threat-intel SocGholish Takedown Highlights Malicious TDS Threats A coordinated international law enforcement operation, part of Operation Endgame, successfully disrupted SocGholish, a decade-old malware framework used as an initial-access broker by cybercriminal groups like Evil Corp.… Dark Reading · Jun 23, 2026 High NLtdssmalwareaffiliate
threat-intel Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices Canadian spy agency, CSIS, utilized a novel court-ordered warrant to neutralize two foreign-run botnets operating within Canada. The operation targeted infected servers, SOHO routers, and IoT devices like Ring doorbells… The Hacker News · Jun 22, 2026 High CAUSbotnetiotcybersecurity
threat-intel CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices CISA has issued a warning to Fortinet customers regarding FortiBleed, a campaign targeting 86,644 FortiGate devices globally. The attack, attributed to Russian-speaking threat actors, leverages a two-step approach involv… The Hacker News · Jun 19, 2026 High USINMEcredential_stuffingdefault_credentialspassword_reuse
phishing Imposter scams cost Americans $3.5 billion in 2025 – and it’s getting worse Imposter scams have surged in the United States, resulting in a staggering $3.5 billion in financial losses for consumers in 2025. These scams typically involve fraudulent impersonations of trusted entities like banks an… Graham Cluley · Jun 19, 2026 High USscamsfraudidentity theft
other UK's information commissioner resigns over ‘inappropriate humour’ John Edwards, the Information Commissioner of the UK, has resigned following a workplace investigation into inappropriate conduct, specifically concerning his use of humor. This resignation has created a leadership vacuu… The Record · Jun 19, 2026 Low UKNEresignationleadershipgovernance
threat-intel CISA warns Fortinet users to secure devices after FortiBleed leak CISA has issued a warning to Fortinet customers regarding the "FortiBleed" data leak, which exposed nearly 74,000 firewall and VPN credentials. Threat actors are exploiting these compromised credentials to target interne… BleepingComputer · Jun 19, 2026 High USRUCNcredentialsvpnfirewall
threat-intel Bulgaria allowed surveillance tech firm to sell products to repressive regimes, report says A report by Human Rights Watch revealed that Bulgaria allowed a surveillance technology firm, Circles, to sell its products – including Pixcell, Landmark, and Voice Over Location Enabler software – to repressive regimes… The Record · Jun 18, 2026 High BUELUAsurveillancespywareexport control
apt Operation Escaneo Signals Shift in LatAm Threat Landscape Operation Escaneo, a coordinated cyber campaign led by the MexicanMafia/PanchoVilla threat actor, represents a significant shift in the threat landscape of Latin America. The campaign, spanning 2025-2026, targeted critic… Dark Reading · Jun 18, 2026 High CVE-2022-42475CVE-2023-27997CVE-2024-21762MXECPTlatin americareconnaissancedata exfiltration
threat-intel EU grants Ukraine access to cybersecurity reserve for major attacks The European Union has granted Ukraine access to its cybersecurity reserve, a pool of private cybersecurity firms, to bolster the country's defenses against ongoing cyberattacks, primarily from Russia. This move signifie… The Record · Jun 17, 2026 High UKEURUcyberattackcyberdefenseeu cybersecurity
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
threat-intel AI Use by the US Government This article details the widespread and largely undocumented use of Artificial Intelligence (AI) by the US government under both the Trump and Biden administrations. The Office of Management and Budget (OMB) revealed a m… Schneier on Security · Jun 17, 2026 Medium USaigovernmentautomation
threat-intel Warner warns of CISA cuts, staffing gaps in letter to acting chief This article reports concerns from Senator Mark Warner regarding significant cuts to the Cybersecurity and Infrastructure Security Agency (CISA), including staff reductions, budget constraints, and a lack of permanent le… The Record · Jun 17, 2026 High UScisacybersecurityfunding
vulnerability 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs Recent analysis reveals that three previously patched Fortinet FortiSandbox vulnerabilities – CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089 – are actively being exploited in the wild. A significant number of comprom… SecurityWeek · Jun 17, 2026 High CVE-2026-39808CVE-2026-39813CVE-2026-25089USINALvulnerabilitypatchingexploitation
threat-intel SprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detection A new Windows variant of the SprySOCKS Linux backdoor, developed by the nation-state threat actor FishMonger (also known as Earth Lusca and Aquatic Panda), has been discovered targeting government organizations in Hondur… Dark Reading · Jun 16, 2026 High HNTWTHkernel-driveraptbackdoor
threat-intel Can CISOs Trust Their Applications? TrustCloud Wants to Replace the Questionnaire This article discusses the challenges CISOs face when assessing the trust and security of their enterprise applications, highlighting the manual and time-consuming nature of traditional questionnaire-based approaches. Tr… SecurityWeek · Jun 16, 2026 Medium GBautomationaiapplication security
other Flock Cameras Are Being Used for Stalking Flock Cameras, a manufacturer of residential security cameras, is facing scrutiny due to reports of law enforcement agencies using their systems for excessive and potentially unlawful surveillance. Multiple cases across… Schneier on Security · Jun 16, 2026 High USsurveillanceprivacypolice
threat-intel China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Researchers have identified new Windows variants of the SprySOCKS backdoor, initially linked to the Chinese state-sponsored threat actor Earth Lusca (also known as Aquatic Panda). These variants, designated WIN_DRV and W… The Hacker News · Jun 16, 2026 High CVE-2023-24932CNTWHUbackdoorwindowsstealth
threat-intel Windows version of SprySOCKS Linux malware used to attack govt orgs Windows variants of the SprySOCKS Linux malware, previously linked to the Earth Lusca threat actor, have been used to target government organizations in Taiwan, Thailand, Pakistan, and Honduras. These variants offer adva… BleepingComputer · Jun 16, 2026 High CVE-2023-24932TWTHPKlinuxstealthbackdoor
threat-intel FishMonger’s arsenal upgraded: SprySOCKS for Windows ESET researchers have discovered two new, undocumented Windows variants of FishMonger's SprySOCKS backdoor, operated by the Chinese threat actor I-SOON (believed to be part of the Winnti Group). These variants, WIN_DRV a… WeLiveSecurity · Jun 16, 2026 High CHHOTAwindowsbackdoorkernel driver
other Cyberattack on Russian tech firm Astral disrupts business, government services for week A cyberattack disrupted the operations of Russian tech firm Kaluga Astral for approximately a week, impacting its customers who rely on its software for various business and government services. The company is undergoing… The Record · Jun 15, 2026 Medium RUcyberattackdisruptionrussian