threat-intel IT department put sticky notes on the laptops to help employees log in This article is a collection of security-related news snippets from The Register. It covers a range of topics including a phishing campaign mimicking Signal support, a zero-day exploit targeting on-prem SharePoint, and a… The Register · Aug 6, 2026 Medium CHIRSWphishingzero-dayransomware
phishing ISC Stormcast For Thursday, August 6th, 2026 https://isc.sans.edu/podcastdetail/10040, (Thu, Aug 6th) The ISC Stormcast highlighted a significant increase in BEC (Business Email Compromise) attacks targeting the legal sector, driven by a sophisticated phishing campaign leveraging leaked LinkedIn data. Attackers are imper… SANS Internet Storm Center · Aug 6, 2026 High becphishingwire transfer
threat-intel Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Graham Cluley recounts a bizarre experience where he was contacted by someone posing as a police detective investigating a cybercrime. The individual claimed to have evidence suggesting they possessed a 24-word seed key… Graham Cluley · Aug 5, 2026 High cryptocurrencyhardware walletphishing
threat-intel Prompt injection isn't the bug, AI agent frameworks are This article discusses the increasing risk of prompt injection attacks within AI agent frameworks, rather than the models themselves. The rise of open-source AI models, particularly from China, is prompting a reaction fr… The Register · Aug 5, 2026 Medium CHIRUSprompt injectionaillm
threat-intel Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk Kali365 is leveraging a sophisticated phishing kit to compromise US organizations by abusing legitimate Microsoft authentication flows. The kit uses attacker-controlled device codes to trick users into approving access o… The Hacker News · Aug 5, 2026 High USphishingauthenticationmicrosoft
threat-intel ISC Stormcast For Wednesday, August 5th, 2026 https://isc.sans.edu/podcastdetail/10038, (Wed, Aug 5th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions and a concerning trend of sophisticated phishing attacks leveraging leaked credentials. The report emphas… SANS Internet Storm Center · Aug 5, 2026 High phishingcredential-stuffingbec
threat-intel Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook The Smoke#Screen campaign is a sophisticated social engineering attack leveraging legitimate Remote Monitoring and Management (RMM) tools, specifically ScreenConnect, to gain persistent remote access to compromised netwo… Dark Reading · Aug 4, 2026 High social engineeringremote managementphishing
threat-intel Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens The Greatness PhaaS toolkit, a commercial phishing-as-a-service platform, has added device code phishing capabilities, a significant advancement that allows attackers to bypass Multi-Factor Authentication (MFA) and steal… The Hacker News · Aug 4, 2026 High phishingdevice-code-phishingmfa
threat-intel This one time, at Hacker Summer Camp … This article covers a range of cybersecurity and technology news, including a Chinese AI model release, vulnerabilities in Joomla extensions, a Russian phishing campaign mimicking Signal support, and a significant acquis… The Register · Aug 4, 2026 Medium CHIRairansomwarephishing
threat-intel AI helps Microsoft bug hunters chase a record $20M payday Microsoft security researchers are experiencing a surge in zero-day attacks targeting on-prem SharePoint, fueled by a new wave of exploits leveraging vulnerabilities in third-party extensions. Simultaneously, Chinese act… The Register · Aug 4, 2026 High CHzero-dayphishingcybersecurity
threat-intel Weaponized Email AI Assistants Could Help Attackers Hijack Accounts Attackers are leveraging compromised email accounts and their built-in AI assistants to bypass security measures and conduct sophisticated phishing attacks against executives. By using the AI assistant to gather informat… SecurityWeek · Aug 4, 2026 High phishingaiemail
threat-intel Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access A multi-wave campaign leveraging social engineering to deploy Remote Monitoring and Management (RMM) software, specifically ScreenConnect, is actively targeting users with fake Adobe and Zoom updates, as well as business… The Hacker News · Aug 4, 2026 High phishingmalwaresupply-chain
threat-intel Tennessee congressional hopeful accused of shooting license plate cameras Several AI and open-source model developments are occurring, including Alibaba's release of its Qwen model and competition in the AI space. Simultaneously, security concerns are rising, with reports of phishing attacks i… The Register · Aug 4, 2026 Medium CHIRaiopen-sourcephishing
threat-intel How legitimate cloud platforms enable phishers to bypass MFA Threat actors are increasingly leveraging legitimate cloud platforms – like Cloudflare, Vercel, Netlify, and GitHub Pages – to conduct sophisticated phishing attacks. These attacks utilize multi-stage adversary-in-the-mi… Securelist · Aug 4, 2026 High phishingaitmbitb
threat-intel CAF Bank reopens online service but warns of further outages This article is a collection of cybersecurity and technology news snippets. It covers a range of topics including a phishing campaign mimicking Signal support, a vulnerability impacting Joomla extensions, and a new X11 s… The Register · Aug 4, 2026 Medium CHIRphishingvulnerabilitycybersecurity
threat-intel Fake IRS letters target cryptocurrency holders Scammers are impersonating the IRS to trick cryptocurrency holders into visiting fake websites designed to steal their personal information and digital assets. The IRS does not operate a Digital Asset Compliance Portal,… Graham Cluley · Aug 4, 2026 High HOROphishingcryptocurrencyfraud
threat-intel Device Code Phishing Up 1,500% in 2026; Vishing Doubles Device code phishing and vishing are experiencing a dramatic surge, driven by state-sponsored and cybercriminal groups, and are proving highly effective at bypassing traditional security measures. CrowdStrike reports a 1… Dark Reading · Aug 4, 2026 High USRUEUphishingvishingdevice-code-phishing
threat-intel AI slop pollutes the CVE pipeline with fake vulns This article covers a range of cybersecurity and technology news, including a report on fake vulnerabilities polluting the CVE pipeline due to AI, a phishing campaign impersonating Signal support, and a discussion of var… The Register · Aug 3, 2026 Medium CHUKvulnerabilityphishingransomware
threat-intel Russian spies turn public Wi-Fi into malware delivery systems Russian state actors are leveraging public Wi-Fi networks to deliver malware to victims, specifically by impersonating Signal support to launch phishing attacks. This tactic is part of a broader trend of Russian intellig… The Register · Aug 3, 2026 High RUIRphishingmalwarerussian
threat-intel Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict Multiple US water systems, including those in Georgia and Michigan, are experiencing cyberattacks, potentially linked to the ongoing US-Iran conflict. These attacks are targeting critical infrastructure, raising serious… The Register · Aug 3, 2026 High IRUScyberattackcritical infrastructurewater systems