CyberScoop
cyberscoop · B · active
US-centric cybersecurity policy and incident reporting. Homepage 'The Latest' section lists titles WITHOUT publication dates surfacing in WebFetch — drill into individual articles to recover dates. Article URLs are top-level (e.g. /latvian-russia-ransomware-conti-sentenced/); do not GUESS slugs. RSS at https://cyberscoop.com/feed/ surfaces dates cleanly. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → feed https://cyberscoop.com/feed/ 5 (clean dates + full article URLs; then webfetch the article URL for body) — or webfetch the article URL directly. AVOID: Homepage 'The Latest' lists titles without surfacing dates in WebFetch — use the RSS feed for dates. Do not guess article slugs; take them from the feed.. | 2026-07-05 admiralty audit: B — original security journalism with editorial corroboration; live and drillable via RSS, no change (active).
Cited in 12 entries
Citation cadence
Citation days per ISO week (11 weeks of coverage span, total 10).
- In every confirmed European public-sector and critical-infrastructure incident this week the entry point was an already-valid credential, and the attacker's tool was the platform's own export or admin function2026-08-02
- Open-source supply-chain wave status: a second vendor assesses the escalation at high confidence, the CI trigger that hands over base-repository secrets is named, and two vendors independently attribute the axios compromise to the same DPRK cluster2026-08-02
- Huntress: a three-day credential-stuffing run logged into 92 SonicWall VPN and firewall accounts across 30 organisations, with no follow-on activity observed2026-07-30
- Amazon attributes the axios, debug and chalk npm compromises to a DPRK-linked cluster with medium confidence, and names a small 2025 package compromise as the rehearsal2026-07-30
- Cisco Talos: "ARToken" exposes a full BEC-as-a-service toolkit on top of Microsoft 365 device-code phishing2026-07-02
- CVE-2026-8451 — Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed lineage), public PoC2026-07-01
- FBI "Operation Ghost Hook" seizes the Outsider PhaaS infrastructure Google had sued2026-06-15
- Conti loader developer Oleksii Lytvynenko pleads guilty in US federal court after extradition from Ireland2026-06-14
- Meta files contempt complaint against NSO Group over fresh WhatsApp spyware phishing2026-06-09
- FBI FLASH CSA 260526 — Silent Ransom Group sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social engineering fails2026-05-28
- UNC6671 / BlackFile — GTIG publishes the full profile; group announced shutdown "under this name", rebrand probable2026-05-25
- FBI PSA260521 — Kali365 OAuth device-code PhaaS bypasses M365 MFA without credential capture2026-05-23