threat-intel ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories This week’s ‘ThreatsDay’ bulletin highlights a diverse range of security threats, including AI-powered hacking campaigns, ransomware attacks targeting Russia, and vulnerabilities in various software systems. Notably, a C… The Hacker News · Jul 30, 2026 High CVE-2026-33017CVE-2026-21858CVE-2025-68613RUCCHransomwaresupply chainphishing
threat-intel North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn North Korea's Lazarus Group is sharing its cyber tools and infrastructure with ransomware hackers, specifically the Gunra group, targeting South Korean organizations. The agencies warn that even visiting compromised legi… The Record · Jul 30, 2026 High SONOnorth korearansomwarelazarus group
threat-intel ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale A research firm, Silent Push, demonstrated how artificial intelligence can significantly amplify the effectiveness of ‘dangling DNS takeover’ attacks, a vulnerability where a forgotten DNS record points to a deleted clou… SecurityWeek · Jul 30, 2026 High dangling dnsdns takeovercloud security
threat-intel Mitsubishi Electric CC-Link IE TSN Communication Protocol A critical vulnerability (CVE-2026-13584) exists in the CC-Link IE TSN communication protocol used by Mitsubishi Electric industrial controllers. Attackers with network access can manipulate communication data by sending… CISA Advisories · Jul 30, 2026 Critical CVE-2026-13584cc-linkindustrial control systemsvulnerability
threat-intel o6 Automation open62541 Multiple vulnerabilities have been identified in o6 Automation open62541, a control system software, potentially allowing for denial of service, arbitrary code execution, and information disclosure. These vulnerabilities… CISA Advisories · Jul 30, 2026 Critical CVE-2026-63362CVE-2026-65423CVE-2026-63035vulnerabilitycontrol-systemcisa
threat-intel Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts A state-sponsored threat group, potentially linked to Lazarus and operating between 2025 and 2026, exploited vulnerabilities in AnySign4PC, a certificate-based electronic signature software, to install backdoors on targe… The Hacker News · Jul 30, 2026 High CVE-2020-7882SOwatering holebuffer overflowremote code execution
threat-intel FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks The FCC has added foreign-produced mobile robots and networked power inverters to its Covered List, aiming to mitigate cybersecurity risks associated with these devices. This action prevents new models from receiving equ… The Hacker News · Jul 30, 2026 High CVE-2025-35027CVE-2025-2894UNcybersecuritynational securitysupply chain
threat-intel Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline A coordinated cyberattack targeted over 30 community water systems in Minnesota, leading to operational disruptions and communications failures. While the exact number of compromised systems remains unclear, the attacks… The Hacker News · Jul 29, 2026 High UNcritical infrastructureindustrial control systemscyberattack
threat-intel US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security The U.S. Federal Communications Commission is implementing a ban on new imports of foreign-made humanoid robots and power inverters, primarily targeting China due to national security concerns. This move follows a series… SecurityWeek · Jul 29, 2026 High CHUSchinaroboticsnational security
threat-intel 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack A recent study reveals that 73% of organizations aren't fully prepared to withstand a major cyberattack, despite having incident response plans and security tools. The core issue isn't simply having these capabilities, b… The Hacker News · Jul 29, 2026 High incident responsecybersecurityvulnerability
threat-intel America bans imported robots due to supply chain and security risks The United States is implementing a ban on importing robots due to significant security and supply chain risks. This action is driven by concerns about potential vulnerabilities in these devices, which could be exploited… The Register · Jul 29, 2026 Medium IRroboticssupply chainsecurity
vulnerability Siemens SIMATIC S7-PLCSIM Advanced A vulnerability in Siemens SIMATIC S7-PLCSIM Advanced could allow an unauthenticated attacker to cause a denial-of-service condition by overwhelming the application with high-volume multicast network traffic. Siemens is… CISA Advisories · Jul 28, 2026 High CVE-2026-54429DEindustrial control systemscve-2026-54429denial of service
threat-intel IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains This quarter, phishing, particularly QR code phishing leveraging trusted infrastructure, dominated initial access methods for attackers, with a significant increase in authentication abuse. The threat actor UAT-11764 con… Cisco Talos · Jul 28, 2026 High phishingauthenticationransomware
vulnerability PTC Windchill Vulnerability Exploited in Ransomware Campaign A critical remote code execution vulnerability in PTC's Windchill and FlexPLM PLM platforms has been exploited by a Cl0p ransomware affiliate in a targeted campaign. The attackers are leveraging a chain of vulnerabilitie… SecurityWeek · Jul 27, 2026 Critical CVE-2026-12569rcevulnerabilityransomware
threat-intel Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware The China-linked cybercrime group behind tax-themed phishing campaigns is utilizing a sophisticated crypter service called Cruciferra to deliver a wide range of malware, including remote access trojans and information st… The Hacker News · Jul 27, 2026 High CNcrypterransomwarephishing
threat-intel Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE Threat actors linked to the Cl0p ransomware group are exploiting internet-exposed PTC Windchill and FlexPLM deployments to gain unauthenticated remote code execution and steal sensitive data for extortion. The campaign l… The Hacker News · Jul 25, 2026 Critical CVE-2026-12569vulnerabilityransomwaredata-breach
vulnerability Rockwell Patches Code Execution Flaws in Arena Simulation Software Rockwell Automation has released a patch to address four critical vulnerabilities in its Arena Simulation software, preventing attackers from executing arbitrary code on affected systems. These flaws stem from improper d… SecurityWeek · Jul 25, 2026 Critical CVE-2026-8085CVE-2026-8312CVE-2026-8313otsimulationmemory corruption
threat-intel In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws This week’s cybersecurity news highlights a range of threats, including a new AI-powered malware (Dolphin X), a data breach affecting Abbott, widespread internet outages in Maine, zero-day vulnerabilities in Siemens swit… SecurityWeek · Jul 24, 2026 High CVE-2025-40948CVE-2025-40947CVE-2025-40949GERUUNzero-dayvulnerabilityransomware
vulnerability Weintek cMT3092X Weintek’s cMT3092X HMI and EasyWeb software versions are vulnerable to privilege escalation and credential exposure. A non-privileged user can modify cookies to gain elevated privileges, and user passwords are stored in… CISA Advisories · Jul 23, 2026 High CVE-2026-60134CVE-2026-61892CVE-2026-61886patchplaintextprivilege escalation
vulnerability Panduit IntraVUE Pronetiqs has identified and reported several vulnerabilities in Panduit IntraVUE software versions 3.2.1a14 and earlier, posing significant risks to industrial control systems. These vulnerabilities include plaintext st… CISA Advisories · Jul 23, 2026 High CVE-2026-40430CVE-2026-42933CVE-2026-44955industrial control systemsot securitypassword vulnerability