threat-intel Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths For a year, attackers leveraging the ShinyHunters group gained access to Salesforce environments not through exploiting vulnerabilities, but by exploiting trust placed in connected apps and vendors. They achieved this th… The Hacker News · Jul 14, 2026 High USoathconnected appsvendor compromise
threat-intel Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs A recent Australian Institute of Criminology survey revealed a decrease in overall cybercrime incidents and financial losses experienced by Australians in 2025 compared to 2024. However, this positive trend was largely d… Dark Reading · Jul 2, 2026 Medium AUsmbcybercrimeaustralia
vulnerability ST Engineering iDirect iQ-Series Terminals ST Engineering iDirect has issued a security advisory regarding vulnerabilities in its iQ-Series Terminals, specifically versions through 4.5.2.1. These vulnerabilities allow unauthorized access to device information, in… CISA Advisories · Jul 2, 2026 High CVE-2026-38059CVE-2026-38057USapiauthenticationcsrf
threat-intel Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects This Kaspersky report, based on 2025 compromise assessment engagements, highlights significant missed incidents due to inadequate monitoring, delayed detection, and communication gaps. The analysis reveals a concerning t… Securelist · Jul 2, 2026 High SACNRUmissed incidentsthreat detectionincident response
threat-intel Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Palo Alto Unit 42 researchers have identified a new supply chain threat: "phantom squatting," where large language models (LLMs) hallucinate web domains that adversaries can then register to intercept traffic generated b… Palo Alto Unit 42 · Jul 1, 2026 High USllmaisupply chain
supply-chain OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat This report details a significant supply chain attack leveraging OpenClaw’s Skill Marketplace, highlighting the emerging threat of AI agentic software. Malicious skills, including infostealers and evasion techniques, wer… Palo Alto Unit 42 · Jun 23, 2026 High USaiagenticsupply chain
threat-intel Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices Canadian spy agency, CSIS, utilized a novel court-ordered warrant to neutralize two foreign-run botnets operating within Canada. The operation targeted infected servers, SOHO routers, and IoT devices like Ring doorbells… The Hacker News · Jun 22, 2026 High CAUSbotnetiotcybersecurity
vulnerability Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT This CISA advisory details a vulnerability in the Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT, specifically version 0x0110_v1.1.0. The device is susceptible to unauthorized interception of sensitive health… CISA Advisories · Jun 18, 2026 High CVE-2026-50034CVE-2026-52866INbluetoothbleglucose
threat-intel The Hidden Security Risk in Modern Networks: The Work Between Tools This article highlights a critical operational challenge facing modern network security teams: the ‘work between tools.’ Despite advancements in technology and AI, organizations struggle with fragmented workflows when re… The Hacker News · Jun 9, 2026 Medium workflowautomationalerting
threat-intel Why the browser is now the front line for AI security This BleepingComputer article highlights the escalating threat of AI-powered phishing attacks, primarily targeting the browser environment. Adversaries are leveraging AI to rapidly create and deploy phishing kits, automa… BleepingComputer · Jun 2, 2026 High USaiphishingbrowser
threat-intel How SIEM helps MSPs reduce noise and stop threats faster This BleepingComputer article discusses the challenges MSPs face in managing security alerts due to fragmented security toolsets. The core issue is ‘alert fatigue’ and the inability to quickly identify and respond to act… BleepingComputer · May 28, 2026 High siemmspalert fatigue
threat-intel Smashing Security podcast #469: What your Oura ring won’t tell you This podcast episode, "Smashing Security" #469, discusses cybersecurity concerns, primarily focusing on the potential vulnerabilities of wearable devices like the Oura ring and broader issues within the cybersecurity ind… Graham Cluley · May 27, 2026 Medium CARUwearablesiotmalware
threat-intel Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective This article details a technique for evaluating the exploitability of Windows kernel mode drivers, focusing on the potential for BYOVD (Bring Your Own Vulnerability Driver) attacks. It highlights how vulnerabilities in d… The Hacker News · May 22, 2026 Medium USdriverbyovdkernel mode
malware Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files This report details the evolving tactics of the Gremlin stealer malware, specifically a recent variant employing sophisticated obfuscation techniques to evade detection. The malware, which targets sensitive data like pay… Palo Alto Unit 42 · May 15, 2026 High USobfuscationanti-analysisresource section