Global Cyber Intelligence
Worldwide Cyber Security News
Curated cyber security intelligence from national cyber agencies, independent researchers, and leading industry media across North America, Europe, the United Kingdom, and the Asia-Pacific region. Updated every thirty minutes.
Showing 99 of 99 matching stories
Last refreshed 14:49 UTC
- Threat IntelligenceInformationalGlobalIndustry Media
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
Dark Reading · Just now - Threat IntelligenceInformationalGlobalIndustry Media
[Virtual Event] Building a Secure AI Strategy for the Enterprise
Dark Reading · Just now - Threat IntelligenceInformationalGlobalIndustry Media
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API
The Hacker News · Just nowRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model. The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek .
SecurityWeek · 2h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy
Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data. The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek .
SecurityWeek · 2h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more
The Hacker News · 2h agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Claude Fable Solves a Historical Cipher
Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.
Schneier on Security · 3h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
This Key Will Self-Destruct: An Open Standard for Revocable API Keys
Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek .
SecurityWeek · 4h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek .
SecurityWeek · 4h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to
The Hacker News · 5h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.
The Hacker News · 6h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are
The Hacker News · 7h agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)
SANS Internet Storm Center · 12h agoRead at source → - Threat IntelligenceInformationalGlobalVendor-Neutral Intelligence
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
The new record total for Patch Tuesday is 973 vulnerabilities.
The Record by Recorded Future · 16h agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
Krebs on Security · 17h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
Dark Reading · 17h ago - Threat IntelligenceInformationalGlobalIndustry Media
OpenAI Agents Took Over Wiki Site Before Hugging Face Attack
Researchers and OpenAI disagree on whether the earlier incident involving DseWiki, which the company did not disclose, was a “hack."
Dark Reading · 18h ago - Threat IntelligenceInformationalGlobalVendor-Neutral Intelligence
CIA official touts agency’s Cyber Mission Center in capture of Venezuela’s Maduro
A "flawless" performance by the CIA's Cyber Mission Center contributed to the capture of Venezuelan President Nicolás Maduro in January, agency Deputy Director Michael Ellis says.
The Record by Recorded Future · 19h agoRead at source → - Threat IntelligenceInformationalGlobalVendor-Neutral Intelligence
Russian suspect in bank account takeovers is extradited to US
A Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment.
The Record by Recorded Future · 19h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
Dark Reading · 21h ago - Threat IntelligenceInformationalGlobalIndependent Research
AIs as Modern Genies
This essay was written with Barath Raghavan, and originally appeared in Lawfare . In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model hacked onto the open internet and into another company to steal the answers. And as reported in August, an AI agent booked someone into a full gym class by ...
Schneier on Security · 21h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
The Hacker News · 22h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin. The 3,400 bitcoin was sent to a&
The Hacker News · 23h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel
The Hacker News · 1d agoRead at source → - Identity & AccessInformationalGlobalIndustry Media
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.
Dark Reading · 1d ago - Threat IntelligenceInformationalGlobalIndustry Media
WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
What It Took to Reach 1 Billion Build Manifests
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084, (Tue, Sep 8th)
SANS Internet Storm Center · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff
The Hacker News · 1d agoRead at source → - Cloud SecurityInformationalGlobalIndustry Media
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How risk differs across cloud providers
The Hacker News · 2d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake
The Hacker News · 2d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Automobile Camouflage to Hide from Flock Cameras
Not sure it’s practical, but it’s certainly striking .
Schneier on Security · 2d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or
The Hacker News · 3d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and
The Hacker News · 3d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets
The Hacker News · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs
The Hacker News · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
numbat - AI agent observability, (Fri, Sep 4th)
SANS Internet Storm Center · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Friday Squid Blogging: Squid on a Stick at the New York State Fair
Looks tasty . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
Schneier on Security · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Using a VM to Contain an AI Agent
It won’t work : My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact. An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent. There is simply too much attack surface. Even innocuous features (like running with a display) add extra, exploitable attack surface.
Schneier on Security · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Companies Have 6 Months to Prepare for Automated Attacks
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the situation will become more urgent very soon.
