data-breach French police arrest 21-year-old “HexDex” hacker over 100 alleged data breaches A 21-year-old man suspected of conducting approximately 100 data breaches since late 2025 - including a hack of the French Ministry of National Education that exposed records on almost a quarter of a million employees -… Graham Cluley · Apr 28, 2026 High
apt TGR-STA-1030: New Activity in Central and South America This intelligence report, TGR-STA-1030, details ongoing activity by a persistent cyber espionage group. Recent observations indicate a significant shift in the group's operational focus, concentrating on Central and Sout… Palo Alto Unit 42 · Apr 24, 2026 High cyber espionageregional focustps
threat-intel The calm before the ransom: What you see is not all there is This article highlights a common cybersecurity pitfall: organizations can become overly confident in their security posture due to a period of stability, leading to complacency and a failure to adequately assess current… WeLiveSecurity · Apr 24, 2026 High UScomplacencyrisk assessmentcybersecurity
threat-intel Frontier AI and the Future of Defense: Your Top Questions Answered This article from Palo Alto Networks Unit 42 analyzes the emerging threat posed by frontier AI models, particularly Anthropic’s Mythos, to cybersecurity. The rapid capabilities of these models – including vulnerability i… Palo Alto Unit 42 · Apr 23, 2026 High frontier aivulnerabilityexploit chaining
threat-intel It pays to be a forever student This article from Cisco Talos highlights the importance of broad knowledge beyond traditional cybersecurity for threat intelligence professionals. It emphasizes the need to understand diverse fields like economics and in… Cisco Talos · Apr 23, 2026 High CVE-2025-20333CVE-2025-20362aiphishingindustrial espionage
threat-intel Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System This report details a proof-of-concept (PoC) developed by Palo Alto Unit 42 demonstrating the potential of autonomous AI agents in launching offensive attacks against cloud environments. The PoC, utilizing a multi-agent… Palo Alto Unit 42 · Apr 23, 2026 High USaiautonomouscloud
apt GopherWhisper: A burrow full of malware ESET researchers have identified a new China-aligned Advanced Persistent Threat (APT) group, dubbed GopherWhisper, that targeted a Mongolian governmental entity. The group utilizes a diverse toolkit primarily built in Go… WeLiveSecurity · Apr 23, 2026 High MNaptchinago
threat-intel Smashing Security podcast #464: Rockstar got hacked. The data was junk. The secrets it revealed were not A data breach occurred at Rockstar Games, stemming from a hacker gaining access to the company's systems. The stolen data, initially believed to be embarrassing, ultimately revealed sensitive internal communications, inc… Graham Cluley · Apr 22, 2026 Medium data breachrockstar gamesinternal communications
threat-intel When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks This report details a novel attack technique, dubbed AirSnitch, that exploits vulnerabilities in Wi-Fi encryption protocols (WPA2 and WPA3-Enterprise) to bypass client isolation and intercept network traffic. The attack… Palo Alto Unit 42 · Apr 22, 2026 High wpa2wpa3wi-fi
ransomware ‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty A senior member of the Scattered Spider cybercrime group, Tyler Robert Buchanan, has pleaded guilty to wire fraud conspiracy and aggravated identity theft related to a series of text-message phishing attacks conducted in… Krebs on Security · Apr 21, 2026 High UKUSSPphishingsim-swapcryptocurrency
malware New NGate variant hides in a trojanized NFC payment app A new variant of the NGate malware, dubbed NGate, is targeting Android users in Brazil by abusing the legitimate HandyPay app. Threat actors used generative AI to modify HandyPay, allowing them to steal NFC data, includi… WeLiveSecurity · Apr 21, 2026 High BRnfcandroidmalware
threat-intel Fracturing Software Security With Frontier AI Models This report from Palo Alto Unit 42 highlights the emerging threat posed by advanced AI models, particularly "frontier AI models," which demonstrate autonomous vulnerability discovery and exploitation capabilities. The ra… Palo Alto Unit 42 · Apr 20, 2026 High UNNOaivulnerabilityzero-day
ransomware What the ransom note won’t say This article details the ongoing issues surrounding the BlackCat ransomware gang’s affiliate, who attempted to defraud the group after carrying out a significant attack on Change Healthcare. The incident highlights the i… WeLiveSecurity · Apr 20, 2026 High USransomwarefranchisesupply chain
threat-intel Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) This report from Palo Alto Unit 42 details a significant escalation of cyber risk originating from Iran following a 47-day internet outage. Iranian threat actors, identified as CL-STA-1128 (Cyber Av3ngers), are now aggre… Palo Alto Unit 42 · Apr 17, 2026 High USIRILoticsphishing
Singer loses life savings to fake wallet downloaded from the Apple App Store If you hold cryptocurrency, there's a very simple golden rule that you should always follow. Never hand over your seed phrase. Garrett Dutton, better known as G. Love - the front man of blues-hip-hop outfit G. Love & Spe… Graham Cluley · Apr 17, 2026
phishing That data breach alert might be a trap This article highlights the increasing sophistication and prevalence of fake data breach notification scams, driven by factors like record-breaking data breaches and the use of AI tools. Scammers are leveraging these not… WeLiveSecurity · Apr 17, 2026 High USDEphishingsocial engineeringai
threat-intel A Deep Dive Into Attempted Exploitation of CVE-2023-33538 This report details an ongoing attempt to exploit CVE-2023-33538, a vulnerability in older TP-Link Wi-Fi router models (TL-WR940N v2/v4, TL-WR740N v1/v2, TL-WR841N v8/v10). Automated scans, utilizing Mirai-like malware p… Palo Alto Unit 42 · Apr 16, 2026 High CVE-2023-33538USiotvulnerabilitymirai
Sometimes changing the password on your email mailbox isn’t enough Have you ever taken a look at your Microsoft 365 mailbox rules? If not, it might be worth a few minutes of your time. Because newly released research reveals that hackers may already have beaten you to it. Read more in m… Graham Cluley · Apr 16, 2026
supply-chain Supply chain dependencies: Have you checked your blind spot? This article highlights the growing risk of cyberattacks originating through supply chain vulnerabilities, particularly among small and medium-sized businesses (SMBs). It emphasizes that complex, digitized supply chains… WeLiveSecurity · Apr 16, 2026 High CVE-2019-15126CAUNsupply chaincybersecurityrisk management
threat-intel Smashing Security podcast #463: This AI company leaked its own code. It’s also built something terrifying This article discusses a concerning trend where AI companies are inadvertently leaking their own code and becoming targets for malicious actors. Tanya Janca highlights the vulnerability of software developers, particular… Graham Cluley · Apr 15, 2026 High CAsupply chaindeveloper securitycredential theft