SecLog

Tracking threats to information security and information freedom. Send feedback to seclog@jwest.org.
Stories 485
Sources 1054
Updated 2026.07.14
My filters
Add industries, companies, or keywords you care about (e.g. healthcare, Microsoft, ransomware). "My Feed" shows only stories mentioning at least one of them. Saved as a cookie in this browser. Use "Copy link" to bookmark or share the current filter set.
Microsoft July 2026 Patch Tuesday fixes 570 flaws, including exploited AD FS and SharePoint zero-days
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareGovernmentEducationHealthcareFinance & BankingConsumers & General PublicMicrosoft
Microsoft released its July 2026 Patch Tuesday updates to fix 570 security flaws, including two zero-days already being used in attacks and one publicly disclosed flaw. The exploited bugs are CVE-2026-56155 in Active Directory Federation Services (AD FS), a local privilege-escalation issue, and CVE-2026-56164 in Microsoft SharePoint Server, a network-reachable elevation-of-privilege flaw caused by missing authentication for a critical function; Microsoft also fixed the publicly disclosed BitLocker bypass CVE-2026-50661.
Why it matters: Organizations running affected Microsoft products should treat this as urgent because attackers were already exploiting two of the flaws before patches were available. Admins should prioritize patching AD FS and SharePoint servers immediately and apply Microsoft's SharePoint mitigations such as enabling Antimalware Scan Interface request-body scanning where applicable.
Sources
Ionut Arghire 2026.07.14 98%
This article covers the same July 2026 Microsoft Patch Tuesday event and adds that Microsoft says it fixed a record 622 vulnerabilities, highlights the exploited zero-days CVE-2026-56155 in AD FS and CVE-2026-56164 in SharePoint Server, and notes public disclosure of BitLocker bypass CVE-2026-50661 plus several other critical flaws.
Lawrence Abrams 2026.07.14 100%
This article establishes a distinct July 2026 Microsoft Patch Tuesday event centered on newly fixed zero-days, separate from the already tracked June 2026 Patch Tuesday story.
Full page
Microsoft June 2026 Patch Tuesday fixes 200 flaws, including Windows zero-days CVE-2026-45586 and CVE-2026-50507
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareConsumers & General PublicMicrosoft
Microsoft released its June 2026 security updates to fix 200 vulnerabilities, including three publicly disclosed zero-days in Windows. The zero-days include CVE-2026-45586, a local privilege-escalation flaw in the Windows Collaborative Translation Framework (CTFMON) that can grant SYSTEM access, CVE-2026-49160 in HTTP.sys, and CVE-2026-50507, a BitLocker security-feature bypass requiring physical access. Microsoft says none of the three were known to be exploited at patch time.
Why it matters: Windows systems across enterprises and consumer devices may be exposed to newly public attack methods until they are patched. Organizations should prioritize June Patch Tuesday deployment and review Microsoft’s HTTP.sys mitigation guidance, while users should install Windows updates promptly.
Sources
Lawrence Abrams 2026.07.14 21%
The article references a new Patch Tuesday release and notes that KB5099539 includes July 2026's security fixes, but it is not the same underlying June Patch Tuesday event as this tracked story.
Arctic Wolf Labs 2026.06.11 95%
This article covers the same June 2026 Microsoft Patch Tuesday event and adds a defender-focused recap with counts by severity and component, plus emphasis on six zero-days including CVE-2026-45586, CVE-2026-45585, CVE-2026-50507, CVE-2026-49160, and CVE-2020-17103.
2026.06.10 98%
This article reports on the same June 2026 Microsoft Patch Tuesday event and adds detail that it is Microsoft's largest Patch Tuesday on record, highlights the wormable Windows core flaw CVE-2026-45657, and notes that CVE-2026-41091 in Microsoft Defender was already added to CISA's KEV catalog as actively exploited.
Sergiu Gatlan 2026.06.10 69%
This is part of the same June 2026 Patch Tuesday event and adds concrete detail that the patched zero-days include YellowKey CVE-2026-45585 and MiniPlasma CVE-2020-17103 alongside GreenPlasma CVE-2026-45586.
info@thehackernews.com (The Hacker News) 2026.06.10 98%
This appears to be another report on the same June 2026 Microsoft Patch Tuesday event, describing the monthly batch of fixes, including three zero-days and critical RCE issues; it mainly adds alternate coverage and a slightly different flaw count.
2026.06.09 97%
This article is another report on the same June 2026 Patch Tuesday event, adding count details (206 CVEs, 38 critical), noting that none are yet confirmed exploited in the wild, and highlighting that CVE-2026-50507 is publicly disclosed while CVE-2026-49160 (HTTP.sys) was also patched in the same release.
BrianKrebs 2026.06.09 98%
This article is directly about the same June 2026 Patch Tuesday event and adds context on the record-breaking volume, the link to Nightmare Eclipse's GreenPlasma and YellowKey disclosures, and Microsoft's acknowledgment that June's browser fixes pushed the broader total far beyond the Patch Tuesday count.
Eduard Kovacs 2026.06.09 98%
This article is a direct report on the same June 2026 Microsoft Patch Tuesday event, adding that none of the flaws appears exploited in the wild, identifying CVE-2026-49160 as tied to the HTTP/2 Bomb denial-of-service technique, and noting nearly 40 issues are rated critical across Windows, Azure, Office, Outlook, Exchange, and AI tools.
Lawrence Abrams 2026.06.09 92%
This article is the Windows 10 ESU/LTSC delivery of the June 2026 Patch Tuesday fixes, confirming KB5094127 includes that month's 200 vulnerability fixes and adding operational details about Secure Boot certificate rollout monitoring and a known BitLocker recovery issue after recent updates.
Lawrence Abrams 2026.06.09 100%
The article establishes the broader June 2026 Microsoft Patch Tuesday event and introduces two publicly disclosed zero-days not already captured as standalone tracked stories.
Mayank Parmar 2026.06.09 93%
This article is the Windows 11 client-side rollout detail for the same June 2026 Patch Tuesday event, adding the specific KB packages (KB5094126 and KB5093998), affected Windows 11 versions (25H2/24H2 and 23H2), build numbers, and deployment guidance for installing the security fixes.
Full page
Microsoft extends free Windows 10 Extended Security Updates for consumers to October 2027
Policy & RegulationUrgent PatchesConsumers & General PublicTechnology & SoftwareMicrosoft
Microsoft has quietly extended its free Windows 10 Extended Security Updates program for personal devices by one year, so enrolled users can keep getting security patches until October 12, 2027. Windows 10 reached end of support on October 14, 2025, and Microsoft updated its ESU documentation and blog post to reflect the new date. The consumer ESU program applies to personal Windows 10 devices, not systems managed through Active Directory domains, Microsoft Entra, or mobile device management, though Entra-registered devices remain eligible.
Why it matters: This gives people and small organizations still on Windows 10 more time to keep receiving security fixes instead of running an unpatched operating system. Affected users should verify whether their devices are enrolled in ESU and use the extra year to plan a move to Windows 11 or other supported systems.
Sources
Lawrence Abrams 2026.07.14 75%
This article adds that Microsoft has now shipped Windows 10 ESU update KB5099539, bringing the July 2026 Patch Tuesday security fixes to enrolled Windows 10 and Enterprise LTSC devices and confirming build numbers and included hardening changes.
Lawrence Abrams 2026.06.25 100%
The article establishes a distinct security-support lifecycle change: Microsoft extended free consumer ESU coverage for Windows 10 from October 2026 to October 2027.
Full page
Microsoft releases July 2026 Windows 11 security updates KB5101650 and KB5099414
Urgent PatchesConsumers & General PublicGovernmentTechnology & SoftwareMicrosoft
Microsoft released mandatory July 2026 security updates for Windows 11, affecting supported 25H2, 24H2, and 23H2 systems. The cumulative updates KB5101650 and KB5099414 include Patch Tuesday fixes for 571 previously disclosed vulnerabilities, though this article does not identify specific CVEs in the Windows 11 packages. The release also includes non-security fixes such as Bluetooth reliability improvements and File Explorer changes.
Why it matters: Windows 11 users and administrators should install these updates promptly because they bundle Microsoft’s latest monthly security fixes. Even without a highlighted zero-day in this article, Patch Tuesday updates are routine high-priority maintenance for reducing exposure to known flaws.
Sources
Mayank Parmar 2026.07.14 100%
This article establishes a distinct monthly Windows 11 Patch Tuesday rollout for July 2026 and is not the same underlying event as the tracked June 2026 Microsoft Patch Tuesday story.
Full page
Finland issues wanted notice for convicted Vastaamo hacker after Supreme Court lets psychotherapy breach sentence stand
Breaches & Data LeaksScams & FraudPolicy & RegulationHealthcareVastaamoFinnish PoliceSupreme Court of Finland
Finnish authorities have issued a wanted notice for Aleksanteri Kivimäki, who was convicted over the Vastaamo psychotherapy breach and extortion case affecting tens of thousands of patients. Finland's Supreme Court refused to hear his appeal, leaving in place a nearly seven-year sentence for the 2018 hack and 2020 extortion campaign. The breach exposed data on about 33,000 patients, and more than 24,000 people reportedly received direct extortion demands before therapy notes were leaked online.
Why it matters: This updates one of Europe’s most serious medical-privacy breaches, where deeply sensitive therapy records were stolen and used to extort patients. Affected people and defenders get confirmation that the conviction is final, while the wanted notice shows the offender has not yet been taken back into custody.
Sources
2026.07.14 100%
This article establishes a trackable development in the long-running Vastaamo breach case: the conviction is now final and Finnish police have issued a wanted notice to return the convicted attacker to prison.
Full page
Adobe patches seven critical ColdFusion and Campaign Classic flaws that can lead to remote code execution
Urgent PatchesZero-Days & CVEsTechnology & SoftwareConsumers & General PublicAdobeCanadian Centre for Cyber Security
Adobe released security updates for ColdFusion and Adobe Campaign Classic to fix seven maximum-severity vulnerabilities that could let attackers run code on affected servers. The ColdFusion issues include CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, and CVE-2026-48282, affecting versions 2025.9, 2023.20, and earlier; Adobe says they can be exploited by unauthenticated attackers in low-complexity attacks. CVE-2026-48286 affects on-premises Campaign Classic 7.4.3 build 9396 and earlier; Adobe says hosted instances were already patched.
Why it matters: Organizations running these Adobe products could be exposed to server compromise if they delay patching. Adobe assigned the flaws Priority 1 and recommends installing updates within 72 hours, especially for internet-facing ColdFusion and on-premises Campaign systems.
Sources
Ionut Arghire 2026.07.14 93%
This is a direct follow-on Adobe security release affecting the same vendor and product line, adding a new batch of ColdFusion flaws two weeks later: 13 more ColdFusion issues, including eight critical bugs (CVE-2026-48318, CVE-2026-48322, CVE-2026-48284, CVE-2026-48321, CVE-2026-48325, CVE-2026-48319, CVE-2026-48324, CVE-2026-48327) fixed in ColdFusion 2025 Update 11 and 2023 Update 22.
Sergiu Gatlan 2026.07.06 97%
This updates the same Adobe ColdFusion patch cycle by adding the key new development that one of the patched flaws, CVE-2026-48282, is now being actively exploited in the wild according to CCCS.
info@thehackernews.com (The Hacker News) 2026.07.01 99%
This is the same Adobe July 2026 security update event covering seven CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic, adding another report of the vendor advisory and patch details.
Ionut Arghire 2026.07.01 99%
This article is a direct report on the same Adobe July 2026 security release, adding the specific CVE list, affected versions and builds, vulnerability classes, and Adobe's note that no public exploitation is known yet but the updates carry priority 1.
Sergiu Gatlan 2026.07.01 100%
This article establishes a new patching event centered on Adobe's July 2026 security updates for ColdFusion and Campaign Classic, with specific CVEs, affected versions, and deployment scope.
Full page
Welsh Doxbin administrator jailed for helping coordinate and promote swatting attacks in the UK, US, and Canada
Social Engineering & PhishingScams & FraudPolicy & RegulationConsumers & General PublicEducationMedia & EntertainmentDoxbinFBISouth Wales PoliceTarian ROCUUniversity of CaliforniaLos Angeles Police Department
A Welsh man was jailed after investigators said he helped encourage and support swatting attacks linked to the doxing platform Doxbin. Authorities said Callum Dare, an administrator on Doxbin, used the platform’s #deadnet channel to assist and incite hoax emergency calls, shared montage videos of armed-police responses to encourage copycats, and was tied through seized chat logs, a PayPal account, and device forensics to multiple incidents including threats against a Cardiff hotel, a University of California lecture theater, and victims in Canada.
Why it matters: Swatting can get armed police sent to innocent people’s homes or workplaces and has caused real injuries and deaths. The case highlights how doxing forums can enable harassment and violent hoaxes at scale, so organizations and individuals targeted by online harassment should treat leaked personal data and threat escalation as an immediate safety issue.
Sources
2026.07.14 100%
This article establishes a distinct enforcement story centered on Callum Dare’s role as a Doxbin administrator who encouraged and supported multiple swatting attacks across three countries.
Full page
Progress tells ShareFile Storage Zone Controller customers to shut down on-premises servers over a credible security threat
Urgent PatchesZero-Days & CVEsTechnology & SoftwareProgressShareFile
Progress told organizations using ShareFile Storage Zone Controllers to immediately shut down the Windows servers running them because of a credible external security threat. The affected component is the on-premises Storage Zone Controller used in hybrid ShareFile deployments, where internet-facing servers handle file transfers between local storage and the ShareFile cloud. Progress says it has temporarily disabled access for affected accounts and has not yet disclosed a CVE, attack method, or confirmed compromise.
Why it matters: This is a high-urgency situation for organizations that run ShareFile with on-premises Storage Zone Controllers, because the vendor says disabling cloud access alone is not enough and manual server shutdown is required. Affected admins should treat this as an emergency mitigation, isolate or power down those servers, and watch for vendor updates within 24 hours.
Sources
Lawrence Abrams 2026.07.14 98%
This directly updates the same ShareFile Storage Zone Controller emergency event by confirming the underlying issue was a high-severity zero-day path traversal flaw, adding affected versions (all 5.x and 6.x), impact details, and the newly released fixed versions 5.12.5 and 6.0.2.
info@thehackernews.com (The Hacker News) 2026.07.10 99%
This article is a direct report on the same Progress ShareFile emergency warning, reiterating that organizations running on-premises Storage Zone Controllers should take them offline immediately due to a credible security threat.
Lawrence Abrams 2026.07.10 100%
This article appears to be the first concrete report of Progress warning ShareFile Storage Zone Controller customers about a credible active threat and directing immediate shutdown of affected on-premises servers.
Full page
Canada’s CSE says it hacked and disrupted a ransomware gang and two other foreign criminal groups in 2025
Policy & RegulationSurveillance & PrivacyThreat Actors & APTsRansomwareCSE
Canada’s signals intelligence agency says it carried out state-authorized hacks in 2025 against a ransomware-as-a-service gang, foreign fentanyl-chemical traffickers, and a violent extremist group. In its annual report, the Communications Security Establishment said one operation made the ransomware gang’s infrastructure inoperable and deleted stolen data being advertised on the dark web, and that it also conducted 10 additional technical disruptions against major ransomware gangs last year. The specific groups, malware, and infrastructure were not named.
Why it matters: This is a rare public acknowledgment that a government agency directly disrupted criminal cyber infrastructure rather than only warning about it. Defenders should watch for follow-on disclosures about which ransomware groups were hit, because that could affect threat tracking, infrastructure blocklists, and victim-notification efforts.
Sources
Anna Mackay 2026.07.14 93%
This appears to describe one of the same underlying CSE disruption operations previously reported in broad terms, adding that one target was online foreign criminals brokering fentanyl ingredients and framing it as part of CSE’s expanded offensive cyber activity.
SecurityWeek News 2026.07.10 94%
The roundup restates that Canada’s Communications Security Establishment used its foreign cyber operations authority to hack and disrupt ransomware infrastructure, adding that the operations degraded the groups’ command-and-control capabilities.
2026.07.06 100%
This article establishes a distinct story about Canada publicly disclosing offensive cyber operations against ransomware and other foreign threat actors in 2025.
Full page
Fake LastPass and Bitwarden security-policy emails send users to phishing sites posing as DocuSign
Social Engineering & PhishingConsumers & General PublicTechnology & SoftwareLastPassBitwardenDocuSign
LastPass and Bitwarden users are being targeted by phishing emails that pretend to announce security-policy changes and send people to fake DocuSign-style websites. The messages came from lookalike sender addresses such as hello@lastpassnewsletter.com and hello@bitwardennewsletter.com and linked to domains including lastpasscompliance.com and bitwardencompliance.com. LastPass said its own systems were not breached; the sites reportedly offered a file download for Windows and macOS, suggesting credential theft or malware delivery.
Why it matters: Password-manager users are high-value targets because one stolen master password can expose many other accounts. Users should avoid these messages, verify any alerts directly in the official app or website, and immediately change their master password from a trusted device if they entered it on a phishing page.
Sources
Bill Toulas 2026.07.14 100%
This article establishes a distinct ongoing phishing campaign using fake LastPass and Bitwarden security notices and lookalike compliance domains to lure users to fraudulent sites.
Full page
Broadcom patches seven serious VMware Avi Load Balancer flaws, including auth bypass and remote code execution bugs
Urgent PatchesZero-Days & CVEsTechnology & SoftwareBroadcomVMware
Broadcom released updates for VMware Avi Load Balancer to fix seven serious security flaws that could let attackers break into or take control of affected systems. The issues include critical authentication bypass CVE-2026-47865, high-severity flaws CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, and CVE-2026-47871, enabling authentication bypass, remote code execution, privilege escalation to root, and directory traversal. Broadcom said there is no reported in-the-wild exploitation in the advisory.
Why it matters: Organizations using VMware Avi Load Balancer for application delivery and security should update promptly because several of these bugs could let a network-accessible attacker bypass login protections or gain elevated control. For defenders, this is a straightforward patch-now advisory even without confirmed active exploitation.
Sources
Eduard Kovacs 2026.07.14 100%
This article appears to be the first item here establishing the specific July 2026 Broadcom patch release for the seven VMware Avi Load Balancer CVEs.
Full page
Dutch intelligence says Russian spies hacked internet-connected cameras to track NATO logistics and Ukrainian troops
Threat Actors & APTsGovernmentDefense & AerospaceTransportation & LogisticsAIVDMIVDNATO
Dutch intelligence agencies say Russian state-backed hackers have been breaking into internet-connected security cameras in the Netherlands, other NATO and EU countries, and Ukraine to watch military transport routes and identify Ukrainian troops. The AIVD and MIVD advisory says the operators scan for exposed IP cameras and exploit weak security such as default passwords, outdated firmware, and insecure default configurations; in Ukraine, some compromised cameras were reportedly used to support attempts to kill soldiers and destroy equipment.
Why it matters: This is a live espionage threat with potential real-world consequences beyond data theft, including targeting people and military shipments. Organizations with internet-accessible cameras should immediately change default credentials, update firmware, review exposure and configurations, and assess risks tied to deployed camera vendors.
Sources
2026.07.14 100%
This article establishes a distinct advisory-backed espionage story centered on Russian compromise of internet-connected cameras for military intelligence collection and battlefield targeting, not a previously listed event.
Full page
Unpatched Claude for Chrome flaws let malicious extensions read Gmail, Google Docs, and Calendar data
Zero-Days & CVEsSurveillance & PrivacyConsumers & General PublicTechnology & SoftwareAnthropicGoogle
Researchers say Anthropic's Claude for Chrome extension still has flaws that can let a malicious browser extension trigger Claude to act as the user and access sensitive Google account data. Manifold says the issues remain in version 1.0.80 despite eight releases since disclosure in May 2026. The bugs involve forged click events for pre-approved tasks and a side-panel URL parameter that can force Claude into its 'Act without asking' autonomous mode, extending concerns from the earlier ClaudeBleed issue.
Why it matters: People using Claude for Chrome, especially with 'Act without asking' enabled, could have email, documents, and calendar data exposed without a real approval click. Until Anthropic ships a full fix, users should review installed extensions, disable unnecessary ones, and avoid autonomous mode for sensitive accounts.
Sources
Eduard Kovacs 2026.07.14 100%
This article establishes a distinct ongoing vulnerability story around Anthropic's Claude for Chrome extension, with new reporting that previously disclosed flaws remain exploitable and unpatched in current versions.
Full page
Jalisco and OmegaLord phishing kits target Microsoft 365 accounts and try to bypass MFA
Social Engineering & PhishingConsumers & General PublicTechnology & SoftwareMicrosoft
Researchers found two phishing kits that target Microsoft 365 users and are designed to get around multi-factor authentication protections. Jalisco abuses the OAuth 2.0 device authorization flow, also called device-code phishing, by generating fresh Microsoft device codes in real time and registering attacker-controlled devices on victim accounts. OmegaLord uses a fake PDF reader login page to steal Microsoft account credentials and victims’ phone numbers, which can help attackers intercept or hijack MFA challenges and quickly loot SharePoint and other SaaS data.
Why it matters: Organizations using Microsoft 365 should treat this as an active account-takeover risk, especially where device-code sign-ins are allowed. Defenders should review Entra ID device registrations, restrict or block device-code authentication where possible, tighten app registration policies, and warn users not to enter login codes or phone numbers into unsolicited prompts.
Sources
Bill Toulas 2026.07.14 100%
This article establishes a distinct phishing campaign/tooling story centered on two newly reported kits, Jalisco and OmegaLord, and their Microsoft 365 MFA-evasion methods rather than a single previously tracked kit or law-enforcement action.
Full page
xAI says Grok Build stopped uploading entire code repositories and will delete previously collected user data
Surveillance & PrivacyTechnology & SoftwarexAIGoogle Cloud
xAI's Grok Build coding tool was found sending users' entire code repositories to cloud storage, including full Git history and in some cases sensitive files such as secrets and SSH keys. Researcher Cereblab said the CLI uploaded Git bundles to a Google Cloud Storage bucket even when asked not to open files, and confirmed the behavior stopped only after a server-side setting, disable_codebase_upload, was turned on. Elon Musk separately said previously uploaded user data would be deleted.
Why it matters: Developers and companies using Grok Build may have exposed source code, old secrets, and other sensitive local files without realizing it. Users should review whether the tool was used on sensitive repositories, rotate any exposed credentials, and verify data-retention settings before continuing to use it.
Sources
2026.07.14 100%
This article establishes the underlying event: a researcher-documented data-handling problem in xAI's Grok Build CLI, xAI's server-side change to stop whole-repo uploads, and Musk's pledge to delete previously uploaded data.
Full page
TrendAI says Russian-speaking scammer used jailbroken Gemini to target QAnon and MAGA users with wallet theft and WordPress credential attacks
Scams & FraudSocial Engineering & PhishingMalwareTechnology & SoftwareCryptocurrency & BlockchainConsumers & General PublicGoogleWordPressTelegramTrendAICloudflare
A Russian-speaking threat actor allegedly used a jailbroken Google Gemini account to run a months-long scam and theft campaign aimed at QAnon and MAGA communities, stealing WordPress admin credentials and draining at least one victim's cryptocurrency wallets. TrendAI says the operation ran from September 2025 to May 2026 through a Telegram channel with about 17,000 subscribers, used 73 likely stolen Gemini API keys, pushed a fake StellarMonster wallet app that actually installed the GoToResolve remote access tool, and captured victims' seed phrases through a bogus wallet-import screen.
Why it matters: This matters because it blends political-community targeting, AI-assisted social engineering, malware, and direct crypto theft in a way ordinary users can fall for and defenders may miss. Users should avoid wallet apps and recovery prompts promoted in Telegram channels, while organizations should investigate exposed WordPress credentials and watch for abuse of stolen API keys.
Sources
2026.07.14 97%
This is a direct follow-up on the same bandcampro campaign, adding new evidence from more than 200 Gemini CLI session logs showing Gemini handled most of the operation, including botnet migration, C2 server deployment, proxy setup, password scanning, API scripting, and infostealer-dump processing.
2026.05.22 100%
This article appears to be the first tracked report establishing this specific TrendAI-described campaign by the actor bandcampro using jailbroken Gemini, fake crypto-wallet software, and Telegram-based persona fraud.
Full page
SAP fixes critical NetWeaver and Commerce flaws including NetWeaver SAML bug CVE-2026-44748
Urgent PatchesZero-Days & CVEsTechnology & SoftwareRetail & E-CommerceSAP
SAP released June 2026 security updates for critical flaws in NetWeaver, Commerce Cloud, and Data Hub that could let attackers access sensitive data, crash systems, or bypass normal protections. The most severe issues are CVE-2026-44748, an XML Signature Wrapping flaw in NetWeaver AS ABAP and ABAP Platform SAML authentication rated 9.9; CVE-2026-27671, a 9.8 memory-corruption bug in the SAP kernel's RFC handling affecting NetWeaver and ABAP Platform; CVE-2026-22732, a 9.1 Spring Security header-handling issue affecting Commerce Cloud and Data Hub; and CVE-2026-40128, a 9.0 directory traversal flaw in NetWeaver Application Server Java reachable through crafted HTTP logon requests.
Why it matters: SAP systems often sit at the core of large companies' business operations, so critical flaws in NetWeaver and Commerce can have broad operational and data-security impact. Organizations using affected SAP products should review SAP's June 2026 notes, apply patches promptly, and use temporary mitigations such as disabling SAML where needed until updates are installed.
Sources
Sergiu Gatlan 2026.07.14 93%
This article is an update on SAP's July 2026 security fixes for critical vulnerabilities in NetWeaver and Commerce Cloud, adding specific details on three patched critical flaws: CVE-2026-44747 in NetWeaver AS ABAP, CVE-2026-27690 in SAP Approuter, and CVE-2026-44761 in SAP Commerce Cloud, plus the overall count of 16 fixes in the July release.
Ionut Arghire 2026.07.14 91%
This is the July 2026 SAP Security Patch Day follow-up to the same underlying SAP critical-patch event family, adding newly disclosed critical flaws in NetWeaver Application Server ABAP (CVE-2026-44747), Approuter (CVE-2026-27690), and Commerce Cloud (CVE-2026-44761), plus details on temporary mitigation and affected deployment conditions.
Bill Toulas 2026.06.09 98%
This article is the same June 2026 SAP patch event and adds details on the full set of 15 fixes, highlighting four critical flaws including CVE-2026-44748 in NetWeaver, CVE-2026-27671 in ABAP, CVE-2026-22732 affecting Commerce Cloud and Data Hub, and CVE-2026-40128 in NetWeaver AS Java, plus two high-severity issues.
Ionut Arghire 2026.06.09 100%
This article establishes a new tracked story around SAP's June 2026 Patch Day release and the specific critical CVEs affecting NetWeaver, Commerce Cloud, and Data Hub.
Full page
CISA adds exploited Joomla extension flaws CVE-2026-48908 and CVE-2026-56290 to KEV after web-shell attacks
Urgent PatchesZero-Days & CVEsTechnology & SoftwareMedia & EntertainmentRetail & E-CommerceJoomShaperJoomlackJoomlaCISAiCagendaBalbooa
CISA says attackers are actively exploiting two Joomla page-builder extensions and agencies must patch by July 10. The flaws are CVE-2026-48908 in JoomShaper SP Page Builder before 6.6.2 and CVE-2026-56290 in Joomlack Page Builder CK before 3.6.0. Both are unauthenticated file-upload or access-control bugs that can lead to remote code execution, and reports say attackers have used them to plant hidden admin accounts, web shells, and PHP file manager backdoors.
Why it matters: Website owners using these Joomla extensions could have their sites quietly taken over and used to host backdoors or malicious content. Patch immediately, check for unexpected administrator accounts and uploaded PHP files, and review server logs for suspicious uploads.
Sources
2026.07.14 93%
This article appears to cover the same underlying KEV event for two actively exploited Joomla extension file-upload flaws leading to web-shell deployment, but with corrected CVE IDs and specific affected extensions: iCagenda (CVE-2026-48939) and Balbooa Forms (CVE-2026-56291). It adds details on attack timing, exploit behavior, and patch versions.
Ionut Arghire 2026.07.08 100%
No existing tracked story covers these specific Joomla extension exploitation events or CISA KEV additions, so this article establishes a new story anchored to CVE-2026-48908 and CVE-2026-56290.
Full page
US and allies warn Russian FSB-linked hackers are targeting critical infrastructure routers and Cisco devices
Threat Actors & APTsHealthcareFinance & BankingGovernmentDefense & AerospaceEnergy & UtilitiesTelecommunicationsNSACISACiscoFSB
The US and allied governments warned that Russian state-backed hackers are breaking into routers and other network devices at critical infrastructure organizations around the world. The joint advisory says FSB Center 16-linked actors including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra are abusing Simple Network Management Protocol (SNMP) to copy device configurations off networks and are also exploiting known Cisco flaws CVE-2008-4128 and CVE-2018-0171 for code and command execution. Targeted sectors include communications, defense, energy, finance, government, and healthcare.
Why it matters: Organizations running internet-exposed or poorly secured routers may already be at risk, especially in critical infrastructure. Defenders should urgently disable Cisco Smart Install, turn off SNMPv1/v2, use SNMPv3, restrict management access, and patch affected Cisco devices.
Sources
Ionut Arghire 2026.07.14 100%
This article establishes a distinct multi-country advisory about ongoing Russian router-focused intrusions against critical infrastructure, with specific TTPs and Cisco CVEs that do not match a single existing tracked event.
Full page
Europol-led operation seizes First VPN service used by ransomware and cybercrime actors
Threat Actors & APTsRansomwarePolicy & RegulationHealthcareFinance & BankingGovernmentConsumers & General PublicEuropolU.S. TreasuryOFACFirst VPNFBI
French and Dutch authorities, with Europol and partners from 16 countries, seized 33 servers and multiple domains tied to the 'First VPN' service, which investigators say was widely used in ransomware, fraud, and data-theft attacks. Authorities arrested or questioned a Ukrainian administrator, infiltrated the service, and said intelligence from the takedown identified thousands of users, with 506 users and 83 intelligence packages shared internationally.
Why it matters: The takedown targets a criminal privacy service that allegedly supported major cybercrime operations and may generate follow-on investigations into ransomware and data-theft cases. Defenders and incident responders should watch for new attribution and victim-notification leads emerging from the seized data.
Sources
Sergiu Gatlan 2026.07.14 95%
This is a direct follow-up on the same First VPN / 1VPNS disruption event, adding that the U.S. Treasury and UK coordinated sanctions against the service and its administrator Dmytro Rashevskyi, plus new detail that OFAC also sanctioned crypter seller Yegeniy Silayev for enabling ransomware and malware evasion.
Eduard Kovacs 2026.05.22 98%
This article covers the same First VPN takedown and adds that the alleged administrator was arrested in Ukraine, reiterates FBI details that at least 25 ransomware groups used the service, and notes investigators shared data on 506 identified users plus published IoCs and ATT&CK mappings.
Bill Toulas 2026.05.21 100%
This article appears to be the first tracked report of the coordinated seizure of First VPN infrastructure and the identification of its users.
2026.05.20 98%
This article covers the same Europol-led takedown of First VPN, adding details that the operation occurred May 19-20, involved France, the Netherlands and Ukraine, dismantled 33 servers, and yielded a user database exposing thousands of users tied to ransomware, fraud, and data-theft investigations.
Full page
Compromised Jscrambler npm packages pushed credential-stealing malware in supply-chain attack
Supply ChainMalwareTechnology & SoftwareJscramblernpm
Several Jscrambler npm package versions were maliciously updated to install credential-stealing malware on Windows, macOS, and Linux systems used by developers and cloud operators. Jscrambler said an attacker used stolen or otherwise compromised npm publishing credentials starting July 11, 2026 to publish poisoned versions 8.16, 8.17, 8.18, and 8.20 of the main package; the first clean version is 8.22. Related packages were also affected through dependency chains, including Jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2, and Jscrambler-metro-plugin 9.0.2, with 1,479 downloads recorded before deprecation.
Why it matters: Anyone who installed the affected packages may have had passwords, tokens, cloud credentials, crypto-wallet data, and other secrets stolen. Organizations using these packages should remove the affected versions immediately, scan impacted machines, and rotate credentials and API keys without delay.
Sources
Ionut Arghire 2026.07.14 100%
This article establishes a distinct supply-chain compromise centered on Jscrambler's npm publishing account and poisoned package releases, not a follow-up to an existing tracked event.
Full page
Pentagon pauses CMMC phase 2 contractor cybersecurity certification requirements pending program review
Policy & RegulationDefense & AerospaceGovernmentDepartment of Defense
The Pentagon has suspended the next phase of its contractor cybersecurity certification rollout, delaying stricter checks that were due to start in November 2026 for companies seeking defense contracts. The Cybersecurity Maturity Model Certification (CMMC) phase 2 would have required third-party Level 2 assessments for contractors handling controlled unclassified information (CUI), but the Department of Defense said it will review the program for 60 days, citing industry feedback and too few approved assessors.
Why it matters: This affects defense contractors, subcontractors, and suppliers that do business with the U.S. military, especially smaller firms preparing for CMMC audits. It is not an emergency patching issue, but it changes compliance planning and procurement timelines for organizations handling federal contract information or CUI.
Sources
Eduard Kovacs 2026.07.14 100%
This article establishes a distinct new policy story: the Pentagon's formal pause and review of CMMC phase 2 implementation.
Full page
Infinite Campus says ShinyHunters stole data from 137,100 school staff accounts in Salesforce breach
Threat Actors & APTsSocial Engineering & PhishingBreaches & Data LeaksEducationInfinite CampusSalesforceMicrosoft
Infinite Campus says a March breach of its Salesforce environment exposed data from 137,100 school staff accounts tied to U.S. K-12 districts. The company said the attacker accessed its Salesforce instance rather than customer student databases; leaked records analyzed by Have I Been Pwned reportedly include names, email addresses, employers, job titles, phone numbers, physical addresses, usernames, and support tickets. ShinyHunters claimed responsibility and published a 1.2GB archive of alleged stolen data.
Why it matters: Schools and staff may face targeted phishing, impersonation, and follow-on fraud using exposed contact and support data. Districts using Infinite Campus should warn employees, watch for suspicious messages or password-reset attempts, and review any Salesforce-connected access and monitoring.
Sources
info@thehackernews.com (The Hacker News) 2026.07.14 93%
This article appears to directly expand on the same underlying ShinyHunters-linked Salesforce data-theft activity, adding Microsoft's view that the attackers used three access paths over roughly a year to steal data from Salesforce environments.
Sergiu Gatlan 2026.06.15 100%
This article establishes a distinct breach event at Infinite Campus with identified scope, affected population, attack path through Salesforce, and public attribution to ShinyHunters.
Full page
Klue OAuth breach let Icarus extortion group steal Salesforce customer data from multiple organizations
Scams & FraudThreat Actors & APTsSupply ChainSocial Engineering & PhishingBreaches & Data LeaksTechnology & SoftwareConsumers & General PublicInsuranceTelecommunicationsLegal & Professional ServicesKlueSalesforceHuntressRecorded FutureTaniumJamfInsurityGongHackerOneReliaQuestLastPassBeyondTrust8x8PendoBlackbaudAlertMediaTinesMicrosoft
Klue says attackers abused its Salesforce-connected Battlecards app to steal CRM data from multiple customer organizations, and victims are now receiving extortion demands from the Icarus group. According to ReliaQuest, Huntress, and BleepingComputer, the attackers used compromised Klue service accounts and associated OAuth tokens to access customer Salesforce instances, enumerate objects through Salesforce REST API endpoints, and exfiltrate records over hours; Salesforce has disabled the Klue Battlecards integration while the incident is investigated.
Why it matters: Organizations that connected Klue Battlecards to Salesforce may have had sensitive sales, customer, or internal business data stolen without a malware outbreak or password spray. Affected teams should urgently review Salesforce OAuth-connected apps and token activity, check for unusual API queries, and prepare for extortion emails tied to this campaign.
Sources
info@thehackernews.com (The Hacker News) 2026.07.14 79%
This article adds broader campaign context from Microsoft, saying ShinyHunters-linked actors spent about a year stealing data from Salesforce through three intrusion paths, which helps explain how Salesforce-connected extortion incidents like the Klue breach fit into a wider pattern.
Ionut Arghire 2026.06.26 96%
This article directly updates the same Klue-Salesforce supply-chain incident, adding that roughly two dozen customers have now disclosed impact, naming additional victims such as AlertMedia, Blackbaud, Camunda, Cresta, Deel, Lucanet, Link11, and Tines. It also adds scope claims of 195 affected Klue customers, notes Salesforce and Gong disabled the integration, and reports Klue told customers that Icarus was itself hacked and sample stolen data may now be in another actor’s hands.
Ionut Arghire 2026.06.24 98%
This article directly updates the same Klue-Salesforce breach by adding newly disclosed affected organizations including LastPass, BeyondTrust, 8x8, and Pendo, and reiterates that Icarus used a compromised legacy credential to mint OAuth tokens and exfiltrate CRM data from connected Salesforce instances.
Bill Toulas 2026.06.23 97%
This is a direct update on the same Klue OAuth supply-chain incident, adding that LastPass has confirmed impact, describing the Salesforce data types exposed, stating customer vaults and core infrastructure were not affected, and listing mitigations such as token rotation and Klue access revocation.
2026.06.22 94%
This article is a direct update on the same Klue breach, adding that Huntress and several other security and software vendors disclosed they were affected, that Klue says the intrusion began with a compromised legacy integration credential on June 11, and that the attacker used stolen OAuth tokens to access connected Salesforce customer environments.
Ionut Arghire 2026.06.22 96%
This article directly updates the same Klue breach by adding more confirmed affected organizations, stating Klue’s account of the intrusion path via compromised legacy credentials and stolen OAuth tokens, noting Salesforce and Gong disabled integrations, and reporting that Icarus has claimed the attack on its leak site and set a publication deadline.
Lawrence Abrams 2026.06.19 98%
This article directly updates the same Klue breach by adding Klue's public confirmation, the initial intrusion vector of a compromised legacy integration credential, Icarus's public claim on its leak site, and additional named victims including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity.
Ionut Arghire 2026.06.19 98%
This is a direct update on the same Klue incident, adding confirmed affected customers (Huntress and Recorded Future), details on the stolen Salesforce data fields, Salesforce's disabling of the Klue Battlecards app, ReliaQuest observations on API-based exfiltration, and Huntress's attribution of the attack to the Icarus extortion group via 'Mr Brean' communications.
info@thehackernews.com (The Hacker News) 2026.06.19 98%
This is the same underlying event and adds that Salesforce itself disabled the Klue app integration in response to the OAuth token abuse that exposed customer data across multiple organizations.
Lawrence Abrams 2026.06.18 100%
This article establishes the specific underlying event: a Klue OAuth compromise used by the Icarus extortion group to access and steal data from multiple Salesforce customer environments.
Full page
Lidl says hackers stole customer data from a third-party service provider affecting online shop users in Germany, Belgium and the Netherlands
Breaches & Data LeaksRetail & E-CommerceConsumers & General PublicLidl
Lidl says hackers stole customer data from an external IT service provider used for its online shop operations in Germany, Belgium and the Netherlands. The retailer says its shopping platform itself was not breached, but attackers briefly accessed and exfiltrated part of a separately stored customer database. Exposed data includes names, phone numbers, email addresses, dates of birth, titles, and customer numbers; Lidl says passwords, payment data, and addresses were not affected.
Why it matters: Affected customers face a higher risk of targeted phishing and impersonation scams even if payment details were not exposed. Lidl users in the affected countries should be wary of unsolicited messages, verify any account-related communication, and monitor for identity misuse.
Sources
2026.07.13 100%
This article is the first report here establishing a distinct breach event involving Lidl customer data exposed through a third-party provider.
Full page
Six U-Boot bootloader flaws could let attackers run code before devices start
Zero-Days & CVEsTechnology & SoftwareTelecommunicationsManufacturingEnergy & UtilitiesU-Boot
Researchers disclosed six security flaws in the widely used U-Boot bootloader that could let attackers crash devices or run malicious code before the operating system starts. Binarly identified BRLY-2026-037 through BRLY-2026-042 in U-Boot's FIT (Flattened Image Tree) signature-verification code, including two issues that may allow arbitrary code execution during firmware verification. The vulnerable code reportedly dates back to U-Boot 2013.07 and may affect more than 50 releases plus downstream vendor firmware used in BMCs, networking gear, industrial systems, and IoT devices.
Why it matters: Bootloader flaws are especially serious because they can enable stealthy, persistent malware that starts before normal security tools load. Organizations using devices with U-Boot, especially remotely updatable BMCs and embedded systems, should identify affected products and apply vendor fixes or mitigations as they become available.
Sources
Lawrence Abrams 2026.07.10 100%
This article appears to be the first tracked report of Binarly's disclosure of six U-Boot FIT signature-verification vulnerabilities enabling pre-boot denial of service and possible code execution.
Full page
Squid Proxy flaw CVE-2026-47729 can leak other users’ web requests from shared proxies
Zero-Days & CVEsUrgent PatchesEducationTechnology & SoftwareConsumers & General PublicTelecommunicationsSquid
A newly disclosed flaw in Squid Proxy can expose data from other users who share the same proxy server. Tracked as CVE-2026-47729 and dubbed 'Squidbleed,' the bug is a memory over-read in Squid’s FTP parser that has reportedly existed since 1997. An attacker must control an FTP server reachable through the proxy, and the leak can expose prior users’ cleartext HTTP request data, including credentials, session tokens, and API keys. A fix was merged for Squid 8 in April 2026 and released in Squid 7.6 in June 2026; disabling FTP support is a mitigation.
Why it matters: Organizations using Squid in shared environments such as companies, schools, and public hotspots may be exposing sensitive web traffic if they have not updated. Admins should upgrade to fixed versions or disable FTP support, especially where cleartext HTTP is still in use or Squid terminates Transport Layer Security (TLS).
Sources
Bruce Schneier 2026.07.10 96%
This is a short secondary write-up of the same underlying event: the 'Squidbleed' information-disclosure flaw in Squid Proxy that can expose other users' web requests on shared proxies.
2026.06.23 97%
This article is a direct report on the same Squidbleed event, adding detail on the bug’s 1997 origin, the FTP directory-listing parsing flaw, the conditions required for exploitation, and that the fix shipped in Squid v7.6 on June 8.
info@thehackernews.com (The Hacker News) 2026.06.22 97%
This is another report on the same Squidbleed vulnerability, describing the longstanding Squid Proxy bug and its impact on shared proxy deployments that can expose other users' unencrypted HTTP requests.
Eduard Kovacs 2026.06.22 100%
This article appears to be the initial broad disclosure of CVE-2026-47729, including the vulnerability details, affected software, attack requirements, and patch availability.
Full page
EU lawmakers fail to block revival of interim 'Chat Control' rule allowing voluntary CSAM scanning of user messages
Policy & RegulationSurveillance & PrivacyTechnology & SoftwareConsumers & General PublicEuropean ParliamentCouncil of the European UnionGoogleMicrosoftMetaEuropolSignal
European Union lawmakers failed to stop the return of the interim 'Chat Control' rule, which would again let online communication services scan user messages for child sexual abuse material. Although more Members of the European Parliament voted to scrap it than to keep it, opponents did not reach the 360-vote threshold needed to reject the Council's position. A related amendment that would have limited scanning to judicially identified accounts also failed, while an amendment excluding end-to-end encrypted services passed. The proposal now returns to the Council of the European Union, which has three months to accept or reject the amended text.
Why it matters: This matters because it could restore legal cover for broad message scanning across consumer communications platforms in the EU, with direct privacy and surveillance implications even if encrypted chats are formally excluded. Messaging providers, rights groups, and users should watch the Council process closely because the measure could be reinstated through 2028.
Sources
2026.07.10 98%
This article reports the same underlying event: the European Parliament vote reviving the interim rule that permits platforms to continue voluntary CSAM scanning, adds procedural details about how the measure passed, notes the lapse since April, and clarifies the extension now runs until 2028 while broader Chat Control 2.0 negotiations continue.
2026.07.09 100%
This article establishes a concrete legislative milestone: an unsuccessful parliamentary effort to stop reintroduction of the interim EU Chat Control framework, sending the amended proposal back to the Council for possible revival.
Full page
Ryuk ransomware operator pleads guilty in U.S. over attacks on American companies, school, and servers
RansomwarePolicy & RegulationTechnology & SoftwareEducationConsumers & General PublicDepartment of Justice
A man accused of helping deploy Ryuk ransomware against U.S. victims has pleaded guilty in federal court after being extradited from Ukraine. U.S. prosecutors say Karen Serobovich Vardanyan provided initial access to corporate networks and helped deploy Ryuk between November 2019 and April 2020, encrypting hundreds of servers and workstations. Court records cited attacks including a Michigan company, a technology company in Oregon, and a school in Texas, with the conspirators allegedly receiving about 1,610 bitcoin in ransom payments.
Why it matters: This matters because it ties a named individual to one of the most damaging ransomware operations and shows continued prosecution years after the attacks. Defenders and affected sectors should treat it as a reminder that initial-access brokers and old Ryuk tradecraft still shape current ransomware threats descended from Ryuk and Conti.
Sources
Bill Toulas 2026.07.10 100%
This article establishes a distinct law-enforcement story centered on Karen Vardanyan's guilty plea for his role in the Ryuk ransomware operation, not a previously tracked plea or breach event.
2026.07.10 97%
This article directly updates that same Ryuk criminal case with the guilty plea by Karen Serobovich Vardanyan, additional detail on victim organizations in Michigan, Oregon, and Texas, the 200 bitcoin payment, restitution, and sentencing timeline.
Full page
Microsoft details GigaWiper backdoor that can spy on systems, encrypt files, and wipe Windows disks
RansomwareMalwareThreat Actors & APTsMicrosoft
Microsoft says a threat actor has used a destructive Windows backdoor called GigaWiper for more than eight months to maintain access and sabotage infected systems. First seen in October 2025, the Go-based malware combines older wiping components with backdoor functions, supports command-and-control through RabbitMQ and Redis, and can run PowerShell, upload files, take screenshots, record screens, trigger a Blue Screen of Death, encrypt files in both reversible and destructive modes, and wipe disks at the physical-drive level.
Why it matters: This is not just another infostealer or ransomware sample: it gives attackers a single tool for stealthy access and for crippling machines on demand. Defenders should hunt for the malware’s persistence and command-and-control activity, especially RabbitMQ, Redis, MinIO Client, and destructive commands, because the impact can range from spying to irreversible data loss.
Sources
2026.07.10 99%
This article is a report on the same Microsoft disclosure, adding plain-language details on GigaWiper’s modular design, its use of RabbitMQ and Redis for command-and-control, its disk-wiping and no-recovery encryption functions, and Microsoft’s statement that the tool combines components from Crucio ransomware, a Go version of FlockWiper, and a standalone disk wiper.
Ionut Arghire 2026.07.10 100%
This article establishes a distinct malware-tracking story centered on Microsoft's disclosure of GigaWiper as a named destructive backdoor with combined espionage, encryption, and wiping capabilities.
Full page
Compromised Injective SDK package on npm stole cryptocurrency wallet seed phrases and private keys
Cryptocurrency & BlockchainMalwareSupply ChainCryptocurrency & BlockchainTechnology & SoftwareInjective LabsnpmGitHub
A malicious version of Injective Labs' JavaScript SDK was published to npm after attackers compromised a contributor account, putting developers and downstream crypto apps at risk of wallet theft. The poisoned release was @injectivelabs/sdk-ts version 1.20.21, and 17 related packages were pinned to it. The malware triggered when wallet-generation or wallet-import functions were used, then exfiltrated mnemonic seed phrases and private keys via HTTP requests disguised as legitimate traffic. Injective later published clean version 1.20.23.
Why it matters: Developers who installed or used the affected package may have exposed wallet secrets that let attackers drain funds, so this is urgent for cryptocurrency projects and users tied to those wallets. Affected teams should audit dependencies, rotate environment secrets, and move funds to new wallets if any seed phrase or private key may have been handled by the malicious version.
Sources
info@thehackernews.com (The Hacker News) 2026.07.10 98%
This article appears to cover the same underlying event, adding that a GitHub compromise at Injective Labs was the mechanism used to push the malicious npm packages that stole wallet seed phrases and private keys.
Bill Toulas 2026.07.09 100%
This article establishes a distinct npm supply-chain compromise centered on Injective Labs' SDK, with a specific malicious package version, attack path through a compromised contributor account, and concrete impact of stolen wallet credentials.
Full page
Former DigitalMint negotiator gets prison sentence for helping BlackCat ransomware extort U.S. victims
RansomwarePolicy & RegulationFinance & BankingHealthcareEducationLegal & Professional ServicesNonprofits & NGOsDigitalMintSygniaFBIBlackCatDOJ
A former ransomware negotiator at DigitalMint was sentenced after prosecutors said he secretly helped BlackCat ransomware attacks against U.S. organizations. Court records say Angelo Martino worked with two other former DigitalMint and Sygnia negotiators as BlackCat affiliates between April 2023 and April 2025, demanded payments, threatened to leak stolen data, and shared victims’ insurance limits and negotiation positions with the gang to maximize ransom demands.
Why it matters: This matters because it shows attackers can exploit trusted insiders at companies hired to help victims during ransomware crises. Organizations using outside negotiators or incident-response firms should review access, logging, conflict controls, and what sensitive insurance and negotiation data those vendors can see.
Sources
2026.07.10 96%
This article directly updates the same BlackCat/ALPHV-related prosecution with Angelo Martino's 70-month sentence, ties to DigitalMint and Sygnia personnel, and notes the related guilty pleas and sentencing of co-defendants Ryan Goldberg and Kevin Martin.
Eduard Kovacs 2026.07.10 97%
This article is a direct update on the same DOJ case, adding that Angelo Martino, a former ransomware negotiator, was sentenced to 70 months in prison after pleading guilty to helping BlackCat/ALPHV by sharing victims' negotiation positions; it also notes $10 million in seized assets and that restitution will be set later.
Sergiu Gatlan 2026.07.10 100%
The article establishes a distinct law-enforcement and insider-abuse ransomware story centered on the sentencing of a former DigitalMint negotiator for participating in BlackCat attacks and leaking privileged victim data to the extortion gang.
info@thehackernews.com (The Hacker News) 2026.07.10 99%
This article appears to report the same sentencing event, describing the prison term for the former DigitalMint ransomware negotiator who aided BlackCat extortion attacks against U.S. victims.
Full page
Freedom of the Press Foundation seeks records after ICE investigated a woman for reposting a news report identifying an officer
CensorshipInformation FreedomPolicy & RegulationGovernmentMedia & EntertainmentConsumers & General PublicICEDepartment of Homeland SecurityFreedom of the Press FoundationSyracuse.comThe Minnesota Star TribuneMinnesota Star Tribune
Freedom of the Press Foundation says ICE investigated a New York woman after she reposted on Instagram a newspaper’s identification of an immigration officer involved in a fatal shooting. According to Syracuse.com, agents confronted Paigelynne Gonyea at her polling-place job and warned she could be prosecuted for threatening a federal officer; DHS later claimed she also posted the officer’s home address, which she denies. FPF filed a Freedom of Information Act request with ICE’s Office of Professional Responsibility seeking records on whether similar investigations are targeting people for resharing journalism or naming officers based on published reporting.
Why it matters: This matters to the public and the press because government investigations aimed at people who share lawful news reporting can chill speech without directly censoring a newsroom. Anyone sharing sensitive reporting about law enforcement or immigration officials should watch for official pressure tactics, and transparency from ICE will help clarify whether protected speech is being treated as criminal conduct.
Sources
Freedom of the Press Foundation 2026.07.10 96%
This is the underlying Freedom of the Press Foundation coverage of the same ICE incident, adding details that agents confronted Paigelynne Gonyea at her polling place job and demanded she sign a form letter warning of possible criminal prosecution over reposting a Minnesota Star Tribune image and name.
Caitlin Vogus 2026.07.08 100%
This article establishes a distinct press-freedom story centered on ICE's alleged investigation of a citizen for reposting a news report and FPF's FOIA effort to determine whether federal agents are targeting the sharing of journalism.
Full page
U.S. Supreme Court weighs whether Google geofence warrants violate Americans’ privacy rights in Chatrie case
Surveillance & PrivacyPolicy & RegulationGovernmentTechnology & SoftwareLegal & Professional ServicesConsumers & General PublicGoogleU.S. Supreme CourtFlock Safety
The U.S. Supreme Court is considering whether police can use geofence warrants to make Google hand over location-history data for everyone near a crime scene, a ruling that could affect millions of users. The case, Chatrie, centers on a Fourth Amendment challenge to a reverse warrant that sought unknown suspects by searching Google location data across a defined area and time window; the outcome could also shape the legality of broader reverse searches such as keyword or AI-chat queries.
Why it matters: This could change how easily law enforcement can obtain bulk location and other sensitive platform data about people who are not suspects. It matters to anyone whose phone or online accounts generate location history, and to privacy defenders, platforms, and policymakers watching limits on digital searches.
Sources
2026.07.10 84%
This article follows up on the same Chatrie Supreme Court event and adds concrete downstream implications: legal scholars say the ruling may constrain automated license plate reader searches, reverse keyword searches, cell tower dumps, and brokered location-data use, while Flock Safety argues the decision does not apply to ALPRs.
Associated Press 2026.06.30 98%
This updates the same Chatrie geofence-warrant case with the key outcome: the Supreme Court held that cellphone users retain privacy protections in Google location-history data and sent the case back to the lower court for further analysis of the specific search.
2026.05.22 100%
This article establishes a new tracked story because it centers on the pending Supreme Court decision in Chatrie as a distinct legal event with broad implications for geofence warrants and related reverse-search practices.
Full page
Dutch police say Odido customer-data breach involved a fake IT call that helped hackers access telecom systems
Breaches & Data LeaksSocial Engineering & PhishingTelecommunicationsConsumers & General PublicOdidoDutch National Police
Dutch police say the cyberattack on telecom provider Odido that exposed personal data from more than 6 million customers was helped by a Dutch-speaking man who posed as an Odido IT employee. Authorities say the February breach involved social engineering against customer service staff and access to a compromised customer contact system, which attackers then used to download customer records; police also said they took servers used to distribute the stolen data offline.
Why it matters: This matters for millions of telecom customers whose personal information was exposed and for organizations that rely on call-center staff to gate access to internal systems. Odido customers should watch for follow-on phishing or impersonation attempts, and defenders should review help-desk verification and call-back procedures.
Sources
Sergiu Gatlan 2026.07.10 98%
This is the same February Odido breach and adds Dutch police findings that there are strong indications Dutch-speaking hackers were involved, including a phone call impersonating an Odido IT employee before phishing-enabled data theft.
2026.07.09 100%
This article establishes a distinct tracked story by tying the Odido breach to a specific social-engineering tactic, identifying a suspected local accomplice, and adding law-enforcement details not represented in the existing story list.
Full page
AssuranceAmerica says data breach exposed records of 6.9 million insurance customers and drivers
Breaches & Data LeaksSocial Engineering & PhishingInsuranceConsumers & General PublicAssuranceAmerica
AssuranceAmerica disclosed that attackers broke into its systems in March 2026 and stole data tied to 6,998,886 people. The insurer says the intrusion followed malicious activity targeting one employee on March 16, with suspicious activity detected March 17. Stolen files contained names, contact details, insurance policy and account information, driver and vehicle information, claims-related data, and driver's license numbers.
Why it matters: This is a major breach affecting drivers and insurance customers whose identity and account data could now be misused for fraud or impersonation. Affected people should watch financial and insurance accounts closely, and defenders should treat employee-targeted attacks as a likely entry point.
Sources
SecurityWeek News 2026.07.10 98%
The article adds that AssuranceAmerica's breach affected roughly 7 million people, reinforcing the scale of the previously tracked incident referenced in the roundup.
Sergiu Gatlan 2026.07.09 100%
This article appears to be the first major report establishing AssuranceAmerica's March 2026 breach, its scale, and the categories of data stolen.
Full page
New Jersey court extends prior-restraint order over New Brunswick Today’s school security video to the broader press
Information FreedomCensorshipEducationMedia & EntertainmentNew Brunswick Today
A New Jersey court partially upheld an order restricting publication of a high school security video obtained by New Brunswick Today and broadened it to cover the press generally. Judge Thomas McCloskey’s July 9 order allows publication only if minors’ identities are redacted and requires the outlet to submit the edited video to the school district and court for approval before release. The footage shows a school lockdown incident involving a student with an airsoft BB gun at a New Brunswick high school.
Why it matters: This is a significant press-freedom and censorship development because it imposes prior restraint, forcing media to alter or seek approval for reporting before publication. It matters to journalists, civil-liberties groups, and the public because the order could chill reporting on school security incidents and confidential-source material.
Sources
Freedom of the Press Foundation 2026.07.10 100%
This article establishes a distinct censorship and information-freedom story centered on Judge McCloskey’s July 9 order and its expansion beyond one outlet to the press at large.
Full page
China- and India-linked hackers both breached Pakistan’s Balochistan Police and planted malware on its public complaint portal
Threat Actors & APTsBreaches & Data LeaksMalwareGovernmentBalochistan Police
Hackers linked to China and India spent more than two years inside Pakistani police networks, with Balochistan Police hit most heavily and its public complaint website used to expose visitors to fake software updates. SentinelOne says the intrusions ran from February 2024 to April 2026 and involved activity clusters using PlugX, ShadowPad, Cobalt Strike, and Remcos malware against servers tied to biometric databases, criminal case files, personnel records, and citizen-facing systems.
Why it matters: This is a significant government and privacy breach affecting police operations, sensitive biometric and personnel data, and potentially members of the public who used the complaint portal. Pakistani government defenders should investigate for the named malware families and review all systems connected to Balochistan Police’s public web services; users and staff should treat past update prompts from that portal as suspicious.
Sources
2026.07.10 98%
This is the same underlying event: separate China- and India-linked campaigns compromised Balochistan Police over 2024-2026, including tampering with the public complaint portal to deliver malware. The article adds motive context for both countries, a clearer date range, and more detail on the types of police and citizen data exposed through the affected systems.
Eduard Kovacs 2026.07.10 100%
This article establishes a distinct espionage story: dual China- and India-linked intrusions into the same Pakistani police force over 2024-2026, with malware planted on a public-facing police complaint system.
Full page
Miinto says attackers accessed its order management system and exposed customer order data
Breaches & Data LeaksSocial Engineering & PhishingRetail & E-CommerceConsumers & General PublicMiintoKlarna
Fashion marketplace Miinto told customers that an unauthorized party got into its internal order management system and may have retrieved their order data. The company said exposed data includes names, email addresses, physical addresses, phone numbers, and payment-method information such as card type or Klarna use, but not full card numbers or card verification codes. Miinto did not disclose the scale of the breach or the intrusion method.
Why it matters: Affected shoppers should be alert for phishing messages that use real order details to look convincing. Users should watch for fake Miinto emails, texts, or calls, and the company still needs to clarify how many people were affected and how the intrusion happened.
Sources
2026.07.10 100%
This article appears to be the first concrete report of Miinto's breach, including what system was accessed and what categories of customer data were exposed.
Full page
Zimbra urges customers to patch critical Classic Web Client XSS flaw in Zimbra Collaboration 10.1.19
Urgent PatchesZero-Days & CVEsGovernmentTechnology & SoftwareZimbraGoogle
Zimbra warned customers to quickly update its email and collaboration software after finding a critical flaw in the Classic Web Client that can be triggered by opening a malicious email. Zimbra fixed the stored cross-site scripting issue in Zimbra Collaboration Suite version 10.1.19; it has no CVE yet. The bug affects the Classic UI webmail interface and could let attackers steal session data, mailbox contents, or account settings.
Why it matters: Organizations using Zimbra webmail, especially the Classic interface, should treat this as urgent because a single crafted email could put user accounts and messages at risk. Update to 10.1.19 as soon as possible and limit or disable use of the Classic client if patching will take time.
Sources
Sergiu Gatlan 2026.07.10 100%
This article establishes a new tracked story because it reports Zimbra's release of version 10.1.19 to fix a newly disclosed critical webmail flaw with no CVE yet, rather than updating any existing tracked Zimbra item.
Full page
Pink extortion group uses fake help-desk calls and MFA phishing to steal Microsoft 365 and cloud data
Social Engineering & PhishingScams & FraudThreat Actors & APTsBreaches & Data LeaksHealthcareTechnology & SoftwareManufacturingTransportation & LogisticsConsumers & General PublicDefense & AerospaceMicrosoftOkta
A newly identified extortion group called Pink is calling employees while pretending to be IT support, then stealing account credentials and company data to demand payment. Palo Alto Networks Unit 42 says the group, tracked as CL-CRI-1147 and likely linked to the criminal network known as The Com, uses voice phishing and fake help-desk interactions to capture passwords and multifactor authentication (MFA) approvals, then raids services such as SharePoint, OneDrive, and Microsoft Teams. Unit 42 said Pink's leak site went live on May 31 and published domains and IP addresses tied to the campaign as indicators of compromise.
Why it matters: This matters to organizations that rely on cloud productivity tools because attackers do not need malware or software flaws if they can talk staff into handing over access. Companies should warn staff about unsolicited help-desk calls, tighten help-desk identity checks, review Microsoft 365 logs, and block or investigate the listed phishing infrastructure immediately.
