<rss xmlns:source="http://source.scripting.com/" version="2.0">
  <channel>
    <title>Threat Intel</title>
    <link>https://threatintel.cc/</link>
    <description></description>
    
    <language>en</language>
    
    <lastBuildDate>Wed, 02 Sep 2026 14:19:13 -0400</lastBuildDate>
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/09/02/hackers-target-us-and-eu.html</link>
      <pubDate>Wed, 02 Sep 2026 14:19:13 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/09/02/hackers-target-us-and-eu.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://cybersecuritynews.com/microsoft-365-session-hijacking/&#34;&gt;Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Hackers are exploiting Microsoft 365 sessions, RMM software, and phishing-as-a-service kits like Mirage2FA to hijack corporate accounts across the US and Europe. To mitigate these threats, organizations must revoke active tokens, implement phishing-resistant MFA, and utilize behavioral threat intelligence to detect malicious activity disguised as routine administrative tasks.&lt;/p&gt;
</description>
      <source:markdown>[Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse](https://cybersecuritynews.com/microsoft-365-session-hijacking/)

Hackers are exploiting Microsoft 365 sessions, RMM software, and phishing-as-a-service kits like Mirage2FA to hijack corporate accounts across the US and Europe. To mitigate these threats, organizations must revoke active tokens, implement phishing-resistant MFA, and utilize behavioral threat intelligence to detect malicious activity disguised as routine administrative tasks.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/09/02/gitspawn-flaws-let-malicious-repositories.html</link>
      <pubDate>Wed, 02 Sep 2026 14:17:10 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/09/02/gitspawn-flaws-let-malicious-repositories.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://cybersecuritynews.com/gitspawn-flaws-execute-code/&#34;&gt;GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor and Grok&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;GitSpawn vulnerabilities allow malicious repositories to silently execute arbitrary code on a developer&amp;rsquo;s machine by exploiting background git commands that trigger unauthorized configuration hooks. To prevent this, developers should inspect .git/config files in unverified repositories, while vendors are urged to sanitize background context-gathering operations.&lt;/p&gt;
</description>
      <source:markdown>[GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor and Grok](https://cybersecuritynews.com/gitspawn-flaws-execute-code/)

GitSpawn vulnerabilities allow malicious repositories to silently execute arbitrary code on a developer&#39;s machine by exploiting background git commands that trigger unauthorized configuration hooks. To prevent this, developers should inspect .git/config files in unverified repositories, while vendors are urged to sanitize background context-gathering operations.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/09/02/berlin-rejects-rhysida-ransomware-blackmail.html</link>
      <pubDate>Wed, 02 Sep 2026 14:15:19 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/09/02/berlin-rejects-rhysida-ransomware-blackmail.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.govinfosecurity.com/berlin-rejects-rhysida-ransomware-blackmail-a-32731&#34;&gt;Berlin Rejects Rhysida Ransomware Blackmail - GovInfoSecurity&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The Berlin Senate has officially rejected a 30-bitcoin ransomware demand from the Rhysida hacking group following a major data breach. City officials are currently scanning thousands of systems to assess the extent of the stolen information while refusing to pay the extortionists.&lt;/p&gt;
</description>
      <source:markdown>[Berlin Rejects Rhysida Ransomware Blackmail - GovInfoSecurity](https://www.govinfosecurity.com/berlin-rejects-rhysida-ransomware-blackmail-a-32731)

The Berlin Senate has officially rejected a 30-bitcoin ransomware demand from the Rhysida hacking group following a major data breach. City officials are currently scanning thousands of systems to assess the extent of the stolen information while refusing to pay the extortionists.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/09/02/threat-gang-springs-vishing-attacks.html</link>
      <pubDate>Wed, 02 Sep 2026 14:14:04 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/09/02/threat-gang-springs-vishing-attacks.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.darkreading.com/cyberattacks-data-breaches/threat-gang-springs-vishing-attacks-microsoft-teams-users&#34;&gt;Threat Gang &amp;lsquo;Springs&amp;rsquo; Vishing Attacks on Microsoft Teams Users&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The Spring Ring campaign uses vishing on Microsoft Teams to trick employees into installing malware or granting unauthorized remote access. These social engineering attacks aim to compromise organizational infrastructure by impersonating internal support staff to gain control over domain controllers.&lt;/p&gt;
</description>
      <source:markdown>[Threat Gang &#39;Springs&#39; Vishing Attacks on Microsoft Teams Users](https://www.darkreading.com/cyberattacks-data-breaches/threat-gang-springs-vishing-attacks-microsoft-teams-users)

