threat-intel YARA-X 1.20.0 Release, (Sun, Aug 30th) The YARA-X threat intelligence platform released version 1.20.0, incorporating several improvements and bug fixes. Simultaneously, YARA itself received multiple updates (4.5.6, 4.5.7, and 4.5.8) addressing a significant number of bugs. These updates are primarily focused on enhancing the YARA rule engine's stability an… SANS Internet Storm Center · 6h ago Info yarathreat-intelrule-engine
threat-intel L’IA pirate qui promet anonymat et zéro filtre A French-language security news outlet, ZATAZ, tested DONG, an AI service claiming to offer anonymity and unfiltered content generation. The service allows users to create tools like HTML infostealers and generate explic… ZATAZ · 2d ago High aianonymityinfostealer
threat-intel JavaScript obfuscation: From party trick to phishing kit This article from Cisco Talos explores the techniques used to obfuscate JavaScript code, primarily for malicious purposes like phishing and malware delivery. The author details various methods of hiding code, including s… Cisco Talos · 3d ago High obfuscationjavascriptmalware
threat-intel A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th) This article details a sophisticated phishing page that employs a polymorphic obfuscation technique to evade detection. The page initially presents as broken, causing a 30-second delay and high CPU usage, due to a global… SANS Internet Storm Center · 3d ago Medium phishingobfuscationpolymorphism
threat-intel Exploits and vulnerabilities in Q2 2026 Q2 2026 saw a significant surge in the number of registered vulnerabilities, largely driven by the increasing adoption of AI tools for vulnerability discovery. Researchers are now publishing exploits for vulnerabilities… Securelist · 4d ago High CVE-2018-0802CVE-2017-11882CVE-2017-0199vulnerabilitythreat-intelapt
ransomware Gunra ransomware: what you need to know The Gunra ransomware gang is aggressively targeting organizations across multiple sectors, leveraging unpatched VPNs and firewalls to gain access and deploy their ransomware. They are demanding payments to decrypt stolen… Graham Cluley · 6d ago High vpnfirewallransomware
threat-intel Rethinking Application Security for the AI Era The speed at which attackers can now exploit vulnerabilities – thanks to advancements in AI – is dramatically increasing, shrinking the window from vulnerability disclosure to exploit from months to hours. This necessita… SecurityWeek · 6d ago High aivulnerabilitypatching
threat-intel Chess.com : un nouveau pirate revendique 7,3 millions de profils A cybercriminal claims to have stolen a massive dataset from Chess.com, containing 7.3 million user profiles. The data includes email addresses, usernames, user IDs, and various profile details, representing a significan… ZATAZ · Aug 22, 2026 Medium data-breachscrapinguser-data
threat-intel New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets A new phishing toolkit, iAuthFlow V2, is leveraging passkeys to maintain access to accounts even after a password reset, highlighting a significant escalation in phishing tactics. The tool, sold for $10,000, utilizes a s… SecurityWeek · Aug 21, 2026 High phishingpasskeysocial engineering
threat-intel UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities Chinese-speaking intrusion actor UAT-10147 is employing a sophisticated, cross-platform intrusion toolset, SPECTRE, leveraging AI-assisted development to evade detection. SPECTRE is a cross-platform backdoor with Linux r… Cisco Talos · Aug 20, 2026 High CVE-2019-16098CVE-2021-21551CHaiedrlinux
threat-intel No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns A new AI platform called ‘Kriminal’ is raising concerns within the cybersecurity community due to its permissive nature and explicit marketing targeting cybercriminals. Despite claims of being for research and educationa… Dark Reading · Aug 19, 2026 Medium aicybercrimeosint
threat-intel Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware A Chinese-nexus advanced persistent threat (APT) group, suspected to be operating from China, exploited a newly patched VMware vCenter vulnerability (CVE-2026-59310) to deploy Babuk-derived ransomware. The attack involve… The Hacker News · Aug 17, 2026 High CVE-2026-59310CVE-2026-59309CHGEIRaptvulnerabilityransomware
threat-intel Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware Apple is warning users in over 150 countries about potential mercenary spyware attacks, sending notifications via email and in-app alerts. These sophisticated attacks target specific individuals – journalists, activists,… The Hacker News · Aug 14, 2026 High spywaremercenarythreat-intel
threat-intel ZATAZ vérifiera en direct si votre mail est exposé ZATAZ has discovered a massive collection of 1.7 billion French email addresses and passwords, obtained from a darkweb storage space. The data, dating back to 2013, was extracted from a compromised cloud service and repr… ZATAZ · Aug 13, 2026 High FRdarkwebcredentialsphishing
threat-intel À vendre : les coulisses d’un empire du pari A cybersecurity news platform has uncovered a pattern of suspicious activity by a single online seller offering access to vast databases of gambling-related data, including player information, casino prospects, and crypt… ZATAZ · Aug 10, 2026 High AZGEINdata-breachthreat-intelgambling
threat-intel CPDLC over ATN-B1 Vulnerabilities A CISA advisory highlights vulnerabilities in the CPDLC over ATN-B1 protocol, which relies on legacy, unauthenticated radio frequency links. These vulnerabilities allow for message injection, denial-of-service conditions… CISA Advisories · Aug 7, 2026 High CVE-2025-71409CVE-2025-71410CVE-2025-71411vulnerabilitythreat-intelsupply-chain
vulnerability ABB Ability Zenon ABB has issued a security advisory regarding multiple vulnerabilities in its Ability Zenon industrial automation platform. These vulnerabilities, primarily related to MongoDB, could allow attackers to bypass security, cr… CISA Advisories · Aug 6, 2026 High CVE-2025-14847CVE-2020-7928CVE-2020-7921WOvulnerabilitydata-breachmalware
threat-intel New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts Researchers at Palo Alto Networks have uncovered new attack methods that allow malware to steal passkey-protected accounts, bypassing traditional security measures. These techniques exploit vulnerabilities in Chrome’s sy… SecurityWeek · Aug 5, 2026 High passkeyauthenticationchrome
threat-intel Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk Kali365 is leveraging a sophisticated phishing kit to compromise US organizations by abusing legitimate Microsoft authentication flows. The kit uses attacker-controlled device codes to trick users into approving access o… The Hacker News · Aug 5, 2026 High USphishingauthenticationmicrosoft
threat-intel ISC Stormcast For Wednesday, August 5th, 2026 https://isc.sans.edu/podcastdetail/10038, (Wed, Aug 5th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions and a concerning trend of sophisticated phishing attacks leveraging leaked credentials. The report emphas… SANS Internet Storm Center · Aug 5, 2026 High phishingcredential-stuffingbec