<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Threat Intelligence</title><link>https://cybersecuritytracker.ai/?cats=threat-intel</link><description>Curated cybersecurity news and vulnerability intelligence.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:50 GMT</lastBuildDate><item><title>Steam forum ClickFix attacks infect gamers with XMRig cryptominers</title><link>https://bleepingcomputer.com/news/security/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers</link><guid isPermaLink="false">cst-3223</guid><description>Threat actors are conducting ClickFix attacks on Steam discussion forums, disguising malicious downloads as solutions for gaming and computer issues that instead deliver XMRig cryptominers to infected systems. The campaign exploits the trust users place in community forums when seeking technical support, creating a social engineering vector at scale within a popular gaming platform.</description><pubDate>Sat, 25 Jul 2026 22:37:47 GMT</pubDate></item><item><title>The hacker who humiliated spyware makers and was never caught</title><link>https://techcrunch.com/2026/07/25/the-hacker-who-humiliated-spyware-makers-and-was-never-caught</link><guid isPermaLink="false">cst-3222</guid><description>A profile examines Phineas Fisher, a hacktivist credited with breaching multiple controversial government spyware vendors and remaining unidentified. The article explores Fisher's operations, methods, and significance in the hacker community.</description><pubDate>Sat, 25 Jul 2026 20:24:14 GMT</pubDate></item><item><title>Malicious sites use JavaScript to build malware in browser memory</title><link>https://bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory</link><guid isPermaLink="false">cst-3216</guid><description>A malvertising campaign deploys fraudulent cryptocurrency and trading platform websites containing malicious JavaScript that constructs malware in browser memory, bypassing traditional file-based detection methods.</description><pubDate>Sat, 25 Jul 2026 15:21:09 GMT</pubDate></item><item><title>The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days</title><link>https://wired.com/story/security-news-this-week-the-openai-models-that-hacked-hugging-face-were-active-on-the-internet-for-days</link><guid isPermaLink="false">cst-3215</guid><description>OpenAI models used in a hack of Hugging Face remained active on the internet for several days before detection. The incident underscores the exposure window between initial compromise and discovery in supply chain security contexts.</description><pubDate>Sat, 25 Jul 2026 10:30:00 GMT</pubDate></item><item><title>CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking</title><link>https://thehackernews.com/2026/07/ctm360-research-reveals-how-insurance.html</link><guid isPermaLink="false">cst-3212</guid><description>CTM360 research documents a shift in insurance-focused phishing tactics from delayed account compromise to real-time hijacking. Attackers now move immediately upon credential capture rather than waiting for a later opportunity to exploit stolen usernames and passwords.</description><pubDate>Sat, 25 Jul 2026 10:14:21 GMT</pubDate></item><item><title>Despite multiple takedowns, botnets continue to grow</title><link>https://cyberscoop.com/botnets-residential-proxy-networks-proliferate-lumen-black-lotus-labs</link><guid isPermaLink="false">cst-3199</guid><description>Botnets powered by residential proxy networks are expanding despite periodic takedowns, with Lumen Technology's Black Lotus Labs tracking approximately 60 million compromised IP addresses globally. A single botnet provider, IPIDEA, rebounded to pre-disruption size within hours after coordinated action in January, demonstrating the resilience of the ecosystem. Researchers conclude that isolated takedowns are ineffective and that coordinated regulation and enforcement across industry and law enforcement is required to address the growing threat.</description><pubDate>Fri, 24 Jul 2026 19:47:44 GMT</pubDate></item><item><title>Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts</title><link>https://bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts</link><guid isPermaLink="false">cst-3192</guid><description>Attackers are modifying DNS settings on hotel and conference center Wi-Fi networks to redirect users to fraudulent Microsoft 365 login pages, capturing credentials in the process. This technique exploits the trusted nature of venue Wi-Fi to conduct large-scale phishing attacks against travelers and conference attendees. The attackers gain access to authentic Microsoft 365 accounts without triggering multi-factor authentication if users enter their credentials on the fake login page.