threat-intel 'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China A sophisticated, full-service mobile malware-as-a-service (MaaS) framework called ‘Flying Eagle’ has emerged from the Chinese cybercriminal underground, enabling criminals to build and deploy mobile malware campaigns wit… Dark Reading · Jul 30, 2026 High CHmaasmobile malwarecybercrime
threat-intel Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity Russia has charged Telegram founder Pavel Durov with aiding terrorist activity, alleging that the platform was used by Ukrainian special services and terrorist organizations to plan attacks and facilitate cybercrime with… The Hacker News · Jul 29, 2026 High RUUArussiaukraineintelligence
threat-intel Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates A remote access trojan (RAT) called Flying Eagle, along with a related control kit called Night Dragon, is circulating through criminal Telegram channels. Researchers have identified 170 servers hosting the RAT framework… The Hacker News · Jul 29, 2026 High CNandroidrattelegram
data-breach ShinyHunters Claims Ernst & Young Hack The extortion group ShinyHunters has claimed responsibility for a recent data breach at Ernst & Young, exposing sensitive personal and financial information of EY clients. The stolen data includes names, addresses, Socia… SecurityWeek · Jul 29, 2026 High data breachextortiontor
threat-intel ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques to steal credentials. The threat landscape is evolving rapi… SANS Internet Storm Center · Jul 29, 2026 High phishingcredential-stealingbusiness-application
vulnerability 'Certighost' Flaw Haunts Microsoft Active Directory Certificates A critical vulnerability, dubbed ‘Certighost,’ has been patched by Microsoft that allowed a low-privileged domain user to impersonate a domain controller and compromise an Active Directory environment. The flaw stemmed f… Dark Reading · Jul 28, 2026 Critical CVE-2026-54121UNcertificateactive directorypkis
threat-intel Charity bank pulls online services over third-party software flaw A charity bank in the UK has temporarily shut down its online services due to a vulnerability in third-party software. The issue stems from a flaw within a specific software component, leading to potential security risks… The Register · Jul 28, 2026 Medium vulnerabilitybankingsecurity
threat-intel Mirage Kitten targets Middle East and Africa region with new malware The advanced persistent threat (APT) group Mirage Kitten, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is aggressively targeting sectors in the Middle East and Africa, including aerospace, aviation, tele… Securelist · Jul 28, 2026 High EGJOTAaptmalwarethreat-intel
vulnerability ISC Stormcast For Tuesday, July 28th, 2026 https://isc.sans.edu/podcastdetail/10026, (Tue, Jul 28th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise a… SANS Internet Storm Center · Jul 28, 2026 Critical rceapacheactivemq
threat-intel AI Agent Drives Espionage Attack on Thai Ministry of Finance Threat actors used an autonomous AI agent, Hermes, to conduct espionage against Thailand's Ministry of Finance. The attack, supported by open-source tools like LinPEAS and Hades (a custom Windows/Linux malware), involved… Dark Reading · Jul 28, 2026 High CHHOaiespionagemalware
threat-intel FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown The FBI, in collaboration with international law enforcement agencies, successfully dismantled LockBit, one of the most prolific ransomware-as-a-service (RaaS) groups, through Operation Cronos. The operation focused on b… Dark Reading · Jul 27, 2026 High UNRUransomwareraasoperation cronos
threat-intel Hackers used autonomous AI agent to spy on Thailand's finance ministry Hackers used an autonomous AI agent, Hermes developed by Nous Research, to conduct a cyber-espionage campaign targeting Thailand's Ministry of Finance. The agent independently explored the ministry's network, gathering i… The Record · Jul 27, 2026 High CNaicyberespionageautonomous agent
threat-intel Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware The China-linked cybercrime group behind tax-themed phishing campaigns is utilizing a sophisticated crypter service called Cruciferra to deliver a wide range of malware, including remote access trojans and information st… The Hacker News · Jul 27, 2026 High CNcrypterransomwarephishing
threat-intel Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable A sophisticated malvertising campaign, dubbed SourTrade and linked to Confiant, is using legitimate browser technologies like Bun and a ServiceWorker to build Windows executables for victims, primarily targeting retail t… The Hacker News · Jul 25, 2026 High malvertisingbrowserbun
threat-intel BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery North Korean threat actors, operating under the BlueNoroff campaign, are using a sophisticated phishing kit to target crypto investors and venture capitalists. The kit leverages compromised trusted contacts and typosquat… The Hacker News · Jul 24, 2026 High KPphishingzoommicrosoft teams
vulnerability Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researchers discovered a vulnerability, dubbed ‘Certighost,’ allowing low-privilege Active Directory users to impersonate Domain Controllers by obtaining certificates. The flaw leverages a chase mechanism within Active D… The Hacker News · Jul 24, 2026 High CVE-2026-54121active directorycertificate authoritykerberos
threat-intel Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry A Thai Ministry of Finance employee installed the Hermes AI assistant, a tool designed for mail management and task automation, on a rented server. The agent, left running unattended, autonomously scanned the ministry's… The Hacker News · Jul 24, 2026 High CVE-2026-31431CVE-2026-43284CVE-2026-43500THHOaiunattendeddefault
threat-intel ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions and a concerning trend of Log4j exploitation attempts. The threat landscape remains volatile, with attack… SANS Internet Storm Center · Jul 24, 2026 Medium phishinglog4jbec
threat-intel Agentic AI Challenges Progress in Confidential Computing Artificial intelligence is driving increased adoption of confidential computing, but the proliferation of AI agents within enterprises poses a new security challenge. These agents can retain sensitive data and secrets, e… Dark Reading · Jul 23, 2026 High UNaiconfidential computingsecurity
threat-intel State Department imposes visa restrictions on foreign cyber scammers The State Department is implementing new visa restrictions targeting individuals involved in foreign cybercrime networks, specifically those linked to scams like sextortion and human trafficking. This follows a broader e… The Record · Jul 23, 2026 High PHCACHcybercrimevisa restrictionssoutheast asia