threat-intel 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May. These packages, initially designed as tutoring tools, lo… The Hacker News · Jul 14, 2026 High USbotnetddosproxy
threat-intel CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks A new macOS information stealer, CrashStealer, is utilizing a sophisticated delivery chain involving a notarized dropper to bypass Gatekeeper and silently collect sensitive data from users. The malware, implemented in na… The Hacker News · Jul 13, 2026 High macosinformation stealernotarized dropper
threat-intel Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found A popular Chrome and Edge header-editing extension, ModHeader, was found to contain a hidden browsing history collector, despite claims it didn't collect data. Researchers at Stripe OLT discovered the collector was dorma… The Hacker News · Jul 13, 2026 High CNextensiondata-collectionheader-editing
vulnerability Organizations Warned of Exploited Joomla Extension Vulnerabilities Two critical vulnerabilities in Joomla extensions – Balbooa Forms and iCagenda – have been actively exploited by threat actors, allowing for remote code execution without authentication. Both vulnerabilities have been ad… SecurityWeek · Jul 13, 2026 Critical CVE-2026-56291CVE-2026-48939joomlavulnerabilityremote code execution
vulnerability iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days Two zero-day vulnerabilities in Joomla extensions – iCagenda and Balbooa Forms – are being actively exploited in a global campaign targeting vulnerable CMS systems. Both flaws allow for remote code execution via file upl… The Hacker News · Jul 13, 2026 Critical CVE-2026-48939CVE-2026-56291CVE-2025-6389AUjoomlavulnerabilityzero-day
threat-intel Europe revives law allowing big tech to scan for CSAM The European Parliament has revived a law allowing big tech companies like Google, Microsoft, and Meta to scan users' messages to detect child sexual abuse material (CSAM). This move, driven by a procedural vote and conc… The Record · Jul 10, 2026 Medium privacyencryptionchild_protection
threat-intel More Countries Jump on the Social Media Ban Wagon More countries are implementing social media bans for minors, driven by concerns about mental health and safety. However, companies are struggling to comply while minimizing user disruption and avoiding intrusive data co… Dark Reading · Jul 10, 2026 Medium AUUNsocial mediaage verificationprivacy
vulnerability Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers A remote client can crash HTTP/3 servers running XQUIC, Alibaba's HTTP/3 and QUIC library. The vulnerability, dubbed XRING, stems from an incorrect size calculation during table resizing within the QPACK header compressi… The Hacker News · Jul 10, 2026 High CVE-2026-42530httphttp3quic
threat-intel Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking A University of Michigan, New Mexico, and IIT Delhi study found that 281 popular free Android VPN apps on the Google Play Store have significant security flaws, including leaking user traffic, sending data in plain text,… The Hacker News · Jul 10, 2026 High CVE-2016-6329CVE-2016-2183vpnandroidsecurity
threat-intel "Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th) This phishing email campaign uses a clever technique to evade AI-based email security filters. The attacker employs a large, padded HTML attachment containing a credential-stealing page. The padding itself – a massive bl… SANS Internet Storm Center · Jul 10, 2026 High phishingai evasioncontent classification
threat-intel Summer of Clearinghouses The article discusses the recent surge in ‘clearinghouses’ – collections of pre-disclosure vulnerabilities – and argues that these are largely a distraction from the real issue: the speed at which vulnerabilities are dis… The Hacker News · Jul 9, 2026 High vulnerabilityopen sourceclearinghouse
threat-intel Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes A China-based threat actor, dubbed Lurking Lizard, has been running a sophisticated, multi-year residential proxy business. The operation involves tricking users into installing malicious 7-Zip installers and other fake… The Hacker News · Jul 9, 2026 High CHresidential proxybotnetmalware
threat-intel _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th) A self-propagating bot, originating from Belarus (as claimed by its creator), has been scanning for open ports and attempting brute-force login attempts on various servers worldwide. The bot’s purpose is to raise awarene… SANS Internet Storm Center · Jul 9, 2026 Medium BYscanbrute-forcessh
threat-intel Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself A 15-year-old in Japan used an AI chatbot to automatically cancel nearly 47,000 anime streaming subscriptions within hours. Simultaneously, researchers have documented the first fully autonomous, agentic AI-driven ransom… Graham Cluley · Jul 8, 2026 High JPairansomwarecyberattack
threat-intel 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros Researchers at Nebula Security discovered GhostLock (CVE-2026-43499), a 15-year-old Linux kernel vulnerability that allows an unprivileged user to gain root access on a machine. The flaw, discovered by their AI-driven bu… The Hacker News · Jul 8, 2026 High CVE-2026-43499CVE-2026-53166CVE-2026-46242linuxkernelprivilege-escalation
threat-intel Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation A financially motivated campaign utilizing Vidar stealer and XMRig cryptocurrency miner has been active since April 2026, targeting consumers and small- and medium-sized businesses globally, primarily in the U.S. and EU.… Palo Alto Unit 42 · Jul 7, 2026 High USDEmalvertisingdll hijackinganti-forensic
data-breach Major Japanese telco says cyberattack exposed 12 million emails KDDI, a major Japanese telecommunications company, disclosed that a cyberattack exposed the email addresses and passwords of over 12 million customers due to a vulnerability in third-party software. The breach impacted a… The Record · Jul 7, 2026 Medium JPdata breachpasswordvulnerability
threat-intel Google Is Suing Chinese Scammers Who Are Using Gemini Google is taking legal action against a Chinese group, Outsider Enterprise, who were leveraging Google's Gemini AI to create sophisticated phishing campaigns. The group utilized Telegram to offer ‘phishing-as-a-service,’… Schneier on Security · Jul 7, 2026 Medium CNphishingaigemini
vulnerability CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware The CERT Coordination Center has issued a warning about a hidden backdoor embedded in Tenda router firmware. This vulnerability, tracked as CVE-2026-11405, allows attackers to bypass password verification and gain full a… The Hacker News · Jul 7, 2026 High CVE-2026-11405routerbackdoorfirmware
threat-intel RCS and DNS: The NAPTR Record, (Mon, Jul 6th) This article details the observation of NAPTR records being utilized in RCS (Rich Communication Services) communications, specifically within Verizon’s network. NAPTR records, defined in RFC 2915, are typically used to r… SANS Internet Storm Center · Jul 6, 2026 Medium USrcsdnsnaptr