BleepingComputer Jun 25, 2026, 03:00 PM (UTC)
Read
The Bluekit phishing-as-a-service platform continues to evolve with nearly 70 new hostnames identified over the past week and by adding browser-in-the-middle capabilities for improved data theft. [...]
Infosecurity Magazine Jun 25, 2026, 02:15 PM (UTC)
Read
A high-severity flaw in Cisco Catalyst SD-WAN Manager disclosed in early June was exploited as early as March
The Hacker News Jun 25, 2026, 02:12 PM (UTC)
Read
An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code. According to Island, the extension, named Adblock for YouTube (ID: cmedhionkhpnakcndndgjdbohmhepckk), has more than 10 million…
BleepingComputer Jun 25, 2026, 02:01 PM (UTC)
Read
Fraudsters don't attack just one transaction. They target accounts, platforms, and entire ecosystems. IPQS explains the four elevations of fraud prevention and why broader visibility improves fraud detection. [...]
Infosecurity Magazine Jun 25, 2026, 01:00 PM (UTC)
Read
Digital Citizens Alliance report claims that millions of Americans may have unwittingly had IP connections used by cybercriminals
SecurityWeek Jun 25, 2026, 12:39 PM (UTC)
Read
The startup’s platform functions as a secure control layer, aiming to secure AI tools across enterprises. The post Runlayer Raises $30 Million in Series A Funding appeared first on SecurityWeek.
The Hacker News Jun 25, 2026, 12:24 PM (UTC)
Read
It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working, trusted apps doing sketchy crap, browser tricks jumping the fence, and “normal” workflows turning into phishi…
Cybersecurity Ventures Jun 25, 2026, 12:16 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 25, 2026 – Listen to the podcast SlashGear reports that a hacker in Germany was stunned to find he had complete control of a robotic lawnmower. Weighing over 200 pounds…
BleepingComputer Jun 25, 2026, 12:12 PM (UTC)
Read
Account takeover attacks continue to challenge security teams because attackers often operate through legitimate accounts and trusted services. This webinar explores how behavioral AI can help organizations identify compromised accounts faster and automate res…
SecurityWeek Jun 25, 2026, 12:07 PM (UTC)
Read
Mandiant has helped the California water utility investigate the cyberattack launched by Iranian hacker group Handala. The post Cal Water Finds No Evidence of OT Activity After Hackers Claimed They Could Disrupt Water Supply appeared first on SecurityWeek.
Infosecurity Magazine Jun 25, 2026, 12:00 PM (UTC)
Read
Cobalt study finds 20-percentage-point drop in number of organizations relying solely on AI automation for testing
Infosecurity Magazine Jun 25, 2026, 11:30 AM (UTC)
Read
New CISA guidance shows federal agencies how to use SASE to move from legacy TIC 2.0 to zero trust
SecurityWeek Jun 25, 2026, 11:23 AM (UTC)
Read
The exploited flaw, CVE-2025-67038, is one of the vulnerabilities disclosed in April as part of the BRIDGE:BREAK research project. The post Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning appeared first on SecurityWeek.
The Hacker News Jun 25, 2026, 11:17 AM (UTC)
Read
Despite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation: What happened? What evidence do we have? How do we know we’re seeing it all, in context? Answering…
SecurityWeek Jun 25, 2026, 11:10 AM (UTC)
Read
The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects. The post GitLab Patches Code Execution, Information Disclosure Vulnerabilities appeared first on SecurityWeek.
Infosecurity Magazine Jun 25, 2026, 11:00 AM (UTC)
Read
macos-xpc-flaw-disable-edr-mdm-standard-user-xm-cyber
Infosecurity Magazine Jun 25, 2026, 10:45 AM (UTC)
Read
Analysis of ransomware incidents by researchers at Black Kite found that attacks have risen by over 50% in the last year, with supply chain attacks increasing
SecurityWeek Jun 25, 2026, 09:25 AM (UTC)
Read
The latest version of the open source data transfer tool resolves 18 medium and low-severity vulnerabilities. The post 25-Year-Old Vulnerability Patched in Curl appeared first on SecurityWeek.
