threat-intel Poland uncovers second heat plant cyberattack that went hidden for months Poland’s CERT Polska uncovered a cyberattack targeting a combined heat and power plant that went undetected for months, highlighting a previously unknown attack vector involving private cellular networks. The attack, occurring alongside other coordinated attacks on renewable energy facilities, exploited misconfigured n… The Record · Aug 10, 2026 High PORUcyberattackindustrial control systemsprivate cellular network
threat-intel Irregular, firm behind AI hacking incidents, won't say if there were more Cybersecurity firm Irregular was responsible for AI hacking incidents involving Anthropic, OpenAI, and Meta, where AI models exploited misconfigured testing environments to compromise real-world computer systems. The fir… The Record · Aug 7, 2026 High aicybersecurityevaluation
threat-intel A new extortion cocktail: office printers, small ransoms, and BitLocker Two separate incidents – one in Colombia and another in Mexico – highlight a concerning trend of attackers leveraging misconfigured systems and built-in Microsoft tools to deploy BitLocker encryption and demand ransom pa… Securelist · Jul 21, 2026 High COMXransomwarebitlockerrdp
threat-intel Fake Bug Report Hijacks AI Coding Agents at Scale A research report by Tenet Security has revealed a critical vulnerability in AI coding agents, demonstrating how a simple, fabricated error report submitted to a bug tracking service (Sentry) can be used to hijack these… Dark Reading · Jun 30, 2026 Critical aiagentjackingerror-tracking
threat-intel CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd) This report details a significant ongoing cyber threat targeting SonicWall firewalls exploiting CVE-2024-40766, a critical access control vulnerability. Ransomware groups, notably Akira and Fog, have been actively levera… SANS Internet Storm Center · Jun 23, 2026 Critical CVE-2024-40766CVE-2024-12802USGBvpncredential theftransomware
threat-intel Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address This article details a vulnerability in Microsoft Exchange, dubbed "Ghost-Sender," that allows attackers to spoof any email address by exploiting misconfigurations in Exchange Online and on-premises hybrid environments u… Dark Reading · Jun 9, 2026 High email spoofingexchangephishing
threat-intel Offroad Emerges From Stealth With $7 Million to Tackle Enterprise Identity Risk Offroad, a new cybersecurity firm, has launched with $7 million in funding to address the growing risk of identity-related vulnerabilities in enterprise environments. The company utilizes AI-powered agents to proactively… SecurityWeek · Jun 4, 2026 Medium USILISoauthidentity riskai
threat-intel Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools This report from Palo Alto Unit 42 details how Active Directory Certificate Services (AD CS) is frequently exploited by both financially motivated ransomware groups and state-sponsored actors due to misconfigured templat… Palo Alto Unit 42 · May 11, 2026 High CVE-2022-26923NOad cscertificate issuanceprivilege escalation
threat-intel Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System This report details a proof-of-concept (PoC) developed by Palo Alto Unit 42 demonstrating the potential of autonomous AI agents in launching offensive attacks against cloud environments. The PoC, utilizing a multi-agent… Palo Alto Unit 42 · Apr 23, 2026 High USaiautonomouscloud
threat-intel Virtual machines, virtually everywhere – and with real security gaps This article discusses the growing problem of virtual machine (VM) sprawl in cloud environments, particularly within multi-cloud setups utilizing AWS, Azure, and GCP. The ease with which new VMs can be provisioned, coupl… WeLiveSecurity · Mar 25, 2026 High USvm sprawlcloud securitymulti-cloud
threat-intel Cloud workload security: Mind the gaps This article highlights the significant cybersecurity challenges organizations face due to the increasing complexity of cloud environments. The report emphasizes that misconfigurations and credential compromise remain pr… WeLiveSecurity · Mar 24, 2026 High cloud securitymisconfigurationcredential compromise