threat-intel Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs A recent Australian Institute of Criminology survey revealed a decrease in overall cybercrime incidents and financial losses experienced by Australians in 2025 compared to 2024. However, this positive trend was largely d… Dark Reading · Jul 2, 2026 Medium AUsmbcybercrimeaustralia
ransomware Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials The Anubis ransomware group, a rebranded version of Sphinx, is actively exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to gain initial access to victim networks. They leverage legitimate RMM tools like Scree… The Hacker News · Jul 2, 2026 High CVE-2025-5777USUKAUcitrixbleedransomware-as-a-servicecredential theft
ransomware Ransomware Thugs Masquerade as Interpol to Entice Small Biz A new ransomware campaign is targeting small businesses globally, impersonating Interpol to lure victims into downloading malware. The campaign utilizes basic social engineering techniques, delivering a rudimentary ranso… Dark Reading · Jul 2, 2026 Medium USEUSAsocial engineeringphishingsmall business
threat-intel Supreme Court decision threatens EU-US data transfer agreement A Supreme Court ruling questioning the independence of the U.S. Federal Trade Commission (FTC) poses a significant threat to the EU-U.S. Data Privacy Framework (DPF), a key agreement enabling data transfers between the t… The Record · Jul 2, 2026 High USEUdataprotectionprivacyeu-us
threat-intel FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations A large-scale credential theft campaign, dubbed FortiBleed, has been linked to both the INC and Lynx ransomware groups, utilizing stolen Fortinet credentials for follow-on intrusions. The operation involved extensive sca… The Hacker News · Jul 2, 2026 High CVE-2026-35616USLAAScredential theftransomwarefortinet
threat-intel 2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience This report from Bitdefender highlights a significant gap between cybersecurity awareness and operational resilience within organizations. Despite recognizing the growing importance of AI and the need to reduce the attac… The Hacker News · Jul 1, 2026 High USGBaicybersecurityrisk
threat-intel Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware This article details a new phishing and malware tactic called "phantom squatting," where large language models (LLMs) generate non-existent domain names that attackers quickly register and use to host malicious content.… The Hacker News · Jul 1, 2026 High USUAEUllmphishingdomain squatting
threat-intel House passes kids’ online safety bill, but Senate approval unlikely The House of Representatives passed the Kids Internet and Digital Safety (KIDS) Act, aiming to bolster online safety for children, but the bill faced criticism for lacking key provisions like a ‘duty of care’ and strong… The Record · Jun 30, 2026 Medium USonline safetychildrenprivacy
threat-intel Justices rule that cellphone location histories are protected by the Fourth Amendment The Supreme Court ruled that police use of cellphone location history data obtained from tech companies constitutes a Fourth Amendment search and requires a warrant. This decision effectively rejects the "third-party doc… The Record · Jun 29, 2026 High USfourth amendmentlocation trackingprivacy
threat-intel Ukraine to use seized crypto from cybercrime group to buy war bonds Ukraine is utilizing cryptocurrency seized from a notorious international cybercrime group to bolster its war effort. Over $8.3 million in digital assets, obtained from investigations targeting attacks across Europe and… The Record · Jun 29, 2026 High UKRUUScybercrimecryptocurrencywar bonds
threat-intel Inside the inbox: Why cybercriminals want to break into your email account Cybercriminals are increasingly targeting email accounts due to the wealth of personal and business information contained within them, including access to other accounts and potential blackmail material. Phishing attacks… WeLiveSecurity · Jun 29, 2026 High phishingsocial engineeringbec
ransomware Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk Recent breaches targeting educational institutions, including ransomware attacks on Oracle E-Business Suite and Instructure's Canvas platform, highlight the vulnerability of the sector due to legacy technology, understaf… Dark Reading · Jun 27, 2026 High USthird-party riskransomwareeducation
threat-intel SMB cyber readiness: the road to resilience starts here A recent ESET report reveals that while small and medium-sized businesses (SMBs) are increasingly confident in their cybersecurity budgets and preparedness, a significant number still struggle with implementing effective… WeLiveSecurity · Jun 26, 2026 Medium cybersecuritysmbphishing
threat-intel Robinhood Cuts Access Approval Time to Support High-Velocity Development This Dark Reading article reports on Robinhood’s efforts to streamline its system access approval process to support faster development cycles and incident response. The company’s previous reliance on company-managed dev… Dark Reading · Jun 25, 2026 Medium application securityremote accessincident response
threat-intel AI and Liability A German court ruled that Google is liable for its AI-generated search summaries, marking a significant shift in how internet publishers are held accountable. The ruling established that AI-generated content, particularl… Schneier on Security · Jun 25, 2026 Medium DEailiabilitygoogle
phishing Bluekit phishing kit adopts browser-in-the-middle for login theft Bluekit, a phishing-as-a-service platform, has evolved by incorporating browser-in-the-middle (BitM) capabilities, allowing it to steal login credentials more effectively. The platform utilizes the rrweb JavaScript libra… BleepingComputer · Jun 25, 2026 High USphishingbitmbrowser-in-the-middle
threat-intel Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability A popular Google Chrome ad blocker extension, Adblock for YouTube, with over 10 million installs, has been found to contain a dormant script injection capability. Researchers discovered the extension’s architecture allow… The Hacker News · Jun 25, 2026 High USadblockjavascriptprivacy
threat-intel Google releases new privacy controls for activity history, personalization Google is releasing new privacy controls for its Search services and Google Play, allowing users to manage their saved history and personalized recommendations more granularly. The changes separate these functions into d… BleepingComputer · Jun 24, 2026 Low privacysearchpersonalization
threat-intel Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup This Smashing Security podcast episode discusses a potential security risk at FIFA where a hacker could have used a ‘rickroll’ tactic to disrupt the World Cup. The conversation highlights a Black Kite report detailing a… Graham Cluley · Jun 24, 2026 High UKNLSEransomwaresupply chainrickroll
threat-intel ISC Stormcast For Wednesday, June 24th, 2026 https://isc.sans.edu/podcastdetail/9984, (Wed, Jun 24th) The SANS Internet Storm Center's Stormcast for June 24th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The broadcast detailed ongoing campaigns involving phishing attack… SANS Internet Storm Center · Jun 24, 2026 Medium phishingmalwarethreat-intelligence