THE HUNTER’S LEDGER
The Wire
Threat Intelligence Headlines
Recent threat-intel reporting from public sources, refreshed every two hours. Headlines and links only, every item goes to the original publisher. This is aggregation rather than original research. My original research can be found in the reports section.

Updated 10 September 2026, 06:00 UTC · 546 items from the last 30 days

Generated from my own OpenCTI instance, not scraped

The headlines are other people’s reporting, but the pipeline is mine. Every item here comes out of the OpenCTI threat-intelligence platform I run and maintain myself, the same instance that holds the STIX bundles for every report I publish and feeds the blocklists on my own network. It refreshes every two hours, straight from that platform.

Wednesday 9 September 2026
BleepingComputerCisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacksRecorded FutureCISA head says agency must change quickly to prevent the 'worst that could happen'governmentRecorded FutureUS disrupts Xinbi Guarantee marketplace fueling the cyber scam economycybercrimegovernmentMicrosoftPasskey-themed social engineering leads to identity and cloud compromisesocial engineeringRecorded FutureElectronic health record company says customer data stolen in breachcybercrimeprivacySecurityWeekAI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warnsartificial intelligencegoogleSecurityWeekAndroid’s September 2026 Updates Patch 180 Vulnerabilitiesandroidmobile & wirelessRecorded FutureMultiple Chinese hacking groups seen using identical Chrome zero-day exploitchinamalwareSecurityWeekChipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security AdvisoriesamdarmCisco TalosActive exploitation of Cisco Secure Firewall Management Center vulnerabilitiescisco talos antiviruscisco talos malware protectionAlienVaultVwork: Weaponized Open-source Software as an Addon for Gigabudandroid banking trojangigabudAlienVaultGrand Theft Auto VI hype leads to malwaregaminggta6AlienVaultPhishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistencebrowser-in-the-browserhideul.exeRecorded FutureFBI puts its cyber strategy on papercybercrimegovernmentAlienVaultAgents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MFai-orchestrated campaigncve-2026-81578BleepingComputerVeradigm warns of patient data breach after ransomware gang claims attackhealthcareSecurityWeekFortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extensionfortinetnetwork securityBleepingComputerMFA's Weakest Link: Account Recovery Is the New Attack PathRecorded FutureUkraine prosecutor general steps down amid scam call center bribery probecybercrimegovernmentAlienVaultOnce in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Daysbluemoonbrowser-extensionSecurityWeekICS Patch Tuesday: Schneider Electric, Siemens Fix Critical FlawsavevaicsSecurityWeekIvanti Patches Critical Flaws Across Enterprise Security Productsivantinetwork securityBleepingComputerOver 36,000 exposed Plex servers vulnerable to recent flawsPalo Alto NetworksUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructurearktunnelc2SecurityWeekNew Phishing Attack Creates Malicious Pages Inside the Victim’s BrowserphishingSecurityWeekChrome 153 Patches Seventh Zero-Day of 2026chromevulnerabilitiesBleepingComputerNew Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM accessmicrosoftAlienVaultPeeling Back the Layers: Inside Vidar - From Virtualized Code to Stolen Credentialsanti-analysisazure tokensBleepingComputerGoogle warns of new Chrome zero-day bug exploited in attacksgoogle
Tuesday 8 September 2026
Recorded FutureMicrosoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploitedCisco TalosMicrosoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiespatch tuesdayRecorded FutureScammer behind $245 million crypto heist pleads guilty to RICO chargescybercrimegovernmentBleepingComputerDoppelCart fraud network uses 119,000 fake shops to steal credit cardsBleepingComputerHackers breach F5 BIG-IP APM devices to deploy Linux rootkitSecurityWeekMicrosoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Daysmicrosoftpatch tuesadySecurityWeekAdobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Dayadobecve-2026-75650Zero Day InitiativeThe September 2026 Security Update Reviewblog postBleepingComputerMicrosoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysmicrosoftRecorded Future‘White hat’ hackers take $47 million bounty after $320 million crypto theftcybercrimeAlienVaultRedis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Filesbotnetcron-injectionAlienVaultInside a Packed Android RAT Loaderaccessibility abuseadb propagationSecurityWeekHackers Return $263 Million Stolen From Liquid NetworkbitcoincybercrimeBleepingComputerShinyHunters hackers claim breach of Florida "DAVID" DMV databaseBleepingComputerSAP warns of maximum severity 'OVERPASS' kernel vulnerabilitySecurityWeekSAP Patches Critical Extended Passport Processing Vulnerabilitycve-2026-44756sapGoogleGTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AIthreat intelligenceBleepingComputerAdobe fixes critical Magento zero-day exploited to backdoor serversSecurityWeekParty’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin TheftbitcoincybercrimeRecorded FutureFrench prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattackcybercrimeAlienVaultMacSync: The Evasive macOS Stealer Exploiting ClickFix LuresapplescriptclickfixBleepingComputerHackers build AI frameworks for widescale credential theftartificial intelligencegoogleSecurityWeekMikroTik Patches Critical Flaws Chained to Hack Routersmikrotiknetwork securitySecurityWeekMathspace Data Breach Exposes Over 1 Million Peopledata breachesmathspaceSecurityWeekN-able Patches Critical Zero-Day in N-centralcve-2026-86218n-centralCisco TalosClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Managercisco talos antiviruscisco talos malware protectionCisco TalosClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2cisco talos web filteringthreat spotlightBleepingComputer220 million traveler records exposed in Vietnam-linked APIS leakCrowdstrikeSeptember 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEsexposure management
Monday 7 September 2026
AlienVaultBypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxycredential harvestinggoogle infrastructure abuseAlienVaultTracking BigBear 2.0 Evilginx2 Phishing Campaignbigbearbigbear 2.0BleepingComputerMagento StyleSmuggler zero-day exploited to deploy Linux backdoorBleepingComputerBigBear Microsoft 365 phishing service bypassed MFA at 258 organizationsBleepingComputerMathspace discloses data breach affecting over 1 million peopleAlienVaultPEEP: A Browser RAT Posing as a Chrome Extensionbrowser extensionchrome ratBleepingComputerTrezor data breach impact now reaches 81,000 customersSecurityWeekNightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day ExploitscrowdstrikeexploitSecurityWeekNorth Korean Hackers Deploy New Linux Espionage ToolkitlinuxmalwareSecurityWeekOpenAI Agents Hijack Another Victim Websiteartificial intelligenceattacksSecurityWeekAdobe Commerce Zero-Day Exploited to Backdoor Online StoresvulnerabilitiesRecorded FutureBerlin investigates new data leak after hackers publish stolen login credentialscybercrimegovernmentSecurityWeekModified ScreenConnect Clients Used in Worm-Like CampaignmalwarescreenconnectBleepingComputerHackers exploit new MikroTik RouterOS flaws to hijack routershardwareBleepingComputerConnectWise warns of new ScreenConnect flaw without patchAlienVaultKimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolveai-generated decoyskimsukyBleepingComputerN-able patches max severity N-central flaw amid ongoing attacks
Sunday 6 September 2026
BleepingComputerAttackers conceal phishing lures using invisible Unicode charactersAlienVaultREVSTEALER ramps up: analysis of up-and-coming infostealerapp-bound-encryptioncredential-theftAlienVaultBengalSEO Part 1: Anatomy of the Operationblack hat seogarage2global
Saturday 5 September 2026
AlienVaultStyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attackadobe commercebackdoorBleepingComputerOver 5,400 hacked sites serve ClickFix payloads stored on the blockchainSecurityWeekElementor Pro WordPress Plugin Vulnerability Exploited to Hack Sitesapplication securityvulnerabilities
Friday 4 September 2026
BleepingComputerIDScan sued over alleged data breach affecting 153 million driverslegalAlienVaultDPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectorscurlratdprk aptSecurityWeekIn Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuationin other newsnetwork securitySecurityWeekHPE Patches Critical RCE Vulnerabilities in AOS-CXnetwork securityRecorded FutureUS, Britain to coordinate on scam center takedownscybercrimegovernmentBleepingComputerCritical Citrix NetScaler auth bypass now leveraged in attacksRecorded FutureUK account-hack losses surge as new reporting system exposes hidden casescybercrimegovernmentBleepingComputer39 New Methods That Compromise Passkey AuthenticationSecurityWeekSangoma Switchvox Vulnerabilities Exploited in the WildvulnerabilitiesBleepingComputerNew CrowdStrike 'FalconFlank' zero-day grants SYSTEM privilegesAlienVaultAngry Birds: Toy Ghouls’ new toysbabukbackdoorSecurityWeek12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeovercve-2026-6471postgresqlBleepingComputerGoogle warns of new Chrome zero-day flaw exploited in attacksSecurityWeekVMware Workstation and Fusion Updates Patch Critical Vulnerabilitycve-2026-59346vmwareSecurityWeekGoogle Patches 6th Chrome Zero-Day of 2026chromevulnerabilitiesAlienVaultAttack Cases in Korea Involving the Installation of Radmin and UltraVNCnetch-gatewayproxy abuseGoogleWhat’s new with Google Cloudgoogle cloudinside google cloudElasticData access: the hidden cost of security vendor lock-insecurity operationssoc
Thursday 3 September 2026
AlienVaultContagious Interview steps outside the developer workflowfake job interviewmacosBleepingComputerFrench hospital fined €500,000 after breach exposes data of 727,000healthcarelegalBleepingComputerCoder's registry infrastructure compromised to push malicious modulesRecorded FutureLarge group of Serbian opposition, activist figures targeted with spywareprivacyBleepingComputerHPE patches critical ArubaOS-CX remote code execution flawCisco TalosThe story behind the intelligencethreat source newsletterAlienVaultChinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asiaai-assisted intrusionsfengtai governmentMicrosoftASCII smuggling crosses over from AI prompt injection to phishing evasionphishingsocial engineeringSecurityWeekManchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusalcybercrimedata breachesBleepingComputerCritical Elementor Pro flaw exploited to take over WordPress sitesBleepingComputerYour Employee’s Password Appeared in an Infostealer Log. Now What?AlienVaultNode.js: Old Technique Makes a Comebackadaptixc2asukastealerRecorded FutureUS and Canadian court data exposed in Thomson Reuters breachcybercrimeprivacyBleepingComputerPlex warns users to patch security vulnerabilities immediatelySecurityWeekOver 3 Million WordPress Sites Affected by Migration Plugin Vulnerabilitycve-2026-19949vulnerabilitiesSecurityWeekCisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilitiesciscocve-2026-20354Palo Alto NetworksAttackers Expose Ongoing AI Tool Use Targeting Organizations in Latin Americaagentic aichatgptAlienVaultRogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activitycryptocurrency minerrmm abuseAlienVaultFake Software Installers Disable Windows Update and Weaken Microsoft Defenderchinese threat clusterdefender exclusions
Wednesday 2 September 2026
MicrosoftImpersonating IT support: how threat actors turn a remote session into enterprise-wide accessBleepingComputerHackers exploit Sangoma Switchvox flaw to deploy reverse shellsBleepingComputerWordPress backup plugin flaw exposes millions of sites to takeover attacksRecorded FutureRussian national facing 20 years for malware campaign that infected 80,000 freelancerscybercrimemalwareAlienVaultInside The Gentlemen: Undisclosed TukTuk C2 Framework and EDR Neutralization Researchbyovddefense sectorRecorded FutureHealth data of more than 9.5 million people leaked from Aesto record systemcybercrimemalwareBleepingComputerHackers exploit critical JFrog Artifactory flaw to forge admin tokensRecorded FutureNew pro-Ukraine hacker group targets Russian companies with custom ransomwarecybercrimegovernmentBleepingComputerRansomware protection for MSPs: A 6-point checklist for faster recoveryAlienVaultGaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon3snakealphaagentAlienVaultUncovering StreamRat: From Meta Ads to Full Device Takeoveraccessibility servicesandroidAlienVaultInside Knight Office, a New M365 AiTM Phishing Kitaitmcredential harvestingRecorded FutureHackers expose donor data from Russian fundraisers for Ukrainians, political prisonerscybercrimeSecurityWeekRockwell Automation Patches Over a Dozen Vulnerabilities Across Productsicsics/otBleepingComputerDropbox