supply-chain Trivy, Not LiteLLM Behind the 2,500 Org Compromise A sophisticated supply chain attack, initially linked to the LiteLLM malware, has impacted over 2,500 organizations, primarily through a compromise of the Trivy scanner. The attack, orchestrated by TeamPCP, exploited vul… SecurityWeek · Aug 14, 2026 High GEBRFRsupply-chainvulnerabilitycredential-theft
threat-intel Cyber actualités ZATAZ de la semaine du 10 au 16 août 2026 This week’s ZATAZ news highlights a surge in data breaches and phishing attacks targeting various organizations across Europe. Key incidents include a data leak exposing 148,288 motorists’ information from Cars.no, a mas… ZATAZ · Aug 13, 2026 High CVE-2026-59310FRTAPAphishingdata-breachransomware
threat-intel New Mirai variant adds stealth capabilities to notorious botnet code A new, stealthier variant of the Mirai botnet, dubbed Evooo1Bot, has been actively exploiting vulnerabilities in internet-facing hardware for over a month. This malware boasts advanced features like encrypted communicati… The Record · Aug 13, 2026 High CACHGEmiraibotnetvulnerability
threat-intel Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants The Head Mare APT group is exploiting multiple vulnerabilities in TrueConf servers to deliver the PhantomCore and PhantomGraph backdoors. Attackers connect to TrueConf servers without authorization, call a server functio… Securelist · Aug 11, 2026 Critical aptmalwarebackdoor
threat-intel Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities A Chrome extension, initially banned for stealing AI chat conversations, has returned to the Chrome Web Store and is now targeting enterprise browsers through Google's CDN. The extension employs a sophisticated affiliate… SecurityWeek · Aug 11, 2026 High chromeextensionaffiliate
threat-intel IT threat evolution in Q2 2026. Mobile statistics In Q2 2026, mobile malware attacks continued to decline, with Trojan-Banker applications representing the most prevalent threat. Despite a drop in new Trojan variants, the landscape remained dominated by Mamont banking T… Securelist · Aug 10, 2026 Medium mobilemalwarebanking
threat-intel Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials A malicious Microsoft Visual Studio Code extension named Solidity Pro has been identified as a sophisticated information stealer, capable of harvesting a wide range of sensitive data from users’ systems, including crypto… The Hacker News · Aug 10, 2026 High vscodeextensionmalware
threat-intel Cyber actualités ZATAZ de la semaine du 3 au 9 août 2026 This week, ZATAZ reports on a significant number of cyber incidents impacting France and beyond. A staggering 1.7 billion French IDs were found on the dark web, alongside 43 ransomware demands targeting France, primarily… ZATAZ · Aug 9, 2026 High FRTAdarkwebransomwaredata breach
threat-intel Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer A sophisticated campaign involving nearly 800 malicious npm packages has been deployed to deliver cross-platform malware – a Remote Access Trojan (RAT) and infostealer – targeting Windows, macOS, and Linux systems. The p… The Hacker News · Aug 7, 2026 High RUnpmsupply chainmalware
threat-intel Why metaphor may dictate your security strategy Cisco Talos’ analysis highlights the evolving threat landscape driven by AI, arguing that adversaries are increasingly weaponizing AI to bypass security measures and accelerate malicious activities. The research emphasiz… Cisco Talos · Aug 6, 2026 High aiprompt engineeringmalware
threat-intel ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories This week's 'ThreatsDay' bulletin highlights a diverse range of security threats, including a China-linked telecom risk, a multi-stage phishing attack leveraging ClickOnce files, a supply chain attack involving 846 softw… The Hacker News · Aug 6, 2026 High CVE-2025-21079CVE-2025-58486CVE-2026-25177CHUSsupply-chainmalwarephishing
vulnerability ABB Ability Zenon ABB has issued a security advisory regarding multiple vulnerabilities in its Ability Zenon industrial automation platform. These vulnerabilities, primarily related to MongoDB, could allow attackers to bypass security, cr… CISA Advisories · Aug 6, 2026 High CVE-2025-14847CVE-2020-7928CVE-2020-7921WOvulnerabilitydata-breachmalware
threat-intel Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service Maksim Silnikau, a Belarusian national, has been sentenced to 16 years in prison for his role in creating and operating Ransom Cartel, a ransomware-as-a-service operation that targeted over 18 companies globally between… The Hacker News · Aug 6, 2026 High BEPOUNransomwarethreat intelligencecybercrime
threat-intel Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures A macOS ClickFix operation is using browser fingerprinting to deliver malware lures to a targeted subset of Mac users. The operation, involving over 250 domains and distributing malware like MacSync and AMOS, hides the m… The Hacker News · Aug 5, 2026 High browser fingerprintingmacosclickfix
threat-intel Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data A cluster of 77 malicious extensions masquerading as legitimate developer tools on the Open VSX marketplace have been discovered. These extensions, dubbed ‘evil twins,’ exfiltrate sensitive developer data, including work… The Hacker News · Aug 5, 2026 High supply chainmalwareopen vsx
supply-chain Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack A sophisticated supply chain attack, dubbed ChainDrop, has infected over 2,200 malicious versions of 440 NPM packages, resulting in over 500 million weekly downloads. The attack began with a compromised GitHub account an… SecurityWeek · Aug 5, 2026 High supply chainnpmgithub
threat-intel QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer A long-standing supply chain attack targeting QuickFox, a VPN tool used by overseas Chinese users, has been ongoing since August 2025. The attack, attributed to tactical overlaps with the Chinese state-sponsored threat a… The Hacker News · Aug 5, 2026 High CNsupply-chainmalwarechina
threat-intel AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project Researchers have demonstrated a concerning vulnerability where large language models (LLMs) can be manipulated to inject malware into open-source projects. By simply releasing a model, developers inadvertently enabled ma… The Register · Aug 5, 2026 High llmprompt injectionopen source
threat-intel Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access A multi-wave campaign leveraging social engineering to deploy Remote Monitoring and Management (RMM) software, specifically ScreenConnect, is actively targeting users with fake Adobe and Zoom updates, as well as business… The Hacker News · Aug 4, 2026 High phishingmalwaresupply-chain
threat-intel Almost Half of Malware Samples Communicate Direct to IP Almost half (45.32%) of malware samples with Command & Control (C2) activity bypass DNS entirely, communicating directly to IP addresses. This behavior, known as D2IP, is prevalent across various threat types, including… Palo Alto Unit 42 · Aug 4, 2026 High BRd2ipdnsc2