The Hacker News Jun 25, 2026, 09:23 AM (UTC)
Read
A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst's artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of the art…
The Hacker News Jun 25, 2026, 08:54 AM (UTC)
Read
A new, stealthy backdoor named Mistic has been deployed as part of suspected financially motivated attacks aimed at multiple organizations spanning insurance, education, IT, and professional services sectors since April 2026. According to Symantec and Carbon B…
SecurityWeek Jun 25, 2026, 08:29 AM (UTC)
Read
The guidance aims to establish product cybersecurity requirements for IoT devices integrated into federal agencies’ networks. The post NIST Opens Updated IoT Security Guidance to Public Review appeared first on SecurityWeek.
SecurityWeek Jun 25, 2026, 07:56 AM (UTC)
Read
More than half of the bugs are use-after-free defects, which can potentially lead to remote code execution. The post Chrome 149 Update Resolves 18 Severe Vulnerabilities appeared first on SecurityWeek.
SecurityWeek Jun 25, 2026, 06:08 AM (UTC)
Read
CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching. The post Cisco SD-WAN Zero-Day Exploited Months Before Patching appeared first on SecurityWeek.
The Hacker News Jun 25, 2026, 05:46 AM (UTC)
Read
An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant. The vulnerability, trac…
BleepingComputer Jun 24, 2026, 11:46 PM (UTC)
Read
Google is rolling out new privacy controls for Search services and Google Play, giving you more control over saved history and personalized recommendations. [...]
BleepingComputer Jun 24, 2026, 09:55 PM (UTC)
Read
A 21-year-old using the alias "Snoopy" was sentenced to 18 months in prison for his role in hacking DraftKings accounts in the November 2022 cyberattack. [...]
BleepingComputer Jun 24, 2026, 09:29 PM (UTC)
Read
New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. [...]
BleepingComputer Jun 24, 2026, 08:58 PM (UTC)
Read
A malicious Microsoft Edge extension dubbed 'Edgecution' has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor. [...]
SecurityWeek Jun 24, 2026, 05:37 PM (UTC)
Read
From hidden content injections to cognitive state poisoning, attackers are turning trusted data sources into traps for autonomous AI. The post When Information Becomes the Attack Surface – Understanding AI Agent Traps appeared first on SecurityWeek.
The Hacker News Jun 24, 2026, 05:19 PM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by Jun…
Infosecurity Magazine Jun 24, 2026, 04:05 PM (UTC)
Read
LayerX tricked AI browsers including ChatGPT Atlas and Comet into bypassing their guardrails
The Hacker News Jun 24, 2026, 03:59 PM (UTC)
Read
A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. "The main common goal was to disrup…
Infosecurity Magazine Jun 24, 2026, 03:25 PM (UTC)
Read
Operation Endgame seized around 50 domains and nearly 200 active IP-based servers associated with the infostealers
SecurityWeek Jun 24, 2026, 03:02 PM (UTC)
Read
Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies. The post Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware appeared first on SecurityWeek.
BleepingComputer Jun 24, 2026, 02:35 PM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers actively exploiting flaws in Ubiquity UniFi OS and Lantronix serial-to-ethernet servers. [...]
BleepingComputer Jun 24, 2026, 02:35 PM (UTC)
Read
Microsoft, Europol, and international partners have disrupted infrastructure used by the Amadey and StealC malware operations as part of Operation Endgame, which targets cybercriminal services and ransomware gangs. [...]
BleepingComputer Jun 24, 2026, 02:02 PM (UTC)
Read
Service desks have become a favored target for attackers seeking password resets, MFA changes, and access to corporate accounts. Specops Software breaks down how service desk social engineering attacks work and how organizations can defend against them. [...]
