<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Use Case Intel — Threat Intel Feed</title>
    <description>High-fidelity IOCs aggregated from The Hacker News, BleepingComputer, Microsoft Security Blog and CISA KEV. Refreshed daily. CVEs/hashes via regex; domains/IPs only when defanged by the source author.</description>
    <link>https://clankerusecase.com/</link>
    <atom:link href="https://clankerusecase.com/intel/iocs.rss.xml" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <pubDate>Mon, 15 Jun 2026 01:48:51 +0000</pubDate>
    <lastBuildDate>Mon, 15 Jun 2026 01:48:51 +0000</lastBuildDate>
    <generator>usecaseintel/generate.py</generator>
    <item>
      <title>[IPV4/MED] 92.112.198.22</title>
      <link>https://cybersecuritynews.com/chrome-extensions-hide-ad-tracking/</link>
      <description>&lt;p&gt;&lt;strong&gt;IPV4:&lt;/strong&gt; &lt;code&gt;92.112.198.22&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-14 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: 152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:ipv4:92.112.198.22</guid>
      <pubDate>Sun, 14 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[IPV4/MED] 147.79.120.202</title>
      <link>https://cybersecuritynews.com/chrome-extensions-hide-ad-tracking/</link>
      <description>&lt;p&gt;&lt;strong&gt;IPV4:&lt;/strong&gt; &lt;code&gt;147.79.120.202&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-14 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: 152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:ipv4:147.79.120.202</guid>
      <pubDate>Sun, 14 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/MED] yowgames.com</title>
      <link>https://cybersecuritynews.com/chrome-extensions-hide-ad-tracking/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;yowgames.com&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-14 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: 152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:yowgames.com</guid>
      <pubDate>Sun, 14 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/MED] tabplugins.com</title>
      <link>https://cybersecuritynews.com/chrome-extensions-hide-ad-tracking/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;tabplugins.com&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-14 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: 152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:tabplugins.com</guid>
      <pubDate>Sun, 14 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/MED] owhit.com</title>
      <link>https://cybersecuritynews.com/chrome-extensions-hide-ad-tracking/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;owhit.com&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-14 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: 152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:owhit.com</guid>
      <pubDate>Sun, 14 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/MED] chromewallpaper.com</title>
      <link>https://cybersecuritynews.com/chrome-extensions-hide-ad-tracking/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;chromewallpaper.com&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-14 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: 152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:chromewallpaper.com</guid>
      <pubDate>Sun, 14 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/MED] avads.live</title>
      <link>https://cybersecuritynews.com/chrome-extensions-hide-ad-tracking/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;avads.live&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-14 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: 152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:avads.live</guid>
      <pubDate>Sun, 14 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/CRIT] temp.sh</title>
      <link>https://www.stepsecurity.io/blog/400-aur-packages-hijacked-atomic-arch-campaign</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;temp.sh&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-13 · Sources: StepSecurity, The Hacker News, BleepingComputer&lt;/p&gt;&lt;p&gt;Context: 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:temp.sh</guid>
      <pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate>
      <category>StepSecurity</category>
      <category>The Hacker News</category>
      <category>BleepingComputer</category>
    </item>
    <item>
      <title>[DOMAIN/CRIT] gs.thc.org</title>
      <link>https://www.bleepingcomputer.com/news/security/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;gs.thc.org&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-13 · Sources: BleepingComputer&lt;/p&gt;&lt;p&gt;Context: Chinese hackers hijack auth flow, spy on isolated network for a decade&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:gs.thc.org</guid>
      <pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate>
      <category>BleepingComputer</category>
    </item>
    <item>
      <title>[DOMAIN/CRIT] github.com/fardewoak/nodejs-argo</title>
