daily cyber × ai intelligence

index

tagged

[recorded-future]

4 editions · 3 items

August 28, 2026

  • BlueDelta ran initial-access campaigns against European diplomacy from late September 2025 to early April 2026, delivering a lightweight Windows batch-script backdoor dubbed HOOKEDGE via macro-enabled Word documents. Targets were government and diplomatic bodies in Romania, Spain and Türkiye, with lures impersonating Spain's Ministry of the Presidency (Recorded Future). · Threat Activity

in Australia Charges Two Over the TeamPCP Supply-Chain Spree

June 23, 2026

  • Klue breach fallout widens to a who's-who of security vendors — after Icarus posted stolen data on June 22, affected Klue customers now include HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium. Huntress says no product data, telemetry, passwords, or card data were touched — exposure is limited to business metadata (names, products trialed, subscription/pricing, sales notes) — and warns the data is ripe for Klue/Huntress impersonation. SecurityWeek · Huntress · Threat Intelligence

in Five Eyes Warns Frontier AI Will Reshape Offensive Cyber Ops as a New Entra ID Conditional Access Bypass Surfaces

June 20, 2026

FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token

FortiBleed has compromised ~86,644 internet-facing FortiGate devices in a credential-harvesting campaign, while a leaked GitHub token gave FulcrumSec access to Novo Nordisk, exfiltrating 1.3TB including unreleased drug formulas and internal AI models. Mastra npm packages were trojanized by Sapphire Sleet (North Korea–nexus), and multiple AI infrastructure flaws emerged: SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot, Pickle in the Middle in Google Vertex AI, and vulnerabilities in LiteLLM. Ransomware gangs including Qilin, Gentlemen, and DragonForce continue dominating the threat landscape with EDR-killing tradecraft and cloud-based C2 abuse.