threat-intel The ransomware negotiator who was working for the other side A Florida man, Angelo John Martino III, was sentenced to 70 months in prison for secretly providing ransomware negotiation details and actively deploying BlackCat ransomware alongside two colleagues. He exploited his rol… Graham Cluley · Jul 14, 2026 Critical USransomwarenegotiationinsider threat
threat-intel CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks A new macOS information stealer, CrashStealer, is utilizing a sophisticated delivery chain involving a notarized dropper to bypass Gatekeeper and silently collect sensitive data from users. The malware, implemented in na… The Hacker News · Jul 13, 2026 High macosinformation stealernotarized dropper
threat-intel Europe revives law allowing big tech to scan for CSAM The European Parliament has revived a law allowing big tech companies like Google, Microsoft, and Meta to scan users' messages to detect child sexual abuse material (CSAM). This move, driven by a procedural vote and conc… The Record · Jul 10, 2026 Medium privacyencryptionchild_protection
threat-intel Fresh ATM Crypto Software Bugs: Jackpot or Bust? A researcher, Matt Burch, discovered nine vulnerabilities in CryptoPro Secure Disk, a full-disk encryption solution used by ATM manufacturer Diebold Nixdorf. These vulnerabilities could allow attackers to bypass encrypti… Dark Reading · Jul 10, 2026 High USatmencryptionjackpotting
threat-intel Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip Spanish authorities, with assistance from the FBI, arrested a man suspected of aiding pro-Russian hacktivist groups, specifically in facilitating the escape of a Ukrainian hacker linked to CARR. The investigation uncover… The Record · Jul 8, 2026 Medium SPPOBErussianhacktivismddos
vulnerability Hitachi Energy PROMOD V Hitachi Energy has identified an insecure HTTP transmission vulnerability in its PROMOD V product versions. This vulnerability, stemming from a lack of HTTPS support on the Digipede server, could allow attackers to inter… CISA Advisories · Jul 7, 2026 High CVE-2026-10763WOhttpvulnerabilitycybersecurity
threat-intel France to Stop Certifying Non-Quantum-Safe Encryption France’s cybersecurity agency, ANSSI, is implementing a significant shift in encryption standards. Starting in 2027, they will no longer certify security products that don't offer quantum-resistant encryption, effectivel… Schneier on Security · Jul 6, 2026 Medium FRencryptionquantumcybersecurity
threat-intel Microsoft Accelerates Post-Quantum Cryptography Shift to 2029 Microsoft is accelerating its transition to post-quantum cryptography (PQC) due to advancements in quantum computing technology, shifting the timeline for critical infrastructure protection. The company is implementing a… The Hacker News · Jul 1, 2026 High quantum computingpost-quantum cryptographypqc
threat-intel US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp The United States government is offering a $10 million reward for information leading to the identification of Russian cyber groups involved in targeting Signal and WhatsApp accounts. These groups, UNC5792 and UNC4221, a… The Record · Jun 29, 2026 High USUKRUsocial engineeringencryptionespionage
threat-intel Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff This report details how Russian authorities utilized Cellebrite's UFED forensic tools to access Andrey Pivovarov's iPhone 12 in June 2021, despite Cellebrite's subsequent announcement of a sales cutoff to Russia and Bela… The Hacker News · Jun 26, 2026 High RUGBJOforensiciphonecustody
threat-intel Trump directs federal agencies to protect US data from quantum threats President Trump issued two executive orders focused on bolstering U.S. cybersecurity against future threats from quantum computing. One order prioritizes accelerating the development and practical application of quantum… The Record · Jun 23, 2026 Medium USUKquantum computingcryptographycybersecurity
ransomware New Prinz Eugen ransomware prioritizes recent files for encryption A new ransomware variant, Prinz Eugen, is targeting organizations with a focus on encrypting recently modified files to maximize disruption. The group employs a hands-on-keyboard approach, utilizing legitimate RMM tools… BleepingComputer · Jun 20, 2026 High GBransomwarerdpencryption
threat-intel The browser blind spot: Why your security tool may not be blocking what you think it is [Guest Diary], (Wed, Jun 17th) This article highlights a significant security gap in Cloud Access Security Broker (CASB) deployments due to the increasing use of the QUIC protocol. CASBs, traditionally designed to inspect TCP traffic, fail to detect w… SANS Internet Storm Center · Jun 17, 2026 High quiccasbssl
data-breach Over 73,000 French govt employees affected in Tchap messenger breach A breach of the French government’s Tchap messaging platform has affected over 73,000 employees within the public sector. The attackers exploited a compromised user account to access public chat room data, including name… BleepingComputer · Jun 12, 2026 High FRmessagingdata breachencryption
threat-intel NSO Group Hacking WhatsApp Despite Court Order Recent reports indicate that NSO Group, a cybersecurity firm specializing in offensive intelligence, has been found to be utilizing its Pegasus spyware to target WhatsApp users despite a court order restricting its use.… Schneier on Security · Jun 10, 2026 High spywarewhatsappnsogroup
malware Argamal: Malware hidden in hentai games A new malware campaign, dubbed "Argamal," is targeting users of hentai games. The campaign involves injecting a malicious implant into legitimate game files, leveraging COM hijacking to establish persistence and achieve… Securelist · Jun 3, 2026 High UShentaicom hijackingpersistence
vulnerability ABB Terra AC Wallbox ABB has identified and addressed vulnerabilities in its Terra AC Wallbox product versions (<=1.8.33). These vulnerabilities, specifically related to heap and stack memory pollution due to improper handling of communicati… CISA Advisories · May 21, 2026 Medium CVE-2025-10504CVE-2025-12142CVE-2025-12143GLbluetoothfirmwarebuffer overflow
vulnerability Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit This report details a zero-day vulnerability, dubbed ‘YellowKey,’ affecting Windows 11 and Server 2025, allowing attackers to bypass BitLocker Device Encryption through a USB drive exploit. Microsoft has released a mitig… The Hacker News · May 20, 2026 High CVE-2026-45585USbitlockerwinrezero-day
vulnerability Zero-Day Exploit Against Windows BitLocker A new zero-day exploit, dubbed YellowKey, has been discovered targeting Windows BitLocker encryption. The vulnerability allows attackers to bypass BitLocker's security measures with physical access to the affected device… Schneier on Security · May 18, 2026 High zero-dayencryptionbitlocker