threat-intel Personal Information Exposed in Apollo Global Data Breach Apollo Global Management suffered a data breach due to a social engineering attack, exposing sensitive personal information like names, contact details, and Social Security numbers. The attack was attributed to the UNC6671 and BlackFile cybercrime group, who have been targeting similar organizations in the financial se… SecurityWeek · 6d ago High vishingsocial engineeringdata breach
threat-intel ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories This week's ThreatsDay Bulletin highlights a diverse range of security threats, including AI-related attacks, data breaches, and malware campaigns. Key concerns include GhostJacking, where AI agents are hijacked to execu… The Hacker News · Aug 13, 2026 High CVE-2026-20685USUKSWaiagentjackingdata breach
ransomware ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors This week’s security news is dominated by AI-related threats, including a vulnerability exploited in Metabase, a new Shai-Hulud worm leveraging the MCP Registry, and a Chinese review of Palo Alto Networks. Alongside the… The Hacker News · Aug 10, 2026 High CVE-2026-34348CVE-2026-18497CVE-2026-63508CHransomwaresupply-chainvishing
threat-intel UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data UNC6671, a data extortion group linked to ShinyHunters and potentially SLH, is leveraging sophisticated vishing tactics to steal SaaS data from organizations across multiple sectors. They impersonate IT help desks, direc… The Hacker News · Aug 7, 2026 High NOAUU.vishingphishingdata-breach
threat-intel Vishing Extortion Group UNC6671 Rebrands After Making Millions UNC6671, an extortion group previously known as BlackFile, has rebranded and continued its operations under multiple names (Redact, Pink, Helix, and Falcon) while targeting sectors like financial services and private equ… SecurityWeek · Aug 7, 2026 High vishingphishingransomware
threat-intel Device Code Phishing Up 1,500% in 2026; Vishing Doubles Device code phishing and vishing are experiencing a dramatic surge, driven by state-sponsored and cybercriminal groups, and are proving highly effective at bypassing traditional security measures. CrowdStrike reports a 1… Dark Reading · Aug 4, 2026 High USRUEUphishingvishingdevice-code-phishing
threat-intel Turning the Tables on Email Scammers With 'ScamBuster' ScamBuster is an open-source, AI-driven system designed to turn the tables on email scammers. By mimicking victim personas and engaging with attackers, it gathers valuable intelligence – including financial details and i… Dark Reading · Jul 10, 2026 High aiphishingthreat intelligence
threat-intel Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers Okta has warned of a sophisticated vishing campaign targeting Microsoft 365 customers, primarily through impersonating legitimate Microsoft Entra ID login pages. The campaign, attributed to the O-UNC-066 threat actor gro… SecurityWeek · Jul 10, 2026 High vishingpasskeyphishing
threat-intel Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access A threat actor, linked to the O-UNC-066 group (affiliated with The Com/Scattered Spider), is using a sophisticated, operator-controlled phishing kit to trick users into enrolling fake Microsoft Entra passkeys, gaining un… The Hacker News · Jul 10, 2026 High passkeyphishingvishing
threat-intel Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks The Silent Ransom group is conducting a targeted extortion campaign against US law firms, utilizing a sophisticated multi-stage attack chain involving vishing, IT impersonation, and physical intrusions. Google’s Mandiant… Dark Reading · Jun 8, 2026 High USvishingsocial engineeringremote access
threat-intel UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign UNC3753, also known as Chatty Spider and the Silent Ransom Group, is a threat actor engaged in a financially motivated data theft and extortion campaign targeting organizations in the U.S. between January and May 2026. T… The Hacker News · Jun 8, 2026 High USvishingsocial engineeringdata exfiltration
data-breach Charter Communications data breach affects 4.9 million accounts Charter Communications experienced a data breach impacting approximately 4.9 million accounts following a sophisticated attack by the ShinyHunters extortion gang. The attackers gained access through a voice phishing (vis… BleepingComputer · May 29, 2026 High USCHdata breachvishingsalesforce