ddos Large DDoS attack knocks Norwegian public services offline A massive DDoS attack has severely disrupted several Norwegian public services for over 30 hours, impacting digital identity verification and government data exchange. The attack, the third of its kind since June, is significantly larger than previous incidents and continues to affect critical infrastructure, including… The Record · 5d ago Medium NOddosdhscyberattack
threat-intel ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More This week saw a surge in high-impact cyberattacks and vulnerabilities, highlighting the increasing sophistication and speed of threat actors. AI is now being weaponized to craft exploit scripts targeting Siemens PLCs, wh… The Hacker News · 6d ago High CVE-2026-19478CVE-2021-27101CVE-2023-34362UNRUvulnerabilitysupply-chainransomware
threat-intel In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug This week’s cybersecurity news highlights a range of active threats and vulnerabilities. A severe code injection flaw in Ray-Project Ray is being actively exploited by a Mirai-based botnet, while T-Mobile took drastic ac… SecurityWeek · Aug 21, 2026 High CVE-2025-62593JACAvulnerabilityddosransomware
threat-intel CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification Researchers have uncovered two denial-of-service (DoS) attacks exploiting how Content Delivery Networks (CDNs) handle HTTP/3 traffic, leading to significant amplification of requests and causing severe performance issues… The Hacker News · Aug 20, 2026 High CVE-2026-14456CHSIcdnddoshttp3
threat-intel Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS Evooo1Bot, a Linux botnet derived from Mirai, has significantly expanded its capabilities beyond simple DDoS attacks. It now incorporates advanced features like encrypted C2 communications, SSH brute-force scanning, a re… Dark Reading · Aug 17, 2026 High CVE-2007-3010CVE-2016-6277CVE-2018-14558miraiddosbotnet
threat-intel New Mirai variant adds stealth capabilities to notorious botnet code A new, stealthier variant of the Mirai botnet, dubbed Evooo1Bot, has been actively exploiting vulnerabilities in internet-facing hardware for over a month. This malware boasts advanced features like encrypted communicati… The Record · Aug 13, 2026 High CACHGEmiraibotnetvulnerability
threat-intel Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing A new version of the Kimwolf/AISURU Android and IoT botnet, Kimwolf v7, has been discovered by Palo Alto Networks Unit 42. This version significantly improves its operational resilience and DDoS attack capabilities by ut… The Hacker News · Aug 11, 2026 High botnetddosadb
threat-intel “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI Cisco Talos researchers have discovered that threat actors are increasingly leveraging artificial intelligence (AI) to significantly enhance their malicious capabilities, bypassing traditional safeguards and exhibiting a… Cisco Talos · Aug 4, 2026 High aiartificial intelligencethreat intelligence
threat-intel Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process A new Mirai-derived botnet, Tengu, is leveraging hardware watchdog timers and other persistence mechanisms to re-establish itself on compromised Linux devices, even after defenders attempt to kill its main process. The b… The Hacker News · Jul 28, 2026 High botnetmiraiiot
threat-intel TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Researchers at Palo Alto Networks Unit 42 have uncovered TuxBot v3 Evolution, a developing IoT botnet framework leveraging AI assistance. While the LLM provided some code, it also introduced errors that needed manual cor… The Hacker News · Jul 15, 2026 High iotbotnetddos
threat-intel Guten Tag, Bonjour, Hola to Our European Cyber Defenders! Dark Reading is launching a new section, DR Global Europe, to provide region-specific cybersecurity intelligence tailored for professionals in the EU and UK. This expansion addresses unique cyber threats facing Europe, i… Dark Reading · Jul 15, 2026 High RUUKSPcybersecurityddosransomware
threat-intel 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May. These packages, initially designed as tutoring tools, lo… The Hacker News · Jul 14, 2026 High USbotnetddosproxy
threat-intel Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip Spanish authorities, with assistance from the FBI, arrested a man suspected of aiding pro-Russian hacktivist groups, specifically in facilitating the escape of a Ukrainian hacker linked to CARR. The investigation uncover… The Record · Jul 8, 2026 Medium SPPOBErussianhacktivismddos
threat-intel Ukrainian media outlets now among 'priority targets' for Russian hackers Ukrainian media outlets are increasingly becoming priority targets for Russian hackers as part of a broader campaign to undermine public trust and spread propaganda amid Russia’s ongoing invasion of Ukraine. Recent attac… The Record · Jul 6, 2026 High UKRUcyberattacksukrainerussia
malware RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS A new botnet, RustDuck, is leveraging Rust programming to hijack routers, IP cameras, and servers for DDoS attacks. Developed by QiAnXin's XLab, the botnet utilizes a two-stage approach, exploiting vulnerabilities in dev… The Hacker News · Jun 30, 2026 High CVE-2017-17215CVE-2025-29635CVE-2024-1781CNddosbotnetrust
phishing ISC Stormcast For Monday, June 29th, 2026 https://isc.sans.edu/podcastdetail/9986, (Mon, Jun 29th) The SANS Internet Storm Center's June 29th, 2026 Stormcast reported a heightened level of online threats, primarily focusing on phishing campaigns and malicious email activity. The report highlighted an increase in obser… SANS Internet Storm Center · Jun 29, 2026 Medium phishingemailthreat intelligence
threat-intel Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances In 2025, the Russian-aligned threat actor Gamaredon significantly ramped up its cyberespionage operations targeting Ukraine, utilizing a sophisticated and evolving toolkit. The group, linked to the FSB, employed a combin… WeLiveSecurity · Jun 25, 2026 HighCVSS 8.8 CVE-2025-8088RUcyberespionagerussiaspearphishing
threat-intel ISC Stormcast For Tuesday, June 23rd, 2026 https://isc.sans.edu/podcastdetail/9982, (Tue, Jun 23rd) The SANS Internet Storm Center's Stormcast for June 23rd, 2026, reported a heightened level of online threats and potential disruptions. The broadcast highlighted several ongoing campaigns and emerging vulnerabilities th… SANS Internet Storm Center · Jun 23, 2026 Medium stormcastthreat intelligencephishing
threat-intel ISC Stormcast For Tuesday, June 16th, 2026 https://isc.sans.edu/podcastdetail/9974, (Tue, Jun 16th) The SANS Internet Storm Center's June 16th, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observ… SANS Internet Storm Center · Jun 16, 2026 Medium phishingddosbotnet
threat-intel HTTP/2 Bomb Attacks Put Telcos, Healthcare Orgs at Risk This article reports on the ‘HTTP/2 Bomb’ vulnerability, a denial-of-service exploit leveraging features within the HTTP/2 protocol to amplify junk traffic and cause widespread disruptions. The vulnerability affects a si… Dark Reading · Jun 15, 2026 High CVE-2026-49975UShttp2ddosamplification