      <link>https://www.stepsecurity.io/blog/400-aur-packages-hijacked-atomic-arch-campaign</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;github.com/fardewoak/nodejs-argo&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-13 · Sources: StepSecurity&lt;/p&gt;&lt;p&gt;Context: 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:github.com/fardewoak/nodejs-argo</guid>
      <pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate>
      <category>StepSecurity</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] advisory-tracker.com</title>
      <link>https://cybersecuritynews.com/agentjacking-attack-hijacks-ai-coding-agent/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;advisory-tracker.com&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-13 · Sources: Cyber Security News, The Hacker News&lt;/p&gt;&lt;p&gt;Context: New Agentjacking Attack Hijacks Your AI Coding Agent to Run Code From a Hacker’s Server&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:advisory-tracker.com</guid>
      <pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[CVE/CRIT] CVE-2026-20253</title>
      <link>https://thehackernews.com/2026/06/critical-splunk-enterprise-flaw-lets.html</link>
      <description>&lt;p&gt;&lt;strong&gt;CVE:&lt;/strong&gt; &lt;code&gt;CVE-2026-20253&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-13 · Sources: The Hacker News, Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:cve:CVE-2026-20253</guid>
      <pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[CVE/CRIT] CVE-2024-20399</title>
      <link>https://www.bleepingcomputer.com/news/security/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade/</link>
      <description>&lt;p&gt;&lt;strong&gt;CVE:&lt;/strong&gt; &lt;code&gt;CVE-2024-20399&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-13 · Sources: BleepingComputer, The Hacker News, CISA KEV&lt;/p&gt;&lt;p&gt;Context: Chinese hackers hijack auth flow, spy on isolated network for a decade&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:cve:CVE-2024-20399</guid>
      <pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate>
      <category>BleepingComputer</category>
      <category>The Hacker News</category>
      <category>CISA KEV</category>
    </item>
    <item>
      <title>[SHA256/HIGH] feabf10c8a9ba2775bb0f7f9d0b20203112b7df8e6d333a44d5a11eae0e38e86</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;feabf10c8a9ba2775bb0f7f9d0b20203112b7df8e6d333a44d5a11eae0e38e86&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:feabf10c8a9ba2775bb0f7f9d0b20203112b7df8e6d333a44d5a11eae0e38e86</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] fd3f13db41cd5b442fa26ba8bc0e9703ed243b3516374e3ef89be71cbf07436b</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;fd3f13db41cd5b442fa26ba8bc0e9703ed243b3516374e3ef89be71cbf07436b&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:fd3f13db41cd5b442fa26ba8bc0e9703ed243b3516374e3ef89be71cbf07436b</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/CRIT] f099c5d9ec417d4445a0328ac0ada9cde79fc37410914103ae9c609cbc0ee068</title>
      <link>https://www.bleepingcomputer.com/news/security/early-warning-signs-of-supply-chain-attacks-live-in-the-dark-web/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;f099c5d9ec417d4445a0328ac0ada9cde79fc37410914103ae9c609cbc0ee068&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: BleepingComputer, Aikido, StepSecurity, Snyk&lt;/p&gt;&lt;p&gt;Context: Early Warning Signs of Supply-Chain Attacks Live in the Dark Web&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:f099c5d9ec417d4445a0328ac0ada9cde79fc37410914103ae9c609cbc0ee068</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>BleepingComputer</category>
      <category>Aikido</category>
      <category>StepSecurity</category>
      <category>Snyk</category>
    </item>
    <item>
      <title>[SHA256/HIGH] e848d73a68e4e8aea00a6257552b5872907dfaf7cce3d94636d7e59d286edeab</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;e848d73a68e4e8aea00a6257552b5872907dfaf7cce3d94636d7e59d286edeab&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:e848d73a68e4e8aea00a6257552b5872907dfaf7cce3d94636d7e59d286edeab</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/CRIT] dc67467a39b70d1cd4c1f7f7a459b35058163592f4a9e8fb4dffcbba98ef210c</title>
      <link>https://www.bleepingcomputer.com/news/security/early-warning-signs-of-supply-chain-attacks-live-in-the-dark-web/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;dc67467a39b70d1cd4c1f7f7a459b35058163592f4a9e8fb4dffcbba98ef210c&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: BleepingComputer, Aikido, StepSecurity, Snyk&lt;/p&gt;&lt;p&gt;Context: Early Warning Signs of Supply-Chain Attacks Live in the Dark Web&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:dc67467a39b70d1cd4c1f7f7a459b35058163592f4a9e8fb4dffcbba98ef210c</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>BleepingComputer</category>
      <category>Aikido</category>
      <category>StepSecurity</category>
      <category>Snyk</category>
    </item>
    <item>
