threat-intel France to Stop Certifying Non-Quantum-Safe Encryption France’s cybersecurity agency, ANSSI, is implementing a significant shift in encryption standards. Starting in 2027, they will no longer certify security products that don't offer quantum-resistant encryption, effectivel… Schneier on Security · Jul 6, 2026 Medium FRencryptionquantumcybersecurity
threat-intel New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions Researchers at Shandong University have developed a new technique called TrojPix that allows data to be exfiltrated from air-gapped systems by subtly modulating pixels on a screen and transmitting them as a radio signal.… The Hacker News · Jul 6, 2026 Medium air-gapdata exfiltrationpixel modulation
vulnerability Multiples vulnérabilités dans Roundcube (06 juillet 2026) Multiple vulnerabilities have been discovered in Roundcube Webmail, impacting versions 1.6.x (prior to 1.6.17) and 1.7.x (prior to 1.7.2). These vulnerabilities include denial-of-service attacks, server-side request forg… CERT-FR · Jul 6, 2026 Medium CVE-2026-54432CVE-2026-54433CVE-2026-62641webmailvulnerabilityssrf
threat-intel Cyber readiness for SMBs: Getting the basics right This article highlights the ongoing importance of traditional cybersecurity threats for small and medium-sized businesses (SMBs), despite growing concerns about AI-powered attacks. The primary risks remain phishing, unpa… WeLiveSecurity · Jul 3, 2026 Medium USphishingvulnerabilityai
threat-intel Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs A recent Australian Institute of Criminology survey revealed a decrease in overall cybercrime incidents and financial losses experienced by Australians in 2025 compared to 2024. However, this positive trend was largely d… Dark Reading · Jul 2, 2026 Medium AUsmbcybercrimeaustralia
threat-intel How We Added WebAuthn to a Browser-Based RDP Client This Palo Alto Unit 42 article details the development of a browser-based RDP client that supports WebAuthn redirection, allowing users to utilize security keys like YubiKeys during remote sessions. The team overcame sig… Palo Alto Unit 42 · Jul 2, 2026 Medium webauthnrdpbrowser
ransomware Ransomware Thugs Masquerade as Interpol to Entice Small Biz A new ransomware campaign is targeting small businesses globally, impersonating Interpol to lure victims into downloading malware. The campaign utilizes basic social engineering techniques, delivering a rudimentary ranso… Dark Reading · Jul 2, 2026 Medium USEUSAsocial engineeringphishingsmall business
threat-intel How to Conduct a Successful Audit of AI-Driven Software Development This SecurityWeek article discusses the need for a new type of audit – an ‘agentic development lifecycle’ (ADLC) audit – to address the security risks introduced by AI-driven software development, particularly large lang… SecurityWeek · Jul 2, 2026 Medium aillmsoftware security
threat-intel Identity Lifecycle Management Wasn't Built for AI Agents This article discusses the challenges of applying traditional identity lifecycle management (IGA) tools to the increasing use of AI agents within enterprise environments. The current IGA model relies on human employees w… The Hacker News · Jul 2, 2026 Medium aigovernanceidentity
vulnerability Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability A PoC exploit has been available since public disclosure, and the first exploitation attempts were observed last week. The post Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability appeared first on Securi… SecurityWeek · Jul 2, 2026 Medium CVE-2026-20230
phishing ISC Stormcast For Thursday, July 2nd, 2026 https://isc.sans.edu/podcastdetail/9992, (Thu, Jul 2nd) The SANS Internet Storm Center's July 2nd, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing and malicious email campaigns. The broadcast highlighted several emerging trends and… SANS Internet Storm Center · Jul 2, 2026 Medium phishingemailthreat-intelligence
threat-intel When Too Much Security Data Became the Risk This article details how Vensure Employer Solutions, an HR services provider, struggled with the exponential growth of telemetry data flowing into its SIEM environment due to rapid acquisitions and expansion. The overwhe… Dark Reading · Jul 1, 2026 Medium telemetrysiemdata-overload
threat-intel US lifts export controls on Anthropic’s frontier cybersecurity AI models The U.S. government has lifted export controls on Anthropic’s Fable 5 and Mythos 5 cybersecurity AI models following a ‘jailbreak’ exploit discovered in Fable 5. This marks the first instance of export controls being app… The Record · Jul 1, 2026 Medium USCHaijailbreakexport controls
threat-intel Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors This article discusses the growing hype surrounding Frontier AI and the concerns of enterprises regarding its impact on security. It highlights the need for organizations to critically evaluate vendor claims related to F… SecurityWeek · Jul 1, 2026 Medium frontier aivendor evaluationhype
phishing Why Ask Credentials If There Are Secret Codes?, (Wed, Jul 1st) This morning, an interesting phishing email hit my mailbox. It targets Metamask[ 1 ], a cryptocurrency wallet, available as a browser extension and a mobile app, that lets users store, send, and receive crypto money. It'… SANS Internet Storm Center · Jul 1, 2026 Medium
phishing ISC Stormcast For Wednesday, July 1st, 2026 https://isc.sans.edu/podcastdetail/9990, (Wed, Jul 1st) The SANS Internet Storm Center's July 1st, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The broadcast highlighted several emerging tr… SANS Internet Storm Center · Jul 1, 2026 Medium phishingemailbotnet
phishing Scammers race to cash in on Venezuelan earthquake disaster Following a devastating earthquake in Venezuela, a surge of newly registered domain names emerged, many referencing aid and rescue efforts. Researchers discovered that a significant portion of these domains lacked identi… Graham Cluley · Jun 30, 2026 Medium VEdisasterfraudscams
threat-intel Why Identity Security Is Your Cyber Career Entry Point This Dark Reading article, part of their ‘Heard It From a CISO’ video series, discusses the evolving landscape of cybersecurity career entry points. It highlights that while AI is automating certain tasks, human oversigh… Dark Reading · Jun 30, 2026 Medium aicybersecurityidentity security
threat-intel House passes kids’ online safety bill, but Senate approval unlikely The House of Representatives passed the Kids Internet and Digital Safety (KIDS) Act, aiming to bolster online safety for children, but the bill faced criticism for lacking key provisions like a ‘duty of care’ and strong… The Record · Jun 30, 2026 Medium USonline safetychildrenprivacy
threat-intel This month in security with Tony Anscombe – June 2026 edition This month’s security roundup highlights a critical CISA policy demanding rapid patching of vulnerabilities for federal agencies, a targeted cyberattack campaign against US-based Automatic Tank Gauges (ATGs), a surge in… WeLiveSecurity · Jun 30, 2026 Medium USUKCAvulnerabilitycyberattacksocial media