BleepingComputer
IntelDigest
Filtered security headlines, refreshed every six hours. Links out, always.
Huntress
Huntress Tragic Quadrant: Top Cyber Threats Wrecking Businesses
CISA
CISA Adds One Known Exploited Vulnerability to Catalog
The Hacker News
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
Huntress
Defender Exclusion Abuse: How Attackers Hide Malware from MDAV
The Hacker News
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
CISA
CISA Adds One Known Exploited Vulnerability to Catalog
The Hacker News
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
Microsoft Security
Star Blizzard refines phishing and malware delivery with the RedFlick technique
CISA
CISA Adds One Known Exploited Vulnerability to Catalog
Huntress
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix
The Hacker News
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
CISA
CISA Adds Two Known Exploited Vulnerabilities to Catalog
The Hacker News
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Hacker News
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
SANS ISC
A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)
CISA
CISA Adds One Known Exploited Vulnerability to Catalog
CISA
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Malware Traffic Analysis
2026-09-24: Files for an ISC Diary (Macfinger ClickFix activity)
Huntress
The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint
CISA
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Malware Traffic Analysis
2026-09-15: SmartApeSG ClickFix to unidentified RAT to MeshAgent
ESET Research
Beware the SparroWock: The backdoor that bites, the commands that catch
Zscaler ThreatLabz
Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
Securelist
NightEagle targets Russian companies
Zscaler ThreatLabz
SloppyRAT: A New Tool For Ransomware Attacks
Cisco Talos
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Rapid7
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Rapid7
Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
Huntress
Inside Knight Office, a New M365 AiTM Phishing Kit
Unit 42
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Huntress
Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress
Rapid7
PaperCut NG/MF Critical Zero-Day Exploited in the Wild
Elastic Security Labs
From 88 lines to 1: Detecting DLL hijacking with Elastic Defend
Malware Traffic Analysis
2026-08-21: SmartApeSG ClickFix campaign leads to two RATs
Huntress
Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware
Zscaler ThreatLabz
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
Huntress
Akira Hits Safe Mode: Ransomware Rebooting Around EDR
Zscaler ThreatLabz
CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials
Huntress
Credential Stuffing Campaign Hits SonicWall | Huntress SOC Tracking
Zscaler ThreatLabz
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
Huntress
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
Elastic Security Labs
New North Korean campaign uses fake coding interviews to steal developer credentials
Fortinet
The TTF Trap: A Global Campaign of a Low-Detection Lua Loader
Elastic Security Labs
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
Zscaler ThreatLabz
ClaudeFix: Shared Claude Chats Meet ClickFix
Huntress
Threat Actors Achieve Persistence After SQL Injection
Elastic Security Labs
ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit
The DFIR Report
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
The DFIR Report
Apache ActiveMQ Exploit Leads to LockBit Ransomware