data-breach Medtronic Data Breach Impacts 3.8 Million People Medical technology giant Medtronic is notifying more than 3.8 million individuals that their personal and medical information was compromised in a recent data breach. The incident occurred in April 2026, when the infamou… SecurityWeek · Jul 3, 2026 High
malware PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords PamStealer, a new macOS information stealer developed by Jamf Threat Labs, utilizes deceptive tactics like mimicking the Maccy clipboard manager and exploiting Pluggable Authentication Modules (PAM) to steal login creden… The Hacker News · Jul 3, 2026 High RUBYKZmacosstealercredential theft
vulnerability Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution The DuneSlide vulnerabilities enable zero-click prompt injection attacks that escape Cursor's sandbox and execute arbitrary code on the underlying operating system. The post Critical Cursor AI Code Editor Flaws Could Lea… SecurityWeek · Jul 3, 2026 High CVE-2026-50548CVE-2026-50549
threat-intel Spyware found on phone of European Parliament member probing it A former European Parliament member, Stelios Kouloglou, was repeatedly targeted with Pegasus spyware while investigating the misuse of commercial spyware. Citizen Lab researchers discovered the infections occurred during… The Record · Jul 3, 2026 High GRDERUspywarepegasuseuropean parliament
threat-intel Launch of UK's National Cyber Action Plan delayed amid Labour leadership crisis The UK’s National Cyber Action Plan, intended to bolster the nation’s defenses against cyber threats, has been delayed again due to ongoing political instability within the Labour Party following Prime Minister Keir Star… The Record · Jul 2, 2026 High UKcybersecurityukpolitical delay
threat-intel Apple Reverses Age-Old Patch Policy to Keep Up With AI Apple is shifting its security patching strategy to a more frequent, independent release model in response to the accelerating pace of AI-driven attacks. Historically, Apple bundled security updates with major OS release… Dark Reading · Jul 2, 2026 High USaizero-daypatching
threat-intel FBI Seizes NetNut Proxy Platform, Popa Botnet The FBI, in collaboration with industry partners including Google and Lumen, has seized hundreds of domains associated with NetNut, a residential proxy service operated by Alarum Technologies, following findings linking… Krebs on Security · Jul 2, 2026 High USproxybotnetresidential proxy
ransomware FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs The FortiBleed operation, initially focused on stealing credentials from thousands of Fortinet FortiGate firewalls, has expanded to involve ransomware-as-a-service (RaaS) gangs Inc Ransom and Lynx. SOCRadar researchers d… Dark Reading · Jul 2, 2026 High USGBcredential theftransomware-as-a-servicezero-day
threat-intel Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices Google, in collaboration with the FBI and Lumen, has significantly reduced the size of the NetNut residential proxy network, which utilizes millions of home devices worldwide as relays for internet traffic. This network,… The Hacker News · Jul 2, 2026 High ISCHproxyresidentialbotnet
ransomware Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials The Anubis ransomware group, a rebranded version of Sphinx, is actively exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to gain initial access to victim networks. They leverage legitimate RMM tools like Scree… The Hacker News · Jul 2, 2026 High CVE-2025-5777USUKAUcitrixbleedransomware-as-a-servicecredential theft
threat-intel Catan and Mouse This Cisco Talos Threat Source newsletter highlights the emergence of ARToken, a sophisticated phishing-as-a-service (PhaaS) platform with capabilities previously undocumented. The platform, similar to EvilTokens, offers… Cisco Talos · Jul 2, 2026 High CVE-2026-48558USphishingbecai
ransomware The Gentlemen ransomware: what you need to know The Gentlemen ransomware group is a sophisticated and aggressive cybercriminal operation, despite its seemingly formal name. They are known for deploying double extortion tactics, stealing data and threatening to leak it… Graham Cluley · Jul 2, 2026 High ransomwaredouble extortioncybercrime
threat-intel Supreme Court decision threatens EU-US data transfer agreement A Supreme Court ruling questioning the independence of the U.S. Federal Trade Commission (FTC) poses a significant threat to the EU-U.S. Data Privacy Framework (DPF), a key agreement enabling data transfers between the t… The Record · Jul 2, 2026 High USEUdataprotectionprivacyeu-us
threat-intel ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories This week’s security news highlights several vulnerabilities and ongoing threats across various sectors. A phishing campaign targeting small businesses globally with ransomware, a root escape vulnerability in Claude Cowo… The Hacker News · Jul 2, 2026 High CVE-2026-33825CHUNGEphishingransomwaresandbox
threat-intel ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API The ToddyCat APT group is utilizing a new malware, Umbrij, to gain unauthorized access to Gmail accounts via the Google API. Umbrij leverages the OAuth 2.0 protocol to obtain access tokens, allowing attackers to control… The Hacker News · Jul 2, 2026 High RUoauthgoogle apiheadless browser
ransomware FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks Researchers say credentials harvested from hundreds of thousands of FortiGate firewalls are being used to facilitate ransomware attacks by the INC and Lynx operations. The post FortiBleed Campaign Linked to INC, Lynx Ran… SecurityWeek · Jul 2, 2026 High
threat-intel Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. This article reports on a significant investment by IBM and Red Hat into Project Lightwell, a new service designed to address the growing challenge of securing open-source software supply chains. Driven by Anthropic's My… Dark Reading · Jul 2, 2026 High USaivulnerabilityopen source
vulnerability ST Engineering iDirect iQ-Series Terminals ST Engineering iDirect has issued a security advisory regarding vulnerabilities in its iQ-Series Terminals, specifically versions through 4.5.2.1. These vulnerabilities allow unauthorized access to device information, in… CISA Advisories · Jul 2, 2026 High CVE-2026-38059CVE-2026-38057USapiauthenticationcsrf
threat-intel ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials Researchers at LayerX discovered a vulnerability dubbed ‘BioShocking’ that exploits the tendency of AI browsers to prioritize game-like objectives over security protocols. The attack leverages a puzzle-solving scenario t… SecurityWeek · Jul 2, 2026 High aibrowsercredentials
ransomware AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack A security firm, Sysdig, has identified what appears to be the first fully automated ransomware attack orchestrated by an AI agent, dubbed JADEPUFFER. The agent exploited a vulnerability in Langflow, an open-source AI ap… The Hacker News · Jul 2, 2026 High CVE-2025-3248CVE-2021-29441CHairansomwareautomation