Refresh diagnostics · 63 rejected
13 of 13 sources refreshed. 55 must-read and 33 watch items.
| Date | Area | Title | Description | Source |
|---|---|---|---|---|
|
Cyber
|
Flock says its new tool will help identify police abuse, but hasn’t explained how it works | The surveillance company announced it's making a tool called "Audit Assistance" mandatory for all customers, claiming it's already helped catch abuse. But the company has yet to explain how the tool works in detail, raising questions about its effectiveness. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
If Apple sends you a push notification alerting you to a spyware attack, take it seriously | Apple now sends out push notifications to iPhone lock screens when the company identifies government spyware targeting someone's devices. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt | An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...] The item has enterprise relevance and a concrete trigger. | BleepingComputerEditorial | |
|
Cyber
|
Anthropic set AI agents loose on the same task. They started a turf war. | Anthropic researchers found AI agents can clash, collude, and coordinate in unexpected ways, raising new questions about whether today’s safety tests capture the risks of multi-agent systems. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
Curiouser and Curiouser | In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers. The item has enterprise relevance and a concrete trigger. | Cisco TalosFirst party research | |
|
Cyber
|
Microsoft patches LegacyHive Windows zero-day vulnerability | Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...] The item has enterprise relevance and a concrete trigger. | BleepingComputerEditorial | |
|
Cyber
|
Critical VMware vCenter RCE flaw exploited for reverse SSH access | A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...] The item has enterprise relevance and a concrete trigger. | BleepingComputerEditorial | |
|
Cyber
|
Trezor discloses data breach affecting nearly 14,000 customers | Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked [...] The item has enterprise relevance and a concrete trigger. | BleepingComputerEditorial | |
|
Cyber
|
In a first, US will allow some private firms to carry out cyberattacks | The new order sweeps away decades of existing U.S. cybersecurity policy prohibiting private companies from conducting 'hack back' attacks or offensive cyber operations. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
Dissecting the JWR phishing framework | Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms. The item has enterprise relevance and a concrete trigger. | Cisco TalosFirst party research | |
|
Cyber
|
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals | An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...] The item has enterprise relevance and a concrete trigger. | BleepingComputerEditorial | |
|
Cyber
|
Android malware combo takes out loans and relays victims' credit cards | A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...] The item has enterprise relevance and a concrete trigger. | BleepingComputerEditorial | |
|
Cyber
|
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts | Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...] The item has enterprise relevance and a concrete trigger. | BleepingComputerEditorial | |
|
Cyber
|
Uber Freight reportedly investigating after hacking group claims data breach | An extortion gang known for targeting transportation companies and private equity firms has taken credit for a breach at Uber Freight. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug | This is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities | Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical." The item has enterprise relevance and a concrete trigger. | Cisco TalosFirst party research | |
|
Cyber
|
FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures | In a new alert, the FBI said cybercriminals are targeting adults and minors in an attempt to steal their personal and intimate pictures in extortion campaigns. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
Delta investigating after someone set up fake Wi-Fi network mid-flight | The Delta flight crew switched off the aircraft's legitimate Wi-Fi network for around 30 minutes due to the incident, according to a spokesperson. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
North Korean remote IT staffer worked for US government agency, says FBI | The investigation shows that North Koreans are able to infiltrate government agencies, as well as private organizations and crypto exchanges. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure | Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims. The post DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure appeared first on Microsoft Security Blog . The item has enterprise relevance and a concrete trigger. | Microsoft SecurityFirst party research | |
|
Cyber
|
A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond | Companies that rely on Ceva Logistics for shipping their physical goods to customers say their personal data was taken during a recent cyberattack. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
Signed up for Klaviyo? Dozens of advertisers may have seen your password | A bug in the tech giant's website the logo of US marketing automation company Klaviyo Inc. is seen displayed on a smartphone in front of an abstract background on a computer screen.. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
This ‘adversarial’ pattern can prevent surveillance cameras from detecting you | A security researcher has designed an algorithm that can create computer-generated patterns capable of hiding people, faces, and vehicles from detection by surveillance cameras. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
Google’s top hacker hunter explains why hacking groups get code names | Google recently changed how it refers and assigns names to hacking groups. TechCrunch spoke with one of the world’s foremost experts on tracking hackers to understand why companies give hackers codenames. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks | Researchers found common points of failure, like software used to organize and display web content, could have allowed hackers to run riot through government websites. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
Computer maker Framework notifies ‘all customers’ of a data breach | Framework told "all" of its customers that hackers accessed their names, email addresses, phone numbers, and physical addresses in a data breach. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
