threat-intel Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 A joint bulletin from the FBI, MI5, ASIO, CSIS, and NZSIS warns of a Chinese intelligence operation targeting Western professionals via LinkedIn and other job platforms. The operation involves posing as recruitment firms… Graham Cluley · Jun 5, 2026 High CHUNAUrecruitmentintelligencelinkedin
threat-intel New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework A new threat cluster, OP-512, is targeting Microsoft IIS servers with a custom web shell framework, exhibiting sophisticated evasion techniques and centralized management capabilities. ReliaQuest has linked the activity… The Hacker News · Jun 5, 2026 High CNiisweb shellespionage
threat-intel Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities The Five Eyes intelligence alliance has issued an alert warning of a sophisticated Chinese espionage campaign targeting government and military personnel through fake job opportunities on platforms like LinkedIn. This ta… SecurityWeek · Jun 5, 2026 High CHUNAUespionagesocial-engineeringrecruitment
threat-intel Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It The article highlights the increasing use of agentic AI in defense and intelligence networks, emphasizing the potential risks associated with its deployment. A recent incident involving Anthropic's Claude Mythos model de… The Hacker News · Jun 4, 2026 High aiagentic aidefense
threat-intel Five Eyes warn Chinese spies are using job sites to recruit insiders The Five Eyes intelligence alliance has issued a joint warning about Chinese military intelligence services using online job platforms to recruit individuals with access to sensitive information. This tactic, described a… The Record · Jun 4, 2026 High CHAUCArecruitmentespionagecybersecurity
threat-intel New cyber force would cost up to $11 billion to start, commission says This article reports on a commission’s recommendation for the U.S. to establish a dedicated cyber warfare force, estimated to cost up to $11 billion and staffed by approximately 30,000 personnel. The proposal stems from… The Record · Jun 3, 2026 High UNRUCHcybersecuritymilitarydefense
threat-intel As the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge Caution This article reports on the U.S. Department of Defense's push to integrate artificial intelligence into military operations, particularly within the Special Operations Command, while facing concerns from tech companies a… SecurityWeek · Jun 1, 2026 Medium UNartificial intelligenceaimilitary
threat-intel Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say As a result of sanctions and the ongoing war in Ukraine, Russian intelligence agencies are intensifying their efforts to steal Western technology and defense secrets. This includes targeting advanced machine tools, resea… SecurityWeek · May 30, 2026 High RUSEFIsanctionsespionagecyberattack
threat-intel Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels North Korean state-sponsored threat actor Kimsuky has expanded its arsenal and tactics, utilizing HTTPSpy, HelloDoor, and VS Code tunnels to target South Korean military and corporate entities between March and April 202… The Hacker News · May 29, 2026 High KRnorth koreanremote access trojansocial engineering
threat-intel ESET APT Activity Report Q4 2025–Q1 2026 ESET’s Q4 2025 – Q1 2026 APT Activity Report highlights a period of intense geopolitical activity driving advanced cyber espionage. China-aligned actors were mobilized to monitor maritime and energy developments, while I… WeLiveSecurity · May 28, 2026 High CHIRPOaptcyber espionagegeopolitics
threat-intel Rudd orders Cyber Command reviews as Pentagon presses reform agenda U.S. Cyber Command is undergoing a comprehensive review commissioned by newly appointed head Gen. Joshua Rudd to modernize the military’s digital warfare arm. The review, led by MITRE, will examine acquisition processes… The Record · May 27, 2026 Medium UNcybersecuritymodernizationacquisition
threat-intel Iranian APT Targets Aviation, Software Companies With Updated Tools The Iranian APT group, known as Nimbus Manticore, has been aggressively updating its tactics and tools to target aviation and software companies globally. The group, linked to Charming Kitten and the IRGC, is employing… SecurityWeek · May 26, 2026 High AEIRSAaptphishingappdomain
ddos Canadian man arrested, charged for running KimWolf DDos botnet A Canadian man, Jacob Butler, has been arrested and charged with operating the KimWolf DDoS botnet, a significant online threat that disrupted numerous websites. Law enforcement agencies, in a coordinated international e… The Record · May 22, 2026 High CAUSGEddosbotnetcybercrime
threat-intel Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada A 23-year-old man, identified as Jacob Butler (a.k.a. ‘Dort’), has been arrested in Canada and faces criminal charges for operating the Kimwolf DDoS botnet. The botnet, responsible for massive DDoS attacks and targeting… Krebs on Security · May 21, 2026 High CAUSddosbotnetiot
threat-intel Smashing Security podcast #468: High-speed train hacks and homicidal lawnmowers This Smashing Security podcast episode discusses several ongoing cybersecurity incidents and investigations. The conversation touches on the ongoing Lazarus Group activities, including the upcoming ‘Cyberhack’ season, an… Graham Cluley · May 20, 2026 High NOTAnorth koreamalwarethreat intelligence
threat-intel What Will Make AI BOMs Real? This article discusses the growing momentum behind the adoption of AI Bills of Materials (AIBOMs) within the cybersecurity industry. Driven by standards development, commercial tool releases, regulatory pressure, and evo… Dark Reading · May 19, 2026 Medium USEUaisbommodel-training
threat-intel The quest for greater tech independence The article explores the growing trend of nations, particularly in Europe, seeking greater tech sovereignty – the ability to independently control their digital infrastructure and technology supply chains – driven by con… WeLiveSecurity · May 19, 2026 High EUCHUStech sovereigntydigital independencesupply chain
threat-intel The time of much patching is coming This article from Cisco Talos anticipates a significant increase in software patching due to advancements in AI-powered vulnerability detection and the uncovering of long-standing technical debt. The surge in discovered… Cisco Talos · May 14, 2026 High USvulnerabilitypatchingai
threat-intel Kimsuky targets organizations with PebbleDash-based tools This report details the ongoing activity of the Kimsuky threat actor group, also known as APT43, who have been utilizing a PebbleDash-based malware platform to conduct targeted attacks. The group has significantly evolve… Securelist · May 14, 2026 High KRBRDEspear phishingremote access trojansouth korea
threat-intel FrostyNeighbor: Fresh mischief and digital shenanigans FrostyNeighbor, a long-running cyberespionage group allegedly linked to Belarus, is continuing its operations targeting governmental organizations in Ukraine and other Eastern European countries. The latest activity invo… WeLiveSecurity · May 14, 2026 High BYPLLTcyberespionagecobalt strikepicassoloader