threat-intel What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out Lookout has launched a new Mobile Security Exposure Center (MSEC) designed to provide organizations with a deeper understanding of the vulnerabilities hidden within their mobile apps. MSEC creates a ‘software bill of mat… SecurityWeek · Jul 27, 2026 High CHmobile-securitysbomvulnerability
threat-intel GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption GitHub has implemented a three-day cooldown period for Dependabot to mitigate the risk of malicious packages being rapidly adopted by downstream projects. This new feature aims to slow down the spread of poisoned package… The Hacker News · Jul 27, 2026 Medium supply-chainpackage-managementdependency-updates
vulnerability Multiples vulnérabilités dans les produits Atlassian (27 juillet 2026) Multiple vulnerabilities have been discovered in Atlassian products, including Confluence Data Center and Jira Service Management. These vulnerabilities allow for remote code execution, privilege escalation, denial of se… CERT-FR · Jul 27, 2026 High CVE-2022-37599CVE-2022-37601CVE-2022-37603vulnerabilitysupply-chaindata-breach
threat-intel Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE Threat actors linked to the Cl0p ransomware group are exploiting internet-exposed PTC Windchill and FlexPLM deployments to gain unauthenticated remote code execution and steal sensitive data for extortion. The campaign l… The Hacker News · Jul 25, 2026 Critical CVE-2026-12569vulnerabilityransomwaredata-breach
threat-intel Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks CERT-UA has warned of a new phishing campaign led by the UAC-0099 threat cluster (linked to Russia) utilizing a malicious Notepad++ plugin to deliver the MATCHBOIL.V2 malware. The campaign begins with a phishing email co… The Hacker News · Jul 24, 2026 High CVE-2025-66376CVE-2026-8496CVE-2025-49113RUUKALphishingmalwarevulnerability
threat-intel ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories This week's "ThreatsDay" bulletin highlights a diverse range of security threats, from malware targeting PLCs with Iranian involvement to AI-generated vulnerabilities and deceptive apps. Key concerns include a GitHub sup… The Hacker News · Jul 23, 2026 High IRmalwarethreat intelligencesupply-chain
threat-intel Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors, known as LAUNDRY BEAR, has been aggressively targeting Western organizations using the Zimbra Collaboration Suite (ZCS) since July 2025, seeking to gather sensitive inform… CISA Advisories · Jul 23, 2026 High CVE-2025-66376MOPOSPphishingsupply-chainmalware
threat-intel Talking smack about a doctor got him access to private medical files This article is a collection of security and technology news snippets. It highlights a vulnerability impacting Joomla websites due to extension bugs, a Russian phishing campaign mimicking Signal support, and Microsoft's… The Register · Jul 23, 2026 Medium RUIRvulnerabilityphishingransomware
threat-intel Attackers Are Learning to Live Off the AI Toolchain Attackers are increasingly leveraging AI coding assistants and CI/CD pipelines to hide malicious activity, a trend exemplified by the Sandworm_Mode worm. This ‘living off the AI toolchain’ approach makes detection incred… Dark Reading · Jul 22, 2026 High aimalwaresupply-chain
threat-intel Ransomware Is Accelerating, But It's Not Because of AI Ransomware activity is surging, with a 25% increase in incidents between April 2025 and March 2026, driven by a fragmented ecosystem and the emergence of numerous new groups. Black Kite researchers found that many victim… Dark Reading · Jul 21, 2026 High USEUransomwarevulnerabilitysupply-chain
threat-intel Siemens SIDIS Secured SmartPlug Siemens SIDIS Secured SmartPlug versions prior to V7.26.0310 are affected by multiple vulnerabilities stemming from components like OpenSSL, OpenSSH, and libarchive. These vulnerabilities include side-channel attacks, in… CISA Advisories · Jul 21, 2026 High CVE-2022-23303CVE-2019-9494CVE-2022-23304vulnerabilitysupply-chainopen ssl
threat-intel ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More This week saw a flurry of vulnerabilities and attacks, including a WordPress core flaw leading to remote code execution, exploitation of zero-day vulnerabilities in SonicWall VPN appliances, and a new malware framework (… The Hacker News · Jul 20, 2026 High CVE-2026-63030CVE-2026-60137CVE-2026-15409INTÜBRvulnerabilityzero-dayransomware
threat-intel Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei A cyberattack disrupted operations at Nichirei, a major Japanese frozen food producer, impacting its logistics, warehousing, and shipping services. The company disconnected systems as a precaution, and is investigating a… SecurityWeek · Jul 17, 2026 Medium JPcyberattackdata-breachransomware
threat-intel ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files ACR Stealer, an infostealer active since 2024, is leveraging deceptive lures – primarily mimicking Claude AI assistant pages and fake CAPTCHAs – to steal browser credentials, Microsoft 365 files, and sensitive documents.… The Hacker News · Jul 17, 2026 High infostealerdeceptive lureransomware
threat-intel Multiples vulnérabilités dans les produits IBM (17 juillet 2026) Multiple vulnerabilities have been discovered in IBM products, including remote code execution, privilege escalation, and denial-of-service vulnerabilities. Several CVEs have been assigned, covering a wide range of IBM p… CERT-FR · Jul 17, 2026 High CVE-2020-28500CVE-2020-7760CVE-2020-8203vulnerabilitysupply-chainremote-code-execution
threat-intel Begun, the Patch Wars have Cisco Talos has identified a sophisticated, financially motivated Russian-speaking adversary, UAT-11795, actively targeting users in the U.S. and Europe since June 2025. This campaign utilizes trojanized software install… Cisco Talos · Jul 16, 2026 High UNRUEUsupply-chainaptzero-day
threat-intel ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories This week’s security news is a mixed bag, encompassing a range of threats from sophisticated ransomware attacks to deceptive software distribution and widespread surveillance techniques. A new ransomware family, Spirals,… The Hacker News · Jul 16, 2026 High CVE-2026-46817CVE-2023-4346CVE-2026-35273NESPPOransomwareinfostealerbrandjacking
threat-intel OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps OkoBot, a malware framework, has been actively targeting hardware wallet users since April 2025, primarily through phishing attacks leveraging a module called SeedHunter. SeedHunter intercepts the wallet's desktop softwa… The Hacker News · Jul 15, 2026 High BRVNCAphishingmalwarehardware wallet
supply-chain Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install A malicious npm package, jscrambler 8.14.0, was released with a hidden infostealer that silently dropped and executed during installation. The package, pushed by a compromised account, included a Rust-based stealer targe… The Hacker News · Jul 11, 2026 High npmsupply-chainrust
ransomware No Manners Here: The Ruthless Rise of The Gentlemen Ransomware The Gentlemen, a rapidly growing Ransomware-as-a-Service (RaaS) program, has significantly increased its victim count in 2026, becoming the second most active RaaS program globally. Leveraging a 90% affiliate payout stru… Palo Alto Unit 42 · Jul 10, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073USCAGBransomware-as-a-serviceracksedge-device-attack