Category: Threat Intel
- ISC Stormcast For Thursday, October 1st, 2026
- Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
- Over 543,000 valid credentials exposed in public GitHub repositories
- DIVD says Zammad zero-days enabled AI-driven network breach
- Russian state hackers use new RedFlick technique to push malware
- Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
- Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
- Scans Target Wordfence-Protected WordPress Sites
- ISC Stormcast For Wednesday, September 30th, 2026
- Star Blizzard refines phishing and malware delivery with the RedFlick technique
- Beyond source code: A path to the keys to the kingdom
- Phishing Abuses RMM Tools for Persistent Access
- Using Device Linking to Eavesdrop on WhatsApp and Signal
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware
- Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
- New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
- French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
- NetScaler Zero Days CVE-2026-88771 & CVE-2026-88772 Exploited in the Wild
- Dutch national arrested again for hacking and extortion, still on probation