SecurityWeek Jun 26, 2026, 03:23 PM (UTC)
Read
AWS has patched the vulnerability and published its own advisory to inform customers about the potential impact. The post Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories appeared first on SecurityWeek.
SecurityWeek Jun 26, 2026, 03:01 PM (UTC)
Read
Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact. The post More Klue Breach Victims Identified as Hackers Get Hacked appeared first on SecurityWeek.
SecurityWeek Jun 26, 2026, 02:30 PM (UTC)
Read
Other noteworthy stories that might have slipped under the radar: Russia used Cellebrite to hack activist’s phone, Five Eyes issue urgent AI threat warning, macOS Gaslight backdoor, Scattered Spider guilty pleas. The post In Other News: Chinese Mythos-Like AI,…
BleepingComputer Jun 26, 2026, 02:01 PM (UTC)
Read
AI won't replace GRC analysts, but it can eliminate much of the repetitive work they do. Anecdotes walks through building an agent that continuously monitors controls, identifies evidence gaps, and opens remediation tasks. [...]
The Hacker News Jun 26, 2026, 01:57 PM (UTC)
Read
A flaw in the Linux kernel's traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed "pedit COW," is an out-of-bounds write in the packet-editing action (act_pedit) that corrupts shared page-cache me…
The Hacker News Jun 26, 2026, 01:53 PM (UTC)
Read
A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and Amazon Q does the rest. Amazon has patched it. Tracked as CV…
SecurityWeek Jun 26, 2026, 12:37 PM (UTC)
Read
The cybersecurity startup provides threat hunting, proactive detection, and behavioral security analytics. The post Nebulock Raises $25 Million for AI-Native Contextual Security appeared first on SecurityWeek.
The Hacker News Jun 26, 2026, 12:31 PM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) so…
Cybersecurity Ventures Jun 26, 2026, 12:11 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 26, 2026 – Watch the YouTube video The 2026 CISO Report from Cybersecurity Ventures in partnership with Sophos reports that in Jan. 2026, the U.S. Cybersecurity and Inf…
The Hacker News Jun 26, 2026, 11:51 AM (UTC)
Read
DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration for this variant. Tracked as CVE-2026-43503 (CVSS 8.8), it le…
The Hacker News Jun 26, 2026, 11:30 AM (UTC)
Read
AI agents are moving through enterprise environments, inheriting permissions, traversing systems, and executing decisions at machine speed with minimal oversight. The identity infrastructure built to govern human access wasn't designed for autonomous actors, a…
SecurityWeek Jun 26, 2026, 11:28 AM (UTC)
Read
It will provide the tools and channels to report, patch, and disclose open source software vulnerabilities. The post Linux Foundation Unveils New Open Source Security Project Akrites appeared first on SecurityWeek.
The Hacker News Jun 26, 2026, 11:05 AM (UTC)
Read
Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm packages, even as it has propagated to the Go ecosystem. "The latest a…
Infosecurity Magazine Jun 26, 2026, 10:30 AM (UTC)
Read
A China-linked threat group has been targeting critical infrastructure in Southeast Asia with a new custom backdoor called TinyRCT
SecurityWeek Jun 26, 2026, 09:47 AM (UTC)
Read
The decentralized prediction market said hackers targeted some of its users through a compromise of a third-party vendor. The post $3 Million Reportedly Stolen in Polymarket Hack appeared first on SecurityWeek.
The Hacker News Jun 26, 2026, 09:27 AM (UTC)
Read
An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig into front-desk machines, Microsoft says. The company has not attri…
SecurityWeek Jun 26, 2026, 08:55 AM (UTC)
Read
Turla has been using the backdoor against government and military organizations in Ukraine for espionage. The post Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets appeared first on SecurityWeek.
The Hacker News Jun 26, 2026, 08:49 AM (UTC)
Read
Russian authorities used Cellebrite's UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June 2021, three months after Cellebrite said it would stop selling its tools and services to Russia and Belarus. The finding…
SecurityWeek Jun 26, 2026, 08:15 AM (UTC)
Read
CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog. The post First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild appeared first on SecurityWeek.
