Cyber Intelligence
Curated cybersecurity news and threat intelligence
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet has issued a critical security warning for a zero-day vulnerability (CVE-2026-104286) in FortiMail that is actively being exploited in the wild. The flaw allows attackers to execute unauthorized code or commands on affected devices.
Alleged KillSec Ransomware Mastermind a 16-Year-Old
Law enforcement from multiple countries successfully disrupted the KillSec ransomware operation, which had targeted approximately 500 victims globally over a two-year period. The investigation revealed that the alleged mastermind behind the cybercrime operation is a 16-year-old minor.
AI agents hacked the hackers, stealing email addresses from security research org
AI agents exploited chained vulnerabilities in Zammad to breach a security research organization, stealing email addresses through session hijacking and code execution. The attack demonstrated critical flaws enabling rapid root-level escalation in the widely-used helpdesk platform.
Microsoft says threat actors are ahead in the early AI race
Microsoft warns that threat actors are leveraging AI capabilities more effectively than defenders, accelerating vulnerability discovery and malware development. Security teams are struggling to match the pace of AI-enabled attacks, creating a critical defensive gap.
Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing
Chinese-linked threat actors conducted a sophisticated phishing campaign impersonating an Anthropic executive and former White House official to target AI policy influencers through a fake advisory committee invitation. The incident highlights state-sponsored efforts to infiltrate and gather intelligence on key figures in the AI policy and security space.
Microsoft catches hackers exploiting Zimbra bug before disclosure
Microsoft detected attackers actively exploiting a Zimbra mail server vulnerability weeks before it was assigned a CVE identifier. The early detection demonstrates proactive threat hunting and highlights the risk of zero-day exploitation before public disclosure.
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
International law enforcement conducted Operation KillSwitch against the KillSec ransomware gang, seizing their infrastructure and data leak site while making three arrests. The investigation identified a 16-year-old as the alleged administrator of the criminal organization.
Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader
Law enforcement successfully shut down the KillSec ransomware operation, taking control of their leak site and recovering at least 110 terabytes of stolen data from victims. Police have identified and are investigating an alleged teenage leader of the ransomware group.
Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation
A critical zero-day vulnerability in Cisco Catalyst SD-WAN Manager is being actively exploited, allowing unauthenticated remote attackers to gain administrative access to affected systems. This vulnerability poses an immediate threat to organizations using Cisco's SD-WAN infrastructure.
MI5 warns UK academics their research may have helped Chinese spies
MI5 has warned UK academic institutions that their research may have inadvertently assisted Chinese intelligence agencies and urged them to verify funding sources to comply with national security laws. The warning highlights risks of foreign espionage targeting sensitive research through academic partnerships and financing.
China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders
China-linked threat actor TA419 conducted targeted phishing attacks against US AI policy experts by impersonating AI policymakers and economists to compromise Microsoft 365 accounts. The campaign represents a sophisticated social engineering effort targeting high-value government and policy sector individuals involved in AI governance.
Kiteworks patches max severity code injection vulnerability
Kiteworks released security updates addressing 126 vulnerabilities, including a maximum severity code injection flaw in its Email Protection Gateway solution. The patch is critical for users of the secure file-sharing platform to prevent potential exploitation.
CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer
CloudSyncD is a macOS backdoor that disguises itself as a fake Zoom installer to steal passwords and establish a two-stage malware infection on affected systems. This threat represents a significant social engineering attack targeting Mac users through a trusted application mimic.
Warlock Ransomware Hits Large Spanish, Portuguese Orgs
A Chinese-linked threat actor known as Warlock ransomware has attacked large organizations in Spain and Portugal, displaying characteristics of both cybercriminal gangs and state-associated APT groups. The group, active for approximately one year, targets organizations in geographically unexpected locations.
Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure
CVE-2026-73570, a Zimbra vulnerability, is being actively exploited in the wild before its public disclosure. The flaw can be triggered via specially crafted emails without requiring user interaction.
ShinyHunters suspect arrested, and is now investigated over alleged murder plots
A 24-year-old alleged key member of the ShinyHunters cybercrime group has been arrested in the Netherlands. The suspect is also under investigation for allegedly attempting to arrange two murders, adding serious criminal charges beyond cyber offenses.
Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
The US Treasury Department has blacklisted a prominent ATM malware developer and his network as part of ongoing enforcement actions against Tren de Aragua, a criminal organization involved in ATM jackpotting schemes. This government action represents a significant step in disrupting financially motivated cybercriminal operations targeting financial infrastructure.
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
Multiple zero-day vulnerabilities in Zammad were exploited and chained together to achieve session hijacking, remote code execution, and privilege escalation to root level. The DIVD (Dutch Institute for Vulnerability Disclosure) discovered and disclosed these critical flaws in the ticketing system.
Hackers stole Pentagon personnel records of over 3 million people
Hackers breached the Pentagon's Defense Manpower Data Center (DMDC) in October 2025, stealing personal data of over 3 million military service members. The Pentagon is notifying affected personnel of the compromise of their information in the human resources management system.
500,000 Active Credentials Left Exposed on GitHub
Approximately 500,000 active credentials were exposed on GitHub, with 200,000 of those exposed after GitHub enabled push protections by default. This incident highlights the ongoing risk of developers inadvertently committing sensitive authentication credentials to public repositories.
Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
Cisco has released a patch for an exploited zero-day vulnerability in Catalyst SD-WAN that allows remote, unauthenticated attackers to gain administrative access to vulnerable appliances. This critical flaw poses significant risk to organizations using Cisco's SD-WAN infrastructure.
Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders
Google has launched Gemini 4 Argon, a frontier AI model with guardrail-free access for vetted security defenders. The model has demonstrated the ability to identify critical vulnerabilities in widely-used hospital software.
MI5 Warns Over 100 Academics Helped China's Espionage Plans
MI5 has warned that over 100 UK academics have been contributing to China's General Technology Research Institute, potentially aiding Chinese espionage efforts. This represents a significant national security concern regarding intellectual property theft and foreign intelligence gathering.
Metamask discloses security incident affecting its infrastructure
MetaMask, a major cryptocurrency wallet provider, disclosed an ongoing security incident affecting its infrastructure. The incident impacts some of the company's infrastructure systems, though specific details about the scope and nature of the compromise were not provided in the announcement.
FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers
The FTC has launched an investigation into OpenAI and Anthropic regarding potential risks to consumers from their AI systems. The investigation represents regulatory scrutiny of major AI companies and their impact on consumer safety.
Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
Threat actors are exploiting custom GPTs on ChatGPT by abusing legitimate OpenAI and Google domains to deliver remote access trojans (RATs) to unsuspecting users. This social engineering campaign follows the ClickFix attack pattern, using trusted platforms as lures for malware distribution.
Russian state hackers use new RedFlick technique to push malware
Russian state-sponsored actor Star Blizzard has deployed a new malware installation technique called RedFlick to distribute its CosmicPulse backdoor. This represents an evolution in the threat actor's tactics and demonstrates ongoing sophisticated espionage operations by Russian state-backed groups.
DIVD says Zammad zero-days enabled AI-driven network breach
The Dutch Institute for Vulnerability Disclosure (DIVD) disclosed that its network breach was facilitated by exploitation of two zero-day vulnerabilities in the open-source Zammad ticketing system. The vulnerabilities were leveraged in an AI-driven attack against the organization's infrastructure.
16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows
A 16-year-old security researcher discovered a vulnerability in Microsoft systems that granted admin access to databases containing 17.3 trillion rows of data. The finding highlights the value of external security research and responsible disclosure in identifying critical access control issues.
Over 543,000 valid credentials exposed in public GitHub repositories
Over 543,000 valid credentials were discovered exposed in public GitHub repositories in July, representing a significant security risk despite GitHub's built-in protections. The incident highlights the ongoing challenge of preventing accidental leaks of sensitive authentication data in code repositories.
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
CISA has issued a warning about a critical pre-authentication remote code execution vulnerability in MikroTik RouterOS that could allow attackers to execute arbitrary code or cause denial-of-service attacks. This vulnerability affects widely-deployed networking equipment and requires immediate attention from affected organizations.
Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
Russian APT actor Star Blizzard has adopted a new phishing tactic called "RedFlick" to target Ukrainian-linked organizations including NGOs, think tanks, and journalists. The campaign aims to deploy the CosmicPulse backdoor, representing an evolution in the threat actor's attack methodology.
Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco has released security updates to address a critical zero-day vulnerability (CVE-2026-76504) in Catalyst SD-WAN Manager that is actively being exploited by attackers. The flaw allows attackers to escalate privileges to administrator level.
Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
Google's research indicates that AI is accelerating vulnerability discovery and finding different types of vulnerabilities than traditional methods, with discovered vulnerabilities more likely to enable remote code execution. This finding highlights changing threat landscapes as AI tools become more prevalent in security research.
AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
Google research indicates that AI-discovered vulnerabilities have a higher propensity for enabling remote code execution compared to other vulnerability types. The findings highlight increasing trends in both disclosure and active exploitation of these AI-identified security flaws.
WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
WatchGuard has released patches addressing 15 vulnerabilities in Fireware OS, including critical code execution, denial of service, authorization bypass, and path traversal bugs. This proactive patching effort helps secure WatchGuard firewall deployments against multiple attack vectors.
Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
Multiple security firms have confirmed exploitation of two NetScaler zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in ongoing attacks targeting government and financial organizations. The attacks have been occurring over a period of weeks, indicating active and sustained threat activity.
TeamViewer urges users to patch severe flaws “as soon as possible”
TeamViewer has issued an urgent warning to users to immediately patch high-severity vulnerabilities affecting its client and host software. The remote access software company is urging customers to apply patches as soon as possible to mitigate security risks.
Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Chrome and Firefox have released updates addressing over 100 vulnerabilities, some of which could enable remote code execution and sandbox escape attacks. Users are advised to update their browsers immediately to mitigate these critical security risks.
Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware
Cybersecurity researchers at Huntress have identified an active campaign combining ChatGPT feature abuse with ClickFix techniques to deliver trojan malware to users searching for ChatGPT on Google. This attack leverages social engineering and legitimate service vulnerabilities to distribute potent malware to unsuspecting victims.
Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit
Anthropic has raised concerns about liability risks associated with autonomous AI agents, while OpenAI faces a hacking-related lawsuit, highlighting emerging legal questions about responsibility for AI agent actions. The issue marks a shift from theoretical AI safety discussions to real courtroom battles over accountability.
Bitget hacked via zero-day in third-party security products
Cryptocurrency exchange Bitget suffered a major breach resulting in $387.5 million in stolen funds, with attackers exploiting a zero-day vulnerability in third-party security products. The incident highlights risks associated with dependencies on third-party security software.
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
Russian state-sponsored APT group Star Blizzard has been conducting large-scale phishing campaigns using a 'RedFlick' infection chain to deploy the CosmicPulse backdoor malware. This represents a significant escalation in their attack operations and poses a threat to targeted organizations.
Pentagon personnel database breach exposes personal data of millions
A Pentagon personnel database was compromised for nine months before detection, affecting over three million individuals. This significant breach of U.S. military personnel data represents a critical security incident with major national security implications.
ShinyHunters Defiant After FBI Calls on Members to Come Forward
ShinyHunters, a threat actor group, has responded defiantly after an alleged leader's arrest by the FBI, claiming they never intended to publish stolen data. The FBI has publicly called on group members to surrender following the arrest.
Apple Patches CoreGraphics Zero Day Exploited in Attacks
Apple has released a patch for CVE-2026-86950, a zero-day vulnerability in the iOS CoreGraphics engine that was actively exploited in attacks. The vulnerability patch addresses a critical security issue that could have exposed iOS users to compromise.
Spectre bug is back, this time to haunt JIT engines
Researchers have discovered a new variant of the Spectre vulnerability that targets JIT (Just-In-Time) engines by recovering stale indirect branch prediction entries. This represents a significant security threat to systems using JIT compilation, particularly in web browsers and JavaScript engines.
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
South Africa's air traffic control systems have been targeted by a cyberattack involving ransomware toolkit installation on operational networks. This incident represents a significant threat to critical aviation infrastructure and prompted the country to seek external assistance.
High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
OpenSSL and WolfSSL, widely-used open source cryptographic libraries, have each received patches addressing approximately a dozen high-severity vulnerabilities. These patches are critical for securing systems that rely on these foundational security libraries.
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Apple has disclosed that CVE-2026-86950, an out-of-bounds write vulnerability, is being actively exploited by attackers in targeted campaigns. The flaw represents a zero-day vulnerability being weaponized in sophisticated attacks against Apple systems.