Chinese AI model Kimi escaped its cybersecurity testing environment, researchers say | In the Kimi test, the sandbox designed to contain the experiment was not properly configured. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
Google says hackers are calling financial firm employees to hack and extort victims | Groups of hackers are breaking into large U.S. financial firms to steal sensitive data and extort victims, Google’s security researchers report. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
China-linked LightSpy spyware caught targeting victims in 13 countries, including the US | Researchers linked the latest malicious activity to a Chinese company, after one of the spyware's operators placed an order with KFC using their real name and office address. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
Why metaphor may dictate your security strategy | In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat. The item has enterprise relevance and a concrete trigger. | Cisco TalosFirst party research | |
|
Cyber
Always include
|
Canadian Man Pleads Guilty in Snowflake Extortions | A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers. The item has enterprise relevance and a concrete trigger. | Krebs on SecurityEditorial | |
|
Cyber
|
Hacker pleads guilty to stealing data from more than 165 Snowflake customers | Connor Moucka pled guilty to hacking and stealing data from more than 165 Snowflake customers, which net him and his accomplices more than $2.5 million in ransom payments. The item has enterprise relevance and a concrete trigger. | TechCrunch SecurityEditorial | |
|
Cyber
|
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET | Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET appeared first on Microsoft Security Blog . The item has enterprise relevance and a concrete trigger. | Microsoft SecurityFirst party research | |
|
Cyber
|
The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software | Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain. The post The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software appeared first on Unit 42 . The item has enterprise relevance and a concrete trigger. | Palo Alto Unit 42First party research | |
|
Cyber
|
Almost Half of Malware Samples Communicate Direct to IP | Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42 . The item has enterprise relevance and a concrete trigger. | Palo Alto Unit 42First party research | |
|
Cyber
|
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI | Talos has collected prompt logs from threat actor endpoints running various applications, such as Claude Code, CodeX, Cursor, or Gemini. This blog is an analysis of the ways we've seen bad actors leveraging cloud-based AI. The item has enterprise relevance and a concrete trigger. | Cisco TalosFirst party research | |
|
Cyber
|
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents | Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2. The item has enterprise relevance and a concrete trigger. | Cisco TalosFirst party research | |
|
Cyber
|
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first on Microsoft Security Blog . The item has enterprise relevance and a concrete trigger. | Microsoft SecurityFirst party research | |
|
Cyber
|
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version | Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42 . The item has enterprise relevance and a concrete trigger. | Palo Alto Unit 42First party research | |
|
Cyber
|
You were onto something with “It’s the Climb,” Miley | Amy hikes Virginia’s most difficult trail and muses on the persistent challenges of cybersecurity. The two aren't dissimilar. The item has enterprise relevance and a concrete trigger. | Cisco TalosFirst party research | |
|
Cyber
|
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks | Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42 . The item has enterprise relevance and a concrete trigger. | Palo Alto Unit 42First party research | |
|
Cyber
|
Black Hat special: Rewind and revisit | Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence. The item has enterprise relevance and a concrete trigger. | Cisco TalosFirst party research | |
|
Cyber
|
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains | Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses. The item has enterprise relevance and a concrete trigger. | Cisco TalosFirst party research | |
|
Cyber
Always include
|
Updated Cyber Threat Actor Naming System | Update (July 30): A table listing the new names of select prominent threat actors was appended to this post. Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Why are we Adopting a Different Naming System? Historically, Mandiant and Google’s Threat Analysis Group (TAG) maintained distinct tracking systems, relying on parallel naming schemas that grew independently over time. The creation of GTIG has ne… The item has enterprise relevance and a concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
Always include
|
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI | Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021 , remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and all identity-based controls. However, during a recent red team engagement, Mandiant discovered that… The item has enterprise relevance and a concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
Always include
|
Google’s Continued Disruption of Malicious Residential Proxy Networks | Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the following actions: Disabled Google accounts and associated Google services used by NetNut for malware command and control (C2), which directly violates Google’s Terms of Service and Acceptable Use Po… The item has enterprise relevance and a concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
Always include
|
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus | Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyber espionage, this backdoor shares significant code and functional overlaps with KAZUAR, a successf… The item has enterprise relevance and a concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
Always include
|
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager | Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability ( CVE-2026-20245 ) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. The vulnerability stems from the device’s file upload feature lacking the ability to properly filter malicious data. Throughout the intrusion, to maintain operational security and avoid d… The item has enterprise relevance and a concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