</description><pubDate>Fri, 24 Jul 2026 17:50:37 GMT</pubDate></item><item><title>'Wrench' attacks against crypto holders appear to be on the rise</title><link>https://therecord.media/wrench-attacks-against-cryptocurrency-holders</link><guid isPermaLink="false">cst-3184</guid><description>Security researchers report an increase in physical attacks including home invasions and kidnappings targeting cryptocurrency holders. These strong-arm tactics represent a shift in criminal methods beyond traditional digital attacks.</description><pubDate>Fri, 24 Jul 2026 15:55:00 GMT</pubDate></item><item><title>BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery</title><link>https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html</link><guid isPermaLink="false">cst-3180</guid><description>North Korean threat actors known as BlueNoroff are running phishing campaigns that impersonate Zoom and Microsoft Teams to deliver malware, leveraging typosquatted domains and compromised industry contacts. The group profiles cryptocurrency wallets during the social engineering process before distributing malicious payloads to targets.</description><pubDate>Fri, 24 Jul 2026 15:12:35 GMT</pubDate></item><item><title>In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws</title><link>https://securityweek.com/in-other-news-dolphin-x-ai-powered-malware-car-anti-theft-device-hack-400-linux-kernel-flaws</link><guid isPermaLink="false">cst-3182</guid><description>A roundup of several security stories including Siemens ROX II industrial switch vulnerabilities, a Russian espionage campaign targeting Zimbra webmail, a ransomware extortion attempt against Stadler Rail, AI-powered malware called Dolphin X, a car anti-theft device hack, and over 400 Linux kernel flaws.</description><pubDate>Fri, 24 Jul 2026 14:20:00 GMT</pubDate></item><item><title>Updated Cyber Threat Actor Naming System</title><link>https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system</link><guid isPermaLink="false">cst-3186</guid><description>Google Threat Intelligence Group is launching a new cryptonym-based naming system for tracking threat actors, replacing the separate schemas previously maintained by Mandiant and Google's Threat Analysis Group. The system uses memorable two-word combinations where the first word identifies the actor and the second word indicates its origin, type, or motivation, with categories assigned to countries and cybercriminal groups. Google will rename several dozen active groups initially and continue on a rolling basis, preserving legacy names and mappings for cross-reference.</description><pubDate>Fri, 24 Jul 2026 14:00:00 GMT</pubDate></item><item><title>Europol flags 4,340 URLs for removal in 'The Com' crackdown</title><link>https://bleepingcomputer.com/news/security/europol-flags-4-340-urls-for-removal-in-the-com-crackdown</link><guid isPermaLink="false">cst-3158</guid><description>Europol identified and flagged 4,340 URLs for removal during an operation targeting "The Com," a decentralized network of nihilistic violent extremist groups. The operation involved coordination across multiple weeks to disrupt online content associated with the network.</description><pubDate>Fri, 24 Jul 2026 12:56:53 GMT</pubDate></item><item><title>IL: Weeks after cyberattack, ETHS students receive phishing scam emails</title><link>https://databreaches.net/2026/07/24/il-weeks-after-cyberattack-eths-students-receive-phishing-scam-emails?pk_campaign=feed&amp;pk_kwd=il-weeks-after-cyberattack-eths-students-receive-phishing-scam-emails</link><guid isPermaLink="false">cst-3173</guid><description>Evanston Township High School students received phishing emails six weeks after a prior cyberattack disrupted campus operations for two days. The malicious messages, sent from a compromised student email account, offered lucrative part-time job opportunities ($550 for two to three hours weekly) and were signed by a fake Human Resource department. The incident suggests continued compromise or exploitation of school infrastructure following the earlier attack.</description><pubDate>Fri, 24 Jul 2026 12:07:02 GMT</pubDate></item><item><title>Golden Chickens Resurfaces With Four New Malware Families and Modular Implants</title><link>https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html</link><guid isPermaLink="false">cst-3164</guid><description>The Golden Chickens malware-as-a-service operation has returned with four newly identified malware families, including TinyEgg, ChonkyChicken, a modular variant of ChonkyChicken, and a modified web browser credential stealer. The threat group continues operations despite previous public disclosures about their infrastructure and tactics. The new families include modular implants that expand the operator's technical capabilities.</description><pubDate>Fri, 24 Jul 2026 10:09:24 GMT</pubDate></item><item><title>Satellite Images Reveal How Suspected Scam Compounds Appear Out of Nowhere</title><link>https://wired.com/story/satellite-images-reveal-how-giant-scam-compounds-keep-on-expanding</link><guid isPermaLink="false">cst-3157</guid><description>Satellite imagery analysis shows that dozens of alleged scam compounds have emerged in Myanmar in recent months, even as authorities claim to be cracking down on these criminal operations. The rapid construction of these facilities suggests that scam networks are adapting and expanding their physical infrastructure despite enforcement efforts.