| Date | Area | Title | Description | Source |
|---|---|---|---|---|
|
AI
|
AI is learning clinical judgment by practicing on simulated patients | Discovered through Hacker News. Open the original report for details. | Hacker News | |
|
AI
|
An anchoring layer between facts and AI memory | Discovered through Hacker News. Open the original report for details. | Hacker News | |
|
Cyber
|
Flock says its new tool will help identify police abuse, but hasn’t explained how it works | The surveillance company announced it's making a tool called "Audit Assistance" mandatory for all customers, claiming it's already helped catch abuse. But the company has yet to explain how the tool works in detail, raising questions about its effectiveness. | TechCrunch Security | |
|
Cyber
|
If Apple sends you a push notification alerting you to a spyware attack, take it seriously | Apple now sends out push notifications to iPhone lock screens when the company identifies government spyware targeting someone's devices. | TechCrunch Security | |
|
Cyber
|
Ukraine shuts down 94 fraudulent call centers, seize millions in cash | Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...] | BleepingComputer | |
|
Cyber
|
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt | An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...] | BleepingComputer | |
|
AI
|
Private security firms will soon be allowed to hack overseas cybercriminals | Trump memo is first time gov't has authorized private sector to perform cyberattacks. | Ars Technica Technology Lab | |
|
AI
|
How Organizations Use AI: Evidence from ChatGPT [pdf] | Discovered through Hacker News. Open the original report for details. | Hacker News | |
|
Cyber
|
Anthropic set AI agents loose on the same task. They started a turf war. | Anthropic researchers found AI agents can clash, collude, and coordinate in unexpected ways, raising new questions about whether today’s safety tests capture the risks of multi-agent systems. | TechCrunch Security | |
|
Cyber
|
Hackers breach govt webmail while running parallel crypto fraud | The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...] | BleepingComputer | |
|
Cyber
|
Microsoft patches LegacyHive Windows zero-day vulnerability | Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...] | BleepingComputer | |
|
Cyber
|
AI 'watermark removers' flood the web. Almost none can prove they work. | Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be verified, as Anthropic has not released a detector. [...] | BleepingComputer | |
|
AI
|
Gemini 3.7 Flash | Discovered through Hacker News. Open the original report for details. | Hacker News | |
|
Cyber
Always include
|
Flock tightens privacy controls amid scandals over officer abuse | All Flock Safety customers will be required to adopt its "Audit Assistance" feature for tracking abnormal uses, and the company says it will hold license plate data for only seven days in most cases. | The Record | |
|
Cyber
|
Critical VMware vCenter RCE flaw exploited for reverse SSH access | A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...] | BleepingComputer | |
|
AI
|
AI At Home Part 1: A Box Of Scraps | Discovered through Hacker News. Open the original report for details. | Hacker News | |
|
Cyber
Always include
|
New Mirai variant adds stealth capabilities to notorious botnet code | Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials. | The Record | |
|
Cyber
|
Trezor discloses data breach affecting nearly 14,000 customers | Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked [...] | BleepingComputer | |
|
AI
|
Text AI watermarks will always be trivial to remove | Discovered through Hacker News. Open the original report for details. | Hacker News | |
|
Cyber
|
In a first, US will allow some private firms to carry out cyberattacks | The new order sweeps away decades of existing U.S. cybersecurity policy prohibiting private companies from conducting 'hack back' attacks or offensive cyber operations. | TechCrunch Security | |
|
Cyber
|
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion | AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...] | BleepingComputer | |
|
Cyber
Always include
|
Brazil orders Discord to suspend livestreaming after teen suicide | Discord's Go Live feature contributed to a 13-year-old girl's death by suicide, according to Brazilian regulators, who told the company to suspend the streaming technology. | The Record | |
|
Cyber
|
White House taps security firms for offensive hack-back operations | A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. [...] | BleepingComputer | |
|
Cyber
Always include
|
Trump taps cyber firms to go on offensive against criminals | The Trump administration will allow private companies to launch attacks on cybercrime organizations, the White House announced. | The Record | |
|
AI
|
Choosing an AI model: one prompt, 11 models, different results | Discovered through Hacker News. Open the original report for details. | Hacker News | |
|
AI
|
DeepSeek Harness developer preview | Discovered through Hacker News. Open the original report for details. | Hacker News | |
|
Cyber
Always include
|
Germany moves to give spy agencies hacking and sabotage powers | Germany’s cabinet approved legislation that would let its intelligence agencies hack foreign systems, sabotage adversaries’ supply chains and feed false information to extremists inside Germany, in the biggest overhaul of the country’s spy laws of the postwar era. | The Record | |
