threat-intel Dark Caracal Adds New Malware to Cyber Espionage Arsenal The Dark Caracal cyber-espionage group, linked to Lebanon, has added a new modular malware framework called GoCaracal to its arsenal. This framework, developed since 2026, is used for data theft, maintaining persistent a… Dark Reading · 4d ago High LBVEBRcyber-espionagedata theftmalware
threat-intel Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit The NSA is hosting a reunion for former members of its elite hacking unit, Tailored Access Operations (TAO), in an attempt to rebuild the group and bolster its capabilities. The event, spearheaded by NSA Deputy Director… The Record · 4d ago High hackingintelligencereunion
vulnerability 'HTTP Terminator' Hunts for Novel Desync Attacks A new open-source tool, dubbed 'HTTP Terminator,' developed by PortSwigger, utilizes AI to automatically discover novel HTTP request smuggling vulnerabilities. The tool identifies previously unknown attack vectors by ana… Dark Reading · 4d ago Medium httpvulnerabilityweb application
threat-intel Red Flags That Expose Fake North Korean IT Workers North Korean operatives are increasingly sophisticated in their attempts to infiltrate organizations by posing as IT workers, often leveraging stolen or fabricated identities and VPNs to mask their locations. Huntress In… Dark Reading · 4d ago High CHNEnorth koreanvpnproxy
threat-intel Medical device firm Boston Scientific says cyberattack has disrupted shipment processes Boston Scientific, a major medical device manufacturer, experienced a cyberattack that disrupted its shipment processes and impacted access to critical business applications. The company is working with cybersecurity exp… The Record · 4d ago Medium cyberattackmedical devicesdata breach
threat-intel More than 100 water systems were hit in July cyberattacks Multiple U.S. water systems were targeted in a July cyberattack, with over 100 systems affected. The attacks involved exploiting vulnerabilities in Joomla extensions, allowing attackers to gain unauthorized access and po… The Register · 4d ago High USRUjoomlasupply chaincritical infrastructure
threat-intel Meta pledges to overhaul kids’ safety protections, pay $17 billion to settle social media case Meta has reached a landmark settlement with U.S. states totaling $17 billion, requiring significant changes to its platforms to protect children's safety and privacy. The agreement includes limiting daily app usage for u… The Record · 4d ago High child safetyprivacysocial media
threat-intel Android Malware Hijacks Update System for Car Head Units Threat actors, linked to the BadBox click-fraud botnet, are exploiting legitimate update mechanisms in car head units to spread malware. This marks the first known instance of malware targeting automotive infotainment sy… Dark Reading · 4d ago High CHandroidbotnetmalware
threat-intel FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations The FBI has disrupted a Chinese-linked hacking infrastructure, QScan and QTRouter, operated by the group QTFY, which has been targeting U.S. critical infrastructure since 2018. These tools were used to steal data and con… The Hacker News · 4d ago High CVE-2024-8190CVE-2024-8963CVE-2024-9380CHcyber espionageiotproxy
threat-intel US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate The U.S. Department of Justice and FBI have taken down Chinese hacking tools – QScan and QTRouter – used by China’s Ministry of State Security and People’s Liberation Army to target U.S. agencies, including the Federal R… The Record · 4d ago High CHchinaiotcyberattack
threat-intel Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th) This article from the SANS Internet Storm Center details a PowerShell script used to analyze Entra ID Directory roles and identify users with administrative privileges. The script lists each role and the number of users… SANS Internet Storm Center · 4d ago Medium entradirectoryadminrightssecurityaudit
threat-intel Iran-linked hackers expand infrastructure across Europe and Middle East, report says Iranian-linked hackers, known as Tortoiseshell, are expanding their operations across Europe and the Middle East, including establishing infrastructure in Britain. The group, associated with Iran's Islamic Revolutionary… The Record · 4d ago High UKBESAiranaptssh tunnel
threat-intel Boston Scientific discloses 'global disruption' in ongoing cyberattack Boston Scientific is experiencing a significant cyberattack that has caused a global disruption. The company disclosed that an ongoing attack is impacting its operations, though details about the nature of the attack rem… The Register · 4d ago High cyberattackhealthcarecybersecurity
threat-intel Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler Iranian state-sponsored hacking group Nimbus Manticore (linked to Charming Kitten) has expanded its toolset with a TWOSTROKE-like backdoor and SSH tunneling utility, furthering its espionage activities targeting defense,… The Hacker News · 4d ago High IRMIEUsshbackdoorc2
threat-intel AI Speeds Up Malware Development, Not Its Success Rate: Analysis A Palo Alto Networks Unit 42 analysis of 405 AI-linked malware samples revealed that while AI is accelerating malware development, it hasn't significantly improved the malware's ability to evade detection. The majority o… SecurityWeek · 4d ago Medium CHUNaimalwaresandbox
data-breach Carhartt data breach affects 12.9M, half of what ShinyHunters claimed A data breach affecting Carhartt exposed the personal information of 12.9 million customers, with the attackers claiming a larger initial target size. The breach highlights ongoing risks associated with exploiting vulner… The Register · 4d ago High data breachvulnerabilityextension
threat-intel NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions A new phishing toolkit called NovaCookies is being used to steal Microsoft 365 sessions by abusing legitimate Docusign notifications and mimicking genuine email shares. Developed by an adversary-in-the-middle (AitM) oper… The Hacker News · 4d ago High USUKCAphishingaitmmicrosoft 365
threat-intel CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing CISA conducted two red team assessments against two critical infrastructure organizations, revealing vastly different defensive capabilities. Organization A was completely compromised at the domain level, with no detecti… The Hacker News · 4d ago High red teamdomain compromisecredential theft
vulnerability Adobe and Nvidia Patch Dozens of Vulnerabilities Adobe and Nvidia released patches addressing dozens of security vulnerabilities across their products, including critical flaws that could lead to code execution and data breaches. Nvidia released four advisories focusin… SecurityWeek · 4d ago High vulnerabilitysecurityai
threat-intel Spyware for Babies A growing trend of surveillance technology targeting babies is raising serious privacy concerns. Companies like Nanit are collecting vast amounts of biometric and behavioral data, utilizing AI to monitor development and… Schneier on Security · 4d ago Medium privacysurveillanceai