Sources
Ionut Arghire 2026.07.10 95%
This is a direct update on the same underlying campaign and actor, adding Okta’s details on Pink/O-UNC-066 using voice calls, fake Microsoft Entra passkey enrollment pages, real-time operator-driven phishing, and attacker passkey registration to take over Microsoft 365 accounts.
Bill Toulas 2026.07.08 95%
This article adds specific tradecraft for the same Pink extortion activity: vishing calls that abuse Microsoft Entra passkey registration campaigns, a phishing kit that imitates Entra enrollment in real time, and post-login passkey registration under attacker control to persist access and steal SharePoint and OneDrive data.
2026.06.04 100%
The article establishes a distinct new threat story: a newly branded extortion cluster, Pink, with a named leak site, tradecraft, likely affiliation, and concrete indicators of compromise.
Full page
NHS Forth Valley investigates staff email transfer that exposed maternity patients' personal and treatment data
Breaches & Data LeaksSurveillance & PrivacyHealthcareNHS Forth ValleyInformation Commissioner's OfficePolice Scotland
NHS Forth Valley is investigating a data exposure after a staff member sent a spreadsheet from its maternity system to their personal email account, affecting about 150 women who used local maternity services. The trust said the file included data such as names, dates of birth, NHS numbers, pregnancy treatment information, and total number of children; it has notified affected patients, the Information Commissioner's Office, and Police Scotland, and says there is no evidence the data was shared further.
Why it matters: This involves highly sensitive health and identity data, so affected patients could face privacy harm even if the file was not broadly distributed. Healthcare organizations should review controls that prevent emailing patient data to personal accounts, and affected individuals should watch for follow-up scams or misuse of their information.
Sources
2026.07.10 100%
This article appears to be the first concrete report of this specific NHS Forth Valley maternity-data exposure event, with affected scope, data types, and official notifications.
Full page
Researchers show HalluSquatting attack can make AI coding assistants fetch fake packages and run attacker commands
MalwareSupply ChainTechnology & SoftwareGitHubGoogle
Researchers say attackers can abuse recurring AI hallucinations to make coding assistants download malicious repositories or packages and execute commands on a user’s machine. The 'HalluSquatting' technique pre-registers fake resource names that large language model tools such as Cursor, Windsurf, GitHub Copilot, Cline, Gemini CLI, and OpenClaw repeatedly invent during repo-cloning or skill-installation tasks, creating a scalable prompt-injection path to remote code execution and possible malware or botnet deployment.
Why it matters: Organizations using AI coding or automation assistants could be exposed even without a direct phishing message or malicious email. Teams should treat AI-suggested package and repository names as untrusted, restrict agent terminal actions, and add allowlists or review gates before assistants install software or run commands.
Sources
Eduard Kovacs 2026.07.10 100%
This article establishes a distinct story around the newly named HalluSquatting technique and its use of AI hallucinated package and repository names as a malware-delivery and agentic botnet vector, rather than updating a single previously tracked vendor-specific flaw.
Full page
Operation Muck and Load used more than 200 GitHub repositories and a malicious Go module to infect Windows systems
Supply ChainMalwareThreat Actors & APTsTechnology & SoftwareConsumers & General PublicGitHub
Attackers used a network of more than 200 GitHub repositories to trick developers and users into downloading malware on Windows. Socket says the campaign, dubbed Operation Muck and Load, used 222 lure repositories across 190 accounts and a fake Go module posing as a DNS scanning tool based on dnsub. The module secretly ran PowerShell to fetch a resolver from public dead drops including Pastebin, YouTube, Instagram, Telegram, Google Docs, and GitCode, then downloaded and launched payloads such as AsyncRAT, Quasar RAT, Vidar infostealer, spyware, trojan downloaders, and XMRig-related cryptominers.
Why it matters: This is a broad open-source supply-chain and malware delivery operation that can hit developers, enterprise users, and anyone who runs code from untrusted GitHub projects. Organizations should review use of Go packages and GitHub repositories tied to the campaign, block the listed dead-drop services where appropriate, and hunt for PowerShell-based payload delivery on Windows endpoints.
Sources
Ionut Arghire 2026.07.10 100%
This article establishes a distinct campaign centered on Operation Muck and Load, with its own GitHub repository network, malicious Go module, and malware-delivery chain rather than updating an already tracked specific incident.
Full page
Ohio county reportedly paid Kairos extortion group $1 million after 2025 data-theft attack
Scams & FraudBreaches & Data LeaksGovernmentConsumers & General PublicUnion CountyRansom-ISACKairos
A small Ohio county government reportedly paid $1 million to a cyber extortion group to stop stolen records from being published. Ransom-ISAC says Kairos stole more than 2 terabytes of data, about 1.6 million files, in a May 2025 intrusion that began with a brute-force attack, then negotiated down from a $3 million demand; the incident reportedly involved data theft and extortion rather than file encryption. The victim appears to be Union County, Ohio, which previously disclosed that 45,487 people were affected and that exposed data included Social Security numbers, passport and driver's license details, financial and payment-card data, fingerprint data, and medical information.
Why it matters: This matters because a local government reportedly lost highly sensitive resident data and paid a large ransom despite no way to verify deletion. Government organizations should review exposed remote access points for brute-force weaknesses, harden authentication, and prepare for theft-and-extortion incidents even when ransomware encryption is not used.
Sources
2026.07.09 97%
This article is the core reporting behind that event, adding leaked negotiation details, the gang’s claimed theft of more than 2 TB and 1.6 million files, the reduction from a $3 million demand to a $1 million payment, and the possible link to Union County, Ohio.
Ionut Arghire 2026.07.07 100%
This article appears to be the first tracked item establishing the underlying event: the suspected Union County, Ohio, 2025 intrusion and subsequent $1 million payment to the Kairos extortion group.
Full page
OpenMandriva says contributor deleted repositories and pushed a harmful package change after internal dispute
Supply ChainTechnology & SoftwareConsumers & General PublicOpenMandrivaGitHub
OpenMandriva says a contributor tried to damage the Linux distribution project by deleting repositories and publishing a package change that could have harmed users' systems. The project says repositories on GitHub were wiped in part and an empty package was pushed to the Cooker development branch to obsolete GNOME and COSMIC desktop packages. OpenMandriva is restoring affected data and auditing systems for any other unauthorized changes.
Why it matters: This matters because a trusted contributor account allegedly made destructive changes inside a software project, showing how insider or maintainer abuse can become a supply-chain risk for downstream users. OpenMandriva users and mirrors should watch for project guidance, avoid unreviewed development-branch updates, and verify package integrity while the audit continues.
Sources
Bill Toulas 2026.07.09 100%
This article appears to be the first clear report of the OpenMandriva repository deletion and harmful package publication incident, establishing a distinct new software supply-chain sabotage story.
Full page
U.S. House leaders unveil compromise KIDS Act bill with age-verification and AI chatbot rules but no duty-of-care requirement
CensorshipSurveillance & PrivacyPolicy & RegulationTechnology & SoftwareMedia & EntertainmentConsumers & General PublicCongressU.S. House of RepresentativesEFF
House leaders released a bipartisan kids online safety bill that would require age verification for porn sites, bar minors from using disappearing messages, and force AI chatbots to disclose that they are not human. The compromise package also includes a data broker registry and some preemption of state laws, but it drops the long-debated 'duty of care' provision that would have required platforms to reduce harms tied to product design and algorithms.
Why it matters: This could materially change how online platforms verify ages, handle children’s data, and design youth-facing features, with direct privacy and free-expression implications for both minors and adults. Platforms, privacy advocates, and users should watch the bill’s next House and Senate steps closely because it could create new compliance duties and broader identity-checking requirements.
Sources
India McKinney 2026.07.09 92%
This updates the same underlying event by adding that the House has now passed the KIDS Act package 267-117 and sent it to the Senate, while highlighting continued concerns over mandatory age checks, identity verification, and speech restrictions.
2026.06.30 94%
This updates the same underlying federal legislation by reporting that the House has now passed the compromise KIDS Act and detailing the bill’s political outlook in the Senate, along with criticism over its age-verification and privacy provisions.
Joe Mullin 2026.06.25 93%
This article adds civil-liberties and implementation detail on the same KIDS Act package, specifically how the bill’s 'knows or should have known' standard could pressure platforms to verify ages broadly, use facial age estimation or ID checks, and alter private messaging and moderation practices.
2026.06.23 100%
This article establishes a distinct policy story: the House’s release of a compromise KIDS Act package with specific online safety, age-verification, and AI disclosure provisions, and a notable omission of the duty-of-care standard.
Full page
Helix vishing group steals Microsoft SharePoint data through fake manager calls, device-code phishing, and MFA app enrollment
Social Engineering & PhishingBreaches & Data LeaksThreat Actors & APTsMicrosoft
A newly identified extortion group called Helix is tricking employees into giving attackers access to Microsoft 365 accounts, then stealing files from SharePoint to extort victim organizations. ReliaQuest says the group uses voice phishing (phone calls pretending to be a manager), device-code phishing to capture account access, and multi-factor authentication abuse by enrolling a rogue authenticator app for persistence. After access, Helix enumerates SharePoint content and bulk-downloads files, with infrastructure and tradecraft suggesting possible overlap with the now-defunct BlackFile group and similarities to ShinyHunters campaigns.
Why it matters: Organizations using Microsoft 365 and SharePoint should treat this as an active account-takeover and data-theft threat, especially if staff can be reached by phone or Teams and device-code login flows are enabled. The concrete action is to disable device-code authentication where possible, restrict SharePoint access to managed devices, harden MFA enrollment, and warn employees about calls claiming to be managers or IT staff.
Sources
Bill Toulas 2026.07.09 100%
This article establishes Helix as a distinct named data-extortion actor with a defined intrusion pattern centered on vishing-led Microsoft 365 compromise and SharePoint data theft, rather than merely updating one victim-specific breach.
Full page
Freedom of the Press Foundation sues DOJ for records on alleged concealment of press protections in FBI raid on Washington Post reporter Hannah Natanson
Information FreedomPolicy & RegulationSurveillance & PrivacyGovernmentMedia & EntertainmentNonprofits & NGOsLegal & Professional ServicesDOJFBIWashington PostFreedom of the Press FoundationDepartment of JusticeVirginia State Bar
Freedom of the Press Foundation sued the U.S. Department of Justice under the Freedom of Information Act to uncover whether DOJ hid legal protections for journalists when it sought a warrant to raid Washington Post reporter Hannah Natanson’s home. The suit centers on the Privacy Protection Act of 1980, which generally bars newsroom and journalist-home searches, and follows a judge’s February finding that DOJ’s omission of the law from the warrant process seriously undermined confidence in the government’s disclosures.
Why it matters: This matters to journalists, sources, and the public because it suggests federal investigators may be sidestepping legal safeguards meant to stop raids on reporters. The case could reveal whether the Natanson raid was an isolated abuse or part of a broader DOJ practice with implications for press freedom and government surveillance powers.
Sources
Seth Stern 2026.07.09 93%
This is the same underlying event: the FBI raid on Washington Post reporter Hannah Natanson and the alleged omission of the Privacy Protection Act in the warrant process. The article adds that the Virginia State Bar declined to investigate the prosecutor, that the complaint was resubmitted, and that judges later criticized the omission and said it may have affected approval of the warrant.
Lauren Harper 2026.06.08 100%
This article establishes a distinct new development: a federal FOIA lawsuit seeking records on whether DOJ systematically concealed the Privacy Protection Act from judges in journalist-search warrant cases tied to the Hannah Natanson raid.
Full page
GitHub changes npm defaults in npm 12 to stop auto-running install scripts and block risky remote dependency paths
Supply ChainPolicy & RegulationTechnology & SoftwareGitHubnpm
GitHub says npm 12 will no longer run package install scripts by default, changing behavior that has long let malicious dependencies execute code on developer machines and continuous integration systems. The July release will disable automatic preinstall, install, and postinstall lifecycle scripts unless explicitly allowed with allow-scripts, turn --allow-git off by default, and set allow-remote to none to block remote URL dependency downloads; the move follows repeated supply-chain abuse, including Shai-Hulud-style malicious packages.
Why it matters: Developers and organizations that use npm may need to update build and install workflows before npm 12 ships, but the change should reduce one of the ecosystem's biggest package-based malware risks. Security teams should test projects now, identify legitimate packages that need script exceptions, and tighten CI defaults.
Sources
info@thehackernews.com (The Hacker News) 2026.07.09 97%
This article appears to cover the same npm 12 security-defaults change, specifically that install scripts are disabled by default to reduce supply-chain abuse.
Ionut Arghire 2026.06.13 98%
This article is another report on the same npm 12 security change, adding specific detail that npm install will stop running preinstall, install, and postinstall scripts from dependencies by default, and that Git and remote URL dependency resolution will also be blocked unless explicitly allowed.
Bill Toulas 2026.06.10 98%
This article directly covers GitHub's announced npm 12 security changes, adding specifics on which install hooks and dependency sources will require explicit approval and noting npm 11.16.0 warnings to help developers prepare.
2026.06.10 100%
This article establishes a distinct ecosystem-level security hardening event: npm/GitHub is changing default package-manager behavior in response to supply-chain abuse, rather than detailing a single compromise or malware campaign.
Full page
Forg365 phishing service targets Microsoft 365 accounts with device-code login tricks and cookie-stealing browser extension
Social Engineering & PhishingScams & FraudTechnology & SoftwareConsumers & General PublicMicrosoft
Researchers identified a phishing-as-a-service platform called Forg365 that is built to steal Microsoft 365 accounts and keep access to them after login. The service combines OAuth device-code phishing and adversary-in-the-middle (a login proxy that captures session tokens), uses AI inside its operator dashboard to generate lures, and includes a Chrome-, Edge-, and Brave-compatible extension called ForgCookie that refreshes stolen Microsoft single sign-on cookies for persistent access.
Why it matters: Microsoft 365 users and administrators should treat this as an active account-takeover threat, especially because it abuses legitimate Microsoft authentication flows instead of only stealing passwords. Organizations should harden device-code and OAuth app controls, review suspicious consent grants and session tokens, and warn users not to enter Microsoft verification codes from unsolicited emails.
Sources
Bill Toulas 2026.07.09 100%
This article establishes a distinct new phishing platform, Forg365, with its own infrastructure, attack methods, and post-compromise browser extension; it is not the same underlying event as the separately tracked Kali365 campaign.
Full page
Latvia says ransomware attack on state forestry company LVM stole credentials, keys, and internal data and disrupted customer services for weeks
RansomwareBreaches & Data LeaksGovernmentManufacturingLatvijas Valsts MeziCERT.LVOlpha
Latvia's state-owned forestry company LVM is still restoring systems weeks after a ransomware attack knocked customer and contractor services offline. Latvian authorities said the attackers likely spent more than a week in the network and exploited an unpatched vulnerability in software that had not been updated for two years. CERT.LV said about 44 GB of data was leaked, including internal documents, email, code repositories, digital certificates, cryptographic keys, and user credentials.
Why it matters: This is a significant ransomware and data-theft incident affecting a major state-owned enterprise, with possible downstream risk from leaked credentials and cryptographic material. Organizations in Latvia, especially public-sector and state-linked entities, should review exposure, rotate affected secrets and certificates, and urgently patch internet-facing systems.
Sources
2026.07.09 100%
This article establishes the core facts of the LVM ransomware event: prolonged service disruption, likely initial access through a long-unpatched vulnerability, exfiltration and public leakage of sensitive data, and attribution by Latvian authorities to a foreign financially motivated ransomware group.
Full page
UK launches NCSC Cyber Shield plan to use agentic AI for national cyber defense
Policy & RegulationGovernmentEnergy & UtilitiesTelecommunicationsNCSCGCHQUK government
The UK government has outlined a new national cyber defense program that aims to use agentic artificial intelligence to find, fix, and respond to cyber threats faster across the country. The National Cyber Security Centre said the July 7 plan, called Cyber Shield, is meant to support national-scale scanning, mitigation, coordinated detection and response, and AI-driven vulnerability discovery and remediation, and it is seeking partners from academia, critical national infrastructure, AI labs, and the cyber defense sector.
Why it matters: This matters because it shows the UK is trying to build machine-speed national cyber defense before autonomous AI-enabled attacks become common. For defenders and critical infrastructure operators, the immediate implication is policy and planning rather than patching: track how NCSC turns this into operational requirements, partnerships, and expectations.
Sources
Kevin Townsend 2026.07.09 100%
This article appears to be the first concrete reporting here on the UK's July 7, 2026 Cyber Shield announcement and the related national push to integrate agentic AI into cyber defense.
Full page
Palo Alto Networks patches 13 vulnerabilities in PAN-OS and Prisma Access Agent, including high-urgency firewall flaw CVE-2026-0288
Urgent PatchesZero-Days & CVEsTechnology & SoftwarePalo Alto Networks
Palo Alto Networks released fixes for 13 security flaws affecting its firewall and remote-access products. The most serious issue, CVE-2026-0288, is a high-severity PAN-OS buffer-overflow flaw that can let an unauthenticated attacker with network access crash a firewall and potentially run code via specially crafted traffic against the User-ID Terminal Server Agent feature. Other patched flaws affect PAN-OS and Prisma Access Agent, including command injection, server-side request forgery (making the product send unauthorized internal requests), authentication bypass, information disclosure, privilege escalation, and VPN traffic interception or data loss prevention bypass.
Why it matters: Organizations using Palo Alto firewalls or Prisma Access Agent should review the advisories and patch promptly, especially if exposed management or TSA-related access is broader than best practice. Even though Palo Alto says it has not seen active exploitation, firewall and VPN flaws are routinely targeted once patches are available.
Sources
Eduard Kovacs 2026.07.09 100%
This article appears to be the first item here establishing the specific July 9, 2026 Palo Alto Networks advisory set for 13 vulnerabilities, centered on PAN-OS CVE-2026-0288 and related PAN-OS and Prisma Access Agent fixes.
Full page
Microsoft says three publicly dumped Windows zero-days are already being exploited after Nightmare Eclipse disclosures
Policy & RegulationZero-Days & CVEsRansomwareUrgent PatchesTechnology & SoftwareConsumers & General PublicGovernmentMicrosoftCISA
A researcher’s public release of six Windows zero-days has already led attackers to exploit three of them, and Microsoft says more unpatched flaws remain. Microsoft named the bugs as RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma; it said BlueHammer, RedSun, and UnDefend saw attacks after proof-of-concept exploit code was posted, while YellowKey is tracked as CVE-2026-45585 and, along with GreenPlasma and MiniPlasma, still lacks a fix.
Why it matters: Windows defenders may have little time between public disclosure and real-world attacks, especially when proof-of-concept exploit code is available. Organizations should review Microsoft mitigations immediately, monitor for compromise tied to these bug names and CVE-2026-45585, and prioritize hardening or temporary workarounds where patches do not yet exist.
Sources
2026.07.09 35%
The article provides context on Nightmare Eclipse's broader campaign of public Windows zero-day disclosures, but its main news value is the specific fix for RoguePlanet rather than the wider disclosure spree.
Sergiu Gatlan 2026.06.30 74%
This article adds that one of the publicly dumped Windows zero-days from the Nightmare Eclipse disclosures—BlueHammer / CVE-2026-33825 in Microsoft Defender—is now specifically flagged by CISA as being exploited by ransomware gangs, strengthening the exploitation and impact picture for that broader disclosure wave.
2026.06.11 41%
The piece also fits the broader Nightmare Eclipse disclosure spree by noting GreatXML and RoguePlanet were released after the earlier six dumped Windows zero-days, but its main focus is the separate GreatXML event rather than the already-exploited trio.
2026.06.10 66%
The article also materially updates the broader Nightmare Eclipse disclosure saga by identifying RoguePlanet as the seventh public Microsoft zero-day from the same researcher and connecting it to the earlier pattern in which previously dumped flaws were later exploited before patching.
Sergiu Gatlan 2026.06.10 73%
The article is tied to the same Nightmare Eclipse disclosure wave and adds that Microsoft patched GreenPlasma and MiniPlasma, two of the publicly dumped Windows zero-days, during June 2026 Patch Tuesday.
Lawrence Abrams 2026.06.09 72%
This article adds another public zero-day release by the same researcher, Nightmare Eclipse, extending the ongoing disclosure dispute with Microsoft and showing a newly published Microsoft Defender local privilege-escalation exploit that appears to work on fully patched Windows 10 and 11 systems.
BrianKrebs 2026.06.09 87%
The piece ties two June Patch Tuesday zero-days to the same Nightmare Eclipse disclosure campaign, specifically connecting GreenPlasma to CVE-2026-45586 and YellowKey to CVE-2026-50507, while noting the researcher plans more releases.
Eduard Kovacs 2026.06.03 93%
This article covers the same underlying event: the Nightmare Eclipse/Chaotic Eclipse public disclosure of multiple unpatched Microsoft vulnerabilities, including RedSun, UnDefend, BlueHammer, and YellowKey. It adds new reporting on Microsoft's response to backlash over language seen as threatening legal action, clarifies that Microsoft says it does not intend to pursue action against good-faith researchers, and provides more detail on the researcher-vendor dispute and Microsoft's takedown of the researcher's portal and GitHub access.
2026.06.02 95%
This article covers the same underlying Nightmare-Eclipse Windows zero-day disclosure saga and adds new information that Microsoft publicly softened its rhetoric, said it does not intend to pursue legal action against researchers publishing security research, and acknowledged criticism over its earlier response after some of the dumped flaws were exploited in the wild.
Bruce Schneier 2026.06.02 95%
This article is about the same Nightmare Eclipse disclosure campaign and adds that Microsoft has threatened legal action against the anonymous researcher behind the published Windows exploits.
2026.06.01 93%
This article directly updates the Nightmare Eclipse Windows zero-day disclosure saga by adding Microsoft's walk-back: it says it does not intend to pursue legal action against researchers, acknowledges some researcher interactions fell short, and the source also notes Nightmare Eclipse plans to release another Secure Boot flaw that could bypass BitLocker and affect confidential VMs.
2026.05.29 95%
This directly updates the same Nightmare Eclipse Windows zero-day disclosure campaign with Microsoft's first formal response, confirmation that the researcher threatened another release on July 14, and added context on GitHub and Blogger pages being taken down.
2026.05.28 100%
This article establishes a broader underlying event than the existing YellowKey story: a coordinated cluster of six Windows zero-day disclosures by Nightmare Eclipse, with three already exploited and multiple flaws still unpatched.
Full page
Microsoft patches Windows Defender zero-day RoguePlanet (CVE-2026-50656) that could give attackers SYSTEM access
Urgent PatchesZero-Days & CVEsTechnology & SoftwareConsumers & General PublicMicrosoft
Microsoft has released a fix for a Windows Defender zero-day called RoguePlanet that could let attackers gain full SYSTEM-level control on Windows 10 and Windows 11 devices. The flaw is tracked as CVE-2026-50656 and was publicly disclosed with proof-of-concept code by the researcher using the handle Nightmare Eclipse after June 2026 Patch Tuesday. Microsoft says the issue is fixed in Microsoft Malware Protection Engine version 1.1.26060.3008, the scanning engine used by Defender and related security products.
Why it matters: This affects widely used built-in Windows security software on fully patched consumer and enterprise systems, so defenders should verify the updated Malware Protection Engine version is installed as soon as possible. Public exploit code exists, which raises the risk of copycat abuse even if exploitation is unreliable.
Sources
2026.07.09 97%
This article is a direct update on the same RoguePlanet event, adding that Microsoft has now fixed CVE-2026-50656 via a Microsoft Malware Protection Engine update rather than Patch Tuesday and advising customers to run the latest engine version.
Eduard Kovacs 2026.07.09 97%
This article directly updates the same event by reporting that Microsoft has now rolled out the fix for RoguePlanet via a Microsoft Malware Protection Engine update, after the zero-day exploit was published and after Microsoft's earlier advisory.
info@thehackernews.com (The Hacker News) 2026.07.09 99%
This article covers the same underlying event: Microsoft releasing a fix for the RoguePlanet Windows Defender zero-day, tracked as CVE-2026-50656, which can be exploited to gain SYSTEM privileges on Windows 10 and 11.
Sergiu Gatlan 2026.07.09 100%
The article establishes a distinct new event: Microsoft has now shipped the patch for RoguePlanet, a specific Windows Defender zero-day tracked as CVE-2026-50656, rather than only discussing public disclosure of other Nightmare Eclipse flaws.
Full page
European Commission takes Ireland, Spain, France, and the Netherlands to court over delayed NIS2 cybersecurity law rollout
Policy & RegulationHealthcareGovernmentEnergy & UtilitiesTransportation & LogisticsEuropean CommissionENISAIrelandSpainFranceNetherlands
The European Commission has referred Ireland, Spain, France, and the Netherlands to the EU’s top court for failing to put the NIS2 cybersecurity directive into national law. NIS2 sets minimum cybersecurity, risk-management, and incident-reporting rules for 18 critical sectors including hospitals, energy, transport, and public administration; the four countries are more than 20 months past the October 2024 transposition deadline, and the Commission is seeking lump-sum and daily fines until they comply.
Why it matters: Organizations in affected EU countries face continued legal uncertainty around security and incident-reporting duties for critical services. This matters to governments, regulated operators, and suppliers because NIS2 underpins how Europe enforces baseline cyber defenses for critical infrastructure.
Sources
2026.07.09 100%
This article establishes a distinct enforcement milestone in the NIS2 rollout: the Commission has moved from warnings and delays to formal court action and proposed financial penalties against specific member states.
Full page
KDDI says breach of managed email platform may have exposed 14.2 million users’ email addresses and passwords
Zero-Days & CVEsBreaches & Data LeaksTelecommunicationsConsumers & General PublicKDDISTNetJCOMChubu TelecommunicationsNiftyBIGLOBE
KDDI says attackers broke into an email service it runs for itself and other Japanese internet providers, potentially exposing data tied to up to 14.2 million users. The company said it detected unauthorized access on June 17 and believes the attackers exploited a vulnerability in third-party software used by the platform. KDDI says affected data may include email addresses, hashed and encrypted passwords, and some personal information, including for dormant or canceled accounts. Customers of STNet, JCOM, Chubu Telecommunications, Nifty, and BIGLOBE may also be affected.
Why it matters: This is a large credential-exposure incident affecting consumers who may now face phishing, account-takeover attempts, and identity fraud. Affected users should watch for provider notices, reset passwords anywhere they were reused, and be cautious of emails or calls claiming to be from their ISP or mail provider.
Sources
Ionut Arghire 2026.07.09 97%
This source updates the same KDDI managed email-platform breach, adding a refined impact figure of over 12 million affected people, saying the intrusion occurred on June 17, naming five impacted ISPs, and stating that attackers exploited a zero-day in third-party software for which a patch is still being developed.
Sergiu Gatlan 2026.07.08 98%
This is the same KDDI managed email-platform breach and adds updated confirmed impact numbers, naming 12,233,087 exposed email addresses and 7,616,173 passwords, plus new detail that the intrusion began on May 16 via a third-party zero-day that was still unknown to the vendor as of June 17.
2026.07.07 97%
This is the same KDDI managed-email-platform breach and adds finalized forensic findings: 12.2 million email addresses and 7.6 million passwords were exposed across five Japanese ISPs, with KDDI attributing the intrusion to exploitation of a third-party software vulnerability and saying affected providers are enforcing password resets.
SecurityWeek News 2026.07.03 96%
This article repeats the key scope of the KDDI breach and names the five affected ISP operators, reinforcing that the incident likely exposed email addresses and passwords for roughly 14.22 million people.
2026.07.01 90%
This is the same KDDI managed-email breach and adds that attackers exploited a vulnerability in third-party software, that KDDI says it blocked the intrusion quickly, and that the affected downstream providers include STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE.
2026.06.24 100%
This article appears to be the first tracked report of KDDI's disclosure that unauthorized access to its managed email platform may have exposed credentials and personal data for users across multiple Japanese ISPs.
Full page
GhostLock Linux kernel flaw CVE-2026-43499 lets local attackers gain root on major distributions
Zero-Days & CVEsTechnology & SoftwareLinuxGoogle
Researchers published technical details and exploit code for GhostLock, a 15-year-old Linux kernel bug that can let a local attacker take full control of affected systems. Tracked as CVE-2026-43499, the use-after-free flaw was introduced in Linux 2.6.39 and affects major distributions since 2011; Nebula Security says it can be exploited for local privilege escalation to root and for container escape, and the bug was patched in April 2026.
Why it matters: Organizations and users running Linux systems should verify that April 2026 kernel fixes are installed, especially on shared systems and container hosts. Public exploit code raises the risk of copycat attacks because a local foothold could become full root access.
Sources
Ionut Arghire 2026.07.09 100%
This article appears to be the establishing coverage of GhostLock as a named Linux kernel vulnerability with CVE-2026-43499, exploit code, affected-version history, and demonstrated root/container-escape impact.
Full page
Mount Royal University says hackers stole files and wiped internal drives after June network breach
Breaches & Data LeaksRansomwareEducationMount Royal University
Mount Royal University in Calgary says hackers broke into its network, stole files from a shared storage drive used by students and staff, and deleted data from university systems. The university says the June 17 attack disrupted online services, internet access, and internal systems; data was confirmed stolen from certain folders on its H drive, while a separate J drive holding departmental data was wiped, with no current evidence it was copied first. The CMD Organization extortion group claimed the attack, published sample files including passport scans, and demanded 30 bitcoin.
Why it matters: Students, employees, and former staff may face identity and privacy risks, while the university may lose some data permanently. Affected people should watch for direct breach notices and consider credit and identity monitoring; defenders in education should review file-share access, backup resilience, and extortion response plans.
Sources
Ionut Arghire 2026.07.09 98%
This is a direct update to the same Mount Royal University incident, adding that MRU has now confirmed a ransomware attack, confirmed exfiltration from affected H drive folders, said the second erased storage system was deleted but not exfiltrated, and noted CMD Organization's claimed 10TB theft and $1.9 million ransom demand.
Bill Toulas 2026.07.08 100%
This article appears to be the first tracked item establishing the Mount Royal University breach as a distinct incident with confirmed theft, destructive data wiping, and a public extortion claim by CMD Organization.
Full page
INTERPOL says Operation First Light 2026 led to 5,811 arrests and $293 million seized in global anti-fraud crackdown
Scams & FraudSocial Engineering & PhishingConsumers & General PublicFinance & BankingGovernmentINTERPOLEuropolChina Ministry of Public Security
INTERPOL says police in 97 countries arrested 5,811 suspects and seized $293 million in a coordinated crackdown on online fraud and related money laundering. Operation First Light 2026 ran from January 15 to April 30 and targeted business email compromise, sextortion, impersonation, romance, and investment scams; authorities said they identified more than 142,000 victims, blocked 31,014 bank accounts, reviewed 152,808 cases, and identified 15,606 additional suspects.
Why it matters: This shows the scale of social-engineering fraud hitting consumers, businesses, and governments worldwide. People and organizations should treat unsolicited payment requests, investment pitches, romance approaches, and account-verification messages with caution, and strengthen payment verification and anti-fraud controls.
Sources
Sergiu Gatlan 2026.07.09 100%
This article establishes a distinct new story around INTERPOL's Operation First Light 2026, a specific multinational anti-fraud enforcement action with named scope, timing, arrest totals, and seizure figures.
Full page
GhostApproval flaw in Amazon Q, Cursor, Google Antigravity and other AI coding agents can escape workspace boundaries
Zero-Days & CVEsTechnology & SoftwareAmazonAnthropicCursorGoogleAugmentWindsurf
Researchers found that several major AI coding assistants can be tricked into editing sensitive files outside a project folder, which can let an attacker gain control of a developer’s machine. Wiz calls the issue pattern 'GhostApproval' and says Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf were affected; the attack abuses symbolic links (filesystem shortcuts) in malicious repositories so an agent follows README instructions and writes to targets such as ~/.ssh/authorized_keys. Amazon, Cursor, and Google reportedly fixed the issue, while Augment and Windsurf had not patched at publication and Anthropic reportedly treated it as outside its threat model.
Why it matters: Developers and enterprises using AI coding agents may be giving those tools a path to overwrite sensitive local files and open persistent access from a booby-trapped repository. Users should update affected tools, restrict agent permissions, and avoid letting coding agents automatically follow setup instructions from untrusted repositories.
Sources
Eduard Kovacs 2026.07.09 99%
This article is a direct report on the same GhostApproval event, adding vendor response details: AWS, Google, and Cursor have patched; Anthropic says it added mitigations and does not classify the issue as a vulnerability; Augment and Windsurf had acknowledged reports but had not yet released fixes. It also reiterates the symlink-based attack path and the user-confirmation prompt weakness that can lead to remote code execution on developer machines.
2026.07.08 100%
This article appears to be the first broad report establishing the GhostApproval vulnerability pattern across multiple AI coding agents, with concrete affected products, exploitation mechanics, and patch status.
Full page
Google Chrome 150 security update fixes 27 vulnerabilities, including two critical use-after-free bugs
Urgent PatchesConsumers & General PublicTechnology & SoftwareGoogle
Google released Chrome 150 with security fixes for 27 vulnerabilities affecting users on Windows, macOS, and Linux. The update patches two critical use-after-free memory-safety flaws in Chrome’s Ozone and Views components, plus 11 other use-after-free bugs and additional issues including integer overflow, out-of-bounds read and write, and insufficient validation. Affected versions were updated to 150.0.7871.114/.115 for Windows and macOS and 150.0.7871.114 for Linux.
Why it matters: Chrome is widely used, so even non-exploited critical browser bugs matter because they can quickly become useful to attackers once patch details are public. Users and organizations should update Chrome promptly across managed and personal devices.
Sources
Ionut Arghire 2026.07.09 100%
This article establishes a distinct new Chrome 150 patch event that is separate from the already tracked Chrome 148, 149, and 151 update stories.
Full page
Hidden Tenda router firmware backdoor CVE-2026-11405 can give attackers administrator access
Zero-Days & CVEsConsumers & General PublicTechnology & SoftwareTendaCERT/CC
A hidden backdoor in several Tenda router firmware builds can let someone log into the device as an administrator if they know a separate undocumented password. CERT/CC says CVE-2026-11405 is in the /bin/httpd login() function, where failed normal authentication falls back to checking the plaintext password against the sys.rzadmin.password configuration value and then grants admin access regardless of username. Affected models include Tenda FH1201, W15E, AC10, AC5, and AC6 V2 on listed firmware versions, and no patch is available.
Why it matters: Home and small-office users could have their routers taken over, which can let attackers change network settings, weaken security, and potentially enable wider compromise of devices behind the router. If you use one of the affected models, disable remote web management now and reduce local exposure until Tenda releases a fix.
Sources
Ionut Arghire 2026.07.09 99%
This article is a direct report on the same Tenda firmware backdoor event, adding details from CERT/CC about the flawed login logic, affected device types beyond routers, lack of a vendor patch, and mitigations such as disabling remote web management.
Bill Toulas 2026.07.07 100%
This article appears to be the initial broad reporting on CVE-2026-11405, a distinct Tenda router backdoor disclosure with affected models, technical details, and mitigations, and it does not match an existing tracked story.
Full page
China-linked hackers exploit Roundcube flaws CVE-2024-42009 and CVE-2025-49113 to spy on U.S. and Canadian researchers
Zero-Days & CVEsThreat Actors & APTsSocial Engineering & PhishingMalwareEducationGovernmentRoundcube
A suspected China-aligned hacking group has been breaking into vulnerable Roundcube webmail servers at U.S. and Canadian universities to steal logins and plant backdoors. Proofpoint says the campaign, tracked as UNK_MassTraction, has run since May and targets physics, engineering, astrophysics, particle-physics, and national-security-related research organizations. Attackers use emails that trigger Roundcube cross-site scripting flaw CVE-2024-42009 to load the IceCube stealer, then abuse deserialization flaw CVE-2025-49113 to try to install the SquareShell PHP web shell or the VShell backdoor.
Why it matters: Universities and research groups handling sensitive science and national-security work may have had email accounts and mail servers compromised. Organizations using Roundcube should patch immediately, review mail-server logs for exploitation, and reset credentials and session cookies for potentially affected users.
Sources
2026.07.08 97%
This is the same underlying campaign and adds reporting that Proofpoint directly observed fewer than 10 universities targeted, estimates a few dozen total victims, says the campaign likely remains ongoing, and provides additional detail on the target set and IceCube-to-SquareShell/VShell attack chain.
Bill Toulas 2026.07.08 100%
This article establishes a distinct tracked story by tying active espionage intrusions to specific Roundcube CVEs, named malware payloads, and a defined victim set in academia and national-security-related research.
Full page
Victims of Greece’s Predator spyware scandal sue Intellexa and associates for €8 million over phone hacking
Surveillance & PrivacyPolicy & RegulationGovernmentMedia & EntertainmentIntellexaCytroxKrikelMetaHellenic Police
Eight people targeted in Greece’s Predator spyware scandal have sued Intellexa SA and 13 associated individuals, seeking €1 million each in damages over alleged phone infections in 2020 and 2021. The case centers on Predator, commercial spyware sold by the Intellexa consortium, which investigators linked to campaigns against at least 87 high-profile people in Greece using SMS lures with malicious links that exploited Chrome and Android zero-day vulnerabilities; the suit follows earlier Greek convictions of key figures tied to Intellexa and vendor Krikel.
Why it matters: This is a significant accountability step in one of Europe’s most important commercial-spyware abuse cases, affecting journalists, officials, and other public-interest targets. It matters for privacy, press freedom, and defenders tracking how spyware vendors, governments, and courts respond to unlawful surveillance.
Sources
2026.07.08 98%
This article is a direct report on the same lawsuit, adding that eight Greek victims filed the case on Tuesday, named categories of plaintiffs, cited the requested compensation at about €7.6 million, and noted the April 2027 trial timeline alongside Intellexa founder Tal Dilian’s public response.
2026.07.07 100%
This article establishes a distinct legal and accountability development in the Predatorgate spyware scandal: a new civil lawsuit by named victims against the spyware maker and associated individuals.
Full page
Block will pay $45 million to states over Cash App security and fraud-protection failures
Scams & FraudPolicy & RegulationSurveillance & PrivacyFinance & BankingConsumers & General PublicBlockCash App
Block, the owner of Cash App, agreed to pay $45 million to 46 U.S. states over allegations that the app misled users about its security and left them exposed to scams. State attorneys general said Cash App lacked basic identity checks such as Social Security number or date-of-birth requirements at signup, allowed multiple accounts per person, had no real customer-support phone line until 2021, and failed to adequately investigate fraud or help victims recover funds. The settlement also requires 24/7 live support and reinforces a related 2025 federal consent order.
Why it matters: This matters to millions of payment-app users because weak verification and poor support can make scams easier and recovery harder after money is stolen. Cash App users should be cautious of support-number scams and review account protections, while regulators and fintech firms may face higher pressure to strengthen fraud controls.
Sources
2026.07.08 100%
This article establishes a new tracked story around a multistate settlement specifically tied to Cash App's alleged security, verification, and fraud-response failures.
Full page
Fake Paysafe, Skrill, and Neteller SDK packages on npm and PyPI stole developer credentials and API keys
Supply ChainMalwareBreaches & Data LeaksFinance & BankingTechnology & SoftwareRetail & E-CommerceHospitality & TravelCryptocurrency & BlockchainPaysafeSkrillNetellernpmPyPIAWS
Attackers uploaded fake software packages for Paysafe, Skrill, and Neteller to npm and PyPI, putting developers and any systems that ran them at risk of credential theft. Socket identified 17 malicious packages: 13 on npm with versions 1.0.0 through 1.0.3 and 4 on PyPI at version 1.0.0. The packages imitated legitimate payment software development kits, exposed expected APIs, returned fake success responses, and exfiltrated Paysafe API keys, AWS keys, GitHub tokens, npm tokens, passwords, and host metadata to attacker infrastructure on AWS.
Why it matters: Developers, payment integrations, and continuous integration systems may have had secrets stolen just by importing or running these packages. Organizations that installed them should remove the packages, audit dependency trees and build logs, and rotate exposed credentials immediately.
Sources
Bill Toulas 2026.07.08 100%
This article establishes a distinct cross-ecosystem package-repository compromise targeting developers who use payment SDKs, with a specific package set, credential-theft behavior, and affected brands not covered by an existing tracked story.
Full page
Researchers show GitHub Copilot can be jailbroken through normal coding workflow steps to produce harmful instructions
Technology & SoftwareTechnology & SoftwareConsumers & General PublicGitHubMicrosoftAnthropicGoogle
Researchers found that GitHub Copilot can be pushed past its safety rules if a harmful request is split across ordinary software-development steps instead of asked directly in chat. Alan Turing Institute researchers tested Copilot in Visual Studio Code with Anthropic Claude Sonnet 4.6, Claude Haiku 4.5, Google Gemini 3.1 Pro, and Gemini 3.5 Flash, using 204 harmful prompts from benchmark sets; direct chat prompts were refused in 808 of 816 runs, but workflow-based prompts succeeded in 816 of 816 runs by having the model process harmful content as code or data artifacts.
Why it matters: Teams using AI coding assistants should not assume chat refusal behavior means the tool is safe inside real development workflows. Organizations may need stricter guardrails, monitoring, and usage policies for coding agents, especially where they can generate scripts, pipelines, or artifacts from untrusted inputs.
Sources
2026.07.08 100%
This article establishes a distinct story about a specific workflow-level jailbreak technique demonstrated against GitHub Copilot rather than a patch, CVE, or previously tracked coding-agent prompt-injection issue.
Full page
Taiwan charges two businessmen over LINE account rentals tied to a Chinese espionage phishing campaign
Threat Actors & APTsSocial Engineering & PhishingGovernmentEducationMedia & EntertainmentNonprofits & NGOsLINEICIJTaiwan Ministry of Justice Investigation BureauXiamen Empress Information Technology
Taiwan says two local businessmen helped a China-linked espionage campaign by leasing LINE accounts that were used to trick politicians, journalists, academics, and civil society targets. Taiwan's Ministry of Justice Investigation Bureau alleges the accounts were supplied to Xiamen Empress Information Technology, then used to impersonate reporters, including people tied to ICIJ, and push malware disguised as encrypted communications software in interview and article-invitation lures.
Why it matters: This shows a real-world supply chain for state-linked social-engineering attacks: attackers bought trusted local messaging accounts to make their phishing look legitimate. People in government, media, academia, and NGOs in Taiwan and diaspora communities should be wary of unsolicited interview requests and software downloads sent over messaging apps.
Sources
2026.07.08 100%
This article establishes a distinct new story because it adds official Taiwanese charges and operational details about a China-linked espionage campaign using rented LINE accounts and journalist impersonation, rather than updating an already tracked identical event.
Full page
Accenture confirms breach after hacker offers stolen source code and keys for sale
Breaches & Data LeaksTechnology & SoftwareLegal & Professional ServicesAccentureAzure DevOpsMicrosoft
Accenture says it suffered a security breach after a threat actor began selling allegedly stolen company data online. The actor known as "888" claims to have taken about 35 GB of data in July 2026, including source code, RSA keys, SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files, and shared a screenshot purporting to show an Azure DevOps repository cloned from an Accenture-hosted system. Accenture called it an isolated incident and said it remediated the source, but did not disclose the intrusion method or whether customer data was affected.
Why it matters: Stolen source code and cloud or administrator keys can create follow-on risk well beyond the initial breach, including unauthorized access to internal systems or customer-connected environments. Organizations that work with Accenture should watch for advisories, rotate exposed credentials if notified, and review any trust relationships or shared access.
Sources
Ionut Arghire 2026.07.08 99%
This article is a direct report on the same incident, adding that Accenture confirmed the breach, said it remediated the source of the compromise, and stated there was no operational or service delivery impact while the attacker claimed theft of 35 GB including Azure keys, tokens, SSH/RSA keys, config files, and source code.
Lawrence Abrams 2026.07.07 100%
This article appears to be the first clear reporting of a newly confirmed 2026 Accenture breach tied to a threat actor's sale of allegedly stolen internal data.
Full page
China-aligned UAT-7810 expands router-based ORB network with LONGLEASH malware on Ruckus and ASUS devices
Zero-Days & CVEsThreat Actors & APTsMalwareTechnology & SoftwareTelecommunicationsConsumers & General PublicCiscoRuckusASUS
A China-aligned hacking group is expanding a covert relay network by breaking into internet-facing routers and loading new backdoor malware. Cisco Talos says UAT-7810 is using LONGLEASH, plus DOGLEASH, JARLEASH, and LEASHTEST, to grow an operational relay box (ORB) infrastructure that can proxy traffic for other China-linked actors. Initial access relies on n-day flaws in Ruckus routers (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717) and ASUS AiCloud routers (CVE-2025-2492).
Why it matters: Organizations and consumers with unpatched edge devices could have their routers turned into stealth infrastructure for espionage or follow-on attacks. Patch affected Ruckus and ASUS devices, check Talos indicators of compromise, and review exposed networking gear for web shells, tunneling, and unusual proxy behavior.
Sources
Ionut Arghire 2026.07.08 97%
This article is a direct update on the same UAT-7810 router-compromise campaign, adding detail that Talos observed new Leash-family backdoors including LongLeash, DogLeash, and JarLeash, plus continued exploitation of Ruckus flaws CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 and infrastructure overlap with ASUS AiCloud targeting in Operation WrtHug.
Bill Toulas 2026.07.07 100%
This article establishes a distinct campaign centered on UAT-7810's LONGLEASH malware and the expansion of a China-aligned ORB router network, not the same underlying event as the existing JDY, Calypso, Earth Lusca, or UNC6508 stories.
Full page
Ubiquiti patches seven critical UniFi OS flaws, including command-injection bug CVE-2026-50746
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareConsumers & General PublicUbiquiti
Ubiquiti released fixes for seven critical security flaws in UniFi OS and related applications that could let attackers on the network take over affected devices and services. The most severe issue, CVE-2026-50746, is a command-injection vulnerability in UniFi Connect Application 3.4.16 and earlier; Ubiquiti says users should update to 3.4.20 or later. Additional critical CVEs affect UniFi Talk, UniFi Access, UniFi Protect, UniFi OS Server, and various routers, gateways, NAS, and surveillance products, with six described as low-complexity and requiring no user interaction.
Why it matters: Organizations using UniFi gear, especially internet-exposed deployments, may be at risk of device compromise and follow-on abuse if they do not patch quickly. Admins should identify affected UniFi OS and application versions and update immediately.
Sources
info@thehackernews.com (The Hacker News) 2026.07.08 96%
This article appears to be another report on the same Ubiquiti July 2026 UniFi security release, adding that the affected product set spans UniFi Connect, Talk, Access, Protect, and UniFi OS rather than only framing it around UniFi OS and one flagship CVE.
Sergiu Gatlan 2026.07.08 100%
This article establishes a distinct new patch-and-vulnerability event centered on newly disclosed July 2026 UniFi OS CVEs, not the earlier May/June UniFi OS flaws already tracked.
Full page
Anthropic silently patched Claude Code sandbox bypass enabling outbound network policy evasion
Surveillance & PrivacyUrgent PatchesZero-Days & CVEsTechnology & SoftwareAnthropicCNVDB
SecurityWeek reports that Anthropic patched a Claude Code network sandbox bypass caused by a SOCKS5 hostname null-byte injection flaw that could let attackers evade outbound allowlist restrictions and exfiltrate data. Researcher Aonan Guan said the issue affected Claude Code from October 20, 2025 until fixes shipped in Claude Code 2.1.88/2.1.90 in March-April 2026. The article also references an earlier related bypass, CVE-2025-66479, involving outbound policy misinterpretation.
Why it matters: Organizations using Claude Code in production may have relied on sandboxing to prevent agent-driven data exfiltration, especially in prompt-injection scenarios. Users should update Claude Code and review whether sensitive credentials, tokens, or environment data could have been exposed through sandbox bypasses.
Sources
2026.07.08 33%
This also concerns Claude Code security, but it is a different underlying event: a CNVDB warning about embedded monitoring code in versions 2.1.91 through 2.1.196 and Anthropic’s removal in 2.1.198, rather than the previously tracked sandbox-bypass flaw.
2026.05.20 97%
This article covers the same underlying event: Anthropic's silent patch of a Claude Code sandbox bypass caused by a SOCKS5 hostname null-byte injection flaw. It adds detail on impact, including possible exfiltration of GitHub and cloud credentials, the patch version timeline, and the researcher's criticism that Anthropic issued no CVE or Claude Code-specific advisory.
Eduard Kovacs 2026.05.20 100%
This article establishes a distinct security story about a specific Claude Code sandbox bypass and Anthropic's handling and remediation of the flaw.
Full page
China’s CNVDB tells developers to remove Claude Code versions 2.1.91 to 2.1.196 over data-forwarding code
Surveillance & PrivacySupply ChainTechnology & SoftwareAnthropicCNVDBAlibaba
China’s state vulnerability database warned developers to uninstall or upgrade certain Claude Code releases because they may send user information to remote servers without consent. CNVDB said versions 2.1.91 through 2.1.196 contained a built-in monitoring mechanism it described as backdoor code that could collect data such as location and identity; Anthropic engineer statements cited by the report say related covert anti-model-distillation code was removed in Claude Code 2.1.198 on July 1.
Why it matters: Developers and organizations using Claude Code in sensitive environments may need to review which versions are installed and upgrade or remove older builds now. Even without a CVE, this is a concrete privacy and supply-chain trust issue for teams using AI coding tools on business networks.
Sources
2026.07.08 100%
The article establishes a distinct story because it is about CNVDB’s warning over alleged data-forwarding code in specific Claude Code versions and Anthropic’s subsequent removal of that code, not the previously tracked Claude Code sandbox-bypass vulnerability.
Full page
Spain arrests alleged pro-Russia hacktivist linked to CARR, Z-Pentest, and NoName057(16) after FBI tip
Threat Actors & APTsGovernmentEnergy & UtilitiesFBIPolicía NacionalSpain's National PolicePolicia Nacional
Spanish police arrested a man in Palencia who they say supported pro-Russia hacktivist groups tied to attacks on critical infrastructure in Western countries. Police said the suspect had close ties to CyberArmy of Russia Reborn (CARR) and Z-Pentest, may have carried out actions for NoName057(16), helped a Ukrainian CARR member flee toward Russia via Poland and Belarus, and held seized computer equipment and cryptocurrency allegedly linked to cybercrime proceeds.
Why it matters: This signals continued international disruption of Russian-aligned hacktivist networks that have targeted public and private critical services, often with denial-of-service attacks that can still knock essential systems offline. Organizations in sectors such as energy, water, agriculture, and government should keep DDoS defenses and monitoring tuned for these actors.
Sources
2026.07.08 99%
This article appears to be the same underlying event and adds details that Spanish police say the suspect helped a Ukraine-based CARR-linked hacker flee to Russia via Poland and Belarus, communicated with group members over encrypted apps, had cryptocurrency devices seized, and is being investigated for terrorism-related offenses and computer damage.
Bill Toulas 2026.07.07 99%
This article is the same underlying event: Spain's arrest of a suspect in Palencia tied to CARR, Z-Pentest, and NoName057(16) following FBI-provided intelligence. It adds details that police say the suspect helped a Ukrainian hacker tied to CARR, tried to facilitate escape to Russia via Poland and Belarus, used encrypted messaging to coordinate support, and had crypto wallets frozen over alleged proceeds from stolen-data sales.
2026.07.07 100%
This article establishes a discrete arrest and investigation in Spain tied to specific pro-Russia hacktivist groups, rather than updating an existing tracked breach, vulnerability, or advisory event.
Full page
EU cyber and AI action plan aims to reduce reliance on foreign frontier AI models for security work
Policy & RegulationGovernmentTechnology & SoftwareEnergy & UtilitiesTelecommunicationsEuropean CommissionENISAOpenAIAnthropic
The European Commission published a cybersecurity and artificial intelligence action plan meant to reduce the EU’s dependence on foreign-controlled advanced AI systems. The July 7 communication sets out nine measures across model evaluation, structured access to frontier models, vulnerability management, and scaling EU capability, including a Commission-ENISA blueprint due by year-end for granting access to advanced AI tools for EU institutions, member states, critical infrastructure operators, security vendors, and researchers, plus contingency planning if access is restricted or withdrawn by providers or third-country governments.
Why it matters: This matters because many European defenders may depend on non-EU AI providers whose access rules can change suddenly, potentially cutting off security tooling and research support. Organizations in Europe should watch for the ENISA blueprint, AI Act enforcement from August 2, and any new access or compliance requirements tied to high-risk general-purpose AI models.
Sources
2026.07.08 100%
This article establishes a distinct policy story centered on the EU’s newly published cyber and AI action plan and its proposed framework for access to frontier models.
Full page
Google fixed a Dialogflow CX flaw that could let attackers hijack chatbot conversations across a cloud project
Zero-Days & CVEsSurveillance & PrivacyTechnology & SoftwareFinance & BankingHealthcareConsumers & General PublicGoogle
Google Dialogflow CX had a flaw that could let an attacker silently take over AI chatbot conversations and steal sensitive data from every affected agent in the same Google Cloud project. Varonis says the issue, dubbed Rogue Agent, stemmed from shared Cloud Run execution for Dialogflow CX Code Blocks, where arbitrary Python code could overwrite a key file, manipulate sessions, exfiltrate conversations, bypass VPC Service Controls, and potentially access Google-managed service account tokens through the instance metadata service. Google was notified in November 2025, shipped an initial patch in April 2026, and completed the fix in June 2026.
Why it matters: Organizations using Dialogflow CX for customer support or sensitive workflows may have faced invisible conversation tampering, phishing prompts, and data theft. Users and defenders should review Dialogflow CX configurations, audit past chatbot activity where possible, and treat this as a serious cloud AI isolation failure even though Google says it is now fixed.
Sources
Ionut Arghire 2026.07.08 100%
This article appears to be the first tracked report establishing the underlying event: a Google Dialogflow CX vulnerability affecting shared Cloud Run execution and enabling cross-agent conversation hijacking and data exfiltration.
Full page
Attackers exploit unpatched Langflow flaw CVE-2026-5027 to run code on exposed AI workflow servers
MalwareZero-Days & CVEsUrgent PatchesTechnology & SoftwareGovernmentLangflowCISA
Attackers are exploiting a security hole in Langflow that can let outsiders take over internet-exposed servers without logging in. The flaw, CVE-2026-5027, is an unauthenticated remote-code-execution bug affecting Langflow, an open-source tool for building AI workflows; exploitation means attackers can send crafted requests to run their own commands on vulnerable systems, and the article says no patch is available yet.
Why it matters: Organizations using Langflow should treat this as urgent because an exposed server could be fully compromised with no valid account needed. If you run Langflow, restrict internet access, apply any vendor mitigations, monitor for compromise, and patch immediately once a fix is released.
Sources
Ionut Arghire 2026.07.08 46%
This article references ongoing Langflow exploitation but for a different underlying flaw, adding that attackers chained the newer KEV-listed CVE-2026-55255 with the earlier Langflow RCE bug CVE-2026-33017 in observed attacks.
Sergiu Gatlan 2026.07.08 77%
This updates the broader ongoing Langflow exploitation story by adding a separate actively exploited flaw, CVE-2026-55255, that CISA has now placed in the KEV catalog with a federal patch deadline. It also ties current Langflow exploitation to prior abused flaws including CVE-2025-3248 and references financially motivated post-compromise activity targeting compute and credentials.
info@thehackernews.com (The Hacker News) 2026.07.08 78%
This article adds that CISA has now formally added Langflow CVE-2026-5027 to the Known Exploited Vulnerabilities catalog, confirming active exploitation at the federal-priority level and raising urgency for exposed Langflow deployments.
info@thehackernews.com (The Hacker News) 2026.06.30 96%
This is the same underlying event: exploitation of the unpatched Langflow RCE flaw CVE-2026-5027 on internet-exposed AI workflow servers. The new detail is that attackers are now deploying Monero cryptomining malware on compromised endpoints, showing concrete post-exploitation activity and impact.
Ionut Arghire 2026.06.11 98%
This article is a direct update on the same Langflow event, adding VulnCheck's confirmation of in-the-wild exploitation, details that attackers used the vulnerable POST /api/v2/files endpoint plus default unauthenticated auto-login to get a session token, and an estimate of roughly 7,000 internet-accessible instances.
Bill Toulas 2026.06.10 95%
This article updates the same underlying event by adding that exploitation of CVE-2026-5027 is being observed now, describing the bug as a path traversal in the file upload endpoint, noting arbitrary file write as the immediate impact, and pointing users to the latest Langflow release 1.10.0 while referencing prior fixes in langflow-base 0.8.3 and Langflow 1.9.0.
info@thehackernews.com (The Hacker News) 2026.06.10 100%
This article appears to be the initial report of active exploitation of CVE-2026-5027 in Langflow, and no existing tracked story covers this specific flaw or product.
Full page
Attackers begin exploiting critical Adobe ColdFusion flaw CVE-2026-48282 shortly after patch release
Urgent PatchesZero-Days & CVEsTechnology & SoftwareGovernmentAdobeCISA
Attackers are already using a newly patched Adobe ColdFusion bug to break into vulnerable servers. The flaw, CVE-2026-48282, is a critical path traversal issue rated 10.0 that can lead to arbitrary code execution in ColdFusion 2025 and 2023; Adobe fixed it on June 30 in ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21, and external reporting says exploitation began within hours of public disclosure.
Why it matters: Organizations running Adobe ColdFusion should treat this as an immediate patching priority because internet-facing servers may already be targeted. Apply Adobe's June 30 updates now and review exposed ColdFusion systems for signs of compromise.
Sources
Ionut Arghire 2026.07.08 94%
This article updates the same ColdFusion event by adding that CISA has now added CVE-2026-48282 to the KEV catalog and ordered federal agencies to patch by July 10.
Sergiu Gatlan 2026.07.08 95%
This is a direct update on the same underlying event: active exploitation of Adobe ColdFusion CVE-2026-48282. The new information is that CISA has now added the flaw to the KEV catalog and ordered U.S. federal civilian agencies to patch by Friday under BOD 26-04.
Ionut Arghire 2026.07.07 100%
This article establishes a distinct tracked event: active exploitation of Adobe ColdFusion CVE-2026-48282 after Adobe's June 30 patch, which is not the same as the existing broader Adobe ColdFusion and Campaign Classic patch roundup.
Full page
CISA adds exploited Langflow cross-tenant flaw CVE-2026-55255 to KEV after attackers chain it with older RCE bug
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareLangflowCISA
CISA says attackers are already exploiting a critical Langflow flaw and federal agencies must patch it by July 10. The bug, CVE-2026-55255, is a cross-tenant insecure direct object reference issue fixed in Langflow 1.9.1 that lets attackers execute other users’ flows by supplying a flow UUID. Sysdig said attackers paired it with previously patched Langflow remote code execution flaw CVE-2026-33017 after doing host reconnaissance and harvesting flow IDs.
Why it matters: Organizations running Langflow should treat this as urgent because attackers are already chaining it with another flaw to gain code execution. Update to 1.9.1 immediately and review exposed Langflow servers for unauthorized flow execution, reconnaissance, and post-compromise activity.
Sources
Ionut Arghire 2026.07.08 100%
The existing Langflow tracked story is about a different flaw, CVE-2026-5027, while this article establishes a separate KEV-listed exploitation story centered on CVE-2026-55255 and its chaining with CVE-2026-33017.
Full page
GitHub Agentic Workflows prompt-injection flaw can leak private repository data into public issue comments
Zero-Days & CVEsTechnology & SoftwareGitHubMicrosoft
Researchers say GitHub’s AI-powered Agentic Workflows can be tricked into exposing private repository contents in public comments, putting organizations that mix public and private repos at risk. Noma Labs calls the issue GitLost and says an attacker only needs to open a crafted issue in a public repository within the same GitHub organization; the agent can then fetch data from a private repo and post it publicly. No CVE or complete fix was reported, and GitHub had not added documentation-based mitigations as of publication.
Why it matters: Organizations using GitHub’s autonomous coding and workflow agents may be exposing internal code or secrets without realizing it. Security teams should review any Agentic Workflows permissions and repository access paths immediately, especially where public issue creation can trigger agents with access to private repos.
Sources
Ionut Arghire 2026.07.08 98%
This is the same underlying event: the GitLost prompt-injection issue in GitHub Agentic Workflows. The article adds exploit details, including that a crafted public GitHub issue can trigger on issues.assigned events, that the workflow may have read access across an organization’s public and private repositories, and that researchers bypassed guardrails with phrasing variations such as adding the word “additionally.”
2026.07.07 100%
This article appears to be the first concrete reporting here on the GitLost prompt-injection issue affecting GitHub Agentic Workflows, including exploitation details, impact, and the lack of a vendor fix or mitigation guidance.
Full page
CISA adds actively exploited Adobe Commerce and Magento remote-code-execution flaw CVE-2026-45247 to KEV catalog
Zero-Days & CVEsUrgent PatchesRetail & E-CommerceGovernmentTechnology & SoftwareAdobeCISAMagento
CISA says attackers are exploiting a serious Adobe Commerce and Magento flaw that can let them take over vulnerable online store servers. The issue, CVE-2026-45247, is a remote-code-execution vulnerability, meaning an attacker can run their own commands on the target system from afar; CISA added it to the Known Exploited Vulnerabilities catalog, which federal agencies use to prioritize urgent fixes. Affected product and version details would follow Adobe’s advisory, and internet-exposed commerce systems are the most immediate concern.
Why it matters: Organizations running Adobe Commerce or Magento should treat this as urgent because CISA only adds bugs to KEV when there is evidence of real-world exploitation. For online stores, the risk can include site takeover, payment-data exposure, and malware implantation, so defenders should identify affected instances and patch or mitigate immediately.
