Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: bleeping-computer Clear filter
Police suspects Dutch hackers were involved in Odido breach

1mo ago · bleeping-computer

The Dutch National Police suspect that Dutch hackers were involved in a February 2026 data breach at telecommunications provider Odido. A Dutch-speaking individual impersonated an IT employee in a phone call prior to the attack, enabling the threat actors to conduct phishing and steal personal data of up to 6.2 million customers. The ShinyHunters extortion gang claimed responsibility, publishing an 88GB archive with over 15 million records, continuing their pattern of targeting large organizations through social engineering and SSO compromises.

1 Actors
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison

1mo ago · bleeping-computer

Karen Serobovich Vardanyan, a 34-year-old Armenian national, has pleaded guilty to providing initial access to corporate networks for the Ryuk ransomware operation between November 2019 and April 2020. He facilitated attacks on multiple U.S. organizations, including a Michigan company, a technology firm in Oregon, and a school in Texas, leading to approximately $15 million in ransom payments. Vardanyan was extradited from Kyiv and faces up to 15 years in prison, with sentencing scheduled for September 2026.

1 Malware
Zimbra urges customers to patch critical web client XSS flaw

1mo ago · bleeping-computer

Zimbra has urged customers to patch a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client, which could allow attackers to execute malicious code via specially crafted emails. The flaw affects Zimbra Collaboration Suite users and could lead to theft of session data, account settings, or mailbox contents. Although no CVE has been assigned yet, the vulnerability was reported by Google's Threat Analysis Group and is suspected to be exploited by state-backed actors, particularly Russian-linked groups.

4 Actors 2 CVEs
The Replicant in Your Directory: AI Agents and the Identity Security Gap

1mo ago · bleeping-computer

The article discusses how AI agents and machine identities are outpacing traditional identity governance, creating a growing security gap. These non-human identities, such as service accounts and OAuth applications, often inherit excessive permissions and persist long after their original purpose, increasing the attack surface. A notable incident involved threat actor UNC6395 exploiting a trusted OAuth token from Salesloft's Drift integration to pivot across Salesforce, AWS, and Snowflake environments. The core issue is not new vulnerabilities, but the lack of ownership, visibility, and lifecycle management for machine identities.

1 Actors
Former ransomware negotiator gets 4 years for BlackCat attacks

1mo ago · bleeping-computer

A former ransomware negotiator, Angelo Martino, was sentenced to 70 months in prison for participating in BlackCat (ALPHV) ransomware attacks between April 2023 and April 2025. Alongside accomplices Kevin Tyler Martin and Ryan Clifford Goldberg, Martino targeted at least five U.S. organizations, leveraging insider knowledge of victims' insurance limits to maximize ransom demands. The attackers operated as BlackCat affiliates, paying 20% of ransom proceeds to the core group while extorting tens of millions from victims in financial services, healthcare, and education sectors.

1 Malware
OpenMandriva Linux says contributor tried to sabotage the project

1mo ago · bleeping-computer

The OpenMandriva Linux project faced an internal sabotage attempt allegedly carried out by Davide Beatrici, a developer associated with the Mumble project, following a dispute over project direction and contributor behavior. Beatrici deleted repositories and pushed an empty package to the Cooker repository, targeting the Gnome and Cosmic desktop environments. Although he denied malicious intent, claiming his actions were in response to disagreements over project governance, the OpenMandriva team is restoring affected systems and conducting a security audit. Legal action has been waived by the project despite the severity of the incident.

Injective SDK on npm infected with cryptocurrency wallet stealer

1mo ago · bleeping-computer

Hackers compromised a contributor's GitHub account for the Injective Labs SDK project and published a malicious version (1.20.21) of the @injectivelabs/sdk-ts npm package. This supply-chain attack targeted developers building cryptocurrency-related applications, stealing wallet private keys and mnemonic seed phrases when SDK functions were used. The stolen data was exfiltrated via HTTP POST to a legitimate Injective Labs endpoint to blend in with normal traffic. The malicious package was downloaded 310 times before being deprecated, and 17 associated packages were also compromised.

