Whats The Hax? Signal / noise
Threat intel

Threats, breaches, and defensive intelligence.

Security intelligence Threat intel

Threat intelligence

Follow malware research, ransomware activity, nation-state reporting, phishing campaigns, botnets, and adversary tradecraft from security research teams.

Latest loaded

Angry Birds: Toy Ghouls’ new toys

Securelist · 2d ago
Complete index

Source grid

Every loaded article, grouped by its original feed. Search scans source names and headlines.

Density
Sort
Threat intel Securelist

10 entries on this page

Angry Birds: Toy Ghouls’ new toys 2d ago Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the o… Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set 5d ago Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript. ValleyRAT masquerading as adware 6d ago Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload. Threat landscape for industrial automation systems. Q2 2026 10d ago The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control syst… Exploits and vulnerabilities in Q2 2026 11d ago This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents an… The invisible passenger in your car 16d ago Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It’s delivered through legitimate software for DoFun head units. APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit 23d ago Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and t… Armored Likho expands its cyber-espionage toolkit 24d ago Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on… Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants 26d ago Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems… Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection 26d ago Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade…
Threat intel Recorded Future

20 entries on this page

Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization 3d ago Recorded Future's Automated Signature Creation turns new vulnerabilities into detection signatures in under an hour, matching the pace of AI-driven exploits. H1 2026 Malware Vulnerability Trends 4d ago Learn how adversaries abuse trusted tools, AI, and developer environments for cyberattacks. Get actionable insights on ransomware, mobile threats, and supply chain security. The Agentic SOC – From AI Theater to Real Defense 6d ago Experts from Recorded Future and Accenture offer perspectives on navigating the path to becoming an agentic SOC. Find out how to plan moving beyond “AI theater” by prioritizing me… BlueDelta Targets Defense and Diplomacy with HOOKEDGE 11d ago Discover how the Russian state-sponsored threat group BlueDelta is using the HOOKEDGE backdoor to target defense and diplomatic organizations across Europe Recorded Future Launches AI Alert Filtering 12d ago Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense 13d ago Recorded Future Launches 6 New Capabilities for Third-Party Risk 19d ago CopyCop Targets AI Investment in Armenia 20d ago PurpleDelta's Fraudulent Employment Operations 20d ago Malware Crypting Services and the Threat Actors Who Sell Them 25d ago Mines, Minds, and Machines: The Journey of AI 27d ago The Hugging Face Hack Was Cheap Persistence at Work 28d ago July 2026 CVE Landscape 31d ago Emerging Threats to Neurotechnology 32d ago Hype vs. Reality: What the Hugging Face Incident Means for AI Safety 33d ago 8 Ways AI is Changing Threat Intelligence 35d ago Dealing with AI-Generated Extortion 39d ago Iran War’s Secondary Effects Shape 2026 US Violent Extremism 39d ago Ransomware is the Scoreboard 45d ago TAG-195 Upgrades MaaS Ecosystem with Modular Tools 46d ago
Threat intel Proofpoint News Feed

10 entries on this page

Proofpoint Brings OpenAI GPT Cyber Models into Security Operations to Help Defenders Investigate Threats Faster 3d ago New Proofpoint SOC Analyst Agent combines Proofpoint security expertise with OpenAI Daybreak models to help analysts investigate threats, connect security signals and determine ne… Cybercriminals Turn to Indirect Prompt Injection Attacks 24d ago Cybercriminals are developing indirect prompt injection tools to target AI agents. Russian hackers can steal emails without a click 30d ago Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today’s Most Sophisticated Threats 33d ago Recognition highlights Proofpoint's deep technical integration with Google Cloud Security solutions and commitment to helping organizations protect people, data and AI Helps Proofpoint Launches OEM Program to Help Security Providers Embed Trusted Threat Intelligence and Detection Capabilities 33d ago Accelerates OEM innovation by embedding trusted threat intelligence into security products and customer-facing workflows. Helps partners deliver more prioritized, Max-severity Exchange server flaw under active exploitation by Kremlin hackers 38d ago New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors 45d ago Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes 45d ago US and allies say Russian hackers stole emails without social engineering 45d ago The United States and more than a dozen allied nations said on Thursday that Russian hackers stole emails from users of ​the Zimbra email program without having to fool them into… If you pay a hacker’s ransom, chances are that they’ll come back for more 46d ago
Threat intel WeLiveSecurity

