Global Threat Level: CRITICAL

5 critical threats detected in the last 24 hours. Active threat actors: ShinyHunters, Conti, Qilin. Immediate review of affected systems recommended.

379
CVEs Tracked
227
Critical Threats
270
High Threats
7
Threat Actors

Latest Intelligence

MEDIUMMalware

Alleged ATM malware creator appears in Nebraska court after arrest

Aguirre was added to the FBI’s “Top 10 Most Wanted Fugitives” list in March, becoming the first cybercriminal added to the list.

13m agoGlobalThe Record
MEDIUMAiNEW

South Korean officials believe AI agents were used to hack several banks

The personal data of at least 68,000 people was reportedly exposed in breaches of at least seven financial institutions, with officials saying they believe a Chinese cybersecurity tool was used to hack the banks’ systems.

The Record
HIGHData BreachNEW

FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

Eduard Kovacs reports: The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees, Reuters reported on Tuesday, citing two people familiar with the matter. The FBI has not publicly named the contractor or the organization involved. However, a senior bureau official told Reuters that its... Source

DataBreaches.net
MEDIUMAiNEW

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]

BleepingComputer
MEDIUMVulnerability

ClickFix Attack Hides VBScript Payload in Browser Cache

ClickFix sites stage a VBScript payload in the browser cache to bypass the Run dialog's length limit

Infosecurity Magazine
MEDIUMVulnerability

UK picks banks as lead managers for digital gilt pilot

The UK government has selected six banks as joint lead managers for the Digital Gilt Instrument (Digit) pilot issuance.

Finextra
HIGHRansomware

Osaka Metropolitan University cancels classes after suspected ransomware attack

Osaka Metropolitan University said on Tuesday that the outage left its internal network, email and a range of administrative and academic systems unavailable.

The Record
CRITICALVulnerability

NVD CRITICAL: CVE-2026-106037 — Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in...

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST service, which binds to 0.0.0.0 without authentication on any route. Unauthenticated attackers can call routes such as /api/get, /api/put, /api/remove_all and /api/mount to read cached KV data with user prompts, inject or delete objects, and mount attacker-described segments.

CVE-2026-106037
NIST NVD
HIGHData Breach

FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees. The post FBI Blames Contractor’s Missed Patch for ShinyHunters Breach appeared first on SecurityWeek .

SecurityWeek
LOWAi

Securing Agent-to-Agent Communication: The Next Identity Frontier

As organizations deploy autonomous AI agents, security teams face a significant shift as non-human non-human entities making decisions, invoking tools, and delegating tasks to other agents without human intervention. Security architectures built around human users, static APIs, and distinct endpoints break down when AI agents dynamically collaborate across an environment. As these interactions bec

Rapid7
MEDIUMVulnerability

Gatehouse Bank backs youth homeless charity via new saver account

Gatehouse Bank has today launched a one-year fixed term Community Saver Account in support of the Bank’s charity partner, Depaul UK, a youth homelessness charity.

Finextra
CRITICALVulnerability

How to secure RMM software: 8 controls MSPs should test

RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged access to recovery and tenant isolation. [...]

BleepingComputer
MEDIUMPhishing

Nikkei Discloses Two Employee Cloud Account Compromises

Nikkei says two employee cloud accounts were accessed, with one used to send 9,000 phishing emails

Infosecurity Magazine

Live Activity

Threat Alerts

Real-time alerts for the threats that matter to you. Choose your severity levels and threat categories.