Sources
info@thehackernews.com (The Hacker News) 2026.07.08 95%
This appears to be the same underlying event for the Adobe flaw: CISA adding Adobe Commerce and Magento CVE-2026-45247 to KEV as actively exploited.
Ionut Arghire 2026.06.04 97%
This article is the same underlying event: active exploitation of CVE-2026-45247 and CISA adding it to KEV. It adds product-specific detail that the flaw is in the Mirasvit Full Page Cache Warmer extension, affects versions before 1.11.12, uses unsafe PHP object deserialization via the CacheWarmer cookie, and includes compromise indicators from Sansec.
info@thehackernews.com (The Hacker News) 2026.06.04 100%
This article appears to establish a new tracked event: CISA's KEV addition for CVE-2026-45247 in Adobe Commerce/Magento, and no existing story in the tracker covers this specific CVE or KEV action.
Full page
Joomla warns attackers are actively exploiting JCE flaw CVE-2026-48907 to upload files and run code on websites
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareConsumers & General PublicGovernmentMedia & EntertainmentJoomlaCISAWidget Factory
Joomla site owners using the JCE editor plugin are being targeted in active attacks that can let outsiders take over websites. The flaw, CVE-2026-48907, affects JCE Pro versions before 2.9.99.5 and lets unauthenticated attackers upload editor profiles and then arbitrary files, leading to PHP code execution on the server. Joomla says public exploit code exists, attacks are automated, and version 2.9.99.6 adds further protections and indicators of compromise.
Why it matters: This is urgent for organizations and individuals running Joomla sites because attackers can break in without an account and leave backdoors behind. Update immediately, then check for compromise because patching closes the hole but does not remove anything attackers already installed.
Sources
info@thehackernews.com (The Hacker News) 2026.07.08 84%
This article adds that CISA has placed the Joomla JCE flaw CVE-2026-48907 in KEV, which strengthens the exploitation signal and increases patching urgency for affected Joomla sites.
Sergiu Gatlan 2026.06.17 97%
This is the same underlying event: active exploitation of CVE-2026-48907 in the JCE Joomla plugin. The new information is that CISA has added the flaw to the Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to patch or mitigate by Friday under BOD 26-04.
Ionut Arghire 2026.06.17 100%
The article establishes a distinct exploited-vulnerability event for Joomla JCE, separate from the already tracked LiteSpeed KEV story, with its own CVE, affected versions, exploitation details, and update guidance.
Full page
U.S. extradites alleged Scattered Spider member over social-engineering breach and $8 million extortion attempt against jewelry retailer
Social Engineering & PhishingRansomwareThreat Actors & APTsScams & FraudBreaches & Data LeaksRetail & E-CommerceConsumers & General PublicDepartment of JusticeFBIInterpolGoogle VoicengrokDOJMicrosoft
A 19-year-old accused Scattered Spider member was extradited from Finland to the United States to face charges tied to hacking and extortion. The FBI says Peter Stokes helped breach an unnamed luxury jewelry retailer around May 12, 2025 by calling the IT help desk from Google Voice numbers, posing as employees, and getting password and multifactor authentication resets; the attackers allegedly compromised three accounts, including two IT administrator accounts, used ngrok for persistent access, stole data, and demanded $8 million in cryptocurrency.
Why it matters: This matters because it gives defenders a concrete look at how Scattered Spider is still using help-desk impersonation to break into companies without exploiting software flaws. Organizations, especially those with privileged IT accounts, should harden help-desk identity checks, review MFA reset procedures, and monitor for unauthorized remote-access tools such as ngrok.
Sources
2026.07.07 86%
This article adds specific investigative detail from the Peter Stokes case, explaining that prosecutors relied in part on Microsoft's Windows Global Device Identifier, plus ngrok and VPN records, to link online activity to the alleged Scattered Spider member tied to the same extradition and charging event.
Ionut Arghire 2026.07.03 98%
This article is the same underlying event: the U.S. extradition of 19-year-old Peter Stokes over the May 2025 intrusion and $8 million extortion attempt against a jewelry retailer, and it adds background on Scattered Spider's broader activity and prior guilty pleas.
Sergiu Gatlan 2026.07.02 98%
This is the same extradition event and adds the suspect's name, age, dual U.S.-Estonian citizenship, prior Finland arrest details, aliases, the allegation that he participated in at least four Scattered Spider breaches including a 2023 communications-platform hack, and updated DOJ/FBI framing of the group's broader impact.
2026.07.01 100%
This article establishes a distinct tracked event by identifying an extradited suspect, the victim profile, the timeline, and the specific help-desk social-engineering technique used in an alleged Scattered Spider breach and extortion attempt that is not the same underlying event as the existing TfL guilty-plea story.
Full page
Attackers are exploiting Gitea Docker authentication-bypass flaw CVE-2026-20896 to access private repositories and secrets
Zero-Days & CVEsTechnology & SoftwareGitea
Attackers are actively breaking into some internet-accessible Gitea code-hosting servers by abusing a critical authentication flaw. The bug, CVE-2026-20896, affects official Gitea Docker images before 1.26.3 when reverse-proxy authentication is enabled; an attacker can send a single crafted HTTP header with a valid username to bypass login. Sysdig says exploitation began 13 days after public disclosure, and roughly 6,200 Gitea instances are exposed online, though the vulnerable subset is unknown.
Why it matters: Organizations using self-hosted Gitea could have private source code, deploy keys, API keys, and other secrets exposed or modified without a password. This is urgent: admins should update to fixed Gitea versions immediately and ensure reverse-proxy authentication is not exposed directly to untrusted networks.
Sources
Ionut Arghire 2026.07.07 100%
This article establishes a distinct tracked event by adding that CVE-2026-20896 in Gitea is under active exploitation in the wild, elevating the issue from a disclosed flaw to an urgent defender-relevant incident.
Full page
CAI cloud worm targets Docker, Kubernetes, Redis, etcd, Kubelet, and Ray to steal credentials and mine cryptocurrency
MalwareThreat Actors & APTsTechnology & SoftwareConsumers & General Public
A newly reported malware framework called CAI is infecting cloud and developer infrastructure to steal secrets and run cryptocurrency miners. Hunt.io says the worm scans for exposed services including Docker, Kubernetes, Redis, etcd, Kubelet, and Ray, then deploys miners, credential stealers, and a Python backdoor while also killing rival malware from TeamPCP and PCPJack. Researchers observed the operator move from testing to active compromises between mid-June and early July 2026.
Why it matters: Organizations running internet-exposed cloud management and developer tools could have credentials stolen and systems hijacked for follow-on attacks or cryptomining. Defenders should check exposed Docker, Kubernetes, Redis, etcd, Kubelet, and Ray services, hunt for miners and unknown Python backdoors, rotate exposed secrets, and review cloud access controls now.
Sources
2026.07.07 100%
This article establishes a distinct newly observed cloud worm, CAI, with its own infrastructure, targets, and behavior, rather than merely updating an existing tracked TeamPCP, Miasma, or Megalodon event.
Full page
Supreme Court lets Texas app age-verification law take effect while legal challenge continues
Surveillance & PrivacyPolicy & RegulationTechnology & SoftwareConsumers & General PublicSupreme CourtTexasCCIAAppleGoogleMeta
The U.S. Supreme Court allowed Texas to enforce a law that requires age verification and parental consent for people under 18 to download apps. The Texas App Store Accountability Act, signed in 2025, requires app stores and developers to verify ages and assign age ratings to apps while the Fifth Circuit continues reviewing whether the law violates First Amendment protections. The dispute centers on mandated identity or age checks and the resulting collection of personal data to access online services.
Why it matters: This matters because app stores, developers, parents, and minors in Texas may now have to hand over more personal information to use or approve apps before the courts decide whether the law is lawful. It is a significant privacy-policy development and may influence similar age-verification rules in other states.
Sources
2026.07.07 100%
This article establishes a new tracked story because it reports a specific Supreme Court order allowing enforcement of Texas’s app age-verification law, a distinct legal and privacy event not represented in the existing tracked stories.
Full page
Anthropic says it plans broader release of Mythos-class AI bug-finding models after expanding restricted access to governments
Surveillance & PrivacyPolicy & RegulationZero-Days & CVEsGovernmentTechnology & SoftwareDefense & AerospaceConsumers & General PublicAnthropicU.S. governmentAdobeNvidiaPentagonCommerce DepartmentWhite HouseOpenAIGoogleNSAU.S. Cyber CommandQihoo 360MicrosoftAmazonCISA
Anthropic says it intends to eventually make Mythos-class vulnerability-finding artificial intelligence available more broadly, but for now is expanding its restricted Project Glasswing program to additional partners including U.S. and allied governments. The company says Mythos has scanned more than 1,000 open-source projects, estimated 6,202 high-or-critical-severity vulnerabilities and 23,019 total flaws, and validated many findings through coordinated disclosure; no CVE list or release date for public access was provided.
Why it matters: This matters because a powerful AI system for finding software flaws could help defenders patch faster, but could also accelerate criminal discovery of exploitable bugs if released without effective guardrails. Security teams should expect faster vulnerability discovery pressure in widely used open-source components and be prepared for heavier disclosure and patching volume.
Sources
Mike Lennon 2026.07.07 81%
This advances that same underlying development by reporting a specific real-world government use case: CISA is reportedly using Mythos to scan federal agency code repositories, with the Attack Surface Evaluation team leading audits and reportedly finding many flaws.
Associated Press 2026.07.02 64%
This updates the same underlying Anthropic/Mythos access-control story with new facts: the Trump administration has lifted the broad restrictions on Claude Fable 5, restored Mythos 5 only for government-approved U.S. organizations, and Anthropic says the trigger was an Amazon-reported bypass of Fable 5 safeguards that enabled vulnerability discovery and possible exploitation.
2026.07.01 78%
This updates the same underlying Anthropic frontier-cybersecurity-model access and governance story by reporting that U.S. export controls on Fable 5 and Mythos 5 were lifted after negotiations, restoring global access to Fable 5, keeping Mythos 5 limited to vetted U.S. organizations via Project Glasswing, and adding new government review, jailbreak disclosure, and bug-bounty commitments.
SecurityWeek News 2026.06.26 41%
The article references 'Chinese Mythos-like AI' and broader AI threat concerns, but in this excerpt it does not clearly establish the same concrete underlying event as the tracked Anthropic/Mythos release story beyond thematic overlap.
2026.06.26 83%
This article adds a direct geopolitical and industry response to the same Mythos bug-finding model story: Qihoo 360 says China's access restrictions on Mythos create a strategic imbalance, claims to have built a competing vulnerability-finding system, and says it is organizing local firms against Anthropic's Project Glasswing ecosystem.
Associated Press 2026.06.24 86%
This article adds a concrete example of why Mythos access has been restricted and expanded to governments: a U.S. official says the model found vulnerabilities in classified U.S. systems during Project Glasswing testing, and Sen. Warner publicly characterized the results as breaking into classified systems within hours.
Associated Press 2026.06.20 63%
This article adds that France's president publicly criticized the U.S. directive restricting foreign access to Anthropic's newest models, said Fable 5 and Mythos 5 were taken offline to comply, and called for government-to-government cooperation on AI security and cybersecurity among democracies.
Corynne McSherry 2026.06.18 75%
This article adds that EFF is challenging the Trump administration's sanctions and export controls targeting Anthropic, arguing the measures were retaliatory and led Anthropic to shut down Mythos and Fable rather than comply. It specifically expands the policy and access implications around the same Mythos-class cybersecurity models discussed in the tracked story.
Associated Press 2026.06.16 84%
This article updates the same underlying issue around Anthropic's Mythos-class cybersecurity-capable models by adding that the Trump administration issued export-control-style restrictions barring foreign nationals from access, Anthropic took Fable 5 and Mythos 5 offline to comply, and more than 100 cybersecurity leaders are urging the government to reverse the directive.
2026.06.15 53%
This article adds new detail on the same underlying Fable 5/Mythos model access controversy: it says the reported 'jailbreak' behind the U.S. restriction was allegedly just asking the model to 'fix this code,' and it includes criticism from Katie Moussouris and an open letter arguing the controls harm defenders.
2026.06.15 93%
This updates the same underlying Anthropic Mythos/Fable cybersecurity-model access story by reporting that Anthropic abruptly disabled Fable 5 and Mythos 5 after a U.S. government export-control directive barred access by foreign nationals, including Anthropic staff, and by adding Anthropic's dispute over the claimed jailbreak risk.
Ax Sharma 2026.06.13 82%
This updates the same underlying Anthropic Mythos/Fable access story with a new government-triggered restriction: Anthropic says a U.S. export-control directive forced it to suspend Fable 5 and Mythos 5 globally, including for foreign nationals and some internal staff, after concerns about a reported jailbreak.
Mayank Parmar 2026.06.10 89%
This article advances the same underlying event by reporting Anthropic's public rollout of Fable 5, a guarded version of the Mythos-class model, and adds concrete details on access limits, sensitive-query downgrading to Opus 4.8, temporary availability to Pro/Max/Enterprise users, and the distinction between restricted Mythos 5 and safeguarded Fable 5.
Eduard Kovacs 2026.06.09 84%
This article is a direct follow-up on that same underlying event: Anthropic has now launched Claude Fable 5 for general availability with cyber/bio fallbacks and says Project Glasswing partners are being upgraded from Mythos Preview to Mythos 5, adding concrete rollout details, guardrail design, pricing, and partner-access changes.
Ionut Arghire 2026.06.09 93%
This is a direct follow-up on the same Mythos program, adding concrete exploit-generation results: Anthropic says Mythos Preview produced working Firefox and Windows N-day exploits within hours, showing the model can weaponize disclosed flaws rather than only find bugs.
+ 7 more sources
Full page
UK launches Cyber Resilience Pledge, but fewer than 15 FTSE 350 firms join at launch
Policy & RegulationConsumers & General PublicUK governmentNCSCAvivaLondon Stock Exchange GroupMarks & Spencer
The UK government launched a voluntary Cyber Resilience Pledge for businesses, but only a small number of the country’s biggest listed companies signed on at the start. The pledge asks organizations to make cybersecurity a board-level responsibility, enroll in the National Cyber Security Centre's Early Warning service, and use a risk-based approach to require Cyber Essentials certification in their supply chains. The launch comes as Parliament debates the Cyber Security and Resilience Bill and after the National Cyber Action Plan was delayed.
Why it matters: This matters because it shows limited voluntary uptake of government-backed cyber safeguards among major UK firms, which could strengthen the case for mandatory rules. Organizations doing business in the UK should watch for future regulatory changes and assess whether they already meet the pledge’s expectations around governance, monitoring, and supplier security.
Sources
2026.07.07 100%
The article establishes the launch event itself and provides the core news hook: the government's flagship voluntary cyber scheme debuted with low participation from the FTSE 350, making this a distinct UK cyber policy story.
Full page
Iran-linked Cavern Manticore used compromised IT providers and a modular malware framework to target organizations in Israel
Threat Actors & APTsMalwareSupply ChainGovernmentTechnology & SoftwareSysAidWinDirStat
An Iran-linked hacking group used compromised IT service providers and a custom modular malware framework to break into organizations in Israel, especially government entities and technology suppliers. Check Point says Cavern Manticore, which it links to Iran’s Ministry of Intelligence and Security and possibly OilRig/Lyceum, abused SysAid’s software update feature to sideload a WinDirStat DLL and launch its .NET-based 'Cavern' agent, then pulled modules for file access, database and LDAP enumeration, SMB brute-force, tunneling, and lateral movement through remote monitoring tools.
Why it matters: This matters because the attackers did not just hit one victim directly; they moved through trusted IT providers to reach higher-value targets, which raises risk across connected organizations. Israeli organizations and service providers should review SysAid-related update paths, hunt for the Cavern agent and follow-on modules, and scrutinize remote management and remote desktop activity.
Sources
Ionut Arghire 2026.07.07 100%
This article establishes a distinct campaign centered on Cavern Manticore’s modular C2 framework and multi-hop compromise of Israeli IT providers to reach end targets.
Full page
Linux KVM flaw CVE-2026-53359 lets attackers escape virtual machines on Intel and AMD hosts
Zero-Days & CVEsTechnology & SoftwareLinuxGoogleRed HatGoogle CloudAmazon Web Services
A newly disclosed Linux kernel bug can let an attacker break out of a virtual machine and take control of the underlying host system. The flaw, CVE-2026-53359, affects the shadow MMU (memory-management unit) code in Linux's Kernel-based Virtual Machine (KVM) hypervisor and is described as a use-after-free issue. Researcher Hyunwoo Kim demonstrated it in Google's kvmCTF, and the bug was patched upstream on June 19, 2026. It is notable for affecting both Intel and AMD x86 systems and posing particular risk to multi-tenant cloud environments using nested virtualization.
Why it matters: Organizations and cloud providers running Linux KVM hosts could face full host takeover from a compromised guest, putting other tenants and workloads at risk. Administrators should identify affected KVM hosts, apply the June 2026 kernel fix or vendor backports, and review exposure where untrusted VMs or nested virtualization are allowed.
Sources
Sergiu Gatlan 2026.07.07 98%
This article is a direct report on the same Januscape vulnerability, adding plain-language impact details, confirmation it affected both Intel and AMD, the patch commit defenders should verify, and that a proof-of-concept causing host kernel panic was published while full guest-to-host exploit code was withheld.
Ionut Arghire 2026.07.07 100%
This article establishes a distinct new story around CVE-2026-53359 (Januscape), a newly disclosed cross-vendor Linux KVM VM-escape flaw with upstream patch details and cloud-impact context not covered by an existing tracked story.
Full page
Attackers use fake Microsoft Teams IT support calls to install EtherRAT on employee computers
Social Engineering & PhishingMalwareConsumers & General PublicTechnology & SoftwareMicrosoft
Attackers are calling employees on Microsoft Teams while pretending to be corporate IT staff and tricking them into installing malware that gives remote control of their computers. According to Palo Alto Networks' Unit 42, the campaign starts with an 'Employee Survey' phishing email and PDF, then a Teams voice call from an external Microsoft 365 tenant, followed by abuse of Teams screen sharing and remote tools including HopToDesk and AnyDesk. The attackers then run a malicious MSI installer that fetches Node.js and launches EtherRAT, a cross-platform remote access trojan that can execute commands, steal data, persist, and use Ethereum smart contracts to locate command-and-control servers.
Why it matters: Organizations using Microsoft Teams are at risk of employees being talked into giving attackers direct access to their devices. Defenders should warn staff not to trust unsolicited Teams support calls, restrict external Teams communications and remote-control features where possible, and review logs for suspicious external tenants, remote tool installs, and the listed infrastructure.
Sources
2026.07.07 98%
This is a direct report on the same campaign, adding details on the lure sequence (employee survey email followed by a cross-tenant Teams call), use of HopToDesk or AnyDesk, the EtherRAT MSI installer, Ethereum smart-contract command-and-control discovery, and a forensic indicator in Teams files named "CtrlVirtualCursorWin_*".
Lawrence Abrams 2026.07.06 100%
This article establishes a distinct Teams-based vishing and malware-delivery campaign centered on EtherRAT, with specific lures, attacker tenant details, tooling, and infection chain.
Full page
Google sues alleged China-based 'Outsider Enterprise' over mass phishing texts and fake brand websites
Policy & RegulationThreat Actors & APTsSocial Engineering & PhishingScams & FraudConsumers & General PublicTechnology & SoftwareTelecommunicationsRetail & E-CommerceGovernmentGoogleFBIAT&TT-MobileVerizonShopifyNew York E-ZPass
Google says a China-based fraud network used phishing kits and automated content generation to send millions of scam text messages and steer people to fake websites that stole passwords, payment-card data, and other sensitive information. In a civil complaint, Google linked the Telegram-based 'Outsider Enterprise' to more than 9,000 fraudulent sites and over 1 million malicious URLs, and said Android telemetry saw about 2.5 million related messages in a two-week period in May.
Why it matters: This is a high-volume smishing and credential-theft operation affecting everyday phone users, not just a niche enterprise target set. People should be wary of text messages claiming to be from trusted brands, avoid logging in through SMS links, and carriers and mobile defenders should watch for the cited infrastructure and lures.
Sources
Bruce Schneier 2026.07.07 98%
This is the same underlying event: Google's lawsuit against Outsider Enterprise. The article adds detail that the group used Telegram channels, offered nearly 300 scam templates, and instructed affiliates to use Gemini to build phishing pages impersonating Google, YouTube, and New York E-ZPass, while Google worked with AT&T, Verizon, and T-Mobile to block related scam texts.
Ionut Arghire 2026.06.15 96%
This is the same underlying Outsider Enterprise takedown and adds FBI details on Operation Riptide, domain and Shopify seizures, use of a Telegram bot for intelligence, 9,000 phishing sites, 1 million URLs, 3.8 million stolen credit cards, roughly $1.9 billion in losses, and coordination with carriers to block smishing texts.
Bill Toulas 2026.06.14 95%
This is the same underlying Outsider Enterprise phishing operation and adds the coordinated FBI takedown details: seizure of admin servers, a Telegram bot, a Shopify storefront, $100,000 in USDT, redirection of thousands of domains to an FBI splash page, and claims of 3.8 million stolen card records tied to $1.9 billion in losses.
2026.06.12 100%
This article establishes a distinct tracked story centered on Google's lawsuit and disruption campaign against the alleged 'Outsider Enterprise' phishing infrastructure, with concrete scale metrics and named coordination with U.S. telecom providers and the FBI.
Full page
BeyondTrust patches critical authentication-bypass flaws in Remote Support and Privileged Remote Access
Urgent PatchesZero-Days & CVEsBeyondTrust
BeyondTrust warned customers to urgently patch critical flaws in its Remote Support and Privileged Remote Access products that could let attackers get in without proper authentication. The issues include CVE-2026-40138 and CVE-2026-40139, affecting RS and PRA versions 25.3.2 and earlier, and can allow unauthorized access under specific authentication configurations; two additional high-severity flaws, CVE-2026-40140 and CVE-2026-40141, can cause denial of service or expose restricted resources. Cloud customers were patched by April 21, 2026, while self-hosted customers must apply the April security rollup or upgrade to 25.3.3 or later.
Why it matters: Organizations using BeyondTrust for remote administration could be exposed to break-ins that bypass login controls, including access to privileged accounts. This is high priority for defenders because internet-facing management tools are frequent intrusion targets, so self-hosted customers should update immediately and review exposed appliances.
Sources
Sergiu Gatlan 2026.07.07 100%
This article establishes a new tracked story because it centers on a newly disclosed set of BeyondTrust CVEs (CVE-2026-40138 through CVE-2026-40141) and the vendor's patch guidance, not on a previously listed BeyondTrust exploitation event.
Full page
BonkDAO says attackers used a malicious governance vote to drain $20 million in BONK cryptocurrency
Scams & FraudCryptocurrency & BlockchainConsumers & General PublicBonkDAOBONKUpbitSolana
BonkDAO says attackers stole about $20 million in BONK by pushing through a malicious governance proposal that voted more tokens into wallets they controlled. The attackers reportedly bought a large BONK position in advance to gain voting power inside the decentralized autonomous organization, then used that leverage to approve the transfer. Upbit temporarily suspended BONK deposits and withdrawals while the incident is investigated.
Why it matters: This is a direct loss event affecting BONK holders and users of services that support the token. Anyone exposed to BONK should watch exchange and project notices, review custody risk, and expect possible freezes, volatility, or recovery actions.
Sources
2026.07.06 100%
This article appears to be the first tracked item here about the BonkDAO governance attack and establishes the core event: attackers acquired voting power and used it to approve a transfer of roughly $20 million in BONK.
Full page
Fake job interview phishing campaign impersonates Adobe, OpenAI, Netflix and other brands to steal Google accounts
Social Engineering & PhishingConsumers & General PublicTechnology & SoftwareHospitality & TravelRetail & E-CommerceMedia & EntertainmentGooglePeopleForceSalesforceWise AgentAdobeOpenAI
A phishing campaign is posing as recruiters from more than 30 well-known companies to steal Google account credentials from marketing professionals and job seekers. The operation abuses legitimate services including PeopleForce, Salesforce Marketing Cloud infrastructure on exct.net, and Wise Agent in a redirect chain before sending victims to attacker-controlled domains, where a browser-in-the-browser fake Google sign-in window captures passwords. Researchers say the activity has run for at least five months.
Why it matters: Anyone contacted about a job interview from a major brand could be targeted, especially people in marketing roles. Treat interview scheduling links with caution, verify recruiters through official company channels, and use phishing-resistant multifactor authentication where possible because the campaign is designed to look unusually legitimate.
Sources
Ionut Ilascu 2026.07.06 100%
This article establishes a distinct, multi-brand phishing campaign centered on fake job interviews, abuse of legitimate SaaS platforms, and credential theft via fake Google login prompts.
Full page
Veil#Drop malware campaign uses Blogspot-hosted payloads and PowerShell to install PureLog infostealer
MalwareThreat Actors & APTsConsumers & General PublicTechnology & SoftwareGoogleMicrosoft
Attackers are using compromised websites and Google’s Blogspot service to infect Windows users with a data-stealing malware called PureLog. Securonix says the 'Veil#Drop' framework starts with a fake document JavaScript file that launches PowerShell, pulls later stages from attacker-controlled Blogspot pages, and runs payloads in memory using obfuscation, reflective .NET loading, and trusted Microsoft-signed binaries to evade detection. PureLog steals browser credentials, cookies, session tokens, wallet data, and secrets from messaging, email, FTP, cloud, remote-access, and developer tools.
Why it matters: This is dangerous because one infected employee computer can hand over passwords, tokens, and other secrets that attackers can later use for ransomware, business email compromise, or deeper intrusions. Organizations should block or scrutinize script-based downloads, hunt for suspicious PowerShell and LOLBIN activity, and reset exposed credentials if an infostealer infection is suspected.
Sources
Ionut Arghire 2026.07.06 100%
This article establishes a distinct malware campaign centered on the Veil#Drop delivery framework and PureLog infostealer, not a previously tracked breach, CVE, or patch event.
Full page
Medtronic notifies customers after ShinyHunters-linked breach exposed personal and health data
Breaches & Data LeaksHealthcareMedtronicShinyHunters
Medtronic says hackers accessed corporate IT systems in April 2026 and exposed customer personal data, including some health-related information. The company says the intrusion lasted from April 13 to April 19, 2026, and affected data may include names, contact details, dates of birth, Social Security numbers, and health information. ShinyHunters claimed the attack and said it stole about 9 million records, though Medtronic says the stolen data was not publicly posted online.
Why it matters: Affected customers face identity-theft and phishing risk because the stolen data includes highly sensitive personal information. Medtronic users should watch for breach notices, enroll in credit monitoring, and be cautious of calls, emails, or texts that use their personal details to appear legitimate.
Sources
2026.07.06 97%
This article updates the same Medtronic breach by adding that 3.8 million people are being notified and that the exposed data included Social Security numbers, health-related data, names, contact information, and dates of birth collected from patients with Medtronic devices.
Ionut Arghire 2026.07.03 99%
This article clearly updates the same Medtronic/ShinyHunters breach and adds the reported victim count of 3,834,294 people, the specific data types stolen, and the company's notification and remediation steps.
2026.07.02 97%
This article clearly updates the same April 2026 Medtronic intrusion, adding that breach notices are now going to patients, that data may include names, contact details, dates of birth, Social Security numbers, and health information, and that Medtronic says device operation and therapy delivery were not affected.
Bill Toulas 2026.07.02 100%
This article establishes a trackable breach story by adding concrete victim notification details, the intrusion window, and the categories of data exposed in the Medtronic incident.
Full page
Citizen Lab says Pegasus spyware infected European Parliament member Stelios Kouloglou during committee probe into spyware abuse
Surveillance & PrivacyPolicy & RegulationGovernmentMedia & EntertainmentEuropean ParliamentCitizen LabNSO GroupAppleAccess NowEuropol
Citizen Lab found that former European Parliament member Stelios Kouloglou’s phone was infected multiple times with NSO Group’s Pegasus spyware while he served on the Parliament’s PEGA committee investigating misuse of commercial spyware. The report says infections occurred in October 2022 and March 2023 and links them to the same Pegasus operator behind earlier targeting of Russian- and Belarusian-speaking journalists and opposition figures, based in part on shared targeting infrastructure and email lures.
Why it matters: This is a high-impact surveillance story because it suggests a lawmaker investigating spyware abuse was himself secretly monitored. It raises urgent concerns for politicians, journalists, and activists using iPhones who may have received Apple threat notifications and should seek forensic review if they are at elevated risk.
Sources
2026.07.06 97%
This article advances the same underlying event by adding the policy and accountability response: Amnesty and other civil-liberties groups are urging the EU to investigate who infected Kouloglou's iPhone, explain why PEGA Committee recommendations from May 2023 have not been implemented, and reform the EU Dual-Use Regulation governing spyware exports.
Amina Khan 2026.07.06 95%
This is a direct follow-up to the same Pegasus infection of Stelios Kouloglou. It adds Access Now's call for an EU investigation and highlights Citizen Lab's finding that one infection was launched from the same Apple ID infrastructure previously tied to Pegasus targeting of Russian- and Belarusian-speaking exiled journalists in the EU.
SecurityWeek News 2026.07.03 93%
This source summarizes the same Pegasus targeting of former MEP Stelios Kouloglou and adds the contextual detail that he was targeted while serving on the PEGA committee investigating Pegasus abuse, with no evidence cited of Greek government involvement.
info@thehackernews.com (The Hacker News) 2026.07.03 98%
This article appears to report the same underlying event: Pegasus spyware was used to hack European Parliament member Stelios Kouloglou while he was involved in oversight of spyware abuses, reinforcing and likely summarizing Citizen Lab's findings for the same case.
2026.07.03 100%
The article establishes a distinct concrete event: forensic confirmation that Pegasus infected a specific European Parliament member during the PEGA committee's spyware investigation, with new cross-linking to a broader Pegasus operator campaign.
Full page
Japanese police arrest teen over Bandai Channel cyberattack that canceled 46,000 anime subscriptions
Threat Actors & APTsMedia & EntertainmentConsumers & General PublicBandai ChannelTokyo Metropolitan Police Department
Japanese police arrested a 15-year-old student suspected of hacking Bandai Channel and causing more than 46,000 customer subscriptions to be canceled. Investigators say he analyzed the service's network traffic, found a server-side flaw, and used a program reportedly built with ChatGPT to send fraudulent requests to Bandai Channel's servers in November 2025. The attack disrupted the streaming platform for more than a month, and police say he kept abusing the flaw by rotating IP addresses after the company tried to block him.
Why it matters: This was not a minor prank: it disrupted a paid online service for weeks and directly affected tens of thousands of customers. Companies running consumer web services should review server-side request validation and abuse controls, while affected users should check account status and billing history.
Sources
2026.07.06 100%
This article appears to be the first tracked item establishing the underlying event: the arrest and police details tied to the November 2025 Bandai Channel service-disruption attack.
Full page
Kaspersky says Armored Likho is targeting government and electric power organizations in Russia, Brazil, and Kazakhstan
Threat Actors & APTsMalwareSocial Engineering & PhishingGovernmentEnergy & Utilities
A newly identified hacking group called Armored Likho has been targeting government and electric power organizations in multiple countries, while also running financially motivated attacks against individuals. Kaspersky says the actor uses spear-phishing emails with executable or shortcut (LNK) files to install malware including the Python-based BusySnake Stealer and Go2Tunnel, enabling credential theft, browser cookie and password extraction, Telegram session theft, screenshot capture, reverse SSH tunnels, and persistent remote access.
Why it matters: Government and energy organizations are high-value targets, and the campaign uses common email lures that can reach many users. Defenders should harden email filtering, block malicious LNK/executable attachments, monitor for GitHub-hosted payload retrieval and reverse SSH activity, and hunt for BusySnake, Go2Tunnel, and related persistence mechanisms.
Sources
Ionut Arghire 2026.07.06 100%
This article appears to be the first tracked report establishing Armored Likho as a distinct threat actor, naming its targets, countries, malware set, and initial access methods.
Full page
Ukraine says Russian hackers made media outlets a priority target after attacks on television broadcasters
Threat Actors & APTsSocial Engineering & PhishingDisinformation & Influence OpsMedia & EntertainmentGovernmentSBUSSSCIPChannel 5
Ukraine’s security agency says Russian hackers are increasingly targeting Ukrainian media organizations, including two previously undisclosed attacks on television broadcasters. The SBU said one incident this year was a large distributed denial-of-service, or DDoS, attack against a nationwide TV channel, while another last year combined phishing with attempts to access connected infrastructure to seize a major broadcaster’s platform and publish Russian propaganda as if it came from Ukrainian media.
Why it matters: This is a direct threat to news delivery and public trust during wartime, especially for broadcasters and media operations in Ukraine. Media organizations should urgently harden phishing defenses, review access to broadcast and publishing systems, and prepare for DDoS and account-takeover attempts.
Sources
2026.07.06 100%
This article establishes a distinct, official account of Russian cyber operations specifically prioritizing Ukrainian media, anchored by two newly disclosed attacks on TV broadcasters and a broader warning from Ukrainian authorities.
Full page
North Korea-linked PolinRider campaign hijacks more than 100 open-source packages and repositories to backdoor developers
Supply ChainThreat Actors & APTsMalwareTechnology & SoftwareGitHubPackagistChrome
North Korean hackers are compromising legitimate open-source packages and code repositories to infect software developers with a backdoor and an information stealer. Socket says the PolinRider campaign has been active since December 2025 and has produced 162 malicious release artifacts across 108 packages spanning npm, Packagist, Go modules, and Chrome extensions. The attackers reportedly hijack maintainer accounts, rewrite Git history to hide tampering, and use obfuscated JavaScript loaders to fetch DEV#POPPER remote-access malware and OmniStealer via blockchain and public remote procedure call infrastructure.
Why it matters: This can put developer laptops, source code, cloud accounts, and continuous integration and delivery secrets at risk even when teams install what look like trusted updates. Organizations that installed affected package or extension versions should treat those systems as compromised, investigate from clean machines, and rotate exposed credentials.
Sources
Ionut Arghire 2026.07.06 100%
This article establishes a distinct, named campaign—PolinRider—with its own scope, tactics, malware families, and package ecosystem impact, rather than merely updating a previously tracked single-package or single-namespace compromise.
Full page
Proof-of-concept exploit released for Linux kernel 'Bad Epoll' root flaw CVE-2026-46242
Zero-Days & CVEsTechnology & SoftwareConsumers & General PublicLinuxGoogle
A public exploit is now available for a Linux kernel bug that can let a normal local user gain full root control of a device. The flaw, CVE-2026-46242, is a race-condition use-after-free issue in epoll, the kernel's I/O event notification subsystem. It affects Linux distributions using kernel 6.4 or newer and was also confirmed on Pixel 10 devices running kernel 6.6. The published proof of concept shows privilege escalation through kernel memory leakage and a return-oriented programming, or ROP, chain.
Why it matters: Public exploit code makes this bug much easier for attackers and red teams to weaponize on vulnerable Linux systems and affected Android devices. Organizations and users running affected kernels should prioritize vendor patches and limit untrusted local code execution until updates are applied.
Sources
Ionut Arghire 2026.07.06 100%
This article establishes a distinct story because it centers on CVE-2026-46242 ('Bad Epoll') and the new publication of technical details and proof-of-concept exploit code, which is not the same underlying event as the already tracked Linux kernel flaws such as PinTheft, CIFSwitch, or CVE-2026-46333.
Full page
Sainsbury's expands Facewatch facial-recognition surveillance to up to 200 UK stores
Surveillance & PrivacyRetail & E-CommerceConsumers & General PublicSainsbury'sFacewatch
Sainsbury's says it will expand live facial recognition to as many as 200 supermarkets in the UK by the end of 2026, sharply increasing surveillance of ordinary shoppers. The system, supplied by Facewatch, is already active in more than 55 stores and is used to flag people on watchlists for suspected shoplifting. The expansion follows earlier deployments in London and renewed criticism after a shopper was wrongly confronted in store.
Why it matters: This matters because millions of customers may be scanned while shopping, with risks of false matches, wrongful accusations, and broader normalization of private-sector biometric surveillance. Retailers, policymakers, and privacy advocates will be watching whether the rollout triggers regulatory scrutiny or changes in how facial-recognition alerts are handled.
Sources
2026.07.06 100%
This article establishes a distinct, concrete event: Sainsbury's decision to greatly expand Facewatch live facial-recognition deployment across its store estate, making it a notable UK retail surveillance story.
Full page
Zscaler says prompt-injection websites trick some AI agents into making crypto payments and trusting fake DeBank pages
Scams & FraudSocial Engineering & PhishingTechnology & SoftwareCryptocurrency & BlockchainConsumers & General PublicZscalerDeBankGoogleAnthropicOpenAIMeta
Researchers found two live scam campaigns that hide instructions in web pages to manipulate autonomous AI agents, including one that got some agents to initiate cryptocurrency payments and another that made some models trust a fake DeBank site. Zscaler says the first campaign used search-result poisoning and fake API documentation for a bogus Python package, with hidden prompts in schema markup and HTML telling agents to pay for an API key; the second used typosquatting and search optimization to impersonate DeBank. In tests across 26 large language models, four executed a payment and two misidentified the fake site as legitimate.
Why it matters: Organizations experimenting with AI agents that can browse the web or make transactions could have those agents manipulated by hostile content. Treat web content as untrusted input for AI agents, restrict payment and external-action permissions, and add human approval before any financial or account-trust decision.
Sources
Ionut Arghire 2026.07.06 100%
This article establishes a distinct security story around in-the-wild prompt-injection scam campaigns targeting autonomous AI agents, not just a lab demonstration or a previously tracked flaw.
Full page
Moody Bible Institute says ShinyHunters breach exposed data on 2.3 million students, alumni, donors, and supporters
Breaches & Data LeaksThreat Actors & APTsEducationNonprofits & NGOsMoody Bible Institute
Moody Bible Institute says a cyberattack linked to ShinyHunters exposed personal data tied to more than 2.3 million people. The Christian college disclosed the incident in June 2026, and ShinyHunters later leaked the stolen files on June 23 after an apparent extortion attempt. Reported data includes names, genders, dates of birth, physical and email addresses, phone numbers, marital status, and documents related to students, alumni, donors, and supporters.
Why it matters: This is a large-scale personal-data breach affecting current and former members of an educational and religious institution, creating risk of identity theft, fraud, and targeted phishing. Affected people should monitor financial and online accounts, consider fraud alerts or credit freezes, and be cautious of messages referencing Moody Bible Institute.
Sources
2026.07.06 100%
This article establishes a distinct breach event at Moody Bible Institute, including the victim, threat actor, leaked data types, and approximate number of affected accounts.
Full page
France’s ANSSI says it will stop certifying security products that lack quantum-safe encryption starting in 2027
Policy & RegulationGovernmentConsumers & General PublicANSSI
France’s cyber agency says security products that do not use post-quantum, or quantum-resistant, encryption will no longer receive its approval starting in 2027. ANSSI said the change will apply to certifications required for French government agencies and critical operators, making it a de facto phase-out of older cryptography, and urged businesses to buy only quantum-safe products by 2030.
Why it matters: This is an early hard deadline from a national cyber authority that can force major upgrades across government and critical infrastructure. Organizations selling into or operating in those sectors in France should review whether their products and deployed encryption are on a credible post-quantum migration path now.
Sources
Bruce Schneier 2026.07.06 100%
This article establishes a new tracked story because it reports a specific ANSSI policy announcement with clear dates and direct security impact, not an update to an existing tracked event.
Full page
Automated ransomware attack exploited Langflow CVE-2025-3248 and Nacos CVE-2021-29441 to destroy server data
Zero-Days & CVEsMalwareRansomwareTechnology & SoftwareConsumers & General PublicLangflowAlibaba
Researchers say an attacker used a large language model to automate a full ransomware and extortion attack against exposed servers, ending with encrypted and deleted data. Sysdig said the intrusion began by exploiting Langflow CVE-2025-3248, an unauthenticated remote-code-execution flaw, then moved to a production server running MySQL and Alibaba Nacos, abused Nacos CVE-2021-29441 and the product's default JWT signing key, added a backdoor admin, and encrypted 1,342 configuration records before dropping database schemas.
Why it matters: Organizations running internet-exposed Langflow or Nacos instances could face fast, destructive break-ins that do not reliably allow recovery even if a ransom is paid. Defenders should urgently patch or isolate exposed systems, rotate credentials, and check for cron-based persistence, rogue Nacos admins, and database tampering.
Sources
Bill Toulas 2026.07.04 97%
This appears to be the same underlying JadePuffer incident and adds specific attribution of the intrusion workflow to an autonomous LLM agent, along with concrete details on post-exploitation behavior: PostgreSQL dumping, MinIO enumeration, cron-based persistence, pivoting to Nacos, and encryption of 1,342 configuration items using MySQL AES_ENCRYPT().
Ionut Arghire 2026.07.03 99%
This is a direct update on the same underlying event: a ransomware attack in which attackers exploited Langflow CVE-2025-3248, pivoted to Nacos using CVE-2021-29441 and the default JWT signing key, and used an LLM agent to automate reconnaissance, credential theft, lateral movement, persistence, and destructive encryption.
2026.07.02 100%
This article establishes a distinct incident centered on an automated ransomware intrusion that chained Langflow CVE-2025-3248 with Nacos weaknesses to encrypt and destroy production data.
Full page
Researchers say attested TLS in confidential computing can be bypassed, undermining Intel TDX and cloud trust claims
Surveillance & PrivacyTechnology & SoftwareTechnology & SoftwareGovernmentConsumers & General PublicIntelGoogle CloudAMD
New academic research says a key security check used in confidential computing can verify the software on a server but still fail to prove the client is talking to the right machine. The papers describe diversion and relay attacks against attested TLS, the protocol used to bind remote attestation evidence to a Transport Layer Security (TLS) connection, including intra-handshake attestation designs. The work focuses on protocol designs used with Trusted Execution Environments such as Intel TDX and affects how cloud providers and customers should evaluate confidential-computing trust guarantees.
Why it matters: Organizations relying on confidential computing for sensitive cloud workloads may be getting weaker identity guarantees than they expect, especially for sovereignty, isolation, and protected AI or data-processing use cases. This is not a patch-now CVE story, but defenders, cloud buyers, and regulators should reassess whether remote attestation deployments actually authenticate the intended server and watch for vendor guidance or architectural changes.
Sources
2026.07.04 100%
This article establishes a new story by introducing specific 2026 research papers and conference findings showing that attested TLS, a core trust mechanism in confidential computing, may be fundamentally unable to guarantee endpoint identity.
Full page
Researchers link Popa Android TV box botnet and residential proxy network to NetNut and Alarum Technologies
Scams & FraudMalwareThreat Actors & APTsTechnology & SoftwareConsumers & General PublicNetNutAlarum TechnologiesGoogleFBIShadowserverLumen
Researchers say a sprawling Android TV box botnet called Popa has been turning millions of consumer streaming devices into residential proxies that relay malicious traffic. KrebsOnSecurity, citing Qurium and earlier XLAB findings, says Popa is associated with the Vo1d malware ecosystem and has been used for advertising fraud, account-takeover activity, and mass data scraping; newly analyzed command-and-control domains including ninjatech[.]io are linked to NetNut, a proxy provider owned by Alarum Technologies.
Why it matters: People who bought unofficial streaming boxes may have unknowingly exposed their home internet connections and possibly local networks to abuse by third parties. Consumers should disconnect suspect devices, replace them with trusted hardware, and monitor accounts and network activity; defenders should block known Popa infrastructure and scrutinize traffic from Android-based set-top boxes and residential proxy sources.
Sources
Ionut Ilascu 2026.07.03 95%
This updates the same underlying NetNut/Popa residential proxy network story with a coordinated takedown: Google says the botnet controlled at least 2 million infected Android devices, the FBI seized a domain used by NetNut, Google disabled related C2 infrastructure, and Play Protect warnings and app disabling were used to protect affected users.
2026.07.03 84%
This updates the same underlying NetNut residential proxy ecosystem story by reporting a coordinated disruption by Google, the FBI, Lumen, and Shadowserver, adding that investigators believe NetNut had at least 2 million enrolled devices and that many reseller proxy brands may depend on the same network.
Ionut Arghire 2026.07.03 97%
This article updates the same underlying NetNut/Popa event with new details that Google, the FBI, and partners took coordinated action to disrupt the proxy network, disabled Google accounts and command-and-control services, used Play Protect to block infected apps, and observed 316 threat clusters abusing NetNut in June.
BrianKrebs 2026.07.02 98%
This article is a direct update on the same underlying event: the Popa botnet and its linkage to NetNut. It adds that the FBI, with partners including Google, seized hundreds of NetNut-related domains, replaced the homepage with a seizure banner, and disrupted both the botnet and the proxy network built on top of it.
SecurityWeek News 2026.06.19 62%
It briefly notes the same Popa Android TV botnet story and the claimed linkage to an Israeli firm, adding only summary-level context rather than substantive new facts.
BrianKrebs 2026.06.18 100%
This article establishes a distinct story by adding a concrete attribution link between the long-running Popa/Vo1d consumer-device botnet and NetNut/Alarum infrastructure, rather than merely describing generic residential proxy abuse.
Full page
Gitea CVE-2026-27771 let anyone pull private container images from thousands of self-hosted servers
Urgent PatchesSupply ChainZero-Days & CVEsTechnology & SoftwareGiteaForgejo
A flaw in Gitea could let outsiders download supposedly private software container images from many self-hosted code servers. NoScope says CVE-2026-27771 is an access-control bug in Gitea’s built-in container registry, also affecting Forgejo, where anonymous Docker/OCI pull requests could retrieve private images; Gitea patched it in version 1.26.2, and Shodan data suggested roughly 31,750 internet-facing instances were likely vulnerable.
Why it matters: Private container images can contain source code, credentials, and details about production systems, so this exposure could hand attackers valuable access and intelligence. Organizations running self-hosted Gitea or Forgejo should update to 1.26.2 immediately or enforce authentication for all content access if possible.
Sources
SecurityWeek News 2026.07.03 72%
This source indicates the same researcher disclosed proof-of-concept code affecting Gitea as part of a larger open-source zero-day drop, connecting that specific flaw to a broader disclosure event.
Ionut Arghire 2026.05.28 100%
This article establishes a new tracked story around CVE-2026-27771, a newly reported Gitea/Forgejo container registry access-control flaw with patch availability and internet-scale exposure.
Full page
Unpatched Gogs zero-day lets attackers run code on self-hosted Git servers
Urgent PatchesSupply ChainZero-Days & CVEsTechnology & SoftwareGogs
A newly disclosed flaw in Gogs can let attackers take over internet-exposed code servers if they can register a normal user account. The unpatched argument-injection vulnerability, not yet assigned a CVE, affects Gogs 0.14.2 and 0.15.0+dev and is triggered during the "Rebase before merging" pull-request flow; because open registration is enabled by default, many default-configured servers may be reachable by unauthenticated attackers who simply sign up first. Rapid7 says successful exploitation can lead to remote code execution as the server process user, access to private repositories, and theft of password hashes, API tokens, SSH keys, and 2FA secrets.
Why it matters: Organizations running self-hosted Gogs should treat this as urgent because exposed servers may be compromiseable even without an existing attacker account. Until a fix is available, admins should disable open registration, restrict internet exposure, and review whether rebase-merging can be turned off or tightly limited.
Sources
SecurityWeek News 2026.07.03 74%
This article places the Gogs zero-day into a larger batch of public disclosures and says the researcher published proof-of-concept code for dozens of open-source flaws, including Gogs.
Sergiu Gatlan 2026.06.08 98%
This article is a direct update to the same Gogs argument-injection zero-day: it adds that Gogs released version 0.14.3 on June 7 to fix the flaw, requested a CVE, and published concrete mitigations for users who cannot patch immediately.
2026.05.29 98%
This article is the same underlying Gogs zero-day event and adds that there is still no official fix, Rapid7 has now published a Metasploit exploit module, the researcher says maintainers stopped responding after March 28, and a proposed patch has been submitted while users are urged to disable registration and rebase merging.
Ionut Arghire 2026.05.29 98%
This article is a direct report on the same Gogs zero-day event, adding technical detail from Rapid7 on the argument-injection root cause, the 'Rebase before merging' attack path via malicious branch names, default open registration risk, cross-platform impact, lack of a patch, and the release of a Metasploit module and indicators of compromise.
info@thehackernews.com (The Hacker News) 2026.05.28 97%
This article appears to cover the same underlying Gogs authenticated remote code execution issue, adding another report that characterizes it as critical and exploitable by any authenticated user on affected self-hosted servers.
Sergiu Gatlan 2026.05.28 100%
This article establishes a distinct new Gogs zero-day event: a newly disclosed, unpatched remote-code-execution flaw in current Gogs releases, separate from the earlier CVE-2025-8110 zero-day mentioned only as background.
Full page
Attackers use fake OpenAI organization invites to impersonate companies and target employees
Social Engineering & PhishingTechnology & SoftwareOpenAIPush Security
Attackers are creating fraudulent OpenAI ChatGPT organizations that look like real companies and inviting employees to join them through legitimate OpenAI emails. Push Security said the campaign targeted employees in cybersecurity and technology firms using work addresses, with fake tenants named after the victim company and attacker-controlled Gmail accounts inside posing as company staff. The apparent goal is to get victims to use the workspace and paste in sensitive data such as source code, internal documents, customer information, or research.
Why it matters: This matters because the emails are sent by OpenAI itself, so they can bypass normal phishing suspicion and email defenses. Organizations using ChatGPT Enterprise or shared AI workspaces should warn staff to verify who created tenant invites and avoid joining unexpected workspaces or sharing sensitive data in them.
Sources
SecurityWeek News 2026.07.03 88%
The roundup adds a concrete example of the poisoned-tenant technique being used against Push Security through OpenAI organization invitations that impersonated the company and could have enabled spying or follow-on social engineering.
Lawrence Abrams 2026.06.26 100%
This article establishes a distinct social-engineering campaign centered on attacker-created OpenAI tenants and legitimate organization invitation emails, not a patch, CVE, or previously tracked OpenAI abuse event.
Full page
Researcher publishes proof-of-concept exploits for dozens of open-source zero-days including FFmpeg, OpenVPN, VLC, 7-Zip, and Ghidra
Zero-Days & CVEsTechnology & SoftwareConsumers & General PublicFFmpegOpenVPNVLC7-ZipGhidraGitea
A researcher has publicly released proof-of-concept exploit code for dozens of previously unknown vulnerabilities in widely used open-source software, raising the risk of copycat attacks before many users have fixes. SecurityWeek says the disclosures affect projects including FFmpeg, OpenVPN, VLC, 7-Zip, Ghidra, Gogs, and Gitea, and that nine of the flaws have CVE identifiers so far. The researcher said the bugs were found with large-language-model-assisted fuzzing, an automated bug-hunting technique.
Why it matters: This matters because public exploit code can sharply speed up real-world attacks against unpatched systems and developer tools. Organizations using the named projects should urgently inventory exposure, watch for vendor advisories and patches, and consider temporary mitigations or isolation for internet-facing deployments.
Sources
SecurityWeek News 2026.07.03 100%
This article is the first item here establishing the broader event: a mass public release of open-source zero-days spanning multiple popular projects, beyond any single previously tracked product-specific flaw.
Full page
Google says pro-Russia influence operations are widening beyond Ukraine to target the U.S., Europe, NATO, and Africa
Disinformation & Influence OpsGoogle
Google says covert pro-Russia influence campaigns are broadening their targets and narratives beyond Ukraine, with activity now aimed at the United States, European Union countries, NATO, Russia’s neighbors, the Middle East, Africa, and domestic Russian audiences. The report describes a shift from war-focused messaging to broader pre-war geopolitical objectives, indicating a wider information operation rather than a single isolated propaganda push.
Why it matters: This is relevant because it signals an expanded disinformation threat that can affect elections, public debate, and crisis response across multiple regions. Governments, platforms, researchers, and news consumers should expect more coordinated influence activity and scrutinize suspicious cross-platform narratives and inauthentic amplification.
Sources
SecurityWeek News 2026.07.03 100%
The article identifies a concrete new development in ongoing pro-Russia influence operations: a documented strategic shift in targeting and objectives across regions.
Full page
AdaptHealth says social engineering of a contractor led to theft of patient data from cloud systems
Breaches & Data LeaksSocial Engineering & PhishingSurveillance & PrivacyHealthcareAdaptHealth
AdaptHealth says attackers tricked a third-party contractor and then got into the company's cloud systems, stealing patient data. In its SEC filing, the home medical equipment provider said the intrusion exposed internal patient management systems, document storage platforms, external electronic health record portals, a password file tied to insurance billing, and some personally identifiable information and protected health information. The company said Social Security numbers and payment data are not currently believed to be affected, and it has not yet disclosed the full scope.
Why it matters: This affects healthcare patients whose medical and personal data may now be exposed, and it shows how one manipulated contractor account can open access to sensitive cloud systems. Organizations using contractors should review third-party access, reset exposed credentials, and watch for follow-on fraud or extortion.
Sources
2026.07.03 100%
This article appears to be the initial public disclosure of a distinct AdaptHealth breach, with concrete details from the company's SEC filing about the attack vector, affected systems, and stolen patient data.
Full page
ARToken phishing service tied to EvilTokens expands Microsoft 365 token theft and business email compromise attacks
Social Engineering & PhishingScams & FraudThreat Actors & APTsConsumers & General PublicGovernmentFinance & BankingTechnology & SoftwareLegal & Professional ServicesMicrosoftCloudflare
Researchers say a phishing service called ARToken is tied to the EvilTokens platform and is being used to break into Microsoft 365 accounts and steal long-lived access tokens. Cisco Talos found a React-based ARToken management panel with more than 80 API endpoints, including the same Microsoft OAuth 2.0 device-code phishing and Primary Refresh Token (PRT) workflows previously linked to EvilTokens. The toolkit can access Outlook, SharePoint, and OneDrive, create inbox rules, send mail from victim accounts, and deploy phishing infrastructure through Cloudflare Workers.
Why it matters: This matters because the attacks use Microsoft's legitimate device login flow, which can trick users into handing over access even when multi-factor authentication is enabled. Organizations using Microsoft 365 should urgently review device-code sign-in activity, tighten controls around OAuth and token use, monitor for suspicious inbox rules and mail forwarding, and warn users about unexpected prompts to enter device codes.
Sources
Lawrence Abrams 2026.07.03 100%
This article establishes a distinct tracked story by adding new technical reporting on ARToken as an apparent EvilTokens affiliate platform, with concrete details about its Microsoft 365 token theft, persistence, and BEC automation capabilities.
Full page
Cursor patches DuneSlide flaws CVE-2026-50548 and CVE-2026-50549 that could let malicious prompts run code on developers’ computers
Zero-Days & CVEsTechnology & SoftwareCursor
Cursor fixed two critical security flaws that could let a booby-trapped prompt or attacker-controlled payload escape the AI coding editor’s sandbox and run code on the underlying computer. Cato Networks says CVE-2026-50548 and CVE-2026-50549, both rated 9.8, affected Cursor before version 3.0 and enabled zero-click prompt-injection attacks by abusing automatic terminal command execution, working-directory allowlisting, and symlink-based path resolution to overwrite the cursorsandbox executable and achieve operating-system-level remote code execution.
Why it matters: Developers using vulnerable Cursor versions could have their machines compromised just by getting the IDE to ingest malicious content, making this a high-impact workstation risk. Organizations should update Cursor to version 3.0 or later and treat untrusted prompts, repositories, and MCP-connected content as potentially hostile.
Sources
Ionut Arghire 2026.07.03 100%
This article establishes a distinct tracked story by naming the concrete event: the DuneSlide disclosure and patch for Cursor flaws CVE-2026-50548 and CVE-2026-50549 enabling sandbox escape and OS-level remote code execution.
Full page
UK delays National Cyber Action Plan again after Prime Minister Keir Starmer resigns
Policy & RegulationGovernmentConsumers & General PublicUK governmentNational Cyber Security Centre
The UK government has again delayed its National Cyber Action Plan, the policy meant to strengthen cyber defenses across the wider economy, after Prime Minister Keir Starmer’s resignation triggered political uncertainty. Recorded Future News reports the plan had been due for publication on July 1 but was postponed amid Labour’s leadership contest. The article also ties the delay to a broader slowdown in UK cyber policy, including the Cyber Security and Resilience Bill and long-promised ransomware reporting and payment rules.
Why it matters: This matters because it pushes back government guidance and policy changes that businesses and critical infrastructure operators may be relying on to plan security improvements. For defenders and regulated organizations in the UK, it signals more delay around expected cyber resilience requirements and ransomware-related rules.
Sources
2026.07.02 100%
This article establishes a distinct policy story about the delayed publication of the UK’s National Cyber Action Plan, tied specifically to Starmer’s resignation and the Labour leadership crisis.
Full page
Supreme Court ruling on FTC independence puts EU-U.S. Data Privacy Framework at risk
Surveillance & PrivacyPolicy & RegulationTechnology & SoftwareConsumers & General PublicFTCEuropean CommissionEuropean Data Protection BoardMetaGooglenoyb
A U.S. Supreme Court ruling has triggered a new challenge to the legal framework that lets European personal data flow to U.S. companies. Privacy advocate Max Schrems said he plans to sue to invalidate the EU-U.S. Data Privacy Framework after the Court held the president could remove an FTC commissioner without cause, raising questions about whether the Federal Trade Commission remains independent enough to satisfy the framework’s oversight requirements. The European Commission and the European Data Protection Board said they are reviewing the implications.
Why it matters: If the framework is struck down or suspended, companies that move Europeans’ personal data to U.S. services could face major compliance and operational disruption. This matters now because organizations relying on transatlantic data transfers may need contingency plans, while users face renewed uncertainty over how their data is protected.
Sources
2026.07.02 100%
This article establishes a distinct story about a Supreme Court ruling's direct impact on the legal basis for EU-U.S. personal-data transfers and the resulting challenge to the Data Privacy Framework.
Full page
Fake GitHub pages impersonating Arctic Wolf and other software vendors are spreading BoryptGrab stealer malware
MalwareSocial Engineering & PhishingTechnology & SoftwareConsumers & General PublicArctic WolfGitHubMalwarebytesBitdefender360 Total Security
Attackers created fake GitHub pages that impersonate Arctic Wolf and many other software brands to trick people into downloading malware. Arctic Wolf says one bogus repository used an 'Official Page' link to deliver a ZIP file containing a trojanized installer, 'Arctic-Wolf-3.9.7.exe,' which side-loaded a fake libcurl.dll to decrypt and launch BoryptGrab Stealer, an information-stealing malware family. The company says it found nearly 300 similar repositories using search-engine bait and branding from vendors including Malwarebytes, Bitdefender, and 360 Total Security.
Why it matters: This is a broad social-engineering and malware campaign that can hit employees and consumers who trust GitHub pages and software downloads that look official. Organizations should warn users, block known indicators, and tell staff to download tools only from verified vendor sites or trusted repositories.
Sources
Arctic Wolf Labs 2026.07.02 100%
This article appears to be the first concrete report in the set establishing this specific fake-GitHub vendor-impersonation campaign and naming BoryptGrab Stealer as the payload.
Full page
FortiBleed campaign compromised more than 30,000 Fortinet firewalls and VPN gateways worldwide
Urgent PatchesMalwareRansomwareSocial Engineering & PhishingPolicy & RegulationBreaches & Data LeaksThreat Actors & APTsGovernmentDefense & AerospaceTechnology & SoftwareTelecommunicationsFinance & BankingHealthcareEducationManufacturingTransportation & LogisticsConsumers & General PublicEnergy & UtilitiesLegal & Professional ServicesRetail & E-CommerceHospitality & TravelFortinetChevronSamsungFoxconnComcastAT&TSiemensLenovoCISAMercedes-BenzHuntressHudson RockSophosNextcloudINC RansomLynx
Researchers say more than 30,000 Fortinet firewalls and virtual private network gateways were compromised and can expose the organizations behind them to further hacking. SOCRadar said a campaign it calls FortiBleed systematically tried known passwords against internet-exposed Fortinet devices, harvested working credentials, then monitored traffic and reused newly captured passwords to spread further; victims span companies and government bodies in more than 190 countries.
Why it matters: Organizations using Fortinet edge devices may already have attackers inside even without a new software flaw. This is urgent for network defenders: audit Fortinet logins, rotate passwords and tokens, review device configurations, and check for signs of credential harvesting or unauthorized access.
Sources
2026.07.02 95%
This article directly updates the FortiBleed event by linking the credential-harvesting campaign to ransomware operations, reporting that SOC Radar found a shared operator tied to both INC Ransom and Lynx affiliate panels and linked at least 12 ransomware attacks to FortiBleed victims.
Ionut Arghire 2026.07.02 95%
This source updates the same FortiBleed campaign by adding evidence that harvested FortiGate credentials were used in follow-on ransomware attacks, specifically linking the operation to INC and Lynx, and adding scope figures on scanned portals, admin compromise, domain takeover, and ransomware deployment.
Lawrence Abrams 2026.07.01 98%
This article directly advances the same FortiBleed event by linking the campaign to INC and Lynx ransomware operators, expanding the known scope to 430,000 targeted FortiGate devices and about 19,000 with sniffers deployed, identifying more operational servers, and noting suspected use of an undisclosed Nextcloud zero-day plus persistent backdoor accounts named 'adminin'.
