threat-intel FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys The FBI and CISA have issued an updated advisory warning about Russian intelligence actors targeting Signal users, expanding their tactics to include obtaining Signal Backup Recovery Keys. This allows attackers to fully… The Hacker News · Jun 26, 2026 High USRUNEsignalphishingrecovery key
malware New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks A new cyberattack campaign, dubbed StrikeShark, is utilizing a previously undocumented malware family called SharkLoader to deploy Cobalt Strike Beacon. The campaign has targeted diplomatic organizations in Indonesia and… The Hacker News · Jun 26, 2026 High CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikedll hijackingexploit
threat-intel Meta Is Testing Facial Recognition for Police and Military Meta is reportedly developing facial recognition technology, initially for use by law enforcement and the military. This development involves a prototype being tested with a Pentagon supplier, raising concerns about the… Schneier on Security · Jun 26, 2026 Medium facial recognitionsurveillancemeta
threat-intel Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign A Chinese-speaking Advanced Persistent Threat (APT) group, CL-STA-1062, has been actively targeting government entities and critical infrastructure in Southeast Asia since 2022, utilizing a new custom backdoor called Tin… The Hacker News · Jun 26, 2026 High VNaptbackdoorsoutheast asia
threat-intel Meeting Trump's 2030 Quantum Deadline Will be Expensive, Complex This article discusses the US government's accelerated efforts to prepare for the advent of quantum computing, driven by executive orders focused on post-quantum cryptography (PQC). The government is mandating a transiti… Dark Reading · Jun 26, 2026 High USquantum computingpost-quantum cryptographypqc
apt Turla group adds more malware to Russia’s espionage efforts against Ukraine The Turla group, a long-standing Russian cyber-espionage team, has expanded its operations against Ukraine by deploying a new malware strain called StockStay. This malware, developed since December 2022, targets Ukrainia… The Record · Jun 26, 2026 High UKITNEcyberespionagerussiaukraine
threat-intel Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets Russia-linked APT Turla has been deploying a new .NET backdoor, dubbed StockStay, to conduct ongoing cyber espionage against Ukrainian government and military organizations, as well as entities with interests in Italian… SecurityWeek · Jun 26, 2026 High CVE-2025-8088UKRUITespionagebackdoorphishing
threat-intel Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff This report details how Russian authorities utilized Cellebrite's UFED forensic tools to access Andrey Pivovarov's iPhone 12 in June 2021, despite Cellebrite's subsequent announcement of a sales cutoff to Russia and Bela… The Hacker News · Jun 26, 2026 High RUGBJOforensiciphonecustody
threat-intel Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks Google Threat Intelligence Group (GTIG) has identified a new backdoor, STOCKSTAY, developed and deployed by the Russian state-sponsored threat actor Turla. This multi-component backdoor, built using .NET and leveraging a… The Hacker News · Jun 26, 2026 High CVE-2025-8088UKITNEespionagebackdoorrussia
threat-intel CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Palo Alto Unit 42 has identified a sustained cyber threat campaign, CL-STA-1062, targeting government and critical infrastructure entities in Southeast Asia since at least March 2022. The group, linked to UAT-7237, utili… Palo Alto Unit 42 · Jun 25, 2026 High VNeast asiasoutheast asiabackdoor
threat-intel In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw A critical vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager (CUCM) has been rapidly weaponized by attackers within 24 hours of a proof-of-concept release. The SSRF flaw allows unauthenticated remote… Dark Reading · Jun 25, 2026 Critical CVE-2026-20230USssrfprivilege escalationcisco
threat-intel Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses The Russian cyber espionage group Gamaredon (also known as Aqua Blizzard) has significantly upgraded its arsenal and tactics, becoming a more effective threat actor, particularly in support of the war in Ukraine. The gro… Dark Reading · Jun 25, 2026 High RUUKaptespionagec2
threat-intel DHS chief says president has met with potential CISA nominee; agency plans to hire 600 The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) is seeking to rebuild its workforce following significant layoffs and a prolonged period without a Senate-confirmed direc… The Record · Jun 25, 2026 Medium CHUScisacybersecurityhomeland security
threat-intel Russia used Cellebrite phone-hacking tool to crack down on dissident after firm cut off country This article reports that Russian authorities continued to use Cellebrite’s phone-hacking tool, the UFED, to access the devices of dissident political activist Andrey Pivovarov after Cellebrite announced it was ending it… The Record · Jun 25, 2026 High RUDEsurveillancephone-hackingdissident
threat-intel Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances In 2025, the Russian-aligned threat actor Gamaredon significantly ramped up its cyberespionage operations targeting Ukraine, utilizing a sophisticated and evolving toolkit. The group, linked to the FSB, employed a combin… WeLiveSecurity · Jun 25, 2026 HighCVSS 8.8 CVE-2025-8088RUcyberespionagerussiaspearphishing
threat-intel StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader A new malware family, named SharkLoader, has been identified as part of a broader campaign targeting organizations globally, including diplomatic entities, government organizations, and software development companies. Th… Securelist · Jun 24, 2026 Medium CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikeexploitloader
threat-intel Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says Anthropic’s Mythos AI model identified vulnerabilities within several U.S. government computer systems during a testing exercise conducted in collaboration with intelligence agencies. While the model quickly detected wea… SecurityWeek · Jun 24, 2026 High UNaivulnerabilitysecurity
threat-intel Five Eyes agencies sound alarm about AI’s threat to cybersecurity Five Eyes intelligence agencies are issuing a stark warning about the rapidly escalating threat posed by artificial intelligence (AI) to cybersecurity. They believe AI will dramatically accelerate both offensive and defe… The Record · Jun 23, 2026 High USUKCAaicybersecuritythreat intelligence
threat-intel Trump directs federal agencies to protect US data from quantum threats President Trump issued two executive orders focused on bolstering U.S. cybersecurity against future threats from quantum computing. One order prioritizes accelerating the development and practical application of quantum… The Record · Jun 23, 2026 Medium USUKquantum computingcryptographycybersecurity
threat-intel Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration This article reports on a new executive order issued by President Trump setting deadlines for federal agencies to migrate to post-quantum cryptography. The order prioritizes protecting U.S. data from future decryption by… The Hacker News · Jun 23, 2026 High USpost-quantumcryptographyquantum computing