2 IoCs
Microsoft expects more Windows security updates from AI-discovered flaws

1mo ago · bleeping-computer

Microsoft anticipates an increase in Windows security updates due to the use of artificial intelligence in identifying vulnerabilities within its codebase. The company is leveraging its AI-powered system, MDASH, to scan and validate potential security flaws in critical Windows binaries, leading to faster discovery and remediation. While AI accelerates defensive efforts, Microsoft also acknowledges its use by threat actors to exploit zero-day vulnerabilities. As a result, Microsoft is updating its Secure Development Lifecycle to integrate AI earlier in development and counter emerging AI-enabled attack techniques.

New Helix vishing group emerges in SharePoint data theft attacks

1mo ago · bleeping-computer

A new data-extortion group named Helix has emerged, conducting SharePoint data theft attacks using vishing, device code phishing, and MFA abuse. The group targets organizations by impersonating employees or managers to gain account access, then exfiltrates data for extortion or resale. Helix exhibits operational similarities to ShinyHunters and BlackFile, with potential ties based on infrastructure and tactics. The group's consistent use of automated SharePoint enumeration and exfiltration from a specific IP and user-agent provides a strong technical fingerprint.

1 IoCs 1 Actors
The Hidden Security Risks of Reduced Summer IT Coverage

1mo ago · bleeping-computer

Cybercriminals exploit reduced IT and security staffing during summer months to increase attack success rates, leveraging slower response times and reduced oversight. There is a 40% increase in cyberattacks during holiday periods, with phishing and Business Email Compromise (BEC) campaigns becoming more effective due to AI-driven social engineering. Lean staffing extends attacker dwell time, allowing for lateral movement, data theft, and ransomware deployment before detection.

New Forg365 phishing platform uses AI to target Microsoft 365 accounts

1mo ago · bleeping-computer

A new phishing-as-a-service (PhaaS) platform named Forg365 targets Microsoft 365 accounts using AI-generated lures, adversary-in-the-middle (AiTM) phishing, and device-code authentication exploits. The platform provides attackers with a comprehensive dashboard for campaign management, token handling, and persistent access via a browser extension called ForgCookie. It leverages legitimate services like Amazon SES and Cloudflare Pages to blend malicious activity with normal traffic, evading detection while enabling post-compromise persistence through OAuth token and cookie theft.

1 IoCs
Police arrests 5,800 suspects in global anti-fraud crackdown

1mo ago · bleeping-computer

Operation First Light 2026, a global law enforcement initiative coordinated by INTERPOL, targeted social engineering fraud and money laundering across 97 countries, resulting in 5,811 arrests and the seizure of $293 million in illicit assets. The operation identified over 142,000 victims and disrupted thousands of financial fraud cases, including business email compromise, romance scams, and investment fraud. This effort is part of a broader series of coordinated actions, including Operation Synergia II and Operation Red Card 2.0, aimed at dismantling transnational cybercrime networks.

Microsoft to retire the OWA Light client in Exchange Server

1mo ago · bleeping-computer

Microsoft has announced the retirement of the OWA Light client in Exchange Server, citing modern browser capabilities, improved network conditions, and evolving security requirements as reasons. The lightweight web client, introduced two decades ago for older browsers and low-bandwidth environments, will be disabled in an upcoming update expected in August 2026. This move aims to reduce legacy attack surface and streamline engineering efforts toward the modern Outlook on the web experience.

Microsoft patches RoguePlanet Defender zero-day vulnerability

1mo ago · bleeping-computer

Microsoft has patched a zero-day vulnerability in Microsoft Defender, tracked as CVE-2026-50656 and dubbed 'RoguePlanet', which could allow attackers to gain SYSTEM privileges via a race condition exploit. The vulnerability affects fully patched Windows 10 and 11 systems, regardless of real-time protection status. It was disclosed by a researcher known as Nightmare Eclipse, who has previously revealed other Windows zero-day exploits. Microsoft addressed the flaw through an update to the Malware Protection Engine and has warned against malicious exploitation of such vulnerabilities.

1 IoCs
AssuranceAmerica data breach exposes records of 6.9 million drivers

1mo ago · bleeping-computer

AssuranceAmerica suffered a data breach in March 2026 after attackers targeted an employee and gained unauthorized access to its IT systems. The attackers exfiltrated sensitive customer data, including names, contact information, driver's license numbers, and insurance policy details of nearly 7 million individuals. The company detected the breach on March 17, 2026, and completed its forensic review by June 15, 2026, after which it began notifying affected individuals. AssuranceAmerica has since reset credentials, isolated affected systems, and enhanced monitoring to prevent further compromise.