Arctic Wolf Labs 2026.06.24 95%
This is a direct follow-up on the same FortiBleed campaign and adds concrete reverse-engineering details about the recovered CyberStrike Harvester tool, the operator workflow, credential-stuffing and password-spraying tradecraft, offline cracking pipeline, post-authentication capture processing, and the assessment that the campaign is likely an initial-access and credential-monetization operation rather than one primarily driven by a Fortinet CVE exploit.
Ionut Arghire 2026.06.23 95%
This is a direct update on the same FortiBleed campaign, adding attribution to a likely Russian-speaking initial access broker, explaining that the operation is multi-vendor rather than Fortinet-only, detailing the custom FortigateSniffer tool and SSH brute-force intrusion method, and expanding the estimated scale to 110 million captured credentials and 430,000 FortiGate devices in scope.
Lawrence Abrams 2026.06.22 96%
This directly updates the same FortiBleed campaign by adding new findings that the actor used a custom Golang-based sniffer on compromised FortiGate devices to capture RADIUS, NTLM, Kerberos, LDAP, email, database, and other authentication material, reinforcing that the campaign is an ongoing initial-access operation rather than just a dump of old credentials.
Ionut Arghire 2026.06.22 98%
This is a direct update on the same FortiBleed campaign, adding Fortinet's response that the activity does not rely on a new vulnerability, ties it to reused credentials and brute-force attacks, cites prior FortiCloud SSO flaws CVE-2026-24858, CVE-2025-59718, and CVE-2025-59719, and says over 86,000 working credentials were compiled across 194 countries.
info@thehackernews.com (The Hacker News) 2026.06.19 94%
This appears to be an update on the same FortiBleed campaign, adding CISA warning context and a much larger observed impact count of 86,644 exposed or affected FortiGate devices.
Ionut Arghire 2026.06.19 98%
This is a direct update on the same FortiBleed campaign, raising the count from more than 30,000 to 86,644 valid credentials, adding CISA hardening guidance, and citing additional validation from Hudson Rock, Huntress, Kevin Beaumont, and Bob Diachenko about scope, recency, and follow-on compromises.
Sergiu Gatlan 2026.06.19 97%
This article is a direct update on the same FortiBleed credential-leak campaign, adding CISA's warning and mitigation guidance, an updated scale of roughly 74,000 exposed credentials, and additional reporting that threat actors used the leaked credentials to target internet-accessible Fortinet devices across government and private-sector organizations.
Arctic Wolf Labs 2026.06.17 98%
This is the same underlying FortiBleed event and adds a defender-focused summary of the scope across 194 countries, the estimate of 30,791 to 75,000 affected devices, and Fortinet-specific mitigation details about legacy SHA-256 password hashes persisting after upgrades unless admins log in or reset passwords.
2026.06.17 98%
This is the same FortiBleed credential-theft campaign and updates the scope from more than 30,000 to around 75,000 compromised Fortinet devices, adds verification from Hudson Rock and Kevin Beaumont that the credentials are real, and adds details about 21,632 affected domains across 194 countries and at least four full compromises including a Turkish NATO defense contractor.
Lawrence Abrams 2026.06.17 96%
This article appears to be a direct update on the same FortiBleed event, adding that an exposed server contained credentials for 73,932 Fortinet/FortiGate VPN URLs, with usernames, email addresses, and plaintext passwords, along with claimed evidence of large-scale brute-force and compromise activity across 194 countries.
Eduard Kovacs 2026.06.17 100%
The article introduces a separate, concrete campaign dubbed FortiBleed involving large-scale compromise of Fortinet firewalls and VPN gateways, not just exploitation of the already tracked FortiSandbox CVE story.
Full page
FTC considers changing or dropping privacy order against X over Twitter’s use of 2FA phone numbers and emails for ads
Surveillance & PrivacyPolicy & RegulationGovernmentTechnology & SoftwareMedia & EntertainmentConsumers & General PublicFTCXTwitter
The U.S. Federal Trade Commission is considering whether to modify or set aside a 2022 privacy order against X, formerly Twitter, over the company’s use of account security data for targeted advertising. The original order followed FTC allegations that Twitter collected phone numbers and email addresses for account security, including two-factor authentication (2FA), then used that data for ads in violation of a 2011 privacy order; the case involved more than 140 million users and a $150 million penalty. The FTC has opened a public comment period through July 2, 2026.
Why it matters: This matters to X users because it concerns whether protections imposed after a major misuse of security-related personal data will remain in force. It also matters more broadly because weakening the order could signal reduced privacy enforcement around companies that repurpose security data for advertising.
Sources
Bill Budington 2026.07.02 94%
This article directly updates the same FTC petition event by adding EFF and allied groups' formal opposition, arguing that X's name change, management changes, AI ambitions, and claimed compliance burden are not valid grounds to lift or shorten the 2022 order.
2026.06.04 100%
The article establishes a fresh regulatory development: the FTC is actively reconsidering an existing privacy enforcement order against X/Twitter, with potential consequences for user data protections and future privacy enforcement.
Full page
Citrix patches NetScaler information disclosure flaw CVE-2026-8451 and five other vulnerabilities in ADC and Gateway
Urgent PatchesZero-Days & CVEsTechnology & SoftwareTelecommunicationsGovernmentFinance & BankingHealthcareConsumers & General PublicCitrixNetScaler
Citrix released security updates for NetScaler ADC and NetScaler Gateway to fix six vulnerabilities that could expose sensitive memory, crash devices, or allow unauthorized file access. The fixes cover CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, another medium-severity out-of-bounds read issue, and the NetScaler-specific HTTP/2 Bomb CVE-2026-13474; affected releases include 14.1-72.61 and 13.1-63.18, with FIPS and NDcPP builds also updated. WatchTowr says CVE-2026-8451 is a CitrixBleed-style memory disclosure bug tied to the XML parser and exploitable when NetScaler is configured as a Security Assertion Markup Language identity provider.
Why it matters: Organizations running self-managed NetScaler systems should treat this as a prompt patching issue because one flaw can leak memory and may help attackers chain toward full appliance compromise. Admins should update affected versions quickly and verify whether exposed features such as Security Assertion Markup Language identity provider mode are enabled.
Sources
Ionut Arghire 2026.07.02 95%
This article directly updates the same CVE-2026-8451 NetScaler event by adding that attackers began probing and exploiting the flaw within 24 hours of disclosure, with observed payloads matching the public watchTowr detection artefact and targeting SAML IdP endpoints.
Ionut Arghire 2026.07.01 100%
The article establishes a distinct NetScaler patch event beyond the broader HTTP/2 Bomb story by introducing Citrix-specific CVEs, affected product versions, and a separate high-severity CitrixBleed-style information disclosure flaw.
Full page
CISA says attackers are exploiting Microsoft SharePoint remote-code-execution flaw CVE-2026-45659
Urgent PatchesZero-Days & CVEsGovernmentTechnology & SoftwareCISAMicrosoft
CISA warned that attackers are now actively exploiting a Microsoft SharePoint server flaw that can let a low-privilege user run code on vulnerable systems. The bug, CVE-2026-45659, is a deserialization issue in SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition; Microsoft released fixes on May 21, 2026 after the CVE was omitted from its May security update listing. CISA added it to the Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to patch by Saturday.
Why it matters: Organizations running on-premises SharePoint, especially internet-exposed servers, should treat this as urgent because attackers can exploit it remotely with only Site Member-level access. Patch immediately, review internet exposure, and check for signs of compromise on SharePoint servers.
Sources
2026.07.02 98%
This article is a direct update on the same event: CISA adding CVE-2026-45659 to the KEV catalog and confirming active exploitation. It adds context that Microsoft had previously rated exploitation as 'Less Likely,' reiterates that only a valid SharePoint account with Site Member permissions is needed, and notes the federal remediation deadline of July 4 under BOD 26-04.
Sergiu Gatlan 2026.07.02 100%
This article establishes a distinct tracked event by adding the key new development that CVE-2026-45659 in Microsoft SharePoint is now under active exploitation and has entered CISA's KEV process.
Ionut Arghire 2026.07.02 98%
This article directly matches that event and adds that CISA placed the flaw in the KEV catalog on July 2, 2026, cited active exploitation, and that Microsoft had previously shipped an out-of-band fix in late May for affected SharePoint Server 2016, 2019, Subscription Edition, and SharePoint Enterprise Server 2016.
Full page
ConsentFix phishing trick steals Microsoft 365 session tokens through fake OAuth sign-in steps
Social Engineering & PhishingTechnology & SoftwareConsumers & General PublicMicrosoftDropboxDocSend
Attackers are using a new phishing technique called ConsentFix to hijack Microsoft 365 accounts by tricking users into completing what looks like a normal sign-in step. The lure often arrives through services such as Dropbox or DocSend and asks the victim to drag a localhost callback link into the browser during a Microsoft OAuth consent flow; doing so exposes OAuth session tokens, giving attackers access to email and other Microsoft 365 services without needing the user's password and effectively bypassing multi-factor authentication for that session. The article also says a full how-to guide, code, screenshots, and a video tutorial were posted on a Russian cybercrime forum in March 2026.
Why it matters: Microsoft 365 users and organizations can lose account access in seconds even when users do not type passwords into a fake page. Defenders should review OAuth app-consent controls, train users about drag-and-drop and fake verification prompts, and monitor for suspicious token issuance and cloud-session abuse.
Sources
Sponsored by Huntress Labs 2026.07.02 100%
This article establishes a distinct, named attack pattern focused on Microsoft 365 OAuth consent-flow abuse and session-token theft, rather than updating an already tracked incident or campaign in the list.
Full page
India temporarily blocks Telegram and disables message editing over NEET medical exam cheating scams
Information FreedomCensorshipPolicy & RegulationScams & FraudSocial Engineering & PhishingEducationConsumers & General PublicTelecommunicationsTelegramNational Testing AgencyIndian governmentRelianceMinistry of Electronics and Information TechnologyReliance JioDelhi High CourtWhatsAppMeta
India temporarily restricted Telegram nationwide ahead of the rerun of its medical entrance exam after authorities said scammers were using the app to sell fake leaked test papers. The National Testing Agency said access would be blocked until June 22 and Telegram's message-editing feature disabled in India until June 30; officials said fraudsters used edited posts to make it appear they had advance access to real NEET-UG questions, and police in Ahmedabad arrested suspects tied to eight Telegram channels in a scheme that moved about 15 million rupees.
Why it matters: This affects millions of Telegram users in India and shows how governments may impose platform-level restrictions in response to fraud and rumor campaigns. Students and families should be wary of Telegram channels offering leaked exam papers, while defenders and rights groups should track the censorship and platform-governance implications of disabling communications tools to address scams.
Sources
2026.07.02 34%
This involves the same government regulator, MeitY, taking security-related action against a messaging platform in India, but it is a different underlying event: a proposed WhatsApp usernames rollout pause over impersonation and scam concerns rather than Telegram restrictions tied to exam-cheating scams.
Ax Sharma 2026.06.18 93%
This is a direct update on the same Telegram block tied to the NEET-UG exam. It adds the government’s court affidavit saying Telegram admitted it could not proactively detect exam-leak channels, confirms officials warned the company before the block, notes the Delhi High Court has reserved its ruling, and adds Jio’s denial regarding the BGP route-leak accusations.
Ax Sharma 2026.06.17 94%
This article adds that the India Telegram block appears to have disrupted access outside India, including in the UAE, because AS18101 announced Telegram IP prefixes; it also adds the dispute over whether the BGP event was deliberate sabotage or a misconfigured domestic block leaked globally.
2026.06.16 96%
This article is a direct update on the same underlying event: India's temporary Telegram block and message-editing restriction tied to the NEET-UG exam rerun. It adds Telegram founder Pavel Durov's criticism, details from Telegram's court challenge in New Delhi, and the company's claim that it removed 900+ NEET-related links and proposed narrower content takedowns instead of a nationwide block.
2026.06.16 100%
This article establishes a new story because it centers on a distinct government-ordered platform block and feature restriction tied to exam-fraud scams around India's NEET-UG retest, with no direct match in the tracked stories list.
Full page
India orders WhatsApp to explain and pause username rollout over impersonation and scam fears
Policy & RegulationSocial Engineering & PhishingScams & FraudConsumers & General PublicWhatsAppMetaMinistry of Electronics and Information Technology
India told WhatsApp to justify its planned username feature within three days and asked the company to halt the rollout until regulators review it. The Ministry of Electronics and Information Technology said letting people contact others by username instead of phone number could increase impersonation, phishing, and 'digital arrest' scams, especially by attackers posing as officials, banks, or government departments; WhatsApp said the feature is not yet live and will roll out later this year with account-age, shared-group, and country signals plus reserved high-profile names.
Why it matters: This could affect WhatsApp users in its biggest market and signals a direct government intervention in a messaging platform feature over fraud and account-trust concerns. Users should be cautious about new first-contact messages when usernames launch, and defenders should watch for impersonation scams that exploit name-based discovery.
Sources
2026.07.02 100%
The article establishes a distinct story: a specific Indian regulatory action aimed at stopping WhatsApp's upcoming usernames feature because of concrete security and fraud concerns.
Full page
Cisco patches Cisco Unified CM flaw CVE-2026-20230 that could lead to root access, warns public PoC exists
Urgent PatchesZero-Days & CVEsTechnology & SoftwareTelecommunicationsConsumers & General PublicGovernmentCiscoCISA
Cisco released fixes for a serious security flaw in Cisco Unified Communications Manager and Unified Communications Manager Session Management Edition that could let remote attackers gain a path to full control of affected appliances. The bug, CVE-2026-20230, is a server-side request forgery issue caused by improper validation of certain HTTP requests; on systems with the WebDialer service enabled, an unauthenticated attacker can send crafted requests to write files to the underlying operating system and potentially escalate to root. Cisco fixed it in Unified CM and Unified CM SME 14SU6 and plans to include fixes in 15SU5.
Why it matters: Organizations running affected Cisco call-management systems should check whether WebDialer is enabled and apply updates quickly, especially because proof-of-concept exploit code is already public. Even without confirmed in-the-wild exploitation, the flaw could give attackers a foothold that leads to full device compromise.
Sources
Sergiu Gatlan 2026.07.02 98%
This updates the same underlying event by adding Cisco’s vendor confirmation that CVE-2026-20230 is now being actively exploited, along with the recommendation to upgrade to fixed releases or disable the vulnerable WebDialer service as a mitigation.
Ionut Arghire 2026.07.02 97%
This article updates the same CVE-2026-20230 event with the key new fact that Cisco has now confirmed active exploitation in the wild after previously saying it was only aware of public proof-of-concept code.
Bill Toulas 2026.06.26 96%
This is a direct update to the same CVE-2026-20230 event, adding that CISA has now added the flaw to KEV after active exploitation was observed and ordered federal agencies to patch by June 28.
2026.06.24 95%
This article updates the same Unified Communications Manager event by adding that CVE-2026-20230 is now being exploited in the wild and describing the observed exploitation chain using WebDialer SSRF to deploy rogue Axis services and JSP shells.
Eduard Kovacs 2026.06.24 96%
This is a direct update to the same CVE-2026-20230 story, adding the key new development that Defused has observed in-the-wild exploitation against decoys after Cisco's June 3 patch, alongside newly published technical details and proof-of-concept code.
Lawrence Abrams 2026.06.23 95%
This is a direct update to the same CVE-2026-20230 event, adding that the flaw is now being actively exploited in the wild, that observed attacks used file:// payloads to write test files, and that technical details and a PoC have now been published.
info@thehackernews.com (The Hacker News) 2026.06.04 99%
The article appears to cover the same underlying event: Cisco’s patch release for CVE-2026-20230 in Unified Communications Manager and the fact that proof-of-concept exploit code is publicly available.
Sergiu Gatlan 2026.06.04 99%
This article is the same underlying event: Cisco's disclosure and patching of CVE-2026-20230 in Unified CM, including that public PoC exploit code exists, the flaw affects systems with WebDialer enabled, and admins can disable WebDialer until updating to fixed releases.
Ionut Arghire 2026.06.04 100%
This article establishes a new tracked story by disclosing Cisco's patch release and warning about public exploit code for CVE-2026-20230 in Unified CM/Unified CM SME; it is distinct from the existing Cisco Secure Workload story, which concerns a different product and CVE.
Full page
White House AI executive order sets 30-day voluntary review window and creates federal AI cybersecurity clearinghouse
Policy & RegulationSurveillance & PrivacyGovernmentTechnology & SoftwareWhite HouseCISAOffice of Management and BudgetTreasuryOffice of the National Cyber DirectorAnthropicCommerce DepartmentPentagonOpenAIGoogle
The White House issued a new artificial intelligence executive order that shortens the voluntary federal review period for certain advanced AI models to 30 days after public release and launches an AI cybersecurity clearinghouse. The order says access to designated "covered frontier" models should include confidentiality, cybersecurity, insider-risk, and intellectual-property safeguards, and directs Treasury, the Office of the National Cyber Director, the Cybersecurity and Infrastructure Security Agency, and the Office of Management and Budget to coordinate AI-based vulnerability detection and patch-prioritization efforts.
Why it matters: This matters because it shapes how the U.S. government and major AI companies will handle powerful models that could help find software flaws or affect critical infrastructure security. Organizations that rely on federal guidance, grants, or critical infrastructure partnerships should watch for implementation details and any new reporting, testing, or collaboration expectations.
Sources
Associated Press 2026.07.02 56%
The article adds a concrete consequence of that executive-order framework: Anthropic and OpenAI limited release of advanced models during federal review, and the Commerce Department temporarily blocked access after a cybersecurity alarm tied to offensive vulnerability-finding capability.
Associated Press 2026.06.24 52%
The piece provides follow-on context for that executive-order story by linking the administration's AI review and restriction measures to Anthropic's Mythos testing results on classified systems and the subsequent directive limiting foreign access to Mythos and Fable models.
Associated Press 2026.06.20 32%
The article provides international reaction to recent U.S. AI restrictions and governance moves, with Macron urging allied coordination on regulation and access to advanced models rather than unilateral U.S. controls.
Corynne McSherry 2026.06.18 49%
The piece references the administration's broader AI policy framework, contrasting its voluntary 30-day review approach for most models with harsher export controls imposed on Anthropic's Mythos and Fable models. However, the main underlying event here is the targeted action against Anthropic rather than the executive order itself.
Associated Press 2026.06.13 77%
This article describes an immediate consequence of that broader Trump administration AI national-security framework: Anthropic says it took Fable 5 and Mythos 5 offline after receiving a government directive restricting access by foreign nationals, despite the earlier executive order describing review as voluntary.
SecurityWeek News 2026.06.05 95%
This article is direct follow-up coverage of the same executive order, adding industry reaction and criticism about the order's voluntary structure, likely adoption gaps, and how its benchmarking and clearinghouse provisions may affect AI developers and smaller critical-infrastructure operators.
2026.06.04 41%
The piece provides follow-on implementation detail for the same executive-order rollout, noting that CISA is named as a key agency under the order and is expected to issue a binding operational directive by Friday.
2026.06.04 88%
This article adds implementation details to the same executive-order event, reporting that CISA plans to release a binding operational directive for federal agencies this week and that the directive will cover vulnerability alleviation, vulnerability management, and rollout of AI access to partners.
Associated Press 2026.06.02 96%
This article appears to cover the same executive order, adding that Trump signed it after delaying a prior ceremony, that the review is framed as voluntary for frontier labs, that the NSA director will have a key role in determining which models are reviewed and which trusted partners get access, and that the White House says the process is meant to help secure critical infrastructure and government cyber defenses.
2026.06.02 100%
This article is the announcement of the executive order itself, establishing a new policy story rather than updating a previously tracked specific event.
Full page
LayerX says BioShocking prompt-injection attack can make AI browsers copy passwords and other sensitive data
Social Engineering & PhishingSurveillance & PrivacyTechnology & SoftwareConsumers & General PublicOpenAIAnthropicPerplexityFellouGensparkSigma Browser
Researchers say a malicious web page can trick several AI-powered browsers into ignoring safety rules and stealing sensitive data from other sites the user can access. LayerX tested a proof of concept against ChatGPT Atlas, Comet, Fellou, Genspark Browser, Sigma Browser, and Anthropic’s Claude Chrome plugin, using a fictional game scenario to push the browser agent into copying secrets from a GitHub repository; OpenAI reportedly fixed the issue in ChatGPT Atlas, while other products remained vulnerable or unresponsive.
Why it matters: People using AI browsers or browser agents could be tricked into letting them exfiltrate passwords or other sensitive information through normal browsing sessions. Vendors need stronger guardrails and user-confirmation checks, and users should limit these tools’ access to sensitive sites and data.
Sources
Ionut Arghire 2026.07.02 98%
This is a direct report on the BioShocking attack, adding product-level details on the six tested agentic browsers, the GitHub SSH-credential exfiltration demonstration, and vendor response status including OpenAI's patch, Anthropic's failed patch, and non-responses from several vendors.
Bill Toulas 2026.06.30 100%
This article establishes a distinct new story about the BioShocking prompt-injection technique and the vendor responses across multiple AI browser products, rather than updating a previously tracked single-product AI-agent flaw.
Full page
Attackers begin exploiting Oracle E-Business Suite Payments flaw CVE-2026-46817
Zero-Days & CVEsUrgent PatchesThreat Actors & APTsFinance & BankingTechnology & SoftwareOracleCISA
Attackers have started probing and exploiting a critical Oracle E-Business Suite bug that can let outsiders take over the Payments component without logging in. The flaw, CVE-2026-46817, affects the File Transmissions component in Oracle E-Business Suite Payments and can be exploited over HTTP by an unauthenticated attacker. Oracle patched it in late May 2026 in its first monthly Critical Security Patch Update, and Defused says it saw the first exploitation attempts hit EBS honeypots over the weekend.
Why it matters: Organizations running Oracle E-Business Suite Payments now face real attack activity, not just a theoretical flaw. This is patch-now territory for internet-exposed systems, especially where payment workflows are involved.
Sources
2026.07.02 97%
This article directly updates the same event by adding that exploitation of CVE-2026-46817 was observed on June 27 before any public proof-of-concept was released, likely via patch reverse-engineering, with targeted attempts against the Oracle Payments File Transmission component in E-Business Suite 12.2.3 through 12.2.15.
Sergiu Gatlan 2026.07.01 96%
This directly updates the same event by adding exposure scope and urgency: Shadowserver tracks about 950 internet-exposed Oracle E-Business Suite instances, BleepingComputer reports over 900 exposed systems amid ongoing exploitation, and the attacks target the same Oracle Payments File Transmission flaw, CVE-2026-46817.
Ionut Arghire 2026.06.30 100%
The article establishes a distinct story because it moves CVE-2026-46817 from a patched vulnerability to one being actively exploited in the wild, with concrete observations from honeypots.
Full page
Trojanized GitHub exploit repositories used malicious PyPI packages to install ChocoPoC remote-access malware
MalwareZero-Days & CVEsSupply ChainThreat Actors & APTsSocial Engineering & PhishingTechnology & SoftwareGitHubPyPIFortinetPalo Alto NetworksIvantiCheck PointMapbox
Attackers hid malware in GitHub proof-of-concept exploit repositories and infected people who cloned and ran them. Sekoia says at least seven repositories for exploits tied to FortiWeb CVE-2025-64446, React2Shell CVE-2025-55182, MongoBleed CVE-2025-14847, PAN-OS CVE-2026-0257, Ivanti Sentry CVE-2026-10520, Check Point VPN CVE-2026-50751, and Joomla SP Page Builder CVE-2026-48908 pulled malicious PyPI packages including frint and skytext, which installed the ChocoPoC RAT, a remote-access trojan that can run commands and steal credentials and files.
Why it matters: This targets the very people trying to test or defend against vulnerabilities, and it can silently hand over passwords, browser sessions, files, and system access. Anyone who cloned untrusted exploit code from GitHub should review systems for the listed packages and treat such testing as high-risk unless done in isolated environments.
Sources
info@thehackernews.com (The Hacker News) 2026.07.02 97%
This article appears to cover the same ChocoPoC campaign: attackers used fake exploit or proof-of-concept GitHub repositories to target security researchers and deliver the ChocoPoC remote-access trojan, adding reporting detail about the victim profile and lure theme.
Bill Toulas 2026.07.01 100%
This article establishes a distinct malware-delivery campaign centered on trojanized exploit repositories and malicious Python dependencies, not a previously tracked single CVE or vendor patch event.
Bill Toulas 2026.07.01 99%
This article covers the same ChocoPoC campaign and adds reporting details on the frint and skytext PyPI packages, the Mapbox-hosted payload delivery and exfiltration path, the list of seven themed PoC repositories, and evidence the attackers likely used compromised accounts tied to earlier 2025 trojanized-PoC activity.
Full page
FBI warns Kali365 phishing service is hijacking Microsoft 365 accounts through OAuth device-code logins
Scams & FraudSocial Engineering & PhishingConsumers & General PublicTechnology & SoftwareHealthcareFBIMicrosoft
The FBI says criminals are using a Telegram-based service called Kali365 to trick people into granting access to their Microsoft 365 accounts. The phishing-as-a-service platform, first seen in April 2026, abuses Microsoft's legitimate device-code login flow so victims authorize attacker-initiated sessions; the stolen OAuth access and refresh tokens can then be reused to access Outlook, Teams and OneDrive without needing the victim's password or another multi-factor authentication prompt.
Why it matters: This matters because victims can lose control of email, files and collaboration accounts even if multi-factor authentication is enabled. Organizations using Microsoft 365 should urgently review device-code login controls and token protections, monitor for suspicious inbox rules and token use, and warn users not to enter login codes from unsolicited emails.
Sources
2026.07.01 42%
This article covers the same broad device-code phishing tradecraft against Microsoft 365 and adds new details on the EvilTokens/ARToken operator panel, targeted invoice lures, SharePoint lookalike links, anti-analysis features, and built-in post-compromise business email compromise capabilities. It is not the Kali365 service specifically, but it is a closely related update in the same Microsoft 365 OAuth device-code phishing wave.
Arctic Wolf Labs 2026.06.02 94%
This is the same underlying Kali365 operation and device-code phishing activity, but with substantive new details: Arctic Wolf links the operator to 126 malicious hosts, shows panel and token-capture infrastructure, and says the campaign has expanded beyond Microsoft 365 lures to Okta, Xerox DocuShare, GMX, Mail.ru, Yandex Disk, Odnoklassniki, and MAX Messenger account-takeover pages.
Arctic Wolf Labs 2026.06.02 97%
This is a direct follow-up on the same Kali365 operation: it adds new technical detail about the operator’s infrastructure, a cluster of 126 malicious hosts, and expansion beyond Microsoft 365-themed lures into Outlook, Okta, Xerox DocuShare, AWS-themed pages, and a MAX Messenger account-takeover campaign while continuing to abuse Microsoft OAuth device authorization to bypass MFA.
Lawrence Abrams 2026.05.25 99%
This article is the same underlying event: the FBI public warning on Kali365. It adds detail on Kali365's Telegram-based distribution, its two attack modes including the adversary-in-the-middle 'Cookie Link' option, links to prior Arctic Wolf reporting, and the FBI's recommended mitigations such as restricting device-code authentication and reviewing unauthorized device registrations.
2026.05.22 100%
This article establishes a distinct tracked story by tying April 2026 Microsoft 365 account-takeover campaigns to the specific Kali365 phishing-as-a-service platform and adding the FBI's public warning plus operational details on how the abuse works.
Full page
Kubota says hackers accessed North American network systems for more than a month and exposed employee data
Breaches & Data LeaksManufacturingKubota
Kubota says hackers had access to some of its North American network systems for more than a month and may have stolen sensitive data on employees and their dependents. The company says unauthorized access lasted from March 16 to April 20, 2026, and exposed varying combinations of names, Social Security numbers, dates of birth, taxpayer IDs, driver's license or other government ID numbers, direct-deposit bank details, corporate payment card data, and benefits enrollment and limited claims information.
Why it matters: Affected workers and families face identity-theft, financial-fraud, and possible healthcare-fraud risks, so this matters even without reported operational disruption. Anyone notified should review bank and benefits activity closely, use offered identity protection, and watch for follow-on phishing or impersonation attempts.
Sources
Bill Toulas 2026.07.01 100%
This article appears to be the initial public breach disclosure for Kubota's month-long unauthorized network access and resulting employee-data exposure.
Full page
Check Point says DeepSeek-generated browser ransomware sample can be turned into a working Chrome-based file-encryption attack
MalwareRansomwareSocial Engineering & PhishingConsumers & General PublicDeepSeekGoogle
Check Point says code generated by DeepSeek can be adapted into a working browser-based ransomware attack that encrypts a victim’s local files after they approve a browser permission prompt. The sample, dubbed "InfernoGrabber 9000," is a Python Flask web app targeting Android users and abuses Chrome and Chromium-based browsers’ File System Access API to read and write local files without a traditional malware install, relying on phishing-style social engineering rather than a browser exploit or CVE.
Why it matters: This lowers the barrier for criminals to build ransomware-like attacks that run in the browser, where users may trust the prompt because it comes from a legitimate browser feature. Defenders should review controls around Chromium-based browsers and file-access permissions, and users should be wary of websites asking for broad local file access.
Sources
2026.07.01 100%
This article establishes a distinct story about AI-generated browser-native ransomware techniques tied to DeepSeek output and Chrome's File System Access API, rather than updating an existing tracked breach, CVE, or malware campaign.
Full page
DHS confirms hackers breached Homeland Security Information Network and related SharePoint systems
Breaches & Data LeaksGovernmentDHS
The U.S. Department of Homeland Security says hackers breached the Homeland Security Information Network, a platform used to share sensitive but unclassified information with federal, state, local, international, and private-sector partners. DHS says the incident affected a specific legacy HSIN environment and that attackers also targeted a SharePoint collaboration system; the intrusion is believed to have occurred between late May and early June 2026. DHS says it isolated affected systems, mitigated the vulnerability, and launched a forensic investigation, but it has not yet named the threat actor or confirmed whether data was stolen.
Why it matters: This matters because HSIN is used for real-world security coordination, alerts, and incident response, so a breach could expose plans, contacts, or sensitive operational data even if classified networks were not touched. Government and partner organizations should watch for DHS guidance, review HSIN and SharePoint access, and assess whether shared information or accounts may have been exposed.
Sources
Lawrence Abrams 2026.07.01 100%
This article establishes a new story by confirming a newly disclosed cyberattack on DHS's HSIN platform and associated collaboration systems, with no matching existing tracked story covering this specific breach.
Full page
Researchers show Anthropic Claude Desktop can be abused through synced instructions to run commands on a developer’s computer
Social Engineering & PhishingZero-Days & CVEsTechnology & SoftwareAnthropic
Pentera Labs says it turned Anthropic's Claude Desktop into a malicious intermediary that helped achieve remote code execution on a developer workstation. The attack required control of the victim's email inbox and the victim's use of Claude Desktop, then abused account-wide synced personalization and project instructions to make the AI look for command-capable tools and execute attacker-influenced actions across sessions and devices; no CVE is cited in the article.
Why it matters: People may trust AI assistants more than ordinary prompts or attachments, so this kind of abuse could quietly turn a synced desktop agent into an attack path to a user’s computer. Organizations using Claude Desktop or similar agentic tools should review local command-execution permissions, account sync behavior, inbox security, and user approval controls for AI-run actions.
Sources
2026.07.01 100%
This article appears to establish a distinct story about a newly reported Claude Desktop attack chain abusing synced instructions and trusted AI-agent behavior to reach code execution on endpoint systems.
Full page
Mass password-spray campaign uses Azure CLI and OAuth ROPC to break into Microsoft 365 accounts
Social Engineering & PhishingThreat Actors & APTsConsumers & General PublicTechnology & SoftwareGovernmentHealthcareFinance & BankingEducationLegal & Professional ServicesMicrosoftLSHIYHuntress
Attackers made more than 81 million login attempts and successfully compromised Microsoft 365 accounts at dozens of organizations by abusing Azure CLI sign-ins. Huntress says 78 accounts at 64 organizations were breached between June 12 and 21, 2026, using password spraying and the OAuth Resource Owner Password Credentials (ROPC) flow, which can mint tokens without an interactive multi-factor authentication prompt if MFA policies are not enforced for that flow or all cloud apps. Most activity came from infrastructure tied to LSHIY.
Why it matters: Organizations using Microsoft 365 could be exposed even if they believe MFA is enabled, because gaps in conditional access or legacy auth coverage can still let attackers in. Defenders should review Azure and Entra sign-in logs, disable or restrict ROPC where possible, enforce MFA for all cloud applications and users, and reset compromised accounts.
Sources
Bill Toulas 2026.07.01 99%
This is the same Huntress-reported campaign, adding concrete scale and timing details: 81 million login attempts from June 12 to 26, 78 compromised accounts across 64 organizations, and the specific Conditional Access misconfigurations that let Azure CLI plus OAuth ROPC bypass MFA protections.
Ionut Arghire 2026.07.01 100%
This article establishes a distinct ongoing credential-attack story centered on Azure CLI and OAuth ROPC abuse against Microsoft 365 tenants, not a previously tracked breach, CVE, or patch event.
Full page
Blackfield ransomware demands $2 million from Nidec after attack on Taiwanese subsidiary
RansomwareBreaches & Data LeaksManufacturingTechnology & SoftwareNidec
Nidec says a ransomware attack hit part of the server environment at its Taiwanese subsidiary, Nidec Chaun Choung Technology, and the attackers are now demanding $2 million. The company said the June 22, 2026 incident led it to shut down the affected server and network to contain the damage and that it is investigating possible data leakage and any effect on production and shipping. Blackfield claims it stole data and threatened to publish or sell it if Nidec does not negotiate.
Why it matters: This is a disruption and extortion risk for a large global manufacturer whose products feed automotive, computing, robotics, and other supply chains. Organizations connected to Nidec should watch for follow-on fraud or leaked documents, while manufacturers should review ransomware containment, segmentation, and backup recovery plans.
Sources
2026.07.01 93%
This covers the same Nidec incident and adds context that the affected entity was Nidec Chaun Choung Technology in Taiwan, the subsidiary was on an independent network, and the gang claimed theft of more than two terabytes of employee, financial, procurement, manufacturing, legal, and IT data.
Bill Toulas 2026.06.30 100%
This article establishes a distinct 2026 ransomware event affecting Nidec's Taiwanese subsidiary and adds concrete extortion details not represented in the tracked-story list.
Full page
Aflac says hackers breached its Japan subsidiary and stole customer personal and bank account data
Breaches & Data LeaksInsuranceAflacAflac Japan
Aflac disclosed that attackers broke into systems at Aflac Japan and stole sensitive customer information. The company said the unauthorized access occurred between June 15 and June 25, 2026, and affected files include policy and coverage details, personal information, and bank account information. Aflac said the incident is limited to its Japan subsidiary, that some systems were suspended for containment, and that the full scope is still under investigation.
Why it matters: This affects insurance customers whose personal and financial data may now be exposed to fraud or account abuse. Affected users should watch for breach notifications, monitor financial accounts, and be alert for phishing or impersonation attempts, while defenders in insurance should review whether this reflects broader targeting of the sector.
Sources
2026.07.01 95%
This is the same Aflac Japan breach and adds scale and operational detail, including that about 4.38 million policyholders were affected, around 230,000 customers had premium payment account data exposed, and Aflac suspended parts of affected systems while continuing claims and support through other channels.
Ionut Arghire 2026.06.30 98%
This source updates the same Aflac Japan breach with a specific impact figure of 4.38 million affected customers and agents, a timeline showing repeated access from June 15 to June 25, confirmation that the policyholder portal was the source of exfiltration, and added detail that about 230,000 people had insurance premium transfer account information stolen.
Sergiu Gatlan 2026.06.30 100%
This article appears to be the first clear report of Aflac's June 2026 disclosure that Aflac Japan was breached and customer personal and bank account data was accessed.
Full page
Sapporo says suspected cyberattack hit Pokka and Sleeman Breweries subsidiaries
Breaches & Data LeaksManufacturingConsumers & General PublicSapporoPokkaSleeman Breweries
Sapporo says a suspected cyberattack affected two overseas subsidiaries, Pokka in Singapore and Sleeman Breweries in Canada. The company reported suspicious network activity consistent with unauthorized access, shut down affected systems, and is still investigating whether any data was stolen. Sapporo said it has found no impact on its domestic Japan operations.
Why it matters: This is a real intrusion at a major consumer brand with possible downstream effects on staff, partners, or customers of the affected subsidiaries. Organizations connected to Pokka or Sleeman should watch for follow-up notices, and customers should be alert for any breach notifications or password-reset advice.
Sources
2026.07.01 100%
This article appears to be the establishing report for Sapporo's disclosure of suspected unauthorized access affecting Pokka and Sleeman, with no matching tracked story in the list.
Full page
HTTP/2 Bomb denial-of-service attack chain hits default NGINX, Apache, IIS, Envoy and Pingora web server setups
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareNGINXApacheMicrosoftEnvoyCloudflareCitrix
Researchers say a new HTTP/2 attack chain can knock major web servers offline within seconds, potentially affecting more than 880,000 websites using default configurations. The technique combines an HPACK header-compression bomb with Slowloris-style connection holding to exhaust memory; it builds on CVE-2016-6581, CVE-2016-8740, CVE-2016-1546, Apache's 2025 fix CVE-2025-53020, and newly assigned Apache CVE-2026-49975. NGINX reportedly fixed the issue in April, Apache in late May, while Microsoft IIS, Envoy, and Cloudflare Pingora had not yet been patched at publication.
Why it matters: Organizations running internet-facing HTTP/2 servers could be taken offline by a relatively low-resource attacker, so this is operationally urgent even though it is a denial-of-service issue rather than data theft. Admins should review vendor advisories, apply available fixes for NGINX and Apache, and add mitigations or rate-limiting for IIS, Envoy, and Pingora until patches arrive.
Sources
Ionut Arghire 2026.07.01 73%
This article updates the same underlying HTTP/2 Bomb event by adding Citrix’s product-specific impact and mitigation details: NetScaler ADC and Gateway are affected, Citrix assigned CVE-2026-13474 for its implementation, and fixes are available in specific NetScaler versions.
2026.06.09 63%
It ties Microsoft's June patch release to the previously disclosed HTTP/2 Bomb research by stating that Microsoft fixed CVE-2026-49160 in HTTP.sys and introduced a MaxHeadersCount registry mitigation for HTTP/2 and HTTP/3 requests.
Lawrence Abrams 2026.06.09 93%
This directly updates the HTTP/2 Bomb story by confirming Microsoft patched the related Windows HTTP.sys denial-of-service issue as CVE-2026-49160 and added a MaxHeadersCount mitigation setting and KB5102602 guidance.
2026.06.04 98%
This article is another report on the same HTTP/2 Bomb attack chain, adding details that OpenAI Codex helped Calif researchers chain older HPACK bomb and Slowloris-style techniques, and updating patch status for nginx, Apache, Envoy, Microsoft IIS, and Cloudflare Pingora.
Bill Toulas 2026.06.03 98%
This article is a direct report on the same HTTP/2 Bomb event, adding concrete exploitation results, affected versions, patch status, and the Apache CVE assignment (CVE-2026-49975), plus noting that nginx 1.29.8 fixes the issue while IIS, Envoy, and Pingora remain unpatched.
Ionut Arghire 2026.06.03 100%
This article appears to be the first report establishing the newly named HTTP/2 Bomb exploit chain, including affected products, CVE references, patch status, and public proof-of-concept details.
Full page
Microsoft says it will move critical products and services to post-quantum cryptography by 2029
Surveillance & PrivacyPolicy & RegulationGovernmentTechnology & SoftwareConsumers & General PublicMicrosoft
Microsoft said it is speeding up its quantum-safe security plans because it believes the risk from future quantum decryption may arrive sooner than expected. The company said critical products and services will transition to post-quantum cryptography by 2029 under its Quantum Safe Program, with parallel work on TLS 1.3 adoption, crypto-agility so algorithms can be swapped more easily, and modernization of trust chains used for code signing, certificates, software updates, and hardware-backed keys.
Why it matters: Organizations that rely on Microsoft products should start inventorying where they use long-lived encryption and where software or infrastructure will need post-quantum upgrades. This is not an emergency patch, but it is a meaningful timeline signal for governments, enterprises, and regulated sectors planning multi-year crypto migrations.
Sources
info@thehackernews.com (The Hacker News) 2026.07.01 99%
The article covers the same underlying event: Microsoft's announcement that it is accelerating its migration of critical products and services to post-quantum cryptography by 2029.
Lawrence Abrams 2026.06.30 100%
This article establishes a new trackable event: Microsoft publicly accelerated its quantum-safe migration timeline and tied it to its broader Secure Future Initiative.
Full page
FTC fines Amazon $2.25 million for denying identity-theft victims records of fraudulent transactions
Surveillance & PrivacyPolicy & RegulationScams & FraudRetail & E-CommerceConsumers & General PublicAmazonFTC
The U.S. government says Amazon must pay $2.25 million after failing to give identity-theft victims records tied to fraudulent purchases made in their names. The Federal Trade Commission said Amazon violated Section 609(e) of the Fair Credit Reporting Act by refusing or delaying requests from consumers and authorized law-enforcement agencies, sometimes citing "privacy" or "security" reasons, and must now provide records within the law’s 30-day deadline.
Why it matters: People trying to prove fraud and clear their names can be blocked if companies withhold transaction records. This also signals that large platforms face enforcement risk if they fail to meet legal obligations around identity-theft response and consumer access to evidence.
Sources
Sergiu Gatlan 2026.07.01 100%
This article establishes a distinct enforcement story centered on Amazon’s alleged FCRA noncompliance in handling identity-theft victims’ fraud-record requests.
Full page
Apple ships iOS, iPadOS, macOS Tahoe, and Safari updates fixing dozens of security flaws
Urgent PatchesConsumers & General PublicTechnology & SoftwareApple
Apple released security updates for iPhone, iPad, Mac, and Safari users to fix dozens of vulnerabilities that could be triggered by malicious websites or lead to crashes, memory corruption, data leaks, and clipboard hijacking. The updates include iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2, with 26 WebKit flaws and additional bugs in the kernel, IOGPUFamily, libxslt, Web Extensions, and WebRTC; Apple said it has no evidence of active exploitation.
Why it matters: These are broad platform patches for devices many people use every day, and many of the bugs can be triggered just by visiting a malicious website. Users and organizations should update Apple devices and Safari promptly, especially where internet-facing browsing is common.
Sources
Ionut Arghire 2026.07.01 100%
This article establishes a distinct Apple patch-cycle story covering newly released fixes across iOS, iPadOS, macOS Tahoe, and Safari, and it does not match an existing tracked story in the list.
Full page
Google releases Chrome 151 security update fixing 382 vulnerabilities, including 15 critical flaws
Urgent PatchesConsumers & General PublicTechnology & SoftwareGoogle
Google released Chrome 151 with security fixes for 382 browser vulnerabilities affecting Chrome users across supported platforms. Google says 15 of the bugs are rated critical and 67 high severity; many involve memory-safety issues such as use-after-free, type confusion, out-of-bounds access, and input-validation flaws in the renderer that can be triggered by crafted web content and may allow code execution in the browser sandbox or help attackers escape it. No in-the-wild exploitation was disclosed for this batch.
Why it matters: Chrome is one of the most widely used pieces of software, so a large patch batch with multiple critical bugs is broadly important even without confirmed active exploitation. Users and organizations should update browsers promptly through normal patch channels to reduce exposure to malicious websites and drive-by attacks.
Sources
Eduard Kovacs 2026.07.01 100%
This article establishes a distinct new patch event for Chrome 151; the existing tracked Chrome stories are for different releases and different vulnerability counts or zero-day disclosures.
Full page
Arctic Wolf says Anubis ransomware affiliates used CitrixBleed 2 and remote admin tools to break into victim networks
RansomwareThreat Actors & APTsZero-Days & CVEsCitrix
Arctic Wolf says multiple 2026 Anubis ransomware attacks began with either stolen VPN credentials or exploitation of CitrixBleed 2, putting organizations with exposed Citrix access at risk. The report ties Anubis intrusions to CVE-2025-5777 in Citrix NetScaler, then details follow-on use of legitimate remote management tools including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment, plus cloudflared, authenticated proxies, and SSH SOCKS tunnels for persistence and lateral movement.
Why it matters: This matters because attackers are mixing a known edge-device flaw with normal-looking IT tools, making ransomware intrusions harder to spot until systems are already at risk. Organizations using Citrix remote access should patch and review VPN exposure, hunt for these remote admin tools, and closely monitor domain controllers, remote desktop servers, hypervisors, backup systems, and network storage.
Sources
Arctic Wolf Labs 2026.07.01 100%
This article establishes a distinct story by linking Anubis ransomware intrusions to exploitation of CitrixBleed 2 (CVE-2025-5777) and documenting a specific toolset and access pattern not reflected in the existing tracked stories.
Full page
SimpleHelp fixes critical CVE-2026-48558 that lets attackers create rogue remote support accounts
Urgent PatchesThreat Actors & APTsMalwareZero-Days & CVEsTechnology & SoftwareLegal & Professional ServicesHealthcareFinance & BankingConsumers & General PublicSimpleHelpCISA
A critical flaw in SimpleHelp remote management software can let an outsider create a privileged support account on vulnerable servers. The bug, CVE-2026-48558, affects SimpleHelp 5.5.15 and earlier plus 6.0 pre-release builds when OpenID Connect (OIDC) login is enabled and certain technician-group settings are in use. An unauthenticated attacker can bypass normal identity checks and multi-factor authentication to gain technician access; fixes are in 5.5.16 and 6.0RC2.
Why it matters: Organizations using SimpleHelp for remote administration could hand attackers the same kind of access trusted support staff have, including remote control of managed devices and script execution. This is urgent for anyone exposing SimpleHelp to the internet: update now, and if you cannot patch immediately, restrict technician logins with IP allowlists and review logs for suspicious new technician accounts.
Sources
Arctic Wolf Labs 2026.06.30 95%
This source updates the same CVE-2026-48558 event with exploitation details: attackers are abusing the OIDC token-signature validation flaw to bypass MFA, gain technician-level access, steal credentials, and deploy custom malware. It also adds exposure estimates of about 14,000 internet-facing servers and roughly 1,000 directly vulnerable systems, plus CISA KEV urgency and mitigation guidance.
info@thehackernews.com (The Hacker News) 2026.06.30 95%
This article advances the same underlying event by showing that CVE-2026-48558 is not just a disclosed flaw but is being actively exploited to create unauthorized access and deploy TaskWeaver and Djinn Stealer on victim systems.
Ionut Arghire 2026.06.30 96%
This updates the same underlying CVE-2026-48558 SimpleHelp event by adding post-disclosure exploitation details: attackers used the auth-bypass flaw to obtain technician sessions and deploy TaskWeaver and Djinn Stealer, and CISA has now added the flaw to the KEV catalog.
Bill Toulas 2026.06.15 100%
This article establishes a new tracked story because it reports the disclosure and fix of CVE-2026-48558, a distinct SimpleHelp authentication flaw with no corresponding existing story in the tracker.
Full page
Malicious PyPI packages posing as Pyrogram forks backdoor Telegram bot servers
Supply ChainMalwareTechnology & SoftwareConsumers & General PublicPyPITelegramPyrogram
Attackers published at least eight malicious Python packages on PyPI that target developers building Telegram bots and can give the attackers control of infected servers. The packages are trojanized forks of the Pyrogram Telegram framework and include a hidden backdoor file, secret.py, that registers covert Telegram commands to execute attacker-supplied Python or shell code, read arbitrary files, dump credentials and chats, and exfiltrate output via Telegram. Checkmarx says the campaign, active since November 2025, used multiple package names including pyrogram-styled, pyrogram-navy, VLifeGram, and kelragram.
Why it matters: Developers and organizations running Telegram bots could have had production servers quietly turned into remote-access points for attackers. Anyone who installed the named packages should remove them immediately, rotate credentials and API keys, review bot hosts for persistence, and inspect PyPI dependencies and software bill of materials records.
Sources
Bill Toulas 2026.06.30 100%
This article establishes a distinct software supply-chain campaign centered on malicious PyPI packages that backdoor Telegram bot deployments, not a previously tracked package-hijack event.
Full page
Former Huntress analyst alleges insider shared law-enforcement information with DevMan ransomware actor
Threat Actors & APTsPolicy & RegulationRansomwareSupply ChainTechnology & SoftwareHuntressFBI
A former Huntress employee publicly alleged that a current company insider passed information from U.S. law enforcement to a ransomware actor known as DevMan, potentially putting customers at risk. The claims center on an alleged December 2025 insider incident rather than Huntress's separate Klue-related exposure; Huntress said the matter involved an employee who showed poor judgment in communicating with a cybercriminal, and said it took the concerns seriously. The article does not provide technical indicators, affected customer count, or independent confirmation from law enforcement.
Why it matters: If true, this would be a serious insider-threat case at a security vendor, with possible exposure of investigative information and downstream risk to customers. Defenders should watch for confirmation, assess any Huntress notifications, and treat this as a potential trust and supply-chain concern rather than a proven breach at this stage.
Sources
2026.06.30 95%
This article updates the same underlying event by adding Huntress CEO Kyle Hanslovan's public response, confirming that a current employee disclosed law-enforcement outreach to the DevMan ransomware actor, while disputing that it amounted to insider activity and saying internal policy changes and administrative actions followed.
2026.06.25 100%
This article appears to be the first cited report surfacing the specific allegation of a Huntress insider sharing information with the DevMan ransomware operation, making it the anchor for a new tracked story.
Full page
Fake Perplexity Chrome Web Store extension intercepted searches and sent them through attacker servers
MalwareSurveillance & PrivacyConsumers & General PublicPerplexityGoogleMicrosoft
A malicious Chrome Web Store extension posing as Perplexity routed users’ searches through attacker-controlled systems and collected browsing data before forwarding people to legitimate search services. Microsoft said the fake add-on, listed as “Search for perplexity ai,” changed Chromium browser search settings via chrome_settings_overrides and used powerful Declarative Net Request permissions to redirect, rewrite, and monitor traffic. The extension used the domain perplexity-ai[.]online instead of the legitimate perplexity.ai; the reported extension ID was flkebkiofojicogddingbdmcmkpbplcd.
Why it matters: Anyone who installed it may have exposed their searches and browsing activity, and the granted permissions could also have supported credential theft if the operator expanded the campaign. Users should remove the extension immediately and, as a precaution, rotate important passwords and review other installed browser add-ons.
Sources
Bill Toulas 2026.06.30 100%
This article establishes a distinct browser-extension abuse incident involving a fake Perplexity-branded extension distributed through the Chrome Web Store.
Full page
Critical libssh2 flaw CVE-2026-55200 could let a malicious SSH server run code on vulnerable clients
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareConsumers & General Publiclibssh2curlGitPHP
A critical bug in the widely used libssh2 SSH client library could let a hostile SSH server compromise computers and devices that connect to it. Arctic Wolf says CVE-2026-55200 is a pre-authentication memory-corruption flaw in ssh2_transport_read() affecting libssh2 1.11.1 and earlier, triggered by a crafted packet_length value; public proof-of-concept code is available, an upstream patch has been merged but no formal tagged release was available at publication, and many downstream tools may be hard to patch because they statically embed the library.
Why it matters: This is urgent because affected software can be exposed just by connecting to a malicious or compromised SSH server, with no credentials or user interaction required. Organizations should inventory anything that uses libssh2, apply source or downstream patches, and restrict outbound SSH connections to trusted hosts until fixes are in place.
Sources
Arctic Wolf Labs 2026.06.30 100%
This article appears to be the initial trackable report here of CVE-2026-55200 in libssh2, including the core technical details, affected versions, patch status, and practical mitigation guidance.
Full page
CISA adds seven actively exploited flaws, including Microsoft Defender CVE-2026-41091 and CVE-2026-45498, to KEV catalog
Urgent PatchesRansomwareZero-Days & CVEsGovernmentTechnology & SoftwareConsumers & General PublicCISAMicrosoftAdobe
CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog on May 20, 2026, citing evidence of active exploitation. The additions include legacy Microsoft Windows, DirectX, Internet Explorer, and Adobe Reader bugs, plus Microsoft Defender flaws CVE-2026-41091 (elevation of privilege) and CVE-2026-45498 (denial of service). Federal agencies must remediate by the deadlines set under BOD 22-01.
Why it matters: KEV additions indicate real-world exploitation and help defenders prioritize patching and mitigations. Organizations, especially federal agencies, should urgently assess exposure to the newly listed Microsoft Defender and legacy Windows-related vulnerabilities.
Sources
Eduard Kovacs 2026.06.30 31%
This article references a separate KEV-related CISA action, but it is not the same underlying event: it concerns Microsoft Defender flaw CVE-2026-33825 (BlueHammer), adds that Huntress saw zero-day exploitation before patching, and says CISA updated the KEV entry to note use in ransomware attacks.
Eduard Kovacs 2026.06.03 36%
The story intersects because RedSun (CVE-2026-41091) and UnDefend (CVE-2026-45498) are among the disclosed Microsoft flaws discussed in this article, and the piece reiterates that some are exploited in the wild. However, this source is primarily about Microsoft's handling of the disclosure controversy, not CISA's KEV action itself.
Ionut Arghire 2026.05.21 96%
This article covers the same underlying event around Microsoft Defender flaws CVE-2026-41091 and CVE-2026-45498 being actively exploited and added to KEV, and adds specific patch details: Microsoft fixed them in Defender Antimalware Platform version 4.18.26040.7, described the impacts as local SYSTEM privilege escalation and DoS, noted disabled Defender systems are not exploitable, and linked the bugs to the publicly released BlueHammer variants RedSun and UnDefend.
Sergiu Gatlan 2026.05.21 96%
This source is about the same underlying event: active exploitation of Microsoft Defender flaws CVE-2026-41091 and CVE-2026-45498. It adds Microsoft's patch rollout details, affected component versions, the impact of each flaw (SYSTEM privilege escalation and DoS), and fixed versions defenders should verify.
CISA 2026.05.20 100%
This article is the primary CISA alert establishing a new KEV-driven remediation event covering seven specifically identified exploited CVEs.
Full page
CISA says Microsoft Defender zero-day BlueHammer CVE-2026-33825 was used in ransomware attacks
Zero-Days & CVEsRansomwareUrgent PatchesTechnology & SoftwareConsumers & General PublicMicrosoftCISA
A Microsoft Defender security flaw was exploited before a patch was available, and U.S. officials now say ransomware attackers used it in real intrusions. The bug, tracked as BlueHammer and CVE-2026-33825, is a local privilege-escalation flaw in Microsoft Defender; it was publicly disclosed on April 2, patched on April 14, added to CISA’s Known Exploited Vulnerabilities catalog on April 22, and CISA has now updated that entry to specify ransomware use. Huntress said it observed zero-day exploitation before Microsoft released fixes.
Why it matters: Organizations using Windows systems with Microsoft Defender should treat this as a high-priority post-zero-day issue and verify patching immediately. The new ransomware tie raises the urgency because attackers used the flaw to gain higher privileges that can help them take over systems and deploy follow-on malware.
Sources
Eduard Kovacs 2026.06.30 100%
No existing tracked story covers BlueHammer CVE-2026-33825 specifically; this article establishes a distinct event by tying that Microsoft Defender zero-day to observed zero-day exploitation and later ransomware use.
Full page
Adversa says Bash guard bypasses in open-source AI coding agents can turn malicious repositories into code-execution attacks
Supply ChainSocial Engineering & PhishingTechnology & SoftwareHermesOpenCodeRoo-codeContinue
Researchers say most tested open-source AI coding agents can be tricked by malicious repositories into generating and running dangerous shell commands. Adversa calls the issue "GuardFall," a structural guard-bypass pattern rather than a single CVE, and says 10 of 11 tested agents were vulnerable, including Hermes, OpenCode, and Roo-code. The attacks use long-known Bash parsing tricks such as quote removal and $IFS spacing to evade denylist-style protections, with highest risk in auto-execute or CI/CD pipeline use.
Why it matters: Developers and organizations using AI coding agents could have credentials stolen or systems damaged just by letting an agent inspect poisoned project files. Maintainers should harden command-execution guards, and users should disable auto-approve modes, sandbox agents tightly, and treat untrusted repositories and external data sources as potentially hostile.
Sources
Kevin Townsend 2026.06.30 100%
This article establishes a distinct new story about Adversa's newly reported "GuardFall" technique affecting multiple open-source AI coding agents, not a previously tracked single-product agent flaw or repository-specific attack.
Full page
ShinyHunters targets Oracle PeopleSoft servers in data-theft attacks against more than 100 organizations
Breaches & Data LeaksUrgent PatchesThreat Actors & APTsZero-Days & CVEsEducationGovernmentConsumers & General PublicTechnology & SoftwareManufacturingOracleUniversity of NottinghamPeopleSoftShinyHuntersGoogleCouncil of EuropeNissan
Oracle PeopleSoft customers are being hit in ongoing break-ins and extortion attacks that ShinyHunters says have affected more than 100 organizations and 300 PeopleSoft instances. The campaign reportedly targets both cloud and on-premises PeopleSoft deployments, with the attackers claiming to use a chain of older bugs and at least one zero-day, though no CVE has been confirmed by Oracle. Reported evidence includes extortion notes, exposed attacker tooling, and IP-based indicators of compromise tied to infrastructure previously linked to ShinyHunters.
Why it matters: PeopleSoft is widely used for payroll, HR, finance, procurement, and student systems, so a compromise can expose highly sensitive employee, customer, or student data. Organizations running PeopleSoft should urgently review logs for the listed IPs, investigate possible unauthorized SSH access, and prepare incident response while waiting for Oracle guidance.
Sources
Eduard Kovacs 2026.06.30 95%
This article confirms Nissan as another victim in the same PeopleSoft zero-day campaign and adds specific breach details: Nissan Americas says attackers exploiting CVE-2026-35273 may have stolen employee SSNs, banking, tax, and payroll-related data affecting current and former employees in the U.S., Canada, Mexico, and Brazil.
2026.06.15 98%
This article adds a newly identified victim in the same PeopleSoft zero-day campaign: the Council of Europe. It reports the group claims to have stolen 297 GB and 429,000 files including HR, payroll, banking, tax, and medical records, and reiterates the campaign details around CVE-2026-35273 and 100+ affected organizations.
Eduard Kovacs 2026.06.12 97%
This source directly advances the same event by tying the campaign to the specific zero-day CVE-2026-35273, confirming Google/Mandiant observed exploitation between May 27 and June 9, noting Oracle issued mitigations without apparent patches, and adding that higher education made up 68% of notified exposed organizations.
info@thehackernews.com (The Hacker News) 2026.06.11 96%
This appears to be the same underlying campaign and adds the specific zero-day identifier CVE-2026-35273, ties the activity to breaches at universities, and further clarifies that Oracle PeopleSoft servers are the intrusion path used by ShinyHunters.
Lawrence Abrams 2026.06.11 97%
This updates the same underlying incident by identifying the specific flaw exploited as CVE-2026-35273, confirming it is an unauthenticated remote-code-execution zero-day in Oracle PeopleSoft PeopleTools 8.61 and 8.62, and noting Oracle has issued emergency mitigations while a patch is pending.
2026.06.11 98%
This article directly updates the same underlying event by identifying the claimed exploit as PeopleSoft zero-day CVE-2026-35273, stating it affects roughly 300 vulnerable instances and more than 100 organizations, and tying the campaign concretely to the University of Nottingham breach and Oracle's out-of-band alert/mitigations.
Eduard Kovacs 2026.06.11 95%
This source adds Oracle's own out-of-band advisory and mitigation guidance for CVE-2026-35273, a critical unauthenticated RCE in PeopleSoft PeopleTools 8.61 and 8.62, which may be one of the zero-days reportedly used in the same ShinyHunters campaign against 100+ organizations.
Sergiu Gatlan 2026.06.11 94%
This article adds a named victim in the PeopleSoft-focused ShinyHunters campaign, with victim confirmation of a breach, reported impact of 454,600 people, and details on the types of data exposed from the University of Nottingham's student records system.
Lawrence Abrams 2026.06.10 100%
This article appears to be the first clear report establishing a distinct ShinyHunters campaign specifically targeting Oracle PeopleSoft environments across many organizations, with claimed victim count, tactics, and IOCs.
Full page
CISA warns Daktronics display controller flaws can let attackers remotely hijack highway signs and digital billboards
Zero-Days & CVEsUrgent PatchesTransportation & LogisticsMedia & EntertainmentCISADaktronics
CISA warned that vulnerabilities in Daktronics display controllers could let attackers remotely tamper with highway signs, digital billboards, and other large electronic displays. The advisory covers Daktronics VFC-DMP-5000, DMP-5000, and DMP-8000 controllers and includes an unauthenticated path traversal flaw, an authenticated arbitrary file upload flaw, and default administrator credentials; together they can enable root-level control. Daktronics released patched firmware, and researchers found multiple internet-exposed controllers still reachable online.
Why it matters: Organizations using these controllers could have public-facing signs altered to show false or malicious messages, and exposed devices may be fully compromised. This is an urgent patch-and-hardening story for operators of transportation, advertising, venue, and airport display systems: update firmware, remove internet exposure, and change default passwords immediately.
Sources
Eduard Kovacs 2026.06.30 100%
This article appears to be the first concrete report tying CISA's advisory and Daktronics' patches to remotely exploitable controller flaws affecting highway signs, billboards, and other large public display systems.
