ransomware Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk Recent breaches targeting educational institutions, including ransomware attacks on Oracle E-Business Suite and Instructure's Canvas platform, highlight the vulnerability of the sector due to legacy technology, understaf… Dark Reading · Jun 27, 2026 High USthird-party riskransomwareeducation
apt Turla group adds more malware to Russia’s espionage efforts against Ukraine The Turla group, a long-standing Russian cyber-espionage team, has expanded its operations against Ukraine by deploying a new malware strain called StockStay. This malware, developed since December 2022, targets Ukrainia… The Record · Jun 26, 2026 High UKITNEcyberespionagerussiaukraine
threat-intel Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets Russia-linked APT Turla has been deploying a new .NET backdoor, dubbed StockStay, to conduct ongoing cyber espionage against Ukrainian government and military organizations, as well as entities with interests in Italian… SecurityWeek · Jun 26, 2026 High CVE-2025-8088UKRUITespionagebackdoorphishing
threat-intel EdTech Attackers Shift From Schools to Their Software Suppliers This article reports a concerning shift in cyberattacks targeting the education sector, with attackers now focusing on edtech software suppliers like Instructure and Oracle rather than individual schools. The Shiny Hunte… Dark Reading · Jun 25, 2026 High edtechsupply chainransomware
threat-intel New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new stealthy backdoor, Mistic (MLTBackdoor), linked to the KongTuke IAB has been used in financially motivated attacks targeting organizations across insurance, education, IT, and professional services since April 2026… The Hacker News · Jun 25, 2026 High USbackdoorremote access trojanclickfix
threat-intel Stealthy Mistic backdoor linked to ransomware access broker KongTuke A new stealthy backdoor, dubbed Mistic, has been identified as a tool used by the initial access broker KongTuke to facilitate ransomware attacks against organizations in the insurance, education, IT, and professional se… BleepingComputer · Jun 24, 2026 High USbackdoorinitial accessransomware
threat-intel SocGholish Takedown Highlights Malicious TDS Threats A coordinated international law enforcement operation, part of Operation Endgame, successfully disrupted SocGholish, a decade-old malware framework used as an initial-access broker by cybercriminal groups like Evil Corp.… Dark Reading · Jun 23, 2026 High NLtdssmalwareaffiliate
threat-intel Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites An international law enforcement operation, dubbed Operation Endgame, successfully disrupted SocGholish’s infrastructure and removed malware from nearly 15,000 WordPress websites. The takedown, involving agencies from mu… The Hacker News · Jun 19, 2026 High NLCADEbotnetwordpressmalware
threat-intel CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices CISA has issued a warning to Fortinet customers regarding FortiBleed, a campaign targeting 86,644 FortiGate devices globally. The attack, attributed to Russian-speaking threat actors, leverages a two-step approach involv… The Hacker News · Jun 19, 2026 High USINMEcredential_stuffingdefault_credentialspassword_reuse
threat-intel NY man charged after harassing college student with AI-generated nudes A New York man, Anthony Belford, has been charged with cyberstalking after using AI-generated nude images and fabricated messages to harass a college student following a transfer. The investigation revealed the use of nu… BleepingComputer · Jun 19, 2026 High USGAILaicyberstalkingharassment
threat-intel Telegram admits it couldn't police exam-leak channels, India tells court India's government blocked Telegram access following reports of leaked exam materials for the NEET-UG 2026 medical entrance exam, leading to disruptions for users globally. Telegram initially admitted limitations in proa… BleepingComputer · Jun 18, 2026 Medium INAEexamleakregulatory
threat-intel India's Telegram ban hit the UAE too. Here's how to get around it Following the ban of Telegram in India due to leaked exam materials from the NEET medical entrance exam, the platform experienced disruptions in access for users globally, notably in the UAE, attributed to a BGP hijackin… BleepingComputer · Jun 17, 2026 High INAEbgproutingexam fraud
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
threat-intel ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures ClickFix campaigns are expanding their malware delivery tactics with new loaders, including BabaDeda Loader, Lorem Ipsum Loader, and Storage Crypter, targeting education and financial organizations. These attacks utilize… The Hacker News · Jun 16, 2026 High RUBYsocial engineeringloaderpayload
threat-intel India temporarily blocks Telegram over medical exam cheating fears India temporarily blocked access to the Telegram messaging app due to concerns about cheating during a nationwide rerun of the NEET-UG medical entrance exam. Authorities cited instances of scammers using Telegram to dist… The Record · Jun 16, 2026 Medium INtelegramexamcheating
threat-intel Hacker Conversations: Isira Adithya, the Evolution of an Ethical Hacker This article details the story of Isira Adithya, a young Sri Lankan-born ethical hacker who developed a passion for understanding technology from a young age. Starting with tinkering with electronics and computer games,… SecurityWeek · Jun 16, 2026 Low UKLKethical hackingbug bountycybersecurity
threat-intel North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels North Korean threat actors, operating under the UNK_DeadDrop campaign, are employing a sophisticated phishing technique targeting developers across numerous sectors, including finance and cryptocurrency, using malicious… The Hacker News · Jun 15, 2026 High USGBAUdevelopergithubvscode
threat-intel Ex-school district employee jailed for hacks on former employer A former IT employee, Ezekiel Dean Potter, was sentenced to prison for a prolonged cyberattack against the Saydel Community School District. Potter exploited his previous access to disrupt operations, steal data, and cau… BleepingComputer · Jun 13, 2026 High UScyberattackdata-breachaccount-compromise
threat-intel Phishing Attack Volume Down 20%, but Risk Still Rising The volume of phishing attacks has decreased by 20% across multiple industries, despite a shift towards more sophisticated attacks utilizing AI. Threat actors are prioritizing targeted campaigns with higher conversion ra… Dark Reading · Jun 12, 2026 High CAESAUphishingaicloud
threat-intel British high school sends students home following cyberattack Great Marlow School in Buckinghamshire, England, experienced a cybersecurity incident that forced the closure of the school for a second day, impacting students and staff. The incident, potentially linked to ransomware a… The Record · Jun 11, 2026 Medium UKUScyberattackschoolransomware