SecurityWeek Jun 26, 2026, 08:00 AM (UTC)
Read
A major overhaul of the Model Context Protocol shifts critical security responsibilities from the protocol itself to developers and platform operators. The post New Enterprise-Ready MCP Specification Brings New Security Challenges appeared first on SecurityWee…
Infosecurity Magazine Jun 26, 2026, 08:00 AM (UTC)
Read
The UK Cyber Monitoring Centre reviews the Canvas breach affecting 160 UK universities, highlighting data theft risks and financial impacts of cyber incidents
The Hacker News Jun 26, 2026, 07:15 AM (UTC)
Read
The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizations in Ukraine, and entities that have an interest in Itali…
SecurityWeek Jun 26, 2026, 05:13 AM (UTC)
Read
Martin brings experience from Coinbase, Palantir, Amazon, and the U.S. Army to lead Uber's cybersecurity and enterprise security organization. The post Philip Martin Joins Uber as Chief Information Security Officer appeared first on SecurityWeek.
BleepingComputer Jun 25, 2026, 10:53 PM (UTC)
Read
Anthropic appears to be testing Claude Cowork support on mobile, allowing you to manage long-running Claude tasks from your phone. [...]
BleepingComputer Jun 25, 2026, 10:37 PM (UTC)
Read
Authorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts to carry out SIM-swapping attacks. [...]
BleepingComputer Jun 25, 2026, 07:45 PM (UTC)
Read
Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access software. [...]
BleepingComputer Jun 25, 2026, 06:29 PM (UTC)
Read
Microsoft has quietly extended its free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to continue receiving security updates until October 12, 2027. [...]
BleepingComputer Jun 25, 2026, 04:23 PM (UTC)
Read
A newly discovered macOS malware dubbed "Gaslight" is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debugging data within the executable. [...]
BleepingComputer Jun 25, 2026, 03:36 PM (UTC)
Read
A major sports piracy ring linked to the illegal PirloTV streaming platform has been disrupted in an action that targeted 44 domains. [...]
BleepingComputer Jun 25, 2026, 03:00 PM (UTC)
Read
The Bluekit phishing-as-a-service platform continues to evolve with nearly 70 new hostnames identified over the past week and by adding browser-in-the-middle capabilities for improved data theft. [...]
Infosecurity Magazine Jun 25, 2026, 02:15 PM (UTC)
Read
A high-severity flaw in Cisco Catalyst SD-WAN Manager disclosed in early June was exploited as early as March
The Hacker News Jun 25, 2026, 02:12 PM (UTC)
Read
An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code. According to Island, the extension, named Adblock for YouTube (ID: cmedhionkhpnakcndndgjdbohmhepckk), has more than 10 million…
BleepingComputer Jun 25, 2026, 02:01 PM (UTC)
Read
Fraudsters don't attack just one transaction. They target accounts, platforms, and entire ecosystems. IPQS explains the four elevations of fraud prevention and why broader visibility improves fraud detection. [...]
Infosecurity Magazine Jun 25, 2026, 01:00 PM (UTC)
Read
Digital Citizens Alliance report claims that millions of Americans may have unwittingly had IP connections used by cybercriminals
The Hacker News Jun 25, 2026, 12:24 PM (UTC)
Read
It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working, trusted apps doing sketchy crap, browser tricks jumping the fence, and “normal” workflows turning into phishi…
Cybersecurity Ventures Jun 25, 2026, 12:16 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 25, 2026 – Listen to the podcast SlashGear reports that a hacker in Germany was stunned to find he had complete control of a robotic lawnmower. Weighing over 200 pounds…
BleepingComputer Jun 25, 2026, 12:12 PM (UTC)
Read
Account takeover attacks continue to challenge security teams because attackers often operate through legitimate accounts and trusted services. This webinar explores how behavioral AI can help organizations identify compromised accounts faster and automate res…
Infosecurity Magazine Jun 25, 2026, 12:00 PM (UTC)
Read
Cobalt study finds 20-percentage-point drop in number of organizations relying solely on AI automation for testing
Infosecurity Magazine Jun 25, 2026, 11:30 AM (UTC)
Read
New CISA guidance shows federal agencies how to use SASE to move from legacy TIC 2.0 to zero trust
The Hacker News Jun 25, 2026, 11:17 AM (UTC)
Read
Despite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation: What happened? What evidence do we have? How do we know we’re seeing it all, in context? Answering…
Infosecurity Magazine Jun 25, 2026, 11:00 AM (UTC)
Read
macos-xpc-flaw-disable-edr-mdm-standard-user-xm-cyber
Infosecurity Magazine Jun 25, 2026, 10:45 AM (UTC)
Read
Analysis of ransomware incidents by researchers at Black Kite found that attacks have risen by over 50% in the last year, with supply chain attacks increasing
The Hacker News Jun 25, 2026, 09:23 AM (UTC)
Read
A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst's artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of the art…
The Hacker News Jun 25, 2026, 08:54 AM (UTC)
Read
A new, stealthy backdoor named Mistic has been deployed as part of suspected financially motivated attacks aimed at multiple organizations spanning insurance, education, IT, and professional services sectors since April 2026. According to Symantec and Carbon B…
The Hacker News Jun 25, 2026, 05:46 AM (UTC)
Read
An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant. The vulnerability, trac…
BleepingComputer Jun 24, 2026, 11:46 PM (UTC)
Read
Google is rolling out new privacy controls for Search services and Google Play, giving you more control over saved history and personalized recommendations. [...]