Infosecurity Magazine Jun 24, 2026, 02:00 PM (UTC)
Read
SentinelLabs found a North Korea-linked macOS backdoor using prompt injection on AI triage tools
The Hacker News Jun 24, 2026, 12:48 PM (UTC)
Read
Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains. The "critical exploitable pattern" has been codenamed Cordyceps by Novee Security. The issue can a…
Infosecurity Magazine Jun 24, 2026, 12:45 PM (UTC)
Read
Customers of the affected Japanese email services are “strongly advised” to change their email passwords
Cybersecurity Ventures Jun 24, 2026, 12:23 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 24, 2026 – Read the full story from BreackLock AEV, BAS, and penetration testing each answer a different security question. Adversarial Exposure Validation (AEV) maps w…
Infosecurity Magazine Jun 24, 2026, 12:00 PM (UTC)
Read
An NCC Group report warns state-backed hackers are attempting to hide activity by posing as ransomware groups and deploying commercially available malware
The Hacker News Jun 24, 2026, 11:30 AM (UTC)
Read
We are standing at the end of an era we never thought to mourn: the era of human-speed threats. For years, cybersecurity moved to a rhythm organizations could follow. A researcher found a bug, a CVE was cataloged, a vendor navigated a patch cycle, and weeks or…
BleepingComputer Jun 24, 2026, 10:41 AM (UTC)
Read
A new backdoor dubbed Mistic has been observed in financially motivated attacks targeting organizations in the insurance, education, IT, and professional services sectors. [...]
Infosecurity Magazine Jun 24, 2026, 09:30 AM (UTC)
Read
New ReliaQuest study reveals the six ways AI is practically being used in attacks today
The Hacker News Jun 24, 2026, 08:55 AM (UTC)
Read
The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by subsidiaries of Cambodia-based corporate conglomerate HuiOne Group, as the Treasury unveiled fresh sanctions against nine individuals and 26 entiti…
Infosecurity Magazine Jun 24, 2026, 08:40 AM (UTC)
Read
Public Accounts Committee (PAC) warns that museums and galleries aren’t getting enough government support on cyber
The Hacker News Jun 24, 2026, 06:50 AM (UTC)
Read
Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, tracked as CVE-2026-2…
BleepingComputer Jun 23, 2026, 09:48 PM (UTC)
Read
A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks. [...]
BleepingComputer Jun 23, 2026, 09:06 PM (UTC)
Read
Tata Electronics has confirmed in a statement to BleepingComputer that it was the target of a cyberattack that impacted parts of its IT infrastructure. [...]
BleepingComputer Jun 23, 2026, 08:22 PM (UTC)
Read
Microsoft has released the KB5095093 preview cumulative update for Windows 11 24H2 and 25H2, which fixes numerous bugs and begins rolling out new features, including the new Point-in-Time restore feature. [...]
BleepingComputer Jun 23, 2026, 07:59 PM (UTC)
Read
Healthcare technology company Xsolis says that sensitive data belonging to nearly 1.4 million individuals was compromised in a phishing attack that gave attackers access to its network. [...]
