threat-intel ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More This week’s security recap highlighted several concerning trends, including a disruption of the NetNut residential proxy network used for botnet operations, a fake Proof-of-Concept (PoC) malware targeting vulnerability r… The Hacker News · Jul 6, 2026 High CVE-2026-48276CVE-2026-48283CVE-2026-48277USESSPbotnetproxymalware
threat-intel SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing Researchers at the Hong Kong University of Science and Technology have developed a method to bypass AI coding agent scanners by using self-extracting packing and character substitution to disguise malicious skills. Their… The Hacker News · Jul 6, 2026 High aiskillsmalware
threat-intel North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign North Korean threat actors, linked to the Contagious Interview campaign, have been publishing 108 malicious packages and extensions across platforms like npm, Packagist, and Go, as part of the PolinRider operation. This… The Hacker News · Jul 4, 2026 High KPnorth koreangithubmalware
threat-intel In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting This report details several significant cybersecurity events across multiple sectors, including a Canadian hacker’s imprisonment for a Texas GOP cyberattack, a large KDDI data breach impacting 14 million users, and the d… SecurityWeek · Jul 3, 2026 High CAJAUNzero-dayhacktivismdata breach
phishing Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS This article details a concerning trend in phishing attacks where threat actors are leveraging user-agent data to dynamically adapt their campaigns to the specific device and operating system of the victim. Attackers are… Dark Reading · Jul 1, 2026 High USphishinguser-agentmalware
threat-intel Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware This article details a new phishing and malware tactic called "phantom squatting," where large language models (LLMs) generate non-existent domain names that attackers quickly register and use to host malicious content.… The Hacker News · Jul 1, 2026 High USUAEUllmphishingdomain squatting
malware Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery This report details a concerning trend in malware delivery – the evolution of ClickFix, a technique where users are tricked into running malicious code by hand. Researchers have uncovered a new API-driven approach to gen… The Hacker News · Jul 1, 2026 High RUIRNOmalwarepayloadapi
threat-intel Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer An attacker exploited a critical vulnerability (CVE-2026-48558) in SimpleHelp’s OpenID Connect (OIDC) flow to deploy the TaskWeaver and Djinn Stealer malware. This allowed for unauthorized access to authenticated ‘Techni… The Hacker News · Jun 30, 2026 Critical CVE-2026-48558USoidccredential theftai
malware USB drives carrying China-linked malware infected Japanese military networks for nearly a year Japanese military networks, specifically the Ground Self-Defense Force (JGSDF), were compromised by a year-long campaign utilizing counterfeit USB drives loaded with malware. The incident, discovered in February 2025, in… Graham Cluley · Jun 30, 2026 High JACHusb drivesmalwarejapan
vulnerability Critical SimpleHelp Vulnerability Exploited for Malware Delivery A critical vulnerability (CVE-2026-48558) in SimpleHelp RMM software allowed unauthorized access and subsequent malware deployment. The flaw, related to OpenID Connect authentication, enabled attackers to gain full techn… SecurityWeek · Jun 30, 2026 Critical CVE-2026-48558USoidcauthenticationmalware
threat-intel ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More This week’s security news highlights several concerning vulnerabilities and attacks, including a DirtyClone Linux kernel flaw, exploitation of PTC Windchill vulnerabilities, and the emergence of new malware like Gaslight… The Hacker News · Jun 29, 2026 High CVE-2026-43503CVE-2026-12569CVE-2026-47729UKRUlinuxkernelai
threat-intel Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer A sophisticated cyberattack has been uncovered involving hijacked npm and Go packages designed to deploy a Python-based information stealer. Attackers leveraged a VS Code task trigger to execute malicious code disguised… The Hacker News · Jun 29, 2026 High KPvscodenpmfont-file
threat-intel Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign A Chinese-speaking Advanced Persistent Threat (APT) group, CL-STA-1062, has been actively targeting government entities and critical infrastructure in Southeast Asia since 2022, utilizing a new custom backdoor called Tin… The Hacker News · Jun 26, 2026 High VNaptbackdoorsoutheast asia
apt Turla group adds more malware to Russia’s espionage efforts against Ukraine The Turla group, a long-standing Russian cyber-espionage team, has expanded its operations against Ukraine by deploying a new malware strain called StockStay. This malware, developed since December 2022, targets Ukrainia… The Record · Jun 26, 2026 High UKITNEcyberespionagerussiaukraine
supply-chain Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack A sophisticated supply chain attack, spearheaded by the Miasma malware family (linked to Mini Shai-Hulud and Hades), is targeting npm packages and GitHub Actions workflows. The attackers are leveraging compromised npm pa… The Hacker News · Jun 26, 2026 High RUsupply chainnpmgithub actions
threat-intel Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools This Securelist article details Kaspersky's 2026 threat analysis for small and medium-sized businesses (SMBs), highlighting a significant increase in cyberattacks disguised as artificial intelligence (AI) tools, particul… Securelist · Jun 25, 2026 High USaismbmalware
threat-intel ISC Stormcast For Wednesday, June 24th, 2026 https://isc.sans.edu/podcastdetail/9984, (Wed, Jun 24th) The SANS Internet Storm Center's Stormcast for June 24th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The broadcast detailed ongoing campaigns involving phishing attack… SANS Internet Storm Center · Jun 24, 2026 Medium phishingmalwarethreat-intelligence
threat-intel SocGholish Takedown Highlights Malicious TDS Threats A coordinated international law enforcement operation, part of Operation Endgame, successfully disrupted SocGholish, a decade-old malware framework used as an initial-access broker by cybercriminal groups like Evil Corp.… Dark Reading · Jun 23, 2026 High NLtdssmalwareaffiliate
threat-intel Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries Google is implementing a new Android developer verification system, starting September 30, 2026, in Brazil, Indonesia, Singapore, and Thailand, to combat app scams and malware. This will block installations of apps from… The Hacker News · Jun 22, 2026 Medium BRIDSGapp scamsdeveloper verificationopen source
supply-chain Microsoft links Mastra AI supply chain attack to North Korean hackers Microsoft has attributed a recent supply chain attack targeting over 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. The attack involved compromising an npm maintainer account… BleepingComputer · Jun 20, 2026 High KPsupply-chainnpmcryptocurrency