accounts breached through Lenovo email verification flawcloudSecurityWeekExploit Published for Fresh Cleo Harmony Vulnerabilitycleopoc exploitPalo Alto NetworksAn AI-Assisted Cyber Attack: Inside a Unit 42 Investigationagentic aifrontier aiAlienVaultHackers Weaponize Microsoft Teams Help Desk Calls for Malware and Network Lateral MovementAlienVaultSality's P2P Network Turned Against Itself, Cutting Off New Malware Payloadsbotnet takedownclipperSecurityWeekChrome and Firefox Updates Patch Dozens of VulnerabilitieschromefirefoxBleepingComputerUS charges Russian for infecting 80,000 freelancers with malwareSecurityWeek23-Year-Old Sality P2P Botnet DisruptedbotnetdisruptedBleepingComputerSality botnet infrastructure dismantled in joint global takedownBleepingComputerSonicWall warns of actively exploited SMA1000 zero-day flawsSecurityWeekSonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacksexploitedsma1000CrowdstrikeCrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacksendpoint security & xdrCrowdstrikeCrowdStrike Delivers the Next Evolution of the Agentic SOCagentic socCrowdstrikeCrowdStrike Announces Agentic Identity Providernext-gen identity security
Tuesday 1 September 2026
AlienVaultOne leftover build path links an infostealer, a remote-access tool, and a ransomware familyamsi evasionbuild path attributionMicrosoftCounterfeit installers to system compromise: Tracking a deceptive software download campaignmalwareKrebs on SecurityFBI Probes Service Selling 153M+ Drivers Licensesa little sunshinecyberaBleepingComputerHackers abuse Faronics Deploy admin tool to install ScreenConnectRecorded FutureChina's 'Fire Ant' campaign used compromised Cisco routers as platform for more attackschinaBleepingComputerAesto Health says data breach affects over 9.5 million patientshealthcareSecurityWeekSevii Targets AI-Speed Attacks With Preemptive Autonomous Defenseincident responseAlienVaultThe Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RATazure table storagecredential theftBleepingComputerCritical Langflow flaw exploited to steal OpenAI and AWS keysRecorded FutureHealthcare facilities operator Nutex says patient, employee data stolen in August incidentcybercrimeindustryBleepingComputerHackers push malicious Virtualizor update in BGP hijacking attackBleepingComputerNovocure data breach affects more than 1,400 cancer patientshealthcareBleepingComputerNearly 22,000 Microsoft Exchange servers vulnerable to hijack attacksmicrosoftSecurityWeekExperiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollarsartificial intelligenceexploitRecorded FutureIranian cyber spies target aviation, fintech developers with new malwarecybercrimeSecurityWeekHackers Start Exploiting Critical Langflow Vulnerabilityartificial intelligenceexploitedSecurityWeekRansomware Gang Claims Nutex Health Data Breachdata breachesgentlemenSecurityWeekCritical JFrog Artifactory Vulnerability Reportedly Exploited in the WildexploitedjfrogBleepingComputerFive Venezuelans plead guilty to ATM jackpotting attacks in USSecurityWeek9.5 Million Impacted by Aesto Health Data Breachaesto healthdata breachesSecurityWeekWatchGuard Patches Critical VulnerabilitiespatchrceAlienVaultSwitches to Node.js and JavaScript malwareaviation sectorazure infrastructureAlienVaultMirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware setaviation sectorazure infrastructureBleepingComputerRecently patched PaperCut zero-days used in data theft attacksAlienVaultFinancially Motivated Threat Actor Targets Brazilai-assisted malwarebanking softwareAlienVaultFinancially Motivated Threat Actor BREEZE COMET Targets Brazilai-assisted malwarebanking softwareSecurityWeekPaperCut Exploitation Escalates to Active IntrusionsexploitedpapercutCrowdstrikeCrowdStrike Falcon Guardian Defines the Next Generation of AI Securitysecuring ai
Monday 31 August 2026
BleepingComputerCronos blockchain restarts after $74 million Tectonic exploitcryptocurrencyAlienVault13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seedscredential exfiltrationcryptocurrency theftRecorded FutureFraudsters steal $6 million from Tectonic crypto platform after inflating token pricecybercrimeBleepingComputerMicrosoft warns of TerminalFix attacks deploying reverse tunnelsAlienVaultAnatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystemagentev2ai-powered cybercrimeAlienVaultToolkit: AI-Assisted Development and Persistent Threat Operationsai-assisted-developmentbehavior-based-detectionAlienVaultShai-Hulud Trinitite Hits @7nohe/openapi-react-query-codegencredential-theftgithub-actionsAlienVaultSkimming on the Blockchain: A Magecart Campaign That Uses EtherHiding, Found by Malvertising Scanningblockchain abusecard-skimmingBleepingComputerChinese Fire Ant hackers turn Cisco routers into spying platformsRecorded FutureBerlin says it won’t pay ransom after hackers steal government datacybercrimegovernmentSecurityWeekNightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploitchaotic eclipseendpoint securityAlienVaultBreaking the Seal: Static Deobfuscation of JSCeal's Compiled V8 Bytecodebrowser theftcryptocurrency stealerSecurityWeekServiceNow Patches 3 Critical Code Injection VulnerabilitiespatchedservicenowBleepingComputerBerlin confirms data theft after Rhysida ransomware attack claimsgovernmentSecurityWeekMcKesson Confirms Data Breach as Attacker Deadline Loomsdata breachesextortionSecurityWeekAnthropic Warns Claude Users of Infostealer Malware Infectionsartificial intelligenceanthropicSecurityWeekCritical Ruby on Rails Vulnerability in Attackers’ Crosshairsexploitedruby on railsAlienVaultValleyRAT is spreading disguised as adwareadware disguisebackdoorAlienVaultAn Inside Look at Voice Phishing Campaigns in Microsoft Teamsdomain controllermicrosoft teamsSecurityWeekExtortion Group Claims Manchester Airports Group Data Breachairportdata breachesPalo Alto NetworksSpring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teamscloaked ursaentra idAlienVaultReal-time Open Source Software Supply Chain Securitybinding.gypgithub actionsSecurityWeekBerlin Won’t Pay Extortion Group Claiming Data Theftberlindata breachesSecurityWeekMore Details Emerge on Exploited PaperCut VulnerabilitiesexploitedpapercutCrowdstrikeAgents of Chaos: A New $100K Agentic Security Challengesecuring aiAlienVaultCampaign deploys a reverse tunnel through multistage intrusionactive directory reconnaissanceclickfix
Sunday 30 August 2026
BleepingComputerFulcrumSec claims Manchester Airports hack, theft of 86 GB of dataBleepingComputerAnthropic warns infostealer malware is hijacking Claude sessions to drain usageartificial intelligence
