threat-intel Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks A sophisticated npm worm, linked to the Keyv vulnerability and attributed to the Shai-Hulud threat actor family, has spread across hundreds of packages, injecting credential-stealing and malicious code. The worm leverage… The Hacker News · Aug 4, 2026 High npmsupply-chaincredential-stealing
threat-intel Fake IRS letters target cryptocurrency holders Scammers are impersonating the IRS to trick cryptocurrency holders into visiting fake websites designed to steal their personal information and digital assets. The IRS does not operate a Digital Asset Compliance Portal,… Graham Cluley · Aug 4, 2026 High HOROphishingcryptocurrencyfraud
threat-intel [Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents This Cisco Talos webinar will provide a behind-the-scenes look at some of the most significant cybersecurity incidents they handled in Q2 2026, focusing on how they responded and the strategic implications for organizati… Cisco Talos · Aug 3, 2026 Info incident-responsecybersecuritywebinar
threat-intel An analysis of incidents at Brazilian educational institutions This report details cyberattacks targeting educational institutions in Brazil since 2025, highlighting a trend of leveraging readily available tools and valid accounts to gain access and deploy ransomware and other malwa… Securelist · Aug 3, 2026 High BRransomwarethreat-intelinsider-threat
threat-intel Pass the Passkey: A Novel Attack Surface in Passwordless Authentication This report details a new attack vector, dubbed ‘Pass-ta-key,’ that allows malware running on a compromised endpoint to bypass traditional security measures and gain unauthorized access to passkey-protected accounts. Res… Palo Alto Unit 42 · Aug 3, 2026 High USpasskeyauthenticationmalware
threat-intel Black Hat special: Rewind and revisit This article is a promotional piece from Cisco Talos highlighting their Humans of Talos series, a podcast showcasing the diverse backgrounds of threat intelligence professionals. It announces their presence at Black Hat… Cisco Talos · Jul 30, 2026 Info threat-intelpodcastblack hat
threat-intel Mythos Asks the Right Question. It Doesn't Answer It. The article argues that AI-powered exploit discovery tools like Mythos are compressing the time between vulnerability disclosure and exploitation, but the real problem isn't faster patching – it's that most security team… The Hacker News · Jul 29, 2026 High vulnerabilitythreat-intelai
threat-intel ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques to steal credentials. The threat landscape is evolving rapi… SANS Internet Storm Center · Jul 29, 2026 High phishingcredential-stealingbusiness-application
threat-intel Mirage Kitten targets Middle East and Africa region with new malware The advanced persistent threat (APT) group Mirage Kitten, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is aggressively targeting sectors in the Middle East and Africa, including aerospace, aviation, tele… Securelist · Jul 28, 2026 High EGJOTAaptmalwarethreat-intel
threat-intel 'Wrench' attacks against crypto holders appear to be on the rise Crypto theft is increasingly shifting from online attacks to physical coercion, known as ‘wrench’ attacks. CertiK reports a 33% year-over-year increase in these in-person attacks, with a significant rise in associated fi… The Record · Jul 24, 2026 High FRUNGEcryptophysical-securityself-custody
threat-intel ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions and a concerning trend of Log4j exploitation attempts. The threat landscape remains volatile, with attack… SANS Internet Storm Center · Jul 24, 2026 Medium phishinglog4jbec
threat-intel Year-long Russian attacks infect users as soon as they look at an email Russian actors are leveraging phishing attacks, impersonating Signal support, to compromise users. This follows a broader trend of Russian state-sponsored actors targeting various systems and platforms, including exploit… The Register · Jul 23, 2026 High CVE-2025-66376RUphishingthreat-intelrussian
threat-intel Talking smack about a doctor got him access to private medical files This article is a collection of security and technology news snippets. It highlights a vulnerability impacting Joomla websites due to extension bugs, a Russian phishing campaign mimicking Signal support, and Microsoft's… The Register · Jul 23, 2026 Medium RUIRvulnerabilityphishingransomware
threat-intel ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions with sophisticated spear-phishing attacks. The campaigns leveraged stolen credentials and a new, highly c… SANS Internet Storm Center · Jul 23, 2026 High phishingspear-phishingcredential-stuffing
threat-intel Fake Bahrain Alert App Deploys Android Surveillance Malware A malicious Android application, dubbed ‘BH Alert,’ is being distributed through fake Google Play sites mimicking Bahraini government entities to deliver a four-stage surveillance platform. The app leverages users' trust… Dark Reading · Jul 22, 2026 High BHKUandroidspywaremalware
threat-intel Multiples vulnérabilités dans les produits Elastic (22 juillet 2026) Multiple vulnerabilities have been discovered in Elastic products, including Elasticsearch and Kibana. These vulnerabilities can lead to data integrity compromise, data confidentiality breaches, and denial-of-service att… CERT-FR · Jul 22, 2026 High CVE-2018-17245CVE-2026-42397CVE-2026-49092vulnerabilityssrfelastic
threat-intel Hacker Turns AI Jailbreaks Into Offensive Attack Platform A Russian-speaking cybercriminal, known as ‘Trim,’ successfully weaponized publicly available AI language models to create a commercial offensive cybertooling platform. By developing and publishing jailbreaking technique… Dark Reading · Jul 21, 2026 High RUaijailbreakoffensive-security
threat-intel 20+ Hijacked Government Websites Became an Attack Channel A sophisticated campaign, dubbed PhantomEnigma, has hijacked over 20 Brazilian government websites to deliver malware and conduct attacks against banks and public agencies. Attackers leveraged compromised .gov.br infrast… The Hacker News · Jul 16, 2026 High BRgovernmentphishingmalware
threat-intel ISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Jul 15, 2026 Medium phishingvulnerabilityemail
threat-intel 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May. These packages, initially designed as tutoring tools, lo… The Hacker News · Jul 14, 2026 High USbotnetddosproxy