threat-intel ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories This week's ThreatsDay highlights a diverse range of cyber threats, from global fraud operations and ransomware tool overlaps to sophisticated social engineering attacks and vulnerabilities in popular software. Key event… The Hacker News · Jul 9, 2026 High CVE-2026-9181CVE-2025-49760CVE-2025-59200CHTAESsocial engineeringphishingransomware
threat-intel Taiwan charges two businessmen over alleged role in Chinese espionage campaign Taiwanese authorities have charged two businessmen for allegedly facilitating a Chinese espionage campaign targeting Taiwanese politicians, academics, journalists, and civil society groups. The suspects operated a compan… The Record · Jul 8, 2026 High CHTAespionagephishingcybercrime
threat-intel China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors A China-linked advanced persistent threat group, UAT-7810, has expanded its arsenal with new backdoors, including LongLeash, DogLeash, and JarLeash, as part of a long-running espionage campaign. The group primarily targe… SecurityWeek · Jul 8, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717CNbackdooraptespionage
threat-intel ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More This week’s security recap highlighted several concerning trends, including a disruption of the NetNut residential proxy network used for botnet operations, a fake Proof-of-Concept (PoC) malware targeting vulnerability r… The Hacker News · Jul 6, 2026 High CVE-2026-48276CVE-2026-48283CVE-2026-48277USESSPbotnetproxymalware
threat-intel US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp The United States government is offering a $10 million reward for information leading to the identification of Russian cyber groups involved in targeting Signal and WhatsApp accounts. These groups, UNC5792 and UNC4221, a… The Record · Jun 29, 2026 High USUKRUsocial engineeringencryptionespionage
threat-intel FCC votes to toughen rules in bid to better protect undersea cables The FCC has voted to implement stricter regulations for undersea cables, aiming to bolster national security and protect internet traffic. This includes mandating licensing for submarine line terminal equipment (SLTE) an… The Record · Jun 26, 2026 High CHUKUSundersea cablescybersecuritynational security
threat-intel Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets Russia-linked APT Turla has been deploying a new .NET backdoor, dubbed StockStay, to conduct ongoing cyber espionage against Ukrainian government and military organizations, as well as entities with interests in Italian… SecurityWeek · Jun 26, 2026 High CVE-2025-8088UKRUITespionagebackdoorphishing
threat-intel Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks Google Threat Intelligence Group (GTIG) has identified a new backdoor, STOCKSTAY, developed and deployed by the Russian state-sponsored threat actor Turla. This multi-component backdoor, built using .NET and leveraging a… The Hacker News · Jun 26, 2026 High CVE-2025-8088UKITNEespionagebackdoorrussia
threat-intel Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses The Russian cyber espionage group Gamaredon (also known as Aqua Blizzard) has significantly upgraded its arsenal and tactics, becoming a more effective threat actor, particularly in support of the war in Ukraine. The gro… Dark Reading · Jun 25, 2026 High RUUKaptespionagec2
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
threat-intel SprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detection A new Windows variant of the SprySOCKS Linux backdoor, developed by the nation-state threat actor FishMonger (also known as Earth Lusca and Aquatic Panda), has been discovered targeting government organizations in Hondur… Dark Reading · Jun 16, 2026 High HNTWTHkernel-driveraptbackdoor
threat-intel China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Researchers have identified new Windows variants of the SprySOCKS backdoor, initially linked to the Chinese state-sponsored threat actor Earth Lusca (also known as Aquatic Panda). These variants, designated WIN_DRV and W… The Hacker News · Jun 16, 2026 High CVE-2023-24932CNTWHUbackdoorwindowsstealth
threat-intel FishMonger’s arsenal upgraded: SprySOCKS for Windows ESET researchers have discovered two new, undocumented Windows variants of FishMonger's SprySOCKS backdoor, operated by the Chinese threat actor I-SOON (believed to be part of the Winnti Group). These variants, WIN_DRV a… WeLiveSecurity · Jun 16, 2026 High CHHOTAwindowsbackdoorkernel driver
threat-intel Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails A China-linked espionage group, UNC6508, gained access to North American medical, academic, and military research networks via a backdoor on REDCap servers, stealing sensitive research and defense emails. The attackers e… The Hacker News · Jun 15, 2026 High CHUSCAespionageredcapgoogle workspace
threat-intel Chinese hackers breach REDCap servers, steal medical research A Chinese espionage campaign, attributed to UNC6508, targeted a North American medical research institution by exploiting vulnerabilities in the REDCap platform. The attackers deployed the custom malware, ‘Infinitered,’… BleepingComputer · Jun 15, 2026 High CHUSCAespionagecredential_theftredcap
apt Chinese hackers hijack auth flow, spy on isolated network for a decade Chinese cyber espionage group Velvet Ant conducted a decade-long operation, gaining persistent access to a large organization’s isolated critical infrastructure network by hijacking its authentication flow. The attackers… BleepingComputer · Jun 13, 2026 Critical CHespionageauthenticationpersistence
threat-intel FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers The FBI has taken down thirteen websites used by Chinese intelligence operatives to target and recruit U.S. government employees with access to sensitive information. These websites impersonated consulting firms offering… SecurityWeek · Jun 11, 2026 High USCNespionagerecruitmentcybersecurity
threat-intel OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack OceanLotus, a 15-year-old APT group with a history of targeting China and human rights activists, has been conducting a prolonged cyber espionage operation against Vietnamese entities, including a transport construction… The Hacker News · Jun 11, 2026 High VNsupply chainbackdoorespionage
threat-intel OceanLotus: From external espionage to domestic targeting OceanLotus, a Vietnamese-aligned cyberespionage group (formerly APT32), has shifted its focus from external espionage to domestic targeting, particularly in relation to corruption investigations in Vietnam. Since 2020, f… WeLiveSecurity · Jun 11, 2026 High VNsupply-chainespionagebackdoor
threat-intel UK weakens proposed telecoms defenses against Chinese hackers after industry pushback The UK government has weakened proposed cybersecurity protections for its telecoms networks in response to pushback from telecom companies regarding the cost and practicality of implementing measures designed to counter… The Record · Jun 9, 2026 High UKCHespionagetelecomscybersecurity