threat-intel Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks Google has launched an AI-powered cybersecurity platform, AI Threat Defense, designed to proactively combat increasingly sophisticated cyberattacks leveraging artificial intelligence. This platform utilizes AI to identif… SecurityWeek · May 28, 2026 High GBaicybersecuritythreat detection
malware BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model An advanced Android remote access Trojan, BTMOB RAT, is spreading across Brazil and Latin America through a malware-as-a-service (MaaS) model. Delivered via a no-code interface, it allows cybercriminals to create malicio… Dark Reading · May 28, 2026 High BRARandroidratmaas
threat-intel ESET APT Activity Report Q4 2025–Q1 2026 ESET’s Q4 2025 – Q1 2026 APT Activity Report highlights a period of intense geopolitical activity driving advanced cyber espionage. China-aligned actors were mobilized to monitor maritime and energy developments, while I… WeLiveSecurity · May 28, 2026 High CHIRPOaptcyber espionagegeopolitics
threat-intel JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware A previously undocumented threat actor, dubbed JINX-0164, is targeting cryptocurrency firms through sophisticated social engineering tactics and bespoke macOS malware to steal digital assets. The campaign involves luring… The Hacker News · May 28, 2026 High KPmacossocial engineeringcryptocurrency
malware Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years In April 2026, a cybercrime gang has been using fake video player plugin updates to distribute a cryptocurrency miner, a tactic that has been ongoing since at least 2022. The gang leverages pirated digital libraries and… Securelist · May 28, 2026 High RUTOcryptominerstackoverflowfake update
threat-intel Out of the Crypt: The Evolving Cyber Extortion Economy This report from Palo Alto Unit 42 highlights a significant shift in the cyber extortion landscape, moving away from ransomware-based pressure towards pure data theft and extortion. The trend is driven by factors like ad… Palo Alto Unit 42 · May 27, 2026 High USdata theftextortionsupply chain
malware GPU mining malware spreads via SEO poisoning, AI chatbots A cryptojacking campaign utilizing SEO poisoning and AI chatbot manipulation is spreading through malicious downloads of popular system utilities. The campaign leverages a ZIP archive containing a malicious DLL and a Scr… BleepingComputer · May 27, 2026 High UScryptojackingseo poisoningai chatbots
ransomware Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th) This report details the reconstruction of an Akira ransomware attack on a mid-sized organization, focusing on the critical early stages of the intrusion. The analysis, based solely on firewall and Windows event logs, rev… SANS Internet Storm Center · May 27, 2026 High USbrute-forcecredential-stuffinglateral-movement
threat-intel Ransomware Actors Show Up In Person to Steal Law Firm Data The Silent Ransom Group (SRG), also known as Luna Moth and UNC3753, is targeting law firms through sophisticated social engineering tactics, including impersonating IT personnel and conducting in-person visits to gain ac… Dark Reading · May 27, 2026 High RUsocial engineeringdata theftlaw firms
threat-intel UK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About Russia British intelligence chief Anne Keast-Butler warned of the escalating threat posed by Russia’s cyber activities, particularly the weaponization of artificial intelligence, and emphasized the urgent need for increased cyb… SecurityWeek · May 27, 2026 High UKRUCHartificial intelligencecybersecurityrussia
data-breach Latin American Cybercriminals Hoover Up Government Data Recent investigations reveal a surge in cybercriminal activity targeting government agencies across Latin America, primarily driven by groups like La Pampa Leaks and the Chronus Group. These actors are stealing and monet… Dark Reading · May 27, 2026 High URMECOgovernmentdata breachlatin america
malware Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users Two separate malware campaigns are targeting Windows and Android users across Latin America and Europe, primarily focusing on banking trojans. The first campaign utilizes the Grandoreiro malware, an actively evolving ban… The Hacker News · May 27, 2026 High PTBRESbanking trojanandroid malwaredll side-loading
malware Malicious npm Package Stole Files From Claude AI User Directory via GitHub A malicious npm package, "mouse5212-super-formatter," was discovered that leveraged GitHub to steal files from Anthropic's Claude AI user directory. The package masqueraded as a legitimate archive deployment sync utility… The Hacker News · May 27, 2026 High USnpmgithubai
vulnerability Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate Novee researchers discovered an account takeover vulnerability in the open source CFP management tool Pretalx. The post Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate appeared… SecurityWeek · May 27, 2026 High CVE-2026-41241
vulnerability MediaArea heap-based buffer overflow vulnerabilities Cisco Talos’ Vulnerability Discovery & Research team recently disclosed four vulnerabilities in MediaArea MediaInfoLib library. The vulnerabilities mentioned in this blog post have been patched by their respective vendor… Cisco Talos · May 27, 2026 High CVE-2026-25104CVE-2026-25713CVE-2026-28764
supply-chain Glassworm botnet disrupted after resilient C2 infrastructure takedown The Glassworm botnet, a supply-chain threat targeting developers, has been significantly disrupted following a coordinated takedown of its resilient command-and-control infrastructure. The botnet utilized a complex archi… BleepingComputer · May 27, 2026 High supply-chainbotnetc2
Dutch police arrest man over cyber breach at Ajax football club The suspect was detained in the central Dutch town of Buren, where law enforcement officers also searched his home and seized multiple digital storage devices, according to a statement released Tuesday by the Dutch Natio… The Record · May 27, 2026 High
apt Iranian intelligence service behind hack of LA transit system, researchers say Iranian intelligence service operatives, known as Ababil of Minab, were responsible for a significant cyberattack targeting the Los Angeles County Metropolitan Transportation Authority (LACMTA). The group, linked to the… The Record · May 27, 2026 High IRISTUirancyberattackcritical infrastructure
threat-intel FBI warns of in-person data theft attacks from extortion gang The FBI has issued a warning about the Silent Ransom Group (SRG), an extortion gang now employing in-person data theft tactics targeting U.S. law firms. This shift involves social engineering, including phishing and impe… BleepingComputer · May 27, 2026 High USsocial engineeringphishingdata theft
threat-intel GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure CrowdStrike, in collaboration with Google and Shadowserver Foundation, successfully disrupted the command-and-control infrastructure of the GlassWorm malware campaign, which targeted software developers through compromis… The Hacker News · May 27, 2026 High RUCIsupply chaindeveloperc2