threat-intel Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine The Gamaredon group is exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy a multi-stage malware campaign targeting Ukraine. This campaign utilizes GammaWorm and GammaSteel, designed for data theft and persistenc… The Hacker News · Jun 2, 2026 High CVE-2025-8088CVE-2026-21509RUUAwinrarmalwarevulnerability
supply-chain Red Hat removes tainted packages after software pipeline compromise Red Hat removed numerous software packages from its distribution pipeline after a compromised GitHub account was used to distribute credential-stealing malware. The attack, utilizing a variant of the Mini Shai-Hulud worm… The Record · Jun 2, 2026 High NOUKsupply chaingithubmalware
supply-chain Red Hat npm packages compromised to steal developer credentials A supply-chain attack targeting Red Hat npm packages resulted in the distribution of a new variant of the Shai-Hulud credential-stealing malware, dubbed 'Miasma'. The attackers compromised a Red Hat employee's GitHub acc… BleepingComputer · Jun 1, 2026 High USsupply chaincredential theftgithub
supply-chain Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm A new supply chain attack, dubbed Miasma, has compromised Red Hat npm packages, utilizing a self-propagating worm to steal credentials and secrets from developer machines. The attack, leveraging techniques similar to the… The Hacker News · Jun 1, 2026 High USsupply chain attackcredential theftgithub actions
malware WordPress malware campaign hides payloads in Steam profiles A WordPress malware campaign has infected nearly 2,000 websites by hiding command-and-control (C2) data within Steam Community profile comments. The attackers utilize invisible Unicode characters to encode malicious payl… BleepingComputer · Jun 1, 2026 High USwordpresssteemunicode
threat-intel YARA-X 1.17.0 Release, (Sun, May 31st) The SANS Internet Storm Center released version 1.17.0 of YARA-X, a tool used for identifying and analyzing malware. This update includes several performance enhancements and a single bug fix, indicating ongoing maintena… SANS Internet Storm Center · May 31, 2026 Info yaramalwarethreat-detection
malware ChatGPT share links abused to host fake outage pages to deliver malware Threat actors are exploiting ChatGPT's content-sharing feature to host convincing fake outage pages designed to trick users into downloading malware. This 'LLMShare' campaign leverages Google ads and a legitimate OpenAI… BleepingComputer · May 29, 2026 High aimalwarephishing
threat-intel New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks A new, Russian-linked cyber threat group, dubbed GREYVIBE, has been targeting Ukraine and related entities since August 2025 with a range of sophisticated attacks. The group utilizes multiple attack vectors, including ph… The Hacker News · May 29, 2026 High RUrussianaigenai
threat-intel GreyVibe hackers use ChatGPT, Gemini to power cyberattacks GreyVibe, a threat actor likely linked to Russia, has been conducting cyber espionage campaigns targeting Ukrainian organizations since August 2025, utilizing a diverse range of custom malware and AI-generated lures. The… BleepingComputer · May 28, 2026 High RUUKaiphishingmalware
threat-intel Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks A newly identified Russia-linked threat actor, GreyVibe, is utilizing artificial intelligence to enhance the speed, scale, and sophistication of its cyberattacks, primarily targeting Ukrainian military, government, and b… SecurityWeek · May 28, 2026 High RUairussiamalware
threat-intel Smashing Security podcast #469: What your Oura ring won’t tell you This podcast episode, "Smashing Security" #469, discusses cybersecurity concerns, primarily focusing on the potential vulnerabilities of wearable devices like the Oura ring and broader issues within the cybersecurity ind… Graham Cluley · May 27, 2026 Medium CARUwearablesiotmalware
malware Malicious npm Package Stole Files From Claude AI User Directory via GitHub A malicious npm package, "mouse5212-super-formatter," was discovered that leveraged GitHub to steal files from Anthropic's Claude AI user directory. The package masqueraded as a legitimate archive deployment sync utility… The Hacker News · May 27, 2026 High USnpmgithubai
threat-intel GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure CrowdStrike, in collaboration with Google and Shadowserver Foundation, successfully disrupted the command-and-control infrastructure of the GlassWorm malware campaign, which targeted software developers through compromis… The Hacker News · May 27, 2026 High RUCIsupply chaindeveloperc2
malware AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites Microsoft has identified a cryptojacking campaign utilizing AI chatbots to recommend malicious download sites, a novel approach to social engineering. The campaign impersonates legitimate system utilities like CrystalDis… The Hacker News · May 27, 2026 High CVE-2025-33073USaicryptojackingsocial engineering
threat-intel ISC Stormcast For Wednesday, May 27th, 2026 https://isc.sans.edu/podcastdetail/9946, (Wed, May 27th) The SANS Internet Storm Center's Stormcast for May 27th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The broadcast detailed ongoing campaigns involving phishing attacks… SANS Internet Storm Center · May 27, 2026 Medium phishingmalwareemail
supply-chain Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos A six-hour malware campaign, dubbed 'Megalodon,' targeted over 5,500 GitHub repositories, injecting malicious commits containing credential-stealing payloads. The campaign, orchestrated by an unknown threat actor potenti… Dark Reading · May 26, 2026 High githubsupply-chainmalware
threat-intel The Hackers Behind Shai-Hulud: Lucky or Skilled? The cybercrime group TeamPCP has been identified as a primary driver behind the Shai-Hulud worm, causing significant damage to the open-source ecosystem through exploiting vulnerabilities like React2Shell and misconfigur… Dark Reading · May 26, 2026 High USsupply-chainopen-sourcedeveloper-tooling
threat-intel Iranian APT Targets Aviation, Software Companies With Updated Tools The Iranian APT group, known as Nimbus Manticore, has been aggressively updating its tactics and tools to target aviation and software companies globally. The group, linked to Charming Kitten and the IRGC, is employing… SecurityWeek · May 26, 2026 High AEIRSAaptphishingappdomain
threat-intel BTMOB: A stealthy RAT burrowing deep into Android devices BTMOB is a stealthy Android remote access trojan (RAT) that’s rapidly evolving and spreading through phishing campaigns and a ‘malware-as-a-service’ model. It allows attackers to steal data, take control of devices, and… WeLiveSecurity · May 26, 2026 High ARandroidmalwareremote access trojan
ransomware Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks A critical vulnerability (CVE-2026-26980) in Ghost CMS is being exploited to hijack over 700 websites, primarily through ClickFix attacks. Threat actors are leveraging this SQL injection flaw to steal admin API keys and… The Hacker News · May 25, 2026 Critical CVE-2026-26980CNsql injectionclickfixjavascript