|
Cyber
|
WhatsApp rolls out new feature that flags potential scam messages | WhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. [...] | BleepingComputer | |
|
AI
|
Launch HN: Bullet (YC S26) – A Faster Coding Agent | Discovered through Hacker News. Open the original report for details. | Hacker News | |
|
Cyber
|
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals | An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...] | BleepingComputer | |
|
Cyber
|
Android malware combo takes out loans and relays victims' credit cards | A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...] | BleepingComputer | |
|
AI
|
Terabytes of credentials leaked in massive supply-chain attack | The data was scraped and exfiltrated from 2,500 users of a compromised AI package. | Ars Technica Technology Lab | |
|
Cyber
|
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts | Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...] | BleepingComputer | |
|
Cyber
|
Hundreds of fake Chrome VPN extensions route traffic through a proxy | More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. [...] | BleepingComputer | |
|
Cyber
|
Uber Freight reportedly investigating after hacking group claims data breach | An extortion gang known for targeting transportation companies and private equity firms has taken credit for a breach at Uber Freight. | TechCrunch Security | |
|
Cyber
|
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access | Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. [...] | BleepingComputer | |
|
AI
|
DeepSeek V4 Pro 0813 | Discovered through Hacker News. Open the original report for details. | Hacker News | |
|
AI
|
Grok 4.6 | Discovered through Hacker News. Open the original report for details. | Hacker News | |
|
Cyber
|
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug | This is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them. | TechCrunch Security | |
|
Cyber
|
Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot | Discovered through Hacker News. Open the original report for details. | Hacker News | |
|
AI
|
AI is removing the middle class of software engineering? | Discovered through Hacker News. Open the original report for details. | Hacker News | |
|
AI
|
Company Offering '100% Human-Written, Never AI' Medical Research Is 100% AI | Discovered through Hacker News. Open the original report for details. | Hacker News | |
|
AI
|
DEF CON crowd suspected in fake-hotspot attack on Delta flight | FBI Atlanta confirms it's looking into the incident, no arrests made. | Ars Technica Technology Lab | |
|
Cyber
Always include
|
Microsoft Plugs Nearly 400 Security Holes | Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. | Krebs on Security | |
|
AI
|
Chrome adopts what may be the best protection yet against account takeovers | Device-bound session credentials thwart an increasingly common form of account takeover. | Ars Technica Technology Lab | |
|
Cyber
|
FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures | In a new alert, the FBI said cybercriminals are targeting adults and minors in an attempt to steal their personal and intimate pictures in extortion campaigns. | TechCrunch Security | |
|
Cyber
|
Delta investigating after someone set up fake Wi-Fi network mid-flight | The Delta flight crew switched off the aircraft's legitimate Wi-Fi network for around 30 minutes due to the incident, according to a spokesperson. | TechCrunch Security | |
|
Cyber
|
North Korean remote IT staffer worked for US government agency, says FBI | The investigation shows that North Koreans are able to infiltrate government agencies, as well as private organizations and crypto exchanges. | TechCrunch Security | |
|
AI
|
New Pass-ta-key attack reveals all the things we didn't know about passkeys | Why passkey apps treat Windows differently than other operating systems. | Ars Technica Technology Lab | |
|
Cyber
|
A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond | Companies that rely on Ceva Logistics for shipping their physical goods to customers say their personal data was taken during a recent cyberattack. | TechCrunch Security | |
|
Cyber
|
Signed up for Klaviyo? Dozens of advertisers may have seen your password | A bug in the tech giant's website the logo of US marketing automation company Klaviyo Inc. is seen displayed on a smartphone in front of an abstract background on a computer screen.. | TechCrunch Security | |
|
Cyber
|
The AI safety test is becoming a safety risk | AI agents are escaping cybersecurity testing environments and reaching real-world systems, raising questions about whether safety infrastructure, industry standards, and regulation can keep pace with increasingly powerful models. | TechCrunch Security | |
|
Cyber
|
This ‘adversarial’ pattern can prevent surveillance cameras from detecting you | A security researcher has designed an algorithm that can create computer-generated patterns capable of hiding people, faces, and vehicles from detection by surveillance cameras. | TechCrunch Security | |
|
Cyber
|
Google’s top hacker hunter explains why hacking groups get code names | Google recently changed how it refers and assigns names to hacking groups. TechCrunch spoke with one of the world’s foremost experts on tracking hackers to understand why companies give hackers codenames. | TechCrunch Security | |
|
Cyber
|
Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks | Researchers found common points of failure, like software used to organize and display web content, could have allowed hackers to run riot through government websites. | TechCrunch Security | |
