threat-intel TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor Microsoft has disclosed a new ClickFix variant, TerminalFix, that uses fake Cloudflare CAPTCHAs to trick users into executing malicious PowerShell commands via Windows Terminal or PowerShell. The campaign employs a multi-stage attack leveraging DLL sideloading, reconnaissance, and a reverse-tunnel backdoor to gain pers… The Hacker News · 15h ago High clickfixdll sideloadingreverse tunnel
threat-intel Ransomware : avec 181 victimes, 2026 dépasse déjà toute l’année 2025 A ZATAZ report indicates that France experienced 181 ransomware-related claims as of August 20, 2026, surpassing 2025’s total by a significant margin. However, the report cautions that these claims are based on criminal… ZATAZ · Aug 22, 2026 High FRransomwarefrancethreat intelligence
threat-intel Enterprise Defenses Recovered at the Edge and Collapsed Inside A new report from Picus Labs reveals a concerning trend in cybersecurity defenses: while overall prevention effectiveness has improved, defenses are significantly weaker *inside* a network, failing to stop quiet, reconna… The Hacker News · Aug 12, 2026 High detectionloggingreconnaissance
threat-intel Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities A Chrome extension, initially banned for stealing AI chat conversations, has returned to the Chrome Web Store and is now targeting enterprise browsers through Google's CDN. The extension employs a sophisticated affiliate… SecurityWeek · Aug 11, 2026 High chromeextensionaffiliate
threat-intel MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection MedusaHVNC is a sophisticated remote access trojan (RAT) sold as a service, utilizing hidden Windows desktops to evade detection and maintain a persistent presence on victims' systems. BlackFog researchers discovered the… SecurityWeek · Jul 27, 2026 High RUrathidden desktopencryption
threat-intel New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands A new modular malware, TELEPUZ, is spreading via ClickFix lures and is being developed by a solo developer or small team. The malware steals data, runs commands, and evades detection through various techniques, including… The Hacker News · Jul 16, 2026 High BRINclickfixpastejackingmalware-as-a-service
threat-intel ISC Stormcast For Tuesday, June 23rd, 2026 https://isc.sans.edu/podcastdetail/9982, (Tue, Jun 23rd) The SANS Internet Storm Center's Stormcast for June 23rd, 2026, reported a heightened level of online threats and potential disruptions. The broadcast highlighted several ongoing campaigns and emerging vulnerabilities th… SANS Internet Storm Center · Jun 23, 2026 Medium stormcastthreat intelligencephishing
ransomware State of ransomware in 2026 Kaspersky’s 2026 ransomware threat report highlights a shift in the landscape, with ransomware attacks declining overall but becoming more sophisticated. Key trends include the emergence of post-quantum cryptography rans… Securelist · May 12, 2026 High USransomwarequantum cryptographyedr