The Spring Ring campaign uses vishing on Microsoft Teams to trick employees into installing malware or granting unauthorized remote access. These social engineering attacks aim to compromise organizational infrastructure by impersonating internal support staff to gain control over domain controllers.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/09/02/irans-shadow-banking-network-extends.html</link>
      <pubDate>Wed, 02 Sep 2026 14:12:38 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/09/02/irans-shadow-banking-network-extends.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://cryptobriefing.com/iran-shadow-banking-network-sanctions/&#34;&gt;Iran&amp;rsquo;s shadow banking network extends beyond US sanctions, investigation reveals&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Iran maintains access to the global financial system by utilizing a shadow banking network of shell companies and exchange houses in the UAE and China to bypass US sanctions. Investigations reveal this infrastructure moved approximately $9 billion in 2024, prompting intensified US regulatory efforts to disrupt these illicit financial channels.&lt;/p&gt;
</description>
      <source:markdown>[Iran&#39;s shadow banking network extends beyond US sanctions, investigation reveals](https://cryptobriefing.com/iran-shadow-banking-network-sanctions/)

Iran maintains access to the global financial system by utilizing a shadow banking network of shell companies and exchange houses in the UAE and China to bypass US sanctions. Investigations reveal this infrastructure moved approximately $9 billion in 2024, prompting intensified US regulatory efforts to disrupt these illicit financial channels.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/09/02/google-launches-gemini-flash-cyber.html</link>
      <pubDate>Wed, 02 Sep 2026 14:11:43 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/09/02/google-launches-gemini-flash-cyber.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://cybersecuritynews.com/gemini-3-8-flash-cyber/&#34;&gt;Google Launches Gemini 3.8 Flash Cyber to Identify and Auto-Patch Security Vulnerabilities&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Google has introduced Gemini 3.8 Flash Cyber, a specialized AI model designed to autonomously identify and generate patches for software vulnerabilities. Available exclusively to vetted teams through the Fairwind Program, the model significantly enhances cybersecurity defense by outperforming larger competitors in vulnerability discovery and remediation.&lt;/p&gt;
</description>
      <source:markdown>[Google Launches Gemini 3.8 Flash Cyber to Identify and Auto-Patch Security Vulnerabilities](https://cybersecuritynews.com/gemini-3-8-flash-cyber/)

Google has introduced Gemini 3.8 Flash Cyber, a specialized AI model designed to autonomously identify and generate patches for software vulnerabilities. Available exclusively to vetted teams through the Fairwind Program, the model significantly enhances cybersecurity defense by outperforming larger competitors in vulnerability discovery and remediation.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/09/02/health-data-of-more-than.html</link>
      <pubDate>Wed, 02 Sep 2026 14:09:49 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/09/02/health-data-of-more-than.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://therecord.media/health-data-aesto-cyberattack-leak&#34;&gt;Health data of more than 9.5 million people leaked from Aesto record system | The Record from Recorded Future News&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The healthcare data company Aesto confirmed a cyberattack resulted in the data breach of sensitive information belonging to more than 9.5 million people. Hackers accessed Amazon Web Services infrastructure last December, exposing Social Security numbers, medical records, and financial data across 30 affected organizations.&lt;/p&gt;
</description>
      <source:markdown>[Health data of more than 9.5 million people leaked from Aesto record system | The Record from Recorded Future News](https://therecord.media/health-data-aesto-cyberattack-leak)