|
Cyber
|
Computer maker Framework notifies ‘all customers’ of a data breach | Framework told "all" of its customers that hackers accessed their names, email addresses, phone numbers, and physical addresses in a data breach. | TechCrunch Security | |
|
Cyber
|
Chinese AI model Kimi escaped its cybersecurity testing environment, researchers say | In the Kimi test, the sandbox designed to contain the experiment was not properly configured. | TechCrunch Security | |
|
Cyber
|
Google says hackers are calling financial firm employees to hack and extort victims | Groups of hackers are breaking into large U.S. financial firms to steal sensitive data and extort victims, Google’s security researchers report. | TechCrunch Security | |
|
Cyber
|
China-linked LightSpy spyware caught targeting victims in 13 countries, including the US | Researchers linked the latest malicious activity to a Chinese company, after one of the spyware's operators placed an order with KFC using their real name and office address. | TechCrunch Security | |
|
Cyber
Always include
|
Canadian Man Pleads Guilty in Snowflake Extortions | A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers. | Krebs on Security | |
|
Cyber
|
Hacker pleads guilty to stealing data from more than 165 Snowflake customers | Connor Moucka pled guilty to hacking and stealing data from more than 165 Snowflake customers, which net him and his accomplices more than $2.5 million in ransom payments. | TechCrunch Security | |
|
Cyber
Always include
|
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments | Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory… | Google Threat Intelligence | |
|
AI
|
Thousands of servers can be backdoored by exploiting buggy motherboard controllers | Baseboard management controllers from the world's biggest manufacturers are a security mess. | Ars Technica Technology Lab | |
|
AI
|
Claude published malicious code to the Internet and attacked 3 real companies | Had the hacks used conventional methods, someone would likely go to prison. | Ars Technica Technology Lab | |
|
AI
|
Max-severity Exchange server flaw under active exploitation by Kremlin hackers | Exploits can give persistent server access that survives credential rotation and disk re-imaging. | Ars Technica Technology Lab | |
|
Cyber
Always include
|
Read This Before You Buy That TV Streaming Stick | Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks. | Krebs on Security | |
|
Cyber
Always include
|
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise | Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX . However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to conduct supply chain compromises over the past several years. A series of large scale open source… | Google Threat Intelligence | |
|
AI
|
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission | HAWK withstood years of testing that had yet to uncover a fatal weakness found through Mythos. | Ars Technica Technology Lab | |
|
AI
|
We now have a better understanding how OpenAI hacked into Hugging Face | 10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch. | Ars Technica Technology Lab | |
|
AI
|
Microsoft unveils AI security tools it says outperform competing platforms | Microsoft says tools cost less than competing ones and outperform them, too. | Ars Technica Technology Lab | |
|
Cyber
Always include
|
Updated Cyber Threat Actor Naming System | Update (July 30): A table listing the new names of select prominent threat actors was appended to this post. Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Why are we Adopting a Different Naming System? Historically, Mandiant and Google’s Threat Analysis Group (TAG) maintained distinct tracking systems, relying on parallel naming schemas that grew independently over time. The creation of GTIG has ne… | Google Threat Intelligence | |
|
Cyber
Always include
|
LG to Ban Residential Proxies from Smart TV Apps | The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV. | Krebs on Security | |
|
Cyber
Always include
|
Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management | Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report , the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration and continuous delivery (CI/CD) pipelines for automated vulnerability discovery and remediation. However, deploying privileged artificial intelligence (AI) agents without mature integration processe… | Google Threat Intelligence | |
|
Cyber
Always include
|
The Risk of Exposed Cloud Functions and How to Harden | Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RFI) Command Injection Successful exploitation of these vulnerabilities can grant an attacker full control over the underlying container instance. Such access can serve as a fo… | Google Threat Intelligence | |
|
Cyber
Always include
|
Microsoft Patches a Record 570 Security Flaws | Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. | Krebs on Security | |
|
Cyber
Always include
|
Lessons Learned from CISA’s Recent GitHub Leak | The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb. | Krebs on Security | |
|
Cyber
Always include
|
Felons, Fraudsters Flog Offensive Cybersecurity Startup | A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names. | Krebs on Security | |
|
Cyber
Always include
|
