Threat Intelligence

Live from 5 sources · updated 22:44, 10 Jul 2026

↻ Refresh
Total stories
58
all sources
Vulnerabilities
8
CVEs & exploits
Malware / APT
9
active campaigns
Breaches
2
data leaks
Sources live
5/7
The Hacker News, SANS ISC, Talos
Threat categories
Vulnerability 8 Malware 8 APT 1 Breach 2 Other 39
Stories by source
Source:
Category:
The Hacker News
1

SecurityInjective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

The Hacker News 5h ago Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious packa
2

VulnerabilitySix New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

The Hacker News 6h ago Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardw
3

SecurityLaser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched

The Hacker News 7h ago Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a T
4

VulnerabilityResearcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

The Hacker News 8h ago Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that,
5

MalwareNew MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

The Hacker News 9h ago The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MO
6

VulnerabilityUnpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

The Hacker News 10h ago A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a sh
7

SecurityFrom 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale

The Hacker News 11h ago Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey
8

BreachExposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

The Hacker News 11h ago A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner work
9

BreachStudy of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

The Hacker News 11h ago Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fa
10

SecurityHackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

The Hacker News 12h ago A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Micr
11

VulnerabilityAttackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

The Hacker News 13h ago Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it.
12

MalwareRansomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks

The Hacker News 14h ago A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for thei
SANS ISC
13

SecurityMy Stack Simulator, (Wed, Jul 8th)

SANS ISC 6h ago The stack is a memory region where a program stores temporary data -Â&&amp
14

Malware"Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)

SANS ISC 13h ago Anyone who deals with phishing messages caught by basic security filters knows that most phishing samples tend to blend into one a
15

SecurityISC Stormcast For Friday, July 10th, 2026 https://isc.sans.edu/podcastdetail/10002, (Fri, Jul 10th)

SANS ISC 20h ago (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
16

SecurityISC Stormcast For Thursday, July 9th, 2026 https://isc.sans.edu/podcastdetail/10000, (Thu, Jul 9th)

SANS ISC 1d ago (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
17

Security_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th)

SANS ISC 1d ago [This is a Guest Diary by Jason Callahan, an ISC intern as part of the SANS.edu BACS program]
18

SecurityISC Stormcast For Wednesday, July 8th, 2026 https://isc.sans.edu/podcastdetail/9998, (Wed, Jul 8th)

SANS ISC 2d ago (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
19

SecurityMore Odd DNS Records: NIMLOC, (Tue, Jul 7th)

SANS ISC 3d ago Yesterday, I talked about NAPTR records and how they are related to RCS. But there is another "odd" record that shows up in my DNS
20

SecurityISC Stormcast For Tuesday, July 7th, 2026 https://isc.sans.edu/podcastdetail/9996, (Tue, Jul 7th)

SANS ISC 3d ago (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
21

APTRCS and DNS: The NAPTR Record, (Mon, Jul 6th)

SANS ISC 4d ago Over the last year, with recent updates to iOS and Android, RCS (Rich Communication Services) has become an increasingly used prot
22

SecurityISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th)

SANS ISC 4d ago (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Talos
23

VulnerabilityWolfSSL, GeoVision, VTK vulnerabilities

Talos 1d ago Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in G
24

SecurityWinning 54% of the time

Talos 1d ago With Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be
25

MalwareUAT-7810 continues building ORB networks using new malware

Talos 3d ago Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.
26

SecurityCatan and Mouse

Talos 8d ago What do board games and cybersecurity have in common? Pattern recognition. Strategy. Adaptation. In this week’s Threat Source Bill
27

SecurityMartin Lee: Running through the Arctic (and the threat landscape)

Talos 9d ago Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? In this Humans of Talos, we’re joined by
28

SecurityARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365

Talos 9d ago Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API end
29

SecurityBeyond IOCs: AI-enabled threat intelligence

Talos 15d ago In this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of in
30

SecurityIntroduction to COM usage by Windows threats

Talos 15d ago Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-proc
31

SecurityClose Encounters of the Human Kind

Talos 22d ago In the latest Threat Source, Hazel channels her inner Spielberg to explore why humans are delightfully irrational, reminding us th
32

SecurityScripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model

Talos 22d ago Cisco Talos detailed a new approach to reverse engineering that pairs local AI agents with traditional analysis tools like the VB6
33

SecurityA tale of two eras

Talos 29d ago In this week’s newsletter, Amy reminisces on the tech toys of their childhood, inspired by a hilarious lesson about why your digit
34

VulnerabilityMicrosoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities

Talos 31d ago Microsoft Patch Tuesday details for June 2026.
Unit 42
35

MalwareVidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

Unit 42 3d ago A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel ev
36

SecurityHow We Added WebAuthn to a Browser-Based RDP Client

Unit 42 8d ago A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection.
37

SecurityPhantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

Unit 42 9d ago Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more
38

SecurityThreat Brief: Mitigating Large-Scale Credential Attacks

Unit 42 14d ago We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting securi
39

SecurityCL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

Unit 42 15d ago Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, includ
40

SecurityOpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

Unit 42 17d ago Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute ag
41

MalwareThe Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration

Unit 42 18d ago Unit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams acr
42

VulnerabilityPickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

Unit 42 24d ago Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article f
43

SecurityInside the Modern SOC: The 72-Minute Race

Unit 42 24d ago Attackers can move from access to exfiltration in 72 minutes. Learn how modern SOC teams close the speed gap with Unit 42's AI-dri
44

SecurityTracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered

Unit 42 28d ago Unit 42 has discovered a new macOS Tahoe 26 forensic artifact that tracks user menu selections across the operating system. Learn
45

SecurityTrust No Skill: Integrity Verification for AI Agent Supply Chains

Unit 42 29d ago Protect enterprise AI agents from supply chain risks by auditing third-party skills for hidden vulnerabilities and multi-stage att
46

SecurityBlinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility

Unit 42 31d ago Unit 42 research examines attack scenarios targeting cloud logging services. Learn how to defend against log manipulation and defe
CheckPoint
47

SecurityCavern Manticore: Exposing Iran-Linked Modular C2 Framework

CheckPoint 4d ago Key Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used
48

Security6th July – Threat Intelligence Report

CheckPoint 4d ago For the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin. TOP ATTAC
49

Security22nd June – Threat Intelligence Report

CheckPoint 9d ago For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTA
50

MalwareBrowser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique

CheckPoint 9d ago Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, large language models have reshaped sof
51

Security29th June – Threat Intelligence Report

CheckPoint 11d ago For the latest discoveries in cyber research for the week of 29th June, please download our Threat Intelligence Bulletin. TOP ATTA
52

SecurityFrom Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker

CheckPoint 23d ago Key Points Introduction In this research, we analyze a clipboard hijacker campaign that is hidden inside a collection of “solution
53

Security15th June – Threat Intelligence Report

CheckPoint 25d ago For the latest discoveries in cyber research for the week of 15th June, please download our Threat Intelligence Bulletin. TOP ATTA
54

VulnerabilityFrom SQLi to RCE – Exploiting LangGraph’s Checkpointer

CheckPoint 29d ago By Yarden Porat AI agents need memory. Frameworks like LangGraph provide it through checkpointers – persistence layers that
55

Security8th June – Threat Intelligence Report

CheckPoint 32d ago For the latest discoveries in cyber research for the week of 8th June, please download our Threat Intelligence Bulletin. TOP ATTAC
56

MalwareImpersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem

CheckPoint 37d ago Research by: Alexey Bukhteyev Key Takeaways Introduction When we search Google for a popular piece of software, we usually cl
57

Security1st June – Threat Intelligence Report

CheckPoint 39d ago For the latest discoveries in cyber research for the week of 1st June, please download our Threat Intelligence Bulletin. TOP ATTAC
58

SecurityAI Threat Landscape Digest March-April 2026

CheckPoint 45d ago Executive Summary During the March–April 2026 reporting period, AI use in offensive operations advanced from development and plann

The Hacker News · SANS ISC · Talos · SecureList · Unit 42 · CheckPoint · Dark Reading ·
No tracking · No ads · Server-side RSS · Cached 30 min

Innovative Project Ideas?

You can always reach out to us by going to the Contact Us page

Harnessing the power of AI and next-generation cybersecurity, Aiomoshield protects what matters most

Product

Analytics & Reporting

Email Marketing

PPC Advertising

SEO Optimization

Soc. Media Management

Content Marketing

Resources

Blog

Case Studies

Ebooks & Guides

Webinars

FAQs

Press & Media

Quick Links

Get a Free Quote

Request a Demo

Pricing Plans

Testimonials

Support Center

Legal

Terms of Service

Privacy Policy

Cookie Policy

Disclaimer

Data Processing Agreement