threat-intel Protéger un document image avant de la partager PROTECTION D’IMAGE by ZATAZ.COM is a free browser-based tool designed to help users protect sensitive information in images and PDFs before sharing them. The tool offers features like watermarking, masking, metadata removal, and batch processing, all while keeping the processing entirely local – no data is uploaded or… ZATAZ · 2d ago Medium watermarkingmetadataprivacy
threat-intel Surveillance – Everything You Wanted to Know, But Were Afraid to Ask The article explores the increasingly pervasive use of surveillance technologies by various entities – companies, law enforcement, criminals, and intelligence agencies – and the ethical and legal concerns surrounding thi… SecurityWeek · Aug 20, 2026 High surveillanceprivacydata collection
threat-intel TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks Researchers have uncovered TWINLOOT, a sophisticated Python implant framework that leverages Microsoft services – specifically SharePoint Online and Teams TURN relays – to steal credentials and move laterally across netw… The Hacker News · Aug 18, 2026 High c2microsoftlateral movement
threat-intel 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets A new typosquatting campaign targeting RubyGems users has been identified, leveraging a Rust-based stealer to steal browser credentials, cryptocurrency wallets, and Telegram data. The campaign utilizes a 'StubMaker' tool… The Hacker News · Aug 18, 2026 High typosquattingrubymalware
threat-intel Who’s Tracking You? Use This New Service to Find Out DecryptAds is a new service designed to expose the complex ecosystem of adtech companies tracking users online. By scraping data from files like ads.txt, app-ads.txt, and sellers.json, it reveals a network of data broker… Krebs on Security · Aug 14, 2026 High CHRUUAadtechdata-brokermalvertising
threat-intel Multiples vulnérabilités dans les produits Palo Alto Networks (13 août 2026) Multiple vulnerabilities have been discovered in Palo Alto Networks products, including remote code execution, privilege escalation, and denial-of-service attacks. Several CVEs have been identified, impacting various pro… CERT-FR · Aug 13, 2026 High CVE-2026-0291CVE-2026-0292CVE-2026-0293vulnerabilitythreatsecurity
threat-intel No Perfect Fix for AI Browser Prompt Injection Flaws Research presented at Black Hat USA 2026 revealed that despite numerous security guardrails, AI-powered web browsers remain vulnerable to prompt injection attacks. Artem Chaikin demonstrated how attackers can bypass thes… Dark Reading · Aug 5, 2026 High prompt injectionai securityweb browser
threat-intel Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware A sophisticated campaign, dubbed CaptiveCrunch, is leveraging hijacked hotel Wi-Fi networks to deliver surveillance malware – specifically CornFlake, a remote access trojan – to unsuspecting guests. The attacks are orche… The Hacker News · Aug 1, 2026 High USUKcaptive portaldns redirectionremote access trojan
threat-intel Agentic Browsers Rewind Web Security by 20 years Researchers at Zenity have discovered a significant vulnerability class – "PleaseFix" – that allows attackers to socially engineer AI agentic browsers to perform malicious actions, including account takeover and remote c… Dark Reading · Jul 27, 2026 High agentic browserssocial engineeringzero-click
threat-intel New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands Researchers at Seoul National University, the University of Illinois Urbana-Champaign, and Largosoft have discovered a new attack method called Agent Data Injection (ADI) that can manipulate AI agents by subtly corruptin… The Hacker News · Jul 16, 2026 High CVE-2025-32711prompt-injectiondata-exfiltrationai-security
threat-intel Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks Researchers at KU Leuven discovered significant privacy vulnerabilities in 85 popular crypto wallet extensions running as browser extensions. These wallets leak address information, allowing trackers to link separate wal… The Hacker News · Jul 14, 2026 High privacycryptowallet
threat-intel Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks Securonix researchers identified a complex malware delivery framework called ‘Veil#Drop’ that utilizes compromised websites, specifically Blogspot, to deploy information-stealing malware. The framework employs multiple l… SecurityWeek · Jul 6, 2026 High malwareinformation stealerevasion
threat-intel Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs A recent Australian Institute of Criminology survey revealed a decrease in overall cybercrime incidents and financial losses experienced by Australians in 2025 compared to 2024. However, this positive trend was largely d… Dark Reading · Jul 2, 2026 Medium AUsmbcybercrimeaustralia
threat-intel How We Added WebAuthn to a Browser-Based RDP Client This Palo Alto Unit 42 article details the development of a browser-based RDP client that supports WebAuthn redirection, allowing users to utilize security keys like YubiKeys during remote sessions. The team overcame sig… Palo Alto Unit 42 · Jul 2, 2026 Medium webauthnrdpbrowser
threat-intel ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials Researchers at LayerX discovered a vulnerability dubbed ‘BioShocking’ that exploits the tendency of AI browsers to prioritize game-like objectives over security protocols. The attack leverages a puzzle-solving scenario t… SecurityWeek · Jul 2, 2026 High aibrowsercredentials
threat-intel FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations A large-scale credential theft campaign, dubbed FortiBleed, has been linked to both the INC and Lynx ransomware groups, utilizing stolen Fortinet credentials for follow-on intrusions. The operation involved extensive sca… The Hacker News · Jul 2, 2026 High CVE-2026-35616USLAAScredential theftransomwarefortinet
phishing Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS This article details a concerning trend in phishing attacks where threat actors are leveraging user-agent data to dynamically adapt their campaigns to the specific device and operating system of the victim. Attackers are… Dark Reading · Jul 1, 2026 High USphishinguser-agentmalware
threat-intel New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials A LayerX security firm discovered a new attack technique, dubbed BioShocking, that exploits AI browsers to trick users into revealing their login credentials. The method involves manipulating the AI browser into believin… The Hacker News · Jun 30, 2026 High N/aiprompt injectioncredential theft
threat-intel Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement A coordinated international effort, led by Microsoft and Europol, successfully dismantled a significant cybercrime-as-a-service infrastructure used by multiple threat actors. The operation resulted in the seizure of subs… The Record · Jun 24, 2026 High RUcybercrime-as-a-servicesupply chaininfostealer
ransomware Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered A coordinated international law enforcement operation, involving Bitdefender, Bitsight, ESET, Microsoft, and Europol, successfully disrupted the Amadey and StealC malware networks, recovering 27 million stolen credential… The Hacker News · Jun 24, 2026 High NLCADEmaascredential theftransomware