Saturday 29 August 2026
SecurityWeekHasbro Data Breach Exposed Employee Personal Informationdata breacheshasbroMicrosoftTerminalFix campaign deploys a reverse tunnel through multistage intrusionclickfixAlienVaultStill Circling: Inside the Operator Behind the GitHub LoaderasyncratautoitAlienVaultFake MP4 File Carries Malicious Payloadcloudflareencrypted payload
Friday 28 August 2026
BleepingComputerMcKesson discloses breach after ShinyHunters claims patient data thefthealthcarePalo Alto NetworksPerturbation Probing: A New Diagnostic for the Fragility of LLM Safetyartificial intelligenceinsightsBleepingComputerPaperCut releases second emergency patch for exploited flawsBleepingComputerGiveWP WordPress donation plugin flaw lets hackers execute server commandsRecorded FuturePaperCut warns of hackers using printer management software flaw in attackscybercrimeindustrySecurityWeekIn Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctionsin other newsvulnerabilitiesAlienVaultA fake resume invoked China's defence-tech elite, then installed VShellacademic lurebeijing institute of technologyBleepingComputerAI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?SecurityWeekATF Confirms Cyber Incident After Ransomware Group Claims AttackatfqilinBleepingComputerOver 8,300 Gitea servers vulnerable to code execution attacksSecurityWeekOpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systemsartificial intelligencecisa kevBleepingComputerToy-making giant Hasbro disclose data breach affecting employeesAlienVaultJuly 2026 Threat Trend Report on APT Attacks (South Korea)aptautoitBleepingComputerServiceNow warns of three max severity security vulnerabilitiesSecurityWeekPaperCut Releases Emergency Patch for Exploited Zero-DayexploitedpapercutAlienVaultOpen Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruptionbotnetc2 infrastructure
Thursday 27 August 2026
AlienVaultAttacks on AI Infrastructure: 90-Day Honeypot Telemetryai infrastructurecredential theftAlienVault19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloadsbrowser extensionscredential harvestingAlienVaultInside the AsyncAPI Supply Chain Compromiseasyncapici/cd pipeline exploitationAlienVaultImplants in the Supply ChainbackdoordarklanternAlienVaultHow guardrails might become the attacker's best friendagentic socai guardrailsBleepingComputerNearly 700 rogue AI agents coordinated in the Hugging Face attackartificial intelligenceRecorded FutureWhite House bans foreign-made equipment for power generation over cyber backdoor concernscybercrimegovernmentCisco Talos“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friendthreat source newsletterAlienVaultDefense and Diplomacy Targeted with HOOKEDGEapt28diplomatic targetingBleepingComputerPaperCut warns of NG, MF flaw exploited in zero-day attacksBleepingComputerManchester Airports Group says hackers stole travelers' dataBleepingComputerAustralia arrests alleged TeamPCP hackers behind supply-chain attackslegalAlienVault‘The Gentlemen’ Profile: Why This Ransomware Group Wants In Before It Locks You Outasia-pacificdata-exfiltrationRecorded FutureAustralia charges two men for TeamPCP supply-chain hacking spreecybercrimemalwareSecurityWeekAustralia Arrests 2 Alleged TeamPCP HackersarrestedaustraliaRecorded FutureDOJ firearms agency says hackers breached system containing investigation targetscybercrimegovernmentSecurityWeekOpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hackartificial intelligencehugging faceBleepingComputerCarhartt data breach exposes information of 12.9 million accountsKrebs on SecurityTwo Alleged ‘TeamPCP’ Hackers Arrested in Australiaaikido securitybreadcrumbsCisco TalosJavaScript obfuscation: From party trick to phishing kittool talkBleepingComputerCISA orders feds to patch Citrix NetScaler RCE flaw by SaturdaySecurityWeekUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attackschinachina aptBleepingComputerATF confirms “major incident” after recent Qilin breach claimsAlienVaultAI-Powered PhaaS Supply Chainai voice phishingapple activation lockAlienVaultCaught in 4K: The Aurora Filesactive directory compromiseadcs exploitationSecurityWeekPro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital ServicescybercrimecyberwarfareSecurityWeekRecent Citrix NetScaler Vulnerability Exploited in the Wildcisa kevcitrix
Wednesday 26 August 2026
AlienVaultInside cyber espionage infrastructurechina-nexuscritical infrastructure targetingAlienVaultInhospitable: Tracking Russian Cyber Espionage Infrastructurecredential harvestingdevice code phishingBleepingComputerCritical Avada WordPress theme flaw enables zero-click RCERecorded FutureExclusive: NSA to host a hacker reunion in bid to rebuild secretive unitgovernmentleadershipBleepingComputerNew GPUThor attack defeats NVIDIA ECC protection for root accesshardwareAlienVaultPhilippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilitieschinese-speaking operatorcve-2023-49105AlienVaultExpands Toolset With New Backdoor, SSH Tunnelbackdoorcyber-espionageAlienVaultDark Caracal Reloaded: New Malware, Same Hunting GroundsasiogatebandookRecorded FutureUS takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and SenatechinagovernmentRecorded FutureIran-linked hackers expand infrastructure across Europe and Middle East, report sayscybercrimemalwareSecurityWeekAI Speeds Up Malware Development, Not Its Success Rate: Analysisartificial intelligenceai malwareBleepingComputerHackers target Microsoft SharePoint RCE chain with PoC exploitBleepingComputerFBI disrupts proxy network enabling Chinese espionage operationsBleepingComputerUbiquiti patches three max severity security vulnerabilitiesSecurityWeekAdobe and Nvidia Patch Dozens of VulnerabilitiesadobenvidiaAlienVaultRMM Phishing Campaign: Malware Analysiscanada revenue agencyfake tax documentsSecurityWeekCISA: Over 100 Internet-Exposed Water Systems Targeted in July CyberattackscisaicsBleepingComputerHackers now exploit critical Gitea flaw in code injection attacksCisco TalosChoose your fighter: Balancing competing requirements to select models for your AI SOCartificial intelligencetool talkSecurityWeekChrome 152 Patches Over 300 VulnerabilitieschromepatchesSecurityWeekSensitive Information Exposed in Nutex Health Data Breachdata breacheshealthcareAlienVaultFortinet Vulnerability CVE-2026-35616 and EKZ Stealer, Attacking Obfuscating Compilers with Binary Ninja Workflowsbinary ninjacontrol-flow flatteningSecurityWeekCISA Warns of Exploited Gitea Vulnerabilitycisa kevexploitedAlienVaultClickFix Phishing Hidden in Malicious npm Packagesclickfixcloudflare captcha
