CYBERSECURITY INTEL FREE'Dself-hosted CTI

LATEST // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 44 matching records.
AUTO-POLL // 2026-08-16 03:50 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-08-14 21:36 UTC
Vendor Research
TIER 2

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

Tenable Blog · Research Special Operations · indexed 2026-08-16 02:02 UTC

Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts, and exfiltrated more than 2,564 personnel records in approximately four days.The Taiwan campaign is…

AI SecurityAPT / Nation-StateCloud SecurityInitial AccessNetwork SecurityThreat ActorsVulnerabilities CVE-2025-3248
P30
2026-08-13 06:09 UTC
Security Journalism
TIER 3

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication

MicrosoftThreat ActorsVulnerabilities CVE-2026-55040
P15
2026-08-12 17:39 UTC
Security Journalism
TIER 3

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and

APT / Nation-StateMalwareMicrosoftThreat ActorsVulnerabilities
P25
2026-08-12 09:01 UTC
Security Journalism
TIER 3

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were

Threat ActorsVulnerabilities CVE-2026-59310
P5
2026-08-11 18:36 UTC
Security Journalism
TIER 3

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,

APT / Nation-StateMalwareNetwork SecurityThreat Actors
P0
2026-08-10 16:38 UTC
Security Journalism
TIER 3

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted

MicrosoftRansomwareThreat ActorsThreat Intelligence
P15
2026-08-10 11:33 UTC
Security Journalism
TIER 3

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026. The activity involves exploiting a vulnerability chain

Cloud SecurityThreat ActorsVulnerabilities
P0
2026-08-08 06:57 UTC
Security Journalism
TIER 3

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. "We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said. "This is not a duplicate of our

DFIRMicrosoftThreat Actors
P0
2026-08-07 18:16 UTC
Security Journalism
TIER 3

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via

PhishingThreat Actors
P0
2026-08-07 12:00 UTC
Vendor Research
TIER 2

Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026

Tenable Blog · Nick Hayes · indexed 2026-08-16 02:02 UTC

Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event.Key takeawaysBuilding defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove the cost of finding and exploiting a vulnerability down to 1990s levels; it also removed the engineering barrier that kept defenders from building the automation they’ve always wanted. The unglamorous work won the room: triage, reconciliation…

AI SecurityCloud SecurityMicrosoftThreat ActorsVulnerabilities
P0
2026-08-06 17:00 UTC
Independent Research
TIER 2

Canadian Man Pleads Guilty in Snowflake Extortions

Krebs on Security · BrianKrebs · indexed 2026-08-16 02:02 UTC

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.

CybercrimeThreat Actors
P0
2026-08-06 14:00 UTC
Vendor Research
TIER 2

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory…

AppleCredential ExposureData BreachesInitial AccessMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-07-31 21:01 UTC
Vendor Research
TIER 2

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-08-16 02:02 UTC

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first on Microsoft Security Blog.

MalwareMicrosoftPhishingThreat Actors
P0
2026-07-30 16:05 UTC
Vendor Research
TIER 2

Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

Tenable Blog · Ashley Lukeeram · indexed 2026-08-16 02:02 UTC

Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance.Key takeaways:Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active Querying for isolated, hard-to-reach process-control systems, enables operators to establish a requir…

Cloud SecurityDFIRICS / OTThreat ActorsThreat IntelligenceVulnerabilities
P10
2026-07-30 14:00 UTC
Vendor Research
TIER 2

Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to conduct supply chain compromises over the past several years. A series of large scale open source s…

AI SecurityAppleAPT / Nation-StateCredential ExposureCybercrimeData BreachesDFIRLinuxMalwareRansomwareThreat ActorsThreat Intelligence
P15
2026-07-30 10:00 UTC
Vendor Research
TIER 2

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-16 02:02 UTC

Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42.

Threat Actors
P0
2026-07-29 21:00 UTC
Vendor Research
TIER 2

Amazon identifies North Korean hacker group behind open-source supply chain attacks

AWS Security Blog · CJ Moses · indexed 2026-08-16 02:02 UTC

Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the […]

Threat ActorsThreat Intelligence
P0
2026-07-24 14:00 UTC
Vendor Research
TIER 2

Updated Cyber Threat Actor Naming System

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Update (July 30): A table listing the new names of select prominent threat actors was appended to this post. Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Why are we Adopting a Different Naming System? Historically, Mandiant and Google’s Threat Analysis Group (TAG) maintained distinct tracking systems, relying on parallel naming schemas that grew independently over time. The creation of GTIG has ne…

AppleAPT / Nation-StateDFIRMicrosoftThreat ActorsThreat Intelligence
P0
2026-07-20 09:36 UTC
Vendor Research
TIER 2

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-08-16 02:02 UTC

An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.Key takeaways:Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations. Multiple security firms have confirmed in-the-w…

Cloud SecurityDFIRMicrosoftNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-60137CVE-2026-601377CVE-2026-63030
P70
2026-07-16 14:00 UTC
Vendor Research
TIER 2

Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration and continuous delivery (CI/CD) pipelines for automated vulnerability discovery and remediation. However, deploying privileged artificial intelligence (AI) agents without mature integration processes…

AI SecurityAppleMicrosoftThreat ActorsThreat IntelligenceVulnerabilities
P10
2026-07-16 12:00 UTC
Vendor Research
TIER 2

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.Key TakeawaysCISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-202…

Cloud SecurityMalwareMicrosoftRansomwareThreat ActorsVulnerabilities CVE-2026-32201CVE-2026-45659CVE-2026-55040CVE-2026-56164CVE-2026-58644
P95
2026-07-15 14:00 UTC
Vendor Research
TIER 2

The Risk of Exposed Cloud Functions and How to Harden

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RFI) Command Injection Successful exploitation of these vulnerabilities can grant an attacker full control over the underlying container instance. Such access can serve as a fo…

AI SecurityAppleCloud SecurityInitial AccessMalwareThreat ActorsVulnerabilities
P15
2026-07-15 13:14 UTC
Vendor Research
TIER 2

CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild

Tenable Cyber Exposure Alerts · Scott Caveza · indexed 2026-08-16 02:02 UTC

SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.Key takeawaysCVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances. Zero-day exploitation of these vulnerabilities has been observed and confirmed by SonicWall. Patches and indicators of compromise are available and urgent patching is recommended.BackgroundSonicWall's Secure Mobile Ac…

Cloud SecurityNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-15409CVE-2026-15410
P100
2026-07-07 14:00 UTC
Vendor Research
TIER 2

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and all identity-based controls. However, during a recent red team engagement, Mandiant discovered that …

AppleCredential ExposureMicrosoftThreat ActorsThreat Intelligence
P0
2026-06-25 14:00 UTC
Vendor Research
TIER 2

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyber espionage, this backdoor shares significant code and functional overlaps with KAZUAR, a successf…

APT / Nation-StateMalwareMicrosoftThreat ActorsThreat Intelligence
P0
2026-06-24 11:00 UTC
Vendor Research
TIER 2

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. The vulnerability stems from the device’s file upload feature lacking the ability to properly filter malicious data. Throughout the intrusion, to maintain operational security and avoid det…

Initial AccessMicrosoftNetwork SecurityThreat ActorsVulnerabilities CVE-2026-20127CVE-2026-20182CVE-2026-20245
P40
12