Full page
India's .bank.in registrar IDRBT exposed bank-domain administrator data through unauthenticated API endpoints
Breaches & Data LeaksSocial Engineering & PhishingFinance & BankingReserve Bank of IndiaIDRBT
The sole registrar for India's mandatory .bank.in banking domains allegedly exposed sensitive data on thousands of bank staff through open web API endpoints. Researcher Srikanth L said IDRBT's registration portal exposed 33+ unauthenticated REST endpoints that returned bcrypt password hashes, mobile numbers, email addresses, login IP addresses, and device fingerprints for 5,576 employees managing bank domains; the issue was reportedly disclosed in early June 2026 and later fixed.
Why it matters: This could have given attackers the exact information needed to impersonate bank officials, target domain administrators, and abuse banking-domain trust for phishing or account takeover. Indian banks and regulators should review registrar access logs, rotate credentials, harden domain security controls such as DNSSEC and DMARC, and warn staff about targeted social engineering.
Sources
2026.06.30 100%
This article appears to be the first tracked report of the IDRBT .bank.in registrar exposure and establishes the core event: unauthenticated API access leaking sensitive bank-domain administration data.
Full page
Researchers show 'SymJack' attack can trick Claude Code, Copilot CLI, Gemini CLI and other AI coding agents into installing malicious tools
Social Engineering & PhishingTechnology & SoftwareSupply ChainTechnology & SoftwareAnthropicGoogleGitHubCursorxAIMicrosoft
Researchers say attackers can abuse trusted-looking project files in code repositories to make AI coding agents install attacker-controlled components and run malicious code on a developer's machine or in continuous integration (CI) systems. Adversa's 'SymJack' technique uses disguised symbolic links (symlinks) and a copy command to silently register a malicious Model Context Protocol (MCP) server; the firm says it worked against Claude Code, Gemini CLI, Antigravity CLI, Cursor Agent CLI, Grok Build CLI, and GitHub Copilot CLI, and published a proof of concept on GitHub. Anthropic reportedly hardened Claude Code to resolve symlinks before approval and show the true destination path.
Why it matters: Teams using AI coding agents could unknowingly approve changes that steal SSH keys, cloud tokens, browser sessions, or CI secrets and then push malicious code downstream. This is urgent for developers and DevOps teams using agentic coding tools: review repository trust assumptions, restrict or audit MCP server registration, scrutinize file-copy prompts, and apply vendor mitigations where available.
Sources
Bill Toulas 2026.06.27 78%
This article adds a specific Claude Code attack chain in which a benign-looking repository and setup error cause the agent to run an initialization command that fetches and executes attacker-controlled instructions from a DNS TXT record, extending the broader story of AI coding agents being manipulated through trusted project workflows.
info@thehackernews.com (The Hacker News) 2026.06.12 95%
This appears to cover the same underlying event: a newly disclosed attack against AI coding agents that manipulates trusted project context to make agents execute attacker-controlled actions or install malicious components. The article uses the name 'Agentjacking,' but the core event matches the tracked story about AI coding agents such as Claude Code, Copilot CLI, and Gemini CLI being tricked into unsafe tool execution.
Kevin Townsend 2026.05.27 100%
This article appears to be the initial reporting of the SymJack technique as a named, cross-vendor attack pattern with a public proof of concept and documented vendor responses.
Full page
Uni-App scam framework is powering more than 200,000 fake investment, crypto, gambling, and phishing websites
Scams & FraudSocial Engineering & PhishingConsumers & General PublicCryptocurrency & BlockchainDCloudWhatsApp
Researchers say criminals have used templates built with DCloud's Uni-App framework to launch more than 200,000 scam websites targeting internet users. Infoblox identified over 236,000 second-level domains tied to the ecosystem, including fake crypto exchanges, pig-butchering investment sites, gambling and prediction-market impersonators, WhatsApp phishing pages, and credential-harvesting sites; the activity has grown since mid-2022 and accelerated after late 2024.
Why it matters: This is a mass-scale fraud and phishing infrastructure that can steal money, passwords, and cryptocurrency from ordinary users. Consumers should be wary of unsolicited investment offers and crypto platforms, while defenders can use the shared framework fingerprints and domain patterns to block or investigate related sites.
Sources
Ionut Arghire 2026.06.27 100%
This article establishes a distinct underlying story: a specific shared scam-site ecosystem built on Uni-App templates, with quantified scale, infrastructure patterns, and named fraud operations such as RainbowEx, LSSC, and YST.
Full page
FBI and CISA warn Russian intelligence hackers are phishing for Signal backup recovery keys to read past messages
Social Engineering & PhishingThreat Actors & APTsGovernmentDefense & AerospaceMedia & EntertainmentFBICISASignal
The FBI and CISA say Russian intelligence-linked hackers are now trying to trick Signal users into handing over backup recovery keys, which can let the attackers restore and read victims’ past messages. The updated June 2026 public service announcement says the campaign, tracked as UNC5792 and UNC4221, previously focused on stealing Signal verification codes, PINs, or linking attacker-controlled devices, but now impersonates Signal support to push victims into enabling Secure Backups and then sending the recovery key needed to decrypt stored message history.
Why it matters: This matters because it can expose not just future chats but a victim’s historical Signal conversations, including sensitive government, military, journalistic, and Ukraine-related communications. At-risk users should treat any messages claiming to be from Signal support as suspicious, never share backup recovery keys, and review linked devices and backup settings immediately.
Sources
Lawrence Abrams 2026.06.26 100%
This article establishes a distinct, updated phase of a Russian intelligence phishing campaign: the shift from hijacking Signal accounts via codes or linked devices to stealing Signal Secure Backup recovery keys to access historical messages.
Full page
DHS watchdog says Secret Service used personal phones and insecure government devices during protective missions
Surveillance & PrivacyPolicy & RegulationGovernmentU.S. Secret ServiceDepartment of Homeland Security
A Department of Homeland Security watchdog found that U.S. Secret Service personnel routinely used personal cell phones for official protective work, including overseas trips, because government-issued devices lacked needed capabilities. The inspector general said the practice violated policy and exposed mission communications, location data, contacts, and other sensitive information to cyber threats; it also found vulnerable apps and insufficient real-time threat detection on government-furnished devices reviewed across 2022 to 2025.
Why it matters: This affects the security of senior U.S. officials and the agents protecting them, not just ordinary workplace compliance. Agencies with sensitive field operations may need to review mobile-device management, ban work on unmanaged personal phones, and harden issued phones against spyware and location tracking.
Sources
2026.06.26 100%
This article establishes a distinct oversight and operational-security story centered on a DHS inspector general report about Secret Service mobile-device practices, not a previously tracked breach, CVE, or policy item.
Full page
CISA says attackers are exploiting PTC Windchill and FlexPLM remote-code-execution flaw CVE-2026-12569
Zero-Days & CVEsUrgent PatchesManufacturingDefense & AerospaceTechnology & SoftwareRetail & E-CommerceGovernmentPTCCISA
Attackers are actively breaking into organizations that use PTC Windchill and FlexPLM, a product lifecycle management platform used by many industrial companies. The flaw, CVE-2026-12569, is an improper input validation bug that lets a remote unauthenticated attacker run arbitrary code through crafted requests. PTC began releasing patches and mitigations on June 17 and said attackers have used the bug to install persistent JSP web shells for remote command execution and data theft; CISA has added it to the Known Exploited Vulnerabilities catalog.
Why it matters: This is urgent for manufacturers and other firms that rely on Windchill or FlexPLM, because attackers can break in over the network without valid credentials and keep long-term access. Organizations should apply PTC's patches or mitigations immediately, check for the published indicators of compromise, and treat exposed servers as potentially compromised.
Sources
Bill Toulas 2026.06.26 93%
This updates the same CVE-2026-12569 story with CISA's KEV addition and a June 28 federal remediation deadline for actively exploited PTC Windchill and FlexPLM systems.
info@thehackernews.com (The Hacker News) 2026.06.26 97%
This source updates the same underlying event by adding that CISA placed the PTC Windchill flaw into the Known Exploited Vulnerabilities catalog and that web-shell attacks against exposed systems are ongoing.
Eduard Kovacs 2026.06.26 100%
This article establishes a new tracked story by reporting the first confirmed in-the-wild exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM, along with CISA KEV listing and PTC's web-shell and data-exfiltration details.
Full page
Polymarket says third-party vendor compromise injected malicious script and stole about $3 million from users
Supply ChainBreaches & Data LeaksScams & FraudCryptocurrency & BlockchainConsumers & General PublicPolymarket
Polymarket says hackers compromised a third-party vendor and used it to inject malicious code into the prediction market’s website, leading to theft from some users. The company said it removed the affected dependency and will refund impacted users. Blockchain tracking cited in the report says about $3 million in pUSD was stolen from at least 11 victims, then bridged from Polygon to Ethereum and swapped into about 1,893 ETH.
Why it matters: Users who connected wallets to Polymarket may have been exposed to a website-based theft campaign even if Polymarket itself was not directly breached. Affected users should watch for official notification, review wallet activity, and be cautious of follow-up phishing or refund scams tied to the incident.
Sources
Bill Toulas 2026.06.26 98%
This article reports the same Polymarket incident and adds details that the malicious JavaScript was injected into the frontend through a vendor dependency, that fewer than 15 accounts were affected, and that the stolen funds were bridged from Polygon to Ethereum and swapped into about 1,893 ETH.
Eduard Kovacs 2026.06.26 100%
This article appears to be the first tracked item here establishing the Polymarket incident as a distinct third-party compromise and crypto theft event.
Full page
Meta is reportedly testing real-time facial recognition for police and military with a Pentagon supplier
Surveillance & PrivacyGovernmentDefense & AerospaceConsumers & General PublicMeta
Meta is reportedly prototyping smart-glasses facial-recognition features for police and military users, raising new surveillance and civil-liberties concerns. The post points to reporting that Meta is working with a Pentagon supplier on technology that could identify people in real time through wearable devices, extending facial recognition from consumer or social features into frontline government and security use.
Why it matters: This matters because it could bring always-on identity tracking into routine law-enforcement and military operations, affecting both the public and organizations handling sensitive locations or events. The concrete takeaway is to watch for procurement, deployment, and policy disclosures around biometric wearables and real-time identification.
Sources
Bruce Schneier 2026.06.26 100%
This article establishes a distinct surveillance story about Meta's own reported facial-recognition prototyping for police and military use, rather than a confirmed procurement contract or an existing platform-policy dispute already tracked.
Full page
AWS patches Amazon Q Developer flaw CVE-2026-12957 that lets malicious repositories steal cloud credentials
Supply ChainUrgent PatchesZero-Days & CVEsTechnology & SoftwareAWSAmazon
AWS patched a flaw in Amazon Q Developer that could let a booby-trapped code repository steal a developer’s cloud credentials just by being opened in a supported development tool. Wiz said Amazon Q Developer would automatically act on workspace configuration files without user approval, enabling background command execution and credential theft from active environments; AWS assigned CVE-2026-12957 and also fixed related symbolic-link handling issue CVE-2026-12958 across VS Code, JetBrains, Eclipse, Visual Studio plugins, and the language server in version 1.65.0.
Why it matters: Developers and organizations using Amazon Q could have exposed AWS or other cloud access keys simply by opening a malicious repository, pull request, or fake coding test. Update the Amazon Q Developer plugin and ensure the language server is on 1.65.0 or later, especially where auto-update may be blocked.
Sources
2026.06.26 98%
This is the same underlying event: CVE-2026-12957 in Amazon Q Developer. The article adds The Register's summary of Wiz's findings, including that opening a repository containing a malicious .amazonq/mcp.json file could auto-execute commands via MCP in VS Code and inherit AWS credentials, API keys, tokens, and SSH agent access, and notes Amazon fixed it in language server version 1.65.0.
Eduard Kovacs 2026.06.26 100%
This article establishes a distinct new vulnerability story centered on AWS's patch and advisory for Amazon Q Developer credential-theft flaws CVE-2026-12957 and CVE-2026-12958.
Full page
California Assembly advances AB 2047, a bill that would require surveillance software on 3D printers
Surveillance & PrivacyPolicy & RegulationTechnology & SoftwareConsumers & General PublicCalifornia State AssemblyEFF
California’s Assembly advanced AB 2047, a bill that would require 3D printers to use software that monitors prints and tries to block firearm-related designs. EFF says the amended bill still mandates surveillance of all prints, relies on vague third-party standards, and continues to pressure manufacturers, resellers, and open-source developers to implement or support filtering technology, even after changes carving out some resale and entertainment uses.
Why it matters: This is a security- and rights-relevant policy fight because it would normalize device-level monitoring of lawful activity and could burden open-source tools and creators far beyond its stated target. People in California, printer makers, and open-source developers may need to track the bill closely and oppose or prepare for compliance requirements if it advances.
Sources
Cliff Braun 2026.06.26 100%
The article reports a specific new legislative step and substantive amendments to AB 2047, establishing a distinct ongoing policy story about mandated 3D printer surveillance in California.
Full page
Two alleged Scattered Spider members plead guilty over 2024 Transport for London cyberattack
Breaches & Data LeaksSocial Engineering & PhishingThreat Actors & APTsTransportation & LogisticsGovernmentConsumers & General PublicHealthcareTransport for LondonSSM HealthSutter HealthNational Crime Agency
Two alleged Scattered Spider members pleaded guilty to carrying out the September 2024 cyberattack on Transport for London, which disrupted transit-related services for months and exposed customer data tied to Oyster refund systems. The U.K. National Crime Agency said the pair infiltrated TfL's network, forcing 28,000 employees to reset passwords in person and contributing to about £29 million in losses and recovery costs; investigators also cited evidence of Telegram coordination and access to stolen-credential marketplaces.
Why it matters: This was a real-world, high-impact intrusion against a major public transport system, with costs, service disruption, and customer-data exposure. Transit agencies and other large organizations should treat it as another concrete Scattered Spider case and review identity controls, help-desk processes, credential exposure, and incident-response readiness.
Sources
SecurityWeek News 2026.06.26 98%
This source directly updates the same guilty-plea case and adds operational impact details from the 2024 Transport for London compromise, including disruption to fare refund systems, millions in remediation costs, and in-person password resets for 28,000 employees.
BrianKrebs 2026.06.23 98%
This article directly updates that same underlying event by reporting that Owen Flowers and Thalha Jubair pleaded guilty on the first day of trial over the August 2024 Transport for London attack, and adds details linking Flowers to the SSM Health and Sutter Health intrusions and Jubair to broader Scattered Spider phishing and SIM-swapping activity.
Bill Toulas 2026.06.23 99%
This article covers the same underlying TfL intrusion and updates it with the defendants' guilty pleas, the NCA's statement that the attack caused £29 million in losses, details that 28,000 staff had to reset passwords in person, and added evidence tying the pair to the breach and to other intrusions.
2026.06.23 100%
This article establishes a distinct tracked story because the existing list does not already include the Transport for London breach and this source provides the core event: guilty pleas, official attribution to Scattered Spider, timing, operational impact, and scope of exposed data.
Full page
Tata Electronics confirms cyberattack after extortion group claims theft of Apple and Tesla documents
Breaches & Data LeaksSupply ChainThreat Actors & APTsManufacturingTechnology & SoftwareTata ElectronicsAppleTesla
Tata Electronics says it suffered a cyberattack affecting some of its systems, after an extortion group claimed to have stolen and published confidential files tied to the company and its clients. The group, World Leaks, allegedly posted sample data that researchers said appeared to include Apple supplier specifications and Tesla-related manufacturing documents. Tata said it detected the incident weeks earlier and that operations were not disrupted, but it did not confirm the scope of data theft or whether a ransom demand was made.
Why it matters: This matters because Tata is part of the global manufacturing supply chain for major technology brands, so stolen internal documents could expose sensitive business, product, or partner information. Customers and partners should watch for follow-on fraud or espionage risks, and organizations in Tata’s supply chain should review any shared data and access paths.
Sources
SecurityWeek News 2026.06.26 94%
This source updates the same Tata Electronics breach with a claimed leak size of more than 630 GB and says the published data includes manufacturing specifications, schematics, and confidential drawings tied to Apple and Tesla, allegedly leaked by World Leaks.
Bill Toulas 2026.06.23 98%
This source directly updates the same Tata Electronics incident by adding Tata's confirmation to BleepingComputer, saying the attack hit parts of its IT infrastructure but did not disrupt operations, and by describing the alleged leaked Apple manufacturing files and linking the claim to World Leaks, the Hunters International rebrand.
2026.06.23 100%
This article establishes the story by providing Tata Electronics' own confirmation of a cyberattack following public claims by World Leaks that it stole and leaked client-related documents.
Full page
Citizen Lab says Russia used Cellebrite UFED to extract data from activist Andrey Pivovarov’s iPhone after Cellebrite said it left the market
Policy & RegulationSurveillance & PrivacyGovernmentNonprofits & NGOsConsumers & General PublicCellebriteCitizen LabOpen Russia
Researchers and rights groups say Russian authorities used Cellebrite’s UFED phone-forensics tool to access devices belonging to activist Andrey Pivovarov, helping support his prosecution and imprisonment. Citizen Lab says a Russian forensic report documented UFED use about three months after Cellebrite said it had stopped sales and services to Russia in March 2021; Cellebrite disputes that any post-exit use was authorized and says any legacy tools there are obsolete.
Why it matters: This is a surveillance and privacy story with direct consequences for activists, journalists, and dissidents: commercial forensic tools can still be used by abusive states even after a vendor claims to have exited the market. It raises urgent due-diligence and export-control questions for vendors and governments, and warns at-risk users that seized devices may be mined with commercial extraction tools.
Sources
SecurityWeek News 2026.06.26 97%
This source is another report on the same event, adding that local agency documents showed Russian investigators used legacy Cellebrite deployments after 2021 and alleging the extracted Telegram and WhatsApp data may have supported later phishing against the activist’s contacts.
2026.06.25 99%
This article is a direct report on the same underlying event and adds details on timing, the specific devices involved, how Citizen Lab tied the USB Host ID to Cellebrite, and Cellebrite’s response that any post-March 2021 use in Russia was unauthorized legacy use.
Donna Wentworth 2026.06.25 100%
This article establishes a distinct surveillance-abuse story centered on documented Russian use of Cellebrite UFED against a named activist after the vendor publicly said it had terminated contracts and services in Russia.
Full page
North Korea-linked Gaslight macOS malware uses fake error messages to mislead AI analysis tools
Threat Actors & APTsMalwareConsumers & General PublicTechnology & Software
Researchers found a new macOS malware family called Gaslight that steals data and gives attackers backdoor access while also trying to confuse AI-based malware analysis tools. SentinelOne says the Rust-based sample contains about 3.5 KB of embedded prompt-injection text and 38 fake system, crash, and debug messages meant to make large language model analysis pipelines abort or mistrust their own results; the company attributes the malware with high confidence to a North Korean-linked threat actor.
Why it matters: This matters because it shows attackers are adapting malware to interfere with newer AI-assisted security workflows, not just traditional sandboxes and analysts. Defenders using automated malware triage should validate AI findings against manual and non-LLM tooling, and macOS users and admins should treat the sample as a real backdoor and infostealer threat.
Sources
SecurityWeek News 2026.06.26 62%
The roundup cites the same newly reported Gaslight macOS backdoor as one of the week's notable developments, but provides no meaningful new technical detail beyond acknowledging the malware's existence.
Lawrence Abrams 2026.06.25 100%
This article establishes a distinct new event: the first reporting here is about the newly identified Gaslight macOS malware family, its embedded prompt-injection anti-analysis technique, and its attribution to a North Korean-linked actor.
Full page
Apple removes Russia’s state-backed Max messaging app from the App Store
Policy & RegulationInformation FreedomSurveillance & PrivacyCensorshipGovernmentTechnology & SoftwareConsumers & General PublicAppleVKRoskomnadzor
Apple removed Russia’s state-backed Max messaging app from the App Store, cutting off new iPhone and iPad downloads and updates for existing users. Apple told BBC Russia the removal was done to comply with sanctions regulations, while Russian officials said about 20 million users lost access through Apple’s marketplace. Max, developed by VK and promoted by the Russian state as a Telegram and WhatsApp alternative, is deeply integrated with government services, digital ID, e-signatures, and payments; critics warn its lack of end-to-end encryption could make user communications easier for authorities to monitor.
Why it matters: This affects Russian users who rely on Max and highlights how app-store controls, sanctions, and state-backed platforms can shape access to communication tools. It also matters for privacy watchers because Max is closely tied to government infrastructure, so users should weigh surveillance risks and loss of updates if they continue using it.
Sources
2026.06.26 91%
This article reports that Apple also removed a broader set of VK-operated apps from the App Store, including VKontakte, VK Messenger, VK Music, VK Video, Odnoklassniki, and Mail.ru services, and explicitly ties the move to the same sanctions-compliance rationale Apple cited for removing the Max app earlier in the month.
2026.06.04 100%
This article establishes a new story about Apple’s removal of the Max app as a distinct platform-access and privacy event, not the same underlying event as any listed tracked story.
Full page
Russia-linked Turla uses new StockStay backdoor to spy on Ukrainian government and military targets
Social Engineering & PhishingMalwareThreat Actors & APTsGovernmentDefense & AerospaceEducationGoogle
Google says the Russia-linked Turla hacking group has been using a newly detailed backdoor called StockStay to spy on government and military organizations in Ukraine. The .NET malware, developed since 2022, overlaps with Turla’s Kazuar implant and was delivered through phishing emails, malicious RDP configuration files, and in one November 2025 case a WinRAR exploit chain using CVE-2025-8088. Google also says compromised Ukrainian infrastructure and diplomacy- or education-themed lures were used in the campaign.
Why it matters: This is an active espionage campaign against wartime government and defense targets, with tactics defenders can hunt for now. Ukrainian and European public-sector organizations should review phishing defenses, inspect for StockStay-related persistence and WebSocket command-and-control traffic, and investigate any exposure to the cited WinRAR exploit chain.
Sources
2026.06.26 97%
This is the same underlying event: Google's disclosure that Turla used the StockStay malware against Ukrainian government and military organizations. The article adds details on StockStay's development since at least December 2022, its code similarities to Kazuar, its evolution from a fake stock app to PDF reader and calculator disguises, and phishing delivery via malicious Remote Desktop Protocol configuration files sent with academic and diplomatic lures, including abuse of a compromised Ukrainian university account and a diplomatic education platform.
Ionut Arghire 2026.06.26 100%
This article establishes a distinct campaign centered on Turla’s StockStay malware, its Ukraine-focused targeting, and its delivery methods; it is not the same underlying event as any listed tracked story.
Full page
Ukraine says Russian intelligence used fake messaging-support messages to hijack officials' and activists' chat accounts
Social Engineering & PhishingThreat Actors & APTsGovernmentDefense & AerospaceConsumers & General PublicSBUFBI
Ukraine’s security service says Russian intelligence and affiliated hackers ran a long-running social-engineering campaign to break into messaging accounts used by officials, military personnel, politicians, activists and other targets in Ukraine, Europe and the United States. According to the SBU, the attackers did not exploit a software flaw in the messaging apps; instead they impersonated platform support in text messages and tricked victims into handing over credentials, one-time verification codes, or PINs. The FBI reportedly worked with Ukraine on uncovering the activity, but the agencies did not name the specific Russian service, platforms, or victim count.
Why it matters: This is an account-takeover campaign aimed at high-value communications, so affected users could lose access to sensitive military, political, and personal information without any app vulnerability being involved. Organizations should urgently warn staff that support-themed texts asking for login details or verification codes are fraudulent and should review messaging-app account protections and recovery settings.
Sources
2026.06.26 100%
This article establishes a distinct SBU-announced Russian social-engineering campaign focused on hijacking messaging accounts across Ukraine, Europe, and the U.S., with new attribution and scope details not tied to a single previously tracked incident.
Full page
Suspected Miasma worm compromises more than 70 Microsoft GitHub repositories and breaks Azure CI/CD workflows
MalwareSupply ChainTechnology & SoftwareMicrosoftGitHubJFrognpm
GitHub disabled more than 70 Microsoft repositories after attackers allegedly used a compromised contributor account to push malicious commits into projects including Azure/durabletask and Azure/functions-action. StepSecurity says the Miasma worm planted configuration files that could trigger remote code execution when a developer opened the repository in an integrated development environment or AI coding tool such as Claude Code, Gemini CLI, or Cursor, and the takedowns disrupted workflows that depended on Azure/functions-action@v1.
Why it matters: This affects developers and organizations that rely on Microsoft's open-source Azure tooling, with both supply-chain risk and immediate build-pipeline disruption. Teams using the affected repositories should review recent commits, rotate contributor and automation tokens, check developer machines for malicious config execution, and verify dependencies before restoring pipelines.
Sources
2026.06.26 92%
This article updates the same Miasma self-propagating supply-chain campaign with a new infection wave: attackers compromised npm maintainer account "czirker" and poisoned 20-plus Leo Platform and RStreams package versions, while Microsoft and Sonatype describe evolved tradecraft including Bun-based execution, GitHub Actions memory scraping, and republishing through stolen maintainer access.
Bill Toulas 2026.06.10 82%
This article adds specific technical detail about the same Miasma campaign family linked to the Microsoft repository compromises, including that the source code was deliberately leaked via compromised GitHub accounts, how it steals cloud and CI/CD secrets, abuses GitHub as its control channel, targets npm, PyPI, RubyGems and JFrog Artifactory, and includes a destructive dead-man switch that wipes files if a stolen GitHub token is revoked.
2026.06.09 95%
This is a direct update on the same Miasma campaign, adding that the worm's full attack toolkit was open sourced via GitHub using previously compromised accounts, with new technical detail on its capabilities across GitHub, package registries, Artifactory, GitHub Actions, AI tool config poisoning, SSH lateral movement, and GitHub-based command-and-control.
Bill Toulas 2026.06.09 99%
This article is a direct update on the same June 5 Microsoft GitHub repository compromise, adding that GitHub disabled 73 repositories for 105 seconds, Microsoft has restored them, notified a small number of potentially affected customers, and BleepingComputer ties the incident more concretely to the Miasma/Shai-Hulud supply-chain campaign and the earlier durabletask compromise.
Ionut Arghire 2026.06.09 68%
The article ties the Miasma variant to the broader Shai-Hulud family and notes it emerged after the worm source code was released, helping connect the malware lineage behind related GitHub and CI/CD compromise activity.
2026.06.08 100%
The article establishes a distinct Microsoft-focused compromise event: a suspected Miasma worm infection of 73 GitHub repositories that triggered GitHub takedowns and caused downstream Azure CI/CD failures, even if it is related to the broader Mini Shai-Hulud lineage.
Full page
FCC approves tougher undersea cable security rules and plans licensing for submarine cable terminal equipment
Policy & RegulationTelecommunicationsTelecommunicationsTechnology & SoftwareFCCHuaweiChina TelecomZTEChina Mobile
The U.S. Federal Communications Commission voted to tighten security rules for undersea internet cables and to block Chinese and other foreign-adversary equipment from key parts of those systems. The order would require licensing for submarine line terminal equipment (SLTE), the gear that links submarine cables to U.S. terrestrial networks, and would streamline approvals for operators that meet security and oversight conditions. The rules also expand scrutiny of equipment suppliers and third-party service providers tied to cable operations.
Why it matters: Undersea cables carry most of the world's internet traffic, so new security rules for the equipment and operators behind them matter well beyond telecom companies. Cable operators, vendors, and policymakers should review the new licensing and procurement restrictions, especially around foreign-sourced equipment and service providers.
Sources
2026.06.26 100%
This article establishes a distinct policy story because it reports the FCC's formal vote and concrete new requirements for undersea cable security, rather than commentary or a previously tracked approval.
Full page
Nearly 1 million passport images were exposed after an ID-verification database used by cannabis dispensaries was leaked online
Breaches & Data LeaksSurveillance & PrivacyConsumers & General PublicRetail & E-Commerce
A database containing nearly one million passport records from around the world was reportedly leaked online, exposing highly sensitive identity documents submitted by users. The leaked data appears tied to an identity-verification system used by cannabis dispensaries, where customers uploaded passports for age or identity checks. The post does not name the affected vendor, breach method, or confirmed time window, but the exposed records involve passport data repurposed for a lower-value authentication workflow.
Why it matters: Passport exposure can enable identity theft, account verification abuse, and long-term fraud because passports are hard to replace and often reused to prove identity elsewhere. People who uploaded passports for dispensary verification should watch for impersonation or account-opening fraud, and organizations should reassess whether they collect and retain full document images at all.
Sources
Bruce Schneier 2026.06.26 100%
This article establishes a distinct breach story centered on the online leak of nearly one million passport records from an ID-verification database used by cannabis dispensaries.
Full page
Polish authorities arrest SIM-swapping gang accused of breaching telecom partners and stealing millions in cryptocurrency
Scams & FraudSocial Engineering & PhishingBreaches & Data LeaksTelecommunicationsCryptocurrency & BlockchainConsumers & General PublicPolish Cybercrime BureauFBIHomeland Security Investigations
Polish authorities arrested four people accused of stealing millions by hijacking victims’ phone numbers and taking over their cryptocurrency accounts. Investigators say the group breached entities working with telecommunications operators and compromised employee email accounts using software and social engineering, then intercepted SMS messages and email traffic to conduct SIM-swapping attacks; the operation involved support from the FBI and Homeland Security Investigations.
Why it matters: SIM swapping can let criminals bypass text-message security codes and seize control of email, financial, and crypto accounts. Telecom-adjacent organizations should review partner access and employee email protections, and users should move high-value accounts away from SMS-based authentication where possible.
Sources
Bill Toulas 2026.06.25 100%
This article establishes the story by reporting the arrests, the attack method used against telecom partners and employee accounts, and the alleged theft and laundering of millions tied to SIM-swapping attacks.
Full page
Symantec and Zscaler link new Mistic backdoor to KongTuke ransomware access broker
Threat Actors & APTsRansomwareMalwareSocial Engineering & PhishingInsuranceEducationTechnology & SoftwareLegal & Professional ServicesMicrosoft
Researchers say a newly identified backdoor called Mistic is being used to quietly keep access inside company networks in attacks tied to KongTuke, an initial access broker linked to ransomware groups. Symantec says Mistic has been used since April 2026 against organizations in insurance, education, IT, and professional services, including deployment after ModeloRAT in at least one case. The malware is side-loaded through MpExtMs.exe and a malicious version.dll, can run payloads in memory, steal credentials via a fake login prompt, and receive commands from attacker-controlled servers; Zscaler says it also appeared in a multi-stage ClickFix infection chain and can load Beacon Object Files for in-memory post-exploitation.
Why it matters: Organizations in the named sectors may be facing a low-visibility foothold used to prepare ransomware attacks, not just one-off malware infections. Defenders should hunt for KongTuke and ClickFix activity, review Symantec and Zscaler indicators, and watch for suspicious DLL side-loading, fake login prompts, and Microsoft Teams-based social engineering.
Sources
2026.06.25 96%
This article is a direct follow-on to the same Mistic/KongTuke event, adding that Symantec and Carbon Black saw Mistic in multiple intrusions since April across insurance, education, IT, and professional services, including one case where it appeared alongside KongTuke's ModeloRAT and was side-loaded via MpExtMs.exe and EndpointDlp.dll.
info@thehackernews.com (The Hacker News) 2026.06.25 98%
This is the same underlying event: reporting on the newly identified Mistic backdoor and its connection to the KongTuke access-broker ecosystem, including its use in ClickFix and ModeloRAT-linked delivery campaigns.
Ionut Arghire 2026.06.24 98%
This is the same underlying event: reporting on the new Mistic RAT/MLTBackdoor used by the KongTuke/Woodgnat initial access broker. It adds detail that the actor has used Mistic since April 2026, is targeting education, insurance, IT, and professional services, and is using Microsoft Teams helpdesk lures plus ClickFix/FileFix/CrashFix-style social engineering to get victims to run malicious PowerShell.
Bill Toulas 2026.06.24 100%
This article establishes a distinct threat story by introducing Mistic as a newly reported backdoor and concretely linking it to KongTuke's ransomware-access operations across multiple sectors.
Full page
Rights groups challenge Paraguay’s secrecy over police facial-recognition surveillance in Asunción
Surveillance & PrivacyPolicy & RegulationGovernmentConsumers & General PublicParaguay Ministry of the InteriorParaguay National PoliceInter-American Commission on Human Rights
EFF, TEDIC, and CEJIL filed a complaint against Paraguay over the government’s refusal to disclose how police facial-recognition surveillance is being used in Asunción. The case centers on cameras installed in 2019 by the Ministry of the Interior and National Police, and seeks details on contracts, protocols, biometric-data processing, and whether authorities performed human-rights or data-protection impact assessments before deployment.
Why it matters: This matters to the public because facial recognition can enable large-scale biometric surveillance with little visibility into how people’s data is collected or used. The case could force more transparency and oversight in Paraguay and help set a precedent for surveillance safeguards across Latin America.
Sources
Veridiana Alimonti 2026.06.25 100%
This article establishes a new tracked story because it is a specific legal and human-rights challenge tied to Paraguay’s use of facial-recognition surveillance and there is no existing tracked story about this same underlying event.
Full page
U.S. state officials pressure abortion-information websites including Plan C and Mayday Health to remove online content
Information FreedomCensorshipPolicy & RegulationHealthcareNonprofits & NGOsConsumers & General PublicGovernmentPlan CMayday HealthPrairie Abortion FundAlabama Attorney GeneralArkansas Attorney GeneralNorth Dakota Attorney General
State attorneys general and lawmakers are targeting websites that publish information about abortion access, even when those sites do not sell or prescribe medication. EFF says Alabama and Arkansas sent cease-and-desist demands to groups including Plan C and Mayday Health, North Dakota pressured Prairie Abortion Fund over links to outside resources, and South Dakota passed a law that Mayday Health says could criminalize online abortion-related "advertising" and informational speech.
Why it matters: This is a live censorship and digital-rights issue affecting people seeking health information and the groups that publish it. It matters beyond abortion because legal threats, takedown demands, and broad speech restrictions can chill lawful online information and set precedent for suppressing other sensitive topics.
Sources
Lisa Femia 2026.06.25 100%
This article establishes a concrete, ongoing censorship campaign centered on specific state legal threats and laws aimed at abortion-information websites, rather than updating an existing tracked event.
Full page
Scammers abuse Shopify's Shop app to plant fake order receipts and run callback phishing attacks
Social Engineering & PhishingScams & FraudRetail & E-CommerceConsumers & General PublicShopifyShopNortonMcAfeeApplePayPal
Attackers are abusing Shopify's Shop order-tracking app by inserting fake purchase receipts into users' order histories, then using the listed phone numbers to trick people into calling scammers. The fake receipts impersonate brands including Norton, McAfee, Apple, and PayPal, and the callback phishing flow aims to steal credentials, payment-card details, and one-time passcodes; some victims are also persuaded to install remote-access software. Researchers said they found no evidence that Shop, Shopify, or the impersonated brands were breached, and the insertion method is still unclear.
Why it matters: This matters because the scam appears inside a trusted shopping app rather than email, making it more believable and more likely to fool consumers. Users should avoid calling numbers shown on unexpected Shop receipts, verify charges directly with their bank or merchant, and reset credentials and contact their card issuer if they already engaged with the scammers.
Sources
Bill Toulas 2026.06.25 100%
This article establishes a distinct scam campaign centered on abuse of the Shop app itself as the lure delivery channel for callback phishing, not just generic invoice phishing.
Full page
DOJ, Thai police and tech firms disrupt 1.4 million scam accounts tied to Southeast Asia fraud compounds
Scams & FraudPolicy & RegulationGovernmentTechnology & SoftwareTelecommunicationsCryptocurrency & BlockchainConsumers & General PublicDOJRoyal Thai PoliceAppleGoogleMetaMicrosoftInterpolAmnesty International
Law enforcement and major tech companies say they disrupted more than 1.4 million accounts and related infrastructure used by scam networks operating from Southeast Asia. The operation, called Disruption Week, involved the US Department of Justice, Royal Thai Police, and firms including Apple, Google, Meta, Microsoft, Coinbase, SpaceX, Silent Push, TRM Labs, and Zenlayer; it led to 63 arrests, the freezing of over $3.8 million in cryptocurrency, and takedowns of social-media accounts, Microsoft accounts, Starlink kits, servers, and malicious network infrastructure linked to fraud compounds in Cambodia, Laos, and Burma.
Why it matters: This matters because the operation targeted industrial-scale scam networks that steal money from victims worldwide and rely on mainstream platforms and connectivity to operate. Users should remain cautious of investment and impersonation scams, while defenders and platforms should watch for follow-on account rebuilds, infrastructure shifts, and related fraud activity.
Sources
Robert Lemos 2026.06.25 73%
This article adds broader context and follow-on reporting to the same underlying regional scam-compound ecosystem, arguing that corruption and police collusion in countries including Cambodia are blunting the impact of cross-border crackdowns and helping the fraud infrastructure persist.
Ionut Arghire 2026.06.04 100%
This article establishes a new tracked story around the named 'Disruption Week' crackdown and its specific cross-industry takedown of scam accounts, infrastructure, and crypto assets tied to Southeast Asian fraud compounds.
Full page
DHS says it will reshape CISA as workforce and budget cuts raise concerns about U.S. cyber defense capacity
Surveillance & PrivacyPolicy & RegulationGovernmentEducationEnergy & UtilitiesCISADHSTreasury DepartmentMS-ISACPalantir
The Homeland Security secretary said the Trump administration plans to refocus and rebuild CISA even as the agency has lost roughly a third of its staff and faces proposed budget cuts. Secretary Markwayne Mullin told lawmakers CISA now has about 2,200 personnel and likely needs about 2,800, while the White House's fiscal 2027 budget would cut more than $700 million. He also signaled a new nominee to lead CISA and defended assigning Treasury a lead role in an AI vulnerability clearinghouse created by the new executive order.
Why it matters: CISA is the main federal agency that helps defend civilian networks, coordinate with private companies, and warn about major cyber risks, so sharp cuts or mission changes can affect incident response and national cyber preparedness. This matters to defenders, state and local governments, and the public because it signals potential changes in federal cyber support, vulnerability handling, and long-term staffing capacity.
Sources
2026.06.25 87%
This advances the same underlying event: the Trump administration’s restructuring of CISA after major staffing cuts. It adds that the president has met with a potential CISA director nominee, that DHS believes CISA needs about 600 hires, that rebuilding may take about a year, and that DHS wants broader clarity from Congress on CISA’s role.
2026.06.17 88%
This advances the same underlying event by adding Sen. Mark Warner's letters documenting claimed one-third staffing cuts, regional leadership gaps, reduced support to state and local entities, and the funding fight over MS-ISAC after DHS stopped paying for it.
2026.06.04 84%
This article adds concrete new information to that same broader CISA restructuring event: the Trump administration is considering Palantir CTO Shyam Sankar to fill the long-vacant CISA director role, while DHS says a nomination is imminent and CISA is being tasked with implementing the new AI executive order.
2026.06.03 100%
This article establishes a distinct policy story centered on DHS's stated plan to reshape CISA amid staffing losses, budget reductions, and pending leadership changes, rather than a specific breach or vulnerability event already tracked.
Full page
FCC proposal would require phone carriers to verify customer identity and collect ID numbers, threatening anonymous burner phones
Surveillance & PrivacyPolicy & RegulationTelecommunicationsConsumers & General PublicFCCAT&TComcast
The U.S. Federal Communications Commission is considering a rule that would make it much harder to buy or renew a phone plan without tying it to your real identity. The proposal would require telecom providers to collect and store personal data including a government-issued identification number and physical address for new and renewing customers, and would also require extra information for some business and foreign bulk-plan buyers, including intended use and IP address.
Why it matters: This would affect ordinary phone users nationwide by ending much of the anonymity associated with prepaid or 'burner' phones and by creating larger stores of sensitive identity data at telecoms. Privacy and security teams, civil-liberties groups, and consumers should watch the rulemaking closely because any mandated data collection also creates new breach, misuse, and surveillance risks.
Sources
Cooper Quintin 2026.06.25 98%
This article directly discusses the same FCC rulemaking and adds civil-liberties opposition from EFF and ACLU, plus specific arguments that the proposal would not meaningfully reduce robocalls and would instead expand data collection and threaten anonymous phone access.
Bruce Schneier 2026.06.15 100%
This article establishes a distinct policy and privacy story about a new FCC proposal to mandate identity collection for phone-plan customers; it does not match an existing tracked event in the list.
Full page
PirloTV sports piracy network disrupted as 44 domains are seized in anti-piracy operation
Policy & RegulationMedia & EntertainmentConsumers & General PublicPirloTVUEFAIMPI
Authorities and rights holders disrupted the PirloTV sports piracy network by seizing 44 domains used to direct viewers to unauthorized live sports streams. ACE said the domains drew more than 950 million visits a year, with strong usage in Mexico, Colombia, Spain, and the United States. The operation involved UEFA, UC3, and Mexican authorities, including IMPI, and targeted a platform known for rapidly shifting to new domains after takedowns.
Why it matters: This affects millions of users who rely on unauthorized sports-streaming sites and shows how quickly major piracy networks can be disrupted, especially around high-profile events like the World Cup. It also signals continued cross-border domain seizure and takedown efforts against large online abuse ecosystems.
Sources
Bill Toulas 2026.06.25 100%
This article establishes a distinct new event: the seizure of 44 PirloTV-linked domains in a coordinated anti-piracy enforcement action, separate from the previously tracked CINEMAGOAL and KRATOS 2 cases.
Full page
Bluekit phishing platform adds browser-in-the-middle login theft to capture account sessions
Social Engineering & PhishingConsumers & General PublicTechnology & SoftwareMicrosoftGoogleAppleGitHubYahooLedger
Bluekit, a phishing-as-a-service platform used to steal logins for major email and online accounts, has added a more advanced browser-in-the-middle technique that can hand attackers live authenticated sessions. Netcraft says the kit now uses the legitimate rrweb JavaScript library to stream a real browser session over WebSockets while relaying the victim’s interactions to the attacker, and it still includes anti-analysis features such as browser fingerprinting, WebRTC IP checks, obfuscated scripts, fake CAPTCHAs, and live victim monitoring. Reported targets include Outlook, Gmail, Yahoo, ProtonMail, iCloud, GitHub, and Ledger users.
Why it matters: This makes phishing pages harder to spot and can let criminals bypass normal login protections by stealing valid session tokens, not just passwords. Organizations should tighten phishing defenses, watch for suspicious login-session activity and WebSocket-based fake login pages, and remind users to be cautious with branded sign-in links and unusual page lag.
Sources
Bill Toulas 2026.06.25 100%
This article establishes a distinct story about Bluekit's evolution into a browser-in-the-middle phishing platform, including specific new infrastructure growth and tradecraft changes that defenders may need to detect.
Full page
Cyberattack disrupts Ufagormolzavod dairy shipments and accounting in Russia's Bashkortostan region
Breaches & Data LeaksManufacturingUfagormolzavod
A cyberattack disrupted logistics and accounting systems at Russian dairy producer Ufagormolzavod, forcing the company to handle shipments and paperwork manually. The company said production continued, but document processing and outbound shipments slowed. No threat actor, malware family, vulnerability, or data theft details were disclosed, and it is not yet known whether the incident is linked to other recent attacks on Russian dairy-sector organizations in Bashkortostan.
Why it matters: This is a real operational disruption affecting a food manufacturer, showing that even when production stays online, attacks on business systems can still slow deliveries and day-to-day operations. Organizations in manufacturing and regional supply chains should review resilience for logistics, accounting, and manual fallback processes.
Sources
2026.06.25 100%
The article appears to be the first report of this specific cyberattack on Ufagormolzavod and provides the initial facts about the disruption.
Full page
Cyberattack disrupts Ukrposhta mobile app as pro-Russian IT Army of Russia claims breach and data theft
Threat Actors & APTsBreaches & Data LeaksGovernmentTransportation & LogisticsConsumers & General PublicUkrposhta
Ukraine's state postal operator said a cyberattack disrupted its mobile app after attackers hit the company's IT systems overnight. Ukrposhta has not confirmed data theft, but the pro-Russian group IT Army of Russia claimed it had earlier breached a server, exfiltrated a user database, and stolen internal data. No malware family, vulnerability, or CVE was identified, and the confirmed impact so far is limited to app outages.
Why it matters: This affects a major public-facing service in Ukraine and could have privacy implications if the data-theft claims are confirmed. Ukrposhta users should watch for service notices and possible follow-on phishing, while defenders should treat the incident as a potentially broader Russia-linked intrusion rather than a simple outage.
Sources
2026.06.25 100%
This article appears to be the first concrete report of the Ukrposhta incident, tying a confirmed service disruption to a claimed pro-Russian intrusion and possible exfiltration.
Full page
Iran-linked Handala claims breach of California Water Service and leaks customer data and RTKBase credentials
Threat Actors & APTsBreaches & Data LeaksEnergy & UtilitiesCalifornia Water ServiceMandiant
Iran-linked hackers calling themselves Handala say they broke into California Water Service and published 5GB of stolen data. The leak reportedly includes customer personal information, billing records, administrative credentials for Cal Water's RTKBase GNSS base-station platform, and an NTRIP source password; Dataminr assesses the RTKBase instance was likely the initial access point or lateral-movement path into a separate billing environment, though confirmed disruption of industrial control systems has not been reported.
Why it matters: A water utility serving about 2 million customers may have exposed sensitive customer data, and the presence of infrastructure credentials raises concern about follow-on intrusion or disruption. Cal Water and any connected operators should rotate exposed credentials immediately, audit RTKBase and billing access, and review segmentation and logs for further compromise.
Sources
Eduard Kovacs 2026.06.25 96%
This directly updates the same Cal Water/Handala incident with Mandiant’s investigation results, saying the activity was limited to a small number of accounts in two third-party platforms and that no evidence was found of threat actor activity in Cal Water’s internal IT or OT environments.
Eduard Kovacs 2026.06.16 96%
This article updates the same Handala-Cal Water incident with the company's first public response, saying it activated its incident response plan, is coordinating with state and federal partners, and has found no known operational disruption so far despite the leaked data claims.
Ionut Arghire 2026.06.12 100%
This article appears to be the first concrete report in the set about Handala's claimed intrusion into Cal Water, including the alleged victim, leaked data types, and suspected access path.
Full page
CISA says attackers are exploiting Lantronix EDS5000 command-injection flaw CVE-2025-67038
Urgent PatchesZero-Days & CVEsThreat Actors & APTsTechnology & SoftwareEnergy & UtilitiesManufacturingTransportation & LogisticsHealthcareCISALantronix
CISA says hackers are actively exploiting a critical flaw in Lantronix EDS5000 serial-to-Ethernet servers, and affected organizations should patch quickly. The bug, CVE-2025-67038, affects EDS5000 firmware 2.1.0.0R3 and stems from unsanitized input in the HTTP remote-procedure-call module, allowing remote root-level command injection; Lantronix says users should upgrade to version 2.2.0.0R1.
Why it matters: Organizations using these device-management servers could be exposed to full remote takeover if they have not updated. This is urgent because CISA has confirmed exploitation in the wild and federal agencies have a three-day remediation deadline.
Sources
Eduard Kovacs 2026.06.25 96%
This article updates the same event by tying the exploited flaw to the earlier BRIDGE:BREAK OT research, noting CISA added it to KEV on June 23 with a June 26 remediation deadline for federal agencies, and adding context on possible OT and healthcare impact plus internet exposure.
info@thehackernews.com (The Hacker News) 2026.06.24 99%
This article appears to report the same CISA warning about active exploitation of the Lantronix EDS5000 flaw, reinforcing the exploitation status and urgency to patch or mitigate affected serial-to-Ethernet servers.
Bill Toulas 2026.06.24 100%
The article appears to be the first tracked item here tying CVE-2025-67038 in Lantronix EDS5000 to CISA-confirmed active exploitation and KEV inclusion.
Full page
GitLab fixes 13 security flaws in CE and EE, including high-severity XSS and data-exposure bugs
Urgent PatchesZero-Days & CVEsTechnology & SoftwareGitLab
GitLab released security updates for its self-managed Community Edition and Enterprise Edition platforms, fixing 13 vulnerabilities that could let attackers run code in users’ browsers or expose sensitive project data. The most serious issues are CVE-2026-10086, an authenticated cross-site scripting flaw in the GitLab EE Analytics dashboard; CVE-2026-10712, an unauthenticated cross-site scripting flaw in the Web IDE workbench asset handler; and CVE-2026-12053, an information disclosure bug in Duo Workflows. Fixes are in GitLab CE/EE 19.1.1, 19.0.3, and 18.11.6.
Why it matters: Organizations running self-managed GitLab should update quickly, because these flaws can help attackers hijack browser sessions, tamper with settings, or expose sensitive development data and secrets. GitLab.com is already patched, but private GitLab servers remain the admins’ responsibility.
Sources
Ionut Arghire 2026.06.25 100%
This article establishes a distinct patch event centered on GitLab's June 2026 CE/EE security releases and the specific CVEs fixed in those versions.
Full page
Curl patches 18 vulnerabilities, including 25-year-old libcurl authentication-bypass flaw CVE-2026-8932
Urgent PatchesZero-Days & CVEsTechnology & SoftwareConsumers & General Publiccurl
Curl released an update fixing 18 security vulnerabilities, including a 25-year-old flaw in libcurl that could let applications reuse the wrong mutual-TLS identity and bypass authentication. The bugs affect curl/libcurl, with four rated medium and 14 low severity; the oldest, CVE-2026-8932, was introduced in curl 7.7 in 2001 and affects libcurl applications rather than the curl command-line tool. Other fixed issues include CVE-2026-8926, CVE-2026-8925, CVE-2026-9080, CVE-2026-10536, and CVE-2026-9547.
Why it matters: Curl and libcurl are embedded across servers, apps, phones, cars, and enterprise software, so even medium-severity flaws can have broad downstream impact. Organizations and software vendors that ship or depend on libcurl should update promptly and review where client-certificate authentication is used.
Sources
Ionut Arghire 2026.06.25 100%
This article establishes a new tracked story around curl's June 2026 security release and the specific long-lived libcurl flaw CVE-2026-8932, which is not represented in the existing story list.
Full page
Google Chrome 149 security update fixes 18 severe browser vulnerabilities
Urgent PatchesConsumers & General PublicTechnology & SoftwareGoogle
Google released a Chrome 149 security update that fixes 18 serious browser flaws affecting Windows, macOS, and Linux users. The batch includes four critical and 14 high-severity vulnerabilities in Chrome 149.0.7827.196/197 for Windows and macOS and 149.0.7827.196 for Linux; more than half are use-after-free memory-corruption bugs that can potentially lead to remote code execution, alongside out-of-bounds read, uninitialized use, insufficient validation of untrusted input, and implementation flaws. Google said none are known to be exploited in the wild.
Why it matters: Chrome is widely used, so browser security fixes can quickly affect large numbers of people and organizations. Users and IT teams should update Chrome promptly because several of the patched bugs could potentially let attackers run code through a malicious webpage.
Sources
Ionut Arghire 2026.06.25 100%
This article establishes a distinct Chrome 149 patch-release story about a new batch of 18 severe vulnerabilities, separate from the already tracked Chrome 149 zero-day and broader 429-fix update story.
Full page
Cisco discloses exploited Catalyst SD-WAN Manager zero-day CVE-2026-20245 with no patch yet
Threat Actors & APTsZero-Days & CVEsUrgent PatchesTechnology & SoftwareTelecommunicationsGovernmentCiscoMandiant
Cisco says attackers are exploiting a new zero-day in Catalyst SD-WAN Manager, and affected organizations do not yet have a patch. The flaw, CVE-2026-20245, is a command-injection vulnerability in the command-line interface that lets an authenticated local attacker with netadmin privileges execute arbitrary commands as root by uploading a crafted file. Cisco said exploitation has been limited but observed cases where attackers pushed configuration changes to edge devices, and published indicators of compromise.
Why it matters: Organizations running Cisco Catalyst SD-WAN Manager face an actively exploited flaw that can give attackers full control of the system, with no fix available yet. Defenders should urgently check Cisco's indicators of compromise, restrict and review privileged access, hunt for abuse of related SD-WAN flaws, and prepare to patch as soon as Cisco releases updates.
Sources
Eduard Kovacs 2026.06.25 96%
This is a direct update on the same underlying event: exploitation of Cisco Catalyst SD-WAN Manager zero-day CVE-2026-20245. The new source adds that Mandiant observed exploitation as early as March 2026 at a service provider, describes use of SSH access via the default vmanage-admin account, privilege escalation to root, password changes for stealth, cleanup steps, and possible links to earlier SD-WAN zero-days CVE-2026-20127 or CVE-2026-20182.
2026.06.24 88%
This source adds specific incident details to the same CVE-2026-20245 story, including Mandiant's report that exploitation began earlier than Cisco initially disclosed and that an attacker at a communications service provider escalated from a compromised admin account to root and exfiltrated SD-WAN fabric configurations.
Lawrence Abrams 2026.06.24 96%
This article updates the same underlying event by detailing Mandiant's incident findings on CVE-2026-20245 exploitation, including use of rogue peering, the vmanage-admin account, the tenant-upload CSV payload, creation of a temporary root account named 'troot,' and anti-forensic cleanup. It also ties the intrusion path to previously disclosed Cisco SD-WAN authentication-bypass flaws CVE-2026-20127 and CVE-2026-20182.
2026.06.17 28%
The article mentions CVE-2026-20245 only as background and is not primarily about that later zero-day, so it is related product context rather than the same underlying event.
info@thehackernews.com (The Hacker News) 2026.06.10 92%
This source updates the same Cisco event by saying CISA added CVE-2026-20245 to KEV amid active exploitation, which strengthens the operational urgency for organizations running Catalyst SD-WAN Manager while waiting for a vendor fix and applying available mitigations.
info@thehackernews.com (The Hacker News) 2026.06.06 99%
This article covers the same underlying event: Cisco's disclosure that CVE-2026-20245 in Catalyst SD-WAN Manager is being exploited in the wild and currently lacks an available fix.
2026.06.05 98%
This article is a direct report on the same event: Cisco's disclosure that CVE-2026-20245 in Catalyst SD-WAN Manager is being exploited in the wild with no patch available. It adds reporting detail that exploitation appears to date back at least a week, that all versions and deployment types including FedRAMP are affected, and that Cisco says attackers would need netadmin access or exploitation of CVE-2026-20182 or CVE-2026-20127.
Sergiu Gatlan 2026.06.05 99%
This article covers the same underlying event: Cisco's warning that CVE-2026-20245 in Catalyst SD-WAN Manager is being exploited as a zero-day with no patch available. It adds concrete details on the privilege-escalation path, affected deployment types, Mandiant's role in reporting, the dependency on valid netadmin access or exploitation of CVE-2026-20182/CVE-2026-20127, observed configuration changes pushed to edge devices, and example indicators of compromise in scripts.log.
Eduard Kovacs 2026.06.05 100%
This article establishes a distinct new event: Cisco's disclosure of in-the-wild exploitation of CVE-2026-20245 in Catalyst SD-WAN Manager, a separate zero-day from the other Cisco and SD-WAN stories already tracked.
Full page
ASIO says nation-state hackers breached an Australian critical infrastructure provider and prepared for possible sabotage
Threat Actors & APTsEnergy & UtilitiesTelecommunicationsTransportation & LogisticsASIO
Australia’s domestic security agency says a state-backed hacking group got into the network of an unnamed Australian critical infrastructure provider and stole active user credentials, including accounts used by IT defenders. ASIO said the intruders were not just spying but mapping the network and maintaining access so they could disrupt or cripple operations later; the agency says it attributed the intrusion and is still working with the victim and partners on remediation.
Why it matters: This is the kind of intrusion that can move from hidden access to real-world disruption of essential services. Australian critical infrastructure operators and defenders should review credential exposure, hunt for persistent access, and treat state-backed reconnaissance inside operational networks as an urgent incident.
Sources
2026.06.25 100%
The article is the first concrete report here of ASIO publicly disclosing that a nation-state compromised an Australian critical infrastructure provider, stole defender credentials, and appeared to be positioning for sabotage.
Full page
ASIO says a foreign intelligence service used a fake consulting approach to seek AUKUS information from an Australian clearance holder
Threat Actors & APTsSocial Engineering & PhishingGovernmentDefense & AerospaceASIOAUKUS
Australia’s security service says a foreign spy posed as a consultant online, paid an Australian security clearance holder for reports, and then tried to obtain insider information on AUKUS, the Australia-UK-U.S. defense pact. ASIO says the target reported the contact, helped the agency study the operation, and that officers directly warned the suspected foreign operative to stop targeting Australians.
Why it matters: This is a clear example of online social engineering used for state espionage against defense-related personnel. People with government or defense access should treat paid research requests, consulting offers, and requests for nonpublic policy or program details as potential recruitment attempts.
Sources
2026.06.25 100%
The article establishes a distinct espionage story with a specific recruitment-style targeting operation against an Australian clearance holder for AUKUS-related information.
Full page
Third defendant sentenced over 2022 DraftKings credential-stuffing attack that hijacked 60,000 betting accounts
Social Engineering & PhishingScams & FraudPolicy & RegulationConsumers & General PublicDraftKingsDOJ
A third man has been sentenced for his role in the 2022 attack that broke into thousands of DraftKings customer accounts and stole or resold access to them. The Justice Department said the group used credential stuffing, meaning reused usernames and passwords from other breaches, to access more than 60,000 accounts on the fantasy sports and betting platform; Nathan Austad was sentenced to 18 months and ordered to pay about $1.8 million, while the scheme stole roughly $600,000 from 1,600 accounts.
Why it matters: This highlights the ongoing risk of password reuse and account takeover for consumer financial and betting accounts. Affected users should reset reused passwords, enable phishing-resistant multi-factor authentication where available, and review account balances and withdrawal history.
Sources
Bill Toulas 2026.06.24 98%
This is a direct update to the same November 2022 DraftKings account-takeover case, adding the 18-month prison sentence for Nathan Austad ('Snoopy'), along with forfeiture, restitution, and details on his role selling access to stolen accounts.
Eduard Kovacs 2026.06.24 100%
The article establishes a trackable enforcement and threat story around the 2022 DraftKings credential-stuffing attack by adding a new sentencing outcome for one of the participants.
Full page
Malicious Microsoft Edge extension used Native Messaging to install a Python backdoor in ransomware-linked attacks
MalwareRansomwareSocial Engineering & PhishingConsumers & General PublicTechnology & SoftwareMicrosoft
Attackers used a fake Microsoft Edge update process to trick employees into installing a malicious browser extension that helped deploy malware on their computers. Zscaler says the 'Edgecution' campaign starts with Microsoft Teams messages from fake IT support and uses Chrome Native Messaging in Microsoft Edge to let the extension communicate with a local Python-based backdoor outside the browser sandbox. The activity is linked by tactics and infrastructure patterns to an initial access broker associated with the Payouts Kings ransomware operation.
Why it matters: This matters because it turns a browser extension into a bridge for full system compromise, not just in-browser abuse, and it is being used in real ransomware-linked intrusions. Organizations should warn users about fake IT support messages, restrict extension installs, and monitor or lock down Native Messaging host configurations on managed endpoints.
Sources
Bill Toulas 2026.06.24 100%
This article establishes a distinct new story because it introduces the Edgecution malware campaign, its Edge Native Messaging technique, and its reported link to a Payouts Kings-associated initial access broker rather than updating a previously tracked event.
Full page
Operation Endgame removes SocGholish malware from nearly 15,000 WordPress sites and seizes 106 servers tied to Evil Corp
Threat Actors & APTsMalwareTechnology & SoftwareConsumers & General PublicRetail & E-CommerceWordPressEuropolEurojustFBIDutch National High Tech Crime UnitMicrosoft
Police in Europe and North America removed SocGholish malware from nearly 15,000 hacked WordPress websites and took more than 100 related servers and domains offline. Authorities in the Netherlands, Canada, the United States, and Germany said the action targeted the SocGholish botnet, also known as FakeUpdates or GhoLoader, which infects visitors through fake browser-update prompts on compromised sites. Europol and Eurojust said the operation was part of Operation Endgame and disrupted infrastructure linked to the Evil Corp cybercrime group.
Why it matters: This cuts off a long-running malware infection path that has been used to infect everyday web visitors and deliver other crimeware and ransomware. WordPress site owners should check for compromise, rotate credentials, enable multi-factor authentication, and remove unknown accounts; users should avoid software update prompts shown on random websites.
Sources
2026.06.24 92%
This source also updates the SocGholish/Operation Endgame action, specifying that the broader operation targeted SocGholish alongside Amadey and StealC and noting 14,971 infected websites plus Europol's attribution of SocGholish to Evil Corp-linked criminal activity.
Lawrence Abrams 2026.06.24 86%
This is another Operation Endgame action and adds that the same coordinated campaign disrupted Amadey and StealC infrastructure, affecting 326 servers and 142 domains, recovering 27 million stolen credentials, and again targeting SocGholish/FakeUpdates as part of the broader takedown.
info@thehackernews.com (The Hacker News) 2026.06.19 99%
This is the same Operation Endgame action against SocGholish infrastructure and infected WordPress sites, adding the specific cleaned-site count of 14,971 and reinforcing the server disruption details.
2026.06.19 98%
This article reports the same Operation Endgame takedown of the SocGholish/FakeUpdates infrastructure, adding details on participating countries, domain and server seizures, cleanup of infected WordPress sites, and the malware's use as an access path for ransomware groups including DoppelPaymer, WastedLocker, Hades, LockBit, and RansomHub.
