#threat-intelligence
10 articles
From April to July 2026, ZCyberNews published 30 articles on threat-intelligence, with ClickFix, Commercial Surveillance Vendors, and GopherWhisper among the most frequently observed threat actors. Key vulnerabilities included CVE-2025-24054, CVE-2025-33053, and CVE-2026-21513. The coverage spanned government, technology, financial services, civil society, and critical-infrastructure sectors across Global, Asia, Europe, Iran, and North America. The severity mix comprised 11 high, 12 informational, and 3 medium reports.
HIGHExposed WebDAV Malware Lab Reveals AI-Driven Delivery Pipeline
Rapid7 MDR found an exposed server with 1,048 artifacts — LNK lures, WebDAV scripts, CVE-2025-33053 tests — revealing attackers using generative AI to systematize malware delivery.
HIGHGoogle TAG Report Details Commercial Surveillance Vendor Industry
Google TAG's 2026 report maps 50+ commercial surveillance vendors selling spyware to governments — targeting journalists, activists, and lawyers.
MEDIUMGoogle: AI Prompt Injection Attacks Rising, Still Low-Sophistication
Google reports a rise in malicious AI prompt injection attacks, but most remain low-sophistication and harmless. Indirect injection attempts target LLM-integrated apps.
HIGHIranian Handala Hack Breaches FBI Director Patel's Gmail
Iranian state-affiliated group Handala Hack breached FBI Director Patel's personal Gmail account, leaking personal photos and documents after the FBI seized the group's domains.
INFORMATIONALElastic Security Backs UK MoD Defence Cyber Marvel 2026 Exercise
Elastic Security Labs deployed AI-driven detection pipelines for the UK Ministry of Defence's Defence Cyber Marvel 2026 exercise, processing 1.2TB of telemetry across 50 simulated…
HIGHGopherWhisper APT Uses Go Tools, Legit Services in Gov Attacks
GopherWhisper, a new state-backed APT, targets government entities with a Go-based toolkit abusing Outlook, Slack, and Discord for C2.
MEDIUMCaller-as-a-Service Fraud Operations Mimic Corporate Call Centers
Flare researchers detail 'Caller-as-a-Service' fraud, where criminal operations use hiring, training, and KPIs to manage scam callers targeting victims in North America and Europe.
HIGHRansomware Attackers Operate Like Businesses, ESET Research Reveals
ESET analysis of 100+ ransomware attacks shows threat actors run business operations with defined roles, KPIs, and supply chains, not just technical attacks.
HIGHAI-Powered Vulnerability Discovery Accelerates Exploit Timelines, Strains
Qualys warns that AI agents like Claude Mythos can cut vulnerability discovery time from months to hours, compressing the patch window and overwhelming security teams with a surge of new CVEs.
HIGHAnthropic Restricts Access to AI Model Capable of Automated Vulnerability
Anthropic has restricted its Claude Mythos Preview AI to ~50 critical infrastructure vendors, citing its advanced ability to autonomously find and exploit software vulnerabilities, raising concerns about dual-use risks and offensive cyber capabilities.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.