threat-intel Spur Raises $200 Million for IP Intelligence Platform Spur Intelligence, a company specializing in IP intelligence and bot detection, has secured $200 million in funding from Insight Partners to combat increasing fraud and security challenges driven by the widespread use of… SecurityWeek · Jul 29, 2026 Info ip intelligencefraud preventionvpn
threat-intel Wi-Fi public : ce que votre fournisseur, pirates et marketing peuvent voir This article highlights the significant data collection practices of Wi-Fi providers, even when users are using HTTPS. While HTTPS protects content, providers can still track domains visited, connection times, data trans… ZATAZ · Jul 28, 2026 Medium wifiprivacydns
threat-intel Outdated VPNs should be purged from federal agencies, senator says Senator Ron Wyden is urging federal agencies to remove outdated and insecure VPNs from their systems, citing a growing threat of foreign adversaries exploiting these vulnerabilities to gain access to sensitive U.S. gover… The Record · Jul 27, 2026 High RUCHvpnzero-trustremote access
threat-intel Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption The Dysphoria IoT botnet has evolved to become significantly harder to disrupt by incorporating blockchain-based name services and utilizing infected devices as relays. This complex architecture, stemming from the JackSk… The Hacker News · Jul 27, 2026 High CVE-2025-9528JPiotbotnetc2
threat-intel Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access Threat actors are exploiting a vulnerability in Palo Alto Networks PAN-OS to gain initial access and deploy Qilin ransomware. The vulnerability, CVE-2026-0257, allows unauthenticated remote access, leading to widespread… The Hacker News · Jul 21, 2026 High CVE-2026-0257ransomwarevulnerabilityvpn
threat-intel More than 1,000 domains illegally streaming World Cup games seized, DOJ says The Department of Justice, in collaboration with Homeland Security Investigations, has seized over 1,000 domains illegally streaming the World Cup. This operation targets a cyber gang, Los Ciberinfiltrados, involved in d… The Record · Jul 20, 2026 Medium BUPEARcybercrimepiracystreaming
threat-intel SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access A threat actor, identified as UTA0533, successfully exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances to gain root access. The attacker leveraged these vulnera… The Hacker News · Jul 19, 2026 High CVE-2026-15409CVE-2026-15410zero-dayvpnroot access
threat-intel U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support The U.S. Treasury Department has sanctioned a VPN service provider, First VPN Service (1VPNS), and its administrator, Dmytro Rashevskyi, for enabling ransomware groups to carry out attacks against U.S. companies and inst… The Hacker News · Jul 14, 2026 High CVE-2018-0171CVE-2008-4128RUUKUNvpnransomwarecyber espionage
threat-intel VPN service favored by ransomware groups is sanctioned by US The U.S. government has sanctioned a VPN service, First VPN, and its administrator, citing their role in enabling ransomware attacks against critical U.S. infrastructure. The sanctions target not only the VPN providers b… The Record · Jul 13, 2026 High USUKBEvpnransomwarecybercrime
threat-intel Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking A University of Michigan, New Mexico, and IIT Delhi study found that 281 popular free Android VPN apps on the Google Play Store have significant security flaws, including leaking user traffic, sending data in plain text,… The Hacker News · Jul 10, 2026 High CVE-2016-6329CVE-2016-2183vpnandroidsecurity
threat-intel Winning 54% of the time Cisco Talos Intelligence has identified a China-nexus threat actor, UAT-7810, expanding its Operational Relay Box (ORB) network. The group exploits unpatched vulnerabilities in Ruckus and ASUS routers to deploy custom ma… Cisco Talos · Jul 9, 2026 High CHorbproxyrouter
threat-intel CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd) This report details a significant ongoing cyber threat targeting SonicWall firewalls exploiting CVE-2024-40766, a critical access control vulnerability. Ransomware groups, notably Akira and Fog, have been actively levera… SANS Internet Storm Center · Jun 23, 2026 Critical CVE-2024-40766CVE-2024-12802USGBvpncredential theftransomware
threat-intel CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices CISA has issued a warning to Fortinet customers regarding FortiBleed, a campaign targeting 86,644 FortiGate devices globally. The attack, attributed to Russian-speaking threat actors, leverages a two-step approach involv… The Hacker News · Jun 19, 2026 High USINMEcredential_stuffingdefault_credentialspassword_reuse
threat-intel CISA warns Fortinet users to secure devices after FortiBleed leak CISA has issued a warning to Fortinet customers regarding the "FortiBleed" data leak, which exposed nearly 74,000 firewall and VPN credentials. Threat actors are exploiting these compromised credentials to target interne… BleepingComputer · Jun 19, 2026 High USRUCNcredentialsvpnfirewall
vulnerability CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding a widespread compromise of credentials associated with Fortinet devices, dubbed ‘FortiBleed.’ Approximately 74,000 Forti… CISA Advisories · Jun 18, 2026 High USGBcredentialsfirewallvpn
data-breach FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. A significant data leak, dubbed "FortiBleed," has exposed approximately 73,932 Fortinet VPN credentials for firewall URLs across numerous organizations worldwide. The leak, discovered by Bob Diachenko, reveals a multi-op… BleepingComputer · Jun 17, 2026 High USGBJPvpncredentialsbreach
threat-intel UK to require ID or face scan before you can make social media accounts The UK government is implementing new regulations to restrict social media access for under-16s, requiring platforms to verify users' ages through ID uploads or facial scans. This follows a model established in Australia… BleepingComputer · Jun 16, 2026 Medium GBage-verificationsocial-mediaprivacy
threat-intel Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive A recent study by Spur Intelligence found that anonymized infrastructure, primarily through VPNs and residential proxies, is now a dominant factor in nearly every security incident. Despite the abundance of IP data avail… The Hacker News · Jun 16, 2026 High USanonymizationip intelligencevpn
threat-intel Who Runs the Ransomware Group ‘The Gentlemen?’ The Gentlemen, a prolific ransomware group, is being led by a Russian individual known as Zeta88/Hastalamuerte. Extensive investigation by Check Point and Intel 471 has revealed that this administrator, whose real identi… Krebs on Security · Jun 10, 2026 High RUransomwarerandsomware-as-a-servicerussian cybercrime
vulnerability CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day The Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive (BOD) 22-01, requiring U.S. federal agencies to patch a critical zero-day vulnerability in Check Point’s Remote Acces… BleepingComputer · Jun 9, 2026 High CVE-2026-50751CVE-2024-24919zero-dayvpnikev1