</description><pubDate>Fri, 24 Jul 2026 10:00:00 GMT</pubDate></item><item><title>Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks</title><link>https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html</link><guid isPermaLink="false">cst-3143</guid><description>CERT-UA disclosed that UAC-0099, a Russia-aligned threat group, is distributing a malicious program disguised as a Notepad++ plugin to compromise Windows systems. The campaign delivers malware called MATCHBOIL.V2, continuing the group's pattern of using trojanized software delivery mechanisms.</description><pubDate>Fri, 24 Jul 2026 06:50:57 GMT</pubDate></item><item><title>The best-funded companies open the most phishing attachments</title><link>https://helpnetsecurity.com/2026/07/24/phishing-simulation-benchmark-report</link><guid isPermaLink="false">cst-3149</guid><description>Analysis of 13.9 million simulated phishing messages reveals that only one in ten recipients report suspicious emails to security teams, leaving organizations vulnerable to attackers who need only a single successful compromise. Well-funded companies show higher rates of employees opening phishing attachments, possibly due to larger user populations or weaker security awareness practices.</description><pubDate>Fri, 24 Jul 2026 05:00:30 GMT</pubDate></item><item><title>New Dolphin X malware uses AI to rank high-value targets</title><link>https://bleepingcomputer.com/news/security/new-dolphin-x-malware-uses-ai-to-rank-high-value-targets</link><guid isPermaLink="false">cst-3133</guid><description>Dolphin X is a newly identified remote access trojan that incorporates machine learning to profile and rank infected systems, allowing operators to prioritize targeting high-value victims. The malware demonstrates an emerging trend of threat actors integrating AI capabilities into their attack tooling to improve operational efficiency.</description><pubDate>Thu, 23 Jul 2026 21:20:34 GMT</pubDate></item><item><title>Fake Claude app promoted by Bing ads pushes SectopRAT malware</title><link>https://bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-pushes-sectoprat-malware</link><guid isPermaLink="false">cst-3135</guid><description>Attackers are using malvertising on Bing search results to distribute a fake Claude desktop application installer that harvests credentials and installs the SectopRAT remote access trojan. The malicious installer is hosted on a subdomain of the legitimate Claude.ai domain, creating a convincing social engineering lure.</description><pubDate>Thu, 23 Jul 2026 19:48:30 GMT</pubDate></item><item><title>DNS Poisoning Tactics Expand to Hospitality Wi-Fi</title><link>https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality</link><guid isPermaLink="false">cst-3139</guid><description>Attackers have compromised public Wi-Fi gateways at hotels, conference centers, and similar venues to redirect traffic and steal Microsoft 365 credentials from traveling corporate employees through DNS poisoning tactics. The campaign, active since at least June 2026, affects organizations across financial services, healthcare, legal, energy, and retail sectors globally. ReliaQuest assesses the tradecraft mirrors tactics previously attributed to APT28 (also known as Fancy Bear and Forest Blizzard), a Russian military intelligence group.</description><pubDate>Thu, 23 Jul 2026 18:00:00 GMT</pubDate></item><item><title>Intelligence Insights: July 2026</title><link>https://redcanary.com/blog/threat-intelligence/intelligence-insights-july-2026</link><guid isPermaLink="false">cst-3131</guid><description>ClearFake maintains prominence in threat intelligence reporting, while CastleLoader emerges as a new malware variant of note in July 2026.</description><pubDate>Thu, 23 Jul 2026 17:12:43 GMT</pubDate></item><item><title>International alert spotlights Russia-linked attacks on Zimbra webmail</title><link>https://therecord.media/zimbra-webmail-zero-click-phishing-russia-laundry-bear</link><guid isPermaLink="false">cst-3111</guid><description>A Russian-linked threat group called Laundry Bear has conducted targeted attacks against Zimbra webmail users globally using zero-click phishing techniques, according to U.S. and other government authorities. The activity represents a coordinated espionage campaign leveraging a popular email platform to gain unauthorized access to user accounts.