The healthcare data company Aesto confirmed a cyberattack resulted in the data breach of sensitive information belonging to more than 9.5 million people. Hackers accessed Amazon Web Services infrastructure last December, exposing Social Security numbers, medical records, and financial data across 30 affected organizations.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/09/02/kimi-k-outperforms-rival-openweight.html</link>
      <pubDate>Wed, 02 Sep 2026 14:08:06 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/09/02/kimi-k-outperforms-rival-openweight.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://cryptobriefing.com/kimi-k3-bitcoin-vulnerability-detection/&#34;&gt;Kimi K3 outperforms rival open-weight models in finding Bitcoin vulnerabilities&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The Kimi K3 open-weight AI model successfully identified nearly 8,000 potential security issues across 501 Bitcoin projects within two weeks. It outperformed rival models in vulnerability detection benchmarks, though it remains significantly less capable than leading closed-source alternatives.&lt;/p&gt;
</description>
      <source:markdown>[Kimi K3 outperforms rival open-weight models in finding Bitcoin vulnerabilities](https://cryptobriefing.com/kimi-k3-bitcoin-vulnerability-detection/)

The Kimi K3 open-weight AI model successfully identified nearly 8,000 potential security issues across 501 Bitcoin projects within two weeks. It outperformed rival models in vulnerability detection benchmarks, though it remains significantly less capable than leading closed-source alternatives.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/09/02/whatsapp-video-call-flaw-lets.html</link>
      <pubDate>Wed, 02 Sep 2026 14:06:46 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/09/02/whatsapp-video-call-flaw-lets.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://cybersecuritynews.com/whatsapp-video-call-flaw/&#34;&gt;WhatsApp Video Call Flaw Lets Anyone Bypass Your Android Lock Screen and View Your Photos&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A WhatsApp vulnerability on Android allows attackers to bypass the lock screen and view private photos by answering an incoming video call. Users can protect their devices by restricting app permissions for photo and video access in the system settings.&lt;/p&gt;
</description>
      <source:markdown>[WhatsApp Video Call Flaw Lets Anyone Bypass Your Android Lock Screen and View Your Photos](https://cybersecuritynews.com/whatsapp-video-call-flaw/)

A WhatsApp vulnerability on Android allows attackers to bypass the lock screen and view private photos by answering an incoming video call. Users can protect their devices by restricting app permissions for photo and video access in the system settings.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/09/01/rhysida-claims-berlin-hack-tb.html</link>
      <pubDate>Tue, 01 Sep 2026 19:16:44 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/09/01/rhysida-claims-berlin-hack-tb.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://tech-insider.org/rhysida-berlin-government-ransomware-breach-2026/&#34;&gt;Rhysida Claims Berlin Hack: 5.79 TB, 30 BTC Demand [2026]&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The Rhysida ransomware group has claimed a 5.79 TB data breach against the Berlin state government, demanding 30 Bitcoin to prevent publication. In line with official no-payment policies, the Governing Mayor has confirmed a major cyber incident but refused to meet the extortion demands.&lt;/p&gt;
</description>
      <source:markdown>[Rhysida Claims Berlin Hack: 5.79 TB, 30 BTC Demand [2026]](https://tech-insider.org/rhysida-berlin-government-ransomware-breach-2026/)

The Rhysida ransomware group has claimed a 5.79 TB data breach against the Berlin state government, demanding 30 Bitcoin to prevent publication. In line with official no-payment policies, the Governing Mayor has confirmed a major cyber incident but refused to meet the extortion demands.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/09/01/hackers-claim-millions-of-patient.html</link>
      <pubDate>Tue, 01 Sep 2026 19:15:48 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/09/01/hackers-claim-millions-of-patient.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://techcrunch.com/2026/08/31/hackers-claim-millions-of-patient-records-stolen-during-data-breach-at-healthcare-giant-mckesson/&#34;&gt;Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson | TechCrunch&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The hacking group ShinyHunters has claimed responsibility for a data breach at the healthcare giant McKesson, allegedly stealing millions of patient and employee records via phishing and social engineering. The attackers are reportedly demanding a $55 million ransom after compromising sensitive information from the company&amp;rsquo;s cloud-hosted environments.&lt;/p&gt;
</description>
      <source:markdown>[Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson | TechCrunch](https://techcrunch.com/2026/08/31/hackers-claim-millions-of-patient-records-stolen-during-data-breach-at-healthcare-giant-mckesson/)

