threat-intel ISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Jul 15, 2026 Medium phishingvulnerabilityemail
vulnerability CISA Urges SharePoint Hardening After New Exploitations The Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations with on-premises SharePoint Server instances (versions 2016, 2019, and Subscription Edition) about active exploitation of vulnerabiliti… CISA Advisories · Jul 14, 2026 High CVE-2026-32201CVE-2026-45659CVE-2026-56164sharepointvulnerabilityiis
threat-intel Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks Researchers at KU Leuven discovered significant privacy vulnerabilities in 85 popular crypto wallet extensions running as browser extensions. These wallets leak address information, allowing trackers to link separate wal… The Hacker News · Jul 14, 2026 High privacycryptowallet
vulnerability SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud SAP released 19 security patches on July 26th, 2026, addressing critical vulnerabilities across several of its flagship products, including NetWeaver, Approuter, and Commerce Cloud. The most severe vulnerability, CVE-202… SecurityWeek · Jul 14, 2026 Critical CVE-2026-44747CVE-2026-27690CVE-2026-44761sapvulnerabilitypatch
threat-intel Valarian Raises $50 Million for Sovereign Infrastructure Control Layer Valarian, a UK-based company focused on sovereign infrastructure control, has secured $50 million in Series A funding to bolster its platform, ACRA. ACRA is designed to provide a layer of control and governance for AI mo… SecurityWeek · Jul 14, 2026 Medium UKsovereigntydata-controlkubernetes
vulnerability ISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th) The ISC Stormcast highlighted a significant vulnerability in Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise across various industri… SANS Internet Storm Center · Jul 13, 2026 High activemqvulnerabilitydeserialization
vulnerability Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched Researchers at Ledger's Donjon security team have discovered a method to bypass the password protection on Tangem crypto wallet cards using a precisely timed laser pulse. The attack requires physical access to the card a… The Hacker News · Jul 10, 2026 High hardware walletlaser attackfirmware
threat-intel ISC Stormcast For Friday, July 10th, 2026 https://isc.sans.edu/podcastdetail/10002, (Fri, Jul 10th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in widely used communication… SANS Internet Storm Center · Jul 10, 2026 High phishingvulnerabilityslack
threat-intel ISC Stormcast For Thursday, July 9th, 2026 https://isc.sans.edu/podcastdetail/10000, (Thu, Jul 9th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging a newly discovered phishing technique that bypasses traditional email security filters. The c… SANS Internet Storm Center · Jul 9, 2026 Critical USphishingzero-dayransomware
threat-intel SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users A new banking fraud operation, tracked as REF6045, is targeting Mexican banks, fintech companies, and cryptocurrency exchanges using a malware toolset called SCMBANKER. The operation leverages fake CAPTCHA verification p… The Hacker News · Jul 8, 2026 High MXbankingmalwarephishing
threat-intel RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service A new Android malware operation, RedWing, is being sold on Telegram as a ready-made bank fraud service. Developed by a Russian threat actor group, RedWing allows even unskilled criminals to steal banking logins and one-t… The Hacker News · Jul 7, 2026 High RUandroidmalwarefraud
threat-intel DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts A Microsoft 365 device code phishing campaign, leveraging collaboration-themed lures, has been observed targeting M365 accounts. The campaign, utilizing a reusable tooling layer called DEBULL, bypasses multi-factor authe… The Hacker News · Jul 7, 2026 High HRTRdevice-codephishingmicrosoft
vulnerability CitrixBleed-ing Again? NetScaler Vulnerability Under Attack A vulnerability in Citrix's NetScaler products has quickly been exploited by attackers following the release of a proof-of-concept exploit. The flaw allows attackers to potentially gain unauthorized access to systems, hi… Dark Reading · Jul 6, 2026 High memory-disclosurecitrixvulnerability
threat-intel Attackers vote themselves $20 million in BONK cryptocurrency Attackers exploited a governance mechanism within the decentralized finance project overseeing BONK cryptocurrency, draining $20 million worth of the token. This was achieved through a malicious governance proposal, leve… The Record · Jul 6, 2026 High KRdaogovernancecryptocurrency
apt Armored Likho APT Targeting Government, Electric Power Entities The Armored Likho APT group is actively targeting government and electric power entities across multiple countries, including Russia, Brazil, and Kazakhstan. The group utilizes a diverse toolkit of malware, including RAT… SecurityWeek · Jul 6, 2026 High RUBRKZaptspear-phishingrat
threat-intel Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments Threat actors are exploiting prompt injection vulnerabilities in AI agents to trick them into making cryptocurrency payments and promoting fraudulent platforms. Zscaler identified two campaigns utilizing SEO poisoning an… SecurityWeek · Jul 6, 2026 Medium prompt-injectionaicybersecurity
threat-intel Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT A China-nexus threat actor is conducting a targeted phishing campaign against Indian taxpayers and tax professionals, leveraging fake tax filing utilities to deploy a remote access trojan (DcRAT). The campaign, dubbed Op… The Hacker News · Jul 6, 2026 High CHINphishingremote access trojantax
threat-intel U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case A U.S. government entity reportedly paid $1 million to the group known as Kairos to prevent the leak of stolen data following a data breach at Union County, Ohio. Kairos, however, operated solely through data theft extor… The Hacker News · Jul 4, 2026 High USRUdatatheftextortionnegotiation
threat-intel Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. This article reports on a significant investment by IBM and Red Hat into Project Lightwell, a new service designed to address the growing challenge of securing open-source software supply chains. Driven by Anthropic's My… Dark Reading · Jul 2, 2026 High USaivulnerabilityopen source
malware Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures The Ousaban banking trojan, originating in Brazil and previously tracked as Javali, is targeting Windows users in Spain and Portugal with a phishing campaign utilizing fake PDF lures. The trojan, which has evolved over t… The Hacker News · Jul 1, 2026 High PTESbanking trojanphishinggeofencing