Tuesday 25 August 2026
BleepingComputerLACMA data breach last year exposed social security and medical dataBleepingComputerHackers abuse npm mirrors to host phishing redirect pagesRecorded Future58 arrested in international cybercrime crackdowncybercrimegovernmentBleepingComputerAnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodesappleartificial intelligenceRecorded FutureEmployee benefits platform Paylogix says hackers stole financial and health datacybercrimeprivacyAlienVaultWhat the Source Leak Says About HookBotandroid banking trojanblackrockBleepingComputerMassive DDoS attack disrupts Norway’s government digital servicesBleepingComputerHospital operator Nutex Health says data stolen in cyberattackhealthcareSecurityWeekWordPress Websites Targeted via MiniOrange Plugin VulnerabilitiesexploitedminiorangeBleepingComputerHackers breached over 270 Zimbra servers in ongoing attacksRecorded FutureLarge DDoS attack knocks Norwegian public services offlinecybercrimegovernmentSecurityWeekFirst Malware Built Specifically for Car Head Units Fuels Botnetandroid malwarebadboxBleepingComputerPolice arrests dozens of suspects in global cybercrime crackdownPalo Alto NetworksThe State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic ExecutionbackdoorbitcoinCisco TalosThe safety penalty: Reclaiming operational sovereignty in the age of AIlanding page top storyon the radarSecurityWeekSilent Patches Don’t Stop Attackers—They Blind DefenderspatchesvulnerabilitiesSecurityWeekCISA Warns of Exploited Oracle WebLogic Vulnerabilitycisa kevexploitedAlienVaultTracking PavinLoader across ClickFix and fake download campaigns.net loaderamatera stealerAlienVaultFake GTA 6 Extended Look and demo sites deliver an infostealerbrowser data theftcredential theftAlienVaultFake security scans trick victims into uninstalling their antivirusantivirus removalfake security scanAlienVaultExtended Rapid Response: RecruitTrap Recruit Scams are Targeting Enterprise Credentials on Mobilebrowser-in-browsercredential-harvestingElasticInside Elastic's agentic SOC: How we took AI alert triage from 60% to 92% accuracysecurity-labs
Monday 24 August 2026
Recorded FutureUS sanctions Iranian cyber actors as UK discloses power plant attackgovernmentnation-stateAlienVaultA ClickFix cluster: Observed activity from recent ClickFix campaignsclickfixdead drop resolverAlienVaultTen Minutes to Containment: How Agentic MXDR Scoped a Fake Claude Desktop Intrusionblockchain c2claude desktopBleepingComputerUnpatched Calix flaw lets hackers bypass NAT to expose internal deviceshardwareBleepingComputerHackers target WordPress sites in miniOrange auth bypass attacksRecorded FutureIndian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderlycybercrimeSecurityWeekReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limitedcybercrimedata breachesBleepingComputerReliaQuest confirms failed data-theft attack after ShinyHunters breachBleepingComputerSouth Korean startup platform breach exposes key management failuresRecorded FutureHackers infecting Android car systems to build proxy botnetcybercrimemalwareAlienVaultAnatomy of a macOS ClickFix Crimekit that Weaponises EtherHidingamosamos stealerSecurityWeek91 Vulnerabilities Patched in Spring Application FrameworkspringvulnerabilitiesBleepingComputerCISA orders urgent patching of actively exploited Zimbra flawSecurityWeekPersonal Information Exposed in Apollo Global Data BreachapollocybercrimeSecurityWeekIran-Linked Hackers Shut Down UK Power Plant for Four Dayscritical infrastructurecyberattacksElasticHow a team of entity maintainers monitors, connects and scores entities in Elastic Securitysecurity-labs
Sunday 23 August 2026
BleepingComputerToxicPanda Android malware uses VPN permissions to block Google Playmobile
Saturday 22 August 2026
BleepingComputerHackers infect Android car head units with proxy botnet malwarehardwareBleepingComputerNamed Pipes Under Attack: Securing Windows Interprocess Communication
Friday 21 August 2026
Palo Alto NetworksConnecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainchaindropinsightsRecorded FutureLawmakers call for investigation into impact of CISA staffing cutsgovernmentleadershipBleepingComputerNew SynkLoader malware pushed in Microsoft Teams phishing campaignSecurityWeekFormer NSA Director Paul Nakasone Launches National Security Advisory FirmuncategorizedRecorded FutureU.S. Bank says breach claims related to fourth-party incidentcybercrimeBleepingComputerHundreds of leaked AWS keys give full control over corporate accountscloudSecurityWeekIn Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bugin other newsvulnerabilitiesRecorded FutureCanada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolencybercrimeprivacySecurityWeekNew Phishing Toolkit Uses Passkeys to Maintain Access After Password Resetsphishingphishing kitRecorded FutureRussian network monitoring firm confirms cyberattack claimed by pro-Ukraine hackerscybercrimeSecurityWeekCritical Isolated-vm Vulnerability Leads to RCE on Hostisolated-vmvulnerabilitiesBleepingComputerCISA orders feds to patch actively exploited TrueConf Server flawsBleepingComputerMicrosoft warns of max severity Entra ID flaw exploited in attacksmicrosoftBleepingComputerHackers abuse FTP server banners to deliver new Windows malwareBleepingComputerSickKids data breach exposes employee and job applicant infoSecurityWeekRust Supply Chain Attack Linked to North Korean HackersarrayrefmalwareAlienVaultHead Mare APT Group exploits vulnerabilities in unpatched TrueConf server to deliver PhantomCore malware to conference participantsbackdoorhead mareSecurityWeekCISA Urges Immediate Patching of Exploited TrueConf Vulnerabilitiescisa kevexploitedAlienVaultSynkLoader: when you throw in everything but the kitchen sinkcredential phishingfake lock screen
Thursday 20 August 2026
