threat-intel Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network Berlin's state government is facing an extortion attempt following a data breach of its state network. Rhysida, a threat group, is suspected of stealing 5.79 terabytes of data, including maps and geodata, and the group gained initial access through compromised credentials and exploiting vulnerabilities like Zerologon.… The Hacker News · 2d ago High CVE-2020-1472GEUKdata breachransomwaresupply-chain
threat-intel ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body A Chinese-speaking threat actor exploited a critical vulnerability in ownCloud to steal sensitive nuclear records from a Philippine research body. The attacker used custom Python scripts and open-source tools to gain una… The Hacker News · 2d ago High CVE-2023-49105CVE-2024-28000CVE-2026-53362PHCHvulnerabilitycyberattackdata breach
threat-intel CISA: Most exploited vulnerabilities should have been eradicated decades ago This article highlights a concerning trend: many vulnerabilities that should have been addressed long ago are still being actively exploited. The Register points to a situation where tech companies are now selling soluti… The Register · 2d ago Medium CHIRvulnerabilityphishingransomware
threat-intel Industry that built the problem offers to sell you the solution Several tech companies are grappling with the rising costs associated with AI development and deployment, leading to a paradoxical situation where they are now offering solutions to their customers – often at a premium.… The Register · 2d ago Medium USIRCHaihardwarecybersecurity
threat-intel China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access A Chinese-made router manufacturer, Zhibotong Electronics (ZBT) through its brand Zbtlink, ships routers with two factory-installed implants – SPEAKINGSTONE and DARKLANTERN – that provide unauthenticated remote access to… The Hacker News · 2d ago High CVE-2026-74232CVE-2026-74233CVE-2026-66747CHc2routerfirmware
threat-intel Chinese Routers Sold Worldwide Contain Backdoors Chinese router manufacturer Shenzhen Zhibotong Electronics Co. Ltd. (ZBT) has been selling routers containing multiple backdoors, some dating back a decade, to white-label distributors worldwide. These backdoors, includi… Dark Reading · 3d ago High CHUSRUbackdoorsupply-chainespionage
threat-intel 2,3 millions de détenteurs crypto français ciblés A ZATAZ report has uncovered two separate cybercrime listings offering access to a database of 2.3 million French cryptocurrency holders, containing sensitive information like identities, contact details, addresses, and… ZATAZ · 3d ago High FRcryptokidnappingdata-breach
threat-intel Australia charges two men for TeamPCP supply-chain hacking spree Two men in Perth, Australia, have been charged in connection with their alleged involvement in the TeamPCP cybercrime syndicate, which has been linked to a massive supply-chain hacking campaign targeting over 1,000 organ… The Record · 3d ago High AUsupply-chaincybercrimehacking
threat-intel Australia Arrests 2 Alleged TeamPCP Hackers Australian authorities have arrested two men linked to the TeamPCP cybercrime group, a notorious organization responsible for stealing over 500,000 corporate credentials and causing significant financial damage. The grou… SecurityWeek · 3d ago High AUsupply-chaincredential-theftcybercrime
threat-intel Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Two men, believed to be members of the Australian cybercrime group TeamPCP, have been arrested in Western Australia. TeamPCP is a prolific group responsible for a long-running series of software supply chain attacks, emb… Krebs on Security · 3d ago High AUSOsupply-chaincybercrimeopen-source
threat-intel Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools A new campaign targeting Cambodia is utilizing a sophisticated multi-stage attack leveraging a vulnerable OPSWAT driver to deploy the open-source remote access trojan, Spark RAT. Attackers are using deceptive phishing em… The Hacker News · 3d ago High CVE-2026-36425KHphishingransomwaremalware
threat-intel First Malware Built Specifically for Car Head Units Fuels Botnet Researchers at Kaspersky have identified a new malware specifically designed for car head units, linked to the BadBox botnet. This represents a significant expansion of the BadBox threat, which has previously targeted An… SecurityWeek · 5d ago High CNbotnetmalwaresupply-chain
threat-intel ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More This week saw a surge in high-impact cyberattacks and vulnerabilities, highlighting the increasing sophistication and speed of threat actors. AI is now being weaponized to craft exploit scripts targeting Siemens PLCs, wh… The Hacker News · 6d ago High CVE-2026-19478CVE-2021-27101CVE-2023-34362UNRUvulnerabilitysupply-chainransomware
threat-intel WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords Two new malware families, WordlistLoader and SynkLoader, are being used to deliver the Amatera Stealer via ClickFix phishing campaigns. WordlistLoader reconstructs shellcode for Amatera, utilizing techniques to evade det… The Hacker News · 6d ago High phishingransomwaremalware
threat-intel Corée du Sud : des responsables politiques visés par une fuite A South Korean private certification agency has been hacked, exposing the contact information of high-ranking political figures and highlighting a major cybersecurity risk among third-party providers. Korean authorities… ZATAZ · Aug 22, 2026 High SOKENIcyberattackdata breachidentity theft
threat-intel Pokémon Center touché par la cyberattaque d’un prestataire A cyberattack targeting CEVA Logistics, a third-party logistics provider, has exposed customer data of the Pokémon Center in Europe. This follows a similar incident affecting Steam users and The Pokémon Company, with pot… ZATAZ · Aug 21, 2026 High FRsupply-chainphishingdata-breach
threat-intel In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug This week’s cybersecurity news highlights a range of active threats and vulnerabilities. A severe code injection flaw in Ray-Project Ray is being actively exploited by a Mirai-based botnet, while T-Mobile took drastic ac… SecurityWeek · Aug 21, 2026 High CVE-2025-62593JACAvulnerabilityddosransomware
threat-intel ISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Aug 21, 2026 High phishingransomwaresupply-chain
threat-intel SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted SafePal, a leading crypto hardware wallet manufacturer, suffered a data breach affecting nearly 40,000 customers who placed orders between March 2, 2026 and April 11, 2026. The stolen data included personal information l… The Record · Aug 17, 2026 High data breachcryptocurrencyhardware wallet
supply-chain ChainDrop worm crawls into npm supply chain, evades standard defenses A ChainDrop worm is exploiting vulnerabilities within the npm package manager supply chain, bypassing standard security defenses. This allows attackers to inject malicious code into legitimate packages, potentially compr… The Register · Aug 15, 2026 High supply-chainnpmvulnerability