ransomware AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android A new type of ransomware, dubbed ‘InfernoGrabber v9.0’, has emerged utilizing AI-generated code to exploit vulnerabilities in Chromium-based browsers on Windows and Android. The malware, created using the DeepSeek AI mod… The Hacker News · Jul 1, 2026 High CVE-2023-4863USairansomwarebrowser
threat-intel ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Cisco Talos has identified a new phishing-as-a-service (PhaaS) platform called ARToken, which shares significant similarities with the existing EvilTokens platform operated by Sekoia and tracked by Microsoft. ARToken uti… Cisco Talos · Jul 1, 2026 High USphishingeviltokensreact
threat-intel Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware This article details a new phishing and malware tactic called "phantom squatting," where large language models (LLMs) generate non-existent domain names that attackers quickly register and use to host malicious content.… The Hacker News · Jul 1, 2026 High USUAEUllmphishingdomain squatting
phishing ISC Stormcast For Wednesday, July 1st, 2026 https://isc.sans.edu/podcastdetail/9990, (Wed, Jul 1st) The SANS Internet Storm Center's July 1st, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The broadcast highlighted several emerging tr… SANS Internet Storm Center · Jul 1, 2026 Medium phishingemailbotnet
threat-intel Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Palo Alto Unit 42 researchers have identified a new supply chain threat: "phantom squatting," where large language models (LLMs) hallucinate web domains that adversaries can then register to intercept traffic generated b… Palo Alto Unit 42 · Jul 1, 2026 High USllmaisupply chain
threat-intel Why Identity Security Is Your Cyber Career Entry Point This Dark Reading article, part of their ‘Heard It From a CISO’ video series, discusses the evolving landscape of cybersecurity career entry points. It highlights that while AI is automating certain tasks, human oversigh… Dark Reading · Jun 30, 2026 Medium aicybersecurityidentity security
threat-intel Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data This report details a new security vulnerability impacting AI agent-based systems, specifically leveraging the Model Context Protocol (MCP). Attackers can inject malicious instructions into tool descriptions used by AI a… The Hacker News · Jun 30, 2026 High N/aiagentsupply-chain
threat-intel 282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study Researchers at Wake Forest University discovered that nearly two-thirds (282 out of 444) of AI chatbot apps for iOS exposed API keys and open access to AI proxy services through network traffic. This vulnerability, dubbe… The Hacker News · Jun 30, 2026 High USapiaiiot
threat-intel Vulnerabilities Expose Private Data in Indian Government Systems A security researcher discovered 14 vulnerabilities across multiple Indian government IT systems, including portals for education, civil service, and scholarships. These vulnerabilities exposed sensitive personal data, s… Dark Reading · Jun 29, 2026 High INvulnerabilitydata-breachidentity-access-management
threat-intel Ukraine to use seized crypto from cybercrime group to buy war bonds Ukraine is utilizing cryptocurrency seized from a notorious international cybercrime group to bolster its war effort. Over $8.3 million in digital assets, obtained from investigations targeting attacks across Europe and… The Record · Jun 29, 2026 High UKRUUScybercrimecryptocurrencywar bonds
threat-intel 236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers A report by Infoblox has identified over 236,000 websites utilizing the DCloud Uni-App framework, many of which are being exploited for cryptocurrency scams, phishing attacks, and wallet draining operations. These sites,… The Hacker News · Jun 29, 2026 High ARUSGBscamphishingcrypto
threat-intel Why Post-Quantum Cryptography Starts With Credentials This article discusses the growing threat posed by quantum computing to current encryption methods, particularly public-key cryptography used to protect credentials. The article highlights the ‘Harvest Now, Decrypt Later… The Hacker News · Jun 29, 2026 High USquantum computingcryptographycredentials
threat-intel Inside the inbox: Why cybercriminals want to break into your email account Cybercriminals are increasingly targeting email accounts due to the wealth of personal and business information contained within them, including access to other accounts and potential blackmail material. Phishing attacks… WeLiveSecurity · Jun 29, 2026 High phishingsocial engineeringbec
threat-intel Guardian Agents: The Next Layer of Identity Governance This article discusses the emerging threat of ‘guardian agents’ – AI agents operating autonomously within enterprise environments, inheriting permissions and traversing systems at machine speed. The existing identity gov… The Hacker News · Jun 26, 2026 High aiagentic aiidentity governance
threat-intel SMB cyber readiness: the road to resilience starts here A recent ESET report reveals that while small and medium-sized businesses (SMBs) are increasingly confident in their cybersecurity budgets and preparedness, a significant number still struggle with implementing effective… WeLiveSecurity · Jun 26, 2026 Medium cybersecuritysmbphishing
threat-intel In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw A critical vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager (CUCM) has been rapidly weaponized by attackers within 24 hours of a proof-of-concept release. The SSRF flaw allows unauthenticated remote… Dark Reading · Jun 25, 2026 Critical CVE-2026-20230USssrfprivilege escalationcisco
threat-intel AI and Liability A German court ruled that Google is liable for its AI-generated search summaries, marking a significant shift in how internet publishers are held accountable. The ruling established that AI-generated content, particularl… Schneier on Security · Jun 25, 2026 Medium DEailiabilitygoogle
threat-intel The Four Elevations of Effective Fraud Prevention This article discusses a multi-layered approach to fraud prevention, emphasizing the importance of monitoring across all customer touchpoints – from individual transactions to platform-wide activity. It advocates for col… BleepingComputer · Jun 25, 2026 High fraudaccount-takeoverauthentication
threat-intel When Information Becomes the Attack Surface – Understanding AI Agent Traps This article discusses a new security risk related to AI agents – "traps" – where malicious information can be injected into the data sources an agent uses, leading it to make incorrect decisions or take unintended actio… SecurityWeek · Jun 24, 2026 High aiagentsecurity
ransomware Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered A coordinated international law enforcement operation, involving Bitdefender, Bitsight, ESET, Microsoft, and Europol, successfully disrupted the Amadey and StealC malware networks, recovering 27 million stolen credential… The Hacker News · Jun 24, 2026 High NLCADEmaascredential theftransomware