Ionut Arghire 2026.06.19 99%
This article reports the same Operation Endgame event and adds concrete details on SocGholish's role as a JavaScript loader, the count of 14,971 cleaned WordPress sites, 106 seized C2 servers and domains, links to TA569/DEV-0206 and Evil Corp, and examples of follow-on payloads including LockBit, RansomHub, AsyncRAT, and NetSupport RAT.
Sergiu Gatlan 2026.06.18 100%
This article establishes a distinct new story about the June 2026 Operation Endgame action specifically targeting SocGholish-infected WordPress sites and related infrastructure tied to Evil Corp.
Full page
Microsoft, Europol and partners disrupt shared Amadey and StealC malware infrastructure in Operation Endgame
Threat Actors & APTsMalwareConsumers & General PublicTechnology & SoftwareMicrosoftEuropol
Microsoft, Europol, and industry partners said they disrupted hundreds of domains and command-and-control servers used by the Amadey loader and StealC infostealer malware families. The action was part of Operation Endgame and targeted shared infrastructure identified through analysis of both malware families; authorities said they seized more than 25 million stolen credentials from over 385,000 systems, identified 18,000 compromised computers, and also used a vulnerability in the StealC control panel to support the takedown.
Why it matters: This matters because Amadey and StealC are widely used to break into computers and steal passwords, cookies, and crypto-wallet data at scale. Organizations should hunt for signs of these malware families, rotate exposed credentials, and check endpoints for infostealer or loader infections if they may have been affected.
Sources
2026.06.24 98%
This article covers the same takedown event and adds concrete scope details: 326 servers and 142 domains dismantled, €41 million in suspected criminal crypto assets identified, 27 million stolen credentials reclaimed, and Microsoft's statement that AI analysis linked Amadey and StealC to shared infrastructure.
2026.06.24 97%
This article is a direct update on the same takedown, adding that Microsoft used Copilot and other AI tools to connect StealC and Amadey through shared infrastructure, enabling a RICO-based racketeering suit against five defendants. It also reiterates the scale of the disruption: 200+ domains/C2 servers, about 27 million recovered stolen credentials, and more than $47 million in flagged or restricted crypto assets when combined with the related SocGholish action.
info@thehackernews.com (The Hacker News) 2026.06.24 98%
This is the same Operation Endgame event targeting the shared Amadey and StealC malware network, adding reporting that 27 million stolen credentials were recovered and reinforcing the scope and impact of the disruption.
Eduard Kovacs 2026.06.24 100%
This article establishes a distinct law-enforcement and industry takedown of the shared infrastructure behind the Amadey and StealC malware ecosystem, separate from previously tracked Operation Endgame actions against SocGholish.
Full page
EFF says some police agencies use Flock Safety license-plate readers to alert on ICE 'Immigration Violator' hotlist entries
Surveillance & PrivacyPolicy & RegulationGovernmentConsumers & General PublicFlock SafetyICEFBIBlue Island Police DepartmentSparks Police Department
EFF says some local police departments using Flock Safety automated license plate readers are subscribed to an NCIC 'Immigration Violator' hotlist populated exclusively by ICE, so officers can be alerted when cameras spot vehicles tied to immigration records. Based on public-records responses, EFF identified at least Blue Island Police Department and Sparks Police Department as having the hotlist enabled, while other agencies used NCIC hotlists but had that specific topic disabled; the report highlights possible conflicts with local laws or agency policies that bar immigration-enforcement use.
Why it matters: This matters to immigrants, drivers, and local communities because routine traffic surveillance may be feeding immigration enforcement even where local rules appear to forbid it. Agencies using Flock should review which NCIC topics are enabled, and the public can use records requests and contract reviews to verify how ALPR systems are being used.
Sources
Dave Maass 2026.06.24 100%
This article establishes a distinct story by documenting a specific ALPR surveillance use case—ICE-linked immigration hotlist matching in Flock Safety systems—and naming agencies found to have it enabled.
Full page
Section 702 FISA surveillance authority is set to lapse after Congress fails to renew it
Surveillance & PrivacyPolicy & RegulationGovernmentTelecommunicationsNSACongressFBIFHFAFannie MaeFreddie Mac
A major U.S. foreign-surveillance program is poised to expire after Congress and the White House failed to agree on an extension before the deadline. Section 702 of the Foreign Intelligence Surveillance Act lets U.S. intelligence agencies collect, without a warrant, communications of foreigners overseas from service providers; existing court-approved orders may continue for now, but no new orders could be sought during a lapse, and provider compliance could become legally contested.
Why it matters: This matters for both privacy and national security: it could temporarily curb a powerful surveillance authority while creating uncertainty for telecom and internet providers asked to assist. Organizations tracking surveillance policy, lawful-access obligations, and civil-liberties risk should watch whether courts, Congress, or providers change how 702 orders are handled in the coming days.
Sources
Christian Romero 2026.06.24 94%
This source confirms that Section 702 has now actually lapsed and frames it as a privacy-policy development, adding follow-up context on the expiration's significance for warrantless domestic surveillance.
India McKinney 2026.06.12 96%
This article confirms that the anticipated lapse has now happened: Section 702 expired at the June 12, 2026 deadline, and adds context on the congressional impasse and civil-liberties push for a warrant requirement on FBI queries of Americans' communications.
2026.06.12 100%
This article establishes a new tracked story because it centers on the imminent lapse of Section 702 itself, a distinct surveillance-policy event not represented in the existing story list.
Full page
Chained UniFi OS Server flaws CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 can give attackers root access without logging in
Urgent PatchesZero-Days & CVEsTechnology & SoftwareConsumers & General PublicTelecommunicationsUbiquitiCISA
Researchers say attackers can take over vulnerable UniFi OS Server systems without a password and gain full root control. Bishop Fox showed that three patched bugs in UniFi OS Server 5.0.6 and earlier—CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910—can be chained from the network to bypass authentication, read files, and trigger command injection, leading to remote code execution and trivial privilege escalation via passwordless sudo.
Why it matters: UniFi OS Server can manage core business systems such as networking, cameras, and door access, so compromise can hand attackers broad control of an organization’s environment. Organizations using affected versions should patch immediately and check for suspicious requests to the noted endpoints, because the attack leaves little or no login evidence.
Sources
Bill Toulas 2026.06.24 95%
This updates the same UniFi OS vulnerability chain by adding that CISA has now placed CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 in the Known Exploited Vulnerabilities catalog based on active exploitation, and that federal agencies have three days to patch or mitigate.
Ionut Arghire 2026.06.24 95%
This article updates the same Ubiquiti UniFi OS vulnerability chain with concrete evidence of in-the-wild exploitation, reports of rogue 'John Sim' administrator accounts, and the key new development that CISA added all three CVEs to the KEV catalog with a three-day federal patch deadline.
Bill Toulas 2026.06.08 100%
This article establishes a distinct story by surfacing a newly detailed exploit chain and defender guidance for three UniFi OS Server CVEs that together enable unauthenticated root-level remote code execution.
Full page
Kandji patches CVE-2026-39118 after researchers show macOS trust-cache and XPC chain can disable EDR and MDM agents
Zero-Days & CVEsUrgent PatchesSurveillance & PrivacyTechnology & SoftwareConsumers & General PublicAppleKandjiCrowdStrike
Researchers showed that a normal non-admin macOS user can silently turn off some enterprise security tools, including endpoint detection and response (EDR) and mobile device management (MDM) agents. XM Cyber said the attack chains weakly validated XPC service connections, malicious changes to Interface Builder NIB files, and persistence in macOS's code-signing trust cache after a signed app runs; it demonstrated the technique against CrowdStrike Falcon Sensor and Kandji, and Kandji assigned CVE-2026-39118 and patched its product.
Why it matters: Organizations using macOS fleets could lose key security monitoring and management controls without obvious alerts, even from a standard user account. Defenders should review Kandji fixes, validate CrowdStrike detections, and assess exposed XPC privilege paths on managed Macs now.
Sources
Eduard Kovacs 2026.06.24 100%
This article appears to be the first tracked report establishing the specific macOS attack chain, its impact on CrowdStrike Falcon and Kandji, and Kandji's assignment of CVE-2026-39118.
Full page
Bajaj Auto says ransomware attack hit company operations and its technology subsidiary
RansomwareManufacturingBajaj AutoBajaj Auto Technology
Indian vehicle maker Bajaj Auto disclosed that a ransomware attack hit its operations and also affected Bajaj Auto Technology Limited. In a regulatory filing, the company said it detected the incident on June 24, 2026, took containment steps, and brought in cybersecurity experts; it has not yet named the threat actor, said whether data was stolen, or disclosed any ransom demand.
Why it matters: This is a live disruption at one of India’s largest manufacturers, so suppliers, employees, and customers may face operational delays while the scope is still unclear. Manufacturers and partners should watch for follow-up notices, be alert for extortion or phishing tied to the incident, and review exposure if they connect systems or data with Bajaj Auto.
Sources
2026.06.24 100%
This article is the initial disclosure of the ransomware incident affecting Bajaj Auto and its subsidiary, with no existing tracked story for the same event.
Full page
London Metropolitan Police will expand live facial recognition cameras into the West End and Soho
Surveillance & PrivacyPolicy & RegulationGovernmentConsumers & General PublicMetropolitan PoliceThames Valley Police
London’s Metropolitan Police said it will begin using static live facial recognition cameras in the West End and Soho by the end of 2026, extending a six-month pilot in Croydon. The system places cameras on street infrastructure, compares passersby against short-lived police watchlists created up to 24 hours in advance, and sends officers to stop people flagged as matches. The force said 24 Croydon deployments scanned more than 470,000 people, led to 173 arrests, and produced one false alert.
Why it matters: This expands biometric surveillance in a major public area without new legislation specifically governing it, affecting residents, workers, and tourists. It matters for privacy and civil-liberties watchdogs, policymakers, and the public because it signals broader routine police use of face-scanning technology in public spaces.
Sources
2026.06.24 100%
The article establishes a distinct new policy and deployment milestone: the Met’s move from pilot use of live facial recognition to planned static deployments in central London public spaces.
Full page
Novee says GitHub Actions workflow flaws in major open-source projects could let attackers hijack repositories and software releases
Supply ChainTechnology & SoftwareConsumers & General PublicMicrosoftGoogleApacheCloudflarePython Software Foundation
Novee says insecure CI/CD workflows in widely used open-source repositories could let unauthenticated attackers take over projects and poison downstream software releases. The researchers call the issue class "Cordyceps" and say vulnerable GitHub Actions YAML workflows let untrusted pull requests or comments trigger low-privilege jobs that flow into high-privilege jobs, enabling command injection, forged approvals, malicious code pushes, artifact poisoning, and cloud credential theft. Confirmed affected repositories include projects from Microsoft, Google, Apache, Cloudflare, and the Python Software Foundation.
Why it matters: This matters because one weak workflow in a popular project can spread malicious code or stolen credentials far beyond the original repository, affecting developers, companies, and end users. Maintainers should urgently review GitHub Actions and other CI/CD workflows for unsafe trust boundaries, especially where pull requests, comments, signing keys, cloud credentials, or release publishing are involved.
Sources
Ionut Arghire 2026.06.24 100%
This article establishes a distinct new story about a newly named class of CI/CD workflow vulnerabilities affecting major open-source repositories and the broader software supply chain, not a follow-up to a previously tracked incident.
Full page
DOJ seizes cloud infrastructure allegedly used by Cambodia's Huione Group to support online scams and money laundering
Policy & RegulationScams & FraudConsumers & General PublicCryptocurrency & BlockchainDOJFBIFinCENHuione GroupTelegramHuione Cloud
The U.S. government says it seized a cloud computing account used by subsidiaries of Cambodia-based Huione Group to run backend systems for cyber-enabled scam operations. DOJ said the infrastructure supported Telegram channels advertising stolen credit-card and identity data, malware-theft proceeds, human-trafficking procurement, and laundering help for romance and investment scams. The action follows earlier U.S. financial restrictions after FinCEN alleged Huione laundered at least $4 billion in illicit funds from 2021 to 2025, including proceeds tied to North Korean cyber theft.
Why it matters: This is a significant disruption of infrastructure tied to industrialized scam networks that victimize consumers and help move criminal proceeds across borders. It matters to the public because these operations power romance and investment fraud at scale, and to defenders because it shows the specific platforms and laundering ecosystem authorities are targeting.
Sources
info@thehackernews.com (The Hacker News) 2026.06.24 98%
The article appears to report the same Justice Department seizure of a Huione Cloud account tied to scam and laundering operations, adding another source on the same enforcement action rather than a distinct event.
2026.06.23 100%
This article establishes a distinct enforcement story centered on the U.S. seizure of cloud infrastructure allegedly used by Huione Group subsidiaries, rather than a previously tracked advisory, scam-loss report, or separate account-disruption action.
Full page
Xsolis says phishing-linked breach exposed health and personal data of 1.4 million people
Breaches & Data LeaksSocial Engineering & PhishingHealthcareTechnology & SoftwareInsuranceXsolisHHS
Healthcare technology company Xsolis disclosed a data breach affecting 1,396,519 individuals whose information it received from hospitals, health systems, and payers. Xsolis said attackers gained access after a targeted phishing attack on January 20, 2026, with unauthorized activity detected on January 22. Exposed data includes names, dates of birth, addresses, Social Security numbers, health insurance details, and medical treatment information, according to the company and the U.S. Department of Health and Human Services breach tracker.
Why it matters: This is a large-scale exposure of sensitive medical and identity data, creating long-term risks of identity theft, insurance fraud, and targeted scams for affected people. Healthcare organizations and partners using Xsolis should review third-party access and phishing defenses, while affected individuals should watch for breach notices, fraud, and medical-identity misuse.
Sources
Bill Toulas 2026.06.23 99%
This article is the same underlying breach event and adds detail on the January 20 phishing attack, January 22 detection, the exposed data elements, password resets, and mitigation steps described in Xsolis' notices.
Eduard Kovacs 2026.06.23 100%
This article appears to be the first concrete report in this set establishing Xsolis as the breached organization, the phishing intrusion timeline, and the confirmed scope of 1.4 million affected individuals.
Full page
ClickFix campaign targets macOS users with Atomic macOS Stealer through silent DMG mounting
MalwareSocial Engineering & PhishingScams & FraudConsumers & General PublicCryptocurrency & BlockchainAppleGoogleMicrosoftDiscordLedgerTrezor
A new scam-style malware campaign is tricking Mac users into pasting a Terminal command that silently installs a password and crypto-stealing program. Palo Alto Networks says the ClickFix attack uses a fake CAPTCHA to get victims to run a command that downloads a malicious DMG disk image, mounts it with macOS hdiutil without showing it in Finder, and launches Atomic macOS Stealer (AMOS). The malware steals browser credentials, cookies, Keychain data, Telegram and Discord data, documents, and cryptocurrency wallet information, and can replace Ledger Live and Trezor Suite with trojanized versions.
Why it matters: This can lead directly to stolen passwords, drained crypto wallets, and account takeover for Mac users who follow the fake verification prompt. Users should never paste commands into Terminal from websites, and organizations should warn users about ClickFix lures and watch for AMOS-related activity.
Sources
Lawrence Abrams 2026.06.23 100%
This article establishes a distinct macOS-focused ClickFix campaign using silent DMG mounting to deliver Atomic macOS Stealer, with concrete delivery mechanics and theft targets.
Full page
Trump executive order sets 2030 and 2031 deadlines for U.S. federal post-quantum cryptography migration
Policy & RegulationGovernmentWhite HouseNISTCISANSADHSDepartment of Commerce
President Trump signed an executive order requiring U.S. federal agencies to start moving sensitive systems to quantum-resistant encryption before current cryptography can be broken by future quantum computers. The order directs OMB, NIST, NSA, DHS, and CISA to issue migration guidance; agencies must inventory high-value assets and high-impact systems, use post-quantum cryptography for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. Federal contractors must also comply with NIST post-quantum standards by the end of 2030.
Why it matters: This matters because it turns a long-term cryptography risk into a concrete compliance deadline for government systems and companies that serve them. Federal agencies and contractors need to begin crypto inventories and migration planning now or risk scrambling to replace vulnerable encryption later.
Sources
2026.06.23 99%
This article reports the same executive order and adds details that Commerce, NSA, and DHS must issue practical migration guidance, agencies must appoint transition leads, and Commerce must launch a pilot program by the end of 2027.
Eduard Kovacs 2026.06.23 100%
This article establishes a distinct policy story: a new executive order that formally accelerates federal post-quantum cryptography migration and sets specific deadlines.
Full page
Dify patches four CVEs that could expose private chats and files across tenants in its AI app platform
Zero-Days & CVEsUrgent PatchesSurveillance & PrivacyTechnology & SoftwareConsumers & General PublicDify
Dify fixed four security flaws that could let attackers on shared cloud instances read other customers’ AI chats, preview uploaded documents, and reach internal APIs. The issues are CVE-2026-41947, CVE-2026-41948, CVE-2026-41949, and CVE-2026-41950, affecting multi-tenant Dify deployments; Zafran said a low-bar console account could abuse tracing and plugin-daemon features for cross-tenant access, and Dify released fixes in version 1.14.2. The report also notes Dify used a PDFium build vulnerable to CVE-2024-5846 until December 21, 2025.
Why it matters: Organizations using Dify, especially in shared cloud setups, may have exposed private prompts, responses, and uploaded files to other users. Admins should update to Dify 1.14.2 immediately and apply any recommended web application firewall rules for CVE-2026-41948.
Sources
Ionut Arghire 2026.06.23 100%
This article appears to be the first tracked report establishing the DifyTap vulnerability cluster as a distinct event, with named CVEs, attack paths, and the vendor's fixed version.
Full page
Samsung fixed Galaxy KNOX kernel flaw CVE-2026-20971 that exposed devices from the S9 through S25 to local kernel attacks
Zero-Days & CVEsUrgent PatchesSurveillance & PrivacyConsumers & General PublicTechnology & SoftwareSamsung
Samsung patched a high-severity flaw in its KNOX security framework that affected a wide range of Galaxy phones and tablets, including models from the Galaxy S9 through S25. The bug, CVE-2026-20971, was an eight-year-old use-after-free vulnerability in the interaction between the PROCA process authenticator and FIVE kernel integrity system. Researchers said an untrusted app could trigger kernel memory corruption on Android 13, 14, 15, and 16; Samsung fixed it in the January 2026 security release.
Why it matters: This matters because the flaw sat in Samsung’s device-security layer for years across many generations of phones, creating a potential path to deeper device compromise if attackers could get code onto a target device. Samsung users and enterprise mobile admins should make sure affected Galaxy devices have the January 2026 update or later installed.
Sources
Kevin Townsend 2026.06.23 100%
This article establishes a distinct story about CVE-2026-20971 in Samsung KNOX, including the root cause, affected Galaxy generations, and confirmation that Samsung shipped a fix in January 2026.
Full page
U.S. extradites alleged Market0Day and Spoxy operator over phishing-kit and smishing marketplace scheme
Social Engineering & PhishingScams & FraudFinance & BankingConsumers & General PublicDOJJPMorgan ChaseBank of AmericaWells FargoAmerican Express
A 26-year-old Algerian man was extradited to the United States after prosecutors accused him of running two cybercrime marketplaces that sold phishing tools and mass-texting services. The Justice Department says Abdellah Belmili, also known as Spox, administered Market0Day in 2020 and later launched Spoxy, where criminals could buy phishing kits, access to compromised email servers, and bulk SMS services for large-scale smishing campaigns. Prosecutors say the scheme targeted major banks including JPMorgan Chase, Bank of America, Wells Fargo, and American Express, involved about 5,600 victims, and brought roughly $900,000 into an account he controlled between 2020 and 2023.
Why it matters: This matters because it shows the infrastructure behind phishing and bank-fraud campaigns, not just individual scams, and names the services used to enable them. Financial institutions and consumers should stay alert for bank-themed phishing emails and text messages, while defenders can use the marketplace names and actor alias to support threat tracking and fraud investigations.
Sources
Eduard Kovacs 2026.06.23 100%
This article establishes a distinct story: the extradition and U.S. prosecution of the alleged administrator of the Market0Day and Spoxy cybercrime marketplaces.
Full page
FFmpeg fixes PixelSmash flaw CVE-2026-8461 that can crash apps and enable code execution in Jellyfin under some conditions
Urgent PatchesZero-Days & CVEsTechnology & SoftwareConsumers & General PublicMedia & EntertainmentFFmpegJellyfinNextcloudKodiEmbyPhotoPrismOBS Studio
FFmpeg fixed a newly disclosed bug that can crash or potentially compromise apps and servers that process malicious video files. The flaw, CVE-2026-8461, is a heap out-of-bounds write in FFmpeg's MagicYUV decoder affecting libavcodec users; JFrog showed remote code execution on Jellyfin 10.11.9 and Nextcloud setups with movie previews enabled, while other apps including Kodi, Emby, PhotoPrism, OBS Studio, and desktop thumbnailers may be vulnerable to denial of service. FFmpeg 8.1.2 contains the fix.
Why it matters: Organizations and self-hosting users that automatically scan or preview uploaded media should treat this as urgent because a booby-trapped video can trigger processing without being played. Update FFmpeg and any bundled copies in products like Jellyfin, and review whether automated media preview or ingestion workflows expose internet-facing systems.
Sources
Ionut Arghire 2026.06.23 97%
This article is a fuller write-up of the same PixelSmash event, adding exploitation details, affected application examples such as Kodi, mpv, Jellyfin, Emby, Nextcloud, Immich, PhotoPrism, and OBS Studio, and clarifying near-zero-click and zero-click delivery paths through thumbnailing, media scanning, and upload processing.
Bill Toulas 2026.06.22 100%
This article appears to be the first tracked item establishing the PixelSmash / CVE-2026-8461 event: a newly disclosed FFmpeg decoder flaw, proof-of-concept impact on major downstream apps, and release of the upstream fix.
Full page
London Hydro says customer data may have been exposed in a security incident
Breaches & Data LeaksEnergy & UtilitiesConsumers & General PublicLondon Hydro
London Hydro says a security incident may have exposed customer account information for some electricity users in and around London, Ontario. The utility said affected data can include names, addresses, email addresses, phone numbers, account and billing numbers, service addresses, pricing plans, contract start dates, and meter information. It has not yet disclosed the attack method, whether data was stolen or only accessed, how many customers were affected, whether ransomware or a third party was involved, or whether operational grid systems were touched.
Why it matters: Customers could face convincing phishing, billing fraud, or impersonation scams using real account details, even if payment-card and banking data were not involved. Affected users should watch for suspicious utility messages and account changes, while defenders should seek more detail on scope, intrusion path, and any impact on utility operations.
Sources
Ionut Arghire 2026.06.23 96%
This source confirms the incident as a data breach caused by hackers and adds specific categories of potentially stolen data, including names, addresses, contact details, billing numbers, service addresses, pricing plans, contract dates, and meter information, while noting no financial or payment data is believed affected.
2026.06.22 100%
This article appears to be the first tracked report of London Hydro's disclosed customer-data breach and establishes the core facts of the incident.
Full page
WhatsApp malware campaign uses compromised accounts and fake business documents to install remote access on Windows PCs
Social Engineering & PhishingMalwareConsumers & General PublicWhatsAppManageEngine
Attackers are using hijacked WhatsApp accounts to send fake business and financial documents that infect Windows computers when opened. Kaspersky says the campaign delivers heavily obfuscated VBScript files through WhatsApp, then downloads additional scripts that modify User Account Control settings in the Windows Registry and silently installs ManageEngine Endpoint Central configured to connect to attacker-controlled servers. Victims have been seen in Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, Australia, Russia, Vietnam, and Malaysia.
Why it matters: People can be infected by files that appear to come from trusted contacts, turning a chat message into full remote access on their PC. Users should avoid opening script attachments from WhatsApp and verify unexpected files out-of-band; defenders should look for suspicious wscript.exe activity and unauthorized ManageEngine Endpoint Central installs.
Sources
Bill Toulas 2026.06.22 100%
This article establishes a distinct ongoing malware campaign centered on compromised WhatsApp accounts, localized fake document lures, and abuse of ManageEngine Endpoint Central for attacker remote access.
Full page
JaredFromSubway Ethereum MEV bot lost $15 million after attacker used fake trading pools and token approvals
Breaches & Data LeaksScams & FraudCryptocurrency & BlockchainCryptocurrency & BlockchainJaredFromSubway
The JaredFromSubway Ethereum trading bot lost about $15 million after an attacker tricked it into approving malicious contracts and then drained its funds. According to Blockaid and JaredFromSubway, the attacker created fake MEV (maximal extractable value) opportunities using bogus pools and tokens so the bot would grant ERC-20 spending approvals to attacker-controlled helper contracts; the attacker later used those lingering approvals and the transferFrom function to withdraw WETH, USDC, and USDT.
Why it matters: This is a major crypto theft that shows how automated on-chain trading systems can be manipulated even without directly breaking a blockchain. Crypto firms, bot operators, and smart-contract developers should review approval logic, route validation, and allowance revocation controls immediately.
Sources
Bill Toulas 2026.06.22 100%
This article appears to be the first item here establishing the specific $15 million theft from the JaredFromSubway MEV bot through fake pool and token manipulation.
Full page
ShapedPlugin supply-chain attack used official WordPress plugin updates to install backdoors on customer sites
Supply ChainBreaches & Data LeaksMalwareTechnology & SoftwareRetail & E-CommerceConsumers & General PublicShapedPluginWordPressWooCommerce
ShapedPlugin’s official update system was compromised and pushed malware-tainted WordPress plugin updates to paying customers, putting affected websites at risk of credential theft and remote tampering. WordPress is tracking the incident as CVE-2026-10735. Affected paid plugins were Product Slider Pro before 3.5.4 for WooCommerce, Real Testimonials Pro 3.2.5, and Smart Post Show Pro before 4.0.2; Wordfence says the malicious code acted as a loader that fetched a second-stage backdoor, hid it as fake WooCommerce plugins, and stole admin logins, two-factor authentication secrets, database credentials, and recent WooCommerce order data.
Why it matters: Website owners who installed these paid plugin updates may have had their WordPress and store credentials stolen and their sites quietly backdoored. Affected admins should update immediately, look for the fake WooCommerce plugins, rotate passwords and keys, and review their sites for unauthorized changes.
Sources
info@thehackernews.com (The Hacker News) 2026.06.22 99%
The article covers the same underlying event: ShapedPlugin's official update channel for paid WordPress plugins was compromised and delivered backdoored updates to customer sites.
Bill Toulas 2026.06.18 100%
This article establishes a distinct new supply-chain incident centered on ShapedPlugin’s compromised release infrastructure and malware delivered through official paid plugin updates.
Full page
Microsoft fixes AutoGen Studio flaw that could let a malicious webpage run commands on a developer’s machine
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareMicrosoft
Microsoft fixed a vulnerability chain in AutoGen Studio that could let a malicious webpage trick an AI agent into running commands on the computer hosting the tool. The issue, dubbed AutoJack, affected AutoGen Studio builds made directly from the GitHub main branch before hardening commit b047730; Microsoft said it never shipped in a PyPI release. The chain involved unauthenticated MCP WebSocket access, localhost trust bypass, and attacker-controlled server_params that could launch PowerShell, Bash, or other executables.
Why it matters: Developers experimenting with AI agents could have exposed their own workstation to remote command execution just by having a browsing-capable agent visit hostile content. Anyone who built AutoGen Studio from GitHub during the affected window should update and run it only in an isolated, low-privilege environment.
Sources
Bill Toulas 2026.06.22 100%
This article establishes a distinct vulnerability-and-fix event in Microsoft AutoGen Studio, with concrete technical details, affected scope, and remediation guidance not covered by an existing tracked story.
Full page
Brazil investigates suspected hack of national emergency alert system after rogue warning hit phones nationwide
Breaches & Data LeaksGovernmentGovernmentTelecommunicationsConsumers & General PublicSEDECFederal PoliceAnatelDefesa Civil NacionalBrazil Ministry of Integration and Regional DevelopmentBrazil Federal PoliceBrazil National Protection and Civil Defense Secretariat
Brazil says an unauthorized emergency alert was sent to mobile phones across multiple states and the federal district, prompting an investigation into its public warning system. The bogus 'extreme' alert, containing the word 'misanthropy,' was reportedly issued through the Defesa Civil Alerta dispatch platform used for severe-weather and disaster warnings. SEDEC, Federal Police, and Anatel are investigating, and the platform was taken offline after the suspected intrusion.
Why it matters: A compromised emergency warning system can cause public panic and undermine trust in life-safety alerts people rely on during real disasters. Mobile users in Brazil should verify unusual emergency messages with official channels, while public-sector operators should review access controls, monitoring, and recovery plans for alerting infrastructure.
Sources
2026.06.22 96%
This is the same underlying event and adds specific details including the number of unauthorized alerts sent, the affected regions, use of both cell broadcast and SMS, suspension of the system, blocking of the Public Alert Dissemination Interface, and confirmation of a Federal Police investigation.
2026.06.22 100%
This article appears to be the first tracked report of the nationwide rogue alert event and establishes the core facts: the affected platform, public impact, and official investigation.
Full page
Hackers exploit Gravity SMTP WordPress plugin flaw CVE-2026-4020 to expose API keys and email credentials
Zero-Days & CVEsTechnology & SoftwareConsumers & General PublicWordPressGravity SMTP
Hackers are actively exploiting a flaw in the Gravity SMTP WordPress plugin that can expose sensitive data from affected websites. The bug, CVE-2026-4020, affects Gravity SMTP 2.1.4 and earlier and was fixed in 2.1.5 on March 17. An unauthenticated REST API endpoint can return a JSON system report containing API keys, OAuth tokens, third-party email service credentials, WordPress configuration details, and server and database information. Wordfence says it blocked more than 17 million exploit attempts, with activity spiking on June 7.
Why it matters: Site owners can have email-service secrets and internal configuration exposed without an attacker needing to log in, which can enable account abuse and follow-on compromise. Organizations using Gravity SMTP should update to 2.1.5 immediately and review logs for requests to /wp-json/gravitysmtp/v1/tests/mock-data.
Sources
Ionut Arghire 2026.06.22 96%
This source directly updates the same event by adding that exploitation has surged in June, Defiant has blocked more than 17 million exploit attempts, and exposed data can include API keys, secrets, OAuth tokens, server details, and WordPress configuration data from Gravity SMTP versions before 2.1.5.
info@thehackernews.com (The Hacker News) 2026.06.20 99%
This article appears to cover the same underlying event: active exploitation of the Gravity SMTP WordPress plugin flaw that exposes API keys and email credentials on vulnerable sites.
Bill Toulas 2026.06.19 100%
This article establishes a distinct story about active exploitation of CVE-2026-4020 in the Gravity SMTP plugin, separate from other tracked WordPress plugin exploitation cases.
Full page
Microsoft says North Korea's Sapphire Sleet was behind the Mastra AI npm supply-chain attack affecting 140+ packages
Supply ChainThreat Actors & APTsMalwareTechnology & SoftwareCryptocurrency & BlockchainMicrosoftMastra AInpmMastra
Microsoft says a North Korean hacking group compromised the Mastra AI software supply chain by hijacking an npm maintainer account and pushing malicious updates to more than 140 packages. The attacker used the compromised account "ehindero" to add a typosquatted dependency, "easy-day-js," to packages in the @mastra scope; its post-install script dropped cross-platform malware for Windows, macOS, and Linux that stole credentials, API keys, authentication tokens, browser data, and cryptocurrency-wallet information, and established persistence on infected systems.
Why it matters: Developers and organizations that installed affected Mastra packages could have had secrets and crypto-wallet data stolen from their machines. This is urgent for software teams: identify any use of affected @mastra packages, remove malicious versions, rotate exposed credentials and tokens, and investigate systems that contacted the attackers' command-and-control servers.
Sources
Ionut Arghire 2026.06.22 98%
This article covers the same Mastra npm supply-chain compromise and adds concrete details on the June 17 attack window, the compromised 'ehindero' maintainer account, the typosquatted easy-day-js dependency, cross-platform postinstall payload behavior, and crypto-extension targeting.
Lawrence Abrams 2026.06.20 100%
This article establishes a distinct tracked story by adding high-confidence attribution of the Mastra AI npm compromise to Sapphire Sleet and detailing the attack chain, malware capabilities, and follow-on activity.
Full page
Researchers release unpatchable BootROM exploit for Apple A12 and A13 iPhones
Zero-Days & CVEsConsumers & General PublicTechnology & SoftwareAppleSynopsys
Researchers disclosed a hardware-level exploit that can break the secure boot process on older iPhones using Apple A12 and A13 chips. The exploit, called usbliter8, affects SecureROM (the BootROM code burned into the device) on iPhone XS, XR, 11, and 11 Pro models and other A12/A13 devices. It abuses a flaw in the Synopsys DesignWare USB controller during Device Firmware Update (DFU) mode to corrupt memory and run unsigned code; no CVE was cited, and exploitation requires physical access and DFU mode.
Why it matters: Owners of affected devices will not get a software fix because the bug is in chip-level code, so these phones remain vulnerable for life. The risk is mainly to people facing physical-device seizure or forensic access rather than mass remote attacks, and the practical mitigation is to replace affected hardware if this threat model matters.
Sources
Eduard Kovacs 2026.06.22 98%
This article adds mainstream reporting details on the same Usbliter8 disclosure, including affected iPhone XS/XR/11 and Apple Watch S4/S5 models, the physical USB attack requirement, and the researchers' note that the exploit bypasses SecureROM signature checks but does not directly compromise the Secure Enclave Processor.
info@thehackernews.com (The Hacker News) 2026.06.19 97%
This article appears to describe the same underlying event: disclosure of the unpatchable 'usbliter8' BootROM/SecureROM exploit affecting Apple A12 and A13 devices, adding another report and framing it as a break of the SecureROM boot chain.
2026.06.19 100%
This article appears to be the initial reporting of a newly disclosed BootROM exploit for Apple A12 and A13 devices, and it does not match any existing tracked story about this same underlying event.
Full page
Gizmodo site compromise served ClickFix malware prompts to readers through a hijacked account
MalwareSocial Engineering & PhishingMedia & EntertainmentConsumers & General PublicGizmodo
Gizmodo readers were briefly exposed to fake verification prompts on the news site after a compromised account was used to inject malicious code into article pages. The attack delivered ClickFix social-engineering lures that tried to make users run commands locally; according to reporting and researcher analysis, the Windows flow attempted to install NetSupport RAT, a remote-access trojan, while the macOS payload appeared misconfigured and did not execute cleanly.
Why it matters: Anyone who followed the prompt on a Windows device may have installed remote-access malware that can steal files or pull down more malicious tools. Affected users should check for suspicious commands or downloads, run endpoint scans, and site operators should review account security and script-injection controls.
Sources
2026.06.22 100%
This article establishes a distinct incident: a compromise of Gizmodo that was used to serve ClickFix malware lures to site visitors, rather than a generic report on the ClickFix technique.
Full page
Canada’s spy agency used a first-of-its-kind warrant to remove malware from botnet-infected devices
Surveillance & PrivacyPolicy & RegulationMalwareConsumers & General PublicCommunications Security Establishment
Canada’s signals intelligence agency reportedly got court approval to access and clean malware from devices infected by a botnet, marking a new kind of government cyber operation affecting victims inside Canada. The report centers on the Communications Security Establishment using a warrant to disrupt infections on victim systems rather than only monitor or seize infrastructure, raising questions about legal authority, oversight, and how defensive government hacking will be used in future botnet takedowns.
Why it matters: This matters because it could set a precedent for governments remotely accessing privately owned devices in the name of cyber defense. People and organizations in Canada should watch for official guidance on whether their systems were affected and what safeguards, notification, and oversight rules apply.
Sources
info@thehackernews.com (The Hacker News) 2026.06.22 100%
This article establishes a distinct story about Canada using a novel legal authority for active cyber defense on victim devices, not a previously tracked breach, CVE, or takedown event.
Full page
AryStinger botnet hijacked more than 4,000 D-Link routers to act as attacker-controlled proxies
MalwareConsumers & General PublicTechnology & SoftwareTelecommunicationsD-Link
A newly documented botnet called AryStinger infected more than 4,000 older D-Link routers and turned them into systems that relay malicious traffic and help attackers scan and probe other networks. XLab said the malware targets end-of-life D-Link DIR-850L and DIR-818LW devices by exploiting older flaws including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837; researchers also found a Go-based variant aimed at network-attached storage systems. Infected devices can proxy traffic, tamper with Domain Name System settings, execute commands, and monitor network traffic.
Why it matters: People and organizations still using these unsupported routers may have their internet traffic monitored or redirected without noticing, and their devices can be used to help attack others. Replace end-of-life hardware, apply the latest firmware if any is available, change admin passwords, and disable remote management.
Sources
info@thehackernews.com (The Hacker News) 2026.06.22 99%
This is the same underlying event: AryStinger infecting roughly 4,300 legacy D-Link routers to build a proxy and reconnaissance network for malicious use.
Bill Toulas 2026.06.21 100%
This article appears to be the first concrete report establishing AryStinger as a distinct botnet campaign affecting thousands of D-Link routers worldwide.
Full page
Texas Parks and Wildlife says vendor breach exposed data of 3 million hunting and fishing license customers
Breaches & Data LeaksSupply ChainGovernmentConsumers & General PublicTexas Parks and Wildlife DepartmentTexas Cyber CommandTexas Parks and Wildlife
Texas Parks and Wildlife said attackers breached the vendor that handles state hunting and fishing license sales and stole data on about 3,087,721 Texans. Exposed information includes names, email addresses, phone numbers, home addresses, and possibly driver's license or passport numbers; a state filing also indicates Social Security numbers may have been involved, creating a conflict with the agency's public notice. The breach date is still unknown, and TPWD said it notified Texas Cyber Command on May 13.
Why it matters: This is a large identity-data breach tied to a government service used by millions of residents, so affected people may face phishing, fraud, or identity-theft risk. Texans who bought hunting or fishing licenses should watch for official notices, consider fraud monitoring, and be cautious of follow-up emails or calls referencing the incident.
Sources
Eduard Kovacs 2026.06.22 99%
This is the same underlying incident: TPWD disclosing that a breach at its third-party hunting and fishing license vendor exposed personal data for roughly 3 million customers, including contact details and government ID information.
Bill Toulas 2026.06.19 98%
This is the same underlying TPWD vendor-breach event and adds concrete detail that the exposed data included driver’s license numbers and passport numbers for 3,087,721 customers, while noting SSNs, dates of birth, and payment-card data were not affected.
2026.06.19 100%
This article appears to be the first tracked report establishing the underlying breach event: a third-party compromise affecting Texas Parks and Wildlife license customer data.
Full page
Prinz Eugen ransomware uses stolen RDP access and encrypts recently changed files first
RansomwareMalwareRemotePCStandard Bank
Researchers say a new ransomware group called Prinz Eugen is breaking into organizations and encrypting their newest or most recently changed files first to increase pressure to pay. ThreatDown says the operators appear to use stolen Remote Desktop Protocol (RDP) credentials, legitimate remote monitoring and management tools such as RemotePC, and hands-on-keyboard activity. The Go-based encryptor uses ChaCha20-Poly1305, appends a .prinzeugen extension, may delete originals after verifying decryption works, and currently shows at least several known victims, including a reported Standard Bank incident.
Why it matters: Organizations with exposed or weakly protected remote access are at risk, especially if attackers can reuse stolen credentials and blend in with legitimate admin tools. Defenders should review RDP exposure, audit remote-management tool use, hunt for the listed indicators of compromise, and watch for unusual admin account creation.
Sources
Bill Toulas 2026.06.20 100%
This article appears to be the first tracked item focused on the Prinz Eugen ransomware operation itself, including its access methods, malware design, and known victim details.
Full page
phpBB fixes decade-old authentication bypass that can let attackers log in as any forum user
Urgent PatchesZero-Days & CVEsTechnology & SoftwareConsumers & General PublicphpBB
phpBB has fixed a long-hidden security flaw that can let an attacker sign in as any user on affected forums, including administrators. The bug has no CVE yet and affects phpBB 3.3.16 and earlier plus 4.0.0-a2; phpBB says version 3.3.17 fixes the 3.x branch, while no safe 4.x release is available yet. Researchers said the issue is trivial to exploit with a single HTTP request in default configurations, though separate checks reportedly prevent direct remote code execution through the admin panel.
Why it matters: Forum operators should treat this as urgent because an attacker could impersonate staff, read private messages, and alter or delete content without needing special setup. Update phpBB 3.x to 3.3.17 immediately, and admins on 4.0.0-a2 should move to the patched master branch or apply vendor guidance as soon as possible.
Sources
SecurityWeek News 2026.06.19 93%
This article recaps the same phpBB flaw and adds actionable version detail: affected versions up to 3.3.16 and 4.0.0-a2, patched in 3.3.17, with unauthenticated impersonation possible via a single HTTP request.
Bill Toulas 2026.06.12 100%
This article establishes a new tracked story because it reports the discovery and vendor fix of a distinct phpBB authentication bypass affecting broad deployed versions, and it does not match any existing tracked event.
Full page
China-linked Velvet Ant hijacked Linux authentication and spied on an isolated critical infrastructure network for 10 years
MalwareThreat Actors & APTsCritical infrastructureEnergy & UtilitiesManufacturingGovernment
A China-linked hacking group secretly controlled a large organization's critical infrastructure network for a decade, even after the sensitive environment was separated from the internet. Sygnia attributes the campaign, called Operation Highland, to Velvet Ant, which first compromised internet-facing systems and then built an execution path into the isolated network by altering Nginx and FastCGI (a web-server request handler) configurations. The attackers used modified GS-Netcat and SOCKS5 tools for access and pivoting, then replaced Linux PAM authentication modules and OpenSSH components with trojanized versions to backdoor logins, steal credentials, and record administrator commands.
Why it matters: This is notable because it shows a sophisticated state-linked actor quietly maintaining access to critical systems for years by tampering with core login and remote-access components. Organizations running Linux in segmented or industrial environments should hunt for altered PAM, OpenSSH, Nginx, and startup-service files and review long-term credential exposure and administrative access.
Sources
SecurityWeek News 2026.06.19 75%
The article summarizes the same Velvet Ant intrusion, including long-term access since around 2016, use of backdoored PAM/OpenSSH, proxies, and credential theft in a segregated network.
Bill Toulas 2026.06.13 100%
This article establishes a distinct espionage story centered on Velvet Ant's newly detailed Operation Highland intrusion chain and decade-long persistence inside an isolated critical infrastructure environment; it is not the same underlying event as the existing tracked Velvet Ant-related items.
Full page
Awesome Motive CDN breach injected malware into OptinMonster, TrustPulse, and PushEngage WordPress plugins
MalwareSupply ChainTechnology & SoftwareRetail & E-CommerceConsumers & General PublicMedia & EntertainmentAwesome MotiveOptinMonsterTrustPulsePushEngageUpdraftPlusWordPress
Attackers compromised Awesome Motive's content delivery network and briefly pushed malicious code to websites using OptinMonster, TrustPulse, and PushEngage, putting those sites at risk of takeover. According to Awesome Motive and Sansec, the attackers first breached a marketing server by exploiting a known flaw in the UpdraftPlus WordPress plugin, stole a CDN API key, and altered JavaScript served from Awesome Motive CDN domains. The malicious code activated when a WordPress administrator loaded a page, stole authentication tokens and nonces, created rogue admin accounts, and installed hidden backdoor plugins that enabled arbitrary PHP code execution and web-shell access.
Why it matters: Website owners using these plugins may still have hidden attacker access even though the malicious CDN files were removed. Administrators should immediately check for rogue admin users and unknown plugins, rotate passwords and keys, and scan affected WordPress servers for persistence.
Sources
SecurityWeek News 2026.06.19 95%
This source adds a stronger scope estimate, saying the compromised OptinMonster, TrustPulse, and PushEngage CDN scripts may have affected more than 1.2 million WordPress sites, and repeats the attacker path via a compromised UpdraftPlus instance and CDN key.
Bill Toulas 2026.06.15 100%
This article appears to be the first clear report establishing the underlying event: a CDN-level supply-chain attack on Awesome Motive plugin assets that led to website compromise.
Full page
FTC says Americans lost a record $3.5 billion to impersonation scams in 2025, with social media driving much of the fraud
Social Engineering & PhishingPolicy & RegulationScams & FraudConsumers & General PublicFinance & BankingGovernmentFTCFacebookWhatsAppInstagram
The FTC says Americans lost $3.5 billion to impersonation scams in 2025, making them the most reported fraud category and one of the costliest threats facing the public. The agency said losses tied to social media exceeded $2.1 billion, while victims lost nearly $1 billion to business impersonators and about $920 million to government impersonators; common lures arrived by text, phone, email, social media, and search results, often posing as banks or government agencies.
Why it matters: This is a large-scale public safety and fraud story: ordinary people are losing billions after being tricked by fake banks, businesses, and government officials. People should treat unsolicited messages and calls as suspect, avoid moving money based on "security alerts," and verify requests through official contact channels.
Sources
SecurityWeek News 2026.06.19 88%
The roundup restates the FTC's 2025 impersonation-scam loss figures and adds summary context that bank and government impersonation schemes were major drivers and that the agency is enforcing its Impersonation Rule.
Sergiu Gatlan 2026.06.16 100%
This article establishes a distinct 2025 FTC fraud-loss milestone focused specifically on impersonation scams, with concrete dollar losses, delivery channels, and enforcement context rather than updating a previously tracked single scam campaign or FBI alert.
Full page
Apple patches Beats Studio Buds Bluetooth flaw CVE-2025-20701 that could let nearby attackers eavesdrop
Urgent PatchesZero-Days & CVEsSurveillance & PrivacyConsumers & General PublicAppleBeats
Apple released a firmware update for Beats Studio Buds to fix a flaw that could let someone nearby listen through the earbuds' microphone before they are paired. The issue, CVE-2025-20701, affects Airoha Bluetooth system-on-chip code used in the earbuds and was fixed in Beats Firmware Update 1B211. Apple says an attacker within Bluetooth range could exploit the unpaired device while it is seeking pair requests; researchers previously showed related Airoha flaws CVE-2025-20700 and CVE-2025-20702 could also help attackers hijack headphone functions and issue call commands.
Why it matters: People using affected Beats earbuds could be exposed to nearby spying even without pairing the device first. Users should ensure their Beats Studio Buds receive firmware 1B211 by pairing them with an iPhone, iPad, or Mac and confirming the update in Bluetooth settings.
Sources
SecurityWeek News 2026.06.19 80%
This roundup reiterates Apple's patch for the Beats Studio Buds Bluetooth eavesdropping flaw and serves as a secondary report on the same firmware security update.
info@thehackernews.com (The Hacker News) 2026.06.19 99%
This article reports the same underlying event: Apple's patch for CVE-2025-20701 in Beats Studio Buds that could allow a nearby attacker to access the microphone before pairing is complete.
Sergiu Gatlan 2026.06.18 100%
This article establishes a distinct security-update story: Apple has now issued a fix for a specific disclosed Bluetooth eavesdropping vulnerability affecting Beats Studio Buds.
Full page
Researcher says Google Cloud Config Connector flaw can bypass IAM and give attackers control of GCP organizations
Zero-Days & CVEsTechnology & SoftwareTechnology & SoftwareGoogle
A researcher says an unpatched flaw in Google Cloud's Config Connector could let a Kubernetes user seize broad control of an organization's Google Cloud environment. The issue, dubbed ConfigConfusion, affects Config Connector, Google's open source Kubernetes add-on for managing cloud resources, and allegedly lets a namespace user abuse a missing authorization check to bypass Identity and Access Management (IAM) and assign owner-level permissions at the Google Cloud Organization level. No CVE or patch has been issued.
Why it matters: Organizations using Config Connector with high-privilege service accounts could be exposed to full cloud-environment takeover if the report is accurate. Defenders using Google Cloud and Kubernetes should urgently review Config Connector deployments, reduce org-level permissions, and watch for vendor guidance or a fix.
Sources
SecurityWeek News 2026.06.19 84%
It flags the same unpatched Google Cloud Config Connector issue, summarizing it as a flaw that can enable takeover of Google Cloud organizations.
2026.06.18 100%
This article appears to be the first concrete report establishing the alleged Config Connector IAM-bypass issue, including the affected Google product, the claimed impact, and the fact that it remains unfixed.
Full page
Meta asks court to hold NSO Group in contempt after alleged new WhatsApp phishing targeting
Social Engineering & PhishingSurveillance & PrivacyThreat Actors & APTsPolicy & RegulationTechnology & SoftwareTelecommunicationsConsumers & General PublicMetaWhatsAppNSO Group
Meta says NSO Group again targeted WhatsApp users despite a court order barring it from doing so. WhatsApp said it disrupted NSO-linked social-engineering attempts involving malicious links that redirected targets to external websites, plus test accounts and groups on the platform, and published related domains and indicators of compromise. The report did not include victim counts, timing, or confirmation of successful compromises.
Why it matters: This matters because it suggests a spyware vendor accused of abusing messaging users may still be actively targeting people after a legal ban. WhatsApp users, journalists, activists, and high-risk targets should treat unsolicited links and unusual group invites with caution, and defenders should review the published indicators immediately.
Sources
Anna Mackay 2026.06.19 99%
This source is the same underlying event and adds that WhatsApp alleges NSO again used WhatsApp to lure targets into downloading Pegasus spyware despite last year's court order barring such conduct.
Bruce Schneier 2026.06.10 96%
This is the same underlying event: WhatsApp detecting renewed NSO-linked phishing targeting of its users despite an existing court order, adding an additional source noting the alleged violation and tying it to spyware activity.
Bill Toulas 2026.06.08 98%
This article reports the same underlying event: WhatsApp/Meta says it disrupted new NSO-linked one-click phishing activity targeting WhatsApp users, including test accounts and groups, and names the suspected infrastructure domains used in the campaign.
2026.06.08 99%
This article is a direct update on the same event: WhatsApp says NSO violated the court injunction by targeting users with spearphishing links and test accounts/groups, and that Meta is seeking a contempt order while sharing indicators of compromise.
Eduard Kovacs 2026.06.08 98%
This article is a direct report on the same event: WhatsApp says it detected and disrupted an NSO-linked spear-phishing campaign using malicious links, disabled related test accounts and groups, and is seeking a federal contempt order for violating the permanent injunction barring NSO from targeting WhatsApp users.
2026.06.08 100%
This article establishes a new trackable event: Meta's allegation of a fresh NSO-linked WhatsApp targeting campaign and its request that the court enforce the prior injunction through contempt proceedings.
Full page
Freedom of the Press Foundation says Paramount+ blocked an ad criticizing the Paramount-Skydance and Warner Bros. Discovery merger's press-freedom risks
Information FreedomCensorshipMedia & EntertainmentParamount+ParamountWarner Bros. DiscoveryFreedom of the Press FoundationCNNCBS
Freedom of the Press Foundation said Paramount+ refused to run its ad criticizing the proposed Paramount Skydance and Warner Bros. Discovery merger and warning that it could place CNN and other outlets under politically aligned editorial control. According to FPF, Paramount+ cited a conflict of interest, while the ad argued that David Ellison and President Donald Trump were linked to regulatory-pressure and coverage concerns surrounding the merger; the dispute centers on ad rejection and alleged suppression of criticism rather than a software flaw or cyberattack.
Why it matters: This matters because it is a specific allegation of platform-level suppression tied to a major media-ownership deal and political pressure, with implications for press independence and the public's access to criticism of powerful companies and officials. Affected users and watchdogs should track the merger, the ad-blocking decision, and any broader pattern of editorial or distribution restrictions.
Sources
Freedom of the Press Foundation 2026.06.19 96%
This is the primary source from Freedom of the Press Foundation detailing the same ad-rejection incident, adding Paramount's stated rationale of a 'conflict of interest' and framing it as censorship tied to criticism of the merger and treatment of news outlets.
Freedom of the Press Foundation 2026.06.16 100%
This article appears to establish the event itself: Paramount+ allegedly rejected a specific advocacy ad about the merger and its claimed press-freedom implications.
Full page
Microsoft says CryptoBandits Windows malware steals cryptocurrency and uses Tor as a backdoor
MalwareScams & FraudCryptocurrency & BlockchainConsumers & General PublicMicrosoft
Microsoft says a Windows malware family called CryptoBandits is infecting systems and stealing cryptocurrency by swapping copied wallet addresses, while also giving attackers remote access. The campaign has been active since February 2026 and spreads through malicious .lnk shortcut files and infected USB devices. It drops a portable Tor client, uses a local SOCKS5 proxy for hidden command-and-control traffic, achieves persistence with scheduled tasks, and can steal seed phrases, private keys, clipboard data, and screenshots while receiving follow-on commands.
Why it matters: This matters to both consumers and organizations because an infection can silently redirect crypto payments and provide attackers with ongoing access to a Windows device. Defenders should watch for suspicious .lnk files, USB-based propagation, unexpected local SOCKS5/Tor activity, and script execution via Windows Script Host, while users should avoid opening untrusted shortcut files and verify wallet addresses before sending funds.
Sources
Ionut Arghire 2026.06.19 100%
This article appears to be the first tracked item establishing the CryptoBandits malware campaign as a distinct story, with Microsoft providing the core technical analysis and attack details.
Full page
Rights groups urge the UK to stop planned facial age-estimation checks on asylum-seeking children at the border
Surveillance & PrivacyPolicy & RegulationGovernmentUK Home Office
More than 60 civil-society groups urged the UK government to halt plans to use facial age-estimation technology on asylum-seeking children starting in 2027. The letter says the Home Office's proposed system is biased and inaccurate, especially for 16-to-18-year-olds, and raises unanswered questions about what child images and biometric data were used to train it, what legal basis exists for consent, and why impact assessments and testing results have not been published.
Why it matters: This matters because a government wants to use automated face analysis to make decisions affecting vulnerable children at the border, despite reported error rates and bias concerns. It signals potential expansion of biometric surveillance and creates pressure for disclosure, oversight, and legal scrutiny before deployment.
Sources
2026.06.19 98%
This is the same underlying event: more than 60 rights groups opposing the UK Home Office's planned deployment of facial age-estimation for asylum-seeking children. The article adds specifics on the coalition's letter, the claimed 2.5-year error margin around ages 16 to 18, concerns about ethnicity and skin-tone bias, and demands for Equality and Data Protection Impact Assessments.
Paige Collings 2026.06.19 100%
This article establishes a distinct new story about the UK Home Office's planned 2027 deployment of facial age-estimation for asylum assessments and the organized rights-group pushback against it.
Full page
Splunk patches critical Splunk Enterprise flaw CVE-2026-20253 that lets unauthenticated attackers create or overwrite files
Urgent PatchesZero-Days & CVEsTechnology & SoftwareGovernmentSplunkCISA
Splunk released security updates for a critical flaw in Splunk Enterprise that could let attackers on the network create or modify files without logging in. The bug, CVE-2026-20253, has a CVSS score of 9.8 and affects a PostgreSQL sidecar service endpoint that lacks authentication; Splunk also fixed three high-severity Splunk Enterprise bugs tied to remote code execution, server-side request forgery (making the server send attacker-chosen requests), and cross-site scripting, plus additional issues in Splunk SOAR and third-party components.
Why it matters: Organizations running Splunk Enterprise or Splunk SOAR should treat this as a high-priority update because the most severe issue is remotely reachable without authentication. Admins should patch quickly and review exposure of Splunk services to internal and external networks.
Sources
Sergiu Gatlan 2026.06.19 97%
This updates the same CVE-2026-20253 event with materially new information: Splunk says it has seen limited in-the-wild exploitation, and CISA has added the flaw to its actively exploited workflow for federal agencies under BOD 26-04 with a Sunday remediation deadline.
Eduard Kovacs 2026.06.19 96%
This article updates the same CVE-2026-20253 event with confirmation that the flaw is now being exploited in the wild, notes that WatchTowr published PoC details shortly after disclosure, and adds that CISA placed it in KEV with a June 21 deadline for federal agencies.
Ionut Arghire 2026.06.18 63%
This adds a separate June Splunk security update: Splunk fixed CVE-2026-20266, a critical OS command injection in the AI Toolkit app for Splunk Enterprise, plus CVE-2026-20265, and advises upgrading to AI Toolkit 5.7.4 or uninstalling the app if upgrading is not possible.
Ionut Arghire 2026.06.11 100%
This article establishes a discrete patch event centered on Splunk's June 2026 advisories, led by critical CVE-2026-20253 in Splunk Enterprise.
Full page
UK plans to ban social media access for children under 16 and require stronger age checks
Information FreedomSurveillance & PrivacyPolicy & RegulationCensorshipTechnology & SoftwareConsumers & General PublicUK Department for Science, Innovation and TechnologyTikTokMetaSnapXGoogleUK governmentInstagramYouTubeSnapchat
The UK government says it will block children under 16 from using major social media platforms and require stronger age-verification systems. Prime Minister Keir Starmer said the proposed law would cover user-to-user platforms including TikTok, Facebook, Instagram, Snapchat, X, and YouTube, while exempting messaging services like WhatsApp. The plan also includes restrictions on livestreaming, stranger contact, and some AI chatbot features for minors, with legislation expected before Christmas and enforcement targeted for spring 2027.
Why it matters: This could reshape how millions of children access online services and would likely require platforms to deploy invasive or robust age-assurance controls. Parents, teens, platforms, and privacy advocates should watch the details closely because the practical impact will depend on how identity and age checks are implemented.
Sources
Jillian C. York 2026.06.19 95%
This article is a direct reaction to the same UK policy move, adding detail on the planned Spring 2027 timing, the proposed scope across major platforms, and the privacy and free-expression concerns tied to mandatory age checks and usage restrictions.
Ax Sharma 2026.06.16 97%
This article is a direct update on the same UK under-16 social-media ban and age-check policy, adding specifics that new account creation will likely require ID submission or facial age scans, while many existing accounts may be grandfathered in.
2026.06.16 100%
This article establishes a distinct UK regulatory action centered on banning under-16 social media access and mandating age assurance, not a direct update to an existing tracked story.
Full page
New York man charged with cyberstalking after using fake accounts and AI-generated nude images to harass a college student
Scams & FraudSurveillance & PrivacyPolicy & RegulationEducationConsumers & General PublicDOJInstagramLinkedInRedditXYahoo
A New York man was charged after prosecutors say he used fake social-media and email accounts to harass a Georgia college student with AI-generated nude images and false messages. Federal prosecutors say Anthony Belford created spoofed accounts on Instagram, LinkedIn, Reddit, X, Strava, and Yahoo between January and March 2025 to impersonate the victim, circulate fabricated racist and anti-Muslim statements, and send an AI-generated nude image to the victim's mother.
Why it matters: This is a concrete example of AI-generated intimate-image abuse and impersonation being used for targeted harassment, showing how synthetic media can intensify stalking and reputational attacks. It matters to the public because victims should preserve evidence, report abusive impersonation and nonconsensual intimate-image sharing quickly, and push platforms to remove content fast.
Sources
Sergiu Gatlan 2026.06.19 100%
This article establishes a distinct law-enforcement case centered on AI-generated nudes, spoofed accounts, and cyberstalking of a college student; it does not match an existing tracked story in the list.
Full page
Signal says Canada’s Bill C-22 could force metadata collection and threaten encrypted messaging services
Information FreedomSurveillance & PrivacyPolicy & RegulationGovernmentTechnology & SoftwareTelecommunicationsConsumers & General PublicSignalGovernment of CanadaAppleGoogleCanada Ministry of Public Safety
Citizen Lab highlights concerns that Canada’s proposed lawful-access Bill C-22 could undermine encryption protections and require messaging services to collect metadata. Signal said it would leave the Canadian market rather than comply if the bill mandated such access, while researchers said officials were unwilling to clearly protect encryption.
Why it matters: The proposal could materially affect users of encrypted messaging in Canada, especially journalists, dissidents, and human-rights defenders. Defenders and civil-society groups should track the bill because it may create surveillance obligations or drive privacy-preserving services out of the market.
Sources
Thorin Klosowski 2026.06.18 96%
This article updates the same Bill C-22 legislative fight by reporting that the bill is being rushed toward a vote before June 19, that key backdoor provisions were shielded from separate debate, and that EFF is reiterating opposition alongside Signal, Apple, Google, VPN providers, Citizen Lab, and the Canadian Civil Liberties Association.
Claire Posno 2026.05.25 93%
This is the same underlying policy story around Canada’s proposed Bill C-22. It adds Citizen Lab’s argument that the bill could also pave the way for a U.S.-Canada CLOUD Act agreement enabling foreign law-enforcement requests for real-time surveillance, including wiretaps and device hacking in Canada.
Anna Mackay 2026.05.14 100%
This article establishes a distinct policy and privacy story around Canada’s Bill C-22 and its potential impact on encrypted communications, with a concrete response from Signal.
Full page
KrebsOnSecurity links The Gentlemen ransomware group to a suspected administrator in Izhevsk, Russia
RansomwareThreat Actors & APTsMalwareFortinetMicrosoftCrowdStrikeSentinelOnePalo AltoKaspersky
A new report identifies a suspected real-world operator behind The Gentlemen, one of 2026's most active ransomware groups. KrebsOnSecurity, drawing on Check Point, Intel 471, Flashpoint, and Constella data, says the ransomware-as-a-service group has claimed at least 332 victims since mid-2025 and more than 240 in 2026, recruits affiliates with a 90/10 ransom split, and commonly gains entry through internet-facing VPN and firewall devices before rapidly encrypting networks.
