threat-intel Is Cyber missing the Marque? The White House is considering a program allowing private cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations outside the United States, a move that significantly expands the scope of government-sanctioned cyber activity. This initiative raises critical questions a… Cisco Talos · Aug 20, 2026 High CHoffensive-cybercybercrimeai
threat-intel The Coordination Gap: How Attackers Are Outpacing Law Enforcement The fight against cybercrime is increasingly losing ground due to attackers’ growing coordination and adaptability, outpacing law enforcement’s ability to respond effectively. Carole House, a cybersecurity strategist, ar… Dark Reading · Aug 6, 2026 High cybercrimethreat intelligenceransomware
threat-intel Iran Cyberattacks Against Minnesota Water Systems Preliminary evidence suggests a coordinated cyberattack campaign targeting water systems in multiple US states, with Iran suspected as the source. While no significant damage has been reported, the incident highlights a… Schneier on Security · Aug 4, 2026 Medium USIRcyberattackcritical infrastructureattribution
threat-intel New Tool Traces AI Videos Back to Their Source Researchers at UC Riverside have developed SAGA, a tool designed to trace the origin of AI-generated videos and identify the specific generative model used to create them. The tool goes beyond simple detection, reasoning… Dark Reading · Aug 3, 2026 Medium deepfakeaigenerative-ai
threat-intel Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet Amazon has attributed the September 2025 compromise of npm packages debug and chalk, along with subsequent incidents involving typo-crypto and axios, to North Korea’s Sapphire Sleet group. While initial reports attribute… The Hacker News · Jul 30, 2026 High KPnpmthreat intelligencemalware
threat-intel Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake Cisco Talos has released EvidenceForge, an open-source synthetic security log generator designed to address the limitations of existing synthetic data solutions. The tool utilizes a canonical event model, causal ordering… Cisco Talos · May 27, 2026 Medium synthetic datalog generationthreat hunting
malware Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps A new Android ad fraud scheme, dubbed Trapdoor, has been identified by HUMAN Threat Intelligence, utilizing 455 malicious apps and 183 C2 domains to generate 659 million daily bid requests. The operation leverages malver… The Hacker News · May 19, 2026 High USandroidad fraudmalvertising
malware EDR killers explained: Beyond the drivers This article analyzes the increasing use of "EDR killers" in modern ransomware attacks. These tools, often based on vulnerable drivers or custom scripts, are deployed by affiliates to disrupt endpoint detection and respo… WeLiveSecurity · Mar 19, 2026 High USransomwareedrdrivers