threat-intel ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism Researchers have discovered a new attack technique called ‘HalluSquatting’ that leverages AI assistants’ tendency to fabricate information to create scalable botnets. Attackers register fake repository names, and when us… SecurityWeek · Jul 10, 2026 High aiprompt injectionhallucination
threat-intel Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks A former ransomware negotiator, Angelo Martino, has been sentenced to 70 months in prison for betraying five victims and providing BlackCat ransomware operators with confidential information, allowing them to demand high… The Hacker News · Jul 10, 2026 High USransomwarenegotiatorcollusion
supply-chain Network of 200 GitHub Repositories Used for Malware Infection A threat actor, linked to previous activity associated with the ‘ischhfd83’ email address, has created a network of over 200 GitHub repositories delivering Windows malware through a Go module disguised as a DNS scanning… SecurityWeek · Jul 10, 2026 High supply chaingithubmalware
threat-intel ISC Stormcast For Friday, July 10th, 2026 https://isc.sans.edu/podcastdetail/10002, (Fri, Jul 10th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in widely used communication… SANS Internet Storm Center · Jul 10, 2026 High phishingvulnerabilityslack
threat-intel Dutch police trace Odido telco cyberattack to suspected local accomplice Dutch police are investigating a cyberattack against Odido, a Dutch telecom provider, that exposed the data of over 6 million customers. The attack was facilitated by a Dutch-speaking individual posing as an Odido IT emp… The Record · Jul 9, 2026 High NLcyberattackdata breachtelecom
threat-intel Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure Iran's cyber operations, primarily conducted through groups like Handala and Ababil of Minab, are increasingly targeting a broader range of organizations beyond critical infrastructure. These groups, often described as h… Dark Reading · Jul 9, 2026 Medium CVE-2021-22681IRhacktivismcyber espionagevulnerability exploitation
vulnerability Microsoft Reins in RoguePlanet Zero-Day Threat A disgruntled security researcher, known as "Nightmare-Eclipse," published a proof-of-concept exploit (RoguePlanet) for a Windows Defender vulnerability, leading Microsoft to issue an out-of-band patch. The vulnerability… Dark Reading · Jul 9, 2026 High CVE-2026-50656CVE-2026-33825zero-dayprivilege-escalationmicrosoft
threat-intel AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready This article discusses the growing risk posed by AI agents in software development environments and highlights that most organizations are unprepared to manage this new type of identity. Unlike traditional service accoun… Dark Reading · Jul 9, 2026 High aiidentitygovernance
vulnerability WolfSSL, GeoVision, VTK vulnerabilities Cisco Talos has disclosed a significant number of vulnerabilities across WolfSSL, GeoVision, and VTK-DICOM. These vulnerabilities range from buffer overflows and command injection to session cookie issues and heap overfl… Cisco Talos · Jul 9, 2026 Medium CVE-2026-28739CVE-2026-25106CVE-2026-33091buffer_overflowcommand_injectioncve
threat-intel Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs Datadog Security Labs has discovered a campaign where attackers are systematically mapping corporate GitHub organizations by leveraging dormant accounts and stolen credentials to gather extensive information about a comp… The Hacker News · Jul 9, 2026 Medium githubenumerationapi
threat-intel New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware Microsoft has uncovered a sophisticated Windows backdoor, dubbed GigaWiper, that combines destructive capabilities with remote control functionality. GigaWiper operates by bundling three separate tools – a disk wiper, a… The Hacker News · Jul 9, 2026 High IRISUKransomwarebackdoordata destruction
threat-intel Winning 54% of the time Cisco Talos Intelligence has identified a China-nexus threat actor, UAT-7810, expanding its Operational Relay Box (ORB) network. The group exploits unpatched vulnerabilities in Ruckus and ASUS routers to deploy custom ma… Cisco Talos · Jul 9, 2026 High CHorbproxyrouter
supply-chain npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk GitHub has released npm 12, significantly bolstering supply chain security by disabling install scripts and deprecating granular access tokens (GATs). These changes restrict automated script execution and limit the abili… The Hacker News · Jul 9, 2026 Medium npmsupply chainsecurity
threat-intel ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories This week's ThreatsDay highlights a diverse range of cyber threats, from global fraud operations and ransomware tool overlaps to sophisticated social engineering attacks and vulnerabilities in popular software. Key event… The Hacker News · Jul 9, 2026 High CVE-2026-9181CVE-2025-49760CVE-2025-59200CHTAESsocial engineeringphishingransomware
threat-intel QIZ Security Raises $17 Million for Cryptographic Governance Platform Israeli cybersecurity startup QIZ Security secured $17 million in seed funding to bolster its cryptographic governance platform, addressing the growing threat of quantum computing and the need for continuous cryptographi… SecurityWeek · Jul 9, 2026 Medium IScryptographypost-quantumquantum computing
threat-intel As Global Conflicts Go Digital, Businesses Need Wartime Gameplans As global conflicts become increasingly digital, businesses across various sectors are becoming increasingly vulnerable targets for nation-states engaged in warfare. The case of Intellect Services, a Ukrainian tax softwa… Dark Reading · Jul 9, 2026 High UKIRUNcyberwarfarenation-stategeopolitics
threat-intel Latvian forestry company still restoring systems weeks after ransomware attack A Latvian state-owned forestry company, LVM, is still recovering from a ransomware attack that disrupted its systems for weeks. The attack, attributed to a foreign, financially motivated ransomware group, led to the leak… The Record · Jul 9, 2026 High LVransomwarecyberattackdata breach
threat-intel UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge The UK government is launching a multi-faceted cybersecurity initiative, Cyber Shield, focused on leveraging agentic AI to bolster national cyber defenses against increasingly rapid AI-powered attacks. Simultaneously, th… SecurityWeek · Jul 9, 2026 High UKaicybersecuritynational security
vulnerability Palo Alto Networks Patches 13 Vulnerabilities Palo Alto Networks has released advisories detailing 13 vulnerabilities across its products, including a critical buffer overflow that could lead to arbitrary code execution. While the company reports no active exploitat… SecurityWeek · Jul 9, 2026 High CVE-2026-0288vulnerabilitypatchbuffer overflow
threat-intel NSA revives 'Tailored Access Operations' name for elite hacking unit The National Security Agency (NSA) has revived its elite hacking unit, formerly known as TAO (Tailored Access Operations), as part of a reorganization aimed at bolstering its capabilities against evolving cyber threats f… The Record · Jul 9, 2026 High IRCHNOhackingcyber espionagenational security