threat-intel Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker This Smashing Security podcast episode explores a significant cyberattack targeting the Netherlands National Police Force, attributed to a Russian-backed hacking group known as Void Blizzard. The attack involved stealing… Graham Cluley · Jul 22, 2026 High NEUKNAcyberattackintelrussian
threat-intel Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Glow, a new AI-powered endpoint security startup, secured $180 million in Series A funding, valuing the company at $1.2 billion. Founded by former Meta and Snowflake executives, Glow focuses on mitigating security risks… SecurityWeek · Jul 22, 2026 Info aiendpoint securitycybersecurity
threat-intel Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Oracle released a massive quarterly security update addressing over 1,400 vulnerabilities, primarily identified through the use of AI. The update includes fixes for a wide range of products and services, highlighting the… SecurityWeek · Jul 22, 2026 High patchvulnerabilityai
threat-intel Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA German and US law enforcement dismantled Kratos, a widely used criminal phishing kit, after arresting the developer and taking down over 200 servers. The kit, used by approximately 1,800 customers, was designed to steal… The Hacker News · Jul 22, 2026 High DEUSIDphishingcredential theftmfa bypass
data-breach Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack Spain has fined 23andMe €2.4 million ($2.7 million) for failing to notify Spanish authorities about a 2023 data breach that impacted over 6.9 million people worldwide. The regulator cited inadequate cybersecurity practic… The Record · Jul 21, 2026 High ESgdprdata breachcybersecurity
threat-intel Empirical Security Raises $25 Million in Series A Funding Cybersecurity startup Empirical secured $25 million in Series A funding to bolster its AI-powered threat prediction and risk management solutions. The company, founded by former Kenna Security executives, aims to address… SecurityWeek · Jul 21, 2026 Info aivulnerabilityrisk management
data-breach Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Estée Lauder has been hit by a zero-day vulnerability in Oracle EBS, allowing the Cl0p cybercrime group to steal a massive amount of sensitive data, including personal information and payroll details. The breach, discove… SecurityWeek · Jul 21, 2026 High CVE-2025-61882zero-daydata breachremote code execution
data-breach Clover Health Investments Discloses Data Breach Clover Health Investments suffered a data breach due to a social engineering attack targeting employee accounts. The attackers gained access to member and broker data, but did not reach sensitive corporate financial syst… SecurityWeek · Jul 21, 2026 Medium USdata breachsocial engineeringhealthcare
threat-intel Software provider to more than 2,000 US hospitals says hackers stole employee and customer data Craneware, a UK-based software provider used by over 2,000 U.S. hospitals, has been hacked, resulting in the theft of employee, customer, and partner data. The company has contained the breach and reported it to law enfo… The Record · Jul 20, 2026 High UKUShealthcaredata breachcyberattack
threat-intel Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs A Russian-speaking threat actor, “bandcampro,” leveraged Google Gemini CLI to orchestrate a botnet and conduct various cybercrime activities, including dental clinic control and cryptocurrency fraud. The actor utilized t… The Hacker News · Jul 20, 2026 High USCARUaicybercrimebotnet
threat-intel Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man A Russian tourist, Aleksandr Yuryevich Ermakov, is being held in Armenia on a U.S. extradition warrant, despite his lawyers arguing he is the wrong man. The U.S. seeks Aleksandr Gennadievich Ermakov, a Russian national p… The Hacker News · Jul 17, 2026 High AUUSRUransomwareextraditionidentity-error
ransomware Anubis ransomware: what you need to know The Anubis ransomware, delivered as a service, is targeting healthcare organizations, but its reach extends beyond this sector. This RaaS operation is causing significant disruption and data loss for affected entities, h… Graham Cluley · Jul 16, 2026 High ransomwareraashealthcare
threat-intel Legacy Systems, Real-World Impacts: The Reality of OT Security This article highlights the unique challenges of securing Operational Technology (OT) systems compared to traditional IT environments. Unlike IT, OT vulnerabilities often lead to devastating real-world consequences – lik… SecurityWeek · Jul 16, 2026 High otcybersecurityvulnerability
data-breach 23andMe reaches $18 million settlement with states for massive breach 23andMe has reached a $18 million settlement with 42 state attorneys general due to a significant data breach in 2023 that exposed the genetic and personal information of 6.9 million customers. The company initially deni… The Record · Jul 15, 2026 High data breachgenetic datacybersecurity
threat-intel Finland issues wanted notice for hacker behind massive psychotherapy data breach Finnish authorities have issued a wanted notice for convicted hacker Aleksanteri Kivimäki, following a Supreme Court ruling, in connection with a massive data breach targeting psychotherapy provider Vastaamo. The breach,… The Record · Jul 14, 2026 High FIdata breachcybercrimehacking
vulnerability SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud SAP released 19 security patches on July 26th, 2026, addressing critical vulnerabilities across several of its flagship products, including NetWeaver, Approuter, and Commerce Cloud. The most severe vulnerability, CVE-202… SecurityWeek · Jul 14, 2026 Critical CVE-2026-44747CVE-2026-27690CVE-2026-44761sapvulnerabilitypatch
threat-intel U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support The U.S. Treasury Department has sanctioned a VPN service provider, First VPN Service (1VPNS), and its administrator, Dmytro Rashevskyi, for enabling ransomware groups to carry out attacks against U.S. companies and inst… The Hacker News · Jul 14, 2026 High CVE-2018-0171CVE-2008-4128RUUKUNvpnransomwarecyber espionage
threat-intel Weak Security Continues to Fuel Russian Cyberattacks The UK and EU have jointly sanctioned Russian individuals and entities involved in cyberattacks and disinformation campaigns, coinciding with a US cybersecurity advisory highlighting ongoing Russian state-sponsored attac… Dark Reading · Jul 13, 2026 High UKEUUNrouter securityciscosnmp
threat-intel Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption Jesse McGraw, once a notorious blackhat hacker known as GhostExodus and leader of the Electronik Tribulation Army (ETA), has undergone a dramatic transformation. Driven by a complex mix of factors including neurodiversit… SecurityWeek · Jul 13, 2026 High neurodiversityred-hatosint
data-breach Centers Laboratory Data Breach Affects 540,000 Individuals Centers Laboratory, a healthcare diagnostics company, suffered a data breach in August 2025, exposing the personal and protected health information of over 540,000 individuals. The breach was carried out by the WorldLeak… SecurityWeek · Jul 13, 2026 High data breachcybercrimehealthcare