threat-intel Deux jeux d’été pour vérifier et déchiffrer ZATAZ is offering two summer activities designed to improve critical thinking and information literacy. The first is a game simulating an investigation into disinformation, requiring players to verify images, sources, an… ZATAZ · Jul 24, 2026 Info disinformationcryptographycritical thinking
threat-intel China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks A China-nexus operation, tracked by Group-IB, dubbed JadeProx, is using a new loader called TriBack Loader to target government, healthcare, and education organizations across Asia and Latin America. The operation levera… The Hacker News · Jul 23, 2026 High CVE-2018-11511CVE-2021-24139CVE-2021-31755CHHOVIloaderspear-phishingvulnerability
threat-intel Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors, known as LAUNDRY BEAR, has been aggressively targeting Western organizations using the Zimbra Collaboration Suite (ZCS) since July 2025, seeking to gather sensitive inform… CISA Advisories · Jul 23, 2026 High CVE-2025-66376MOPOSPphishingsupply-chainmalware
vulnerability Multiples vulnérabilités dans Oracle PeopleSoft (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle PeopleSoft, allowing an attacker to cause a denial-of-service, lead to data confidentiality breaches, and compromise data integrity. These vulnerabilities are part… CERT-FR · Jul 23, 2026 High CVE-2025-55130CVE-2025-55131CVE-2025-55132oraclepeoplesoftvulnerability
vulnerability Vulnérabilité dans Moodle (23 juillet 2026) A vulnerability in Moodle versions prior to 5.2.1 allows an attacker to compromise user data confidentiality. The CERT-FR has issued a security bulletin detailing the issue and recommending immediate patching. CERT-FR · Jul 23, 2026 Medium moodlevulnerabilitydata breach
policy French Parliament greenlights social media ban for under-15s France has become the first European nation to enact a ban on social media access for children under 15, a move driven by concerns about child welfare and prompted by similar legislation in other countries. The law will… The Record · Jul 22, 2026 Info FRAUTRsocial mediachild safetyregulation
threat-intel MIT to Become Hotbed of AI Video Surveillance MIT is investing heavily in a massive AI-powered surveillance system, deploying over 500 cameras across campus and surrounding areas. These cameras will collect detailed data on individuals and objects, including facial… Schneier on Security · Jul 21, 2026 Medium surveillancefacial-recognitionprivacy
threat-intel New Index Tracks Material Breaches — And Refuses to Add Up the Losses Richard Bird, a former cybersecurity executive, has launched The Hacker in a Hoodie (HIH) Index, a project tracking disclosed material cyber incidents. The index compiles data from SEC filings and news reports, grading t… SecurityWeek · Jul 20, 2026 Medium cybersecuritydata breachloss reporting
threat-intel HelloNet campaign — new malicious modules launched through the ViPNet update system A Chinese-speaking Advanced Persistent Threat (APT) group, likely operating since May 2026, has been targeting Russian organizations using a sophisticated campaign centered around the ViPNet software suite. The campaign… Securelist · Jul 16, 2026 High CHaptdll hijackingprocess injection
threat-intel 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers have discovered 11 outdated, Microsoft-signed UEFI shim bootloaders that could be exploited to bypass Secure Boot on systems relying on these shims. These bootloaders, primarily from versions 0.7 and earlier,… The Hacker News · Jul 14, 2026 High CVE-2026-8863CVE-2026-10797FIuefisecure bootvulnerability
threat-intel 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May. These packages, initially designed as tutoring tools, lo… The Hacker News · Jul 14, 2026 High USbotnetddosproxy
threat-intel Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths For a year, attackers leveraging the ShinyHunters group gained access to Salesforce environments not through exploiting vulnerabilities, but by exploiting trust placed in connected apps and vendors. They achieved this th… The Hacker News · Jul 14, 2026 High USoathconnected appsvendor compromise
threat-intel New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic A China-linked cybercrime group, Silver Fox, is using a new Rust-based remote access trojan called MODBEACON to target technology, education, and state-owned enterprises in Asia. The trojan utilizes gRPC streaming for en… The Hacker News · Jul 10, 2026 High CNrustgrpcc2
ransomware Mount Royal University Confirms Data Stolen in Ransomware Attack Mount Royal University in Canada suffered a ransomware attack that resulted in the theft of employee and student data. The attackers, identified as CMD Organization, exfiltrated over 10 terabytes of information and are d… SecurityWeek · Jul 9, 2026 High CAransomwaredata breachtor
threat-intel 'GodDamn' Ransomware Uses BYOVD to Smite US Companies The ransomware group Hyadina, operating under the name "GodDamn," is leveraging a Microsoft-approved, malicious kernel driver – dubbed "PoisonX" – to infiltrate US organizations and deploy its ransomware. They utilize a… Dark Reading · Jul 9, 2026 High RUransomwaredriverbyovd
threat-intel New Ghost Phishing Wave Is Breaking Traditional Email Security A new phishing technique called ‘ghost phishing’ is emerging, where malicious links appear harmless during initial email inspection but execute a more damaging attack within the victim’s browser. The EvilTokens campaign,… The Hacker News · Jul 8, 2026 High USEUphishingghost phishingmicrosoft 365
threat-intel Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities A China-aligned threat actor cluster, tracked as UNC5174 and linked to ShadowPad, has been exploiting vulnerabilities in Roundcube webmail software at U.S. and Canadian universities. The campaign leverages CVE-2024-42009… The Hacker News · Jul 7, 2026 High CVE-2024-42009CVE-2025-49113CHUSCAroundcubexsscve-2024-42009
threat-intel Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects This Kaspersky report, based on 2025 compromise assessment engagements, highlights significant missed incidents due to inadequate monitoring, delayed detection, and communication gaps. The analysis reveals a concerning t… Securelist · Jul 2, 2026 High SACNRUmissed incidentsthreat detectionincident response
threat-intel House passes kids’ online safety bill, but Senate approval unlikely The House of Representatives passed the Kids Internet and Digital Safety (KIDS) Act, aiming to bolster online safety for children, but the bill faced criticism for lacking key provisions like a ‘duty of care’ and strong… The Record · Jun 30, 2026 Medium USonline safetychildrenprivacy
threat-intel Vulnerabilities Expose Private Data in Indian Government Systems A security researcher discovered 14 vulnerabilities across multiple Indian government IT systems, including portals for education, civil service, and scholarships. These vulnerabilities exposed sensitive personal data, s… Dark Reading · Jun 29, 2026 High INvulnerabilitydata-breachidentity-access-management