threat-intel More than 100 water systems were hit in July cyberattacks Multiple U.S. water systems were targeted in a July cyberattack, with over 100 systems affected. The attacks involved exploiting vulnerabilities in Joomla extensions, allowing attackers to gain unauthorized access and po… The Register · 4d ago High USRUjoomlasupply chaincritical infrastructure
threat-intel NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions A new phishing toolkit called NovaCookies is being used to steal Microsoft 365 sessions by abusing legitimate Docusign notifications and mimicking genuine email shares. Developed by an adversary-in-the-middle (AitM) oper… The Hacker News · 4d ago High USUKCAphishingaitmmicrosoft 365
threat-intel 'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month A new adversary-in-the-middle (AitM) phishing service called ‘NovaCookies’ is offering a turnkey solution for attackers to steal Microsoft 365 sessions for $320 a month, bypassing MFA protections. The service provides lu… Dark Reading · 4d ago High USphishingaitmmicrosoft 365
threat-intel Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes A sophisticated phishing-as-a-service platform, dubbed AnonyMousKIT, is being used to target stolen Apple devices and trick owners into providing their passcodes and 2FA codes, enabling Activation Lock removal. Operated… The Hacker News · 4d ago High ZABRUSphishingactivation lock2fa
threat-intel ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · 4d ago Medium phishingvulnerabilitycredential theft
threat-intel WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android WhatsApp is bolstering its security by introducing passkeys and enhanced two-step verification to combat phishing attacks and improve account protection for users on both iOS and Android. This move aims to make it signif… The Hacker News · 5d ago Medium passkeysphishingsecurity
threat-intel Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows The Mirage2FA campaign, a commercial phishing-as-a-service toolkit, has impacted approximately 4,532 organizations, primarily in the US, by exploiting legitimate Microsoft 365 login flows and bypassing two-factor authent… The Hacker News · 5d ago High USINSGphishingmicrosoftmfa
threat-intel 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Researchers at OX Security discovered a campaign utilizing 24 npm packages to host fake Cloudflare CAPTCHA pages via unpkg mirrors, redirecting users to phishing infrastructure. The threat actors are leveraging npm's inf… The Hacker News · 5d ago High npmphishingmalware
threat-intel Crooks push Mac malware through fake OpenAI Codex ads Russian threat actors are leveraging fake OpenAI Codex advertisements to distribute malware targeting macOS users. The campaign uses a malicious installer disguised as a legitimate tool, aiming to compromise systems and… The Register · 5d ago Medium RUmacphishingmalware
threat-intel ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited ReliaQuest was targeted by the ShinyHunters group through a sophisticated phishing campaign mimicking security employees to gain access to an Okta dashboard. While the attackers gained temporary view-only access, they we… SecurityWeek · 6d ago Medium phishingsocial engineeringokta
threat-intel Tricky 'SynkLoader' Multitool May Herald Ransomware A sophisticated new malware family, dubbed ‘SynkLoader,’ is making a comeback of older, effective tactics, including screen locking and phishing, to facilitate ransomware attacks. The malware utilizes a combination of no… Dark Reading · 6d ago High phishingransomwarescreen-locking
threat-intel ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More This week saw a surge in high-impact cyberattacks and vulnerabilities, highlighting the increasing sophistication and speed of threat actors. AI is now being weaponized to craft exploit scripts targeting Siemens PLCs, wh… The Hacker News · 6d ago High CVE-2026-19478CVE-2021-27101CVE-2023-34362UNRUvulnerabilitysupply-chainransomware
threat-intel WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords Two new malware families, WordlistLoader and SynkLoader, are being used to deliver the Amatera Stealer via ClickFix phishing campaigns. WordlistLoader reconstructs shellcode for Amatera, utilizing techniques to evade det… The Hacker News · 6d ago High phishingransomwaremalware
threat-intel Security vets rally around $4 paper password books for sale in Australia This article is a collection of snippets from The Register, covering a range of cybersecurity and technology news. It highlights a vulnerability impacting Joomla websites through exploited extensions, a Microsoft SharePo… The Register · 6d ago Medium CHvulnerabilityphishingransomware
threat-intel 84 000 élèves visés par une fraude aux frais scolaires A coordinated phishing campaign targeting 84,000 students at Aix-Marseille University mimics previous scams originating from the Université Bretagne Sud, demanding €450 under the guise of school fees. Despite the univers… ZATAZ · Aug 23, 2026 Medium phishingscamstudent
threat-intel If you're not using AI to attack your own systems, your adversaries will As AI agents increasingly take on tasks traditionally performed by humans, including hacking, a new attack surface is emerging. Companies are now facing a surge in AI-enabled phishing, impersonation, and reconnaissance,… The Register · Aug 22, 2026 High aired teamingcyberattack
threat-intel Rentrée scolaire 2026 : les arnaques à surveiller The article details a surge in cyber scams targeting families and businesses during the 2026 school year preparations, leveraging the high volume of administrative tasks and financial transactions associated with the per… ZATAZ · Aug 22, 2026 High cyber-fraudsocial-engineeringschool-year
threat-intel Corée du Sud : des responsables politiques visés par une fuite A South Korean private certification agency has been hacked, exposing the contact information of high-ranking political figures and highlighting a major cybersecurity risk among third-party providers. Korean authorities… ZATAZ · Aug 22, 2026 High SOKENIcyberattackdata breachidentity theft
threat-intel AWS Security makes an inscrutable choice This article is a collection of security-related news snippets from The Register. It highlights a range of issues, including a phishing campaign impersonating Signal support, a zero-day vulnerability in on-prem SharePoin… The Register · Aug 21, 2026 Medium IRphishingzero-dayransomware
threat-intel Pokémon Center touché par la cyberattaque d’un prestataire A cyberattack targeting CEVA Logistics, a third-party logistics provider, has exposed customer data of the Pokémon Center in Europe. This follows a similar incident affecting Steam users and The Pokémon Company, with pot… ZATAZ · Aug 21, 2026 High FRsupply-chainphishingdata-breach