The hacking group ShinyHunters has claimed responsibility for a data breach at the healthcare giant McKesson, allegedly stealing millions of patient and employee records via phishing and social engineering. The attackers are reportedly demanding a $55 million ransom after compromising sensitive information from the company&#39;s cloud-hosted environments.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/09/01/hackers-leak-sensitive-law-enforcement.html</link>
      <pubDate>Tue, 01 Sep 2026 19:14:52 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/09/01/hackers-leak-sensitive-law-enforcement.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.cnn.com/2026/08/31/politics/hackers-sensitive-data-bureau-alcohol-tobacco-firearms-explosives&#34;&gt;Hackers leak sensitive law enforcement files stolen from the DOJ | CNN Politics&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A Russian-speaking cybercriminal gang known as Qilin has leaked sensitive law enforcement files stolen from the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). The stolen data includes information on ATF investigations and investigative agents, prompting an ongoing cybersecurity assessment by federal agencies.&lt;/p&gt;
</description>
      <source:markdown>[Hackers leak sensitive law enforcement files stolen from the DOJ | CNN Politics](https://www.cnn.com/2026/08/31/politics/hackers-sensitive-data-bureau-alcohol-tobacco-firearms-explosives)

A Russian-speaking cybercriminal gang known as Qilin has leaked sensitive law enforcement files stolen from the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). The stolen data includes information on ATF investigations and investigative agents, prompting an ongoing cybersecurity assessment by federal agencies.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/08/31/microsoft-warns-of-terminalfix-attacks.html</link>
      <pubDate>Mon, 31 Aug 2026 15:37:59 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/08/31/microsoft-warns-of-terminalfix-attacks.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels/&#34;&gt;Microsoft warns of TerminalFix attacks deploying reverse tunnels&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Microsoft warns that TerminalFix attacks use fake CAPTCHA prompts to trick users into running malicious PowerShell commands that establish a reverse tunnel for network infiltration. This multi-stage campaign enables attackers to perform reconnaissance, move laterally, and deploy further threats within compromised systems.&lt;/p&gt;
</description>
      <source:markdown>[Microsoft warns of TerminalFix attacks deploying reverse tunnels](https://www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels/)

Microsoft warns that TerminalFix attacks use fake CAPTCHA prompts to trick users into running malicious PowerShell commands that establish a reverse tunnel for network infiltration. This multi-stage campaign enables attackers to perform reconnaissance, move laterally, and deploy further threats within compromised systems.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/08/31/watchguard-security-advisory-av-canadian.html</link>
      <pubDate>Mon, 31 Aug 2026 15:36:48 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/08/31/watchguard-security-advisory-av-canadian.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.cyber.gc.ca/en/alerts-advisories/watchguard-security-advisory-av26-865&#34;&gt;WatchGuard security advisory (AV26-865) - Canadian Centre for Cyber Security&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The WatchGuard security advisory (AV26-865) identifies critical vulnerabilities affecting Dimension and Fireware OS products. Administrators should apply the latest software updates to mitigate these security risks.&lt;/p&gt;
</description>
      <source:markdown>[WatchGuard security advisory (AV26-865) - Canadian Centre for Cyber Security](https://www.cyber.gc.ca/en/alerts-advisories/watchguard-security-advisory-av26-865)

The WatchGuard security advisory (AV26-865) identifies critical vulnerabilities affecting Dimension and Fireware OS products. Administrators should apply the latest software updates to mitigate these security risks.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/08/31/north-korean-hackers-move-million.html</link>
      <pubDate>Mon, 31 Aug 2026 15:35:54 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/08/31/north-korean-hackers-move-million.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://cryptobriefing.com/north-korean-hackers-move-30-million-in-bitcoin-via-hyperliquid-data-reveals/&#34;&gt;North Korean hackers move $30 million in bitcoin via Hyperliquid, data reveals&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Recent data reveals that North Korean hackers have moved over $30 million in bitcoin through the decentralized derivatives platform Hyperliquid. These ongoing transactions have prompted increased scrutiny regarding the platform&amp;rsquo;s security and regulatory standing.&lt;/p&gt;
</description>
      <source:markdown>[North Korean hackers move $30 million in bitcoin via Hyperliquid, data reveals](https://cryptobriefing.com/north-korean-hackers-move-30-million-in-bitcoin-via-hyperliquid-data-reveals/)