BleepingComputer Jun 24, 2026, 09:55 PM (UTC)
Read
A 21-year-old using the alias "Snoopy" was sentenced to 18 months in prison for his role in hacking DraftKings accounts in the November 2022 cyberattack. [...]
BleepingComputer Jun 24, 2026, 09:29 PM (UTC)
Read
New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. [...]
BleepingComputer Jun 24, 2026, 08:58 PM (UTC)
Read
A malicious Microsoft Edge extension dubbed 'Edgecution' has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor. [...]
The Hacker News Jun 24, 2026, 05:19 PM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by Jun…
Infosecurity Magazine Jun 24, 2026, 04:05 PM (UTC)
Read
LayerX tricked AI browsers including ChatGPT Atlas and Comet into bypassing their guardrails
The Hacker News Jun 24, 2026, 03:59 PM (UTC)
Read
A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. "The main common goal was to disrup…
Infosecurity Magazine Jun 24, 2026, 03:25 PM (UTC)
Read
Operation Endgame seized around 50 domains and nearly 200 active IP-based servers associated with the infostealers
BleepingComputer Jun 24, 2026, 02:35 PM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers actively exploiting flaws in Ubiquity UniFi OS and Lantronix serial-to-ethernet servers. [...]
Infosecurity Magazine Jun 24, 2026, 02:00 PM (UTC)
Read
SentinelLabs found a North Korea-linked macOS backdoor using prompt injection on AI triage tools
The Hacker News Jun 24, 2026, 12:48 PM (UTC)
Read
Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains. The "critical exploitable pattern" has been codenamed Cordyceps by Novee Security. The issue can a…
Infosecurity Magazine Jun 24, 2026, 12:45 PM (UTC)
Read
Customers of the affected Japanese email services are “strongly advised” to change their email passwords
Cybersecurity Ventures Jun 24, 2026, 12:23 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 24, 2026 – Read the full story from BreackLock AEV, BAS, and penetration testing each answer a different security question. Adversarial Exposure Validation (AEV) maps w…
Infosecurity Magazine Jun 24, 2026, 12:00 PM (UTC)
Read
An NCC Group report warns state-backed hackers are attempting to hide activity by posing as ransomware groups and deploying commercially available malware
The Hacker News Jun 24, 2026, 11:30 AM (UTC)
Read
We are standing at the end of an era we never thought to mourn: the era of human-speed threats. For years, cybersecurity moved to a rhythm organizations could follow. A researcher found a bug, a CVE was cataloged, a vendor navigated a patch cycle, and weeks or…
Infosecurity Magazine Jun 24, 2026, 09:30 AM (UTC)
Read
New ReliaQuest study reveals the six ways AI is practically being used in attacks today
The Hacker News Jun 24, 2026, 08:55 AM (UTC)
Read
The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by subsidiaries of Cambodia-based corporate conglomerate HuiOne Group, as the Treasury unveiled fresh sanctions against nine individuals and 26 entiti…
Infosecurity Magazine Jun 24, 2026, 08:40 AM (UTC)
Read
Public Accounts Committee (PAC) warns that museums and galleries aren’t getting enough government support on cyber
The Hacker News Jun 24, 2026, 06:50 AM (UTC)
Read
Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, tracked as CVE-2026-2…
The Hacker News Jun 23, 2026, 06:20 PM (UTC)
Read
A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as FortiBleed that has targeted over 430,000 FortiGate firewalls globally. The campaign, active since February…
Krebs on Security Jun 23, 2026, 04:12 PM (UTC)
Read
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members…
The Hacker News Jun 23, 2026, 03:16 PM (UTC)
Read
Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts. Every skill security scanner the firm tested it against marked it…
The Hacker News Jun 23, 2026, 03:16 PM (UTC)
Read
President Trump signed an executive order on June 22 setting hard deadlines for federal agencies to move high-value assets and high-impact systems to post-quantum cryptography. Key establishment must move by December 31, 2030; digital signatures by December 31…
Infosecurity Magazine Jun 23, 2026, 03:00 PM (UTC)
Read
JFrog found an npm package impersonating postcss-selector-parser to drop a multi-stage Windows RAT
The Hacker News Jun 23, 2026, 02:22 PM (UTC)
Read
GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the risky use of the "pull_request_target workflow" trigger to run malicious code with the workflow's full privileges. Effect…
Infosecurity Magazine Jun 23, 2026, 02:15 PM (UTC)
Read
OpenAI expanded Daybreak with a full GPT-5.5-Cyber release to help defenders patch software flaws
Infosecurity Magazine Jun 23, 2026, 02:00 PM (UTC)
Read
All US federal agencies will have to complete their post-quantum cryptography transition by 2031, according to a new Trump Executive Order
Infosecurity Magazine Jun 23, 2026, 01:00 PM (UTC)
Read
Cybercriminals launch fake GTA 6 pre-order sites offering early access for crypto payments
Cybersecurity Ventures Jun 23, 2026, 12:24 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 23, 2026 – Listen to the podcast Richard Seewald, founder and Managing Partner at Evolution Equity Partners, joins Steve Morgan, founder of Cybersecurity Ventures, for…
The Hacker News Jun 23, 2026, 11:30 AM (UTC)
Read
Every weapon begins as an extension of the hand that holds it. The spear lengthened the reach of the arm. The bow sent the point flying without the throw. The rifle placed a man's death a quarter mile beyond his sight, and the aircraft carried that death acros…
Infosecurity Magazine Jun 23, 2026, 09:29 AM (UTC)
Read
Two young British men have pleaded guilty to hacking Transport for London as part of a Scattered Spider plot
The Hacker News Jun 23, 2026, 08:54 AM (UTC)
Read
Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan (RAT). The list of identified packages, is below - aes-decode-runner-pro (145 downloads) postcss-minify-selector (256 do…
Infosecurity Magazine Jun 23, 2026, 08:30 AM (UTC)
Read
The Five Eyes Alliance has published a rare call to action for organizations facing AI threats
The Hacker News Jun 23, 2026, 05:38 AM (UTC)
Read
Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of legitimate Remote Monitoring and Management (RMM) software. Per findings from Kaspersky, the active campaign is targe…
The Hacker News Jun 23, 2026, 03:56 AM (UTC)
Read
OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative the artificial intelligence (AI) company announced last month. Calling GPT‑5.5‑Cyber its "strongest model yet for findin…
The Hacker News Jun 22, 2026, 06:00 PM (UTC)
Read
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. "Attackers compromised the vendor's build and distribution pipeline,…
The Hacker News Jun 22, 2026, 04:29 PM (UTC)
Read
A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy. The bug traces to a 1997 FTP-parsing change and is…
The Hacker News Jun 22, 2026, 04:13 PM (UTC)
Read
Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily read artificial intelligence (AI) conversions from other cu…
Infosecurity Magazine Jun 22, 2026, 03:00 PM (UTC)
Read
ESET details GentleKiller, the EDR-killer framework the Gentlemen ransomware gang gives affiliates
Infosecurity Magazine Jun 22, 2026, 02:00 PM (UTC)
Read
Apple BootROM exploit exposes unpatchable USB flaw on A12 and A13 devices
The Hacker News Jun 22, 2026, 01:20 PM (UTC)
Read
Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER. According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting poi…
The Hacker News Jun 22, 2026, 12:45 PM (UTC)
Read
Google has set September 30, 2026, as the day it begins enforcing Android developer verification in the first four countries, and the major device-maker app stores are in from the start. On that date, certified Android phones in Brazil, Indonesia, Singapore, a…
Cybersecurity Ventures Jun 22, 2026, 12:19 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 22, 2026 – Visit MidnightInTheWarRoom.com Cybersecurity Ventures predicted that cybercrime would cost the world $10.5 trillion in 2025, according to a post on Public Se…
The Hacker News Jun 22, 2026, 11:58 AM (UTC)
Read
Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for - how attackers are circumventing AI security programs by using legacy infrastructure to hijack AI agents. AI ad…
Infosecurity Magazine Jun 22, 2026, 11:30 AM (UTC)
Read
North Korean threat actor Sapphire Sleet has been linked to a supply chain attack targeting Mastra, according to Microsoft security researchers
The Hacker News Jun 22, 2026, 10:55 AM (UTC)
Read
It’s Monday again. This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control. The annoying part is how little of…