The Hacker News Jun 23, 2026, 06:20 PM (UTC)
Read
A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as FortiBleed that has targeted over 430,000 FortiGate firewalls globally. The campaign, active since February…
Krebs on Security Jun 23, 2026, 04:12 PM (UTC)
Read
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members…
The Hacker News Jun 23, 2026, 03:16 PM (UTC)
Read
Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts. Every skill security scanner the firm tested it against marked it…
The Hacker News Jun 23, 2026, 03:16 PM (UTC)
Read
President Trump signed an executive order on June 22 setting hard deadlines for federal agencies to move high-value assets and high-impact systems to post-quantum cryptography. Key establishment must move by December 31, 2030; digital signatures by December 31…
Infosecurity Magazine Jun 23, 2026, 03:00 PM (UTC)
Read
JFrog found an npm package impersonating postcss-selector-parser to drop a multi-stage Windows RAT
The Hacker News Jun 23, 2026, 02:22 PM (UTC)
Read
GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the risky use of the "pull_request_target workflow" trigger to run malicious code with the workflow's full privileges. Effect…
Infosecurity Magazine Jun 23, 2026, 02:15 PM (UTC)
Read
OpenAI expanded Daybreak with a full GPT-5.5-Cyber release to help defenders patch software flaws
Infosecurity Magazine Jun 23, 2026, 02:00 PM (UTC)
Read
All US federal agencies will have to complete their post-quantum cryptography transition by 2031, according to a new Trump Executive Order
Infosecurity Magazine Jun 23, 2026, 01:00 PM (UTC)
Read
Cybercriminals launch fake GTA 6 pre-order sites offering early access for crypto payments
Cybersecurity Ventures Jun 23, 2026, 12:24 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 23, 2026 – Listen to the podcast Richard Seewald, founder and Managing Partner at Evolution Equity Partners, joins Steve Morgan, founder of Cybersecurity Ventures, for…
The Hacker News Jun 23, 2026, 11:30 AM (UTC)
Read
Every weapon begins as an extension of the hand that holds it. The spear lengthened the reach of the arm. The bow sent the point flying without the throw. The rifle placed a man's death a quarter mile beyond his sight, and the aircraft carried that death acros…
Infosecurity Magazine Jun 23, 2026, 09:29 AM (UTC)
Read
Two young British men have pleaded guilty to hacking Transport for London as part of a Scattered Spider plot
The Hacker News Jun 23, 2026, 08:54 AM (UTC)
Read
Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan (RAT). The list of identified packages, is below - aes-decode-runner-pro (145 downloads) postcss-minify-selector (256 do…
Infosecurity Magazine Jun 23, 2026, 08:30 AM (UTC)
Read
The Five Eyes Alliance has published a rare call to action for organizations facing AI threats
The Hacker News Jun 23, 2026, 05:38 AM (UTC)
Read
Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of legitimate Remote Monitoring and Management (RMM) software. Per findings from Kaspersky, the active campaign is targe…
The Hacker News Jun 23, 2026, 03:56 AM (UTC)
Read
OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative the artificial intelligence (AI) company announced last month. Calling GPT‑5.5‑Cyber its "strongest model yet for findin…
The Hacker News Jun 22, 2026, 06:00 PM (UTC)
Read
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. "Attackers compromised the vendor's build and distribution pipeline,…
The Hacker News Jun 22, 2026, 04:29 PM (UTC)
Read
A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy. The bug traces to a 1997 FTP-parsing change and is…
The Hacker News Jun 22, 2026, 04:13 PM (UTC)
Read
Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily read artificial intelligence (AI) conversions from other cu…
Infosecurity Magazine Jun 22, 2026, 03:00 PM (UTC)
Read
ESET details GentleKiller, the EDR-killer framework the Gentlemen ransomware gang gives affiliates
Infosecurity Magazine Jun 22, 2026, 02:00 PM (UTC)
Read
Apple BootROM exploit exposes unpatchable USB flaw on A12 and A13 devices
The Hacker News Jun 22, 2026, 01:20 PM (UTC)
Read
Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER. According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting poi…
