threat-intel Chinese hackers use new Atlas RAT malware in European cyberattacks A Chinese cybercrime group, tracked as TA4922, is expanding its operations with the deployment of new malware, including the Atlas RAT and RomulusLoader, targeting organizations across Europe and Southeast Asia. The grou… BleepingComputer · Jun 3, 2026 High CHGEITphishingremote access trojanmalware loader
malware Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT A new malspam campaign is leveraging Google's DoubleClick domain to deliver the DesckVB RAT, a .NET-based remote access trojan. The campaign’s scalability and cost-effectiveness stem from its ability to dynamically perso… The Hacker News · Jun 3, 2026 High USmalspamratdoubleclick
threat-intel Lessons for life: Why children’s data is a long-term identity risk This article highlights the growing risk of child identity theft and the broader vulnerability of children’s data in the digital age. Despite efforts to regulate online content for children, their data is increasingly ex… WeLiveSecurity · Jun 3, 2026 High identity theftdata privacyphishing
malware ISC Stormcast For Wednesday, June 3rd, 2026 https://isc.sans.edu/podcastdetail/9956, (Wed, Jun 3rd) The SANS Internet Storm Center's Stormcast for June 3rd, 2026 highlighted a concerning increase in malicious activity across the internet landscape. The broadcast detailed several ongoing threats, including observed phis… SANS Internet Storm Center · Jun 3, 2026 High phishingransomwaremalware
threat-intel FBI-Flagged Phishing Kit Kali365 Expands Its Reach The Kali365 phishing-as-a-service platform, initially focused on compromising Microsoft 365 accounts via MFA bypass, has significantly expanded its capabilities and target list. It now actively targets platforms like AWS… Dark Reading · Jun 2, 2026 High USRUphishingdevice-codemfa
threat-intel Why the browser is now the front line for AI security This BleepingComputer article highlights the escalating threat of AI-powered phishing attacks, primarily targeting the browser environment. Adversaries are leveraging AI to rapidly create and deploy phishing kits, automa… BleepingComputer · Jun 2, 2026 High USaiphishingbrowser
threat-intel The Zero-Knowledge Threat Actor and the End of Responsible Disclosure This article discusses the rise of ‘zero-knowledge’ threat actors, empowered by AI, who pose a significant new challenge to cybersecurity. These actors, lacking deep technical expertise, can rapidly discover and exploit… SecurityWeek · Jun 2, 2026 High aivulnerabilityphishing
phishing ISC Stormcast For Monday, June 1st, 2026 https://isc.sans.edu/podcastdetail/9952, (Mon, Jun 1st) The SANS Internet Storm Center's June 1st, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observe… SANS Internet Storm Center · Jun 1, 2026 Medium phishingemailthreat intelligence
malware ChatGPT share links abused to host fake outage pages to deliver malware Threat actors are exploiting ChatGPT's content-sharing feature to host convincing fake outage pages designed to trick users into downloading malware. This 'LLMShare' campaign leverages Google ads and a legitimate OpenAI… BleepingComputer · May 29, 2026 High aimalwarephishing
threat-intel ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface A vulnerability, dubbed ChatGPhish, has been discovered in OpenAI’s ChatGPT that allows attackers to leverage the AI’s summarization feature to create phishing attacks. By appending malicious content to a webpage, attack… The Hacker News · May 29, 2026 High CVE-2026-25592CVE-2026-26030USprompt injectionphishingai
threat-intel In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks This week’s cybersecurity news highlights a range of incidents, including a data breach affecting Trump Mobile customers, ongoing Russian government intrusion into US Treasury systems, and vulnerabilities in popular soft… SecurityWeek · May 29, 2026 High UNCHdata breachsupply chainphishing
threat-intel ISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950, (Fri, May 29th) The SANS Internet Storm Center's Stormcast for May 29th, 2026 highlighted several ongoing and emerging cyber threats. The report detailed a range of observed malicious activities, including increased phishing attempts an… SANS Internet Storm Center · May 29, 2026 Medium phishingvulnerabilitythreat intelligence
threat-intel GreyVibe hackers use ChatGPT, Gemini to power cyberattacks GreyVibe, a threat actor likely linked to Russia, has been conducting cyber espionage campaigns targeting Ukrainian organizations since August 2025, utilizing a diverse range of custom malware and AI-generated lures. The… BleepingComputer · May 28, 2026 High RUUKaiphishingmalware
threat-intel Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans A Chinese-speaking fraud gang, dubbed GHOST STADIUM, is impersonating FIFA's official website to steal credentials and payment details from fans seeking tickets for the 2026 World Cup. The operation, involving over 300 f… The Record · May 28, 2026 High CNUSCAfraudphishingworld cup
malware BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model An advanced Android remote access Trojan, BTMOB RAT, is spreading across Brazil and Latin America through a malware-as-a-service (MaaS) model. Delivered via a no-code interface, it allows cybercriminals to create malicio… Dark Reading · May 28, 2026 High BRARandroidratmaas
threat-intel ISC Stormcast For Thursday, May 28th, 2026 https://isc.sans.edu/podcastdetail/9948, (Thu, May 28th) The SANS Internet Storm Center's Stormcast for May 28th, 2026 highlighted a concerning increase in observed malicious activity across the internet. The report detailed several ongoing threats, including observed phishing… SANS Internet Storm Center · May 28, 2026 Medium phishingvulnerabilitythreat intelligence
threat-intel Ransomware Actors Show Up In Person to Steal Law Firm Data The Silent Ransom Group (SRG), also known as Luna Moth and UNC3753, is targeting law firms through sophisticated social engineering tactics, including impersonating IT personnel and conducting in-person visits to gain ac… Dark Reading · May 27, 2026 High RUsocial engineeringdata theftlaw firms
malware Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users Two separate malware campaigns are targeting Windows and Android users across Latin America and Europe, primarily focusing on banking trojans. The first campaign utilizes the Grandoreiro malware, an actively evolving ban… The Hacker News · May 27, 2026 High PTBRESbanking trojanandroid malwaredll side-loading
threat-intel FBI warns of in-person data theft attacks from extortion gang The FBI has issued a warning about the Silent Ransom Group (SRG), an extortion gang now employing in-person data theft tactics targeting U.S. law firms. This shift involves social engineering, including phishing and impe… BleepingComputer · May 27, 2026 High USsocial engineeringphishingdata theft
threat-intel FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data The FBI has issued an alert regarding a new tactic employed by the Silent Ransom Group (SRG) involving physical intrusion to steal data from law firms and other organizations. SRG is impersonating IT support personnel,… SecurityWeek · May 27, 2026 High social engineeringremote accessusb drive