threat-intel Red Flags That Expose Fake North Korean IT Workers North Korean operatives are increasingly sophisticated in their attempts to infiltrate organizations by posing as IT workers, often leveraging stolen or fabricated identities and VPNs to mask their locations. Huntress Intelligence, a security firm, has identified multiple instances of this fraud, particularly within th… Dark Reading · 4d ago High CHNEnorth koreanvpnproxy
threat-intel OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation OpenAI has banned a cluster of Russian ChatGPT accounts that were used to run an influence operation, primarily to promote the International Burke Institute (IBI) and its associated website. The operation involved genera… The Hacker News · 4d ago High RUUNCHinfluence operationai manipulationrussian disinformation
ransomware Gunra ransomware: what you need to know The Gunra ransomware gang is aggressively targeting organizations across multiple sectors, leveraging unpatched VPNs and firewalls to gain access and deploy their ransomware. They are demanding payments to decrypt stolen… Graham Cluley · 6d ago High vpnfirewallransomware
threat-intel Cyber actualités ZATAZ de la semaine du 17 au 23 août 2026 This week’s cybersecurity news is dominated by data breaches, ransomware attacks, and widespread data exposures. ShinyHunters is targeting Logitech and Streamlabs, while RingCentral has experienced a massive 1.6 million… ZATAZ · Aug 22, 2026 High FRBESOransomwaredata breachvpn
threat-intel Un recrutement VPN français intrigue sur un forum pirate A Russian cybercriminal forum member is recruiting French speakers to develop a VPN, claiming it is entirely legal. However, the individual's history on the forum – including discussions about buying hacked accounts, spa… ZATAZ · Aug 21, 2026 Medium FRvpnrecruitmentfrance
vulnerability Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers Citrix has released security updates to address two critical vulnerabilities in NetScaler ADC and NetScaler Gateway, including a high-severity authentication bypass. These flaws primarily affect deployments where specifi… The Hacker News · Aug 20, 2026 High CVE-2026-19489CVE-2026-19490CVE-2026-8451authenticationvpnsaml
vulnerability Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler Citrix has announced patches for a critical authentication bypass vulnerability in its NetScaler ADC and NetScaler Gateway products. This flaw, with a CVSS score of 9.3, allows unauthenticated remote attackers to gain ac… SecurityWeek · Aug 20, 2026 Critical CVE-2026-19490CVE-2026-19489patchauthenticationvulnerability
threat-intel Éducation nationale : un pirate annonce une fuite qui exposerait des millions de données A French hacker, ZeroBytes, claims to have exfiltrated 43GB of sensitive educational data from the French Ministry of Education and related institutions. The data includes information on over 2 million students, encompas… ZATAZ · Aug 17, 2026 High FRdata breachfrench educationpassword hashes
vulnerability ANDRITZ HIPASE-250 and 250 SCALA ANDRITZ HIPASE-250 and 250 SCALA devices, versions <=7.20, are vulnerable to several security flaws that could allow an attacker to read stored passwords, access configuration endpoints without authentication, and gain V… CISA Advisories · Aug 13, 2026 High CVE-2026-65309CVE-2026-65310CVE-2026-65311vulnerabilitypasswordauthentication
threat-intel 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One A massive collection of 737 Chrome VPN and proxy extensions are being used to route user traffic through a single SOCKS5 proxy infrastructure, primarily targeting Russian-speaking users seeking access to blocked content.… The Hacker News · Aug 12, 2026 High RUvpnproxychrome
threat-intel Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands Russian state-sponsored threat actors, linked to the Sandworm group, are using fake recruitment campaigns to trick IT professionals in Ukraine into installing malware. They impersonate IT companies like Sopra Steria Bulg… The Hacker News · Aug 11, 2026 High RUUKsocial engineeringvpnrecruitment
threat-intel Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine Polish power plant operators suffered a significant cyberattack that led to the shutdown of a steam turbine and process-water treatment system. The attack exploited a private cellular network used by the grid operator to… The Hacker News · Aug 11, 2026 High CVE-2023-32349CVE-2023-32350PLprivate apnindustrial control systemscyberattack
threat-intel Russian military hackers pose as recruiters to target Ukrainian IT workers Russian military hackers, linked to the Sandworm group (APT44/Seashell Blizzard), are impersonating IT recruiters to target Ukrainian IT workers and install malicious software. The operation involves using legitimate job… The Record · Aug 10, 2026 High UKRUrecruitmentvpnwireguard
ransomware #StopRansomware: Gunra Ransomware The FBI, CISA, and other agencies have issued a joint advisory regarding the Gunra ransomware threat, a sophisticated double-extortion variant derived from the Conti ransomware. Gunra has rapidly expanded through a RaaS… CISA Advisories · Aug 10, 2026 Critical CVE-2024-55591CVE-2025-24472USREransomwaredouble extortionr0aas
vulnerability Vulnérabilité dans SonicWall Global VPN Client (10 août 2026) A vulnerability in SonicWall Global VPN Client allows an attacker to cause a denial-of-service. SonicWall has released a security bulletin and a corresponding CVE to address this issue. CERT-FR · Aug 10, 2026 Medium CVE-2026-66151vpnvulnerabilitydenial-of-service
vulnerability Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses Researchers have discovered a vulnerability in Apple's iCloud Private Relay tool that allows users' real IP addresses to be exposed, even when the tool is active. The issue stems from three WebKit features – DNS prefetch… The Hacker News · Aug 6, 2026 High webkitprivacyip leak
threat-intel QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer A long-standing supply chain attack targeting QuickFox, a VPN tool used by overseas Chinese users, has been ongoing since August 2025. The attack, attributed to tactical overlaps with the Chinese state-sponsored threat a… The Hacker News · Aug 5, 2026 High CNsupply-chainmalwarechina
threat-intel CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability in N-able N-central to its KEV catalog due to active exploitation. This flaw, stemming from incomplete patching of… The Hacker News · Aug 4, 2026 High CVE-2026-18577CVE-2026-18556CVE-2025-8875GEICSWvulnerabilityremote monitoringremote management
vulnerability INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws The INC Ransomware operation has become the dominant threat actor exploiting a series of zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances. Since the beginning of August 2026, the group has been aggressively… The Hacker News · Aug 3, 2026 High CVE-2026-15409CVE-2026-15410AUU.UAzero-dayvpnransomware
threat-intel Read This Before You Buy That TV Streaming Stick A security firm, Bitsight, uncovered a complex and widespread ad fraud network centered around H96 streaming devices. These devices, often sold by major retailers, are secretly used to generate revenue by masquerading as… Krebs on Security · Jul 30, 2026 High CHHOSIiotproxyad fraud