      <title>[SHA256/HIGH] d94a2444268b339dfda2615f7800322fb318e0a484414bb17016cfcd5eb07c44</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;d94a2444268b339dfda2615f7800322fb318e0a484414bb17016cfcd5eb07c44&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:d94a2444268b339dfda2615f7800322fb318e0a484414bb17016cfcd5eb07c44</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] d7ec660a2a29c1aabcbe9bff1ef29be9a9fab8c7fe7c40df4772dd2b5bdf9666</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;d7ec660a2a29c1aabcbe9bff1ef29be9a9fab8c7fe7c40df4772dd2b5bdf9666&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:d7ec660a2a29c1aabcbe9bff1ef29be9a9fab8c7fe7c40df4772dd2b5bdf9666</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] d6abc7003b580472d808b338adef0b28eacc698cd4692f76cb2a91718ab78d88</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;d6abc7003b580472d808b338adef0b28eacc698cd4692f76cb2a91718ab78d88&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:d6abc7003b580472d808b338adef0b28eacc698cd4692f76cb2a91718ab78d88</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/CRIT] cbb9bc5a8496243e02f3cc080efbe3e4a1430ba0671f2e43a202bf45b05479cd</title>
      <link>https://www.bleepingcomputer.com/news/security/early-warning-signs-of-supply-chain-attacks-live-in-the-dark-web/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;cbb9bc5a8496243e02f3cc080efbe3e4a1430ba0671f2e43a202bf45b05479cd&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: BleepingComputer, Aikido, StepSecurity, Snyk&lt;/p&gt;&lt;p&gt;Context: Early Warning Signs of Supply-Chain Attacks Live in the Dark Web&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:cbb9bc5a8496243e02f3cc080efbe3e4a1430ba0671f2e43a202bf45b05479cd</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>BleepingComputer</category>
      <category>Aikido</category>
      <category>StepSecurity</category>
      <category>Snyk</category>
    </item>
    <item>
      <title>[SHA256/HIGH] c91183175ce77360006f964841eb4048cf37cb82103f2573e262927be4c7607f</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;c91183175ce77360006f964841eb4048cf37cb82103f2573e262927be4c7607f&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:c91183175ce77360006f964841eb4048cf37cb82103f2573e262927be4c7607f</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] bb23545380fde9f48ad070f88fe0afd695da5fcae8c5274814858c5a681d8c4e</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;bb23545380fde9f48ad070f88fe0afd695da5fcae8c5274814858c5a681d8c4e&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:bb23545380fde9f48ad070f88fe0afd695da5fcae8c5274814858c5a681d8c4e</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] bab96257018df49ace8fe8adfadc74cf8327fcf9a9dc8a3a7c9ac8e18881df5f</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;bab96257018df49ace8fe8adfadc74cf8327fcf9a9dc8a3a7c9ac8e18881df5f&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:bab96257018df49ace8fe8adfadc74cf8327fcf9a9dc8a3a7c9ac8e18881df5f</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/CRIT] b74caeaa75e077c99f7d44f46daaf9796a3be43ecf24f2a1fd381844669da777</title>
      <link>https://www.bleepingcomputer.com/news/security/early-warning-signs-of-supply-chain-attacks-live-in-the-dark-web/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;b74caeaa75e077c99f7d44f46daaf9796a3be43ecf24f2a1fd381844669da777&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: BleepingComputer, Aikido, StepSecurity, Snyk&lt;/p&gt;&lt;p&gt;Context: Early Warning Signs of Supply-Chain Attacks Live in the Dark Web&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:b74caeaa75e077c99f7d44f46daaf9796a3be43ecf24f2a1fd381844669da777</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>BleepingComputer</category>
      <category>Aikido</category>
      <category>StepSecurity</category>
      <category>Snyk</category>
    </item>
    <item>
      <title>[SHA256/HIGH] b2ba51b4491da8604ff9410d6e004971e3cd9a321390d0258e294ac42010b546</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;b2ba51b4491da8604ff9410d6e004971e3cd9a321390d0258e294ac42010b546&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:b2ba51b4491da8604ff9410d6e004971e3cd9a321390d0258e294ac42010b546</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] a944a09783023a2c6c62d3601cbd5392a03d808a6a51728e07a3270861c2a8ee</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;a944a09783023a2c6c62d3601cbd5392a03d808a6a51728e07a3270861c2a8ee&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:a944a09783023a2c6c62d3601cbd5392a03d808a6a51728e07a3270861c2a8ee</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] a876f648991711e44a8dcf888a271880c6c930e5138f284cd6ca6128eca56ba1</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;a876f648991711e44a8dcf888a271880c6c930e5138f284cd6ca6128eca56ba1&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:a876f648991711e44a8dcf888a271880c6c930e5138f284cd6ca6128eca56ba1</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/CRIT] a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a</title>
      <link>https://www.bleepingcomputer.com/news/security/early-warning-signs-of-supply-chain-attacks-live-in-the-dark-web/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: BleepingComputer, Aikido, StepSecurity, Snyk&lt;/p&gt;&lt;p&gt;Context: Early Warning Signs of Supply-Chain Attacks Live in the Dark Web&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>BleepingComputer</category>