Recent data reveals that North Korean hackers have moved over $30 million in bitcoin through the decentralized derivatives platform Hyperliquid. These ongoing transactions have prompted increased scrutiny regarding the platform&#39;s security and regulatory standing.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/08/31/grok-bot-transforms-coding-tasks.html</link>
      <pubDate>Mon, 31 Aug 2026 15:35:05 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/08/31/grok-bot-transforms-coding-tasks.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://cryptobriefing.com/grok-bot-coding-chatgpt-moment/&#34;&gt;Grok Bot transforms coding tasks as a16z investor calls it a ChatGPT moment&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Grok Bot is an xAI coding agent that utilizes parallel processing and cloud-based architecture to outperform Claude Code in speed and practical automation tasks. An a16z investor has labeled this technical advancement a ChatGPT moment due to its significant impact on developer workflows and industry expectations.&lt;/p&gt;
</description>
      <source:markdown>[Grok Bot transforms coding tasks as a16z investor calls it a ChatGPT moment](https://cryptobriefing.com/grok-bot-coding-chatgpt-moment/)

Grok Bot is an xAI coding agent that utilizes parallel processing and cloud-based architecture to outperform Claude Code in speed and practical automation tasks. An a16z investor has labeled this technical advancement a ChatGPT moment due to its significant impact on developer workflows and industry expectations.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/08/31/sp-set-to-announce-rebalancing.html</link>
      <pubDate>Mon, 31 Aug 2026 15:33:44 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/08/31/sp-set-to-announce-rebalancing.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://cryptobriefing.com/sp500-rebalancing-changes-friday/&#34;&gt;S&amp;amp;P 500 set to announce rebalancing changes this Friday, putting $27 trillion in motion&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The S&amp;amp;P 500 quarterly rebalancing announcement this Friday will trigger mandatory portfolio adjustments across nearly $27 trillion in passive assets. These shifts, which force buying and selling of index components, typically create significant market movement for companies added to or removed from the benchmark.&lt;/p&gt;
</description>
      <source:markdown>[S&amp;P 500 set to announce rebalancing changes this Friday, putting $27 trillion in motion](https://cryptobriefing.com/sp500-rebalancing-changes-friday/)

The S&amp;P 500 quarterly rebalancing announcement this Friday will trigger mandatory portfolio adjustments across nearly $27 trillion in passive assets. These shifts, which force buying and selling of index components, typically create significant market movement for companies added to or removed from the benchmark.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/08/31/hidden-attack-slips-past-claude.html</link>
      <pubDate>Mon, 31 Aug 2026 15:31:29 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/08/31/hidden-attack-slips-past-claude.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.govinfosecurity.com/hidden-attack-slips-past-claude-code-auto-mode-a-32693&#34;&gt;Hidden Attack Slips Past Claude Code Auto Mode&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A security researcher demonstrated that prompt injection attacks can bypass Claude Code Auto Mode, tricking the AI into executing unauthorized malicious code. Anthropic maintains that the feature is a convenience tool rather than a security guarantee and recommends human oversight for sensitive tasks.&lt;/p&gt;
</description>
      <source:markdown>[Hidden Attack Slips Past Claude Code Auto Mode](https://www.govinfosecurity.com/hidden-attack-slips-past-claude-code-auto-mode-a-32693)

A security researcher demonstrated that prompt injection attacks can bypass Claude Code Auto Mode, tricking the AI into executing unauthorized malicious code. Anthropic maintains that the feature is a convenience tool rather than a security guarantee and recommends human oversight for sensitive tasks.
</source:markdown>
    </item>
    
