threat-intel Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware North Korean APT37 group utilized a spear-phishing campaign mimicking Microsoft security alerts to deploy NarwhalRAT malware. The campaign leveraged urgency and confusion to trick victims into executing a malicious LNK f… The Hacker News · Jun 16, 2026 High NOSOspear-phishingratnorth korean
threat-intel From cause to cash: a cross-border look at hacktivist activity This Securelist article details a cross-border hacktivist campaign led by groups including 4BID, with a broadened geographic scope impacting organizations in Kazakhstan, the UAE, Syria, and Egypt. The campaign utilized t… Securelist · Jun 8, 2026 High CVE-2023-44976KZAESYproxyshellransomwarehacktivism
apt Chinese APT deploys new malware to keep access to hacked networks A Chinese Advanced Persistent Threat (APT) group, tracked as UNC5221 (VerdantBamboo), has been conducting a prolonged espionage campaign targeting organizations in the United States, primarily leveraging the Brickstorm b… BleepingComputer · Jun 5, 2026 High CNespionagebackdoorpersistence
ransomware Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin has been exploited by threat actors, allowing for remote code execution and potential site compromise. Attackers have been actively targe… The Hacker News · Jun 5, 2026 Critical CVE-2026-3300MDwordpressvulnerabilityremote code execution
threat-intel PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network PCPJack, a threat actor initially linked to TeamPCP, has established a covert SMTP email relay network by hijacking 230 cloud servers across AWS, Google Cloud, and Azure. The operation involved converting business server… The Hacker News · Jun 5, 2026 High USUKDEsmtp relaycloud proxyc2
threat-intel Reporting from Vegas: Networking, AI, and good boys This Cisco Talos Threat Source newsletter highlights the ongoing challenges of managing data at scale in an AI-driven world, particularly during large technology conferences like Cisco Live. It details Talos’ expansion o… Cisco Talos · Jun 4, 2026 High USRUaithreat huntingc2
threat-intel Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting This article details Cisco Talos' approach to threat hunting, which differs from traditional alert-based detection. Instead of waiting for alerts, Talos analysts formulate hypotheses about adversary behavior based on tel… Cisco Talos · Jun 4, 2026 High USthreat huntingaicorrelation
apt Pakistan Spies on Afghan Finance Ministry With Xeno RAT A Pakistani advanced persistent threat (APT) group, identified as SideCopy and linked to the Transparent Tribe (APT 36), has been conducting espionage against Afghanistan's finance ministry since at least May 2025. The g… Dark Reading · Jun 4, 2026 High AFPKspear-phishingremote-accesspashto
malware Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT A new malspam campaign is leveraging Google's DoubleClick domain to deliver the DesckVB RAT, a .NET-based remote access trojan. The campaign’s scalability and cost-effectiveness stem from its ability to dynamically perso… The Hacker News · Jun 3, 2026 High USmalspamratdoubleclick
malware WordPress malware campaign hides payloads in Steam profiles A WordPress malware campaign has infected nearly 2,000 websites by hiding command-and-control (C2) data within Steam Community profile comments. The attackers utilize invisible Unicode characters to encode malicious payl… BleepingComputer · Jun 1, 2026 High USwordpresssteemunicode
threat-intel ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More This Hacker News recap details several ongoing cyber threats, including an active exploitation of a PAN-OS GlobalProtect authentication bypass vulnerability, a critical zero-day vulnerability in the Gogs Git service, and… The Hacker News · Jun 1, 2026 High CVE-2026-0257CVE-2026-8732CVE-2026-27771RUvulnerabilityauthenticationc2
threat-intel China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan A new cyber espionage campaign, dubbed Operation Dragon Weave, is targeting government, research, and financial institutions in the Czech Republic and Taiwan using spear-phishing emails and a Rust-based loader to deploy… The Hacker News · Jun 1, 2026 High CZTWINspear-phishingc2azure
threat-intel Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels North Korean state-sponsored threat actor Kimsuky has expanded its arsenal and tactics, utilizing HTTPSpy, HelloDoor, and VS Code tunnels to target South Korean military and corporate entities between March and April 202… The Hacker News · May 29, 2026 High KRnorth koreanremote access trojansocial engineering
threat-intel ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More This Hacker News bulletin details several recent cyber threats, including a massive C2 infrastructure footprint discovered in the Middle East dominated by IoT botnets, a privilege escalation vulnerability in Azure Backup… The Hacker News · May 28, 2026 High CVE-2026-8398SAROUSc2supply-chainprivilege-escalation
supply-chain Glassworm botnet disrupted after resilient C2 infrastructure takedown The Glassworm botnet, a supply-chain threat targeting developers, has been significantly disrupted following a coordinated takedown of its resilient command-and-control infrastructure. The botnet utilized a complex archi… BleepingComputer · May 27, 2026 High supply-chainbotnetc2
threat-intel GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure CrowdStrike, in collaboration with Google and Shadowserver Foundation, successfully disrupted the command-and-control infrastructure of the GlassWorm malware campaign, which targeted software developers through compromis… The Hacker News · May 27, 2026 High RUCIsupply chaindeveloperc2
malware Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th) This report details the discovery of a fake Claude webpage distributing the ACR Stealer malware, targeting macOS and Windows users. The initial infection vector involves malicious ads leading to the deceptive site, which… SANS Internet Storm Center · May 26, 2026 High USstealermacoswindows
malware Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor A new Linux malware, dubbed Showboat, has been used in a campaign targeting a telecommunications provider in the Middle East since at least 2022. The malware, developed by a China-linked threat actor group known as Calyp… The Hacker News · May 21, 2026 High CVE-2021-26855AFAZCHlinuxsocks5c2
threat-intel Hackers bypass SonicWall VPN MFA due to incomplete patching Hackers exploited a vulnerability (CVE-2024-12802) in SonicWall Gen6 SSL-VPN appliances to bypass multi-factor authentication and deploy ransomware tools. The attackers gained access to networks within 30-60 minutes, lev… BleepingComputer · May 20, 2026 High CVE-2024-12802USvpnmfacredential theft
apt GopherWhisper: A burrow full of malware ESET researchers have identified a new China-aligned Advanced Persistent Threat (APT) group, dubbed GopherWhisper, that targeted a Mongolian governmental entity. The group utilizes a diverse toolkit primarily built in Go… WeLiveSecurity · Apr 23, 2026 High MNaptchinago