      <category>Aikido</category>
      <category>StepSecurity</category>
      <category>Snyk</category>
    </item>
    <item>
      <title>[SHA256/HIGH] 9f4672c1374034ac4556264f0d4bf96ee242c0b5a9edaa4715b5e61fe8d55cc8</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;9f4672c1374034ac4556264f0d4bf96ee242c0b5a9edaa4715b5e61fe8d55cc8&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:9f4672c1374034ac4556264f0d4bf96ee242c0b5a9edaa4715b5e61fe8d55cc8</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] 7269c00a6164fd01dd516e0a72b2bd84c82e78feb552e06964e4992ff0479dda</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;7269c00a6164fd01dd516e0a72b2bd84c82e78feb552e06964e4992ff0479dda&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:7269c00a6164fd01dd516e0a72b2bd84c82e78feb552e06964e4992ff0479dda</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] 6585ca0d3e26c20ced638f46f4a89eea924d411b8753d3fcf434663593c7cf0b</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;6585ca0d3e26c20ced638f46f4a89eea924d411b8753d3fcf434663593c7cf0b&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:6585ca0d3e26c20ced638f46f4a89eea924d411b8753d3fcf434663593c7cf0b</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/CRIT] 62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0</title>
      <link>https://www.bleepingcomputer.com/news/security/early-warning-signs-of-supply-chain-attacks-live-in-the-dark-web/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: BleepingComputer, Aikido, StepSecurity, Snyk&lt;/p&gt;&lt;p&gt;Context: Early Warning Signs of Supply-Chain Attacks Live in the Dark Web&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>BleepingComputer</category>
      <category>Aikido</category>
      <category>StepSecurity</category>
      <category>Snyk</category>
    </item>
    <item>
      <title>[SHA256/HIGH] 6144d433f8a0316869877b5f834c801251bbb936e5f1577c5680878c7443c98b</title>
      <link>https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;6144d433f8a0316869877b5f834c801251bbb936e5f1577c5680878c7443c98b&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News, BleepingComputer&lt;/p&gt;&lt;p&gt;Context: Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:6144d433f8a0316869877b5f834c801251bbb936e5f1577c5680878c7443c98b</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
      <category>BleepingComputer</category>
    </item>
    <item>
      <title>[SHA256/HIGH] 5c50f79038b31aa8a3a68b24d8b783dfbd2e15fff7586c5609e544a717ef7d05</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;5c50f79038b31aa8a3a68b24d8b783dfbd2e15fff7586c5609e544a717ef7d05&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:5c50f79038b31aa8a3a68b24d8b783dfbd2e15fff7586c5609e544a717ef7d05</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] 5a17cfaea0cc3a82242fdd11b53140c0b56256d769b07c33757d61e0a0a6ec02</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;5a17cfaea0cc3a82242fdd11b53140c0b56256d769b07c33757d61e0a0a6ec02&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:5a17cfaea0cc3a82242fdd11b53140c0b56256d769b07c33757d61e0a0a6ec02</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/CRIT] 4b2399646573bb737c4969563303d8ee2e9ddbd1b271f1ca9e35ea78062538db</title>
      <link>https://www.bleepingcomputer.com/news/security/early-warning-signs-of-supply-chain-attacks-live-in-the-dark-web/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;4b2399646573bb737c4969563303d8ee2e9ddbd1b271f1ca9e35ea78062538db&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: BleepingComputer, Aikido, StepSecurity, Snyk&lt;/p&gt;&lt;p&gt;Context: Early Warning Signs of Supply-Chain Attacks Live in the Dark Web&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:4b2399646573bb737c4969563303d8ee2e9ddbd1b271f1ca9e35ea78062538db</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>BleepingComputer</category>
      <category>Aikido</category>
      <category>StepSecurity</category>
      <category>Snyk</category>
    </item>
    <item>
      <title>[SHA256/CRIT] 46faab8ab153fae6e80e7cca38eab363075bb524edd79e42269217a083628f09</title>
      <link>https://www.bleepingcomputer.com/news/security/early-warning-signs-of-supply-chain-attacks-live-in-the-dark-web/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;46faab8ab153fae6e80e7cca38eab363075bb524edd79e42269217a083628f09&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: BleepingComputer, Aikido, StepSecurity, Snyk&lt;/p&gt;&lt;p&gt;Context: Early Warning Signs of Supply-Chain Attacks Live in the Dark Web&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:46faab8ab153fae6e80e7cca38eab363075bb524edd79e42269217a083628f09</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>BleepingComputer</category>
      <category>Aikido</category>
      <category>StepSecurity</category>
      <category>Snyk</category>
    </item>
    <item>
