threat-intel Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks A former ransomware negotiator, Angelo Martino, has been sentenced to 70 months in prison for betraying five victims and providing BlackCat ransomware operators with confidential information, allowing them to demand high… The Hacker News · Jul 10, 2026 High USransomwarenegotiatorcollusion
vulnerability Microsoft Reins in RoguePlanet Zero-Day Threat A disgruntled security researcher, known as "Nightmare-Eclipse," published a proof-of-concept exploit (RoguePlanet) for a Windows Defender vulnerability, leading Microsoft to issue an out-of-band patch. The vulnerability… Dark Reading · Jul 9, 2026 High CVE-2026-50656CVE-2026-33825zero-dayprivilege-escalationmicrosoft
vulnerability WolfSSL, GeoVision, VTK vulnerabilities Cisco Talos has disclosed a significant number of vulnerabilities across WolfSSL, GeoVision, and VTK-DICOM. These vulnerabilities range from buffer overflows and command injection to session cookie issues and heap overfl… Cisco Talos · Jul 9, 2026 Medium CVE-2026-28739CVE-2026-25106CVE-2026-33091buffer_overflowcommand_injectioncve
threat-intel QIZ Security Raises $17 Million for Cryptographic Governance Platform Israeli cybersecurity startup QIZ Security secured $17 million in seed funding to bolster its cryptographic governance platform, addressing the growing threat of quantum computing and the need for continuous cryptographi… SecurityWeek · Jul 9, 2026 Medium IScryptographypost-quantumquantum computing
threat-intel AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up AI-powered attacks are now executing significantly faster, requiring security teams to adapt their defenses. This article details a new attack methodology leveraging AI models like Mythos, highlighting the need for a shi… The Hacker News · Jul 9, 2026 High aiattackthreat
threat-intel EU unveils cyber plan to reduce reliance on foreign AI systems The European Commission has unveiled a cybersecurity and AI action plan aimed at reducing the EU’s reliance on foreign AI systems, particularly concerning access to ‘frontier’ AI models. The plan focuses on ensuring cybe… The Record · Jul 8, 2026 Medium EUUKaicybersecurityfrontier ai
threat-intel Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security Keyfactor, a cybersecurity firm specializing in cryptographic security and machine identity management, has secured over $1 billion in investment to bolster its growth and address the increasing need for post-quantum cry… SecurityWeek · Jul 7, 2026 Medium machine identitiespost-quantumcryptography
threat-intel BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA BeyondTrust has released patches to address critical security vulnerabilities in its Remote Support and Privileged Remote Access products. These flaws, if exploited, could allow unauthenticated attackers to gain unauthor… The Hacker News · Jul 7, 2026 Critical CVE-2026-40138CVE-2026-40139CVE-2026-40140vulnerabilityauthenticationremote access
threat-intel New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS A new Java-based remote access trojan (RAT) called QuimaRAT, offered as a malware-as-a-service (MaaS), has been released by a threat actor. The tool is cross-platform, supporting Windows, Linux, and macOS, and is adverti… The Hacker News · Jul 6, 2026 High javaratmalware-as-a-service
malware New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos A new remote access trojan (RAT) called ChocoPoC is targeting vulnerability researchers through deceptive proof-of-concept (PoC) repositories on GitHub. The malware, disguised within Python dependencies, steals sensitive… The Hacker News · Jul 2, 2026 High CVE-2025-64446CVE-2025-55182CVE-2025-14847KRproof-of-conceptremote access trojangithub
vulnerability Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack? This article discusses a security vulnerability discovered in Fortinet’s FortiBleed, a tool designed to securely dispose of sensitive data. A researcher identified a flaw allowing unauthorized access to sensitive data, h… Graham Cluley · Jul 1, 2026 High vulnerabilityfortinetsecurity
threat-intel US lifts export controls on Anthropic’s frontier cybersecurity AI models The U.S. government has lifted export controls on Anthropic’s Fable 5 and Mythos 5 cybersecurity AI models following a ‘jailbreak’ exploit discovered in Fable 5. This marks the first instance of export controls being app… The Record · Jul 1, 2026 Medium USCHaijailbreakexport controls
threat-intel ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More This week’s security news highlights several concerning vulnerabilities and attacks, including a DirtyClone Linux kernel flaw, exploitation of PTC Windchill vulnerabilities, and the emergence of new malware like Gaslight… The Hacker News · Jun 29, 2026 High CVE-2026-43503CVE-2026-12569CVE-2026-47729UKRUlinuxkernelai
threat-intel OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review This article reports on a significant shift in the release strategy of AI models ChatGPT and Anthropic’s Claude, driven by a government-led cybersecurity review initiated by the Trump administration. OpenAI is restrictin… SecurityWeek · Jun 29, 2026 High USaicybersecuritygovernment
phishing Cybersecurity firms targeted by fraudulent OpenAI organization invites Cybersecurity firms are being targeted by a sophisticated phishing campaign where attackers create fraudulent OpenAI organizations, mimicking legitimate companies and inviting employees to join them. These invitations, a… BleepingComputer · Jun 26, 2026 Medium phishingopenaicredential_harvesting
threat-intel ESET takes part in Operation Endgame to disrupt Amadey and Stealc ESET, in collaboration with Microsoft DCU and other partners, successfully disrupted the Amadey and Stealc botnets as part of Operation Endgame. These botnets, sold as a service on darknet forums, utilize a MaaS model wh… WeLiveSecurity · Jun 24, 2026 High maasbotnetdarknet
data-breach Scope of Salesforce Attacks Expands as Icarus Leaks Data A series of attacks originating from the Icarus extortion group have expanded the scope of breaches affecting Salesforce customers. Initially targeting Klue’s OAuth tokens, attackers leveraged this access to steal custom… Dark Reading · Jun 23, 2026 High USsalesforceoauthdata breach
threat-intel ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More This week’s cybersecurity news highlights a significant Fortinet vulnerability dubbed ‘FortiBleed,’ where over 80,000 FortiGate devices have been compromised by suspected Russian-speaking threat actors. Simultaneously, t… The Hacker News · Jun 22, 2026 Critical CVE-2026-24858CVE-2025-59718CVE-2025-59719RUcredential_reuseedrransomware
threat-intel Anthropic’s Fable and the State of AI Anthropic’s Fable AI model, designed to identify vulnerabilities in code, has sparked concern due to its capabilities and the potential for misuse. The US government classified it as a dangerous munition and restricted a… Schneier on Security · Jun 19, 2026 High UKUSCZaivulnerabilitycybersecurity
ransomware Killing me gently: Inside Gentlemen’s EDR killer framework The Gentlemen ransomware-as-a-service (RaaS) gang has emerged as a significant and technically agile threat, distinguished by its proactive development and maintenance of a comprehensive suite of Endpoint Detection and R… WeLiveSecurity · Jun 18, 2026 High THBRFRransomwareedrrd