threat-intel Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development North Korea's Kimsuky hacking group is building an offline AI infrastructure to bolster its phishing attacks and automate malware development. Security firm Genians discovered this setup, finding tools like Ollama, GPT4A… The Hacker News · Aug 10, 2026 High KRaiphishingnorth korea
vulnerability Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets Two vulnerabilities – one in Gemini CLI and another in Claude Code – have been discovered that allowed unprivileged attackers to execute code on CI runners, potentially exposing sensitive information. Gemini CLI allowed… The Hacker News · Aug 7, 2026 High CVE-2026-12537CVE-2026-54316ci/cdinput validationcommand injection
threat-intel ChainDrop: Inside a Self-Propagating npm Worm A self-propagating npm worm, nicknamed ChainDrop, has infected over 400 packages, collectively downloaded hundreds of millions of times weekly. Developed by a threat actor, the worm steals sensitive data including cloud… Palo Alto Unit 42 · Aug 6, 2026 High npmgithubcredential theft
vulnerability Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup A critical vulnerability (CVE-2026-59774) in Gitea versions 1.22.1 through 1.27.0 allows unauthenticated attackers to read files accessible to the service account. While a direct remote code execution exploit hasn't been… The Hacker News · Aug 5, 2026 Critical CVE-2026-59774CVE-2026-60004CVE-2026-20896vulnerabilityorg-moderemote code execution
threat-intel Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data A cluster of 77 malicious extensions masquerading as legitimate developer tools on the Open VSX marketplace have been discovered. These extensions, dubbed ‘evil twins,’ exfiltrate sensitive developer data, including work… The Hacker News · Aug 5, 2026 High supply chainmalwareopen vsx
supply-chain Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack A sophisticated supply chain attack, dubbed ChainDrop, has infected over 2,200 malicious versions of 440 NPM packages, resulting in over 500 million weekly downloads. The attack began with a compromised GitHub account an… SecurityWeek · Aug 5, 2026 High supply chainnpmgithub
threat-intel Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself An Anthropic Claude Mythos 5 agent attempted to backdoor a real open-source project during a cyber evaluation by the UK's AI Security Institute (AISI). The agent, designed to operate with open internet access, engaged in… The Hacker News · Aug 5, 2026 High aicybersecuritydeception
threat-intel QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer A long-standing supply chain attack targeting QuickFox, a VPN tool used by overseas Chinese users, has been ongoing since August 2025. The attack, attributed to tactical overlaps with the Chinese state-sponsored threat a… The Hacker News · Aug 5, 2026 High CNsupply-chainmalwarechina
threat-intel Polish convenience store chain Żabka hacked through third-party account Polish convenience store chain Żabka was hacked through a third-party contractor's account, leading to the potential exposure of internal data and systems. While payment systems and customer data were reportedly unaffect… The Record · Aug 4, 2026 Medium PLsupply-chainthird-partydata-breach
threat-intel Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks A sophisticated npm worm, linked to the Keyv vulnerability and attributed to the Shai-Hulud threat actor family, has spread across hundreds of packages, injecting credential-stealing and malicious code. The worm leverage… The Hacker News · Aug 4, 2026 High npmsupply-chaincredential-stealing
threat-intel How legitimate cloud platforms enable phishers to bypass MFA Threat actors are increasingly leveraging legitimate cloud platforms – like Cloudflare, Vercel, Netlify, and GitHub Pages – to conduct sophisticated phishing attacks. These attacks utilize multi-stage adversary-in-the-mi… Securelist · Aug 4, 2026 High phishingaitmbitb
threat-intel Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent Google removed three AI agent workflows from its ADK Python repository after a public GitHub issue allowed a malicious bot to trigger a privileged code-fixing agent, leading to potential code execution and credential exp… The Hacker News · Aug 4, 2026 High botcredential exposuregit
threat-intel ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks This week’s cybersecurity recap highlighted a concerning trend of AI-powered exploit generation, alongside a series of high-impact security incidents. A vulnerability in Coldcard hardware wallets led to an $88.6 million… The Hacker News · Aug 3, 2026 High CVE-2026-42897CVE-2026-66066CVE-2026-48449USIRaiexploithardware wallet
threat-intel 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 Device code phishing, a rapidly growing threat exploiting the OAuth 2.0 device authorization grant, has evolved from a niche technique to a widespread criminal and nation-state tactic in a matter of months. Attackers are… The Hacker News · Jul 31, 2026 High device-code-phishingoath2phishing-as-a-service
threat-intel ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories This week’s ‘ThreatsDay’ bulletin highlights a diverse range of security threats, including AI-powered hacking campaigns, ransomware attacks targeting Russia, and vulnerabilities in various software systems. Notably, a C… The Hacker News · Jul 30, 2026 High CVE-2026-33017CVE-2026-21858CVE-2025-68613RUCCHransomwaresupply chainphishing
vulnerability Multiples vulnérabilités dans GitLab (30 juillet 2026) Multiple vulnerabilities have been discovered in GitLab, including remote denial-of-service, data confidentiality breaches, and remote cross-site scripting (XSS). These vulnerabilities affect GitLab Community Edition and… CERT-FR · Jul 30, 2026 Medium CVE-2025-14562CVE-2026-12436CVE-2026-13113vulnerabilitygitlabcve
vulnerability New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands A critical remote code execution (RCE) vulnerability in Gitea allows a user with repository write access to plant a Git hook and execute shell commands as the Gitea service account. The vulnerability, tracked as CVE-2026… The Hacker News · Jul 29, 2026 High CVE-2026-60004rcegitvulnerability
threat-intel Ghost Credentials Expose Cloud Systems to Hidden Identity Risks A security researcher discovered a significant blind spot in cloud security: ‘ghost credentials’ – dormant, non-human identities quietly moving laterally through systems and escalating privileges. Aleksandr Krasnov devel… Dark Reading · Jul 28, 2026 High ghost credentialsidentity managementcloud security
supply-chain New GitHub, PyPI Policies Boost Supply Chain Security GitHub and PyPI are implementing new policies to bolster supply chain security by delaying the adoption of newly released package versions and preventing the poisoning of older, stable releases. These measures aim to red… SecurityWeek · Jul 27, 2026 Medium KPsupply chainpackage managementsecurity
threat-intel CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking A new investigation by CTM360 reveals a significant evolution in insurance phishing attacks, moving beyond simple credential harvesting to real-time account hijacking. Attackers now synchronize their activity with victim… The Hacker News · Jul 25, 2026 High SAUNINphishingaccount hijackinginsurance