    <item>
      <title>A side project: BagCheck</title>
      <link>https://threatintel.cc/2026/08/31/a-side-project-bagcheck.html</link>
      <pubDate>Mon, 31 Aug 2026 13:39:36 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/08/31/a-side-project-bagcheck.html</guid>
      <description>&lt;p&gt;I recently launched &lt;strong&gt;&lt;a href=&#34;https://bag-check.org/&#34;&gt;BagCheck&lt;/a&gt;&lt;/strong&gt;, a free tool for answering a practical travel question:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Will this bag work for this trip?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;BagCheck lets you check backpacks, carry-ons and personal items against published airline size limits, compare bags side by side and plan multi-airline trips.&lt;/p&gt;
&lt;p&gt;I built it as a personal learning project to sharpen newer technical skills by solving a problem I actually have. I travel frequently, like bags and was tired of repeatedly comparing manufacturer dimensions with airline baggage rules by hand.&lt;/p&gt;
&lt;p&gt;What started as an experiment became a project of love.&lt;/p&gt;
&lt;p&gt;One of the biggest lessons was that &lt;strong&gt;data quality matters more than database size&lt;/strong&gt;. During the research, I found large public bag datasets with enough inconsistent, outdated or difficult-to-substantiate records to convince me that quantity alone is a poor benchmark.&lt;/p&gt;
&lt;p&gt;BagCheck takes a more conservative approach. It emphasizes source-backed data, keeps uncertainty visible and separates &lt;strong&gt;physical fit&lt;/strong&gt; from &lt;strong&gt;ticket allowance&lt;/strong&gt; rather than turning incomplete information into a confident answer.&lt;/p&gt;
&lt;p&gt;It is also independent and non-commercial. There are no affiliate commissions, paid placements or advertising influencing results. Core features do not require an account, and the site&amp;rsquo;s privacy approach is intentionally minimal.&lt;/p&gt;
&lt;p&gt;BagCheck is not a review site and does not try to replace resources such as Pack Hacker, Carryology or One Bag Travel. Its focus is narrower:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;I have this bag. Will it work?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;I am flying these airlines. Which bags should I consider?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Will one bag work across my whole itinerary?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;If that sounds useful, &lt;strong&gt;&lt;a href=&#34;https://bag-check.org/&#34;&gt;try BagCheck&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;You can also read the &lt;strong&gt;&lt;a href=&#34;https://bag-check.org/methodology&#34;&gt;methodology&lt;/a&gt;&lt;/strong&gt; and &lt;strong&gt;&lt;a href=&#34;https://bag-check.org/privacy&#34;&gt;privacy notice&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 id=&#34;disclaimer&#34;&gt;Disclaimer&lt;/h2&gt;
&lt;p&gt;BagCheck is provided for informational and travel-planning purposes only. Airline baggage policies, fare conditions and enforcement practices can change. Always confirm current baggage rules with the operating airline before travel.&lt;/p&gt;
&lt;img src=&#34;https://cdn.uploads.micro.blog/191896/2026/chatgpt-image-aug-31-2026-01-28-03-pm.png&#34;&gt;
</description>
      <source:markdown>I recently launched **[BagCheck](https://bag-check.org/)**, a free tool for answering a practical travel question:


**Will this bag work for this trip?**


BagCheck lets you check backpacks, carry-ons and personal items against published airline size limits, compare bags side by side and plan multi-airline trips.


I built it as a personal learning project to sharpen newer technical skills by solving a problem I actually have. I travel frequently, like bags and was tired of repeatedly comparing manufacturer dimensions with airline baggage rules by hand.


What started as an experiment became a project of love.


One of the biggest lessons was that **data quality matters more than database size**. During the research, I found large public bag datasets with enough inconsistent, outdated or difficult-to-substantiate records to convince me that quantity alone is a poor benchmark.


BagCheck takes a more conservative approach. It emphasizes source-backed data, keeps uncertainty visible and separates **physical fit** from **ticket allowance** rather than turning incomplete information into a confident answer.


