threat-intel Australia Arrests 2 Alleged TeamPCP Hackers Australian authorities have arrested two men linked to the TeamPCP cybercrime group, a notorious organization responsible for stealing over 500,000 corporate credentials and causing significant financial damage. The group exploited software supply chains and package registries to systematically harvest data and funnel… SecurityWeek · 3d ago High AUsupply-chaincredential-theftcybercrime
threat-intel Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows The Mirage2FA campaign, a commercial phishing-as-a-service toolkit, has impacted approximately 4,532 organizations, primarily in the US, by exploiting legitimate Microsoft 365 login flows and bypassing two-factor authent… The Hacker News · 5d ago High USINSGphishingmicrosoftmfa
threat-intel Tricky 'SynkLoader' Multitool May Herald Ransomware A sophisticated new malware family, dubbed ‘SynkLoader,’ is making a comeback of older, effective tactics, including screen locking and phishing, to facilitate ransomware attacks. The malware utilizes a combination of no… Dark Reading · 6d ago High phishingransomwarescreen-locking
supply-chain Trivy, Not LiteLLM Behind the 2,500 Org Compromise A sophisticated supply chain attack, initially linked to the LiteLLM malware, has impacted over 2,500 organizations, primarily through a compromise of the Trivy scanner. The attack, orchestrated by TeamPCP, exploited vul… SecurityWeek · Aug 14, 2026 High GEBRFRsupply-chainvulnerabilitycredential-theft
threat-intel CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps A large-scale phishing campaign, dubbed RecruitTrap, is targeting over 3,000 recruitment-related URLs to steal Google and Facebook credentials, and in some cases, relay MFA prompts in real-time. The campaign uses Browser… The Hacker News · Aug 14, 2026 High phishingbrowser-in-the-browsercredential-theft
threat-intel Un pirate plaide coupable après 165 piratages A Canadian man, Connor Riley Moucka, has pleaded guilty to a massive cloud-based hacking and extortion scheme targeting over 165 organizations. Between February and October 2024, his group exploited stolen credentials to… ZATAZ · Aug 8, 2026 High CAUNSPcloud-securitycredential-theftextortion
threat-intel Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk Kali365 is leveraging a sophisticated phishing kit to compromise US organizations by abusing legitimate Microsoft authentication flows. The kit uses attacker-controlled device codes to trick users into approving access o… The Hacker News · Aug 5, 2026 High USphishingauthenticationmicrosoft
threat-intel Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens The Greatness PhaaS toolkit, a commercial phishing-as-a-service platform, has added device code phishing capabilities, a significant advancement that allows attackers to bypass Multi-Factor Authentication (MFA) and steal… The Hacker News · Aug 4, 2026 High phishingdevice-code-phishingmfa
threat-intel Un pirate revendique un accès au CRM d’ENI A previously unknown cybercriminal, appearing on a dark web forum, claims to have gained access to ENI’s French professional space in October 2025 via phishing, exposing customer data, invoices, and sensitive account man… ZATAZ · Jul 31, 2026 Medium phishingdata-breachcredential-theft
ransomware No Manners Here: The Ruthless Rise of The Gentlemen Ransomware The Gentlemen, a rapidly growing Ransomware-as-a-Service (RaaS) program, has significantly increased its victim count in 2026, becoming the second most active RaaS program globally. Leveraging a 90% affiliate payout stru… Palo Alto Unit 42 · Jul 10, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073USCAGBransomware-as-a-serviceracksedge-device-attack
malware Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT A series of malicious npm packages, disguised as PostCSS tools, have been discovered delivering a Windows-based remote access trojan (RAT). These packages, published by 'abdrizak', leveraged legitimate build tooling to d… The Hacker News · Jun 23, 2026 High USnpmsupply-chainrat
threat-intel What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks Recent breaches attributed to the ShinyHunters cybercrime collective, including attacks on organizations like University of Nottingham and Medtronic, highlight a shift in cyberattack tactics. Attackers are increasingly t… SecurityWeek · Jun 22, 2026 High UKidentity-theftcredential-theftmfa
threat-intel Malicious JetBrains Marketplace plugins steal AI API keys from developers A coordinated malware campaign involving 15 malicious plugins for the JetBrains Marketplace was discovered, designed to steal AI API keys from developers. These plugins, disguised as AI coding assistants and code review… BleepingComputer · Jun 16, 2026 High USapi-keycredential-theftide
threat-intel Ex-school district employee jailed for hacks on former employer A former IT employee, Ezekiel Dean Potter, was sentenced to prison for a prolonged cyberattack against the Saydel Community School District. Potter exploited his previous access to disrupt operations, steal data, and cau… BleepingComputer · Jun 13, 2026 High UScyberattackdata-breachaccount-compromise
threat-intel AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload This article discusses the increasing challenge of AI-powered phishing attacks overwhelming Security Operations Centers (SOCs). Attackers are leveraging AI to create more convincing and varied phishing campaigns, leading… The Hacker News · Jun 8, 2026 High USphishingaisoc
threat-intel Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories A security researcher discovered a flaw in Anthropic's Claude Code GitHub Action that allowed attackers to take over vulnerable public repositories by exploiting a permissive trigger check and prompt injection techniques… The Hacker News · Jun 4, 2026 High prompt-injectiongithub-actionsai-security