vulnerability ISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th) The ISC Stormcast highlighted a significant vulnerability in Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise across various industri… SANS Internet Storm Center · Jul 13, 2026 High activemqvulnerabilitydeserialization
threat-intel Cybercriminals Flock to Healthcare Businesses as Attacks Surge Cyberattacks on healthcare businesses, including service providers supporting hospitals, have surged dramatically, nearly doubling in the past year and significantly outpacing attacks on hospitals themselves. This trend… Dark Reading · Jul 10, 2026 High USGEransomwarecyberattackhealthcare
threat-intel Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers Okta has warned of a sophisticated vishing campaign targeting Microsoft 365 customers, primarily through impersonating legitimate Microsoft Entra ID login pages. The campaign, attributed to the O-UNC-066 threat actor gro… SecurityWeek · Jul 10, 2026 High vishingpasskeyphishing
threat-intel Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access A threat actor, linked to the O-UNC-066 group (affiliated with The Com/Scattered Spider), is using a sophisticated, operator-controlled phishing kit to trick users into enrolling fake Microsoft Entra passkeys, gaining un… The Hacker News · Jul 10, 2026 High passkeyphishingvishing
vulnerability WolfSSL, GeoVision, VTK vulnerabilities Cisco Talos has disclosed a significant number of vulnerabilities across WolfSSL, GeoVision, and VTK-DICOM. These vulnerabilities range from buffer overflows and command injection to session cookie issues and heap overfl… Cisco Talos · Jul 9, 2026 Medium CVE-2026-28739CVE-2026-25106CVE-2026-33091buffer_overflowcommand_injectioncve
threat-intel EU takes member states to court over unimplemented cybersecurity law The European Commission has filed legal action against Ireland, Spain, France, and the Netherlands for failing to implement the NIS2 Directive, a cybersecurity law designed to improve security for critical infrastructure… The Record · Jul 9, 2026 Medium IEESFRcybersecurityeu lawcritical infrastructure
threat-intel 'GodDamn' Ransomware Uses BYOVD to Smite US Companies The ransomware group Hyadina, operating under the name "GodDamn," is leveraging a Microsoft-approved, malicious kernel driver – dubbed "PoisonX" – to infiltrate US organizations and deploy its ransomware. They utilize a… Dark Reading · Jul 9, 2026 High RUransomwaredriverbyovd
vulnerability Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations A vulnerability in Google Cloud’s Dialogflow CX service allowed attackers to silently control agents, manipulate conversations, and exfiltrate sensitive information. The flaw stemmed from a permissive configuration withi… SecurityWeek · Jul 8, 2026 High aicloudpython
threat-intel Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft Google has patched a critical vulnerability in its Dialogflow CX AI chatbot platform, dubbed 'Rogue Agent,' which could have allowed attackers to steal data from AI agents. The flaw stemmed from a permission boundary iss… Dark Reading · Jul 7, 2026 High aichatbotcodeblocks
data-breach Major medical device manufacturer notifies nearly 4 million of breach Medtronic, a leading medical device manufacturer, has notified nearly 4 million individuals that their data may have been compromised in a cyberattack. The breach was linked to the ShinyHunters cybercrime group and resul… The Record · Jul 6, 2026 High data breachcybersecuritymedical devices
threat-intel Launch of UK's National Cyber Action Plan delayed amid Labour leadership crisis The UK’s National Cyber Action Plan, intended to bolster the nation’s defenses against cyber threats, has been delayed again due to ongoing political instability within the Labour Party following Prime Minister Keir Star… The Record · Jul 2, 2026 High UKcybersecurityukpolitical delay
ransomware Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials The Anubis ransomware group, a rebranded version of Sphinx, is actively exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to gain initial access to victim networks. They leverage legitimate RMM tools like Scree… The Hacker News · Jul 2, 2026 High CVE-2025-5777USUKAUcitrixbleedransomware-as-a-servicecredential theft
ransomware The Gentlemen ransomware: what you need to know The Gentlemen ransomware group is a sophisticated and aggressive cybercriminal operation, despite its seemingly formal name. They are known for deploying double extortion tactics, stealing data and threatening to leak it… Graham Cluley · Jul 2, 2026 High ransomwaredouble extortioncybercrime
threat-intel Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. This article reports on a significant investment by IBM and Red Hat into Project Lightwell, a new service designed to address the growing challenge of securing open-source software supply chains. Driven by Anthropic's My… Dark Reading · Jul 2, 2026 High USaivulnerabilityopen source
threat-intel 19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges This article reports the extradition of a 19-year-old, Peter Stokes, known as "Bouquet," from Finland to the United States to face charges related to computer intrusion, fraud, and conspiracy as part of the Scattered Spi… The Hacker News · Jul 1, 2026 High USFIUKsocial engineeringphishinghelp desk
threat-intel Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware This article details a new phishing and malware tactic called "phantom squatting," where large language models (LLMs) generate non-existent domain names that attackers quickly register and use to host malicious content.… The Hacker News · Jul 1, 2026 High USUAEUllmphishingdomain squatting
phishing ISC Stormcast For Wednesday, July 1st, 2026 https://isc.sans.edu/podcastdetail/9990, (Wed, Jul 1st) The SANS Internet Storm Center's July 1st, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The broadcast highlighted several emerging tr… SANS Internet Storm Center · Jul 1, 2026 Medium phishingemailbotnet
threat-intel 282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study Researchers at Wake Forest University discovered that nearly two-thirds (282 out of 444) of AI chatbot apps for iOS exposed API keys and open access to AI proxy services through network traffic. This vulnerability, dubbe… The Hacker News · Jun 30, 2026 High USapiaiiot
vulnerability OFFIS DCMTK Toolkit This CISA advisory details vulnerabilities within the OFFIS DCMTK Toolkit (<=3.7.0) that could allow an attacker to perform actions like file writing, unauthorized data access, memory exhaustion, and system crashes. The… CISA Advisories · Jun 30, 2026 High CVE-2026-50003CVE-2026-50254CVE-2026-35505DEpath traversalmemory leakcve-2026-50003
threat-intel Inside the inbox: Why cybercriminals want to break into your email account Cybercriminals are increasingly targeting email accounts due to the wealth of personal and business information contained within them, including access to other accounts and potential blackmail material. Phishing attacks… WeLiveSecurity · Jun 29, 2026 High phishingsocial engineeringbec