AlienVaultSupply Chain Attack on arrayref: Significant Overlap with DPRK Campaignsbackdoorcompile-time executionAlienVaultPopular Rust Crates Compromised in Build-Time Supply Chain Attackbackdoorbuild-time executionRecorded FutureChina’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malwarecybercrimenation-stateCisco TalosIs Cyber missing the Marque?threat source newsletterBleepingComputerHackers poison arrayref Rust crate to push infostealer malwareAlienVaultHow Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else's Productastroproxybackconnect infrastructureAlienVaultDistinct Clusters Target Individuals of Interest to Russiaapp password phishingatomicAlienVaultN4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for itai infrastructure targetingcloudflare tunnelsAlienVaultInside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asiaanydeskchrome extensionAlienVaultBRIDGEHEAD: An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealerbrowser-credentialscryptocurrency-stealerSecurityWeekHackers Target Zimbra Servers in Active Exploitation CampaignexploitedvulnerabilitiesBleepingComputerCritical Elementor Pro bug exposes WordPress sites to RCE attacksBleepingComputerHow MSPs can catch phishing attacks email filters missGoogleGoing with the Flow(s): Distinct Clusters Target Individuals of Interest to Russiathreat intelligenceSecurityWeekThreat Actor Hacks 14,000 IP Cameras in Ukraine and RussiacameradahuaSecurityWeekAtlassian, Splunk Patch Dozens of Critical, High-Severity VulnerabilitiesatlassianpatchesBleepingComputerCitrix urges admins to patch new NetScaler flaws as soon as possibleSecurityWeekMLflow Vulnerability Exploited for Cloud Credential TheftexploitedmlflowSecurityWeekCisco Patches Critical Crosswork, Secure Workload VulnerabilitiesciscopatchesAlienVaultChinese-speaking adversary integrates agentic AI into post-compromise operationsagentic aibadiisAlienVaultBlend between Banking Malware & Spywareandroidbanking trojanAlienVaultBack-to-School Cyber Risks Surge as Education Remains the World's Most Attacked Sectorapac attacksback-to-schoolSecurityWeekAI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hackingartificial intelligenceics/otBleepingComputerCISA warns of hackers exploiting critical MLflow vulnerabilityBleepingComputerNew Manic Android malware can exfiltrate data through nearby devicesmobileCisco TalosUAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilitiesthreat spotlightCisco TalosUAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operationsthreat spotlightPalo Alto NetworksIdentity Abuse Through Trusted Communication Channelsauthenticationidentity theftBleepingComputerCritical Zimbra RCE flaw now actively exploited in attacksSecurityWeekExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalercitrixnetscalerSecurityWeekCritical GitLab Flaw Exploited Shortly After DisclosureexploitedgitlabAlienVault41 deceptive download sites show a real link, then send you somewhere elseaffiliate fraudbait-and-switchAlienVaultSilkParasite: Tracking a China-Nexus APT Across Central Asiabloodalchemycentral asiaSecurityWeekHackers Using AI to Target Siemens PLCs in Critical US Sectorsartificial intelligenceicsCrowdstrikeCrowdStrike Named Strongest Overall Leader in 2026 Frost Radar™: Cloud Workload Protection Platformscloud & application securityAlienVault77 Firefox Extensions Linked to Crypto Wallet and Credential Theftbrowser extension campaigncloudflare workers
Wednesday 19 August 2026
BleepingComputerRogue ransomware affiliate poses as data recovery firm to steal paymentsBleepingComputerSakura Internet hack exposes data of up to 1.36 million accountsAlienVaultGrandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaignanti-analysisbanking trojanAlienVaultBackdoor delivered through software updatesadblockerbackdoorBleepingComputerHealthtech firm CareCloud data breach impacts 3.7 million patientshealthcareRecorded FutureElectronic health record company CareCloud says 3.7 million people affected by breachcybercrimeBleepingComputerHackers compromise 14,500 Dahua web cameras in 35-day campaignhardwareRecorded FutureNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologycybercrimegovernmentBleepingComputerUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureAlienVaultPost-DEF CON Phishing Uses Malicious Google Doc to Deliver Malwareamosatomic macos stealerBleepingComputerUS charges Iranian hackers over $3.4 billion intellectual property theftlegalAlienVaultScammers are using fake crypto AML checkers to drain your walletcrypto scamcryptocurrencyAlienVaultBalonx Sistema: The Face Behind the PhaaS Affecting Mexican Bankingai vishingandroid ratBleepingComputerPassword spraying attacks surge 155x as hackers exploit MFA gapsAlienVaulthttps://malbearlabs.com/shadow-hvnc-and-shadow-loader-the-kit-that-protects-its-license-better-than-its-customers-dd99520b6af3Recorded FutureUS charges Iranians for sprawling hacking campaign on government agencies, universitiescybercrimenation-stateSecurityWeekUS Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of ThemchargedcyberwarfareAlienVaultFrom ClickFix to MaaS: Exposing a Modular Windows RAT and Its Admin Panelclickfixcryptocurrency theftSecurityWeekCl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaigncl0pdata breachesSecurityWeekCISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple VulnerabilitiesapplecisaBleepingComputerCritical RCE flaw in Windows IKE Extension now actively exploitedmicrosoftCisco TalosDescribing attacks with crime script analysison the radarSecurityWeek943 Patches Rolled Out With Oracle’s August 2026 Security Updateoracleoracle cspuSecurityWeekChrome, Firefox Updates Patch Dozens of VulnerabilitieschromefirefoxBleepingComputerCISA: Medusa ransomware hit over 500 critical infrastructure orgsAlienVaultBeware of Phishing Emails Disguised as Quote Confirmation Requests (PhantomStealer)byovdclipperSecurityWeekCareCloud Data Breach Impact Grows to 3.7 Million Individualscareclouddata breachesAlienVaultClop Returns with Custom Implant in Mass-Extortion Campaigncredential theftcve-2021-27101CrowdstrikeBenchmaxxing: When the Benchmark Becomes the Targetsecuring ai
Tuesday 18 August 2026