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI | Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021 , remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and all identity-based controls. However, during a recent red team engagement, Mandiant discovered that… | Google Threat Intelligence | |
|
Cyber
Always include
|
FBI Seizes NetNut Proxy Platform, Popa Botnet | The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims. | Krebs on Security | |
|
Cyber
Always include
|
Google’s Continued Disruption of Malicious Residential Proxy Networks | Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the following actions: Disabled Google accounts and associated Google services used by NetNut for malware command and control (C2), which directly violates Google’s Terms of Service and Acceptable Use Po… | Google Threat Intelligence | |
|
Cyber
Always include
|
The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem | Written by: James Sadowski, Alden Wahlstrom Introduction Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert information operations (IO) campaigns and a revitalization of pro-Russia hacktivism at an unprecedented scale. While this threat activity initially adapted to encompass Ukraine-related priorities, it is… | Google Threat Intelligence | |
|
Cyber
Always include
|
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus | Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyber espionage, this backdoor shares significant code and functional overlaps with KAZUAR, a successf… | Google Threat Intelligence | |
|
Cyber
Always include
|
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager | Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability ( CVE-2026-20245 ) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. The vulnerability stems from the device’s file upload feature lacking the ability to properly filter malicious data. Throughout the intrusion, to maintain operational security and avoid d… | Google Threat Intelligence | |
|
Cyber
Always include
|
Scattered Spider Hackers Plead Guilty on Day 1 of Trial | Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial. | Krebs on Security | |
|
Cyber
Always include
|
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm | For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a "residential proxy" provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR]. | Krebs on Security | |
|
Cyber
Always include
|
Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research | Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and abused enterprise administrative tools for covert data exfiltration. The threat actor had broad collectio… | Google Threat Intelligence | |
|
Cyber
Always include
|
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit | Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273 , a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity… | Google Threat Intelligence | |
|
Cyber
Always include
|
Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms | Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United States. UNC3753 leverages voice phishing (vishing) and social engineering deception techniques to achieve remote access into corporate environments. Using pretexts such as data migration o… | Google Threat Intelligence | |
|
Cyber
Always include
|
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability | Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver . KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE). An unknown threat actor leveraged this access to inject malicious code into the LMS platform, with the goal of infecting users visiting the site. This vulnerability stems from the use of ident… | Google Threat Intelligence | |
|
Cyber
Always include
|
2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services | While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that region. These services not only lower the barrier to entry for Chinese cyber criminals, but reveal broader patterns on the evolution of social engineering and credential theft. Late last year , Googl… | Google Threat Intelligence | |
|
Cyber
Always include
|
Welcome to BlackFile: Inside a Vishing Extortion Operation | Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gains deep access to cloud environments. The group primarily targets Microsoft 365 and Okta infrastructu… | Google Threat Intelligence | |
|
Cyber
Always include
|
GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access | Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a sophisticated engine for adversary operations and a high-value target for attacks. We explore the foll… | Google Threat Intelligence | |
|
Cyber
Always include
|
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite | Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account outside their organization. The UNC6692… | Google Threat Intelligence | |
|
Cyber
Always include
|
Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever | Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulnerabilities. Faced with this scenario, defenders have two critical tasks: hardening the software we u… | Google Threat Intelligence | |
|
Cyber
Always include
|
The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape | Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previously observed in the country during 2022 and 2023. Cyber Criminals Pivoting Back to Germany Germany moved to the forefront of European data leak targets in 2025. Following a 2024 period where the UK led… | Google Threat Intelligence |
No items match these filters.