30 entries on this page

I’ve been deepfaked: What do I do? 4d ago This month in security with Tony Anscombe – August 2026 edition 6d ago AI-assisted reconnaissance: Why everyone could be a viable target for fraud 10d ago How QR-code phishing can slip past corporate security measures 20d ago Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era? 24d ago Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility 24d ago Black Hat USA 2026: AI is racing ahead of cybersecurity controls 25d ago Are AI tutors safe for your kids? 27d ago This month in security with Tony Anscombe – July 2026 edition 37d ago Beyond the screenshot: Why you should verify what you see 38d ago Forgotten UEFI shims undermining Secure Boot 54d ago ESET Threat Report H1 2026 60d ago Cyber readiness for SMBs: Getting the basics right 65d ago This month in security with Tony Anscombe – June 2026 edition 68d ago Inside the inbox: Why cybercriminals want to break into your email account 69d ago SMB cyber readiness: the road to resilience starts here 72d ago Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances 73d ago ESET takes part in Operation Endgame to disrupt Amadey and Stealc 74d ago Killing me gently: Inside Gentlemen’s EDR killer framework 80d ago Protecting legacy OT systems against modern cyberthreats 81d ago FishMonger’s arsenal upgraded: SprySOCKS for Windows 82d ago EvilTokens: A phishing attack that doesn’t steal your password 83d ago OceanLotus: From external espionage to domestic targeting 87d ago Unpacking SMB cyber-readiness – and what makes or breaks it 88d ago Cybercriminals: the 'auditors' you never hired 89d ago Lessons for life: Why children’s data is a long-term identity risk 95d ago This month in security with Tony Anscombe – May 2026 edition 100d ago ESET APT Activity Report Q4 2025–Q1 2026 101d ago What to consider before asking an AI chatbot for health advice 102d ago BTMOB: A stealthy RAT burrowing deep into Android devices 103d ago
Threat intel SANS Internet Storm Center, InfoCON: green

10 entries on this page

Threat intel Trend Micro Research, News, Perspectives

20 entries on this page

Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility 39d ago Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave 40d ago The Signs Were There: What the First Autonomous Ransomware Case Confirms 45d ago Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It 46d ago Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure 46d ago 13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan 46d ago Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass 47d ago Volume Is Not Risk: Making Sense of the “Vulnpocalypse” 48d ago Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet 55d ago TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry 70d ago From Langflow to Monero: Inside CVE-2026-33017 Cryptominer 76d ago PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM 81d ago Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign 82d ago GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026 89d ago Governing Claude Enterprise in Environments Where Inline Controls Can't Go 91d ago Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open 91d ago Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet 98d ago Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet 104d ago Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware 108d ago One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign 109d ago
Threat intel Threatpost

10 entries on this page

Student Loan Breach Exposes 2.5M Records 1467d ago 2.5 million people were affected, in a breach that could spell more trouble down the line. Watering Hole Attacks Push ScanBox Keylogger 1468d ago Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool. Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms 1469d ago Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system. Ransomware Attacks are on the Rise 1472d ago Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group. Cybercriminals Are Selling Access to Chinese Surveillance Cameras 1473d ago Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed. Twitter Whistleblower Complaint: The TL;DR Version 1474d ago Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk. Firewall Bug Under Active Attack Triggers CISA Warning 1475d ago CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP. Fake Reservation Links Prey on Weary Travelers 1476d ago Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels. iPhone Users Urged to Update to Patch 2 Zero-Days 1479d ago Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack. Google Patches Chrome’s Fifth Zero-Day of the Year 1480d ago An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.

No matching sources found.