AlienVaultCopyCop Targets AI Investment in Armeniaai infrastructurearmeniaAlienVaultMirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US2fa bypassadversary-in-the-middleAlienVaultMacSync Stealer: C2 Infrastructure Rotationc2 infrastructureclickfixPalo Alto NetworksThreat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)credential-based attackshigh profile threatsRecorded FutureMore than 200 victims of Medusa ransomware identified over the last year, CISA sayscybercrimegovernmentBleepingComputerClop created custom web shell for Windchill data theft attacksRecorded FutureBerlin cuts two state ministries off government network after security breachcybercrimegovernmentAlienVaultSigned Overwolf Binary Sideloads ValleyRAT Malware in Indiaastral-pedll sideloadingAlienVaultFraudulent Employment Operationsai-generated personaschatgpt abuseAlienVaultOctagon: A New Android Bot Targeting Crypto Wallets and Banking Appsaccessibility abuseandroidRecorded FutureHackers target Ukrainian agency managing assets seized from sanctioned RussianscybercrimegovernmentBleepingComputerYour Controls Block Known Attacks. What About the Behavior?GoogleStaying Ahead of Adversarial AI Through Agentic Source Code Reviewthreat intelligenceSecurityWeekAI-Driven Vulnerability Surge Breaks the Traditional Patching Modelartificial intelligencepatchSecurityWeek300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin FlawpluginvulnerabilitiesBleepingComputerCISA: Windows Task Host flaw now exploited by ransomware gangsmicrosoftAlienVaultBeware of Phishing Emails Disguised as Transaction Receiptsliving-off-the-landpdf attachmentSecurityWeekHeights Finance Data Breach Impacts at Least 1.2 Million Individualsdata breachesheights financialSecurityWeekGitLab Patches Critical Code Injection VulnerabilitygitlabpatchBleepingComputerMicrosoft starts removing WMIC tool used by cybercriminalsmicrosoftAlienVaultOperation ASTERIX: Anatomy of a Crypto Fraud Pipelineaccount-enumerationai-assisted-developmentSecurityWeekDozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updatesapplemobile & wireless
Monday 17 August 2026
Recorded FutureUkrainian software developer faces 12 years in Swiss ransomware trialcybercrimeRecorded FutureNearly 750k had financial info, SSNs leaked in South Carolina loan company breachcybercrimeBleepingComputerHacker claims 3.6 million Azure account records stolen from major companiesBleepingComputerPokémon Center data breach exposes customer info, cancels some ordersRecorded FutureSafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impactedcybercrimeprivacyRecorded FutureIrregular faces criticism over ‘spin’ in AI hacking postmortemindustryAlienVaultProjextor: Abusing Electron in Trojanized Productivity Applicationsdesktop captureelectron frameworkAlienVaultC2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2backdoorc2looperAlienVaultOperation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoorchina-nexuscloudflare workersSecurityWeek680,000 Impacted by French Tax Authority Data Breachdata breachesdgfipSecurityWeekIrregular Details How a Naming Error Let AI Models Attack a Real Companyartificial intelligenceai testingBleepingComputerPhilips and GE investigating Clop ransomware data theft claimsSecurityWeekConflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malwareartificial intelligenceanthropicBleepingComputerFrench tax authority data breach affects 678,000 individualsSecurityWeek40,000 Impacted by SafePal Data Breachcryptocurrencydata breachesBleepingComputerMicrosoft working on Defender patch for ShieldBreak zero-daymicrosoftSecurityWeekRecent macOS Screen Sharing Vulnerability Exploited in AttacksexploitedmacosSecurityWeekCritical SAP Commerce Cloud Vulnerability Exploited 3 Days After DisclosureexploitedsapSecurityWeekFortune 500 Companies Hit in Azure Data Theft Campaignazurecloud securityCrowdstrikeTeaching AI to Reason Through Detection Triagesecuring ai
Sunday 16 August 2026
BleepingComputerSafePal data breach impacts 39,798 customers, stolen info for saleBleepingComputerLarge-scale DDoS attacks disrupted Threema secure messaging serviceBleepingComputerNew AmnesiaStealer macOS malware hijacks browser sessions via remote control
Saturday 15 August 2026
BleepingComputerNew Evooo1Bot Linux botnet turns routers into traffic relay nodes
Friday 14 August 2026
Recorded FutureInvestigation of banking hack leads to arrests in Germany, BrazilcybercrimegovernmentBleepingComputerHackers arrested over €30M bank fraud exploiting service provider flawlegalAlienVaultNew Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxiescve-2007-3010cve-2016-6277BleepingComputerHackers exploit macOS Screen Sharing flaw to deploy Monero minerappleBleepingComputerThe Modern Attack Chain: Rethinking Google Workspace Security in the Age of AIBleepingComputerMax severity SAP Commerce Cloud flaw now targeted in attacksRecorded FutureFrance investigates tax authority breach after hacker claims 600,000 victimscybercrimegovernmentSecurityWeekIn Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilitiesin other newsvulnerabilitiesBleepingComputerShell investigates 'potential incident' after Clop data theft claimsSecurityWeekTrivy, Not LiteLLM Behind the 2,500 Org Compromiselitellmsupply chainBleepingComputerRingCentral data breach exposed info of 1.6 million accountsAlienVaultCoolClient backdoor goes deeper: Windows kernel rootkit addedcoolclienthoneymyteSecurityWeek1.6 Million Likely Impacted by RingCentral Data Breachdata breachesdata leakSecurityWeekOver 1,000 Charities Hit by Beacon CRM Data BreachbeaconcharitySecurityWeek14,000 Trezor Customers Impacted by Data Breach at ShipMonkdata breachesmetabaseAlienVaultDropcatch Scavengers: Expired Malicious Domains Become Cash Cowsaffiliate frauddropcatchSecurityWeekHackers Exploiting Unpatched GeoServer Zero-DayexploitedgeoserverSecurityWeekAmnesiaStealer macOS Malware Steals Data, Controls Browser Sessionsamnesiastealerinformation stealerBleepingComputerApple sends new ‘Threat Notification’ alerts over mercenary spyware attacksapple
Thursday 13 August 2026
BleepingComputerUkraine shuts down 94 fraudulent call centers, seize millions in cashBleepingComputerAkira hackers disable EDR with Safe Mode, steal data but fail to encryptAlienVaultMulti-Functional Linux Botnet "Evooo1Bot"ddos engineedge device exploitationBleepingComputerHackers breach govt webmail while running parallel crypto fraudCisco TalosCuriouser and Curiouserthreat source newsletterBleepingComputerMicrosoft patches LegacyHive Windows zero-day vulnerabilitymicrosoftBleepingComputerCritical VMware vCenter RCE flaw exploited for reverse SSH accessAlienVaultPATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructuregatesentinelgoogle sheets c2AlienVaultIllegal Streaming Fronts a $7M Dropcatch Domain OperationasyncratdcratRecorded FutureNew Mirai variant adds stealth capabilities to notorious botnet codecybercrimeBleepingComputerTrezor discloses data breach affecting nearly 14,000 customersBleepingComputerWhite House taps security firms for offensive hack-back operationsAlienVaultRecent Attack Activity Analysis Using North Korea-Related Lureschacha20 encryptiondarkhotelSecurityWeekWordPress 7.0.4 Patches Remote Code Execution VulnerabilityrcevulnerabilitiesRecorded FutureGermany moves to give spy agencies hacking and sabotage powerscybercrimegovernmentAlienVaultJewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by SideantinoaptAlienVaultAPT Group Runs Espionage and Crypto Fraud Operations Side by SideantinoaptAlienVaultNew Armored Likho tools target Telegram and eavesdroppingaquilarataudio surveillanceAlienVaultChina-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud businessantinoantino backdoorSecurityWeekFortinet Patches Authentication Flaws in FortiWeb and FortiManagerfortinetpatchesCisco TalosDissecting the JWR phishing frameworkcisco talos antiviruscisco talos dns securityAlienVaultInside a Ukrainian IP Camera Toolkitcamviewcve-2017-7921AlienVaultState Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploitaerospace targetingcve-2025-49113SecurityWeekCritical VMware vCenter Vulnerability in Attackers’ CrosshairsexploitedvmwareSecurityWeekNightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’chaotic eclipseexploit
