Security intelligence
Threat intel
Threat intelligence
Follow malware research, ransomware activity, nation-state reporting, phishing campaigns, botnets, and adversary tradecraft from security research teams.
Angry Birds: Toy Ghouls’ new toys
Securelist · 2d ago ↗sources
Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization
Proofpoint Brings OpenAI GPT Cyber Models into Security Operations to Help Defenders Investigate Threats FasterProofpoint News Feed · Threat intel
↗
I’ve been deepfaked: What do I do?WeLiveSecurity · Threat intel
↗
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)SANS Internet Storm Center, InfoCON: green · Threat intel
↗
Complete index
Source grid
Every loaded article, grouped by its original feed. Search scans source names and headlines.
Density
Sort
Angry Birds: Toy Ghouls’ new toys
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the o…
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
ValleyRAT masquerading as adware
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.
Threat landscape for industrial automation systems. Q2 2026
The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control syst…
Exploits and vulnerabilities in Q2 2026
This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents an…
The invisible passenger in your car
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It’s delivered through legitimate software for DoFun head units.
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and t…
Armored Likho expands its cyber-espionage toolkit
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on…
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems…
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade…
Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization
Recorded Future's Automated Signature Creation turns new vulnerabilities into detection signatures in under an hour, matching the pace of AI-driven exploits.
H1 2026 Malware Vulnerability Trends
Learn how adversaries abuse trusted tools, AI, and developer environments for cyberattacks. Get actionable insights on ransomware, mobile threats, and supply chain security.
The Agentic SOC – From AI Theater to Real Defense
Experts from Recorded Future and Accenture offer perspectives on navigating the path to becoming an agentic SOC. Find out how to plan moving beyond “AI theater” by prioritizing me…
BlueDelta Targets Defense and Diplomacy with HOOKEDGE
Discover how the Russian state-sponsored threat group BlueDelta is using the HOOKEDGE backdoor to target defense and diplomatic organizations across Europe
Recorded Future Launches AI Alert Filtering
Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense
Recorded Future Launches 6 New Capabilities for Third-Party Risk
CopyCop Targets AI Investment in Armenia
PurpleDelta's Fraudulent Employment Operations
Malware Crypting Services and the Threat Actors Who Sell Them
Mines, Minds, and Machines: The Journey of AI
The Hugging Face Hack Was Cheap Persistence at Work
July 2026 CVE Landscape
Emerging Threats to Neurotechnology
Hype vs. Reality: What the Hugging Face Incident Means for AI Safety
8 Ways AI is Changing Threat Intelligence
Dealing with AI-Generated Extortion
Iran War’s Secondary Effects Shape 2026 US Violent Extremism
Ransomware is the Scoreboard
TAG-195 Upgrades MaaS Ecosystem with Modular Tools
Proofpoint Brings OpenAI GPT Cyber Models into Security Operations to Help Defenders Investigate Threats Faster
New Proofpoint SOC Analyst Agent combines Proofpoint security expertise with OpenAI Daybreak models to help analysts investigate threats, connect security signals and determine ne…
Cybercriminals Turn to Indirect Prompt Injection Attacks
Cybercriminals are developing indirect prompt injection tools to target AI agents.
Russian hackers can steal emails without a click
Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today’s Most Sophisticated Threats
Recognition highlights Proofpoint's deep technical integration with Google Cloud Security solutions and commitment to helping organizations protect people, data and AI Helps
Proofpoint Launches OEM Program to Help Security Providers Embed Trusted Threat Intelligence and Detection Capabilities
Accelerates OEM innovation by embedding trusted threat intelligence into security products and customer-facing workflows. Helps partners deliver more prioritized,
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
US and allies say Russian hackers stole emails without social engineering
The United States and more than a dozen allied nations said on Thursday that Russian hackers stole emails from users of the Zimbra email program without having to fool them into…
If you pay a hacker’s ransom, chances are that they’ll come back for more
I’ve been deepfaked: What do I do?
This month in security with Tony Anscombe – August 2026 edition
AI-assisted reconnaissance: Why everyone could be a viable target for fraud
How QR-code phishing can slip past corporate security measures
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
Black Hat USA 2026: AI is racing ahead of cybersecurity controls
Are AI tutors safe for your kids?
This month in security with Tony Anscombe – July 2026 edition
Beyond the screenshot: Why you should verify what you see
Forgotten UEFI shims undermining Secure Boot
ESET Threat Report H1 2026
Cyber readiness for SMBs: Getting the basics right
This month in security with Tony Anscombe – June 2026 edition
Inside the inbox: Why cybercriminals want to break into your email account
SMB cyber readiness: the road to resilience starts here
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
Killing me gently: Inside Gentlemen’s EDR killer framework
Protecting legacy OT systems against modern cyberthreats
FishMonger’s arsenal upgraded: SprySOCKS for Windows
EvilTokens: A phishing attack that doesn’t steal your password
OceanLotus: From external espionage to domestic targeting
Unpacking SMB cyber-readiness – and what makes or breaks it
Cybercriminals: the 'auditors' you never hired
Lessons for life: Why children’s data is a long-term identity risk
This month in security with Tony Anscombe – May 2026 edition
ESET APT Activity Report Q4 2025–Q1 2026
What to consider before asking an AI chatbot for health advice
BTMOB: A stealthy RAT burrowing deep into Android devices
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)
ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, Author: Johannes Ullrich
Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th)
DOUBLECUP's PNG Payload, (Mon, Aug 24th)
DOUBLECUP's PNG Payload, Author: Didier Stevens
ISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064, (Mon, Aug 24th)
Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)
ISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st)
Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)
Using Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)
Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)
Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility
Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave
The Signs Were There: What the First Autonomous Ransomware Case Confirms
Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It
Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure
13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
Volume Is Not Risk: Making Sense of the “Vulnpocalypse”
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry
From Langflow to Monero: Inside CVE-2026-33017 Cryptominer
PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM
Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign
GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026
Governing Claude Enterprise in Environments Where Inline Controls Can't Go
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open
Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign
Student Loan Breach Exposes 2.5M Records
2.5 million people were affected, in a breach that could spell more trouble down the line.
Watering Hole Attacks Push ScanBox Keylogger
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
Ransomware Attacks are on the Rise
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Twitter Whistleblower Complaint: The TL;DR Version
Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
Firewall Bug Under Active Attack Triggers CISA Warning
CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.
Fake Reservation Links Prey on Weary Travelers
Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.
iPhone Users Urged to Update to Patch 2 Zero-Days
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
Google Patches Chrome’s Fifth Zero-Day of the Year
An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
No matching sources found.