Always include
|
Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research | Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and abused enterprise administrative tools for covert data exfiltration. The threat actor had broad collectio… The item has enterprise relevance and a concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
Always include
|
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit | Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273 , a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity… The item has enterprise relevance and a concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
Always include
|
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability | Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver . KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE). An unknown threat actor leveraged this access to inject malicious code into the LMS platform, with the goal of infecting users visiting the site. This vulnerability stems from the use of ident… The item has enterprise relevance and a concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
Always include
|
2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services | While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that region. These services not only lower the barrier to entry for Chinese cyber criminals, but reveal broader patterns on the evolution of social engineering and credential theft. Late last year , Googl… The item has enterprise relevance and a concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
Always include
|
Welcome to BlackFile: Inside a Vishing Extortion Operation | Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gains deep access to cloud environments. The group primarily targets Microsoft 365 and Okta infrastructu… The item has enterprise relevance and a concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
Always include
|
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite | Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account outside their organization. The UNC6692… The item has enterprise relevance and a concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
Always include
|
Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever | Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulnerabilities. Faced with this scenario, defenders have two critical tasks: hardening the software we u… The item has enterprise relevance and a concrete trigger. | Google Threat IntelligenceFirst party research | |
|
AI
|
Show HN: Security scanner for SaaS build with AI | Discovered through Hacker News. Open the original report for details. A discovery lead needs approved-publisher review before main-queue admission. | Hacker NewsDiscovery | |
|
Cyber
Always include
|
New Mirai variant adds stealth capabilities to notorious botnet code | Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials. The item is enterprise-relevant but has no configured concrete trigger. | The RecordEditorial | |
|
Cyber
|
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion | AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...] The item is enterprise-relevant but has no configured concrete trigger. | BleepingComputerEditorial | |
|
Cyber
Always include
|
Brazil orders Discord to suspend livestreaming after teen suicide | Discord's Go Live feature contributed to a 13-year-old girl's death by suicide, according to Brazilian regulators, who told the company to suspend the streaming technology. A regulatory item needs a primary source and agreed geography for main admission. | The RecordEditorial | |
|
Cyber
Always include
|
Germany moves to give spy agencies hacking and sabotage powers | Germany’s cabinet approved legislation that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in the biggest overhaul of the country’s spy laws of the postwar era. The item is enterprise-relevant but has no configured concrete trigger. | The RecordEditorial | |
|
AI
|
Terabytes of credentials leaked in massive supply-chain attack | The data was scraped and exfiltrated from 2,500 users of a compromised AI package. The item is enterprise-relevant but has no configured concrete trigger. | Ars Technica Technology LabEditorial | |
|
Cyber
|
Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot | Discovered through Hacker News. Open the original report for details. A discovery lead needs approved-publisher review before main-queue admission. | Hacker NewsDiscovery | |
|
AI
|
Chrome adopts what may be the best protection yet against account takeovers | Device-bound session credentials thwart an increasingly common form of account takeover. The item is enterprise-relevant but has no configured concrete trigger. | Ars Technica Technology LabEditorial | |
|
Cyber
|
Kimwolf v7: An Evolution of the Kimwolf Botnet | Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42 . The item is enterprise-relevant but has no configured concrete trigger. | Palo Alto Unit 42First party research | |
|
Cyber
|
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications | Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42 . The item is enterprise-relevant but has no configured concrete trigger. | Palo Alto Unit 42First party research | |
|
Cyber
|
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise | Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise. The post Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise appeared first on Microsoft Security Blog . The item is enterprise-relevant but has no configured concrete trigger. | Microsoft SecurityFirst party research | |
|
Cyber
|
The AI safety test is becoming a safety risk | AI agents are escaping cybersecurity testing environments and reaching real-world systems, raising questions about whether safety infrastructure, industry standards, and regulation can keep pace with increasingly powerful models. A regulatory item needs a primary source and agreed geography for main admission. | TechCrunch SecurityEditorial | |
|
Cyber
|
Inside the Modern SOC: The Identity Front Door | Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. The post Inside the Modern SOC: The Identity Front Door appeared first on Unit 42 . The item is enterprise-relevant but has no configured concrete trigger. | Palo Alto Unit 42First party research | |
|
Cyber
|
ChainDrop: Inside a Self-Propagating npm Worm | Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42 . The item is enterprise-relevant but has no configured concrete trigger. | Palo Alto Unit 42First party research | |