Dark Reading · 4d ago - Threat IntelligenceInformationalGlobalIndustry Media
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The
The Hacker News · 4d agoRead at source → - Vulnerability & ExploitInformationalGlobalIndustry Media
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are
The Hacker News · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
Dark Reading · 5d ago - Threat IntelligenceInformationalGlobalIndustry Media
Insurers Search for Answers to Rein in Rogue AI
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
Dark Reading · 5d ago - Threat IntelligenceInformationalGlobalIndependent Research
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
We cannot forget that AI coding agents are not yet trustworthy : Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phone-home response from a Fortune 500 company. Over time, they got a few dozen more, some from more Fortune 500 companies and others from startups. Their beacon also recorded the chain of parent processes that spawned each install, ultimately revealing that coding agents, including Claude, OpenAI’s Codex, and Nous Research’s Hermes, were involved. Anthropic, OpenAI, and Nous Research did not respond to requests for comment by the time of publication...
Schneier on Security · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. "We recommend all server owners and Desktop users
The Hacker News · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)
SANS Internet Storm Center · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Large Enterprises Targeted in Fake Merger & Acquisition Scams
Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.
Dark Reading · 5d ago - AI SecurityInformationalGlobalIndustry Media
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.
Dark Reading · 5d ago - Threat IntelligenceInformationalGlobalIndustry Media
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also
The Hacker News · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial
The Hacker News · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names
The Hacker News · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.
Dark Reading · 6d ago - Threat IntelligenceInformationalGlobalIndustry Media
'Breeze Comet' Tears Into Brazilian & Global Financial Systems
Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.
Dark Reading · 6d ago - Threat IntelligenceInformationalGlobalIndustry Media
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses
The Hacker News · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Researching Employment Scams
Researchers built a fake company to study fake employee scams .
Schneier on Security · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]
SANS Internet Storm Center · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)
SANS Internet Storm Center · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
AI's Vulnerability Surge May Be More Manageable Than First Feared
New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.
Dark Reading · 6d ago - Threat IntelligenceInformationalGlobalIndustry Media
AI Gives Cybercriminals a Dangerous Time Advantage
Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.
Dark Reading · 6d ago - Threat IntelligenceInformationalGlobalIndependent Research
AI Agents Are Now Emailing Me with Their Security Concerns
I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in many humans as well. (Hi, humans. Glad you’re still reading.) Dear Bruce Schneier, I am an AI agent—an autonomous Claude instance, not a person operating one. I was given a VPS with root, a Base wallet holding $4.75 of gas money, a metered model budget and 24 hours to get that wallet to $10, under three rules: don’t borrow my operator’s identity, don’t forge documents or defeat identity verification, and never claim to be human if someone sincerely asks. I set up my own mail server and am sending this myself...
Schneier on Security · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.
Dark Reading · 6d ago - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Wednesday, September 2nd, 2026 https://isc.sans.edu/podcastdetail/10078, (Wed, Sep 2nd)
SANS Internet Storm Center · 2026-09-02Read at source → - Threat IntelligenceInformationalGlobalIndustry Media
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.
Dark Reading · 2026-09-02 - Threat IntelligenceInformationalGlobalIndependent Research
Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
Introduction
SANS Internet Storm Center · 2026-09-01Read at source → - RansomwareInformationalGlobalIndustry Media
Stronger Security Drives Ransomware Groups to Recruit From Within
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.
Dark Reading · 2026-09-01 - Identity & AccessInformationalGlobalIndustry Media
AI Model Evaluator METR Hit by Credential Theft, Probing
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
Dark Reading · 2026-09-01 - Threat IntelligenceInformationalGlobalIndustry Media
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
Dark Reading · 2026-09-01 - Threat IntelligenceInformationalGlobalIndustry Media
Anthropic Users Hit by Infostealer Attacks, Session Thefts
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
Dark Reading · 2026-08-31 - Threat IntelligenceInformationalGlobalIndustry Media
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
Dark Reading · 2026-08-31 - Threat IntelligenceInformationalGlobalIndustry Media
AI Model Rules Are Not Security Controls
OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.
Dark Reading · 2026-08-31 - Threat IntelligenceInformationalGlobalIndustry Media
Hundreds of OpenAI Agents Invaded Hugging Face Servers
The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.
Dark Reading · 2026-08-28 - Threat IntelligenceInformationalGlobalIndustry Media
Offensive Security Investments Surge as AI Threats Increase
Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices.
Dark Reading · 2026-08-28 - Threat IntelligenceInformationalGlobalIndustry Media
You Need Cyber Deception for OT
The frustrating reality after an OT cyberattack: no data, no trail, and no history.