</description><pubDate>Thu, 23 Jul 2026 16:58:00 GMT</pubDate></item><item><title>Hackers abuse Notepad++ plugins to stealthily install malware</title><link>https://bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware</link><guid isPermaLink="false">cst-3099</guid><description>Ukraine's CERT discovered attackers distributing a malicious tool disguised as a Notepad++ plugin to achieve persistence on compromised systems. The attacks use legitimate copies of Notepad++ bundled with the LunchPoke utility to deceive users into running malware. This technique exploits the trust users place in well-known applications and their plugin ecosystems.</description><pubDate>Thu, 23 Jul 2026 16:32:35 GMT</pubDate></item><item><title>ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories</title><link>https://thehackernews.com/2026/07/threatsday-android-spyware-plc-attacks.html</link><guid isPermaLink="false">cst-3103</guid><description>This story appears to be a preview or teaser for a ThreatsDay Bulletin covering multiple threat categories including Android spyware, programmable logic controller (PLC) attacks, and artificial intelligence (AI) image prompt injection attacks among other threats.</description><pubDate>Thu, 23 Jul 2026 15:02:07 GMT</pubDate></item><item><title>Email threat landscape: Q2 2026 trends and insights</title><link>https://microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights</link><guid isPermaLink="false">cst-3123</guid><description>Microsoft's disruption of the Tycoon2FA phishing-as-a-service platform in March 2026 produced sustained impact through Q2, reducing associated phishing volume by 92% overall with no comparable replacement service emerging. Microsoft Threat Intelligence detected approximately 7.6 billion email phishing threats in Q2 2026, though monthly volumes declined modestly from April to June, with credential phishing remaining the primary payload objective. Threat actors expanded beyond email into Microsoft Teams-based social engineering and voice phishing, with malicious call attempts reaching nearly ten times mid-2025 baselines by quarter end.</description><pubDate>Thu, 23 Jul 2026 15:00:00 GMT</pubDate></item><item><title>Russian Global Webmail Espionage</title><link>https://unit42.paloaltonetworks.com/russian-webmail-espionage</link><guid isPermaLink="false">cst-3124</guid><description>Unit 42 identifies a Russian-linked cyberespionage campaign targeting Zimbra webmail servers through JavaScript injection attacks designed to capture user credentials. The threat actors inject malicious code into compromised Zimbra instances to harvest login credentials from victims.</description><pubDate>Thu, 23 Jul 2026 14:10:53 GMT</pubDate></item><item><title>How attackers hosted a fake Claude download page on the claude.ai domain</title><link>https://helpnetsecurity.com/2026/07/23/anthropic-claude-artifacts-download-malware</link><guid isPermaLink="false">cst-3091</guid><description>Threat actors abused Anthropic's Claude Artifacts feature to host a malicious download page on the legitimate claude.ai domain. Employees at 29 organizations were deceived by a sponsored Bing ad linking to this artifact in July, which then redirected them to a spoofed Claude site distributing SectopRAT malware. The attack exploited legitimate platform features to establish trust and bypass initial security skepticism.</description><pubDate>Thu, 23 Jul 2026 13:12:21 GMT</pubDate></item><item><title>China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks</title><link>https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html</link><guid isPermaLink="false">cst-3106</guid><description>Group-IB identified a China-linked threat actor designated JadeProx through an exposed Alibaba Cloud server in Singapore. The group deployed a previously unknown Windows loader called TriBack Loader in attacks against government, healthcare, and education organizations across Asia and Latin America.</description><pubDate>Thu, 23 Jul 2026 12:20:23 GMT</pubDate></item><item><title>How Synthetic Identity Fraud is Coming for Machine Identities</title><link>https://thehackernews.com/2026/07/how-synthetic-identity-fraud-is-coming.html</link><guid isPermaLink="false">cst-3084</guid><description>Synthetic identity fraud differs from traditional identity theft by creating entirely fictional identities using a mix of real and fabricated data points rather than stealing an existing person's information. This approach is difficult to detect because no actual victim monitors the fraudulent account activity. The article discusses how this attack pattern is beginning to extend to machine identities in digital ecosystems.</description><pubDate>Thu, 23 Jul 2026 11:45:00 GMT</pubDate></item><item><title>Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers</title><link>https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html</link><guid isPermaLink="false">cst-3085</guid><description>Researchers discovered a large-scale campaign weaponizing compromised GitHub repositories and Actions runners as attack infrastructure against cPanel and WebHost Manager instances. The campaign involved malicious Packagist development versions across 10 packages associated with a legitimate PHP and DevOps developer between July 12 and 13.