threat-intel Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026 Black Hat USA 2026 highlighted significant concerns surrounding the evolving cybersecurity landscape in the age of artificial intelligence. The conference focused on the potential disruption to the CVE program due to AI-… Dark Reading · 3d ago High aivulnerabilitycybersecurity
threat-intel ATF responds to 'major' cybersecurity incident after ransomware gang's claims This article reports on a significant cybersecurity incident involving a ransomware gang claiming to have exploited a vulnerability in on-prem Microsoft SharePoint, leading to a response from the US Department of Justice… The Register · 3d ago High IRransomwarevulnerabilitysharepoint
threat-intel DOJ firearms agency says hackers breached system containing investigation targets The Bureau of Alcohol, Tobacco, and Firearms (ATF), a part of the Department of Justice, suffered a cyberattack that exposed information about ongoing investigations. The attack was carried out by the Qilin ransomware ga… The Record · 3d ago High ransomwarecyberattackjustice department
threat-intel Russian Hackers Phish EU Officials Over Messaging Apps Russian state-sponsored hackers are increasingly using messaging apps like WhatsApp and Signal to spear-fish EU government officials, bypassing traditional email security measures. The attacks, targeting high-ranking ind… Dark Reading · 3d ago High RUCHIRphishingsocial engineeringmessaging
threat-intel Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools A new campaign targeting Cambodia is utilizing a sophisticated multi-stage attack leveraging a vulnerable OPSWAT driver to deploy the open-source remote access trojan, Spark RAT. Attackers are using deceptive phishing em… The Hacker News · 3d ago High CVE-2026-36425KHphishingransomwaremalware
threat-intel Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services A pro-Russian hacker group, Server Killers, claimed responsibility for a sustained cyberattack targeting multiple Norwegian government digital services. The attack, initiated following Norway’s increased security coopera… SecurityWeek · 3d ago High NORUDEcyberattackrussiacyberwar
threat-intel FBI seizes hacking tools it says China used to attack NASA, DOE, US Senate and other critical networks The FBI has seized hacking tools believed to have been used by Chinese state actors to target critical US infrastructure, including NASA, the Department of Energy, and the US Senate. These tools were used to conduct reco… The Register · 3d ago High CVE-2019-11510CVE-2019-19781CHcyber espionagestate-sponsoredcritical infrastructure
threat-intel Dark Caracal Adds New Malware to Cyber Espionage Arsenal The Dark Caracal cyber-espionage group, linked to Lebanon, has added a new modular malware framework called GoCaracal to its arsenal. This framework, developed since 2026, is used for data theft, maintaining persistent a… Dark Reading · 3d ago High LBVEBRcyber-espionagedata theftmalware
threat-intel FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations The FBI has disrupted a Chinese-linked hacking infrastructure, QScan and QTRouter, operated by the group QTFY, which has been targeting U.S. critical infrastructure since 2018. These tools were used to steal data and con… The Hacker News · 4d ago High CVE-2024-8190CVE-2024-8963CVE-2024-9380CHcyber espionageiotproxy
threat-intel US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate The U.S. Department of Justice and FBI have taken down Chinese hacking tools – QScan and QTRouter – used by China’s Ministry of State Security and People’s Liberation Army to target U.S. agencies, including the Federal R… The Record · 4d ago High CHchinaiotcyberattack
threat-intel CISA Adds Six Known Exploited Vulnerabilities to Catalog The CISA has expanded its Known Exploited Vulnerabilities (KEV) Catalog with six new vulnerabilities, many of which are actively being exploited. Federal agencies are urged to prioritize patching these vulnerabilities, p… CISA Advisories · 4d ago High CVE-2015-3246CVE-2015-5287CVE-2019-1068vulnerabilitypatchrisk
threat-intel 'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month A new adversary-in-the-middle (AitM) phishing service called ‘NovaCookies’ is offering a turnkey solution for attackers to steal Microsoft 365 sessions for $320 a month, bypassing MFA protections. The service provides lu… Dark Reading · 4d ago High USphishingaitmmicrosoft 365
threat-intel Nigeria Looks to Sovereign Cloud for Cyber, National Security Nigeria is pursuing a sovereign cloud initiative to bolster its national cybersecurity, economic development, and technological independence. Driven by increasing cyberattacks and a desire to reduce reliance on foreign c… Dark Reading · 4d ago Medium NGsovereign cloudcybersecuritydata residency
threat-intel Is Cyber Facing an Affordability Crisis? The cybersecurity industry is facing an ‘affordability crisis’ driven by rapidly rising breach costs and defense spending, disproportionately impacting small and medium-sized businesses (SMBs) who often lack the resource… Dark Reading · 5d ago High cybersecurityaffordabilitysmb
ddos Large DDoS attack knocks Norwegian public services offline A massive DDoS attack has severely disrupted several Norwegian public services for over 30 hours, impacting digital identity verification and government data exchange. The attack, the third of its kind since June, is sig… The Record · 5d ago Medium NOddosdhscyberattack
vulnerability CISA Warns of Exploited Oracle WebLogic Vulnerability The CISA has issued a critical warning to federal agencies about a widely exploited vulnerability in Oracle WebLogic servers (CVE-2026-21962). This flaw allows attackers to execute code remotely without authentication, a… SecurityWeek · 5d ago Critical CVE-2026-21962CNoracleweblogicvulnerability
vulnerability Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data A critical, actively exploited vulnerability in Oracle WebLogic Server allows unauthenticated attackers to access sensitive data. Despite patches being released in January, threat actors are still leveraging this flaw, p… The Hacker News · 5d ago Critical CVE-2026-21962CVE-2020-14882CVE-2020-2551rceweblogiccve-2026-21962
vulnerability Exploited Zimbra Flaw Highlights Shrinking Window to Patch A critical vulnerability in Zimbra Unified Communications Suite (ZCS) is being aggressively exploited, prompting CISA to issue a three-day deadline for federal agencies to patch. The flaw, CVE-2026-73570, allows unauthen… Dark Reading · 5d ago High CVE-2026-73570CVE-2026-73750CVE-2025-66376PORULIpatchingvulnerabilityremote code execution
threat-intel ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More This week saw a surge in high-impact cyberattacks and vulnerabilities, highlighting the increasing sophistication and speed of threat actors. AI is now being weaponized to craft exploit scripts targeting Siemens PLCs, wh… The Hacker News · 6d ago High CVE-2026-19478CVE-2021-27101CVE-2023-34362UNRUvulnerabilitysupply-chainransomware
threat-intel Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt AI coding tools are accelerating the influx of open-source packages into organizations’ software stacks, leading to a growing backlog of security vulnerabilities and remediation debt. A recent study of 300 enterprise le… The Hacker News · 6d ago Medium aiopen-sourcevulnerability