      <title>[SHA256/HIGH] 3f476d316efe2514efd70c975d0c87e12357db9fca54a25834d60b28192c6a69</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;3f476d316efe2514efd70c975d0c87e12357db9fca54a25834d60b28192c6a69&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:3f476d316efe2514efd70c975d0c87e12357db9fca54a25834d60b28192c6a69</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] 2fa5b0475c3b70a3ba14c6a3938baf441a08b11841493b85e087d1d5e01eba49</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;2fa5b0475c3b70a3ba14c6a3938baf441a08b11841493b85e087d1d5e01eba49&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:2fa5b0475c3b70a3ba14c6a3938baf441a08b11841493b85e087d1d5e01eba49</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] 2822c72a59b58c00fc088aa551cdeeb92ca10fd23e23745610ff207f53118db9</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;2822c72a59b58c00fc088aa551cdeeb92ca10fd23e23745610ff207f53118db9&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:2822c72a59b58c00fc088aa551cdeeb92ca10fd23e23745610ff207f53118db9</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] 1ed863a32372160b3a25549aad25d48d5352d9b4f58d4339408c4eea69807f50</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;1ed863a32372160b3a25549aad25d48d5352d9b4f58d4339408c4eea69807f50&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:1ed863a32372160b3a25549aad25d48d5352d9b4f58d4339408c4eea69807f50</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] 17bad5ae5b2ac262f5f18854853869840245c344105aa38c7f550ef51d2e5f26</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;17bad5ae5b2ac262f5f18854853869840245c344105aa38c7f550ef51d2e5f26&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:17bad5ae5b2ac262f5f18854853869840245c344105aa38c7f550ef51d2e5f26</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA256/HIGH] 0bb0d54033767f081cae775e3cf9ede7ae6bea75f35fbfb748ccba9325e28e5e</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA256:&lt;/strong&gt; &lt;code&gt;0bb0d54033767f081cae775e3cf9ede7ae6bea75f35fbfb748ccba9325e28e5e&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha256:0bb0d54033767f081cae775e3cf9ede7ae6bea75f35fbfb748ccba9325e28e5e</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA1/HIGH] fcc8a542aad41e758cf6c18571048890be53808e</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA1:&lt;/strong&gt; &lt;code&gt;fcc8a542aad41e758cf6c18571048890be53808e&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha1:fcc8a542aad41e758cf6c18571048890be53808e</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA1/HIGH] e1bdcd1a7157f7d047a88ab4573723fe1e861951</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA1:&lt;/strong&gt; &lt;code&gt;e1bdcd1a7157f7d047a88ab4573723fe1e861951&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha1:e1bdcd1a7157f7d047a88ab4573723fe1e861951</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA1/HIGH] 74d3d5ab6d0fa4c6a5860598231728a6a893ecf7</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA1:&lt;/strong&gt; &lt;code&gt;74d3d5ab6d0fa4c6a5860598231728a6a893ecf7&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha1:74d3d5ab6d0fa4c6a5860598231728a6a893ecf7</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA1/HIGH] 70842cfc27b116d0db2fd7aa33d53a3faf510993</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA1:&lt;/strong&gt; &lt;code&gt;70842cfc27b116d0db2fd7aa33d53a3faf510993&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha1:70842cfc27b116d0db2fd7aa33d53a3faf510993</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA1/HIGH] 63154cd9c79f9d14eb9be6c4efc2a778d31646ec</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA1:&lt;/strong&gt; &lt;code&gt;63154cd9c79f9d14eb9be6c4efc2a778d31646ec&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha1:63154cd9c79f9d14eb9be6c4efc2a778d31646ec</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[SHA1/HIGH] 53b91117db931d3acbbfd15aa8400bb6691e023d</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;SHA1:&lt;/strong&gt; &lt;code&gt;53b91117db931d3acbbfd15aa8400bb6691e023d&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:sha1:53b91117db931d3acbbfd15aa8400bb6691e023d</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[MD5/HIGH] 42b59fdbe1b72895b2951412222ebf40</title>
      <link>https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html</link>
      <description>&lt;p&gt;&lt;strong&gt;MD5:&lt;/strong&gt; &lt;code&gt;42b59fdbe1b72895b2951412222ebf40&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News, BleepingComputer&lt;/p&gt;&lt;p&gt;Context: Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:md5:42b59fdbe1b72895b2951412222ebf40</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
      <category>BleepingComputer</category>
    </item>
    <item>
      <title>[IPV4/HIGH] 193.233.201.21</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;IPV4:&lt;/strong&gt; &lt;code&gt;193.233.201.21&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:ipv4:193.233.201.21</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[IPV4/CRIT] 176.120.22.24</title>
      <link>https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html</link>
      <description>&lt;p&gt;&lt;strong&gt;IPV4:&lt;/strong&gt; &lt;code&gt;176.120.22.24&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News, CISA KEV&lt;/p&gt;&lt;p&gt;Context: ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:ipv4:176.120.22.24</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