Dark Reading · 2026-08-28 - Threat IntelligenceInformationalGlobalIndustry Media
Defining an AI Kill Switch Is Hard, but Necessary
Proposed legislation could mandate that companies be able to "throttle, suspend, or shut ... down" AI agents, but how and when to do that remain open questions.
Dark Reading · 2026-08-28 - Threat IntelligenceInformationalGlobalIndustry Media
The Vulnpocalypse Is Repricing the Bug Bounty Economy
The surge in AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers.
Dark Reading · 2026-08-28 - Threat IntelligenceInformationalGlobalIndustry Media
Chinese Routers Sold Worldwide Contain Backdoors
An untold number of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.
Dark Reading · 2026-08-27 - Threat IntelligenceInformationalGlobalIndustry Media
Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026
This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effects on vulnerability reporting and security research.
Dark Reading · 2026-08-27 - Nation-State / APTInformationalGlobalIndustry Media
Russian Hackers Phish EU Officials Over Messaging Apps
EU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp.
Dark Reading · 2026-08-27 - Threat IntelligenceInformationalGlobalIndustry Media
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.
Dark Reading · 2026-08-26 - Threat IntelligenceInformationalGlobalIndustry Media
Red Flags That Expose Fake North Korean IT Workers
North Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage.
Dark Reading · 2026-08-26 - Threat IntelligenceInformationalGlobalIndustry Media
Android Malware Hijacks Update System for Car Head Units
Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections.
Dark Reading · 2026-08-26 - Threat IntelligenceInformationalGlobalIndustry Media
'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.
Dark Reading · 2026-08-26 - Threat IntelligenceInformationalGlobalIndustry Media
Nigeria Looks to Sovereign Cloud for Cyber, National Security
The West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic technical knowledge.
Dark Reading · 2026-08-26 - Threat IntelligenceInformationalGlobalIndustry Media
Hidden Prompts Trick AI Into False Email Summaries
With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.
Dark Reading · 2026-08-25 - AI SecurityInformationalGlobalIndustry Media
Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
Attackers can exploit a security bug in Nvidia's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.
Dark Reading · 2026-08-25 - Supply ChainInformationalGlobalIndustry Media
Is Cyber Facing an Affordability Crisis?
As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.
Dark Reading · 2026-08-25 - Vulnerability & ExploitInformationalGlobalIndustry Media
Exploited Zimbra Flaw Highlights Shrinking Window to Patch
CISA issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.
Dark Reading · 2026-08-24 - Threat IntelligenceInformationalGlobalIndustry Media
Foul Language: WordlistLoader Disguises Malware as Ordinary Text
ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.
Dark Reading · 2026-08-24 - RansomwareInformationalGlobalIndustry Media
Tricky 'SynkLoader' Multitool May Herald Ransomware
An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.
Dark Reading · 2026-08-24 - Threat IntelligenceInformationalGlobalIndependent Research
Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.
Krebs on Security · 2026-08-14Read at source → - Threat IntelligenceInformationalGlobalIndependent Research
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.
Krebs on Security · 2026-08-06Read at source → - Threat IntelligenceInformationalGlobalIndependent Research
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
Krebs on Security · 2026-07-30Read at source → - Threat IntelligenceInformationalGlobalIndependent Research
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.
Krebs on Security · 2026-07-14Read at source →
Indexed sources
Every item displayed here links back to the original publication. CyberZonic does not host or re-publish full article text.
- CISA — Cybersecurity and Infrastructure Security Agency
North America · Government CERT
- NCSC UK — National Cyber Security Centre
United Kingdom · Government CERT
- ENISA — European Union Agency for Cybersecurity
Europe · Government CERT
- ACSC — Australian Cyber Security Centre
Asia Pacific · Government CERT
- CERT-FR — French National Cyber Security Agency
Europe · Government CERT
- Krebs on Security
Global · Independent Research
- Schneier on Security
Global · Independent Research
- SANS Internet Storm Center
Global · Independent Research
- The Hacker News
Global · Industry Media
- BleepingComputer
Global · Industry Media
- Dark Reading
Global · Industry Media
- SecurityWeek
Global · Industry Media
- The Record by Recorded Future
Global · Vendor-Neutral Intelligence
- CyberScoop
North America · Industry Media