The Hacker News Jun 22, 2026, 12:45 PM (UTC)
Read
Google has set September 30, 2026, as the day it begins enforcing Android developer verification in the first four countries, and the major device-maker app stores are in from the start. On that date, certified Android phones in Brazil, Indonesia, Singapore, a…
Cybersecurity Ventures Jun 22, 2026, 12:19 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 22, 2026 – Visit MidnightInTheWarRoom.com Cybersecurity Ventures predicted that cybercrime would cost the world $10.5 trillion in 2025, according to a post on Public Se…
The Hacker News Jun 22, 2026, 11:58 AM (UTC)
Read
Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for - how attackers are circumventing AI security programs by using legacy infrastructure to hijack AI agents. AI ad…
Infosecurity Magazine Jun 22, 2026, 11:30 AM (UTC)
Read
North Korean threat actor Sapphire Sleet has been linked to a supply chain attack targeting Mastra, according to Microsoft security researchers
The Hacker News Jun 22, 2026, 10:55 AM (UTC)
Read
It’s Monday again. This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control. The annoying part is how little of…
Infosecurity Magazine Jun 22, 2026, 10:15 AM (UTC)
Read
At least four cybersecurity firms confirmed they have been affected by a breach of business intelligence platform Klue via Salesforce integration
Infosecurity Magazine Jun 22, 2026, 09:20 AM (UTC)
Read
The UK’s data protection regulator the information commissioner has resigned after his position became “untenable”
The Hacker News Jun 22, 2026, 09:11 AM (UTC)
Read
Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets. The Federal Court released a public version of the ruling on June 15. It is the first time…
Infosecurity Magazine Jun 22, 2026, 08:30 AM (UTC)
Read
The NCSC has released guidance for Fortinet customers impacted by the FortiBleed threat campaign
The Hacker News Jun 22, 2026, 06:57 AM (UTC)
Read
A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin's XLab calls it AryStinger and counts at least 4,300 infected routers, a total it says is s…
The Hacker News Jun 22, 2026, 06:06 AM (UTC)
Read
A new report from INTERPOL has revealed a "dramatic increase" in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration, new technologies, organized criminal networks, and a disparity in cybersecurity maturity. According…
The Hacker News Jun 20, 2026, 09:56 AM (UTC)
Read
Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw th…
The Hacker News Jun 19, 2026, 06:37 PM (UTC)
Read
Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips. That code is burned into the silicon at manufacture. No software update can rea…
The Hacker News Jun 19, 2026, 06:33 PM (UTC)
Read
The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor. This mature por…
The Hacker News Jun 19, 2026, 03:30 PM (UTC)
Read
Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent to load an attacker's web page, and that page's JavaScript can reach a privileged local ser…
The Hacker News Jun 19, 2026, 03:07 PM (UTC)
Read
Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites. "With these actions we deprive cybercri…
The Hacker News Jun 19, 2026, 02:00 PM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps to secure against ongoing malicious activity aimed at thousands of internet-accessible devices. The sweeping campaign,…
The Hacker News Jun 19, 2026, 11:58 AM (UTC)
Read
Introduction The average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset data. But often, these tools are working in siloes, generating (overlapping) alerts and data. And yet, breach dwell ti…
Infosecurity Magazine Jun 19, 2026, 11:00 AM (UTC)
Read
Working with frontier AI models, this new platform aims to help discovering, prioritizing, validating and remediating code vulnerabilities
The Hacker News Jun 19, 2026, 10:30 AM (UTC)
Read
The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security teams responded with usage policies, domain blocks, and data loss prevention rules. That response made sense at the time.…
Infosecurity Magazine Jun 19, 2026, 10:15 AM (UTC)
Read
SocGholish malware has been removed from 15,000 sites associated with Evil Corp hackers
The Hacker News Jun 19, 2026, 09:03 AM (UTC)
Read
Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026. To that end, organizations will be unable to connect to Salesf…
Infosecurity Magazine Jun 19, 2026, 09:00 AM (UTC)
Read
Half of cybersecurity leaders lack confidence in detecting threats on Slack, Teams and other non-email platforms, despite growing attacker focus
The Hacker News Jun 19, 2026, 06:36 AM (UTC)
Read
Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users. The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorrect autho…
Krebs on Security Jun 18, 2026, 05:37 PM (UTC)
Read
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple securi…
The Hacker News Jun 18, 2026, 05:32 PM (UTC)
Read
F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems. The vulnerabilities are listed below - CVE-2026-42530 (CVSS v4 score: 9.2) - A use-after-free vu…
The Hacker News Jun 18, 2026, 03:33 PM (UTC)
Read
If an autonomous AI agent interacts with your company's core intellectual property today, can your security team instantly name the person who authorized it? For most enterprises, the answer is a simple no. The rush to adopt internal AI tools has left a massiv…
The Hacker News Jun 18, 2026, 03:27 PM (UTC)
Read
The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. Cloud age…
Infosecurity Magazine Jun 18, 2026, 03:00 PM (UTC)
Read
A Rust crypto clipper hides behind fake GitHub stars and AI-narrated YouTube videos
Infosecurity Magazine Jun 18, 2026, 02:45 PM (UTC)
Read
Hospital insider escapes criminal prosecution after attempting to sell royal’s medical records
The Hacker News Jun 18, 2026, 02:30 PM (UTC)
Read
Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign codenamed CryptoBandits that has targeted users since February 2026 with clipboard-intercepting malware with self-spreading capabilities and using the Tor anonymity network to h…
The Hacker News Jun 18, 2026, 02:12 PM (UTC)
Read
Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most prolific cybercrime groups in 2026, claiming no less than 830 victims since August 2023. "The disruption of LockBit and the…
The Hacker News Jun 18, 2026, 01:58 PM (UTC)
Read
An independent PCI assessor tested Reflectiz against the new PCI DSS rules. Here is the verdict: See the full QSA assessment here → When a customer types their card number into your checkout, their browser is running far more than your code. Analytics tags, a…
The Hacker News Jun 18, 2026, 01:30 PM (UTC)
Read
Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure. According to findings f…
Infosecurity Magazine Jun 18, 2026, 12:30 PM (UTC)
Read
Analysis of chatter on underground forums by Sophos finds that hackers fear AI could take work away from them
Infosecurity Magazine Jun 18, 2026, 11:30 AM (UTC)
Read
CloudSEK maps Operation Escaneo, a campaign hitting Latin American infrastructure via perimeter bugs
Infosecurity Magazine Jun 18, 2026, 09:10 AM (UTC)
Read
Richard Horne, the NCSC CEO, said three-quarters of cyber-attacks targeting UK critical infrastructure came from nation-state actors
Infosecurity Magazine Jun 18, 2026, 08:30 AM (UTC)
Read
Interpol claims cybercrime accounts for third of crime in over half of Asia and South Pacific countries
The Hacker News Jun 17, 2026, 06:14 PM (UTC)
Read
An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez, according to new findings from Check Point Research. The threat actor also has at their disposal a dedicated WordPress phis…
The Hacker News Jun 17, 2026, 05:36 PM (UTC)
Read
Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability has now been assigned the CVE identifier CVE-2026-50656 (CVSS score: 7.8), with the tech giant describing it as a priv…
The Hacker News Jun 17, 2026, 04:00 PM (UTC)
Read
A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials. Ordinary stuff, until one move near the end. Before his command-and-control server went dark, he installed OpenSSH and Tails…
Infosecurity Magazine Jun 17, 2026, 03:00 PM (UTC)
Read
Nisos infiltrated a North Korean IT-worker fraud cell running on AI interviews and a US laptop farm
Infosecurity Magazine Jun 17, 2026, 02:00 PM (UTC)
Read
GitBait phishing kit abuses GitHub Pages and the SheetBest API to steal Mexican banking credentials
