threat-intel OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps OkoBot, a malware framework, has been actively targeting hardware wallet users since April 2025, primarily through phishing attacks leveraging a module called SeedHunter. SeedHunter intercepts the wallet's desktop softwa… The Hacker News · Jul 15, 2026 High BRVNCAphishingmalwarehardware wallet
supply-chain Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware A sophisticated supply-chain attack leveraging compromised npm packages has delivered a multi-stage botnet loader, Miasma, to numerous developers. The attacker exploited a GitHub Actions release pipeline to inject malici… The Hacker News · Jul 15, 2026 High supply chainnpmgithub actions
vulnerability Cursor IDE Auto-Executes Malicious Code in Poisoned Repos A security vulnerability in Cursor IDE allows attackers to automatically execute malicious code embedded in poisoned Git repositories. Researchers at Mindgard discovered the flaw in December, but Cursor has not addressed… Dark Reading · Jul 14, 2026 High gitrepositorymalware
threat-intel The serpent’s tongue: Luring the Python out of its den This report from Cisco Talos details a growing threat landscape surrounding Python packages, focusing on supply chain attacks leveraging malicious packages installed through package managers like PyPI. The report highlig… Cisco Talos · Jul 14, 2026 High supply chainpythonmalware
supply-chain Multiple Jscrambler Packages Impacted by Supply Chain Attack A supply chain attack targeting Jscrambler’s NPM package led to the distribution of malicious versions containing malware designed to steal sensitive information from developer and cloud environments. The attack exploite… SecurityWeek · Jul 14, 2026 High npmsupply chainmalware
threat-intel The ransomware negotiator who was working for the other side A Florida man, Angelo John Martino III, was sentenced to 70 months in prison for secretly providing ransomware negotiation details and actively deploying BlackCat ransomware alongside two colleagues. He exploited his rol… Graham Cluley · Jul 14, 2026 Critical USransomwarenegotiationinsider threat
threat-intel 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May. These packages, initially designed as tutoring tools, lo… The Hacker News · Jul 14, 2026 High USbotnetddosproxy
threat-intel Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns Chinese and Indian-aligned threat actors have been conducting sustained cyber espionage campaigns targeting Pakistani law enforcement organizations, including the Balochistan Police, Khyber Pakhtunkhwa Police, Islamabad… The Hacker News · Jul 11, 2026 High CHINPAcyber espionagelaw enforcementchina
threat-intel AI Coding: Do Security Risks Outweigh Productivity Gains? AI coding tools are rapidly increasing in popularity, with 91% of organizations using two or more and 54% using three or more. While developers report productivity gains and ROI, significant security risks are associated… Dark Reading · Jul 10, 2026 High aicodingsecurity
supply-chain Network of 200 GitHub Repositories Used for Malware Infection A threat actor, linked to previous activity associated with the ‘ischhfd83’ email address, has created a network of over 200 GitHub repositories delivering Windows malware through a Go module disguised as a DNS scanning… SecurityWeek · Jul 10, 2026 High supply chaingithubmalware
threat-intel Winning 54% of the time Cisco Talos Intelligence has identified a China-nexus threat actor, UAT-7810, expanding its Operational Relay Box (ORB) network. The group exploits unpatched vulnerabilities in Ruckus and ASUS routers to deploy custom ma… Cisco Talos · Jul 9, 2026 High CHorbproxyrouter
threat-intel Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes A China-based threat actor, dubbed Lurking Lizard, has been running a sophisticated, multi-year residential proxy business. The operation involves tricking users into installing malicious 7-Zip installers and other fake… The Hacker News · Jul 9, 2026 High CHresidential proxybotnetmalware
threat-intel Taiwan charges two businessmen over alleged role in Chinese espionage campaign Taiwanese authorities have charged two businessmen for allegedly facilitating a Chinese espionage campaign targeting Taiwanese politicians, academics, journalists, and civil society groups. The suspects operated a compan… The Record · Jul 8, 2026 High CHTAespionagephishingcybercrime
threat-intel SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users A new banking fraud operation, tracked as REF6045, is targeting Mexican banks, fintech companies, and cryptocurrency exchanges using a malware toolset called SCMBANKER. The operation leverages fake CAPTCHA verification p… The Hacker News · Jul 8, 2026 High MXbankingmalwarephishing
threat-intel China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware A Chinese APT group, UAT-7810, is expanding its Operational Relay Box (ORB) network by utilizing custom malware, including LONGLEASH and LEASHTEST, to establish persistent access for secondary threat actors. The group le… The Hacker News · Jul 8, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717TWaptmalwarec2
threat-intel RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service A new Android malware operation, RedWing, is being sold on Telegram as a ready-made bank fraud service. Developed by a Russian threat actor group, RedWing allows even unskilled criminals to steal banking logins and one-t… The Hacker News · Jul 7, 2026 High RUandroidmalwarefraud
threat-intel Threat landscape for industrial automation systems. Q1 2026 In Q1 2026, the effectiveness of blocking malicious objects on industrial control systems (ICS) decreased significantly, reaching 19.6%, a three-year low. Growth in blocked threats was most pronounced in Southern Europe… Securelist · Jul 7, 2026 Medium UNRUSOicsindustrial control systemsmalware
threat-intel UAT-7810 continues building ORB networks using new malware Cisco Talos Intelligence has identified UAT-7810, a China-nexus APT group, continuing to develop and deploy malware as part of its Operational Relay Box (ORB) network. The group is actively creating new malware variants,… Cisco Talos · Jul 7, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717CHaptmalwarechina
threat-intel Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks Securonix researchers identified a complex malware delivery framework called ‘Veil#Drop’ that utilizes compromised websites, specifically Blogspot, to deploy information-stealing malware. The framework employs multiple l… SecurityWeek · Jul 6, 2026 High malwareinformation stealerevasion
supply-chain North Korean Hackers Target Open Source Developers in Supply Chain Attacks North Korean hackers, linked to the Contagious Interview operation, are engaging in a sophisticated supply chain attack targeting open-source developers. They are leveraging compromised GitHub repositories and malicious… SecurityWeek · Jul 6, 2026 High KRsupply-chaingithubopen-source