‘visib… Dark Reading · May 27, 2026 Critical USaiexploitvulnerability
malware Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users Two separate malware campaigns are targeting Windows and Android users across Latin America and Europe, primarily focusing on banking trojans. The first campaign utilizes the Grandoreiro malware, an actively evolving ban… The Hacker News · May 27, 2026 High PTBRESbanking trojanandroid malwaredll side-loading
malware Malicious npm Package Stole Files From Claude AI User Directory via GitHub A malicious npm package, "mouse5212-super-formatter," was discovered that leveraged GitHub to steal files from Anthropic's Claude AI user directory. The package masqueraded as a legitimate archive deployment sync utility… The Hacker News · May 27, 2026 High USnpmgithubai
threat-intel Rudd orders Cyber Command reviews as Pentagon presses reform agenda U.S. Cyber Command is undergoing a comprehensive review commissioned by newly appointed head Gen. Joshua Rudd to modernize the military’s digital warfare arm. The review, led by MITRE, will examine acquisition processes… The Record · May 27, 2026 Medium UNcybersecuritymodernizationacquisition