Threat Intelligence

Live from 5 sources · updated 21:21, 24 Jul 2026

↻ Refresh
Total stories
58
all sources
Vulnerabilities
13
CVEs & exploits
Malware / APT
13
active campaigns
Breaches
0
data leaks
Sources live
5/7
The Hacker News, SANS ISC, Talos
Threat categories
Vulnerability 13 Malware 10 APT 3 Breach 0 Other 32
Stories by source
Source:
Category:
The Hacker News
1

MalwareBlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The Hacker News 6h ago The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have
2

VulnerabilityCertighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

The Hacker News 7h ago Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain
3

VulnerabilityChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

The Hacker News 9h ago Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a s
4

VulnerabilityBing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

The Hacker News 9h ago A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing work
5

VulnerabilitySeeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

The Hacker News 9h ago AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've col
6

VulnerabilityHacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

The Hacker News 11h ago Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running
7

MalwareGolden Chickens Resurfaces With Four New Malware Families and Modular Implants

The Hacker News 11h ago The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families,
8

VulnerabilityNodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

The Hacker News 13h ago Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as h
9

VulnerabilityKimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

The Hacker News 14h ago Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9,
10

SecurityFake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

The Hacker News 14h ago The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious progra
11

APTRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

The Hacker News 1d ago A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail c
12

VulnerabilityThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

The Hacker News 1d ago Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safe
SANS ISC
13

SecurityISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)

SANS ISC 19h ago (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
14

SecurityWhen the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)

SANS ISC 1d ago Two disclosures, five days apart, described the same intrusion from opposite ends — one from the victim, one
15

SecurityISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd)

SANS ISC 1d ago (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
16

SecurityRondo Meets Geoserver, (Wed, Jul 22nd)

SANS ISC 2d ago This isn't a new attack, but something I saw "pop-up" in our logs this week:&#x
17

SecurityISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd)

SANS ISC 2d ago (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
18

APTCaptive Portal Detection, (Tue, Jul 21st)

SANS ISC 3d ago Not everything our honeypots detect is an attack. Sometimes it is just "odd traffic", and this is one example: Our "First Seen" li
19

SecurityISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)

SANS ISC 3d ago (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
20

VulnerabilityWordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

SANS ISC 4d ago Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially a
21

SecurityISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th)

SANS ISC 4d ago (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
22

SecurityScans for Hikvision Intelligent Security API, (Sun, Jul 19th)

SANS ISC 5d ago We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a l
Talos
23

SecurityDon’t swing at everything

Talos 1d ago Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than eve
24

MalwareChaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Talos 1d ago The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but c
25

SecurityPreview: Cisco Talos at Black Hat USA 2026

Talos 1d ago Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.
26

SecurityBegun, the Patch Wars have

Talos 8d ago Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.
27

SecurityThe Hunter's Paradox: Is it time to embrace automated threat hunting?

Talos 8d ago Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David disc
28

MalwareUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

Talos 8d ago Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a
29

VulnerabilityMicrosoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities

Talos 10d ago Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products
30

Malware[Video] Where protection starts: Cisco Talos Intelligence Integrations

Talos 10d ago Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations
31

SecurityThe serpent’s tongue: Luring the Python out of its den

Talos 10d ago This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, throug
32

VulnerabilityWolfSSL, GeoVision, VTK vulnerabilities

Talos 15d ago Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in G
33

SecurityWinning 54% of the time

Talos 15d ago With Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be
34

MalwareUAT-7810 continues building ORB networks using new malware

Talos 17d ago Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.
Unit 42
35

APTRussian Global Webmail Espionage

Unit 42 1d ago Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credential
36

VulnerabilityThree Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

Unit 42 7d ago A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and p
37

SecurityAI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report

Unit 42 7d ago Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The
38

SecurityThe npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)

Unit 42 8d ago Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and
39

MalwareTuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

Unit 42 9d ago TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture an
40

MalwareNo Manners Here: The Ruthless Rise of The Gentlemen Ransomware

Unit 42 13d ago Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The
41

MalwareVidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

Unit 42 16d ago A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel ev
42

SecurityHow We Added WebAuthn to a Browser-Based RDP Client

Unit 42 21d ago A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection.
43

SecurityPhantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

Unit 42 23d ago Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more
44

SecurityThreat Brief: Mitigating Large-Scale Credential Attacks

Unit 42 28d ago We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting securi
45

SecurityCL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

Unit 42 28d ago Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, includ
46

SecurityOpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

Unit 42 30d ago Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute ag
CheckPoint
47

Security20th July – Threat Intelligence Report

CheckPoint 4d ago For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTA
48

SecurityAI Security Report 2026

CheckPoint 10d ago For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, ch
49

Security13th July – Threat Intelligence Report

CheckPoint 11d ago For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTA
50

SecurityCavern Manticore: Exposing Iran-Linked Modular C2 Framework

CheckPoint 18d ago Key Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used
51

Security6th July – Threat Intelligence Report

CheckPoint 18d ago For the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin. TOP ATTAC
52

Security22nd June – Threat Intelligence Report

CheckPoint 23d ago For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTA
53

MalwareBrowser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique

CheckPoint 23d ago Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, large language models have reshaped sof
54

Security29th June – Threat Intelligence Report

CheckPoint 25d ago For the latest discoveries in cyber research for the week of 29th June, please download our Threat Intelligence Bulletin. TOP ATTA
55

SecurityFrom Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker

CheckPoint 37d ago Key Points Introduction In this research, we analyze a clipboard hijacker campaign that is hidden inside a collection of “solution
56

Security15th June – Threat Intelligence Report

CheckPoint 39d ago For the latest discoveries in cyber research for the week of 15th June, please download our Threat Intelligence Bulletin. TOP ATTA
57

VulnerabilityFrom SQLi to RCE – Exploiting LangGraph’s Checkpointer

CheckPoint 43d ago By Yarden Porat AI agents need memory. Frameworks like LangGraph provide it through checkpointers – persistence layers that
58

Security8th June – Threat Intelligence Report

CheckPoint 46d ago For the latest discoveries in cyber research for the week of 8th June, please download our Threat Intelligence Bulletin. TOP ATTAC

The Hacker News · SANS ISC · Talos · SecureList · Unit 42 · CheckPoint · Dark Reading ·
No tracking · No ads · Server-side RSS · Cached 30 min

Innovative Project Ideas?

You can always reach out to us by going to the Contact Us page

Harnessing the power of AI and next-generation cybersecurity, Aiomoshield protects what matters most

Product

Analytics & Reporting

Email Marketing

PPC Advertising

SEO Optimization

Soc. Media Management

Content Marketing

Resources

Blog

Case Studies

Ebooks & Guides

Webinars

FAQs

Press & Media

Quick Links

Get a Free Quote

Request a Demo

Pricing Plans

Testimonials

Support Center

Legal

Terms of Service

Privacy Policy

Cookie Policy

Disclaimer

Data Processing Agreement