Infosecurity Magazine Jun 22, 2026, 10:15 AM (UTC)
Read
At least four cybersecurity firms confirmed they have been affected by a breach of business intelligence platform Klue via Salesforce integration
Infosecurity Magazine Jun 22, 2026, 09:20 AM (UTC)
Read
The UK’s data protection regulator the information commissioner has resigned after his position became “untenable”
The Hacker News Jun 22, 2026, 09:11 AM (UTC)
Read
Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets. The Federal Court released a public version of the ruling on June 15. It is the first time…
Infosecurity Magazine Jun 22, 2026, 08:30 AM (UTC)
Read
The NCSC has released guidance for Fortinet customers impacted by the FortiBleed threat campaign
The Hacker News Jun 22, 2026, 06:57 AM (UTC)
Read
A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin's XLab calls it AryStinger and counts at least 4,300 infected routers, a total it says is s…
The Hacker News Jun 22, 2026, 06:06 AM (UTC)
Read
A new report from INTERPOL has revealed a "dramatic increase" in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration, new technologies, organized criminal networks, and a disparity in cybersecurity maturity. According…
The Hacker News Jun 20, 2026, 09:56 AM (UTC)
Read
Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw th…
The Hacker News Jun 19, 2026, 06:37 PM (UTC)
Read
Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips. That code is burned into the silicon at manufacture. No software update can rea…
The Hacker News Jun 19, 2026, 06:33 PM (UTC)
Read
The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor. This mature por…
The Hacker News Jun 19, 2026, 03:30 PM (UTC)
Read
Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent to load an attacker's web page, and that page's JavaScript can reach a privileged local ser…
The Hacker News Jun 19, 2026, 03:07 PM (UTC)
Read
Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites. "With these actions we deprive cybercri…
The Hacker News Jun 19, 2026, 02:00 PM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps to secure against ongoing malicious activity aimed at thousands of internet-accessible devices. The sweeping campaign,…
The Hacker News Jun 19, 2026, 11:58 AM (UTC)
Read
Introduction The average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset data. But often, these tools are working in siloes, generating (overlapping) alerts and data. And yet, breach dwell ti…
Infosecurity Magazine Jun 19, 2026, 11:00 AM (UTC)
Read
Working with frontier AI models, this new platform aims to help discovering, prioritizing, validating and remediating code vulnerabilities
The Hacker News Jun 19, 2026, 10:30 AM (UTC)
Read
The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security teams responded with usage policies, domain blocks, and data loss prevention rules. That response made sense at the time.…
Infosecurity Magazine Jun 19, 2026, 10:15 AM (UTC)
Read
SocGholish malware has been removed from 15,000 sites associated with Evil Corp hackers
The Hacker News Jun 19, 2026, 09:03 AM (UTC)
Read
Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026. To that end, organizations will be unable to connect to Salesf…
Infosecurity Magazine Jun 19, 2026, 09:00 AM (UTC)
Read
Half of cybersecurity leaders lack confidence in detecting threats on Slack, Teams and other non-email platforms, despite growing attacker focus
The Hacker News Jun 19, 2026, 06:36 AM (UTC)
Read
Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users. The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorrect autho…
Krebs on Security Jun 18, 2026, 05:37 PM (UTC)
Read
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple securi…
The Hacker News Jun 18, 2026, 05:32 PM (UTC)
Read
F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems. The vulnerabilities are listed below - CVE-2026-42530 (CVSS v4 score: 9.2) - A use-after-free vu…
Infosecurity Magazine Jun 18, 2026, 03:00 PM (UTC)
Read
A Rust crypto clipper hides behind fake GitHub stars and AI-narrated YouTube videos
Infosecurity Magazine Jun 18, 2026, 02:45 PM (UTC)
Read
Hospital insider escapes criminal prosecution after attempting to sell royal’s medical records
Infosecurity Magazine Jun 18, 2026, 12:30 PM (UTC)
Read
Analysis of chatter on underground forums by Sophos finds that hackers fear AI could take work away from them