Mount Royal University confirms breach as hackers claim attack

1mo ago · bleeping-computer

Mount Royal University (MRU) suffered a cyberattack on June 17, 2026, resulting in data theft and deletion from its H and J drives. The threat actor CMD Organization claimed responsibility, exfiltrated sensitive data including passport scans, and demanded a 30 BTC ransom. The attackers also employ an auction model for stolen data and have published samples online. Recovery efforts are ongoing, with potential long-term disruption to university systems.

1 IoCs
Hackers exploit Roundcube flaw to spy on academic researchers

1mo ago · bleeping-computer

A China-linked threat cluster tracked as UNK_MassTraction has been exploiting vulnerabilities in Roundcube webmail servers at academic institutions in the U.S. and Canada since May 2026. The attackers target physics and engineering departments, deploying malware to steal credentials and establish persistent access. Exploitation involves CVE-2024-42009 and CVE-2025-49113 to deploy backdoors such as IceCube, SquareShell, and VShell. Proofpoint attributes the activity to a likely China-aligned espionage group based on infrastructure overlap and linguistic artifacts, though confidence is moderate.

1 Malware 2 CVEs
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials

1mo ago · bleeping-computer

A threat actor has published 17 malicious packages on npm and PyPI that impersonate legitimate Paysafe, Skrill, and Neteller SDKs to steal credentials and access tokens. These packages mimic real software development kits but instead exfiltrate sensitive data such as API keys, tokens, and system metadata to an AWS-hosted command-and-control server. The malware includes basic anti-analysis techniques and targets developers integrating payment functionality, with different activation triggers between npm and PyPI versions.

17 IoCs
Entra passkey enrollment vishing targets Microsoft 365 users

1mo ago · bleeping-computer

A threat actor tracked as O-UNC-066, associated with the Pink extortion gang, is conducting vishing attacks to trick Microsoft 365 users into enrolling Entra passkeys under the attacker's control. The campaign uses voice phishing and phishing kits that mimic legitimate Microsoft enrollment pages, enabling real-time credential and MFA interception. The attacker exploits a new Microsoft passkey registration feature and uses fake BIP-39 recovery phrases to distract victims while stealing credentials. Post-compromise, the actor exfiltrates data from SharePoint and OneDrive to support extortion efforts.

1 IoCs
Telco giant KDDI says data breach affects over 12 million people

1mo ago · bleeping-computer

Japanese telecommunications company KDDI disclosed a data breach affecting over 12 million users, resulting from an attack on May 16 that exploited a zero-day vulnerability in third-party software used by multiple ISPs. The breach exposed email addresses and passwords, with some credentials stored in hashed or encrypted form. KDDI detected and blocked the attackers on June 17, implemented EDR solutions, and is enforcing password resets for affected accounts.

DuckDuckGo browser now blocks YouTube video ads

1mo ago · bleeping-computer

DuckDuckGo has introduced a new feature in its browser that blocks YouTube video ads by leveraging community-maintained filter lists from uBlock Origin and its own compatibility rules. The feature is enabled by default on iOS, Mac, and Windows, while Android users can enable it manually. This functionality enhances user experience by reducing ad interruptions without requiring third-party extensions, aligning DuckDuckGo with browsers like Brave and Opera.

3 Ways AI Powers Service Desk Attacks and How to Prevent Them

1mo ago · bleeping-computer

AI is increasingly being leveraged by threat actors to enhance service desk attacks through more convincing impersonation, accelerated reconnaissance, and scalable social engineering. These attacks exploit the urgency and trust inherent in service desk operations, particularly during employee onboarding, to gain unauthorized access. Attackers use AI to generate realistic communication, personalize phishing attempts, and bypass traditional identity verification methods, making detection more difficult for security teams.

CISA orders feds to patch max severity ColdFusion flaw by Friday

1mo ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to patch a critical vulnerability, CVE-2026-48282, in Adobe ColdFusion by a strict deadline due to active exploitation in the wild. The flaw allows unauthenticated remote attackers to achieve code execution on unpatched systems with low attack complexity. Adobe released patches one week prior and warned of high exploitation risk, with evidence of attacks emerging within hours of disclosure.