Wednesday 12 August 2026
BleepingComputer"City-Forum" data-theft attacks target Salesforce, ServiceNow portalsBleepingComputerAndroid malware combo takes out loans and relays victims' credit cardsmobileAlienVaultInside Multi-Stage Phishing Redirection Chainsbrand impersonationcloudflare workersBleepingComputerHackers exploit critical Adobe Commerce flaw to hijack customer accountsRecorded FutureFBI: Hackers using social engineering to breach accounts and steal explicit contentcybercrimegovernmentAlienVaultCl0p Ransomware: Attack Pattern in Threat Intelligencearchitectural vulnerabilitycve-2023-34362AlienVaultHits Safe Mode: Ransomware Rebooting Around EDRakiraanydeskBleepingComputerPlug and Pwn attack uses fake USB devices for Windows SYSTEM accessmicrosoftBleepingComputerLazarus hackers exploited Windows zero-day to target defense firmsSecurityWeekSharePoint Vulnerability Exploited Shortly After PoC ReleaseexploitedpocBleepingComputerFBI: Hackers target online accounts to steal nude photosAlienVaultStriking gold: Inside the GoldDigger Android malwareaccessibility abuseandroid trojanSecurityWeekWhatsApp Unveils New Scam Alert Featurefraud & identity theftscamSecurityWeekStealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom ToolsetmalwaresalesforceRecorded FutureMicrosoft’s massive Patch Tuesday releases continue as AI reshapes bug discoverycybercrimeBleepingComputerHackers leverage new Microsoft SharePoint exploit in attacksmicrosoftAlienVaultGone with the WindRelay: A New Malware Combo Behind a Growing Fraud Schemeandroid banking trojancontactless payment fraudRecorded FutureCISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaigncybercrimegovernmentBleepingComputerSignal adds new security feature to thwart man-in-the-middle attacksSecurityWeekChipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combinedamdchipmaker patch tuesdayBleepingComputerNew Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privilegesmicrosoftSecurityWeekOver 2,500 Organizations Impacted by LiteLLM Supply Chain Attacklitellmsupply chain attackSecurityWeekFresh Windows Zero-Day Exploited in North Korean CyberattacksaptexploitedSecurityWeekIvanti EPM Update Patches Remotely Exploitable FlawsivantipatchSecurityWeekICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contacticsics patch tuesdaySecurityWeekSonicWall Patches Critical Vulnerabilities in Discontinued GMS PlatformgmssonicwallAlienVault737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirectionbrand impersonationbrowser hijackingSecurityWeekCisco Patches Firewall Zero-Day Exploited for DoS AttacksciscoexploitedAlienVaultTracking Shai-Hulud: Inside the ChainDrop NPM Wormchaindropethereum c2AlienVaultCaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentialsapt29captive portal compromise
Tuesday 11 August 2026
Cisco TalosMicrosoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiespatch tuesdayBleepingComputerDeadLock ransomware uses blockchain to resist infrastructure takedownBleepingComputerSandworm hackers target IT pros with trojanized WireGuard VPN clientAlienVaultFake CCleaner installs GhostDesk Chrome spywarechrome extensionghostdeskAlienVaultShattering the Dream - When a Job Offer Becomes a Zero-Day Attackcve-2026-68820dprk-linkedBleepingComputerCisco warns of ASA and FTD VPN flaw exploited to crash devicesRecorded FutureRansomware group hijacks hospital system’s Facebook page amid ongoing cyberattack falloutcybercrimeSecurityWeekAugust 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-DayexploitedmicrosoftBleepingComputerDelta probes Wi-Fi deauth attack on flight carrying DEF CON attendeesBleepingComputerMicrosoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysmicrosoftZero Day InitiativeThe August 2026 Security Update Reviewblog postSecurityWeekAdobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flawsadobepatch tuesdayAlienVaultCNCMachineRMS: The Undocumented RAT At the End of a BabaDeda ChainbabadedaclickfixBleepingComputerWesco confirms security incident after ExfilSquad claims data theftSecurityWeekZoom Patches Zero-Click Code Execution VulnerabilityvulnerabilitieszoomAlienVaultHow the ErrTraffic Malware Campaign Uses ClickFix and EtherHidingbabadedaloaderblockchainAlienVaultPhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf serverarcbridgebackdoor deploymentAlienVaultAn Evolution of the Botnetaisuruandroid tv boxesAlienVaultSelf-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attackchaindropci/cd compromiseSecurityWeekSAP Patches Critical Code Injection, Memory Corruption Vulnerabilitiespatch tuesdaypatchesBleepingComputerDDoS attacks over 1 Tbps surged fivefold in the second quarterBleepingComputerCISA: Microsoft SharePoint flaw now exploited in ransomware attacksmicrosoftAlienVaultProject CAV3RN uses Google Apps Script for stealthy C2 in Israelc2 relaycommunicationuxtheme.dllAlienVaultFake popular sites offer a free app, instead take over PCsbrand impersonationcryptocurrency lureBleepingComputerCisco warns of high-severity ClamAV flaws with public exploitsPalo Alto NetworksKimwolf v7: An Evolution of the Kimwolf Botnetandroid apkethereumSecurityWeekHacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemptionhackerhacker conversationsBleepingComputerUS and South Korea warn of Gunra ransomware targeting govt agencies

Headlines and links are the property of their publishers and appear here as attributed links. Follow any headline to read the original.

Support Independent Threat Research

Everything here is researched, written, and published independently, and none of it sits behind a paywall. If it is useful to you or your team, these are here if you want them.