It is also independent and non-commercial. There are no affiliate commissions, paid placements or advertising influencing results. Core features do not require an account, and the site&#39;s privacy approach is intentionally minimal.


BagCheck is not a review site and does not try to replace resources such as Pack Hacker, Carryology or One Bag Travel. Its focus is narrower:


**I have this bag. Will it work?**


**I am flying these airlines. Which bags should I consider?**


**Will one bag work across my whole itinerary?**


If that sounds useful, **[try BagCheck](https://bag-check.org/)**.


You can also read the **[methodology](https://bag-check.org/methodology)** and **[privacy notice](https://bag-check.org/privacy)**.


## Disclaimer


BagCheck is provided for informational and travel-planning purposes only. Airline baggage policies, fare conditions and enforcement practices can change. Always confirm current baggage rules with the operating airline before travel.



&lt;img src=&#34;https://cdn.uploads.micro.blog/191896/2026/chatgpt-image-aug-31-2026-01-28-03-pm.png&#34;&gt;
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/08/30/berlin-cyberattack-hackers-demand-million.html</link>
      <pubDate>Sun, 30 Aug 2026 12:32:25 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/08/30/berlin-cyberattack-hackers-demand-million.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.wionews.com/videos/berlin-cyberattack-hackers-demand-2-5-million-ransom-threaten-to-leak-stolen-city-data-1788016790139&#34;&gt;Berlin Cyberattack | Hackers Demand $2.5 Million Ransom, Threaten To Leak Stolen City Data&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A cyberattack in Berlin has left government services disrupted while hackers demand a $2.5 million ransom in bitcoins. If the payment is not made within a week, the perpetrators threaten to leak stolen personal data.&lt;/p&gt;
</description>
      <source:markdown>[Berlin Cyberattack | Hackers Demand $2.5 Million Ransom, Threaten To Leak Stolen City Data](https://www.wionews.com/videos/berlin-cyberattack-hackers-demand-2-5-million-ransom-threaten-to-leak-stolen-city-data-1788016790139)

A cyberattack in Berlin has left government services disrupted while hackers demand a $2.5 million ransom in bitcoins. If the payment is not made within a week, the perpetrators threaten to leak stolen personal data.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/08/30/fulcrumsec-claims-manchester-airports-hack.html</link>
      <pubDate>Sun, 30 Aug 2026 12:30:59 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/08/30/fulcrumsec-claims-manchester-airports-hack.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/&#34;&gt;FulcrumSec claims Manchester Airports hack, theft of 86 GB of data&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The extortion group FulcrumSec has claimed responsibility for a data breach at the Manchester Airports Group (MAG), alleging that they exfiltrated approximately 86 GB of customer information via exposed API credentials. While MAG confirmed a security incident affecting customer bookings, they declined to address specific claims regarding the extent of the stolen data.&lt;/p&gt;
</description>
      <source:markdown>[FulcrumSec claims Manchester Airports hack, theft of 86 GB of data](https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/)

The extortion group FulcrumSec has claimed responsibility for a data breach at the Manchester Airports Group (MAG), alleging that they exfiltrated approximately 86 GB of customer information via exposed API credentials. While MAG confirmed a security incident affecting customer bookings, they declined to address specific claims regarding the extent of the stolen data.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/08/30/abbott-vishing-hack-shinyhunters-leak.html</link>
      <pubDate>Sun, 30 Aug 2026 12:30:15 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/08/30/abbott-vishing-hack-shinyhunters-leak.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://tech-insider.org/abbott-shinyhunters-vishing-breach-2026/&#34;&gt;Abbott Vishing Hack: ShinyHunters Leak 10.9M Emails&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The Abbott Laboratories breach, which exposed 10.9 million email addresses in 2026, was caused by a vishing attack where ShinyHunters impersonated a trusted contact to gain credentials from an employee. This incident highlights a growing trend where cybercriminals bypass security perimeters by targeting IT help desks via social engineering.&lt;/p&gt;
</description>
      <source:markdown>[Abbott Vishing Hack: ShinyHunters Leak 10.9M Emails](https://tech-insider.org/abbott-shinyhunters-vishing-breach-2026/)

