vulnerability Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years A critical Linux kernel vulnerability, dubbed 'Copy Fail' (CVE-2026-31431), has been discovered allowing unprivileged local attackers to escalate their access to root across numerous Linux distributions since 2017. The f… Palo Alto Unit 42 · May 5, 2026 Critical CVE-2026-31431CVE-2026-314331USlinuxkernellpe
threat-intel How the Story of a USB Penetration Test Went Viral This Dark Reading Confidential episode recounts the viral 2006 pen test conducted by Steve Stasiukonis at a credit union, focusing on his use of rigged USB drives to observe employee behavior. The story gained traction t… Dark Reading · May 5, 2026 Medium social engineeringusbpen testing
apt UAT-8302 and its box full of malware Cisco Talos has identified UAT-8302, a China-nexus advanced persistent threat (APT) group, targeting government entities in South America and southeastern Europe. The group utilizes a range of custom malware families, in… Cisco Talos · May 5, 2026 High CVE-2025-0994BRCOCUchinaaptgovernment
threat-intel CloudZ RAT potentially steals OTP messages using Pheno plugin Cisco Talos identified an intrusion campaign initiated in January 2026 involving the deployment of the CloudZ remote access tool (RAT) alongside a new plugin called ‘Pheno.’ This campaign leveraged the Microsoft Phone Li… Cisco Talos · May 5, 2026 High USotpphone linkcredential theft
threat-intel A rigged game: ScarCruft compromises gaming platform in a supply-chain attack A North Korean-aligned APT group, ScarCruft (also known as APT37 or Reaper), conducted a supply-chain attack targeting a video game platform used by ethnic Koreans in the Yanbian region of China. The attackers injected a… WeLiveSecurity · May 5, 2026 High CNKPsupply-chainnorth-koreaespionage
threat-intel Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition A 19-year-old teenager, identified as "Bouquet," has been arrested in Finland and faces US extradition charges for allegedly being a member of the Scattered Spider cybercrime group. The investigation revealed the group’s… Graham Cluley · May 4, 2026 High USGBFIsocial engineeringphishingmfa
phishing “Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security This Securelist article details a concerning trend of attackers leveraging Amazon Simple Email Service (Amazon SES) for phishing campaigns. Attackers exploit legitimate access keys to send convincing emails that bypass s… Securelist · May 4, 2026 High USphishingawsamazon ses
threat-intel Essential Data Sources for Detection Beyond the Endpoint This Unit 42 report highlights the increasing speed of cyberattacks and the limitations of relying solely on endpoint detection and response (EDR) solutions. Attackers are now moving four times faster to exfiltrate data,… Palo Alto Unit 42 · May 1, 2026 High cloud securityendpoint detectionthreat intelligence
threat-intel 20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage This Dark Reading article celebrates the platform’s 20th anniversary, reflecting on its role in covering the evolution of cybersecurity over the past two decades. The piece highlights key moments and figures from the ind… Dark Reading · May 1, 2026 Medium UScybersecurityhistoryindustry
threat-intel That AI Extension Helping You Write Emails? It’s Reading Them First Palo Alto Unit 42 has identified 18 AI-powered browser extensions posing significant security risks. These extensions, masquerading as productivity tools, are actually delivering malicious payloads such as remote access… Palo Alto Unit 42 · Apr 30, 2026 High USaibrowser extensionsgenai
threat-intel Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber This article reports on Anthropic’s release of Claude, dubbed ‘Mythos,’ an AI model capable of rapidly identifying and exploiting software vulnerabilities, including zero-day bugs, across major operating systems and web… Dark Reading · Apr 30, 2026 High aivulnerabilitycybersecurity
threat-intel Great responsibility, without great power This article from Cisco Talos discusses the importance of empathy and understanding in cybersecurity, particularly in recognizing and responding to attacker behavior. It highlights five critical priorities for defenders… Cisco Talos · Apr 30, 2026 High CVE-2026-42208identityanomalythreat-hunting
threat-intel Anti-DDoS Firm Heaped Attacks on Brazilian ISPs A Brazilian DDoS protection firm, Huge Networks, was found to be running a botnet that launched massive DDoS attacks against Brazilian ISPs. This activity stemmed from a security breach in January 2026 that compromised t… Krebs on Security · Apr 30, 2026 High CVE-2023-1389BRUSddosbotnetdns
This month in security with Tony Anscombe – April 2026 edition Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 - here's some of what made the headlines this month WeLiveSecurity · Apr 30, 2026
Iran-linked Handala hackers leak US Marines data, send chilling WhatsApp threats US Marines stationed around the Persian Gulf have been receiving WhatsApp messages from strangers suggesting they call home and make their final goodbyes. Read more in my article on the Hot for Security blog. Graham Cluley · Apr 30, 2026
threat-intel Smashing Security podcast #465: This developer wanted to cheat at Roblox. It cost millions This podcast episode discusses a recent corporate hack stemming from an individual attempting to cheat at the Roblox game. The incident involved a developer gaining unauthorized access to a Microsoft 365 tenant, disablin… Graham Cluley · Apr 29, 2026 High microsoft 365security breachcorporate hack
apt Alleged Silk Typhoon hacker extradited to the United States to face charges A Chinese national, Xu Zewei, has been extradited to the United States to face charges related to his alleged involvement with the Hafnium hacking group, also known as Silk Typhoon. He is accused of attempting to steal c… Graham Cluley · Apr 29, 2026 Critical CHUSstate-sponsoredcyber espionageexchange server
threat-intel AI-powered honeypots: Turning the tables on malicious AI agents This article details a new approach to cybersecurity utilizing generative AI to create dynamic honeypots. By leveraging AI to simulate vulnerable systems and respond to attacker actions, defenders can actively manipulate… Cisco Talos · Apr 29, 2026 Medium CVE-2014-6271aihoneypotgenerative-ai
threat-intel NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later This Dark Reading Confidential episode features a retrospective discussion with Chris Inglis, former NSA Deputy Director during the Edward Snowden affair, 13 years after the events. The conversation focuses on the misund… Dark Reading · Apr 28, 2026 Low USRUnsasnowdenmetadata
threat-intel Five defender priorities from the Talos Year in Review This Cisco Talos report, part of their Year in Review, highlights five key priorities for cybersecurity defenders in the current threat landscape. The report emphasizes the increasing ease of attack due to readily availa… Cisco Talos · Apr 28, 2026 High USidentityvulnerabilityanomaly detection