2026-08-14 14:59 UTC
Security Journalism
TIER 3
BleepingComputer · Bill Toulas · indexed 2026-08-16 02:02 UTC
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]
P10
2026-08-14 06:41 UTC
Security Journalism
TIER 3
SecurityWeek · Ionut Arghire · indexed 2026-08-16 02:02 UTC
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions appeared first on SecurityWeek.
P0
2026-08-14 01:19 UTC
Security Journalism
TIER 3
BleepingComputer · Mayank Parmar · indexed 2026-08-16 02:02 UTC
You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack targeted at your iPhone." [...]
P0
2026-08-11 09:16 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of
P15
2026-08-10 17:09 UTC
Security Journalism
TIER 3
Dark Reading · Alexander Culafi · indexed 2026-08-16 02:02 UTC
Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.
P0
2026-08-07 18:29 UTC
Security Journalism
TIER 3
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture. "
P0
2026-08-06 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC
Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory…
P0
2026-08-05 16:01 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVE-2026-20303CVE-2026-20304CVE-2026-20310CVE-2026-20312CVE-2026-20313 Critical 9.9 Cisco IOS XE Software Security Hardening Release: August 2026 CVE-2026-20267CVE-2026-20268CVE-2026-20269CVE-2026-20270CVE-2026-20271CVE-2026-20272CVE-2026-20273 Critical 9.8 Cisco Integrated Management Controller Argument Injection Vulnerabilities CVE-2026-2020…
P5
2026-08-05 16:00 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are no…
P5
2026-08-05 16:00 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker could exploit this vulnerability by sending a specific BEEP SOAP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. Cisco has released software updates that address this vulnerabilit…
P5
2026-08-05 16:00 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP — Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker mus…
P5
2026-08-05 16:00 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacke…
P5
2026-08-05 16:00 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single …
P30
2026-08-05 16:00 UTC
Vendor Research
TIER 1
Cisco Security Advisories · indexed 2026-08-16 02:02 UTC
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive. Cisco has released software updates that address this vulnerability. There ar…
P5
2026-08-05 15:48 UTC
Vendor Research
TIER 2
Microsoft Security Blog · Microsoft Security Research and Srinivasan Govindarajan · indexed 2026-08-16 02:02 UTC
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving defenders new hunting opportunities. The post From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide appeared first on Microsoft Security Blog.
P0
2026-08-05 12:45 UTC
Vendor Research
TIER 2
Tenable Blog · Ziga Cerkovnik · indexed 2026-08-16 02:02 UTC
Discover how Tenable Hexa AI closes the gap between exposure management and endpoint patching using intent-driven routines, smart guardrails, and human approval.Key takeawaysThe problem: A slow handoff between security workflows creates a days-long remediation gap. The solution: Tenable Hexa AI bridges this gap using intent-driven Routines that automate scoping, deployment, and verification across integrated platforms like Jamf. Safety and control: Autonomy is governed by the harness built into Tenable One, ensuring the AI operates strictly within defined user permissions and guardrails.Find …
P25
2026-07-31 10:00 UTC
Vendor Research
TIER 2
Palo Alto Networks Unit 42 · Adva Gabay and Noa Dekel · indexed 2026-08-16 02:02 UTC
Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42.
P0
2026-07-30 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC
Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to conduct supply chain compromises over the past several years. A series of large scale open source s…
P15
2026-07-24 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC
Update (July 30): A table listing the new names of select prominent threat actors was appended to this post. Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Why are we Adopting a Different Naming System? Historically, Mandiant and Google’s Threat Analysis Group (TAG) maintained distinct tracking systems, relying on parallel naming schemas that grew independently over time. The creation of GTIG has ne…
P0
2026-07-16 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC
Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration and continuous delivery (CI/CD) pipelines for automated vulnerability discovery and remediation. However, deploying privileged artificial intelligence (AI) agents without mature integration processes…
P10
2026-07-15 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC
Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RFI) Command Injection Successful exploitation of these vulnerabilities can grant an attacker full control over the underlying container instance. Such access can serve as a fo…
P15
2026-07-14 14:23 UTC
Vendor Research
TIER 2
Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC
56Critical510Important3Moderate0LowMicrosoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate. This marks the largest Patch Tuesday release ever, crushing the previous record of 198 CVEs in June. Last week, Microsoft announced that its multi-model agentic scanning harness (MDASH) is being used to identify vulnerabilities faster and noted that “customers will …
P65
2026-07-07 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC
Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and all identity-based controls. However, during a recent red team engagement, Mandiant discovered that …
P0
2026-06-11 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC
Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity p…
P45
2026-05-29 14:19 UTC
Vendor Research
TIER 1
Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC
Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered a 1-click open redirection technique in Amazon Cognito that can be triggered by abusing the OAuth error-handling mechanism. The vulnerability stems from AWS's OAuth implementation validation sequence: if validation fails due to an unsupported scope, mismatched PKCE parameters, or an unsupported response type, the error handling processes the failure and automatically issues an HTTP redirect to an attacker-controlled redirect_uri. Because the identity platform evaluates th…
P0
2026-05-29 13:56 UTC
Vendor Research
TIER 1
Tenable Research Advisories · Ben Smith · indexed 2026-08-16 02:02 UTC
Microsoft Entra ID 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered new techniques to trigger 1-click open redirection attacks in Microsoft Entra ID by abusing the OAuth error-handling mechanism. The attack relies on an initial setup phase where a threat actor registers an OAuth application in an actor-controlled tenant and configures its redirect_uri to point to an attacker-controlled domain. When a victim clicks on a specifically crafted authorization link on the trusted login.microsoftonline.com domain, combinations of malformed pa…
P0
2026-05-25 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC
Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE). An unknown threat actor leveraged this access to inject malicious code into the LMS platform, with the goal of infecting users visiting the site. This vulnerability stems from the use of identi…
P55
2026-05-25 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC
While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that region. These services not only lower the barrier to entry for Chinese cyber criminals, but reveal broader patterns on the evolution of social engineering and credential theft. Late last year, Google…
P0
2026-05-11 14:00 UTC
Vendor Research
TIER 2
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC
Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a sophisticated engine for adversary operations and a high-value target for attacks. We explore the foll…
P60