Cybersecurity Ventures Jun 17, 2026, 01:20 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 17, 2026 – Watch the YouTube video “I started my cybersecurity ‘career’ as one of the earlier virus developers in the world,” Nir Zuk, co-founder of Palo Alto Networks,…
Infosecurity Magazine Jun 17, 2026, 01:15 PM (UTC)
Read
The rise of AI-assistants and applications in the enterprise has seen a 93% increase in employees attempting to upload sensitive data, bringing security challenges
Infosecurity Magazine Jun 17, 2026, 12:30 PM (UTC)
Read
Filigran survey at Infosecurity Europe 2026 reveals AI-powered attacks as the top concern, with false positives, alert fatigue and manual processes draining security teams
Infosecurity Magazine Jun 17, 2026, 09:45 AM (UTC)
Read
Ukraine has been added to the EU Cybersecurity Reserve, which provides incident response services against large-scale incidents
Infosecurity Magazine Jun 17, 2026, 09:10 AM (UTC)
Read
Aikido Security has discovered at least 15 IDE plugins on the JetBrains Marketplace
Infosecurity Magazine Jun 17, 2026, 08:45 AM (UTC)
Read
SANS Institute study finds few SOCs have built AI into defined workflows, despite widespread adoption
Infosecurity Magazine Jun 16, 2026, 02:30 PM (UTC)
Read
China-linked SprySOCKS backdoor gains stealthy Windows variants and 30-plus C2 commands
Infosecurity Magazine Jun 16, 2026, 01:15 PM (UTC)
Read
Rokarolla Android trojan steals banking logins and spies on victims while blocking fraud alerts
Cybersecurity Ventures Jun 16, 2026, 12:19 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 16, 2026 – Read the full story from LinkedIn The 2026 CISO Report by Cybersecurity Ventures, published in partnership with Sophos, lays out numbers that explain why mid…
Infosecurity Magazine Jun 16, 2026, 12:00 PM (UTC)
Read
ISSA study finds most security professionals feel challenged by colleagues’ involvement in cyber
Infosecurity Magazine Jun 16, 2026, 11:30 AM (UTC)
Read
Command and control traffic exploited a Teams visitor token to make malicious activity look legitimate to defenders
Infosecurity Magazine Jun 16, 2026, 11:00 AM (UTC)
Read
Athena is a new an industry coalition to fix the vulnerabilities frontier AI models find before attackers can exploit them
Infosecurity Magazine Jun 16, 2026, 08:15 AM (UTC)
Read
The FBI claims couriers are being used to circumvent bank transfers in crypto investment schemes
Infosecurity Magazine Jun 15, 2026, 05:00 PM (UTC)
Read
Tampered OptinMonster and sister plugins plant hidden backdoors on 1.2 million WordPress sites
Infosecurity Magazine Jun 15, 2026, 04:15 PM (UTC)
Read
How the Anubis ransomware group stole and leaked an Italian Adriatic port authority's data
Cybersecurity Ventures Jun 15, 2026, 01:14 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 15, 2026 – Read the full story from CMBlog By harnessing AI, cybercriminals are developing increasingly sophisticated techniques to commit their crimes, posing a growin…
Infosecurity Magazine Jun 15, 2026, 10:30 AM (UTC)
Read
Access to two Anthropic large language models, Mythos 5 and Fable 5, has effectively been banned to any non-US nationals by the Trump administration
Infosecurity Magazine Jun 15, 2026, 09:30 AM (UTC)
Read
Government departments find hundreds of vulnerabilities after testing frontier models
Infosecurity Magazine Jun 15, 2026, 09:00 AM (UTC)
Read
The Office of the Maine Attorney General has suspended its breach reporting portal
Infosecurity Magazine Jun 12, 2026, 02:00 PM (UTC)
Read
Domain of dark web money laundering platform AudiA6 seized and suspects arrested in joint operation by the FBI, Europol and others
Infosecurity Magazine Jun 12, 2026, 01:00 PM (UTC)
Read
NPM, part of GitHub, announced a new version of the npm package manager with several security improvements, including disabling install scripts
Cybersecurity Ventures Jun 12, 2026, 12:34 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jun. 12, 2026 – Watch the YouTube Short During World War II, some of America’s most powerful weapons weren’t bombs or guns. They were women sitting in secret rooms breaking…
Infosecurity Magazine Jun 12, 2026, 11:00 AM (UTC)
Read
As the FIFA World Cup 2026 kicks off, a new Darktrace report warns that sports teams and bodies are a major target for cyber criminals