Why it matters: This is a major ransomware actor by victim volume, so the attribution and tradecraft details help defenders prioritize monitoring of exposed remote-access and edge devices. Organizations should review exposure of VPNs and firewalls, harden remote access, and watch for intrusion patterns associated with fast-moving affiliate-led ransomware attacks.
Sources
Bill Toulas 2026.06.18 61%
This article updates the same underlying Gentlemen ransomware operation with new technical reporting from ESET on how the gang supports affiliates: a maintained suite of BYOVD-based EDR killers including multiple GentleKiller variants, use of external tools such as HexKiller, ThrottleBlood, and HavocKiller, and the Rust-based OxideHarvest stealer. It also adds detail that target selection may be informed by FortiGate endpoint configuration.
BrianKrebs 2026.06.10 100%
This article establishes a distinct story centered on attribution and operational analysis of The Gentlemen ransomware group, not an update to an existing tracked event.
Full page
Senators Cruz and Wyden introduce JAWBONE Act to let people sue over government pressure on platforms to remove lawful speech
Information FreedomCensorshipPolicy & RegulationTechnology & SoftwareConsumers & General PublicAppleGoogleMetaICEBlock
U.S. senators introduced a bipartisan bill that would create new legal and transparency rules around government efforts to get online services to remove lawful speech. The JAWBONE Act would create a federal cause of action against officials who coerce or try to coerce broadcasters, interactive computer services, or AI providers into acting against First-Amendment-protected expression, and would require more transparency about such government-platform communications. EFF ties the proposal to its ongoing challenge over pressure that led Apple to remove the ICEBlock app.
Why it matters: This matters for internet users, app developers, and platforms because it could curb back-channel government pressure that results in lawful speech or apps being removed. The practical takeaway is to watch this bill and related court fights, since they could reshape how agencies communicate with Apple, Google, Meta, and other intermediaries about content moderation.
Sources
India McKinney 2026.06.18 100%
The article establishes a new legislative event—the introduction of the JAWBONE Act—rather than updating an existing tracked story about a specific prior takedown, surveillance case, or court action.
Full page
EFF backs Open Courts Act of 2026 to eliminate PACER fees and modernize federal court records systems
Information FreedomPolicy & RegulationGovernmentLegal & Professional ServicesEFFPACER
EFF and other civil-society groups are supporting the Open Courts Act of 2026, a U.S. bill that would make federal court records free to access and replace the aging PACER and CM/ECF systems. The proposal is framed as both an access and security measure: it would create a unified platform for court filings, remove PACER paywalls, and update legacy judiciary technology that supporters say needs stronger cybersecurity and lower long-term operating costs.
Why it matters: This matters to the public, journalists, lawyers, and watchdog groups because it would reduce barriers to court transparency while also upgrading old federal court technology. If the bill advances, defenders and policy watchers should track how the judiciary handles cybersecurity requirements in the replacement system.
Sources
Joe Mullin 2026.06.18 100%
This article establishes a distinct policy story around the Open Courts Act of 2026 and its proposed security and access changes for federal court records systems.
Full page
Report says Bulgaria approved Circles surveillance exports to governments accused of repressing dissidents
Surveillance & PrivacyPolicy & RegulationGovernmentTelecommunicationsCirclesBulgarian Ministry of Economy and IndustryEuropean CommissionIntellexa
Human Rights Watch says Bulgaria approved exports of Circles surveillance products to multiple governments with records of repression, potentially enabling interception of calls, messages, internet activity, and real-time phone location tracking. The report cites Bulgarian export licensing records from 2018 through 2023 showing sales to agencies in El Salvador, the United Arab Emirates, Serbia, Azerbaijan, Guatemala, Bahrain, Jordan, Malaysia, Morocco, and Panama. Products named include Pixcell, Landmark, and a voice interception tool using the SS7 telecom signaling protocol.
Why it matters: This matters because it shows how commercial spyware and telecom surveillance tools can still reach governments that may use them against journalists, activists, and political opponents despite European Union export rules. It raises immediate policy and human-rights concerns for telecom users, civil society, and regulators, and points to the need for closer scrutiny of surveillance exports and their end users.
Sources
2026.06.18 100%
This article establishes a distinct story by tying newly obtained Bulgarian export-license records to specific Circles surveillance product sales and destination governments, rather than updating an existing tracked event.
Full page
Microsoft faces human-rights scrutiny over Azure and AI services allegedly used in Israeli military surveillance and targeting
Surveillance & PrivacyPolicy & RegulationGovernmentDefense & AerospaceTechnology & SoftwareMicrosoftIsraeli militaryAnthropicPentagon
EFF highlights reports that Microsoft investigated and reportedly suspended certain services in September 2025 after concerns that its Azure cloud and AI offerings were being used by Israeli military and intelligence units in surveillance and targeting operations in Gaza. The article also points to the reported departure of Microsoft's Israel chief amid pressure for disclosure and stronger safeguards.
Why it matters: This is a significant surveillance and privacy accountability story for cloud and AI providers operating in conflict settings. It matters to affected populations, civil society, and enterprise customers because it raises questions about how major vendors assess, restrict, and disclose high-risk government use of their infrastructure.
Sources
Corynne McSherry 2026.06.18 35%
The article echoes that story's core theme of AI services being challenged over military surveillance and targeting uses, but here the concrete event is Anthropic's refusal to support autonomous weapons and spying on Americans and the alleged government retaliation that followed.
Cindy Cohn 2026.05.19 100%
The article establishes a discrete ongoing story: Microsoft's alleged internal response, service suspensions, and leadership fallout tied to claims that its technology supported military surveillance and targeting operations.
Wajd 2026.05.18 95%
This directly updates the same underlying event by adding that Access Now, Amnesty International, EFF, 7amleh, and Fight for the Future sent a joint letter demanding publication of Microsoft's completed legal review, more detail on suspended services related to Unit 8200, and suspension of contracts where services may contribute to abuses.
Wajd 2026.05.18 93%
This directly updates the same underlying event: ongoing scrutiny of Microsoft's Azure and AI services allegedly used by Israeli military and intelligence units, adding a joint letter demanding publication of Microsoft's completed review and more specifics on which Unit 8200 services were suspended or remain active.
Full page
F5 patches critical NGINX vulnerabilities CVE-2026-42530 and CVE-2026-42055 that can crash servers and potentially allow code execution
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareF5NGINX
F5 released emergency updates for NGINX products to fix critical security flaws that can let an unauthenticated attacker crash internet-facing servers and, in some cases, potentially run malicious code. The main issues are CVE-2026-42530 and CVE-2026-42055, both rated 9.2, affecting HTTP modules in NGINX Plus, NGINX Open Source, and NGINX Gateway Fabric; exploitation can trigger worker-process restarts, and arbitrary code execution may be possible if Address Space Layout Randomization (a memory-protection feature) is disabled or bypassed. F5 also patched NGINX Gateway Fabric flaws CVE-2026-11311 and CVE-2026-50107 that let authenticated attackers inject NGINX configuration directives.
Why it matters: Organizations using NGINX to run websites, APIs, or application gateways may be exposed to denial-of-service and possible remote compromise, especially on internet-facing systems. Administrators should identify affected NGINX deployments and apply F5's out-of-band updates promptly.
Sources
info@thehackernews.com (The Hacker News) 2026.06.18 99%
This article reports the same F5/NGINX patch event for the two critical open source NGINX flaws, adding another source confirming the vulnerabilities' severity and remote exploitation risk.
Sergiu Gatlan 2026.06.18 98%
This article covers the same F5 out-of-band patch release for the same two critical NGINX flaws and adds product-level detail on affected software including NGINX Plus, NGINX Open Source, NGINX Gateway Fabric, and NGINX Instance Manager, along with mitigation steps and mention of two additional high-severity Gateway Fabric issues.
Ionut Arghire 2026.06.18 100%
This article establishes a distinct new patching event for multiple newly disclosed NGINX vulnerabilities and does not match any existing tracked story about the same CVEs or release.
Full page
Google says China-linked UNC6508 hid in REDCap servers at North American medical and military research organizations for more than a year
Breaches & Data LeaksMalwareSurveillance & PrivacyThreat Actors & APTsHealthcareDefense & AerospaceGovernmentEducationNonprofits & NGOsGoogleREDCapVanderbilt University
Google says a China-linked espionage group spent more than a year inside North American medical and military research networks, stealing sensitive data and searching Gmail for defense and disease-research information. Google tracks the group as UNC6508 and says the intrusions began by exploiting internet-facing REDCap (Research Electronic Data Capture) servers, then deploying custom InfiniteRed malware to maintain access, harvest REDCap credentials, backdoor the application, and search for data tied to drone technology, defense companies, and Chikungunya research.
Why it matters: Organizations running REDCap in healthcare, research, government, or defense-adjacent environments should treat this as a high-priority intrusion risk and investigate for compromise, not just patch. The campaign shows long-term espionage against sensitive medical and military research, including theft from email and internal systems.
Sources
Ionut Arghire 2026.06.18 94%
This article updates the same underlying UNC6508 REDCap espionage campaign with new internet-wide telemetry from Censys, estimating roughly 8,500 exposed REDCap instances globally and finding only about 1% on the latest version, which strengthens the exposure and urgency around the previously reported targeting of legacy REDCap servers.
Eduard Kovacs 2026.06.15 97%
This article is a direct report on the same GTIG disclosure, adding plain-language detail that UNC6508 targeted REDCap servers at medical, academic, military, and AI-related organizations in North America, deployed the InfiniteRed malware, abused content compliance rules for email exfiltration, and used legacy vulnerable REDCap instances and obfuscation infrastructure.
2026.06.15 100%
This article appears to be the first detailed report establishing this specific UNC6508 espionage campaign against REDCap-backed medical and military research environments.
Bill Toulas 2026.06.15 98%
This is the same underlying GTIG disclosure about UNC6508 compromising vulnerable REDCap servers, deploying InfiniteRed malware, stealing credentials, and exfiltrating medical and research data from North American organizations over a year-long intrusion. It adds reporting emphasis on the medical-research victim and the email-rule exfiltration method.
Full page
Microsoft says USB shortcut worm is spreading crypto-stealing clipper malware through infected Windows drives
MalwareScams & FraudCryptocurrency & BlockchainConsumers & General PublicMicrosoft
Microsoft says a Windows malware campaign is spreading through USB drives and stealing cryptocurrency by swapping copied wallet addresses with attacker-controlled ones. The malware uses malicious LNK shortcut files to launch from removable media, hides real documents and replaces them with lookalike shortcuts, propagates to newly connected USB devices, and uses Tor for command-and-control. It also looks for seed phrases and private keys, captures screenshots, and supports remote code execution through JavaScript fetched from a .onion address.
Why it matters: This can hit ordinary users and organizations that still share files by USB, especially anyone handling cryptocurrency wallets or recovery phrases. Defenders should watch for suspicious wscript.exe and cscript.exe activity, Tor proxy traffic such as localhost:9050, and unusual shortcut files on removable drives; users should avoid opening unexpected files from USB media and verify wallet addresses carefully.
Sources
Bill Toulas 2026.06.18 100%
This article establishes a distinct malware campaign centered on USB-borne LNK worm propagation and cryptocurrency clipboard theft, not a follow-up to an existing tracked story.
Full page
Cyberattack shuts down Mackay Sugar mills in Queensland and halts cane harvest
RansomwareBreaches & Data LeaksManufacturingEnergy & UtilitiesMackay Sugar
A cyberattack forced Mackay Sugar, one of Australia's largest sugar producers, to shut down two mills in Queensland and stop sugarcane harvesting in the Mackay region. The company said the incident affected parts of its operations and that cybersecurity experts and authorities are investigating while systems are restored. No ransomware claim, data-theft disclosure, or technical details about the intrusion method have been confirmed yet.
Why it matters: This is a real-world operational technology and business disruption incident affecting food production and local growers, not just office IT. Organizations in agriculture and other industrial sectors should review incident response plans, segmentation between business and plant systems, and contingency procedures for outages.
Sources
2026.06.18 95%
This article is a direct update on the same Mackay Sugar incident, adding that the Gentlemen ransomware group has claimed responsibility, that Mackay Sugar found evidence an external party accessed parts of its IT environment, and that the company is assessing whether data was stolen while working to resume harvesting.
2026.06.17 97%
This article is a direct update on the same Mackay Sugar incident, adding operational detail that farmers were told to keep cane in the ground, that Farleigh Mill resumed limited manual crushing, that Racecourse and Farleigh were affected while Marian was not, and that The Gentlemen claimed responsibility on its leak site.
Eduard Kovacs 2026.06.15 99%
This article is a direct update on the same Mackay Sugar incident, adding that The Gentlemen ransomware group has claimed the attack, that two mills were impacted, manual crushing resumed at one site, and that restoration of cane supply, harvesting, and mill systems was still underway as of June 15.
2026.06.10 100%
This article establishes the incident itself: a newly disclosed cyberattack on Mackay Sugar that shut down Farleigh and Racecourse mills and interrupted harvest operations.
Full page
DragonForce ransomware used Microsoft Teams relay infrastructure to hide malware traffic in a real attack
RansomwareThreat Actors & APTsMalwareLegal & Professional ServicesMicrosoftHuaweiPalo AltoDragonForce
DragonForce ransomware operators used Microsoft Teams network relays to disguise malware communications during an attack on a major U.S. services company. Symantec says the attackers deployed a custom Go-based backdoor called Backdoor.Turn that abused Teams' TURN relays (servers that help route traffic when direct connections fail) to mask command-and-control traffic as Microsoft activity. The December 2025 intrusion also used bring-your-own-vulnerable-driver tactics, including HWAuidoOs2Ec.sys, wsftprm.sys (CVE-2023-52271), GameDriverx64.sys (CVE-2025-61155), and K7RKScan.sys (CVE-2025-1055), before data theft and ransomware deployment.
Why it matters: This matters because defenders may see the malware's traffic as legitimate Microsoft Teams activity, making detection and blocking harder during a ransomware attack. Organizations should review Microsoft Teams-related network trust assumptions, hunt for the listed indicators, and prioritize controls against driver-based security-tool tampering and suspicious use of SQL/MSSQL servers.
Sources
info@thehackernews.com (The Hacker News) 2026.06.18 99%
This article appears to cover the same underlying event and adds reporting on DragonForce abusing Microsoft Teams relays to mask backdoor command-and-control traffic during an actual ransomware intrusion.
Ionut Arghire 2026.06.17 99%
This article is a direct report on the same incident, adding specifics that the malware is a new Go-based backdoor dubbed Backdoor.Turn, that it obtains anonymous Teams visitor tokens and uses Microsoft TURN relays plus QUIC to mask command-and-control traffic, and that the intrusion likely began via an unknown SQL or MSSQL server vulnerability before ransomware deployment and post-encryption persistence.
2026.06.16 98%
This is the same underlying event: Symantec's report that DragonForce compromised a major U.S. services company and used Microsoft Teams and Skype backend infrastructure plus a Microsoft TURN relay to conceal Backdoor.Turn command-and-control traffic. The article adds detail on the anonymous visitor token request, QUIC connection flow, two-month dwell time, and the possibility that the backdoor was left behind after ransomware deployment for persistence or resale of access.
Bill Toulas 2026.06.16 100%
This article establishes a distinct story because it reports the first known in-the-wild malware abuse of Microsoft Teams TURN relay infrastructure by DragonForce during a real ransomware intrusion, rather than a patch, advisory, or previously tracked breach.
Full page
Atlassian issues broad security updates for Jira, Confluence, Bitbucket, Bamboo, Crowd, and other products over critical dependency flaws
Urgent PatchesZero-Days & CVEsTechnology & SoftwareAtlassian
Atlassian released a large set of security updates for many of its self-hosted products, including Jira, Confluence, Bitbucket, Bamboo, Crowd, Fisheye/Crucible, and Jira Service Management. The fixes cover dozens of third-party dependency vulnerabilities across about 100 bulletins, including critical flaws in Axios (CVE-2026-42043, CVE-2026-40175, CVE-2026-42264), Apache Tomcat (including CVE-2026-41293, CVE-2026-43512, CVE-2026-43515), and Netty (CVE-2026-42584).
Why it matters: Organizations running Atlassian server and data center products may be exposed through bundled components they do not directly track, so administrators should apply the relevant product updates promptly. The story matters because these tools are widely used for code hosting, ticketing, documentation, and internal collaboration.
Sources
Ionut Arghire 2026.06.18 100%
This article is the first item here establishing Atlassian's June 18, 2026 wave of dependency-driven security bulletins across multiple core products.
Full page
Rokarolla Android banking trojan targets 217 banking and cryptocurrency apps through fake Chrome and TikTok downloads
Scams & FraudMalwareSocial Engineering & PhishingFinance & BankingCryptocurrency & BlockchainConsumers & General PublicGoogleTikTokWhatsApp
A newly reported Android malware strain called Rokarolla is stealing financial data from people who install fake Chrome or TikTok apps from malicious websites. Zimperium says the trojan abuses Android Accessibility permissions, notifications, SMS, and call access, then checks for 217 targeted banking and crypto apps and downloads matching fake login overlays to capture credentials, card data, lock-screen PINs, contacts, SMS, and other device data. The malware also uses 137 command-and-control instructions and can disable Google Play Protect and hide its icon.
Why it matters: This can let criminals take over phones and drain financial accounts, especially when victims sideload apps outside Google Play. Android users should avoid APKs from unofficial sites, review Accessibility requests carefully, and treat unexpected prompts to install Chrome, TikTok, or security updates as suspicious.
Sources
Eduard Kovacs 2026.06.18 98%
This article is a direct report on the same Rokarolla Android malware campaign, adding details on distribution via fake Chrome and TikTok apps, lockscreen credential theft, WhatsApp contact harvesting, SMS and call hijacking, screenshot exfiltration, keylogging, clipboard hijacking, and Google Play Protect evasion.
Bill Toulas 2026.06.16 100%
This article appears to be the first concrete report in the dataset establishing Rokarolla as a distinct Android banking-malware campaign, with named malware, delivery method, targeting scope, and technical capabilities.
Full page
Cisco patches critical Cisco ISE and ISE-PIC command-execution flaw CVE-2026-20181
Urgent PatchesZero-Days & CVEsTechnology & SoftwareGovernmentHealthcareFinance & BankingEducationEnergy & UtilitiesTelecommunicationsCisco
Cisco released security fixes for a critical flaw in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that could let an attacker run commands on affected systems. The bug, CVE-2026-20181, is a 9.1-severity input-validation issue that can be exploited over HTTP by a remote attacker with valid administrative credentials to gain OS-level access and then escalate to root; in single-node deployments it can also cause a denial-of-service. Fixes are in ISE/ISE-PIC 3.3 Patch 11 and 3.4 Patch 6, with a hotfix for 3.5 and inclusion planned for 3.5 Patch 4; Cisco also fixed CVE-2026-20190, an unauthenticated information-disclosure flaw.
Why it matters: Organizations using Cisco ISE or ISE-PIC should patch quickly because these systems help control who and what can join the network, making compromise especially sensitive. Even though Cisco says it has no evidence of active exploitation, the combination of root-level impact and possible credential exposure makes this an update-now issue for administrators.
Sources
Ionut Arghire 2026.06.18 100%
This article appears to be the first tracked item here focused on Cisco's disclosure and patching of CVE-2026-20181 in ISE/ISE-PIC, with the core technical details and fixed versions.
Full page
Kodak confirms data breach after ShinyHunters claims theft of customer and internal company data
Breaches & Data LeaksManufacturingKodak
Kodak says an unauthorized third party briefly accessed and copied some company data, and the company is investigating with outside incident-response experts. BleepingComputer reports ShinyHunters claimed the attack on its leak site, alleging it stole more than 2.2 million records containing customer personally identifiable information and internal corporate data, though Kodak has so far only confirmed a limited data-access incident and has not disclosed the intrusion method.
Why it matters: Kodak customers and business contacts could face privacy risks if the stolen data is real and later leaked. Organizations with Kodak relationships should watch for breach notifications and phishing, while defenders should monitor for follow-on extortion or credential abuse tied to the incident.
Sources
Eduard Kovacs 2026.06.18 99%
This article is the same underlying event and adds Kodak's public confirmation that an unauthorized third party accessed a limited amount of company data, that the incident was contained, and that law enforcement and external cyber experts are involved, alongside ShinyHunters' claim of 2.2 million stolen records and a June 18 leak deadline.
Sergiu Gatlan 2026.06.17 100%
This article appears to be the first concrete breach confirmation from Kodak itself tied to ShinyHunters' public claim, establishing a distinct incident rather than updating an existing tracked Kodak story.
Full page
Google says it will use IP addresses for ad personalization in the UK, EU and Switzerland starting August 2026
Surveillance & PrivacyPolicy & RegulationTechnology & SoftwareConsumers & General PublicGoogleICO
Google told advertisers it will begin using users' IP addresses for ad measurement and ad personalization in the European Economic Area, the UK, and Switzerland on or after August 3, 2026. The change affects Google ad systems that already receive IP data through tags, software development kits, HTTP requests, and uploads, but will now use that data to identify devices for personalized advertising. Google says advertisers must obtain valid user consent under its EU User Consent Policy and will register this processing under IAB Europe's Transparency and Consent Framework Feature 3.
Why it matters: This expands how Google can track and profile people in regions where IP addresses are treated as personal data, making it a significant privacy and compliance issue for both users and advertisers. People should review ad and consent settings, while organizations using Google ads should verify that their consent flows meet UK and EU requirements before the change takes effect.
Sources
Ax Sharma 2026.06.17 100%
This article establishes a new story because it reports a specific upcoming Google tracking and ad-personalization change, with a dated rollout and direct privacy-law implications, not an update to any existing tracked event.
Full page
UK cyber chief says hostile states were behind most attacks on Britain’s critical infrastructure in the past year
Threat Actors & APTsGovernmentEnergy & UtilitiesTelecommunicationsTransportation & LogisticsNCSC
Britain’s cyber defense agency says hostile states were behind roughly three-quarters of the cyber incidents it handled affecting critical infrastructure over the past year. NCSC chief Richard Horne said the agency responded to more than 200 incidents affecting critical national infrastructure and its supporting ecosystem in the year to May 2026, and warned adversaries are 'prepositioning' inside infrastructure for possible later disruption, citing tactics similar to the China-linked Volt Typhoon campaign.
Why it matters: This is a high-signal warning that government, utilities, telecom, transport and other essential-service operators may already be dealing with state-backed intrusions designed for future disruption. UK critical-infrastructure defenders should review monitoring, segmentation, access controls and incident-response readiness now rather than treating this as a distant risk.
Sources
2026.06.17 100%
This article establishes a distinct UK-focused story by adding new official incident numbers and a direct public warning from the NCSC that nation-state actors are already embedded across British critical infrastructure.
Full page
EU grants Ukraine access to ENISA cyber reserve for emergency help during major cyberattacks
Policy & RegulationThreat Actors & APTsGovernmentEnergy & UtilitiesTelecommunicationsEuropean CommissionENISAUkraine National Security and Defense Council
The European Union has approved Ukraine’s access to the EU Cybersecurity Reserve, letting Kyiv request emergency help from EU-approved private incident-response experts during major cyberattacks. The reserve is managed by ENISA, the European Union Agency for Cybersecurity, and can provide digital forensics, incident response, recovery support, threat-intelligence sharing, and post-incident hardening when an attack exceeds national capacity.
Why it matters: This expands Ukraine’s ability to respond to large cyber incidents tied to the war with Russia and deepens EU-Ukraine cyber defense cooperation. It matters to governments, critical infrastructure operators, and defenders because it creates a formal rapid-assistance mechanism for cross-border cyber emergencies.
Sources
2026.06.17 100%
This article establishes a new policy and operational support milestone: Ukraine is being formally added to the EU Cybersecurity Reserve, creating a new collective cyber-response arrangement rather than updating a previously tracked incident.
Full page
UN World Food Programme investigates breach of Gaza aid registration system exposing data on about 600,000 households
Surveillance & PrivacyBreaches & Data LeaksNonprofits & NGOsConsumers & General PublicWorld Food Programme
The U.N. World Food Programme says attackers accessed personal data submitted by Palestinians seeking food and cash assistance in Gaza. The incident affected the agency's Self-Registration Application used only in Palestine and exposed names, identification numbers, phone numbers, and neighborhood location details; WFP said the breach occurred on May 14, shut down the platform, and is still investigating how the intrusion happened and whether data was further leaked.
Why it matters: This is not just a privacy breach: exposed aid-recipient data in a war zone can put vulnerable civilians at real physical risk. People who registered for assistance may need to watch for phishing, impersonation, or other misuse of their personal details, while aid organizations should review exposure risks and incident response urgently.
Sources
Amina Khan 2026.06.17 95%
This source is directly about the same May 14, 2026 breach of WFP's Self-Registration Application for Palestine and adds specifics on the notification timeline, the types of exposed data including names, ID numbers, location and household details, the estimate that more than 2 million people had registered through the app, and civil-society demands for transparency and protective measures.
2026.06.05 99%
This is the same underlying incident: the breach of WFP's Gaza self-registration application. The article adds reporting on the public Telegram notices, confirms the exposed data types included names, ID numbers, phone numbers, and location data, notes the platform was suspended for security improvements, and cites reporting that WFP detected the attack on May 14 after a prior warning about vulnerabilities.
2026.06.04 100%
This article establishes a new tracked story by identifying a distinct breach at the World Food Programme's Gaza self-registration platform, including the affected system, exposed data types, and reported scale of about 600,000 households.
Full page
Cisco adds Catalyst SD-WAN Validator to the list of products affected by exploited flaw CVE-2026-20127
Zero-Days & CVEsUrgent PatchesThreat Actors & APTsTechnology & SoftwareTelecommunicationsGovernmentEnergy & UtilitiesCisco
Cisco has updated its February advisory to say another SD-WAN product, Catalyst SD-WAN Validator, is vulnerable to a maximum-severity flaw that attackers have already used. The issue, CVE-2026-20127, is an improper authentication bug that can let an attacker become an administrator; Cisco previously said it could then be chained with CVE-2022-20775, a path traversal flaw, to gain persistent root access on vulnerable SD-WAN systems.
Why it matters: Organizations using Cisco SD-WAN need to confirm Validator was included in their remediation and review logs for signs of compromise. This matters because affected systems can be fully taken over and used to alter core network settings.
Sources
2026.06.17 100%
This article establishes a distinct update to the CVE-2026-20127 story by adding a newly acknowledged affected product, which changes the scope of who must verify patching and hunt for compromise.
Full page
Rockwell Automation patches critical and high-severity flaws in FactoryTalk, Logix controllers, Flex adapters, and RSLinx
Urgent PatchesZero-Days & CVEsManufacturingEnergy & UtilitiesRockwell AutomationCISA
Rockwell Automation released security fixes for multiple industrial control products used in factories and critical operations. The updates cover FactoryTalk Historian Site Edition flaws that can bypass authentication and cause denial of service, a FactoryTalk Analytics PavilionX improper API authorization bug that can allow unauthorized administrative actions, denial-of-service issues in CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers, and a critical unauthenticated flaw in Flex I/O dual-port Ethernet/IP adapters that can let an attacker change the web interface password and potentially take over access. CISA redistributed the advisories, and Rockwell said the newly patched issues are not known to be exploited in the wild.
Why it matters: Organizations running Rockwell industrial equipment should review and apply these updates promptly because the affected products can be used in operational technology environments where outages or unauthorized access can disrupt physical processes. Even without confirmed active exploitation, the mix of critical and high-severity bugs makes this a patch-now item for defenders responsible for ICS and OT systems.
Sources
Eduard Kovacs 2026.06.17 100%
This article establishes a new patch-and-advisory story focused on Rockwell Automation's June 2026 fixes for multiple ICS and OT products, with no existing tracked story covering this specific release.
Full page
Dutch police arrest six suspects tied to bank helpdesk scam call center that also sent visitors to victims’ homes
Social Engineering & PhishingScams & FraudFinance & BankingConsumers & General Public
Dutch police arrested six suspects after raiding an Amsterdam home they say was being used as a makeshift call center for bank helpdesk fraud. Authorities said the group, whose members were aged 15 to 30, called victims while posing as bank staff and in some cases sent people to victims’ homes to supposedly help secure accounts, then stole money. Police seized laptops, phones, and bank cards and said the suspects were caught while speaking with a potential victim.
Why it matters: This shows social-engineering scams are blending phone fraud with in-person impersonation to make lies feel legitimate, especially for older targets. Banks, families, and potential victims should treat unsolicited calls or home visits about account security as suspicious and verify through official channels.
Sources
2026.06.17 100%
This article establishes a distinct, concrete fraud case: a Dutch police raid on an Amsterdam-based bank helpdesk scam operation using both vishing and house calls.
Full page
Researcher releases RoguePlanet Windows zero-day that can give SYSTEM access on patched Windows 10 and 11
Urgent PatchesMalwareZero-Days & CVEsTechnology & SoftwareConsumers & General PublicMicrosoft
A security researcher published a new Windows zero-day exploit that can give an attacker full SYSTEM privileges on fully patched consumer PCs. The proof-of-concept, dubbed RoguePlanet, abuses a race condition in Microsoft Defender to achieve local privilege escalation on Windows 10 and Windows 11 systems with June 2026 updates installed; the researcher says earlier versions also enabled remote code execution through malicious .vhd(x) files on remote SMB shares and BitLocker bypass paths, but the currently released exploit is validated primarily as local escalation and reportedly does not yet work on Windows Server.
Why it matters: This matters because a public exploit can help malware or intruders turn limited access on a Windows machine into full control even after current patches are installed. Organizations should watch for Microsoft guidance, restrict untrusted SMB and disk-image handling where possible, and prioritize detection for SYSTEM-level escalation from Defender-related activity.
Sources
Ionut Arghire 2026.06.17 96%
This article updates the same RoguePlanet event with Microsoft's official acknowledgment, the assigned CVE-2026-50656 identifier, advisory details, and confirmation that a security update is being developed for the publicly released exploit affecting Microsoft Defender on Windows 10 and 11.
Sergiu Gatlan 2026.06.17 96%
This directly updates the same RoguePlanet event by adding Microsoft's response: the flaw is now tracked as CVE-2026-50656, affects the Microsoft Malware Protection Engine in Defender, and Microsoft says it is working on a security update.
Ionut Arghire 2026.06.11 72%
This source is a direct follow-on in the same Nightmare Eclipse disclosure spree, adding that one day after RoguePlanet the researcher released 'GreatXML', a separate Windows zero-day that abuses Microsoft Defender Offline scan and WinRE to bypass BitLocker and obtain a SYSTEM shell.
2026.06.10 99%
This article is directly about the same newly disclosed RoguePlanet Windows Defender zero-day, adding that The Register reports Microsoft is investigating the claim, that the bug targets Microsoft Defender on fully patched Windows 10 and 11 systems, and that Nightmare Eclipse released PoC exploit code after June Patch Tuesday.
Ionut Arghire 2026.06.10 100%
The article establishes a distinct new event: the public release and validation of a new, currently unpatched Microsoft Defender/Windows privilege-escalation exploit called RoguePlanet, separate from the previously tracked YellowKey and other Nightmare Eclipse disclosures.
Full page
Malicious JetBrains Marketplace plugins stole OpenAI, DeepSeek, and other AI API keys from developers
Supply ChainMalwareTechnology & SoftwareJetBrainsOpenAIDeepSeekSiliconFlowGoogle
At least 15 plugins listed in the JetBrains Marketplace were built to steal AI service API keys from developers who installed them. Aikido Security says the plugins, published under seven vendor accounts since October 2025 and still appearing as late as June 10, 2026, exfiltrated keys entered into plugin settings to a hardcoded server over HTTP, including credentials for OpenAI, DeepSeek, and SiliconFlow. The plugins reportedly posed as AI coding assistants, code-review tools, and Git utilities, with nearly 70,000 total downloads claimed across the set.
Why it matters: Developers and organizations using JetBrains IDEs may have had sensitive AI credentials stolen, creating risk of unauthorized model access, data exposure, and billing abuse. Affected users should remove the named plugins, rotate exposed API keys immediately, and review usage logs and downstream secrets access.
Sources
info@thehackernews.com (The Hacker News) 2026.06.17 97%
This article appears to cover the same underlying campaign of malicious JetBrains Marketplace plugins stealing AI service credentials from developers, while adding related detail that Chrome extensions were also used to capture chatbot chats.
Lawrence Abrams 2026.06.16 100%
This article appears to be the first concrete report establishing a coordinated malicious-plugin campaign in the JetBrains Marketplace focused on stealing AI API keys.
Full page
Oracle's first monthly Critical Security Patch Update fixes 77 vulnerabilities across Database, E-Business Suite, REST Data Services and other products
Urgent PatchesZero-Days & CVEsTechnology & SoftwareTelecommunicationsHospitality & TravelGovernmentConsumers & General PublicOracle
Oracle released its first new monthly Critical Security Patch Update, fixing 77 vulnerabilities across several enterprise products used by businesses and public-sector organizations. The May 2026 update covers Oracle Database Server, REST Data Services, Communications, E-Business Suite, and Hospitality Applications, including about a dozen critical-severity flaws and multiple bugs that remote, unauthenticated attackers could exploit over a network. Oracle did not cite active exploitation in this notice but urged customers to patch quickly.
Why it matters: Organizations running affected Oracle software should treat this as a prompt patching event, especially where systems are internet-facing. Several flaws can be exploited remotely without logging in, so defenders should identify exposed Oracle services and apply the new updates as soon as possible.
Sources
Eduard Kovacs 2026.06.17 93%
This article is a direct follow-up on the same underlying Oracle monthly patch program, adding that Oracle's second monthly Critical Security Patch Update for June 2026 fixes 245 vulnerabilities across Communications, E-Business Suite, Enterprise Manager, Fusion Middleware, JD Edwards, MySQL, PeopleSoft, Siebel CRM, Supply Chain, Systems, and Virtualization, including roughly 120 critical flaws and about 100 remotely exploitable without authentication.
Ionut Arghire 2026.06.02 100%
This article establishes a distinct patching story: Oracle's launch of monthly CSPU releases and the first batch of 77 fixes affecting multiple Oracle product lines.
Full page
Google Chrome 149 security update fixes 429 vulnerabilities, including critical ANGLE and Network bugs
Urgent PatchesZero-Days & CVEsTechnology & SoftwareConsumers & General PublicGoogle
Google released Chrome 149 with fixes for 429 security vulnerabilities, a record-sized browser security update that affects users on Windows, macOS, and Linux. The most severe issue is CVE-2026-10881, a CVSS 9.6 out-of-bounds read/write flaw in the ANGLE graphics engine that could let a remote attacker use a crafted HTML page to escape Chrome’s sandbox and potentially run code on the operating system. Google also fixed critical flaws CVE-2026-10882 in Network and CVE-2026-10883 in ANGLE in versions 149.0.7827.53 for Linux and 149.0.7827.53/54 for Windows and macOS.
Why it matters: Chrome is widely used, so a large set of browser bugs with multiple critical issues can put many users and organizations at risk from malicious websites. Users and administrators should update Chrome promptly across all devices and managed fleets.
Sources
Ionut Arghire 2026.06.17 87%
This is another report on the Chrome 149 security update, adding version details and Google’s advisory breakdown showing 33 newly disclosed security defects in 149.0.7827.155/.156, including seven critical-severity flaws and 26 high-severity bugs, while noting no in-the-wild exploitation was mentioned.
Ionut Arghire 2026.06.12 77%
This article covers the same Chrome 149 security release and adds a narrower breakdown of 28 critical- and high-severity bugs fixed in build 149.0.7827.114/.115, including five critical flaws and a concentration of use-after-free issues, while noting Google has not reported in-the-wild exploitation for these specific bugs.
Ionut Arghire 2026.06.05 100%
This article establishes a new tracked story because it covers a distinct Chrome 149 security release, not the previously tracked Chrome 148 update.
Full page
Mozilla releases Firefox 152 and ESR updates to fix 40 vulnerabilities, including high-severity bugs that could allow code execution
Urgent PatchesConsumers & General PublicTechnology & SoftwareMozilla
Mozilla released Firefox 152, Firefox ESR, Thunderbird, and Firefox for iOS updates to fix 40 security vulnerabilities affecting users across desktop and mobile products. The fixes include 13 high-severity issues such as use-after-free memory bugs, privilege-escalation flaws, sandbox escapes, incorrect boundary conditions, and JIT miscompilation problems; Mozilla said some memory-safety flaws could potentially allow arbitrary code execution.
Why it matters: People and organizations using Firefox or Thunderbird should update promptly because some of the patched bugs could let a malicious website or content run code or break browser protections. This affects both everyday users and enterprises that rely on Firefox ESR for managed deployments.
Sources
Ionut Arghire 2026.06.17 100%
The article establishes a distinct patch story for Mozilla products separate from the already tracked Chrome 149 update, with its own affected products, versions, and vulnerability count.
Full page
CISA adds actively exploited LiteSpeed cPanel plugin flaw CVE-2026-54420 to KEV and orders agencies to patch within 3 days
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareCISALiteSpeedcPanelNamecheapCloudLinux
CISA warned that attackers are actively exploiting another flaw in LiteSpeed’s cPanel user-end plugin and told U.S. federal agencies to secure affected servers within three days. The bug, CVE-2026-54420, affects LiteSpeed cPanel user-end plugin versions before 2.4.8 and can let an attacker who already has FTP access or a web shell (a malicious script that gives remote server control) escalate privileges to root on shared hosting servers running CloudLinux/CageFS; LiteSpeed said exploitation has been seen in the wild and provided log-based detection guidance.
Why it matters: Organizations using affected LiteSpeed cPanel hosting plugins should treat this as urgent because active attackers can turn limited server access into full root control. Update to version 2.4.8 or later immediately and check logs for signs of exploitation.
Sources
Ionut Arghire 2026.06.17 89%
This article adds exploitation context and remediation details for the same LiteSpeed event, including that exploitation has occurred since May, the bug affects user-end cPanel plugin versions before 2.4.8, and attackers with FTP or web-shell access can escalate to root on CloudLinux/CageFS shared hosting servers.
Sergiu Gatlan 2026.06.16 100%
This article establishes a distinct tracked event centered on CVE-2026-54420, a separate actively exploited LiteSpeed cPanel plugin flaw from the previously tracked LiteSpeed cPanel plugin zero-day CVE-2026-48172.
Full page
Attackers use FortiClient EMS zero-day CVE-2026-35616 to push infostealer malware to managed devices
MalwareZero-Days & CVEsUrgent PatchesTechnology & SoftwareFortinet
Attackers are using a critical Fortinet server flaw to send malware to computers managed by FortiClient Endpoint Management Server (EMS). The issue, CVE-2026-35616, is a remote code execution bug in FortiClient EMS that can be exploited without authentication via crafted requests; Fortinet patched it in April after warning it had already been used as a zero-day, and Arctic Wolf now says fresh attacks are abusing EMS scripting workflows to deploy EKZ Infostealer disguised as a Fortinet patch.
Why it matters: This can turn a central management server into a way to infect every device it manages, putting passwords, browser cookies, and other sensitive data at risk. Organizations running FortiClient EMS should patch immediately, check for suspicious PowerShell/script activity, and investigate whether fake update jobs were pushed to endpoints.
Sources
Eduard Kovacs 2026.06.17 34%
The article briefly notes Defused also observed exploitation of FortiClient EMS flaws including CVE-2026-35616, but that is secondary to the main FortiSandbox exploitation update.
Bill Toulas 2026.05.28 99%
This article is the same underlying event and adds specific tradecraft from Arctic Wolf: attackers abused FortiClient EMS endpoint APIs and VPN scripting workflows to deliver the EKZ infostealer, used fortitray.exe and PowerShell to fetch a fake Fortinet update, and left detectable log artifacts such as 'Certificate not found in request header.'
Ionut Arghire 2026.05.28 100%
This article establishes a distinct story by adding concrete post-patch exploitation details for FortiClient EMS CVE-2026-35616, including the malware payload, delivery method through EMS-managed VPN scripting, and the risk of compromise spreading to all managed endpoints.
Arctic Wolf Labs 2026.05.27 97%
This source directly updates the same event by naming the payload as EKZ Infostealer, describing how it was disguised as a Fortinet patch, explaining abuse of EMS policy and remote access profile changes to run malicious PowerShell across managed endpoints, and providing detection details including EMS log artifacts and Tor-linked follow-on activity.
Arctic Wolf Labs 2026.05.27 99%
This directly updates the same event by adding victim-observed tradecraft: attackers exploited CVE-2026-35616 in FortiClient EMS, modified EMS configuration, and delivered a fake Fortinet patch that installed the EKZ Infostealer on managed endpoints via PowerShell. It also adds detection clues from EMS logs and notes follow-on activity from Tor exit nodes.
Full page
Fortinet patches critical FortiSandbox bug CVE-2026-25089 that lets attackers run code without logging in
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareFinance & BankingEnergy & UtilitiesGovernmentFortinetFortiSandbox
Fortinet fixed a critical flaw in FortiSandbox that could let an attacker take over affected appliances over the internet without a password. The bug, CVE-2026-25089, is an OS command injection issue in the FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS web interface, exploitable via crafted HTTP requests for arbitrary command execution. Fixes shipped in FortiSandbox 5.0.6 and 4.4.9, FortiSandbox Cloud 5.0.6, and FortiSandbox PaaS 5.0.6; Fortinet also patched two medium-severity flaws in FortiOS, FortiProxy, and FortiPortal.
Why it matters: Organizations using FortiSandbox should update quickly because this is the kind of bug that can allow full remote compromise of a security appliance. Even though Fortinet says it has no evidence of attacks yet, internet-facing management interfaces are high-risk and should be patched or tightly restricted immediately.
Sources
Eduard Kovacs 2026.06.17 92%
This article updates that story with evidence of active exploitation of CVE-2026-25089 after disclosure, and adds that attackers are also targeting FortiSandbox CVE-2026-39808 and CVE-2026-39813 in the wild.
2026.06.16 96%
This article updates the same underlying event by adding that CVE-2026-25089 is now being actively exploited and linking it with two other critical FortiSandbox flaws, CVE-2026-39813 and CVE-2026-39808, that Defused says are also under attack.
info@thehackernews.com (The Hacker News) 2026.06.16 95%
This article updates the same FortiSandbox event by adding that attackers are exploiting three FortiSandbox flaws, including CVE-2026-25089, and broadens the picture from a single critical patched bug to an active exploitation cluster affecting the same product line.
Sergiu Gatlan 2026.06.16 96%
This updates the same FortiSandbox vulnerability event by adding that CVE-2026-25089 is now being exploited in real attacks, alongside CVE-2026-39813 and CVE-2026-39808, after Fortinet's April patches.
Arctic Wolf Labs 2026.06.15 97%
This source covers the same underlying Fortinet FortiSandbox event and adds defender-focused details on affected version ranges, the likely vulnerable 'start VNC' web UI path, cloud and PaaS scope, and recommended mitigations such as restricting web UI exposure and using WAF rules. It also notes that no active exploitation had been confirmed as of mid-June 2026.
Ionut Arghire 2026.06.10 100%
The article establishes a distinct Fortinet patch event centered on CVE-2026-25089 in FortiSandbox, which is not the same underlying event as any existing tracked story.
Full page
Mini Shai-Hulud supply-chain attack compromises 320+ npm packages in @antv namespace via stolen maintainer account
Threat Actors & APTsSupply ChainMalwareTechnology & SoftwareCryptocurrency & BlockchainnpmGitHubMicrosoft
Researchers say a compromised npm maintainer account ('atool') was used to publish hundreds of malicious package versions across the @antv namespace, including downstream widely used packages such as echarts-for-react and timeago.js. The payload steals GitHub Actions secrets and credentials from cloud, Kubernetes, Vault, wallet, and developer-tool paths, exfiltrates data via GitHub and fallback infrastructure, and can republish tampered packages using stolen npm tokens. Reports also link the campaign to malicious PyPI uploads, a compromised GitHub Action, and a VS Code extension.
Why it matters: This is a high-impact ecosystem compromise with downstream risk to developer workstations, CI environments, and software consumers through trusted package updates. Defenders should immediately identify affected package versions, rotate exposed secrets and npm tokens, review CI runners and GitHub repositories for exfiltration, and block known malicious artifacts.
Sources
2026.06.16 64%
This article updates the broader Shai-Hulud supply-chain campaign by describing copycat worm variants now affecting hundreds of packages and thousands of GitHub repositories, and adds new detail on the GitHub commit-metadata and visibility issues researchers say help the worm evade detection.
2026.06.08 63%
This article ties the Microsoft GitHub repository compromises to the broader Mini Shai-Hulud/Miasma worm ecosystem, adding that a descendant worm was used to push malicious commits into more than 70 Microsoft repositories and break Azure-related CI/CD workflows.
2026.06.01 60%
The article says the Red Hat compromise used a Mini Shai-Hulud variant and notes the malware was recently open-sourced, which connects it technically to the broader Mini Shai-Hulud campaign, but this is a distinct compromise affecting different packages, accounts, and victims.
Ionut Arghire 2026.05.20 100%
The article establishes a distinct new Mini Shai-Hulud campaign centered on a compromised npm maintainer account and malicious releases across the @antv ecosystem, rather than updating one of the existing tracked stories.
2026.05.18 78%
This article extends the same broader Shai-Hulud/TeamPCP npm supply-chain campaign by reporting a copycat worm in a new package (chalk-tempalte) plus three additional malicious npm packages from the same actor, including stealers and a DDoS bot component, shortly after TeamPCP open-sourced the worm.
2026.05.18 41%
The article says the TanStack compromise used code from the Shai-Hulud worm published by TeamPCP, providing additional context on the malware family and tradecraft, but the core event here is the TanStack attack rather than the @antv compromise itself.
Full page
Shai-Hulud supply-chain attack trojanizes 19 PyPI bioinformatics packages to steal developer and cloud secrets
MalwareSupply ChainTechnology & SoftwareHealthcareEducationPyPIGitHubnpmAmazon Web ServicesGoogle CloudMicrosoft
Attackers compromised 19 Python packages on PyPI, including popular science and bioinformatics tools, and planted malware that can steal secrets from developer machines and continuous integration systems. Socket linked the activity to the broader Shai-Hulud campaign and said 37 malicious releases used executable .pth startup hooks to trigger code when Python starts, then fetched the Bun JavaScript runtime to run an obfuscated payload that targeted GitHub, npm, PyPI, AWS, GCP, Azure, Kubernetes, SSH, Docker, Vault, and Claude/MCP credentials.
Why it matters: Developers, researchers, and organizations using these packages may have had passwords, tokens, and cloud keys stolen without obvious signs. Anyone who installed affected versions should treat the environment as compromised, rotate secrets, and rebuild from known-good backups.
Sources
2026.06.16 93%
This is a direct update on the same underlying Shai-Hulud supply-chain worm campaign, adding scope estimates of 516 live malicious packages across five ecosystems, more than 3,000 affected repositories, over 200 compromised developer accounts, and details about how GitHub metadata handling aided evasion.
Bill Toulas 2026.06.10 55%
The source describes Miasma as an evolution of the earlier Shai-Hulud worm and notes that the earlier leak helped drive more advanced variants, making this a meaningful follow-on development in the same malware lineage affecting package ecosystems.
Ionut Arghire 2026.06.09 97%
This article is a direct expansion of the same Shai-Hulud malware campaign, adding that new Miasma and Hades variants spread across both npm and PyPI from June 1, hit over 100 packages and 471 malicious artifacts, and used updated loader and evasion techniques while continuing credential theft and self-propagation.
Bill Toulas 2026.06.08 100%
This article establishes a distinct new Shai-Hulud campaign on PyPI, separate from the previously tracked npm-focused Shai-Hulud incident.
Full page
Fake recruiter used a malicious GitHub repo and npm install hook to target a developer with backdoor malware
Supply ChainSocial Engineering & PhishingMalwareTechnology & SoftwareCryptocurrency & BlockchainGitHubHetznerLinkedIn
A developer says a supposed recruiter tried to trick him into reviewing a booby-trapped code repository that would have infected his system. The attack used a GitHub-hosted Node.js project whose package.json contained a prepare post-install hook, so running npm install would execute app/test/index.js; that script used an obfuscated URL and remote command execution logic to fetch and run attacker-supplied code.
Why it matters: This is a real-world example of job-lure social engineering aimed at developers, where normal review steps like cloning a repo and installing dependencies can trigger compromise. Developers and employers should treat unsolicited coding tests and recruiter-supplied repositories as high risk, inspect package scripts before running them, and use isolated analysis environments.
Sources
2026.06.16 100%
This article establishes a distinct incident: a specific recruiter-lure campaign against a named developer using a malicious repository and npm lifecycle hook, rather than updating one of the already tracked package or repository compromise stories.
2026.06.16 99%
This is the same underlying incident: Python developer Roman Imankulov was approached by a fake recruiter and sent a booby-trapped repository whose package.json prepare hook would execute a backdoor on npm install. The article adds details about the malicious file path (app/test/index.js), the obfuscated server URL, the use of a Hetzner VPS for safe analysis, and that an AI coding agent flagged the backdoor before execution.
Full page
Steam Workshop malware campaign used Wallpaper Engine uploads to infect users with stealers, backdoors, miners, and ransomware
MalwareSocial Engineering & PhishingConsumers & General PublicValveSteamWallpaper Engine
Attackers used Steam Workshop uploads for the Wallpaper Engine app to trick Steam users into installing malicious wallpapers. Kaspersky says the abuse has been active since at least late 2025 and relies on Wallpaper Engine's 'application wallpaper' feature, which can run Windows executables as desktop backgrounds. Researchers found dozens of malicious uploads delivering DarkKomet, Lumma, Vidar, cryptominers, botnet loaders, RanEngine, and some ransomware, with some downloads reaching the thousands or tens of thousands before Valve removed the identified items.
Why it matters: This matters to Steam users because installing what looks like harmless custom content can lead to stolen game accounts or full device compromise. Users who installed Wallpaper Engine content from Steam Workshop should review their systems for malware, change Steam credentials, and be cautious with executable community uploads.
Sources
Bill Toulas 2026.06.16 100%
This article establishes a distinct malware-distribution story centered on Steam Workshop and Wallpaper Engine, not a follow-up to an existing tracked event.
Full page
iRhythm says social-engineering breach let hackers steal patient health information from third-party business apps
HealthcareBreaches & Data LeaksSocial Engineering & PhishingScams & FraudHealthcareiRhythm
iRhythm disclosed a data breach after hackers stole patient personal and health information from business applications hosted by a third party. The company said the attackers contacted it on June 9, 2026 with a ransom demand and it later confirmed data was exfiltrated; iRhythm says the intrusion involved social engineering and did not affect its cardiac monitoring devices, clinical systems, payment-card data, manufacturing, or distribution operations.
Why it matters: This affects healthcare patients whose protected health information may now be exposed or used in scams and identity abuse. Healthcare organizations and vendors should review third-party app access, harden staff against social-engineering attacks, and watch for follow-on extortion or phishing tied to stolen patient data.
Sources
Eduard Kovacs 2026.06.16 97%
This article is a direct update on the same iRhythm incident and adds that the company has now confirmed some data was actually stolen after initially disclosing the social-engineering breach involving third-party-hosted business applications and a ransom demand.
2026.06.16 99%
This article reports the same incident and adds details from iRhythm's SEC filing: unauthorized activity was detected June 8, the extortion message arrived June 9, the company deemed the incident material on June 10, and iRhythm says clinical systems, medical devices, and customer connections were not accessed.
Sergiu Gatlan 2026.06.16 100%
This article appears to be the first tracked disclosure of iRhythm's own breach event, including the company’s SEC filing, attack vector, and confirmation that patient data was exfiltrated.
Full page
Novo Nordisk says attackers stole pseudonymized clinical-trial patient data and healthcare professional contact details
Breaches & Data LeaksScams & FraudSocial Engineering & PhishingHealthcareNovo NordiskGitHub
Novo Nordisk disclosed a security breach in which attackers copied non-public data from internal IT systems, including information tied to some clinical-trial participants and healthcare professionals. The exposed trial data included patient IDs, participation details, sex, year of birth, biomarkers, health and immunogenicity data, and lifestyle factors; the company said it was pseudonymized and not directly linked to names. Exposed healthcare professional data included names, registration numbers, email addresses, phone numbers, WhatsApp details, and office locations. Novo Nordisk has not said how many people were affected or how the intrusion happened.
Why it matters: This affects sensitive health-related research data and gives attackers contact details they can use for follow-on phishing or impersonation. Affected organizations and individuals should watch for suspicious emails, calls, and WhatsApp messages while Novo Nordisk investigates scope and attack path.
Sources
Ionut Arghire 2026.06.16 95%
This article updates the same Novo Nordisk breach by adding that FulcrumSec claims responsibility, says it used a GitHub access token in March to clone repositories and obtain more credentials, alleges theft of 1.3TB and over 700,000 files including intellectual property, and says it demanded a $25 million ransom.
Eduard Kovacs 2026.06.15 98%
This article is a direct report of the same Novo Nordisk breach, adding that the company says attackers accessed a limited number of internal IT systems and exposed pseudonymized clinical-trial participant data plus healthcare professional contact details, with no direct identifiers disclosed.
2026.06.12 99%
This article is the same underlying event and adds concrete details about the stolen data fields: pseudonymized clinical-trial participant information, affected internal IT systems taken offline, and a separate warning that healthcare professional contact details could be used for targeted phishing via email, phone, and WhatsApp.
Sergiu Gatlan 2026.06.12 100%
This article is the initial public disclosure of Novo Nordisk's breach and establishes the core facts of the incident, including the affected data types and the warning about phishing risks for healthcare professionals.
Full page
White House memo NSPM-12 reestablishes CNSS and gives NSA a stronger role in securing U.S. national security systems
Policy & RegulationGovernmentDefense & AerospaceWhite HouseNSA
The White House issued a new directive to strengthen cybersecurity for the U.S. government's most sensitive national security systems, including systems used for classified information and military or intelligence support. National Security Presidential Memorandum-12 (NSPM-12) reestablishes the Committee on National Security Systems (CNSS), assigns the National Security Agency a central National Manager role, authorizes emergency directives, and requires agencies to maintain inventories of the national security systems they own or operate.
Why it matters: This matters because it changes how the federal government governs and responds to cyber risk on its most sensitive systems, especially at civilian agencies handling national security workloads. Government defenders should expect updated baseline requirements, new oversight, and possible emergency directives in the next few months.
Sources
Ionut Arghire 2026.06.16 100%
The article is the announcement of the underlying policy event itself: issuance of NSPM-12 to restructure oversight and accountability for national security system cybersecurity.
Full page
EFF says police used Flock Safety license plate reader data for school residency checks, background screening, and minor complaints
Policy & RegulationSurveillance & PrivacyGovernmentEducationTechnology & SoftwareConsumers & General PublicFlock SafetyEFF
EFF says police agencies searched Flock Safety automated license plate reader databases for routine matters far beyond serious criminal investigations, including school residency verification, employment background checks, and noise complaints. Based on analysis of millions of audit-log searches, the report says some agencies queried plates across thousands of shared camera networks nationwide, exposing detailed location histories without a warrant requirement and showing broad mission creep in how ALPR (automated license plate reader) data is used.
Why it matters: This matters to the public because a system marketed for crime-solving is being used to track ordinary people’s movements for low-level administrative and quality-of-life issues. It raises immediate privacy and civil-liberties concerns for anyone whose vehicle data may be swept into shared ALPR networks, and it increases pressure for warrant limits, access controls, and retention safeguards.
Sources
Bruce Schneier 2026.06.16 84%
This is the same underlying story of misuse of Flock Safety surveillance data by police, adding another documented abuse pattern: officers allegedly using the system to stalk people for personal reasons.
Hudson Hongo 2026.06.10 79%
This newsletter item recaps and amplifies EFF's reporting on ALPR mission creep, specifically that license plate reader systems are being used for low-level matters such as noise complaints and other minor investigations rather than only serious crime.
Rindala Alajaji 2026.05.26 100%
This article establishes a distinct surveillance/privacy story centered on EFF's new findings about Flock Safety ALPR mission creep and the warrantless use of location data for non-criminal purposes.
Full page
Atomic Arch supply-chain attack floods Arch Linux AUR with 1,500 malicious packages
Supply ChainMalwareTechnology & SoftwareConsumers & General PublicArch Linux
Attackers uploaded more than 1,500 malicious packages to Arch Linux’s user-run AUR repository, putting users at risk if they installed poisoned software. Arch Linux suspended new AUR account registrations while cleaning up the ongoing 'Atomic Arch' campaign. Researchers say attackers first modified abandoned packages, then added new ones, using altered PKGBUILD install scripts to fetch malicious npm and later Bun-based components that appear designed to steal credentials, SSH artifacts, Vault tokens, browser cookies, and to gain stealthy persistence through eBPF, a Linux kernel technology.
Why it matters: Arch Linux users who installed affected AUR packages should treat those systems as fully compromised, rebuild from clean media, and rotate credentials and secrets. This matters because AUR is widely used for unofficial software and the malware appears built for stealth, persistence, and secret theft rather than a one-off nuisance.
Sources
Ionut Arghire 2026.06.16 100%
This article establishes a distinct large-scale AUR supply-chain compromise affecting Arch Linux packages, separate from the previously tracked story about 400 hijacked Arch Linux AUR packages.
Full page
China-linked Earth Lusca used new Windows SprySOCKS malware variants against government organizations in four countries
Threat Actors & APTsMalwareGovernmentTechnology & SoftwareTelecommunications
Researchers say a China-linked hacking group used new Windows versions of the SprySOCKS backdoor to attack government organizations in Taiwan, Thailand, Pakistan, and Honduras. ESET attributes the activity to Earth Lusca, also tracked as FishMonger, and says the malware includes two Windows variants, WIN_DRV and WIN_PLUS, with capabilities such as file theft, keylogging, process control, SOCKS proxying, and stealth features through a kernel driver. The more advanced variant also used a driver signed with a leaked certificate from the PastDSE project, and ESET saw signs of a possible UEFI bootkit component linked to CVE-2023-24932, though that part was not confirmed.
Why it matters: This matters because it shows a state-linked espionage group expanding from Linux to Windows with stealthier tools for long-term access to government networks. Government, foreign-affairs, technology, and telecom defenders should hunt for the published indicators of compromise, review persistence mechanisms such as scheduled tasks and print processors, and check for Secure Boot-related abuse.
Sources
info@thehackernews.com (The Hacker News) 2026.06.16 97%
The article appears to cover the same underlying event: reporting that the China-linked Earth Lusca campaign expanded SprySOCKS to Windows and used driver-based stealth against government targets in multiple countries, adding technical detail on the Windows backdoor variant.
Bill Toulas 2026.06.16 100%
This article appears to be the first tracked item centered on Earth Lusca's newly reported Windows SprySOCKS variants and their use against government targets in four countries.
Full page
Cisco patches exploited Catalyst SD-WAN Manager zero-day CVE-2026-20262 that can lead to root access
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareTelecommunicationsGovernmentCiscoCISA
Cisco released fixes for a zero-day in Catalyst SD-WAN Manager that attackers were already using to gain deeper control of vulnerable systems. The flaw, CVE-2026-20262, affects SD-WAN vManage deployments including on-prem, Cloud, Cloud-Pro, and FedRAMP environments. Cisco says an authenticated remote attacker can abuse insufficient input validation in a file-upload API to create or overwrite files, then escalate privileges to root. Fixed releases include 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2.
Why it matters: Organizations using Cisco SD-WAN management systems should treat this as urgent because it was exploited before patches were available and can lead to full system compromise. Update immediately and review Cisco's indicators of compromise, especially file-upload attempts involving index.jsp and .war files in vmanage logs.
Sources
Eduard Kovacs 2026.06.16 98%
This article is a direct report on the same event, adding that Cisco described the bug as an arbitrary file write in an affected API endpoint, said exploitation was seen in limited attacks in June 2026, and noted CISA's June 29 federal remediation deadline.
2026.06.15 98%
This article reports the same underlying event: Cisco's patch for actively exploited Catalyst SD-WAN Manager flaw CVE-2026-20262, including that exploitation was observed in June 2026, the bug affects the web UI file-upload path, requires valid low-privilege credentials, and was added to CISA's KEV catalog with a federal patch deadline.
Sergiu Gatlan 2026.06.15 100%
This article establishes a distinct newly patched Cisco SD-WAN zero-day event centered on CVE-2026-20262, which is separate from the already tracked unpatched Catalyst SD-WAN Manager zero-day CVE-2026-20245.
Full page
CISA adds exploited LiteSpeed cPanel plugin zero-day CVE-2026-48172 to KEV and urges immediate removal or patching
Urgent PatchesZero-Days & CVEsTechnology & SoftwareGovernmentCISALiteSpeedcPanel
CISA says a critical bug in the LiteSpeed user-end plugin for cPanel is being actively exploited and can give attackers root-level control of affected servers. The flaw, CVE-2026-48172, is a 9.8-severity privilege-escalation vulnerability affecting user-end plugin versions 2.3 through 2.4.4; LiteSpeed fixed it in version 2.4.5, later bundled in WHM Plugin 5.3.1.0 with user-end plugin 2.4.7, while cPanel also removed the vulnerable plugin via a nightly update on May 19.
Why it matters: Organizations running cPanel with the LiteSpeed user-end plugin could be exposed to full server compromise, so this is an update-now or remove-now situation. Admins should upgrade immediately, remove the plugin if they cannot patch, and review logs and suspicious IP activity for signs of exploitation.