      <category>CISA KEV</category>
    </item>
    <item>
      <title>[IPV4/CRIT] 142.11.200.190</title>
      <link>https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html</link>
      <description>&lt;p&gt;&lt;strong&gt;IPV4:&lt;/strong&gt; &lt;code&gt;142.11.200.190&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News, CISA KEV&lt;/p&gt;&lt;p&gt;Context: ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:ipv4:142.11.200.190</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
      <category>CISA KEV</category>
    </item>
    <item>
      <title>[IPV4/CRIT] 142.11.200.189</title>
      <link>https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html</link>
      <description>&lt;p&gt;&lt;strong&gt;IPV4:&lt;/strong&gt; &lt;code&gt;142.11.200.189&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News, CISA KEV&lt;/p&gt;&lt;p&gt;Context: ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:ipv4:142.11.200.189</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
      <category>CISA KEV</category>
    </item>
    <item>
      <title>[IPV4/CRIT] 142.11.200.188</title>
      <link>https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html</link>
      <description>&lt;p&gt;&lt;strong&gt;IPV4:&lt;/strong&gt; &lt;code&gt;142.11.200.188&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News, CISA KEV&lt;/p&gt;&lt;p&gt;Context: ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:ipv4:142.11.200.188</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
      <category>CISA KEV</category>
    </item>
    <item>
      <title>[IPV4/CRIT] 142.11.200.187</title>
      <link>https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html</link>
      <description>&lt;p&gt;&lt;strong&gt;IPV4:&lt;/strong&gt; &lt;code&gt;142.11.200.187&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News, CISA KEV&lt;/p&gt;&lt;p&gt;Context: ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:ipv4:142.11.200.187</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
      <category>CISA KEV</category>
    </item>
    <item>
      <title>[IPV4/CRIT] 142.11.200.186</title>
      <link>https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html</link>
      <description>&lt;p&gt;&lt;strong&gt;IPV4:&lt;/strong&gt; &lt;code&gt;142.11.200.186&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News, CISA KEV&lt;/p&gt;&lt;p&gt;Context: ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:ipv4:142.11.200.186</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
      <category>CISA KEV</category>
    </item>
    <item>
      <title>[IPV4/CRIT] 108.174.202.99</title>
      <link>https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html</link>
      <description>&lt;p&gt;&lt;strong&gt;IPV4:&lt;/strong&gt; &lt;code&gt;108.174.202.99&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News, CISA KEV&lt;/p&gt;&lt;p&gt;Context: ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:ipv4:108.174.202.99</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
      <category>CISA KEV</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] wellnessmedcare.org</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;wellnessmedcare.org&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:wellnessmedcare.org</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] wellnesscaremed.com</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;wellnesscaremed.com&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:wellnesscaremed.com</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/CRIT] webhook.site</title>
      <link>https://www.bleepingcomputer.com/news/security/early-warning-signs-of-supply-chain-attacks-live-in-the-dark-web/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;webhook.site&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;crit&lt;/strong&gt; · First seen: 2026-06-12 · Sources: BleepingComputer, Aikido, StepSecurity, Snyk, CISA KEV&lt;/p&gt;&lt;p&gt;Context: Early Warning Signs of Supply-Chain Attacks Live in the Dark Web&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:webhook.site</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>BleepingComputer</category>
      <category>Aikido</category>
      <category>StepSecurity</category>
      <category>Snyk</category>
      <category>CISA KEV</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] v0tingsystem.github.io</title>
      <link>https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;v0tingsystem.github.io&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:v0tingsystem.github.io</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] trayo.app</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;trayo.app&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:trayo.app</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] technobrains.dev</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;technobrains.dev&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:technobrains.dev</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/MED] tchap.gouv.fr</title>