</description><pubDate>Thu, 23 Jul 2026 11:28:54 GMT</pubDate></item><item><title>Preview: Cisco Talos at Black Hat USA 2026</title><link>https://blog.talosintelligence.com/preview-cisco-talos-at-black-hat-usa-2026</link><guid isPermaLink="false">cst-3082</guid><description>Cisco Talos will present research and demonstrations at Black Hat USA 2026, including lightning talks on threat actor use of AI prompts, the Warlock ransomware group, zero trust agent identity, and vulnerability discovery trends. The group will deliver a main stage keynote on securing enterprises with AI agents, plus two workshops focused on integrating AI into security operations and monitoring autonomous systems as potential insider threats. Talos threat intelligence is embedded across the Cisco security portfolio and will be showcased at booth 2633.</description><pubDate>Thu, 23 Jul 2026 10:00:14 GMT</pubDate></item><item><title>New msaRAT malware uses Chrome, Edge browsers to route C2 traffic</title><link>https://bleepingcomputer.com/news/security/new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-traffic</link><guid isPermaLink="false">cst-3068</guid><description>Chaos ransomware operators deployed a new backdoor called msaRAT that conceals command-and-control traffic by routing it through Chrome or Edge browsers. This technique allows attackers to blend malicious communications with legitimate browser traffic, making detection more difficult.</description><pubDate>Thu, 23 Jul 2026 10:00:00 GMT</pubDate></item><item><title>Brazilian Banking Trojan Actively Spreading in Portugal</title><link>https://darkreading.com/cyberattacks-data-breaches/brazilian-banking-trojan-spreading-portugal</link><guid isPermaLink="false">cst-3061</guid><description>A Brazilian banking trojan is actively spreading in Portugal, exploiting the shared language between Portuguese businesses and Brazilian threat actors. The linguistic overlap creates favorable conditions for social engineering and targeted attacks against Portuguese organizations.</description><pubDate>Thu, 23 Jul 2026 07:00:00 GMT</pubDate></item><item><title>TAG-195 Upgrades MaaS Ecosystem with Modular Tools</title><link>https://recordedfuture.com/research/tag-195-evolves-maas-ecosystem</link><guid isPermaLink="false">cst-3132</guid><description>Insikt Group identified four new malware families associated with TAG-195, a financially motivated malware-as-a-service (MaaS) developer: TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator. These families demonstrate TAG-195's architectural evolution toward a modular, controller-and-plugin design that loads capability modules on demand rather than embedding all functionality in a single implant. The shift reflects both technical improvements in detection evasion and commercial incentives of the MaaS model, including selective capability provisioning and compartmentalization of risk across customers.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Fake Bahrain Alert App Deploys Android Surveillance Malware</title><link>https://darkreading.com/mobile-security/fake-bahrain-alert-apps-android-surveillance-malware</link><guid isPermaLink="false">cst-3051</guid><description>Cybercriminals distributed a fake alert application disguised as an official Bahrain warning tool, which delivered multi-stage Android spyware to victims. The malware was promoted through counterfeit Google Play storefronts and targeted civilians during a period of heightened tensions from Iranian missile strikes in the region.</description><pubDate>Wed, 22 Jul 2026 19:42:42 GMT</pubDate></item><item><title>Malware is targeting AI tools in software development environments</title><link>https://cyberscoop.com/sandworm-mode-malware-ai-supply-chain-crowdstrike</link><guid isPermaLink="false">cst-3038</guid><description>Sandworm_Mode, a self-propagating worm discovered in February, targets AI coding assistants and software development environments to steal credentials, API keys, and secrets from CI/CD pipelines and major language model providers. The malware blends its activity with legitimate development traffic, uses multi-day delays to evade detection, and destroys compromised environments if unable to spread. CrowdStrike has monitored the threat for four months but has not determined its origin or ultimate intent, though it appears designed for persistent access and may represent a broader trend of supply-chain attacks against AI development toolchains.</description><pubDate>Wed, 22 Jul 2026 17:24:46 GMT</pubDate></item><item><title>Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?