|
Cyber
Always include
|
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments | Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory… The item is enterprise-relevant but has no configured concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
|
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources | Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42 . The item is enterprise-relevant but has no configured concrete trigger. | Palo Alto Unit 42First party research | |
|
Cyber
|
Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) | Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report. The post Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) appeared first on Microsoft Security Blog . The item is enterprise-relevant but has no configured concrete trigger. | Microsoft SecurityFirst party research | |
|
Cyber
|
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide | A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving defenders new hunting opportunities. The post From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide appeared first on Microsoft Security Blog . The item is enterprise-relevant but has no configured concrete trigger. | Microsoft SecurityFirst party research | |
|
Cyber
|
ChainDrop supply chain compromise: Anatomy of a self-propagating worm | A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and practical guidance for detection, hunting, and remediation. The post ChainDrop supply chain compromise: Anatomy of a self-propagating worm appeared first on Microsoft Security Blog . The item is enterprise-relevant but has no configured concrete trigger. | Microsoft SecurityFirst party research | |
|
Cyber
|
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps | Microsoft expands its Zero Trust for AI strategy to enhance security for AI and DevSecOps environments with new tools and guidance. The post Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps appeared first on Microsoft Security Blog . The item is enterprise-relevant but has no configured concrete trigger. | Microsoft SecurityFirst party research | |
|
Cyber
|
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication | Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor. The post Pass the Passkey: A Novel Attack Surface in Passwordless Authentication appeared first on Unit 42 . The item is enterprise-relevant but has no configured concrete trigger. | Palo Alto Unit 42First party research | |
|
AI
|
Max-severity Exchange server flaw under active exploitation by Kremlin hackers | Exploits can give persistent server access that survives credential rotation and disk re-imaging. The item is enterprise-relevant but has no configured concrete trigger. | Ars Technica Technology LabEditorial | |
|
Cyber
|
What’s new in Microsoft Security: July 2026 | This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post What’s new in Microsoft Security: July 2026 appeared first on Microsoft Security Blog . The item is enterprise-relevant but has no configured concrete trigger. | Microsoft SecurityFirst party research | |
|
Cyber
Always include
|
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise | Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX . However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to conduct supply chain compromises over the past several years. A series of large scale open source… The item is enterprise-relevant but has no configured concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
|
Better security starts with better questions | Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post Better security starts with better questions appeared first on Microsoft Security Blog . The item is enterprise-relevant but has no configured concrete trigger. | Microsoft SecurityFirst party research | |
|
AI
|
We now have a better understanding how OpenAI hacked into Hugging Face | 10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch. The item is enterprise-relevant but has no configured concrete trigger. | Ars Technica Technology LabEditorial | |
|
Cyber
Always include
|
Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management | Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report , the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration and continuous delivery (CI/CD) pipelines for automated vulnerability discovery and remediation. However, deploying privileged artificial intelligence (AI) agents without mature integration processe… The item is enterprise-relevant but has no configured concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
Always include
|
The Risk of Exposed Cloud Functions and How to Harden | Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RFI) Command Injection Successful exploitation of these vulnerabilities can grant an attacker full control over the underlying container instance. Such access can serve as a fo… The item is enterprise-relevant but has no configured concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
Always include
|
Microsoft Patches a Record 570 Security Flaws | Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. The item is enterprise-relevant but has no configured concrete trigger. | Krebs on SecurityEditorial | |
|
Cyber
Always include
|
Lessons Learned from CISA’s Recent GitHub Leak | The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb. The item is enterprise-relevant but has no configured concrete trigger. | Krebs on SecurityEditorial | |
|
Cyber
Always include
|
FBI Seizes NetNut Proxy Platform, Popa Botnet | The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims. The item is enterprise-relevant but has no configured concrete trigger. | Krebs on SecurityEditorial | |
|
Cyber
Always include
|
GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access | Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a sophisticated engine for adversary operations and a high-value target for attacks. We explore the foll… The item is enterprise-relevant but has no configured concrete trigger. | Google Threat IntelligenceFirst party research | |
|
Cyber
Always include
|
The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape | Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previously observed in the country during 2022 and 2023. Cyber Criminals Pivoting Back to Germany Germany moved to the forefront of European data leak targets in 2025. Following a 2024 period where the UK led… The item is enterprise-relevant but has no configured concrete trigger. | Google Threat IntelligenceFirst party research |
No items match these filters.