Intelligence Feed

Curated cybersecurity reporting and advisories. Headlines link to original sources.

Items
141
Last update
Jun 21, 2026, 11:43 PM (UTC)
Showing
0 results
The Hacker News Jun 20, 2026, 09:56 AM (UTC)
Read

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw th…

BleepingComputer Jun 19, 2026, 10:31 PM (UTC)
Read

Klue OAuth breach victim list grows as Icarus hackers claim attack

Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments, as the new "Icarus" extortion group publicly claims the attack. [...]

BleepingComputer Jun 19, 2026, 12:12 PM (UTC)
Read

Webinar: How attackers bypass MFA and how defenders can respond

Modern phishing attacks, including Device Code phishing, can undermine MFA protections and grant attackers access to corporate accounts without stealing passwords. This webinar explores how behavioral AI can help security teams detect compromised accounts fast…

The Hacker News Jun 19, 2026, 10:30 AM (UTC)
Read

Forget Data Leakage: Shadow AI's Real Threat Is Access Control

The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security teams responded with usage policies, domain blocks, and data loss prevention rules. That response made sense at the time.…

SecurityWeek Jun 19, 2026, 07:22 AM (UTC)
Read

Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC

WideField will accelerate Agentic SOC capabilities by expanding the lens on threat investigation to include identity, credentials, sessions, and blast radius. The post Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC appeared first on Security…

Krebs on Security Jun 18, 2026, 05:37 PM (UTC)
Read

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple securi…

The Hacker News Jun 18, 2026, 01:58 PM (UTC)
Read

The Scripts on Your Checkout Page Are Now a PCI DSS Problem

An independent PCI assessor tested Reflectiz against the new PCI DSS rules. Here is the verdict: See the full QSA assessment here → When a customer types their card number into your checkout, their browser is running far more than your code. Analytics tags, a…

Cybersecurity Ventures Jun 17, 2026, 01:20 PM (UTC)
Read

Nir Zuk: Backstory of a Cybersecurity Legend

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 17, 2026 – Watch the YouTube video “I started my cybersecurity ‘career’ as one of the earlier virus developers in the world,” Nir Zuk, co-founder of Palo Alto Networks,…

The Hacker News Jun 17, 2026, 10:30 AM (UTC)
Read

The Top 10 Attack Surface Exposures in 2026

Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerability does drop — like MongoBleed earlier this year, which let attackers pull credentials and session tok…

The Hacker News Jun 17, 2026, 07:38 AM (UTC)
Read

145 Mastra npm Packages Compromised via Hijacked Contributor Account

As many as 145 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack co…

Cybersecurity Ventures Jun 16, 2026, 12:19 PM (UTC)
Read

Virtual Or Full-Time CISO: ROI Calculator On Security Leadership

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 16, 2026 – Read the full story from LinkedIn The 2026 CISO Report by Cybersecurity Ventures, published in partnership with Sophos, lays out numbers that explain why mid…

The Hacker News Jun 16, 2026, 08:14 AM (UTC)
Read

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver a new malware called NarwhalRAT. "The attack email contained a messa…

The Hacker News Jun 15, 2026, 11:30 AM (UTC)
Read

The Onboarding Password Mistake That Creates Unnecessary Risk

Employee onboarding is a busy time for IT teams. New starters need devices, accounts, access permissions, and passwords, all delivered within a tight timeframe. That usually means sharing a temporary "first-day" password so employees can access systems for the…

Cybersecurity Ventures Jun 12, 2026, 12:34 PM (UTC)
Read

Code Girls: The Secret Heroes Of World War II

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 12, 2026 – Watch the YouTube Short During World War II, some of America’s most powerful weapons weren’t bombs or guns. They were women sitting in secret rooms breaking…

Cybersecurity Ventures Jun 11, 2026, 01:08 PM (UTC)
Read

Parents: How To Help Your College Students Avoid Roommate Scams

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 11, 2026 – Listen to the podcast Media outlets and cybersecurity industry experts have been warning for the past several years about a persistent scheme that targets co…

Krebs on Security Jun 10, 2026, 02:03 PM (UTC)
Read

Who Runs the Ransomware Group ‘The Gentlemen?’

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by…

Cybersecurity Ventures Jun 10, 2026, 01:12 PM (UTC)
Read

New Book: Cybersecurity for Accounting and Business

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 10, 2026 – Read the book Cybersecurity for Accounting and Business, a new book co-authored by Nancy Bagranoff, Professor at University of Richmond, and Scott R. Boss, A…

Krebs on Security Jun 9, 2026, 10:07 PM (UTC)
Read

A Record-Breaking Patch Tuesday for June 2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's…

Cybersecurity Ventures Jun 9, 2026, 12:41 PM (UTC)
Read

2026 CISO Compensation Data: Salaries, Bonuses, Equity

This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 9, 2026 – Read the report The 2026 CISO Report from Cybersecurity Ventures in partnership with Sophos examines the latest compensation data for CISOs. According to Glas…

Page 1 of 1 0 results