</title><link>https://sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis</link><guid isPermaLink="false">cst-3045</guid><description>SentinelLabs evaluated frontier AI models on a multi-stage malware analysis benchmark based on their investigation of fast16, a 2005 sabotage implant, finding that only OpenAI's GPT-5.6 Sol completed the full eight-stage reverse-engineering task. The benchmark tested whether models could maintain investigative integrity as new evidence contradicted earlier conclusions, with successful completion requiring project-scale recovery including withdrawing incorrect conclusions and repairing technical artifacts. The researchers concluded that the strongest current use case is supervised investigative support where human analysts retain authority over objectives, quality control, and final publication.</description><pubDate>Wed, 22 Jul 2026 16:55:29 GMT</pubDate></item><item><title>New Kimsuky campaign compromised South Korean software vendors</title><link>https://therecord.media/kimsuky-north-korea-espionage-groupware-companies</link><guid isPermaLink="false">cst-3037</guid><description>Researchers have identified a recent campaign by Kimsuky, a North Korean advanced persistent threat (APT) group, targeting South Korean software vendors that produce collaborative work software.</description><pubDate>Wed, 22 Jul 2026 16:47:00 GMT</pubDate></item><item><title>Opening the Black Box: Agentless Threat Detection for Virtual Appliances</title><link>https://wiz.io/blog/agentless-threat-hunting-fortigate</link><guid isPermaLink="false">cst-3029</guid><description>A researcher's guide addresses agentless threat detection for virtual appliances by mapping event logs to real-world attack campaigns. The approach enables continuous monitoring without deploying agents to appliances, potentially offering organizations visibility into security events across distributed infrastructure.</description><pubDate>Wed, 22 Jul 2026 14:24:50 GMT</pubDate></item><item><title>Why Modern SOCs Need Multi-Layered Detections</title><link>https://thehackernews.com/2026/07/why-modern-socs-need-multi-layered.html</link><guid isPermaLink="false">cst-3000</guid><description>The article argues that modern security operations centers require multi-layered detection approaches because traditional endpoint and malware-based defenses no longer catch most attacks. According to the CrowdStrike Global Threat Report, approximately 79% of attacks are malware-free, with threat actors increasingly relying on techniques that evade conventional security tools.</description><pubDate>Wed, 22 Jul 2026 11:25:35 GMT</pubDate></item><item><title>First-Person Identity Theft Story</title><link>https://schneier.com/blog/archives/2026/07/first-person-identity-theft-story.html</link><guid isPermaLink="false">cst-3009</guid><description>A first-person account describes how a victim's email account was compromised after they shared a two-factor authentication code with a scammer, illustrating the cascade of risk when an email account is breached. The article emphasizes that email security serves as the foundation for protecting most online accounts.</description><pubDate>Wed, 22 Jul 2026 11:02:26 GMT</pubDate></item><item><title>Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library</title><link>https://thehackernews.com/2026/07/trojanized-newtonsoftjson-fork-hides.html</link><guid isPermaLink="false">cst-2976</guid><description>Researchers discovered a trojanized Newtonsoft.Json fork published to NuGet under the typosquatted name Newtonsoftt.Json.Net that contains code designed to manipulate live game outcomes on the Digitain platform. The package functions as a working library while hiding malicious game-rigging functionality, differing from typical info-stealing packages found on package registries.</description><pubDate>Wed, 22 Jul 2026 06:00:06 GMT</pubDate></item><item><title>Modern Attack Vectors | Recorded Future</title><link>https://recordedfuture.com/blog/modern-attack-vectors</link><guid isPermaLink="false">cst-3030</guid><description>Modern threat actors have shifted from brute-force attacks to targeting digital identities through stolen session cookies, credential stuffing, and MFA fatigue campaigns. Adversaries increasingly exploit unpatched edge infrastructure like VPNs and supply chain vulnerabilities in open-source repositories. Organizations need real-time, outside-in threat intelligence to detect attack patterns before breaches occur, as traditional internal security telemetry often misses critical pre-attack signals.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Red Teams Don't Find Problems. They Find the Assumptions Behind Them.</title><link>https://reliaquest.com/blog/red-teams-find-assumptions</link><guid isPermaLink="false">cst-3204</guid><description>Red teams are most effective when they identify the underlying assumptions and decisions that enable security weaknesses, rather than just finding vulnerabilities themselves. The relationship between red teams and defenders must be collaborative and trust-based, with both sides working toward the shared goal of reducing organizational risk. Red team programs often lose support when findings are diluted through reporting chains or when leadership lacks direct exposure to insights, making it difficult to drive meaningful remediation.