threat-intel Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows The Mirage2FA campaign, a commercial phishing-as-a-service toolkit, has impacted approximately 4,532 organizations, primarily in the US, by exploiting legitimate Microsoft 365 login flows and bypassing two-factor authent… The Hacker News · 5d ago High USINSGphishingmicrosoftmfa
threat-intel 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Researchers at OX Security discovered a campaign utilizing 24 npm packages to host fake Cloudflare CAPTCHA pages via unpkg mirrors, redirecting users to phishing infrastructure. The threat actors are leveraging npm's inf… The Hacker News · 5d ago High npmphishingmalware
threat-intel E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands Threat actors are utilizing FTP banner responses as dead drop resolvers to deliver two new remote access trojans, E4del and PINHOLE RAT. E4del, a Node.js-based RAT, employs a dynamic beaconing system to blend in with net… The Hacker News · 5d ago High UNdvrftpremote access trojan
threat-intel First Malware Built Specifically for Car Head Units Fuels Botnet Researchers at Kaspersky have identified a new malware specifically designed for car head units, linked to the BadBox botnet. This represents a significant expansion of the BadBox threat, which has previously targeted An… SecurityWeek · 5d ago High CNbotnetmalwaresupply-chain
threat-intel Frontier AI: Vulnerability Management's Systemic Revolution This article discusses how the rapid advancements in Frontier AI models, like those developed by Anthropic, are forcing vulnerability management programs to undergo a significant transformation. Traditional vulnerability… The Hacker News · 5d ago High vulnerability managementfrontier aicybersecurity
threat-intel The safety penalty: Reclaiming operational sovereignty in the age of AI As AI models become more powerful, their built-in safety mechanisms are increasingly causing friction for security teams, leading to a "safety penalty" where analysts are forced to redo work that a model refuses to compl… Cisco Talos · 5d ago High aifrontier-modelsguardrails
threat-intel Silent Patches Don’t Stop Attackers—They Blind Defenders Broadcom’s new program offering early access to CVE-only patches for Spring Framework users is exacerbating the problem of silent patching. While Broadcom continues to issue CVEs, the program effectively provides pre-ale… SecurityWeek · 5d ago High silent patchingvulnerability disclosureai-driven vulnerability
vulnerability Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access Attackers are exploiting two unauthenticated vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing them to gain administrator access to vulnerable sites. The vulnerabilities stem from f… The Hacker News · 5d ago High CVE-2026-61979CVE-2026-15981wordpresssamlauthentication
supply-chain Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff Nine individuals, including employees from Nvidia and Super Micro, have been charged in Taiwan for illegally exporting high-end AI servers to China. These servers, containing banned ‘B300’ GPUs, were part of a scheme to… SecurityWeek · 5d ago High CHTAJAexport controlschinaai
vulnerability Multiples vulnérabilités dans Cisco IOS XE (25 août 2026) Cisco has announced multiple vulnerabilities in its IOS XE software, allowing attackers to bypass security policies and potentially cause unspecified security issues. These vulnerabilities affect several versions of the… CERT-FR · 5d ago High CVE-2026-20267CVE-2026-20268CVE-2026-20269ciscoios xevulnerability
threat-intel US sanctions Iranian cyber actors as UK discloses power plant attack The U.S. has sanctioned several Iranian nationals linked to a hacking operation targeting U.S. critical infrastructure, following a recent cyberattack on a small power plant in the UK. This escalation highlights Iran's c… The Record · 5d ago High IRUNUKcyberattackcritical infrastructureiran
vulnerability Exploited Zimbra Flaw Highlights Shrinking Window to Patch A critical vulnerability in Zimbra Unified Communications Suite (ZCS) is being aggressively exploited, prompting CISA to issue a three-day deadline for federal agencies to patch. The flaw, CVE-2026-73570, allows unauthen… Dark Reading · 6d ago High CVE-2026-73570CVE-2026-73750CVE-2025-66376PORULIpatchingvulnerabilityremote code execution
threat-intel You don't want this Sleepwalker backdoor on your Windows machine A previously unknown backdoor, dubbed ‘Sleepwalker,’ has been discovered in Nvidia’s drivers for Windows machines. This backdoor allows attackers to remotely execute code on vulnerable systems, potentially leading to ful… The Register · 6d ago High backdoorvulnerabilitynvidia
threat-intel Foul Language: WordlistLoader Disguises Malware as Ordinary Text A new malware loader called WordlistLoader is being used to deliver the Amatera infostealer, primarily through ClickFix-style campaigns. WordlistLoader disguises malicious code using lists of ordinary English words, allo… Dark Reading · 6d ago High malwareloaderinfostealer
threat-intel Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly An Indian man, Jay Sunilbharthi Goswami, has been arrested on charges of aiding overseas cyberscammers who defrauded elderly New Yorkers out of $7.5 million. Goswami acted as a money mule, receiving instructions and tran… The Record · 6d ago High INCAUSmoney mulescamcybercrime
threat-intel Iran-linked cyberattack shut down a UK power plant A cyberattack linked to Iran has successfully taken down a UK power plant control system. The attack exploited vulnerabilities in the system, allowing attackers to gain unauthorized access and disrupt operations. This hi… The Register · 6d ago High UKIRcyberattackcritical infrastructureiran
threat-intel Tricky 'SynkLoader' Multitool May Herald Ransomware A sophisticated new malware family, dubbed ‘SynkLoader,’ is making a comeback of older, effective tactics, including screen locking and phishing, to facilitate ransomware attacks. The malware utilizes a combination of no… Dark Reading · 6d ago High phishingransomwarescreen-locking
threat-intel Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials A campaign of malicious Firefox add-ons, dubbed the "Offside Wallet Theft Factory", has been quietly stealing cryptocurrency wallet seed phrases and browser credentials since March 2026. Researchers identified 40 out of… Graham Cluley · 6d ago High browsercryptomalware
threat-intel ToxicPanda Banking Trojan Matures into Enterprise Threat ToxicPanda, a banking Trojan, has evolved into a more sophisticated enterprise threat, expanding its reach beyond individual banking apps to compromise entire Android devices and potentially access corporate resources. T… Dark Reading · 6d ago High LAITPObankingmobileenterprise
threat-intel ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More This week saw a surge in high-impact cyberattacks and vulnerabilities, highlighting the increasing sophistication and speed of threat actors. AI is now being weaponized to craft exploit scripts targeting Siemens PLCs, wh… The Hacker News · 6d ago High CVE-2026-19478CVE-2021-27101CVE-2023-34362UNRUvulnerabilitysupply-chainransomware