vulnerability iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days Two zero-day vulnerabilities in Joomla extensions – iCagenda and Balbooa Forms – are being actively exploited in a global campaign targeting vulnerable CMS systems. Both flaws allow for remote code execution via file upl… The Hacker News · Jul 13, 2026 Critical CVE-2026-48939CVE-2026-56291CVE-2025-6389AUjoomlavulnerabilityzero-day
threat-intel Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th) A SANS Internet Storm Center analysis reveals a widespread scanning campaign targeting servers to identify and exploit vulnerabilities related to AI assistants and local Large Language Models (LLMs). The scans are active… SANS Internet Storm Center · Jul 13, 2026 High aillmscanning
vulnerability ISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th) The ISC Stormcast highlighted a significant vulnerability in Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise across various industri… SANS Internet Storm Center · Jul 13, 2026 High activemqvulnerabilitydeserialization
threat-intel Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions Russia’s FSB, specifically its Center 16 signals intelligence arm, has been formally blamed for a cyberattack that threatened to cut heating to half a million people in Poland last winter. Following this attribution, the… The Record · Jul 12, 2026 High RUPOFRcyberattackcybercrimeespionage
supply-chain Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install A malicious npm package, jscrambler 8.14.0, was released with a hidden infostealer that silently dropped and executed during installation. The package, pushed by a compromised account, included a Rust-based stealer targe… The Hacker News · Jul 11, 2026 High npmsupply-chainrust
threat-intel Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns Chinese and Indian-aligned threat actors have been conducting sustained cyber espionage campaigns targeting Pakistani law enforcement organizations, including the Balochistan Police, Khyber Pakhtunkhwa Police, Islamabad… The Hacker News · Jul 11, 2026 High CHINPAcyber espionagelaw enforcementchina
threat-intel Ghost Accounts Abuse GitHub API in Mass Recon Campaign Threat actors are systematically abusing GitHub's public API using a network of dormant ghost accounts to map organizations, repositories, and user accounts – a reconnaissance tactic that occasionally leads to data exfil… SecurityWeek · Jul 11, 2026 Medium CHINreconnaissancegithubapi
vulnerability Wireshark 4.6.7 Released, (Sat, Jul 11th) Wireshark, a widely used network protocol analyzer, released a security update addressing 12 vulnerabilities and 16 bugs. This update is crucial for maintaining network security and protecting against potential exploits. SANS Internet Storm Center · Jul 11, 2026 Medium wiresharkvulnerabilitynetwork analysis
vulnerability Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions A critical cross-site scripting (XSS) vulnerability in Zimbra's Classic Web Client could allow attackers to execute malicious code through crafted emails, potentially leading to account compromise and data theft. Zimbra… The Hacker News · Jul 11, 2026 High CVE-2025-27915CVE-2023-37580CVE-2024-27443xssvulnerabilityweb client
ransomware No Manners Here: The Ruthless Rise of The Gentlemen Ransomware The Gentlemen, a rapidly growing Ransomware-as-a-Service (RaaS) program, has significantly increased its victim count in 2026, becoming the second most active RaaS program globally. Leveraging a 90% affiliate payout stru… Palo Alto Unit 42 · Jul 10, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073USCAGBransomware-as-a-serviceracksedge-device-attack
vulnerability Friday Squid Blogging: “Squidbleed” Vulnerability A vulnerability, dubbed ‘Squidbleed,’ has been discovered in the Squid proxy server, allowing attackers to leak HTTP requests. This flaw stems from a flawed implementation of the HTTP/2 protocol, potentially exposing sen… Schneier on Security · Jul 10, 2026 Medium http2proxyvulnerability
threat-intel Turning the Tables on Email Scammers With 'ScamBuster' ScamBuster is an open-source, AI-driven system designed to turn the tables on email scammers. By mimicking victim personas and engaging with attackers, it gathers valuable intelligence – including financial details and i… Dark Reading · Jul 10, 2026 High aiphishingthreat intelligence
threat-intel Europe revives law allowing big tech to scan for CSAM The European Parliament has revived a law allowing big tech companies like Google, Microsoft, and Meta to scan users' messages to detect child sexual abuse material (CSAM). This move, driven by a procedural vote and conc… The Record · Jul 10, 2026 Medium privacyencryptionchild_protection
threat-intel Jen Ellis: Connecting Cyber Community With Political Machinery This article chronicles the career of Jen Ellis, a cybersecurity advocate who rose to prominence after witnessing the legal troubles faced by security researcher HD Moore. Initially spurred by a deep sense of injustice a… Dark Reading · Jul 10, 2026 High UNpolicycybersecurityresearch
threat-intel Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages Threat actors compromised the Injective Labs GitHub repository and injected a malicious npm package designed to steal cryptocurrency wallet private keys and mnemonic seed phrases. The package, disguised as telemetry func… The Hacker News · Jul 10, 2026 High npmsupply-chaincryptocurrency
ransomware Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence Two major ransomware figures have been brought to justice in separate U.S. court cases. Karen Vardanyan, a Ryuk ransomware operator, pleaded guilty to conspiracy and computer fraud, while Angelo Martino, a ransomware neg… The Record · Jul 10, 2026 High FRUKUNransomwarenegotiatorextortion
threat-intel Cybercriminals Flock to Healthcare Businesses as Attacks Surge Cyberattacks on healthcare businesses, including service providers supporting hospitals, have surged dramatically, nearly doubling in the past year and significantly outpacing attacks on hospitals themselves. This trend… Dark Reading · Jul 10, 2026 High USGEransomwarecyberattackhealthcare
threat-intel License plate cameras may be next target after Supreme Court reins in location tracking A recent Supreme Court ruling regarding cell phone location history searches has raised significant concerns about the potential impact on license plate recognition (ALPR) technology. The court emphasized that indiscrimi… The Record · Jul 10, 2026 High alprsurveillancefourth amendment
threat-intel URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Progress Software has instructed ShareFile customers to immediately shut down their Storage Zone Controllers due to a "credible external security threat." The company has disabled access to affected accounts and is inves… The Hacker News · Jul 10, 2026 High CVE-2023-24489vulnerabilitysecuritycloud
threat-intel Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot Researchers at Binarly discovered six new vulnerabilities in U-Boot, the firmware that starts up many hardware devices, including routers and servers. These flaws could allow attackers to execute malicious code at boot,… The Hacker News · Jul 10, 2026 High CVE-2026-33243firmwarebootloadervulnerability