The Abbott Laboratories breach, which exposed 10.9 million email addresses in 2026, was caused by a vishing attack where ShinyHunters impersonated a trusted contact to gain credentials from an employee. This incident highlights a growing trend where cybercriminals bypass security perimeters by targeting IT help desks via social engineering.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/08/30/tb-of-valve-data-leaked.html</link>
      <pubDate>Sun, 30 Aug 2026 12:29:04 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/08/30/tb-of-valve-data-leaked.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://gamerant.com/valve-hack-12-tb-leak-portal-2-left-4-dead-half-life-assets/&#34;&gt;12 TB of Valve Data Leaked, Possibly Including Half-Life 2 Episode 3&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A massive 12 TB Valve data leak has surfaced online, containing internal game builds and assets for titles like Portal 2, Left 4 Dead, and F-Stop. While researchers identified a potential connection to Half-Life 2: Episode 3 through a shared weapon model, no definitive evidence confirms an included build for the game.&lt;/p&gt;
</description>
      <source:markdown>[12 TB of Valve Data Leaked, Possibly Including Half-Life 2 Episode 3](https://gamerant.com/valve-hack-12-tb-leak-portal-2-left-4-dead-half-life-assets/)

A massive 12 TB Valve data leak has surfaced online, containing internal game builds and assets for titles like Portal 2, Left 4 Dead, and F-Stop. While researchers identified a potential connection to Half-Life 2: Episode 3 through a shared weapon model, no definitive evidence confirms an included build for the game.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/08/28/tech-cybersecurity-giants-unite-behind.html</link>
      <pubDate>Fri, 28 Aug 2026 13:23:01 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/08/28/tech-cybersecurity-giants-unite-behind.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.securityweek.com/tech-cybersecurity-giants-unite-behind-openai-led-cyber-defense-pledge/&#34;&gt;Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge - SecurityWeek&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Nearly 130 organizations have joined an OpenAI-led initiative to launch a global cyber defense effort aimed at countering the rising sophistication of AI-enabled attacks. The coalition emphasizes coordinated security improvements, shared threat intelligence, and increased support for critical infrastructure to mitigate evolving risks.&lt;/p&gt;
</description>
      <source:markdown>[Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge - SecurityWeek](https://www.securityweek.com/tech-cybersecurity-giants-unite-behind-openai-led-cyber-defense-pledge/)

Nearly 130 organizations have joined an OpenAI-led initiative to launch a global cyber defense effort aimed at countering the rising sophistication of AI-enabled attacks. The coalition emphasizes coordinated security improvements, shared threat intelligence, and increased support for critical infrastructure to mitigate evolving risks.
</source:markdown>
    </item>
    
    <item>
      <title></title>
      <link>https://threatintel.cc/2026/08/28/morocco-denies-dgsn-and-dgst.html</link>
      <pubDate>Fri, 28 Aug 2026 12:43:01 -0400</pubDate>
      
      <guid>http://threatintel.micro.blog/2026/08/28/morocco-denies-dgsn-and-dgst.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://en.yabiladi.com/articles/details/201507/morocco-denies-dgsn-dgst-data.html&#34;&gt;Morocco denies DGSN and DGST data breach after Jabaroot leaks&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Moroccan security authorities have categorically denied a data breach of their systems, dismissing claims by the hacker group Jabaroot as fabricated and derived from outdated third-party databases. Officials emphasized that no cyberattack occurred on their infrastructure and have launched investigations to identify those responsible for spreading false information.&lt;/p&gt;
</description>
      <source:markdown>[Morocco denies DGSN and DGST data breach after Jabaroot leaks](https://en.yabiladi.com/articles/details/201507/morocco-denies-dgsn-dgst-data.html)

Moroccan security authorities have categorically denied a data breach of their systems, dismissing claims by the hacker group Jabaroot as fabricated and derived from outdated third-party databases. Officials emphasized that no cyberattack occurred on their infrastructure and have launched investigations to identify those responsible for spreading false information.
</source:markdown>
    </item>
    
  </channel>
</rss>
