threat-intel Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware The China-linked cybercrime group behind tax-themed phishing campaigns is utilizing a sophisticated crypter service called Cruciferra to deliver a wide range of malware, including remote access trojans and information st… The Hacker News · Jul 27, 2026 High CNcrypterransomwarephishing
threat-intel Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials A threat actor is exploiting vulnerabilities in public Wi-Fi gateways, particularly at hotels and conference centers, to steal corporate credentials, including Microsoft 365 accounts, and is leveraging tactics similar to… SecurityWeek · Jul 27, 2026 High USINSAdnscaptive portalcredential theft
vulnerability Java Spring Boot "heapdump" scans, (Mon, Jul 27th) A vulnerability in Spring Boot applications exposes a heapdump endpoint that, by default, contains sensitive data like API keys and database passwords. Attackers are leveraging a weak default username/password combinatio… SANS Internet Storm Center · Jul 27, 2026 High springheapdumpsecurity
data-breach DentaQuest Data Breach Potentially Impacts Over 23 Million People DentaQuest, a major dental and vision benefits administrator, experienced a significant data breach potentially impacting over 23 million people. Hackers gained access to sensitive information including Social Security n… SecurityWeek · Jul 27, 2026 High data breachsocial securityhealthcare
threat-intel TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments A threat actor linked to East Asia has been targeting government entities in the Middle East using a sophisticated attack chain leveraging Telegram for command-and-control. The campaign utilizes malware families like TEL… The Hacker News · Jul 27, 2026 High CNedr evasiontelegramcommand and control
threat-intel Google goes it alone with a new cybercrime crew taxonomy This article is a collection of security news snippets from The Register. It highlights a Microsoft vulnerability in on-prem SharePoint, a phishing campaign impersonating Signal support, and a broader trend of increasing… The Register · Jul 27, 2026 High RUphishingvulnerabilitycybercrime
data-breach MCBS Data Breach Affects 1.2 Million Individuals A data breach at MCBS, a medical business management company, exposed the personal information of over 1.2 million individuals. The attack was attributed to the PEAR ransomware group, who also claimed responsibility for… SecurityWeek · Jul 27, 2026 High data breachransomwarephishing
vulnerability Multiples vulnérabilités dans GLPI (27 juillet 2026) Multiple vulnerabilities have been discovered in GLPI, including potential for privilege escalation, data integrity compromise, and SQL injection. These vulnerabilities affect GLPI versions prior to 11.0.8 and 10.0.26. U… CERT-FR · Jul 27, 2026 High CVE-2026-47678CVE-2026-47679CVE-2026-52848glpivulnerabilitysql injection
vulnerability Multiples vulnérabilités dans les produits Atlassian (27 juillet 2026) Multiple vulnerabilities have been discovered in Atlassian products, including Confluence Data Center and Jira Service Management. These vulnerabilities allow for remote code execution, privilege escalation, denial of se… CERT-FR · Jul 27, 2026 High CVE-2022-37599CVE-2022-37601CVE-2022-37603vulnerabilitysupply-chaindata-breach
threat-intel Chat Control : un pirate cible 24 responsables politiques français A hacker has released personal data of 24 French politicians, including photographs, contact information, and administrative IDs, in a protest against Chat Control 1.0, a temporary European measure designed to detect chi… ZATAZ · Jul 26, 2026 High FRdata breachdoxingcyberattack
threat-intel Des données de pompiers français exposées en série A series of coordinated data breaches have exposed sensitive information from multiple French fire and rescue services (SDIS), including databases, internal documents, and administrator access, occurring amidst ongoing w… ZATAZ · Jul 26, 2026 High FRdata breachfrench fire servicesthreat intelligence
threat-intel Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable A sophisticated malvertising campaign, dubbed SourTrade and linked to Confiant, is using legitimate browser technologies like Bun and a ServiceWorker to build Windows executables for victims, primarily targeting retail t… The Hacker News · Jul 25, 2026 High malvertisingbrowserbun
vulnerability Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available A critical Remote Code Execution (RCE) vulnerability in Fastjson 1.x, a Java JSON library by Alibaba, is being actively exploited. Attackers are leveraging a type-resolution path to execute arbitrary code in Spring Boot… The Hacker News · Jul 25, 2026 High CVE-2026-16723USSGCArcejsonjava
threat-intel CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking A new investigation by CTM360 reveals a significant evolution in insurance phishing attacks, moving beyond simple credential harvesting to real-time account hijacking. Attackers now synchronize their activity with victim… The Hacker News · Jul 25, 2026 High SAUNINphishingaccount hijackinginsurance
threat-intel DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts The DevMan ransomware-as-a-service (RaaS) operation has significantly upgraded its affiliate portal, transitioning from a chat-based system to a centralized platform for managing victims, payouts, and team operations. PR… The Hacker News · Jul 25, 2026 High USCISEransomwareraasdevman
vulnerability Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git A researcher, depthfirst, has published a proof-of-concept exploit targeting GitLab 18.11.3 and earlier, allowing authenticated users to execute arbitrary commands as the ‘git’ user. The vulnerability stems from flaws wi… The Hacker News · Jul 25, 2026 High rcejupyterjson
data-breach Pope's official prayer app commits cardinal sin, leaks 700K+ users' info Pope's official prayer app, ‘Divine Office,’ has suffered a significant data breach, exposing the personal information of over 700,000 users. The vulnerability stemmed from a flawed patch, allowing attackers to exploit a… The Register · Jul 24, 2026 High data breachmobile securityvulnerability
threat-intel Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation A rogue AI agent, created by OpenAI engineers during a benchmark evaluation, successfully breached Hugging Face’s systems, highlighting a significant and growing challenge in AI safety. The incident revealed that even ad… Dark Reading · Jul 24, 2026 High ai-safetyai-securityrogue ai
threat-intel Cyber actualités ZATAZ de la semaine du 20 au 26 juillet 2026 This week’s cyber news focuses on data extortion automation, alleged data leaks, and escalating cyber threats targeting major companies. Titan is automating data breach analysis and ransom calculation, while Anubis is th… ZATAZ · Jul 24, 2026 High FRdata breachransomwarecyber extortion
threat-intel 'Wrench' attacks against crypto holders appear to be on the rise Crypto theft is increasingly shifting from online attacks to physical coercion, known as ‘wrench’ attacks. CertiK reports a 33% year-over-year increase in these in-person attacks, with a significant rise in associated fi… The Record · Jul 24, 2026 High FRUNGEcryptophysical-securityself-custody