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>North Korea’s IT worker scheme funds Russia’s war effort</title><link>https://cyberscoop.com/north-korea-it-worker-scheme-funds-russia-war-ukraine</link><guid isPermaLink="false">cst-2924</guid><description>A security firm report details how North Korea's IT worker scheme generates revenue through front companies and sanctioned entities that partially fund Russia's military operations and weapons procurement. Analysis of leaked payment server data shows $1.97 million flowing directly to a sanctioned North Korean defense entity between December 2025 and February 2026, with broader distribution across multiple domestic programs and military-related organizations. The scheme represents a significant revenue stream supporting both North Korea's weapons program and its material support to Russia's war effort in Ukraine.</description><pubDate>Tue, 21 Jul 2026 16:00:00 GMT</pubDate></item><item><title>FIFA World Cup 2026 Ticket Fraud Surges As Fake Websites And Domains Rise</title><link>https://news18.com/sports/football/fifa-world-cup-2026-ticket-fraud-surges-as-fake-websites-and-domains-rise-ws-lo-10172861.html</link><guid isPermaLink="false">cst-2946</guid><description>Fraudulent ticket sales for the FIFA World Cup 2026 are increasing through counterfeit websites and domains designed to deceive buyers. Attackers are exploiting the high demand for World Cup tickets by creating convincing fake storefronts to steal money and personal information from unsuspecting fans.</description><pubDate>Tue, 21 Jul 2026 14:23:05 GMT</pubDate></item><item><title>Captive Portal Detection</title><link>https://isc.sans.edu/diary/rss/33172</link><guid isPermaLink="false">cst-2928</guid><description>This article explains how modern operating systems and browsers detect captive portals on public WiFi networks by attempting to access specific HTTP URLs and checking for redirect responses. Different platforms use different detection URLs: Windows checks msftconnecttest.com, Apple uses captive.apple.com, Android and Chrome use generate_204 endpoints, and Firefox uses detectportal.firefox.com. Understanding these detection mechanisms can help network administrators and security analysts recognize benign traffic patterns and assist users who encounter connectivity issues.</description><pubDate>Tue, 21 Jul 2026 13:44:56 GMT</pubDate></item><item><title>Apps targeted at US troops contain Chinese and Russian code</title><link>https://arstechnica.com/security/2026/07/apps-targeted-at-us-troops-contain-chinese-and-russian-code</link><guid isPermaLink="false">cst-2914</guid><description>Researchers examined hundreds of mobile apps marketed to US military personnel and discovered that over 12 percent contained software components from companies in China, Russia, or other foreign nations. One popular app for rating base living conditions included code from Huawei, while two others incorporated Russian advertising services. The findings raise concerns that adversary governments could harvest location and deployment data on service members through these applications.</description><pubDate>Tue, 21 Jul 2026 13:19:38 GMT</pubDate></item><item><title>Cryptohack Roundup: Sentencing in $97M Laundering Case</title><link>https://bankinfosecurity.com/cryptohack-roundup-sentencing-in-97m-laundering-case-a-31946</link><guid isPermaLink="false">cst-2917</guid><description>A roundup article covers sentencing in a cryptocurrency laundering case involving approximately $97 million. The piece aggregates cryptocurrency-related news and enforcement actions.</description><pubDate>Tue, 21 Jul 2026 13:10:10 GMT</pubDate></item><item><title>Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters</title><link>https://sentinelone.com/labs/iran-war-cyber-threat-landscape-a-midyear-assessment-on-what-matters</link><guid isPermaLink="false">cst-2915</guid><description>SentinelLABS released a midyear assessment of cyber threats linked to Iran, finding that actual risk remains lower than public perception and centers on persistent access, trusted administrative accounts, and selective disruption rather than widespread attacks. The report establishes a taxonomy distinguishing Iran-linked operators by organizational affiliation (MOIS, IRGC units, domestic surveillance clusters) and mission set, noting that multiple vendor names often refer to overlapping activity from the same groups. Operational security targets include espionage, destructive hack-and-leak operations, social engineering, dissident surveillance, and opportunistic OT targeting, with impact claims frequently exceeding independently verified evidence.</description><pubDate>Tue, 21 Jul 2026 13:00:21 GMT</pubDate></item></channel></rss>