      <link>https://www.bleepingcomputer.com/news/security/french-govt-says-tchap-breach-affected-over-73-000-accounts/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;tchap.gouv.fr&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-12 · Sources: BleepingComputer&lt;/p&gt;&lt;p&gt;Context: Over 73,000 French govt employees affected in Tchap messenger breach&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:tchap.gouv.fr</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>BleepingComputer</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] t.me/JokerDzV2</title>
      <link>https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;t.me/JokerDzV2&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:t.me/JokerDzV2</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] sumato-soft.org</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;sumato-soft.org&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:sumato-soft.org</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] sniperdz.com</title>
      <link>https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;sniperdz.com&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:sniperdz.com</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] smplfy.in</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;smplfy.in&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:smplfy.in</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/MED] sefaz.services</title>
      <link>https://cybersecuritynews.com/hackers-abuse-legitimate-ninjaone-rmm-software/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;sefaz.services&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:sefaz.services</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/MED] rectalmania.com</title>
      <link>https://cybersecuritynews.com/hackers-abuse-legitimate-ninjaone-rmm-software/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;rectalmania.com&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:rectalmania.com</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/MED] reclameaqui.services</title>
      <link>https://cybersecuritynews.com/hackers-abuse-legitimate-ninjaone-rmm-software/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;reclameaqui.services&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:reclameaqui.services</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] raviral.com/k_fac.php</title>
      <link>https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;raviral.com/k_fac.php&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:raviral.com/k_fac.php</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] raviral.com/host_style/style/js-track/track.js</title>
      <link>https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;raviral.com/host_style/style/js-track/track.js&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:raviral.com/host_style/style/js-track/track.js</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] raviral.com</title>
      <link>https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;raviral.com&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:raviral.com</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/MED] r64.org</title>
      <link>https://cybersecuritynews.com/hackers-abuse-legitimate-ninjaone-rmm-software/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;r64.org&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:r64.org</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] quix.express</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;quix.express&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:quix.express</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] qube.black</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;qube.black&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:qube.black</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] pubg-tournament-official.github.io</title>
      <link>https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;pubg-tournament-official.github.io&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:pubg-tournament-official.github.io</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] pro.riccardomalisano.com</title>
      <link>https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;pro.riccardomalisano.com&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:pro.riccardomalisano.com</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] postino.click</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;postino.click&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:postino.click</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] postify.email</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;postify.email&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:postify.email</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] postfast.eu</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;postfast.eu&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:postfast.eu</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] pheontx.eu</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;pheontx.eu&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:pheontx.eu</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] pastefy.app</title>