Ubiquiti warns of new max severity UniFi OS vulnerability

1mo ago · bleeping-computer

Ubiquiti has disclosed and patched seven critical vulnerabilities in its UniFi OS platform, including a maximum-severity command injection flaw tracked as CVE-2026-50746 in the UniFi Connect Application. The vulnerabilities, affecting various UniFi products such as UniFi Talk, Access, and Protect, allow for low-complexity attacks without user interaction and could enable remote command execution. Internet-exposed UniFi OS instances remain a concern, with over 100,000 instances detected online, making them attractive targets for state-sponsored and cybercriminal groups. Previous incidents have shown exploitation of similar flaws to build botnets for cyberespionage and malicious traffic proxying.

CISA orders feds to prioritize patching Langflow auth bypass flaw

1mo ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to urgently patch CVE-2026-55255, an authentication bypass vulnerability in the Langflow AI development platform. This flaw allows authenticated attackers to access other users' workflows by manipulating the /api/v1/responses endpoint with a victim's flow_id, enabling data theft and resource abuse. Exploitation in the wild has been observed since June 25, with attackers pursuing financial gain through compute resource hijacking and credential theft. CISA has also added related Langflow vulnerabilities to its Known Exploited Vulnerabilities catalog, including CVE-2025-3248 and CVE-2026-33017, exploited by ransomware actors.

3 CVEs
Accenture confirms breach after hacker offers stolen data for sale

1mo ago · bleeping-computer

Accenture confirmed a security breach after a threat actor named '888' claimed responsibility for stealing over 35 GB of data, including source code, authentication keys, and configuration files. The actor posted a screenshot showing access to an Azure DevOps repository hosted under a redacted accenture.com subdomain and offered the data for sale on a cybercrime forum. Accenture stated the issue was isolated and remediated with no impact on operations, but did not confirm the scope or method of the breach.

1 IoCs
Hidden backdoor in Tenda router firmware grants admin access

1mo ago · bleeping-computer

A hidden authentication backdoor in multiple Tenda router firmware versions allows attackers to gain full administrative access to the device's web interface by using an undocumented password comparison mechanism. The vulnerability, tracked as CVE-2026-11405, is located in the '/bin/httpd' binary and remains unpatched as the vendor could not be reached. Successful exploitation enables attackers to reconfigure the device, alter network settings, and disable security features, posing significant risk to the local network.

Chinese hackers develop LONGLEASH malware to expand ORB network

1mo ago · bleeping-computer

Chinese threat actor UAT-7810 is expanding its Operational Relay Box (ORB) network by deploying updated and new malware variants, including LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST. These tools are used to compromise internet-facing networking devices, primarily unpatched Ruckus and ASUS routers, leveraging known vulnerabilities. The ORB infrastructure enables other China-aligned APTs to proxy traffic through compromised regional devices to evade detection and hinder attribution.

The GitHub Actions Attack Pattern Your CI Security Scanners Miss

1mo ago · bleeping-computer

In June 2026, researchers at Novee Security identified a critical CI/CD vulnerability pattern named Cordyceps affecting widely used open-source projects, including those from Microsoft, Google, and Apache. The issue stems from the composition of GitHub Actions workflows that misuse privileged triggers like pull_request_target and workflow_run, enabling attackers to execute code in trusted contexts via pull requests. Despite passing all standard security checks, these pipelines allowed potential theft of long-lived credentials and persistent access to critical systems, highlighting a systemic gap in supply chain governance.

Spain arrests suspected member of pro-Russian hacktivist groups

1mo ago · bleeping-computer

Spanish authorities have arrested a man suspected of being an active member of the pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest. He allegedly provided logistical and operational support to a Ukrainian hacker within CARR and facilitated escape routes to Russia. The groups have been linked to attacks on critical infrastructure in the U.S. and Europe, including SCADA systems, and are loosely associated with the Russian state-backed APT44 (Sandworm). The suspect also participated in operations attributed to the hacktivist group NoName057(16), which promotes pro-Russian and anti-Western narratives.

3 Actors
← Previous Next →