threat-intel Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation Anthropic’s Claude Mythos AI model has demonstrated the ability to rapidly generate working exploits for known vulnerabilities in software like Firefox and Windows, significantly accelerating the attack process. The mode… SecurityWeek · Jun 9, 2026 High USaiexploitationn-day
malware Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models Researchers at the University of Toronto have developed a novel AI-driven computer worm that operates autonomously by leveraging locally hosted, open-weight large language models. The worm dynamically generates attack st… The Hacker News · Jun 9, 2026 Critical CVE-2026-39987CVE-2026-31431CVE-2026-43284GBaiwormllm
threat-intel Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks The Silent Ransom group is conducting a targeted extortion campaign against US law firms, utilizing a sophisticated multi-stage attack chain involving vishing, IT impersonation, and physical intrusions. Google’s Mandiant… Dark Reading · Jun 8, 2026 High USvishingsocial engineeringremote access
other Hands on with Intelligent Terminal, an AI-powered Windows Terminal Microsoft has released Intelligent Terminal, an open-source extension for Windows Terminal that integrates AI assistance directly into the terminal environment. The tool leverages various AI models, such as GitHub Copilo… BleepingComputer · Jun 7, 2026 Low aiwindowsterminal
threat-intel New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework A new threat cluster, OP-512, is targeting Microsoft IIS servers with a custom web shell framework, exhibiting sophisticated evasion techniques and centralized management capabilities. ReliaQuest has linked the activity… The Hacker News · Jun 5, 2026 High CNiisweb shellespionage
apt Pakistan Spies on Afghan Finance Ministry With Xeno RAT A Pakistani advanced persistent threat (APT) group, identified as SideCopy and linked to the Transparent Tribe (APT 36), has been conducting espionage against Afghanistan's finance ministry since at least May 2025. The g… Dark Reading · Jun 4, 2026 High AFPKspear-phishingremote-accesspashto
threat-intel Attackers Use AI to Automate EDR Evasion Testing Attackers are leveraging artificial intelligence to automate the process of testing and developing malware designed to evade endpoint detection and response (EDR) systems. Sophos researchers discovered a sophisticated re… Dark Reading · Jun 3, 2026 High aiedrred teaming
malware Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT A new malspam campaign is leveraging Google's DoubleClick domain to deliver the DesckVB RAT, a .NET-based remote access trojan. The campaign’s scalability and cost-effectiveness stem from its ability to dynamically perso… The Hacker News · Jun 3, 2026 High USmalspamratdoubleclick
threat-intel Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash This article reports on a controversy between Microsoft and a security researcher, known as Nightmare Eclipse, regarding the disclosure of several zero-day vulnerabilities affecting Microsoft products. Microsoft initiall… SecurityWeek · Jun 3, 2026 High CVE-2026-41091CVE-2026-45498CVE-2026-33825USzero-dayvulnerability disclosurelegal action
malware Argamal: Malware hidden in hentai games A new malware campaign, dubbed "Argamal," is targeting users of hentai games. The campaign involves injecting a malicious implant into legitimate game files, leveraging COM hijacking to establish persistence and achieve… Securelist · Jun 3, 2026 High UShentaicom hijackingpersistence
threat-intel Microsoft's Coreutils project brings Linux commands to Windows Microsoft has released Coreutils for Windows, a project bringing commonly used Linux command-line utilities to Windows as native applications. Based on the uutils open-source project, this aims to simplify development wo… BleepingComputer · Jun 2, 2026 Low linuxwindowscommand-line
vulnerability Microsoft Threatening Security Researcher A security researcher known as "Nightmare Eclipse" has been publicly disclosing a series of critical vulnerabilities within Microsoft Windows, including a breach of BitLocker encryption. In response, Microsoft has issued… Schneier on Security · Jun 2, 2026 High securityexploitbitlocker
threat-intel Microsoft's Zero-Day Legal Threats Spark Backlash This article reports on Microsoft's controversial response to a security researcher, "Nightmare-Eclipse," who published several zero-day exploits. Microsoft initially threatened criminal charges against the researcher an… Dark Reading · Jun 1, 2026 High CVE-2026-33825zero-dayvulnerabilityresearcher
threat-intel Critical Windows Netlogon RCE flaw now exploited in attacks A critical Remote Code Execution (RCE) vulnerability (CVE-2026-41089) in Windows Netlogon is now being actively exploited in attacks, according to Belgium's national cybersecurity authority, the Centre for Cybersecurity… BleepingComputer · Jun 1, 2026 Critical CVE-2026-41089CVE-2026-45585CVE-2026-33825BErcenetlogonwindows
threat-intel Microsoft says it will not pursue security researchers after zero-day backlash Microsoft retracted a controversial blog post condemning security researchers who disclose zero-day vulnerabilities, stating it has no intention to pursue legal action against them. The initial statement, perceived as a… The Record · Jun 1, 2026 Medium UKzero-dayvulnerabilityresponsible disclosure
threat-intel China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan A new cyber espionage campaign, dubbed Operation Dragon Weave, is targeting government, research, and financial institutions in the Czech Republic and Taiwan using spear-phishing emails and a Rust-based loader to deploy… The Hacker News · Jun 1, 2026 High CZTWINspear-phishingc2azure
threat-intel Microsoft calls zero-day releases ‘never justifiable’ as researcher threatens to drop more Microsoft is responding to a weeks-long campaign by a pseudonymous researcher, ‘Nightmare Eclipse,’ who released uncoordinated zero-day vulnerabilities in Windows. The researcher, motivated by grievances against Microsof… The Record · May 29, 2026 High zero-dayvulnerabilitydisclosure
threat-intel New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks A new, Russian-linked cyber threat group, dubbed GREYVIBE, has been targeting Ukraine and related entities since August 2025 with a range of sophisticated attacks. The group utilizes multiple attack vectors, including ph… The Hacker News · May 29, 2026 High RUrussianaigenai
threat-intel GreyVibe hackers use ChatGPT, Gemini to power cyberattacks GreyVibe, a threat actor likely linked to Russia, has been conducting cyber espionage campaigns targeting Ukrainian organizations since August 2025, utilizing a diverse range of custom malware and AI-generated lures. The… BleepingComputer · May 28, 2026 High RUUKaiphishingmalware
threat-intel Dutch Raid Fails to Dent Russian Bulletproof Host A Dutch law enforcement operation targeting THE.Hosting, a bulletproof hosting network linked to Russian cybercrime, resulted in the seizure of 800 servers and arrests of two operators but failed to significantly disrupt… Dark Reading · May 28, 2026 High NLRUDKbulletproof hostingcybercrimesanctions evasion