Infosecurity Magazine Jun 18, 2026, 11:30 AM (UTC)
Read
CloudSEK maps Operation Escaneo, a campaign hitting Latin American infrastructure via perimeter bugs
Infosecurity Magazine Jun 18, 2026, 09:10 AM (UTC)
Read
Richard Horne, the NCSC CEO, said three-quarters of cyber-attacks targeting UK critical infrastructure came from nation-state actors
Infosecurity Magazine Jun 18, 2026, 08:30 AM (UTC)
Read
Interpol claims cybercrime accounts for third of crime in over half of Asia and South Pacific countries
Infosecurity Magazine Jun 17, 2026, 03:00 PM (UTC)
Read
Nisos infiltrated a North Korean IT-worker fraud cell running on AI interviews and a US laptop farm
Infosecurity Magazine Jun 17, 2026, 02:00 PM (UTC)
Read
GitBait phishing kit abuses GitHub Pages and the SheetBest API to steal Mexican banking credentials
Cybersecurity Ventures Jun 17, 2026, 01:20 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 17, 2026 – Watch the YouTube video “I started my cybersecurity ‘career’ as one of the earlier virus developers in the world,” Nir Zuk, co-founder of Palo Alto Networks,…
Infosecurity Magazine Jun 17, 2026, 01:15 PM (UTC)
Read
The rise of AI-assistants and applications in the enterprise has seen a 93% increase in employees attempting to upload sensitive data, bringing security challenges
Infosecurity Magazine Jun 17, 2026, 12:30 PM (UTC)
Read
Filigran survey at Infosecurity Europe 2026 reveals AI-powered attacks as the top concern, with false positives, alert fatigue and manual processes draining security teams
Infosecurity Magazine Jun 17, 2026, 09:45 AM (UTC)
Read
Ukraine has been added to the EU Cybersecurity Reserve, which provides incident response services against large-scale incidents
Infosecurity Magazine Jun 17, 2026, 09:10 AM (UTC)
Read
Aikido Security has discovered at least 15 IDE plugins on the JetBrains Marketplace
Infosecurity Magazine Jun 17, 2026, 08:45 AM (UTC)
Read
SANS Institute study finds few SOCs have built AI into defined workflows, despite widespread adoption
Infosecurity Magazine Jun 16, 2026, 02:30 PM (UTC)
Read
China-linked SprySOCKS backdoor gains stealthy Windows variants and 30-plus C2 commands
Infosecurity Magazine Jun 16, 2026, 01:15 PM (UTC)
Read
Rokarolla Android trojan steals banking logins and spies on victims while blocking fraud alerts
Cybersecurity Ventures Jun 16, 2026, 12:19 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 16, 2026 – Read the full story from LinkedIn The 2026 CISO Report by Cybersecurity Ventures, published in partnership with Sophos, lays out numbers that explain why mid…
Infosecurity Magazine Jun 16, 2026, 12:00 PM (UTC)
Read
ISSA study finds most security professionals feel challenged by colleagues’ involvement in cyber
Infosecurity Magazine Jun 16, 2026, 11:30 AM (UTC)
Read
Command and control traffic exploited a Teams visitor token to make malicious activity look legitimate to defenders
Infosecurity Magazine Jun 16, 2026, 11:00 AM (UTC)
Read
Athena is a new an industry coalition to fix the vulnerabilities frontier AI models find before attackers can exploit them
Infosecurity Magazine Jun 16, 2026, 08:15 AM (UTC)
Read
The FBI claims couriers are being used to circumvent bank transfers in crypto investment schemes
Infosecurity Magazine Jun 15, 2026, 05:00 PM (UTC)
Read
Tampered OptinMonster and sister plugins plant hidden backdoors on 1.2 million WordPress sites
Infosecurity Magazine Jun 15, 2026, 04:15 PM (UTC)
Read
How the Anubis ransomware group stole and leaked an Italian Adriatic port authority's data
Cybersecurity Ventures Jun 15, 2026, 01:14 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 15, 2026 – Read the full story from CMBlog By harnessing AI, cybercriminals are developing increasingly sophisticated techniques to commit their crimes, posing a growin…
Infosecurity Magazine Jun 15, 2026, 10:30 AM (UTC)
Read
Access to two Anthropic large language models, Mythos 5 and Fable 5, has effectively been banned to any non-US nationals by the Trump administration
Infosecurity Magazine Jun 15, 2026, 09:30 AM (UTC)
Read
Government departments find hundreds of vulnerabilities after testing frontier models
Infosecurity Magazine Jun 15, 2026, 09:00 AM (UTC)
Read
The Office of the Maine Attorney General has suspended its breach reporting portal