      <link>https://cybersecuritynews.com/malicious-npm-campaign-steals-ssh-keys-api-tokens/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;pastefy.app&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News, Lab52&lt;/p&gt;&lt;p&gt;Context: Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:pastefy.app</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
      <category>Lab52</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] olrh4mibs62l6kkuvvjyc5lrercqg5tz543r4lsw3o6mh5qb7g7sneid.onion</title>
      <link>https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;olrh4mibs62l6kkuvvjyc5lrercqg5tz543r4lsw3o6mh5qb7g7sneid.onion&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News, BleepingComputer&lt;/p&gt;&lt;p&gt;Context: Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:olrh4mibs62l6kkuvvjyc5lrercqg5tz543r4lsw3o6mh5qb7g7sneid.onion</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
      <category>BleepingComputer</category>
    </item>
    <item>
      <title>[DOMAIN/MED] matrix.agent.education.tchap.gouv.fr</title>
      <link>https://www.bleepingcomputer.com/news/security/french-govt-says-tchap-breach-affected-over-73-000-accounts/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;matrix.agent.education.tchap.gouv.fr&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-12 · Sources: BleepingComputer&lt;/p&gt;&lt;p&gt;Context: Over 73,000 French govt employees affected in Tchap messenger breach&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:matrix.agent.education.tchap.gouv.fr</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>BleepingComputer</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] mailora.eu</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;mailora.eu&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:mailora.eu</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] longsauce.com</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;longsauce.com&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:longsauce.com</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] lettermail.eu</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;lettermail.eu&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:lettermail.eu</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] lett.email</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;lett.email&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:lett.email</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/MED] lazybearpottery.net</title>
      <link>https://cybersecuritynews.com/hackers-abuse-legitimate-ninjaone-rmm-software/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;lazybearpottery.net&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:lazybearpottery.net</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] instagram-cutequeen57.netlify.app</title>
      <link>https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;instagram-cutequeen57.netlify.app&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:instagram-cutequeen57.netlify.app</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] inboxly.top</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;inboxly.top&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:inboxly.top</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] inboxally.agency</title>
      <link>https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;inboxally.agency&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:inboxally.agency</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
    <item>
      <title>[DOMAIN/MED] hairdb.com</title>
      <link>https://cybersecuritynews.com/hackers-abuse-legitimate-ninjaone-rmm-software/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;hairdb.com&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;med&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:hairdb.com</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] freefoodaid.com</title>
      <link>https://cybersecuritynews.com/fancy-bear-hackers-abuse-edgerouters-and-cloud-services/</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;freefoodaid.com&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: Cyber Security News&lt;/p&gt;&lt;p&gt;Context: Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:freefoodaid.com</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>Cyber Security News</category>
    </item>
    <item>
      <title>[DOMAIN/HIGH] freefirefff.github.io</title>
      <link>https://thehackernews.com/2026/06/interpol-takes-down-sniper-dz-phishing.html</link>
      <description>&lt;p&gt;&lt;strong&gt;DOMAIN:&lt;/strong&gt; &lt;code&gt;freefirefff.github.io&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Severity: &lt;strong&gt;high&lt;/strong&gt; · First seen: 2026-06-12 · Sources: The Hacker News&lt;/p&gt;&lt;p&gt;Context: INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator&lt;/p&gt;</description>
      <guid isPermaLink="false">usecaseintel:domain:freefirefff.github.io</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
      <category>The Hacker News</category>
    </item>
  </channel>
</rss>