Sources
info@thehackernews.com (The Hacker News) 2026.06.16 99%
This article appears to cover the same underlying event: CISA flagging active exploitation of the LiteSpeed user-end plugin for cPanel flaw CVE-2026-48172 and urging defenders to patch or remove the affected plugin because attackers can gain root privileges.
Sergiu Gatlan 2026.05.27 98%
This article covers the same underlying event—active exploitation of LiteSpeed cPanel plugin flaw CVE-2026-48172 and CISA's KEV action—and adds the concrete BOD 22-01 deadline giving U.S. federal agencies four days, until May 29, 2026, to patch or discontinue use.
Ionut Arghire 2026.05.27 100%
This article establishes a new tracked story centered on CVE-2026-48172: an actively exploited LiteSpeed cPanel plugin zero-day, its vendor fix, cPanel mitigation, and CISA KEV listing.
Full page
Estonia will quarantine emails from Russian .ru domains before they reach government officials
Policy & RegulationSocial Engineering & PhishingGovernmentGovernmentEstonian governmentEstonian Ministry of Justice and Digital AffairsKAPO
Estonia says emails sent from Russian .ru addresses to government officials will be automatically isolated for extra screening before recipients can open them. The policy takes effect August 31 and adds .ru domains to the Estonian public sector's existing email quarantine rules for suspicious messages. Officials say the move responds to increased phishing and malware delivery from Russian servers since 2022 and is part of broader defenses against Russian hybrid threats.
Why it matters: This affects how Estonian public institutions handle potentially hostile communications and could reduce phishing and malware exposure for government staff. Organizations and individuals that use .ru email addresses to contact Estonian authorities may need to switch providers, and defenders should note the policy as a concrete state response to sustained Russian cyber risk.
Sources
2026.06.15 100%
This article establishes a new tracked story because it introduces a specific new Estonian government email-screening policy tied to Russian cyber and phishing risk, rather than updating any existing tracked event.
Full page
DOJ seizes CFAKE and SOCFAKE deepfake porn sites in first publicly announced TAKE IT DOWN Act action
Policy & RegulationDisinformation & Influence OpsScams & FraudConsumers & General PublicDOJHomeland Security Investigations
The U.S. Justice Department seized CFAKE.com and SOCFAKE.com, two sites accused of hosting nonconsensual AI-generated nude images and videos of identifiable women. U.S. authorities said the domains violated the TAKE IT DOWN Act, which criminalizes publication of intimate digital forgeries without consent and requires platforms to remove reported content within 48 hours. The operation involved Homeland Security Investigations and law-enforcement partners in Italy and France, and French authorities arrested a suspect in Nice and seized related cryptocurrency.
Why it matters: This shows the TAKE IT DOWN Act is now being used in real enforcement, which matters to victims, platforms that host user content, and anyone tracking abuse enabled by generative AI. Platforms should review takedown processes and compliance timelines, while users should report nonconsensual deepfake imagery quickly.
Sources
Lawrence Abrams 2026.06.15 100%
This article appears to be the first concrete enforcement action centered on the TAKE IT DOWN Act and establishes a distinct story about seizure of specific deepfake abuse domains.
Full page
Fake breach notices were posted on Maine’s official disclosure portal using the names of VRChat and Discord
Breaches & Data LeaksDisinformation & Influence OpsPolicy & RegulationSurveillance & PrivacyGovernmentTechnology & SoftwareConsumers & General PublicMaine Attorney GeneralVRChatDiscordMaine Attorney General's Office
Fraudulent data-breach notices were submitted to Maine’s public breach portal and published as if they were real, falsely claiming incidents at VRChat and Discord. VRChat told BleepingComputer the filing was fake and used a nonexistent employee name, while Maine’s Attorney General office said notices can be posted without prior verification and that the VRChat entry would be removed. The incident appears to be abuse of a government disclosure system rather than a confirmed breach of the named companies.
Why it matters: This can mislead users, investors, journalists, and incident responders by making fake breaches look official. Organizations should monitor state breach portals for false filings in their name, and users should wait for confirmation from the affected company before reacting to reported breaches.
Sources
2026.06.15 94%
This article updates the same underlying event by reporting Maine's response: the state has taken the public breach portal offline, confirmed the VRChat and Discord notices were hoaxes, and said it is auditing procedures before restoring public access.
Eduard Kovacs 2026.06.15 96%
This article adds that the Maine Attorney General temporarily disabled the public breach portal because of the hoax VRChat and Discord submissions, and confirms the state is reviewing procedures before restoring the database.
Lawrence Abrams 2026.06.12 97%
This updates the same underlying event by adding Maine's official response: the attorney general confirmed the VRChat and Discord notices were hoaxes, removed them, and temporarily disabled public access to the breach portal while reviewing its publication procedures.
Bill Toulas 2026.06.11 100%
This article establishes a distinct story about abuse of Maine’s breach-reporting portal to publish unverified and false disclosures, with VRChat and Discord cited as early known examples.
Full page
University of Nottingham confirms data breach after ShinyHunters leaks student and alumni records
Threat Actors & APTsBreaches & Data LeaksZero-Days & CVEsEducationUniversity of NottinghamShinyHuntersOracle
The University of Nottingham says hackers stole a significant amount of data from its student record system, affecting current students and alumni. SecurityWeek reports ShinyHunters claimed responsibility and published stolen files; Have I Been Pwned found about 455,000 unique email addresses in the leak along with names, usernames, addresses, phone numbers, passport numbers, gender, ethnicity, disability information, citizenship status, academic enrollment details, and fee-payment data.
Why it matters: This exposure includes highly sensitive identity and education records that could fuel phishing, fraud, and identity theft against students and graduates. Affected people should watch for targeted messages, reset reused passwords, and monitor accounts and identity documents, while universities should review access to student-record systems and breach-notification steps.
Sources
2026.06.15 63%
The article connects the Nottingham breach to the same underlying Oracle PeopleSoft exploitation campaign by ShinyHunters, clarifying that Nottingham was one of the 100+ victims hit via CVE-2026-35273.
2026.06.11 98%
This source directly updates the same incident with the university's confirmation that a significant amount of data was accessed, adds suspected categories of exposed information, and cites Have I Been Pwned analysis indicating about 455,000 unique email addresses and extensive personal data in the leaked sample.
Eduard Kovacs 2026.06.11 100%
This article establishes a distinct breach event: the university itself confirms unauthorized access to its student record system after ShinyHunters leaked stolen data, with scope and affected data types now concretely described.
Full page
ShinyHunters claims breach of the Council of Europe and threatens to leak employee, payroll, and medical data
Threat Actors & APTsBreaches & Data LeaksGovernmentHealthcareCouncil of EuropeOracle
ShinyHunters says it hacked the Council of Europe and stole 297 GB of internal data, including employee personal, payroll, and health information. The extortion group posted the organization on its leak site and claims to have exfiltrated more than 429,000 files from departments including HR, the Secretariat, the Parliamentary Assembly, and the European Directorate for the Quality of Medicines & HealthCare. The Council of Europe had not publicly confirmed the incident at the time of publication.
Why it matters: If true, this would expose highly sensitive personal and employment records tied to a major intergovernmental human-rights body, creating identity-theft, privacy, and targeting risks for staff. Affected users should watch for official breach notices and phishing, while defenders should treat this as a potentially serious extortion and data-exfiltration incident.
Sources
2026.06.15 97%
This is a direct update to the Council of Europe breach story, adding that ShinyHunters says the intrusion was part of its broader Oracle PeopleSoft zero-day campaign and specifying the alleged volume and types of stolen files.
Sergiu Gatlan 2026.06.15 97%
This article updates the same underlying event by adding that the Council of Europe has acknowledged it is investigating ShinyHunters' breach claims, while restating the gang's alleged scope of stolen HR, payroll, and medical records and the leak deadline.
Ionut Arghire 2026.06.15 100%
This article appears to be the first concrete report of the claimed Council of Europe intrusion, naming the victim, threat actor, alleged data types, and extortion deadline.
Full page
FBI warns pig-butchering scammers are sending couriers to collect cash from victims in person
Scams & FraudSocial Engineering & PhishingConsumers & General PublicFinance & BankingCryptocurrency & BlockchainFBI
The FBI says cryptocurrency investment scammers are now sending couriers to pick up cash directly from victims after banks or other financial institutions block suspicious transfers. The agency says the fraudsters, often running pig-butchering or romance-baiting scams through social media, dating sites, and messaging apps, authenticate the courier with a password or U.S. dollar bill serial number, then continue the scam by showing fake account gains and demanding more money for bogus taxes or penalties.
Why it matters: This matters because victims may believe an in-person handoff makes the investment scheme legitimate when it is part of the fraud. Consumers should not hand cash to strangers tied to online investment offers, and banks, local police, and fraud teams should watch for courier-based cash collection linked to crypto scams.
Sources
Sergiu Gatlan 2026.06.15 100%
This article establishes a distinct FBI warning about a specific scam technique: courier-based in-person cash pickups used in pig-butchering and related cryptocurrency investment fraud.
Full page
Microsoft fixed critical Microsoft 365 Copilot flaw CVE-2026-42824 that let one click steal mailbox and SharePoint data
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareConsumers & General PublicMicrosoftBing
Microsoft patched a critical flaw in Microsoft 365 Copilot Enterprise that could let an attacker steal sensitive data from a user's email, OneDrive, SharePoint, and calendar after the user clicked a crafted link. The issue, CVE-2026-42824, was demonstrated as a three-part attack chain dubbed SearchLeak that combined parameter-to-prompt injection, an HTML rendering race condition, and a Bing server-side request forgery (SSRF) path to bypass content security protections and exfiltrate Copilot search results.
Why it matters: Organizations using Microsoft 365 Copilot Enterprise could have had internal data quietly siphoned out through normal-looking links, with little visible sign to the victim. The fix is already available, so defenders should verify Microsoft 365 Copilot protections are current and review for suspicious link-based abuse involving Copilot, Bing, OneDrive, SharePoint, and Exchange data.
Sources
info@thehackernews.com (The Hacker News) 2026.06.15 99%
The article appears to cover the same underlying event: Microsoft's fix for CVE-2026-42824 in Microsoft 365 Copilot, described here as a one-click flaw that could expose emails, files, and one-time MFA codes.
Bill Toulas 2026.06.15 100%
This article appears to be the initial report establishing a distinct tracked story around CVE-2026-42824 and the SearchLeak attack chain in Microsoft 365 Copilot Enterprise.
Full page
Cyberattack on Astral disrupted tax reporting and business services for Russian government and enterprise customers
MalwareGovernmentFinance & BankingTechnology & SoftwareTransportation & LogisticsAstralRussian PostMosgortrans
Russian software company Astral said a cyberattack knocked multiple services offline for about a week, disrupting customers that depend on its tools for tax reporting, electronic document management, cash-register operations, and digital-certificate logins. Astral said Russian government agencies are investigating, that it is restoring systems only after security reviews, and that it found no evidence so far of customer-data theft. The company did not name an attacker or disclose technical details about the intrusion.
Why it matters: This is a significant service-disruption incident affecting organizations that rely on Astral for core business and government workflows, even without confirmed data theft. Customers should review continuity plans, monitor vendor guidance, and verify the integrity of certificate-based access and connected business processes as services return.
Sources
2026.06.15 100%
This article appears to be the first tracked report establishing the underlying event: a June 2026 cyberattack on Astral that caused prolonged outages across services used by Russian businesses and government entities.
Full page
More than 400 Arch Linux AUR packages were hijacked to install a Linux rootkit and credential-stealing malware
Supply ChainBreaches & Data LeaksMalwareTechnology & SoftwareConsumers & General PublicArch Linuxnpm
More than 400 community packages for Arch Linux were modified to infect users with malware that steals passwords, tokens, and developer secrets. The attack hit the Arch User Repository (AUR), where a spoofed maintainer and hijacked orphaned packages were used to add install scripts that fetched a malicious npm package named atomic-lockfile. Researchers say the payload includes a Linux infostealer and optional eBPF rootkit features, with theft targets including GitHub, npm, SSH, HashiCorp Vault, Docker, browser cookies, and Slack, Discord, Teams, and Telegram data.
Why it matters: Arch users and developers who installed affected AUR packages may have exposed account credentials and system access, especially on developer workstations and build environments. Review the affected package list and indicators of compromise, remove malicious packages, rotate exposed secrets, and investigate for root-level persistence.
Sources
2026.06.15 95%
This is a direct update on the same AUR compromise event, adding that the number of affected packages grew from about 400 to more than 1,500, that a more sophisticated second wave appeared on June 14, that the malicious packages tried to pull hostile npm JavaScript dependencies, and that Arch Linux disabled new AUR account registrations during cleanup.
info@thehackernews.com (The Hacker News) 2026.06.12 99%
This article appears to report the same underlying event: hijacked Arch Linux AUR packages used to distribute an infostealer and an eBPF rootkit to users who installed the compromised packages.
info@thehackernews.com (The Hacker News) 2026.06.12 99%
This is the same underlying event: a mass compromise of 400+ Arch Linux AUR packages to deliver malware. This source appears to add that the payload was described as a Rust-based credential stealer, but it does not establish a distinct incident.
Bill Toulas 2026.06.12 100%
This article establishes a distinct software supply-chain incident centered on the Arch User Repository, with a defined infection chain, named malicious package, and broad package-compromise scope not covered by the existing tracked stories.
Full page
Finland charges Fitburg cargo ship officers over damage to Baltic Sea telecommunications cables
Information FreedomTelecommunicationsFinnish Prosecution ServiceFinnish CustomsNATO
Finland has charged two officers of the cargo ship Fitburg over damage to submarine telecommunications cables in the Baltic Sea. Prosecutors say the captain and bosun damaged two subsea telecom cables and attempted to damage eight other subsea connections after the vessel dragged a damaged anchor along the seabed for at least 130 kilometers on New Year’s Eve. The case will also test whether Finland can prosecute incidents that occurred outside its territorial waters.
Why it matters: Subsea cables carry critical internet and communications traffic, so damage to them can disrupt connectivity and raise sabotage concerns even when intent is disputed. The case matters for governments, telecom operators, and the public because it could shape accountability and deterrence for future cable-damage incidents in European waters.
Sources
2026.06.15 100%
This article establishes a distinct tracked story because it reports new criminal charges against officers of the Fitburg over a specific 2025 Baltic Sea cable-damage incident, separate from the earlier Eagle S case.
Full page
Ukrainian man pleads guilty in U.S. over role in Conti ransomware attacks
Threat Actors & APTsMalwareRansomwareDOJFBI
A Ukrainian national has pleaded guilty in the United States for helping carry out Conti ransomware attacks that hit victims in the U.S. and other countries. The Justice Department said Oleksii Lytvynenko admitted joining the Conti conspiracy in 2021, possessing data stolen from 12 victims, and helping code a loader, malware used to install tools needed for ransomware intrusions. Prosecutors say Conti targeted more than 1,000 victims worldwide and collected over $150 million before the group fragmented in 2022.
Why it matters: This matters because Conti was one of the most damaging ransomware groups of its era, and the case adds concrete attribution and operational detail defenders can use to understand how these attacks were carried out. It also shows continued law-enforcement pressure on the people behind major ransomware campaigns and their successor groups.
Sources
Ionut Arghire 2026.06.15 99%
This article is a direct report of the same event and adds specifics that Oleksii Oleksiyovych Lytvynenko admitted developing a loader for Conti, joined the operation in September 2021, possessed data from 12 victims including eight in the U.S., and faces sentencing on September 10, 2026.
Lawrence Abrams 2026.06.12 100%
This article establishes a distinct tracked development centered on a guilty plea by a named Conti operator, rather than updating an existing story in the tracker about a different actor, breach, or takedown.
Full page
French government says Tchap messaging service was breached through a hijacked user account
Social Engineering & PhishingBreaches & Data LeaksSurveillance & PrivacyGovernmentEducationTchapDINUMANSSICNILFrench government
France's government says an attacker got into Tchap, the encrypted messaging service used by public-sector workers, by taking over a valid user account. DINUM said ANSSI detected the intrusion on June 8 and blocked the compromised account, while investigators review logs to determine what conversations and data were accessed or stolen. A threat actor claimed the access came from social engineering on an education-related Tchap shard and alleged theft of 13.5GB of files, roughly 650,000 messages, and data on more than 73,000 accounts, plus a flaw allowing shared media files to be downloaded without a token.
Why it matters: This affects a government communications platform with more than 300,000 monthly users, so exposed chats, files, and account metadata could have broad public-sector impact. French agencies and users should treat the incident as potentially sensitive, review what was shared in public rooms, investigate account takeover paths, and reset or harden credentials where appropriate.
Sources
Kevin Townsend 2026.06.15 98%
This article covers the same June 2026 Tchap breach and adds reporting that French officials said about 73,467 government accounts were affected, while the 'misere' actor claimed theft of 13.5GB of files and more than 643,000 messages.
Sergiu Gatlan 2026.06.12 98%
This article clearly updates the same Tchap breach, adding the affected-account count (73,467), confirming that public chat-room data rather than private encrypted conversations was exposed, and describing the categories of data potentially accessed, including names, email addresses, avatars, organizations, and allegedly device metadata and files.
2026.06.09 98%
This article appears to cover the same Tchap incident and adds details that ANSSI detected suspicious activity on June 7, DINUM says only public chat rooms were exposed, CNIL was notified, and the alleged attacker claims much broader access including tens of thousands of accounts, hundreds of thousands of messages, and possible exposure via directory search.
Sergiu Gatlan 2026.06.09 100%
This article establishes a new tracked story by identifying a specific intrusion into France's Tchap government messaging platform, including the access method, affected service, and preliminary scope of potentially exposed data.
Full page
Palo Alto says attackers are exploiting GlobalProtect VPN auth bypass flaw CVE-2026-0257
Zero-Days & CVEsUrgent PatchesThreat Actors & APTsTechnology & SoftwareConsumers & General PublicPalo Alto NetworksCISA
Palo Alto Networks says attackers are now using a GlobalProtect VPN flaw to try to get into corporate networks without valid credentials. The issue, CVE-2026-0257, affects PAN-OS GlobalProtect portal and gateway configurations that use authentication override cookies with specific certificate reuse; attackers can forge those cookies and establish unauthorized VPN access on unpatched devices. Rapid7 says it saw exploitation from at least May 17, 2026, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog.
Why it matters: Organizations that use Palo Alto GlobalProtect could be exposed to unauthorized remote access into internal networks, so this is an urgent patch-now issue. Defenders should update PAN-OS immediately and, if needed, disable authentication override cookies or use a separate certificate for that feature.
Sources
info@thehackernews.com (The Hacker News) 2026.06.15 99%
This is the same underlying event: Palo Alto warning that attackers are actively exploiting the PAN-OS GlobalProtect VPN authentication-bypass flaw CVE-2026-0257 on affected systems.
Arctic Wolf Labs 2026.06.11 97%
This directly updates the same CVE-2026-0257 exploitation story by adding observed timing of exploitation waves, the role of published exploit code, required configuration conditions, and follow-on activity including IPSec tunnel establishment and Impacket-style SMB/NTLM reconnaissance after successful bypass.
2026.06.01 98%
This article is the same underlying event and adds specifics that Rapid7 observed successful exploitation in multiple customer environments as early as May 17, saw attackers establish unauthorized VPN sessions, and notes the flaw has been added to CISA's KEV catalog with a federal patch deadline.
Ionut Arghire 2026.06.01 97%
This directly updates the same CVE-2026-0257 event by adding that exploitation began on May 17, four days after disclosure; describing Rapid7's observed waves from Vultr and Dromatics Systems; noting forged-cookie abuse and partial VPN session establishment; and pointing defenders to Rapid7's PoC scanner and indicators of compromise.
Lawrence Abrams 2026.05.30 100%
This article establishes a new tracked event by confirming active exploitation of Palo Alto PAN-OS GlobalProtect CVE-2026-0257 and linking it to urgent mitigation and KEV listing.
Full page
Belarus-linked GhostWriter uses fake Prometheus training certificates to phish Ukrainian government officials
Threat Actors & APTsMalwareSocial Engineering & PhishingGovernmentEducationMedia & EntertainmentCERT-UAPrometheusCERT PolskaGoogle
Belarus-linked hackers are sending fake course-certificate emails to Ukrainian government staff to infect their computers with espionage malware. CERT-UA says the campaign, active since spring 2026, uses compromised email accounts and messages posing as Ukraine’s Prometheus learning platform; a PDF leads victims to a ZIP that installs OysterFresh, then OysterBlues and OysterShuck, which collect host and user details and may later deliver Cobalt Strike.
Why it matters: This is a targeted government espionage campaign, so affected organizations should treat related Prometheus certificate emails as suspicious, hunt for the named malware and infrastructure, and isolate infected systems quickly. For users, the practical takeaway is not to open certificate attachments or download archives from unexpected training-platform emails, even if they come from known contacts.
Sources
2026.06.14 68%
This is the same broader GhostWriter phishing activity by the Belarus-linked actor, but it describes a distinct campaign shift: targeting personal Gmail accounts of Polish public figures and their families since March, using newly registered phishing domains almost daily and seeking credentials plus two-factor authentication codes.
2026.05.21 100%
The article establishes a distinct CERT-UA-attributed GhostWriter espionage operation using fake Prometheus certificate lures and the OysterFresh malware chain against Ukrainian officials.
Full page
Former Saydel school district IT worker jailed after using stored credentials to sabotage Google, Apple, and Schoology systems
Breaches & Data LeaksThreat Actors & APTsEducationGovernmentSaydel Community School DistrictAppleGooglePowerSchoolGoDaddySchoology
A former IT employee was sentenced after repeatedly breaking into Iowa's Saydel Community School District and disrupting school systems for more than a year after being fired. Prosecutors said he kept more than 300 district usernames and passwords, then used that access between May 2023 and January 2025 to delete the district's Facebook page, tamper with Apple School Manager, access Google and Gmail accounts, and delete Schoology and Gmail accounts, causing teaching disruptions and remediation costs.
Why it matters: This is a clear insider-threat case showing how retained credentials and privileged access can lead to long-running disruption at schools. Education and government IT teams should immediately review offboarding, disable former staff access, rotate passwords and tokens, and audit admin accounts tied to third-party platforms.
Sources
Lawrence Abrams 2026.06.13 99%
This article is the same underlying event and provides the sentencing outcome, prison term, restitution amount, attack timeline, affected services including Apple School Manager, Google, Schoology, and Facebook, plus the detail that investigators recovered district credentials from a USB drive.
2026.06.12 100%
This article establishes the story by providing the sentencing outcome and detailed timeline of the former employee's credential theft, repeated intrusions, and operational impact on the district.
Full page
California sues 23andMe over the 2023 breach that exposed genetic and profile data of nearly 7 million people
Surveillance & PrivacyPolicy & RegulationBreaches & Data LeaksHealthcareConsumers & General Public23andMeCalifornia Attorney GeneralKroll
California has sued 23andMe, now operating as Chrome Holding Co., alleging the company failed to adequately protect customers’ genetic and account data in the 2023 breach affecting nearly 7 million people. The complaint says attackers used credential stuffing—trying usernames and passwords stolen elsewhere—to access about 14,000 accounts, then scrape broader data through 23andMe’s DNA Relatives features; the state also alleges 23andMe failed to require stronger safeguards such as multifactor authentication, missed warning signs for months, and only acted after stolen data was advertised for sale and ransom demands were made.
Why it matters: This matters because the stolen information included highly sensitive genetic and health-related data, and the lawsuit may shape how companies are expected to protect and handle biometric and genomic records. Affected users should reset reused passwords, enable multifactor authentication where available, and review what personal and relative-sharing data remains in their account.
Sources
2026.06.12 88%
This article updates the same underlying 23andMe 2023 breach by reporting that a bankruptcy administrator approved a $46.8 million settlement fund for victims, including payout structure details and the company's bankruptcy context.
Bill Toulas 2026.05.29 98%
This is the same underlying event: California's lawsuit over the 2023 23andMe breach. The article adds details on the complaint's allegations, including failure to defend against credential stuffing, missed intrusion-detection opportunities, a DNA Relatives coding error, and claims that 23andMe misled users before and after the breach.
2026.05.29 98%
This article is the same underlying event: California's lawsuit over 23andMe's 2023 breach. It adds that the suit is now directed at Chrome Holding Co., the post-sale successor to 23andMe, and emphasizes allegations that the company downplayed the breach, failed to implement basic safeguards such as stronger MFA adoption, detected the intrusion only after months, and paid a ransom to the attacker.
Associated Press 2026.05.29 100%
This article establishes a trackable new story because it is not just a recap of the 2023 23andMe breach; it is a concrete state legal action alleging specific security failures, privacy-law violations, and mishandling of genetic data tied to that breach.
Full page
New Jersey police accused of assaulting journalists and denying press protections during Delaney Hall protest coverage
Information FreedomSurveillance & PrivacyGovernmentMedia & EntertainmentConsumers & General PublicNew Jersey policeDelaney HallFreedom of the Press FoundationImmigration and Customs Enforcement
Press-freedom groups say federal and local law enforcement assaulted at least 40 journalists covering protests and a detainee hunger strike near the Delaney Hall immigration detention facility in Newark, New Jersey. The Freedom of the Press Foundation says New Jersey police appeared to decide on the spot who counted as a journalist and who did not, raising concerns about unlawful interference with newsgathering and First Amendment protections during protest reporting.
Why it matters: This matters to the public because it can limit independent reporting on police activity and protests, making it harder to know what is happening on the ground. Journalists, legal observers, and civil-liberties groups should watch for further incidents, preserve evidence, and track whether authorities change policy or face legal challenges.
Sources
Freedom of the Press Foundation 2026.06.12 76%
This source adds context and continuity to the Delaney Hall protest-coverage story by describing recent use of crowd-control munitions, pepper spray, and batons against journalists there, and by framing the attacks within a broader push that can chill reporting, including bans on protective gear at protests.
Caitlin Vogus 2026.06.09 77%
This article adds specific reporting that journalists covering the Delaney Hall protests in Newark said police turned them away for carrying gas masks or bags needed to hold protective equipment, tying PPE restrictions directly to the same protest-policing environment already tracked in the Delaney Hall press-freedom story.
Freedom of the Press Foundation 2026.06.05 100%
This article establishes a distinct press-freedom story centered on alleged police assaults on reporters and ad hoc credentialing decisions during coverage of protests at Delaney Hall in Newark.
Full page
Oxford University says CareerConnect breach at supplier Group GTI exposed user names, emails, and some passwords
Social Engineering & PhishingBreaches & Data LeaksSupply ChainEducationTechnology & SoftwareOxford UniversityGroup GTITargetConnectUniversity of Oxford
Oxford University says a separate breach at its CareerConnect jobs platform exposed users’ full names and email addresses, and encrypted passwords for people not using single sign-on. The affected service is provided by Group GTI and runs on its TargetConnect platform, which Oxford said was compromised on May 28 through an unspecified security vulnerability that has since been fixed; affected alumni, research staff, and employer users had passwords reset, and GTI has not publicly disclosed the flaw or total scope.
Why it matters: Students, alumni, staff, and recruiters who used the platform may now face phishing or credential-stuffing attempts, especially if they reused passwords elsewhere. Affected users should reset reused passwords, watch for convincing job-related scam emails, and universities using GTI TargetConnect should press the vendor for technical details and mitigation guidance.
Sources
SecurityWeek News 2026.06.12 96%
The roundup confirms Oxford was affected by the CareerConnect breach and adds that impacted accounts included alumni, research staff, and employer users, while noting students using single sign-on were not affected.
Sergiu Gatlan 2026.06.08 99%
This article is the same underlying event: Oxford's disclosure that Group GTI's CareerConnect platform was compromised on May 28, exposing names, email addresses, and encrypted passwords for some non-SSO users. It adds Oxford's warning that the intrusion appeared focused on gathering credentials for later phishing and confirms GTI invalidated affected locally set passwords.
2026.06.06 100%
This article establishes a distinct new breach event: an intrusion into Oxford's third-party careers platform provider Group GTI/TargetConnect, explicitly separate from the earlier Canvas incident.
Full page
South Korea fines Coupang $409 million after breach exposed data of more than 37 million customers
Breaches & Data LeaksPolicy & RegulationSurveillance & PrivacyRetail & E-CommerceConsumers & General PublicCoupangCoupang Fulfillment ServicePIPCCoupang Fulfillment Services
South Korea fined e-commerce company Coupang a record $409 million after investigators found that a massive breach exposed the personal data of about 37.55 million people. The Personal Information Protection Commission said the leak was tied to weak basic security controls, including failures in authentication key management and access controls, and also cited violations involving data destruction, breach notification, and interference with the company's data protection officer. Authorities have identified a former Coupang IT employee as the primary suspect.
Why it matters: This is one of South Korea's largest consumer data breaches and affects a huge share of the public, making it important for customers to watch for fraud and account misuse. For defenders and privacy teams, it underscores that basic access controls, key management, and timely breach notification remain critical and that regulators are willing to impose very large penalties.
Sources
SecurityWeek News 2026.06.12 94%
This article adds that South Korea's PIPC tied the penalty to security failures in access controls and authentication key management, while reporting the fine as roughly $400 million and describing exposure of more than 30 million customers.
2026.06.12 99%
This is the same underlying Coupang breach and record PIPC penalty, adding specifics on the former employee’s theft of an authentication signing key, the timeline and scale of scraping activity, non-member victims, extortion emails, and the referral for criminal prosecution over deleted logs.
Sergiu Gatlan 2026.06.11 100%
This article establishes a distinct tracked story by adding the regulator's formal findings, breach scope, and record penalty tied to Coupang's previously disclosed customer data leak.
Full page
Europol and DOJ dismantle AudiA6 crypto-laundering service tied to ransomware payments
RansomwarePolicy & RegulationScams & FraudCryptocurrency & BlockchainConsumers & General PublicEuropolDOJ
Authorities say they shut down AudiA6, a cryptocurrency laundering service allegedly used by ransomware groups and other cybercriminals to wash more than $380 million. Europol said the operation was linked to more than 15 ransomware and large-scale crypto-theft investigations, while arrests in Georgia and earlier evidence from a 2025 arrest in Poland helped identify administrators, seize 25 domains, freeze cryptocurrency, and recover about 6,000 know-your-customer identity records tied to mule accounts.
Why it matters: This matters because ransomware profits only scale when criminals can cash out, and AudiA6 allegedly served as a central laundering hub for that process. Crypto platforms, investigators, and organizations tracking extortion activity should watch for related wallet exposure and mule-account abuse, while victims may gain new leads tying attacks to payment flows.
Sources
SecurityWeek News 2026.06.12 87%
This roundup briefly notes the AudiA6 takedown as one of the week's notable items, serving as a secondary report on the same law-enforcement action against the crypto-laundering service.
Bill Toulas 2026.06.11 100%
This article establishes a distinct story about the takedown of AudiA6 as a ransomware-linked crypto-laundering network, not a follow-up to any tracked story listed.
Full page
CISA adds actively exploited LiteLLM command-injection flaw CVE-2026-42271 to KEV catalog
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareCISABerriAI
CISA says attackers are actively exploiting a critical flaw in BerriAI's LiteLLM, an artificial intelligence gateway used to connect apps to multiple model providers. The bug, CVE-2026-42271, is a command-injection vulnerability, meaning crafted input can make a server run attacker-chosen system commands. CISA added it to the Known Exploited Vulnerabilities catalog, but public details on the attacks remain limited.
Why it matters: Organizations running internet-facing or internally exposed LiteLLM instances should treat this as urgent and patch or isolate affected systems immediately. An actively exploited command-injection flaw can quickly lead to full server compromise and follow-on data theft.
Sources
SecurityWeek News 2026.06.12 100%
This article establishes a distinct tracked event by identifying CVE-2026-42271 in LiteLLM as actively exploited and newly added to CISA's KEV catalog, with concrete action implications for defenders.
Full page
Whistleblower lawsuit accuses IBM and AT&T of concealing foreign-linked hacks from the U.S. government
Breaches & Data LeaksPolicy & RegulationGovernmentTechnology & SoftwareTelecommunicationsIBMAT&T
A former IBM cybersecurity executive has sued IBM and AT&T, alleging the companies hid repeated foreign government-linked intrusions while working on federal business. The complaint says the companies failed to properly disclose multiple breaches to the U.S. government over several years and falsely reassured officials about their security posture in connection with federal contracts.
Why it matters: If the allegations are substantiated, this could affect trust in breach reporting for major government contractors and expose federal systems and data to undisclosed risk. It matters to customers, regulators, and agencies that rely on accurate incident disclosure to respond and protect networks.
Sources
SecurityWeek News 2026.06.12 100%
This article is the first item here describing a concrete legal claim that two major contractors allegedly concealed repeated foreign-linked breaches, making it a distinct security and disclosure story worth tracking.
Full page
Microsoft patches Surface firmware flaw that could permanently brick devices when Secure Boot protections are disabled
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareConsumers & General PublicMicrosoft
Microsoft has been quietly patching a Surface firmware flaw that could make some devices permanently unbootable after a single crafted command sequence. The issue affects Surface hardware using the Surface System Aggregator Module (SSAM or SAM) embedded controller when Secure Core and Secure Boot are disabled; a researcher said arbitrary write commands sent through a driver interface could overwrite controller or boot-related firmware and leave the device unable to complete startup after reboot. No CVE is cited in the report.
Why it matters: This matters for Surface owners and enterprise IT teams because the impact is physical loss of the device until motherboard-level repair or replacement. Organizations managing Surface fleets should review Microsoft's firmware updates, keep Secure Boot and Secure Core enabled where possible, and restrict administrator-level access that could reach the hardware interface.
Sources
2026.06.12 100%
This article appears to be the first concrete report establishing a distinct Microsoft Surface firmware vulnerability and Microsoft's ongoing repair effort, rather than an update to an already tracked SecLog story.
2026.06.12 97%
This source is a direct update on the same Surface firmware-bricking flaw, adding that Microsoft has been quietly patching it for about 90 days, that the issue was surfaced after Copilot generated Python code that overwrote embedded controller firmware, and that exploitation requires admin privileges plus disabled Secure Core and Secure Boot.
Full page
Plymouth City Council email mistake exposed about 500 home-schooling families' addresses
Breaches & Data LeaksSurveillance & PrivacyGovernmentConsumers & General PublicPlymouth City CouncilInformation Commissioner's Office
Plymouth City Council disclosed that a mass email sent to home-schooling families exposed the recipients' email addresses to one another. The incident was caused by staff sending the message without using blind carbon copy (BCC), affecting approximately 500 families; the council said no child-specific information was included, asked recipients to delete the message, and reported the breach to the UK Information Commissioner's Office, which closed the case after giving data-protection advice.
Why it matters: Affected families had their contact details disclosed without consent, creating privacy and possible phishing risks even though no more sensitive data was reportedly included. Public bodies should review bulk-email controls and recipients should be cautious about unexpected follow-up messages referencing the incident.
Sources
2026.06.12 100%
This article establishes a distinct local-government data exposure incident involving Plymouth City Council, separate from other tracked email disclosure mistakes.
Full page
Ivanti patches two critical Sentry flaws, including root remote-code-execution bug CVE-2026-10520
Urgent PatchesZero-Days & CVEsTechnology & SoftwareGovernmentIvantiShadowserverCISA
Ivanti released emergency security updates for its Sentry mobile gateway after finding two critical flaws that could let attackers take over affected systems. The bugs are CVE-2026-10520, a maximum-severity OS command injection issue that can enable remote code execution as root, and CVE-2026-10523, an authentication bypass that can let unauthenticated attackers create rogue admin accounts. Fixes are in Sentry versions R10.5.2, R10.6.2, and R10.7.1; Ivanti said it has no evidence of active exploitation at disclosure.
Why it matters: Organizations using Ivanti Sentry should update immediately because these bugs could hand an attacker full control of a gateway that sits between mobile devices and internal corporate systems. Even without confirmed in-the-wild abuse yet, Ivanti edge and management products have a strong history of rapid post-disclosure exploitation.
Sources
Ionut Arghire 2026.06.12 95%
This article updates the same Ivanti Sentry event by adding that CISA placed CVE-2026-10520 in the KEV catalog as exploited, while Ivanti says the observed activity was attempted exploitation against honeypots and reiterates exposure conditions around management port 8443, mTLS-protected deployments, and affected fixed versions 10.5.2, 10.6.2, and 10.7.1.
Sergiu Gatlan 2026.06.12 96%
This advances the same underlying event by adding that CVE-2026-10520 is now confirmed as actively exploited, has been added to CISA's Known Exploited Vulnerabilities catalog, and is the first flaw subject to CISA's new Binding Operational Directive 26-04 with a three-day federal patch deadline.
Sergiu Gatlan 2026.06.11 97%
This updates the same Ivanti Sentry event by adding that CVE-2026-10520 is now being exploited in the wild after patch release, that Shadowserver observed exploitation attempts and at least two internet-exposed Sentry instances backdoored, and that a public proof-of-concept is being used.
2026.06.10 99%
This article reports the same Ivanti Sentry disclosure, adding patch urgency, affected fixed versions (10.5.2, 10.6.2, 10.7.1), and technical detail from watchTowr that CVE-2026-10520 involved an exposed Apache Tomcat API parsing attacker-controlled MICS configuration commands; it also reiterates CVE-2026-10523 as an unauthenticated admin-account creation flaw.
Ionut Arghire 2026.06.10 94%
This article adds that Ivanti released Sentry 10.5.2, 10.6.2, and 10.7.1 to fix CVE-2026-10520 and CVE-2026-10523, and also notes related EPMM fixes (CVE-2026-6973 and CVE-2026-10727). It reiterates that CVE-2026-10520 is a remote unauthenticated OS command injection leading to root code execution and that CVE-2026-10523 is a remote unauthenticated authentication bypass allowing creation of administrator accounts, with Ivanti saying it has no evidence of active exploitation.
Sergiu Gatlan 2026.06.10 100%
This article establishes a new tracked event: Ivanti's June 2026 disclosure and patching of CVE-2026-10520 and CVE-2026-10523 in Sentry, distinct from prior Ivanti EPMM and other zero-day stories.
Full page
INTERPOL says Operation Secure dismantled Sniper Dz phishing platform and arrested alleged administrator
Social Engineering & PhishingThreat Actors & APTsConsumers & General PublicINTERPOL
INTERPOL says it helped shut down Sniper Dz, a phishing platform used to steal account logins and other sensitive data, and arrested the alleged administrator. The takedown was part of Operation Secure, which targeted phishing, infostealer malware, and related criminal infrastructure across multiple countries. Sniper Dz was described as a phishing-as-a-service platform, meaning a ready-made toolkit criminals could rent or use to run credential-theft campaigns at scale.
Why it matters: This matters because phishing kits lower the barrier for criminals to impersonate trusted brands and steal passwords from large numbers of people and organizations. Defenders should review recent credential-theft activity, harden multi-factor authentication, and warn users to be cautious of login pages and messages that claim urgent account action is needed.
Sources
info@thehackernews.com (The Hacker News) 2026.06.12 100%
This article establishes a distinct story about a named phishing platform takedown and administrator arrest, not a follow-up to an existing tracked event.
Full page
Kyushu Electric says a missing backup drive exposed data for 10.9 million electricity customers
Breaches & Data LeaksEnergy & UtilitiesConsumers & General PublicKyushu Electric Power
Kyushu Electric Power says an external backup drive containing customer data for up to 10.9 million accounts went missing from an unlocked server-room cabinet. The lost data includes names, service addresses, electricity usage, phone numbers, and retail electricity provider information, but the company says no bank-account or payment-card data was on the drive. The device was last handled after a backup on April 27 and discovered missing on May 26; the company has notified police and Japan’s privacy and industry regulators.
Why it matters: This is a large-scale customer data exposure affecting a major regional utility, so impacted people should watch for impersonation, phishing, or scam calls that use account details to appear legitimate. Organizations handling sensitive customer data should also note the physical-security and backup-handling failures highlighted by the incident.
Sources
Bill Toulas 2026.06.11 100%
This article appears to be the first concrete report of Kyushu Electric Power’s missing backup-drive incident and establishes the underlying breach event.
Full page
Group-IB links thousands of fake FIFA World Cup 2026 domains to fraud campaigns targeting ticket buyers
Scams & FraudMalwareSocial Engineering & PhishingMedia & EntertainmentHospitality & TravelConsumers & General PublicGovernmentFIFAFBIGoogle
Researchers say multiple criminal groups have built fake FIFA websites to steal World Cup fans’ passwords, payment details, and money through bogus ticket sales. Group-IB identified four separate campaigns since August 2025, including a Chinese-speaking operation it calls GHOST STADIUM that uses more than 300 active lookalike domains and roughly 3,800 dormant ones. The phishing kit closely copies FIFA’s login flow, can trigger password-reset steps to lock victims out, and is being promoted through Facebook ads offering unrealistically cheap tickets.
Why it matters: Fans trying to buy 2026 World Cup tickets could lose their accounts, have legitimate tickets resold, or pay scammers for fake seats. Users should only type fifa.com directly into their browser, avoid ad-linked ticket offers, and treat lookalike FIFA domains as suspicious.
Sources
Arctic Wolf Labs 2026.06.11 89%
This article adds concrete technical detail to the same underlying World Cup 2026 scam and phishing wave: more than 10,000 themed domains since January 2026, WhatsApp/Telegram/Discord-based funneling, QR-code phishing, adversary-in-the-middle (AiTM) kits that steal Google Workspace sessions, and Android/Windows infostealer and cryptomining payloads tied to ticket and streaming lures.
Arctic Wolf Labs 2026.06.09 84%
This is the same underlying World Cup 2026-themed fraud and phishing ecosystem, but adds materially new details: more than 10,000 themed domains since January 2026, a mobile-first funnel through WhatsApp/Telegram/Discord, a real-time adversary-in-the-middle phishing kit that defeats one-time MFA codes, a Windows infostealer delivered via ticket lures, and targeting of host-city staff and fake FIFA career portals aimed at Google Workspace accounts.
SecurityWeek News 2026.05.29 98%
This source reiterates Group-IB's findings on thousands of fraudulent FIFA-themed domains and adds detail that a Chinese-speaking group dubbed Ghost Stadium ran more than 300 domains, including a near-perfect clone of FIFA's site.
Bill Toulas 2026.05.28 95%
This article covers the same underlying World Cup 2026 fraud campaign ecosystem and adds an FBI public warning, example lookalike domains, fraud types beyond ticketing, and references to Group-IB's Ghost Stadium cluster and Bitdefender observations across multiple countries and ad channels.
2026.05.28 100%
This article establishes a distinct, named fraud operation and broader cluster of World Cup-themed phishing and ticket scams, with concrete infrastructure, tactics, and estimated victim impact.
Full page
Microsoft issues mitigations for YellowKey Windows BitLocker bypass zero-day tracked as CVE-2026-45585
Zero-Days & CVEsUrgent PatchesSurveillance & PrivacyPolicy & RegulationTechnology & SoftwareConsumers & General PublicMicrosoft
Microsoft said it is tracking the publicly disclosed YellowKey Windows BitLocker security feature bypass as CVE-2026-45585 and published mitigations pending a security update. The flaw can allow access to BitLocker-protected drives by abusing specially crafted FsTx files and WinRE behavior; Microsoft recommends disabling autofstx.exe auto-start in WinRE and requiring BitLocker TPM+PIN startup authentication.
Why it matters: Organizations and users relying on BitLocker for device-at-rest protection may need to apply mitigations immediately because PoC details are public and a fix is not yet available. Defenders should review BitLocker startup settings and WinRE configuration now.
Sources
Arctic Wolf Labs 2026.06.11 69%
The recap specifically includes YellowKey as one of the publicly disclosed zero-days addressed in June 2026 and places it in the broader Patch Tuesday rollout affecting BitLocker-protected systems.
Ionut Arghire 2026.06.11 34%
This article covers a different newly released BitLocker bypass exploit ('GreatXML') rather than the YellowKey flaw Microsoft previously mitigated, so it is related by product and researcher but not the same underlying event.
Sergiu Gatlan 2026.06.10 94%
This article updates the same YellowKey event by reporting that Microsoft has now patched CVE-2026-45585 as part of June 2026 Patch Tuesday, moving the story from mitigations-only to an available fix.
BrianKrebs 2026.06.09 41%
The article references the same YellowKey/BitLocker disclosure thread and notes Microsoft's June patching of a related BitLocker elevation-of-privilege issue, though the main event here is Patch Tuesday rather than the original YellowKey mitigation story.
Lawrence Abrams 2026.06.09 52%
This article reports Microsoft’s June Patch Tuesday fix for a separate publicly disclosed Windows BitLocker bypass flaw, CVE-2026-50507, adding another BitLocker zero-day-related development but not the same underlying vulnerability as YellowKey CVE-2026-45585.
Eduard Kovacs 2026.06.03 41%
YellowKey is one of the Nightmare Eclipse-disclosed flaws discussed here. The article adds context that YellowKey was part of a broader batch of publicly dumped Microsoft zero-days that triggered controversy and partial patching, but the main event is the broader disclosure backlash rather than a standalone YellowKey update.
Bruce Schneier 2026.06.02 57%
The post explicitly references the BitLocker-breaking exploit from the Nightmare Eclipse disclosures, adding context that Microsoft is threatening the researcher tied to the YellowKey zero-day case.
2026.05.28 80%
This article adds Microsoft’s broader response to the Nightmare Eclipse zero-day disclosures, reiterates that YellowKey (CVE-2026-45585) remains unpatched, says Microsoft considers exploitation more likely, and places YellowKey alongside five other publicly dumped Windows flaws in the same disclosure campaign.
Ionut Arghire 2026.05.20 99%
This article is directly about the same YellowKey event and adds specifics on Microsoft's mitigation steps, the CVE assignment (CVE-2026-45585), the WinRE/autofstx.exe behavior being blocked, and debate over whether BitLocker+PIN is also affected.
info@thehackernews.com (The Hacker News) 2026.05.20 99%
The article appears to cover the same underlying event: Microsoft's release of mitigations for the YellowKey BitLocker bypass vulnerability CVE-2026-45585.
Sergiu Gatlan 2026.05.20 100%
This article establishes a distinct tracked event by adding Microsoft's official CVE assignment and mitigation guidance for the YellowKey BitLocker zero-day, which is not represented in the existing story list.
Bruce Schneier 2026.05.18 88%
This is an early report on the same YellowKey BitLocker bypass event, noting public disclosure by Nightmare-Eclipse and that the exploit reliably bypasses default Windows 11 BitLocker with physical access.
Full page
CISA adds actively exploited Microsoft Exchange Server XSS flaw CVE-2026-42897 to KEV catalog
Urgent PatchesZero-Days & CVEsGovernmentTechnology & SoftwareCISAMicrosoft
CISA on May 15, 2026 added CVE-2026-42897, a Microsoft Exchange Server cross-site scripting vulnerability, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. Under BOD 22-01, federal civilian agencies must remediate by CISA's due date, and CISA urged all organizations to prioritize patching KEV-listed flaws.
Why it matters: Active exploitation of an Exchange Server flaw raises immediate risk for organizations running the product, especially federal agencies subject to KEV deadlines. Defenders should identify exposed Exchange instances and prioritize remediation or mitigation quickly.
Sources
Arctic Wolf Labs 2026.06.11 63%
The article notes that CVE-2026-42897 was the actively exploited zero-day in this Patch Tuesday cycle and reiterates Microsoft's Exchange Emergency Mitigation Service guidance, connecting this patch release to the previously tracked active exploitation.
Eduard Kovacs 2026.06.11 95%
This article updates the same underlying event by adding that Microsoft has now released patches for the previously mitigations-only zero-day CVE-2026-42897 affecting Exchange Server Subscription Edition, 2016, and 2019.
Sergiu Gatlan 2026.06.10 96%
This article is a direct update to the same CVE-2026-42897 event, adding that Microsoft has now released June 2026 security updates to patch the actively exploited Exchange Server flaw after earlier warning of exploitation and temporary mitigations.
CISA 2026.05.15 100%
This article is the first tracked item here establishing the specific KEV event for CVE-2026-42897 and its active exploitation status.
Full page
Public 'GreatXML' zero-day lets attackers bypass BitLocker on Windows after Microsoft Defender Offline scan is used
Zero-Days & CVEsTechnology & SoftwareConsumers & General PublicGovernmentMicrosoft
A newly published Windows exploit can unlock some BitLocker-protected PCs and open a SYSTEM-level command prompt in Recovery Mode. Security researcher Nightmare Eclipse says the 'GreatXML' proof of concept abuses Microsoft Defender Offline scan behavior rather than a published CVE; systems become vulnerable after Defender Offline scan has been initiated at least once, and the attack involves placing crafted XML files in the recovery partition and booting into Windows Recovery Environment (WinRE).
Why it matters: This weakens one of Windows' main disk-encryption protections for affected machines, especially if an attacker can get local access or trigger the precondition. Windows defenders should watch for Microsoft guidance, restrict unauthorized physical and admin access, and review whether Defender Offline scan can be abused in their environment.
Sources
2026.06.11 98%
This article is directly about the same GreatXML BitLocker-bypass zero-day, adding reporting that the exploit was published on GitHub, Microsoft had not yet responded on GreatXML, and Will Dormann questioned the practical impact because reproducing it appears to require an admin-triggered Defender Offline scan.
info@thehackernews.com (The Hacker News) 2026.06.11 98%
This is the same underlying event: the newly disclosed GreatXML exploit that abuses Windows recovery-partition XML files to bypass BitLocker protections and gain access on affected Windows systems.
Ionut Arghire 2026.06.11 100%
This article establishes a distinct new zero-day event: a separate Nightmare Eclipse disclosure named GreatXML that bypasses BitLocker via Microsoft Defender Offline scan and WinRE, not the previously tracked YellowKey or RoguePlanet flaws.
Full page
Varonis finds OpenClaw AI email agent can be phished into sending AWS keys, database credentials, and customer data
Surveillance & PrivacySocial Engineering & PhishingTechnology & SoftwareOpenClawGoogleOpenAIAmazon Web Services
Researchers found that an OpenClaw AI email agent could be tricked by phishing-style messages into leaking sensitive data instead of protecting it. In Varonis simulations, the open-source agent, connected to Gmail, browser tools, and Google Workspace APIs, sent AWS IAM keys, database credentials, SSH details, and CRM exports to an external account after urgent impersonation emails. The tests used Google Gemini 3.1 Pro and OpenAI GPT-5.4 and showed that URL and OAuth-app checks were stronger than sender-identity verification.
Why it matters: Organizations testing AI agents for email and workflow automation could accidentally give them access to data they can be manipulated into disclosing. Treat this as an immediate design and policy issue: limit agent privileges, block unapproved external sharing, require human approval for high-risk actions, and verify sender identity before deployment.
Sources
info@thehackernews.com (The Hacker News) 2026.06.11 95%
This is the same underlying OpenClaw agent security story, adding that attackers can not only phish the agent into exfiltrating secrets but also trick it into executing code, expanding the known impact and attack surface.
Bill Toulas 2026.06.09 100%
This article establishes a distinct security story about phishing and impersonation attacks against OpenClaw-based AI agents causing sensitive-data exposure in realistic enterprise workflows.
Full page
VRChat says cloud breach exposed data of more than 2.4 million users
Breaches & Data LeaksSurveillance & PrivacyConsumers & General PublicMedia & EntertainmentVRChatMetaSteam
VRChat says attackers accessed its cloud environment and stole account data belonging to 2,436,782 users. The company told Maine regulators the intrusion lasted from May 10 to May 12, 2026, and exposed VRChat usernames, email addresses, VRChat+ subscription status, login history including device and hardware identifiers and IP addresses, plus linked Steam or Meta user IDs. VRChat said passwords, payment card data, and government IDs used for age verification were not affected.
Why it matters: Affected users face increased risk of phishing, account-targeted scams, and privacy exposure because the stolen data links identities, devices, and login activity. Users should watch for impersonation emails and messages tied to VRChat, Steam, or Meta accounts, and defenders should review any reuse of exposed metadata in follow-on attacks.
Sources
2026.06.11 100%
This article appears to be the first concrete reporting in the set on VRChat's own disclosure to Maine regulators that a cloud intrusion exposed data from roughly 2.44 million user accounts.
Full page
Great Marlow School in England sends most students home after cyberattack disrupts school systems
Breaches & Data LeaksEducationGreat Marlow SchoolDepartment for EducationNational Cyber Security Centre
Great Marlow School in Buckinghamshire, England closed to most students for a second day after a cyberattack affected its information and communications technology systems. Only pupils sitting external GCSE and A-Level exams were allowed on site while the school worked with specialist IT and cybersecurity responders and followed guidance from the UK Department for Education and the National Cyber Security Centre; the attack type and any data exposure have not yet been confirmed.
Why it matters: This shows how even a single school cyber incident can quickly disrupt classes, exams, and day-to-day operations for students and staff. Schools and local education defenders should review incident response plans, backups, and access controls now, while affected families should watch for official updates about any possible data exposure.
Sources
2026.06.11 100%
This article is the first concrete report here of the cyber incident at Great Marlow School, establishing a distinct school-disruption event not covered by the existing tracked stories.
Full page
U.S. charges alleged Void Blizzard supporter over cyberespionage attacks on at least 11 American companies
Threat Actors & APTsGovernmentDefense & AerospaceTransportation & LogisticsMedia & EntertainmentHealthcareNonprofits & NGOsDOJFBI
U.S. prosecutors charged a Russian national they say helped the Kremlin-linked hacking group Void Blizzard break into companies in the United States and other countries. According to Reuters and an FBI affidavit cited in the report, Denis Obrezko allegedly bought a virtual private server and internet domain with cryptocurrency to support the group's operations; investigators say at least 11 U.S. companies were compromised, with likely victims in government, defense, transportation, media, healthcare, and nonprofit sectors. Void Blizzard has been described as using purchased or stolen credentials to enter networks and steal emails and internal documents.
Why it matters: This matters because it adds concrete victim scope and infrastructure details to an active Russian espionage campaign targeting multiple sectors. Organizations in the named industries should review logins, watch for credential misuse, and check for suspicious access to email and internal document systems.
Sources
2026.06.11 100%
This article establishes a distinct new story by reporting criminal charges and extradition tied to alleged infrastructure support for the Void Blizzard espionage campaign, including a specific claim that at least 11 U.S. companies were compromised.
Full page
CISA says new directive will change how federal agencies prioritize and patch cyber vulnerabilities
Policy & RegulationZero-Days & CVEsUrgent PatchesGovernmentCISAOMB
CISA says it is about to change how U.S. federal agencies handle software flaws, telling them to focus first on the vulnerabilities and systems that pose the highest real-world risk. Acting Director Nick Andersen said a binding operational directive due Wednesday will shift agencies away from treating every patch the same and toward prioritizing internet-exposed assets, Known Exploited Vulnerabilities, exploit automation, and critical functions; CISA also plans closer risk reviews with critical infrastructure operators.
Why it matters: This could change patching deadlines and vulnerability-management practices across the federal government and influence how critical infrastructure owners prioritize fixes. Agencies and defenders should watch for the directive’s release because it may require faster action on the most dangerous exposed systems while de-emphasizing lower-risk issues.
Sources
Ionut Arghire 2026.06.11 98%
This article is a direct report on the same CISA event: issuance of Binding Operational Directive 26-04. It adds specific details on agency obligations, including policy updates, KEV monitoring, automation of reporting, external asset tagging, and the 3-day, 14-day, and 60-day remediation timelines tied to exploitability, exposure, and impact.
Bill Toulas 2026.06.11 97%
This article appears to be coverage of the same underlying event: CISA's new Binding Operational Directive 26-04. It adds concrete detail on the accelerated remediation windows, including a three-day deadline for certain internet-exposed, actively exploited, automatable flaws that allow partial or full system compromise, plus 60-day and 180-day implementation milestones for FCEB agencies.
2026.06.10 97%
This article is a direct update on the same CISA binding operational directive, adding the specific 72-hour requirement for vulnerabilities meeting three of four criteria, the criteria themselves, the 180-day implementation window, and the requirement to perform compromise triage before patching.
2026.06.09 100%
The article establishes a new, specific CISA policy event: an imminent binding operational directive that will alter federal vulnerability prioritization and remediation requirements.
Full page
OnyxC2 stealer malware is being sold to cybercriminals as a subscription service
MalwareScams & FraudThreat Actors & APTsConsumers & General PublicFinance & BankingTechnology & Software
A newly analyzed malware service called OnyxC2 is being rented to criminals for as little as $250 a month, giving buyers a ready-made tool to steal passwords, cookies, wallet data, and other sensitive information from infected Windows systems. BlackFog says the stealer targets about 210 applications and browser extensions across browsers, password managers, cryptocurrency wallets, FTP and email clients, and some 2FA extensions, and uses encrypted payloads, DLL sideloading, in-memory execution, HVNC hidden remote control, keylogging, reverse proxying, and LSASS dumping to evade detection and maintain access.
Why it matters: This lowers the barrier for account theft and follow-on fraud or intrusion by packaging advanced credential-stealing and remote-access features as a commercial criminal product. Organizations and consumers should treat it as a high-risk infostealer threat: watch for suspicious installers, strengthen endpoint detection, and rotate credentials and session tokens if infection is suspected.
Sources
Kevin Townsend 2026.06.11 100%
This article appears to be the establishing report for a distinct malware threat centered on the OnyxC2 stealer's criminal sale, capabilities, and delivery techniques, not an update to an already tracked event.
Full page
Five Eyes warn China is using LinkedIn, Indeed and Upwork to recruit people with access to state secrets
Social Engineering & PhishingGovernmentThreat Actors & APTsGovernmentDefense & AerospaceTechnology & SoftwareLegal & Professional ServicesCryptocurrency & BlockchainMI5LinkedInIndeedUpworkPayPalWestern UnionFBIJustice Department
MI5 and allied intelligence agencies warned that Chinese intelligence officers and their proxies are using job and networking platforms including LinkedIn, Indeed, and Upwork to spot and cultivate people with access to classified or otherwise sensitive government information. The advisory says the operators pose as recruiters, consultancies, think tanks, or research clients, rank applicants by likely access, request trial reports, then move conversations to encrypted messaging and pay through services such as PayPal, Zelle, Wise, Western Union, or cryptocurrency in exchange for non-public information.
Why it matters: This is a real-world espionage and social-engineering threat aimed at government, defense, foreign-affairs, academic, media, and policy workers. People in or near sensitive roles should treat unsolicited research, consulting, or recruiter outreach on these platforms as potentially hostile, report suspicious contact, and avoid sharing resumes or non-public work details casually.
Sources
Associated Press 2026.06.11 93%
This article advances the same underlying event and campaign: Western governments warning that China is using fake job recruitment on online platforms to approach people with security clearances. It adds the DOJ/FBI seizure of 13 domains, details that the sites used stolen or fake identities and AI-generated photos, and that some recruits were paid via cryptocurrency or online payment systems.
Ionut Arghire 2026.06.05 98%
This article is a direct report on the same Five Eyes alert, adding detail on the fake recruiter workflow: impersonated think tanks and HR firms, ranking resumes by likely access, trial reports on defense and trade topics, escalation to requests for privileged information, movement to encrypted messaging, and payment methods including PayPal, Wise, Western Union, and cryptocurrency.
2026.06.04 98%
This article is another report on the same Five Eyes joint bulletin, adding details that Chinese intelligence officers pose as recruiters or consultants for front companies, shift targets from direct LinkedIn outreach to job-ad responses, screen applicants through interviews and trial reports, then move conversations to encrypted messaging apps and pay for increasingly sensitive information.
2026.06.04 100%
The article centers on a newly published MI5/Five Eyes advisory describing the current recruitment tradecraft, platforms used, target groups, and payment methods in China's state-secrets collection campaign.
Full page
Leonardo plans to add Bluetooth device tracking to U.S. license plate reader systems
Surveillance & PrivacyGovernmentConsumers & General PublicLeonardo
Surveillance company Leonardo plans to expand automatic license plate readers so they also collect Bluetooth identifiers from phones, wearables, and other devices in passing vehicles. The feature, called SignalTrace, would let cameras designed to track cars also help identify and follow specific drivers or passengers by correlating vehicle sightings with nearby device signals. The article describes a product and deployment capability rather than a disclosed software flaw or CVE.
Why it matters: This would make a widely used police tracking tool more invasive by linking vehicles to people, not just plates. It matters for public oversight, privacy advocates, and communities affected by law-enforcement surveillance, because it could significantly widen location tracking without users doing anything wrong.
Sources
Bruce Schneier 2026.06.11 100%
This article establishes a distinct surveillance and privacy story about Leonardo's SignalTrace capability adding Bluetooth-based person/device tracking to existing ALPR deployments.
Full page
Palo Alto Networks patches Cortex XSOAR and XSIAM flaw CVE-2026-0274 that can expose restricted resources
Urgent PatchesZero-Days & CVEsTechnology & SoftwarePalo Alto Networks
Palo Alto Networks released fixes for a serious vulnerability in Cortex XSOAR and Cortex XSIAM that could let attackers access and change protected resources. The flaw, CVE-2026-0274, is a high-severity improper credential-validation issue in the CommvaultSecurityIQ integration and does not require special configuration to be triggered; Palo Alto also patched eight additional medium- and low-severity bugs in PAN-OS, Prisma Access Agent, Cortex XSOAR, and GlobalProtect App.
Why it matters: Teams using affected Palo Alto platforms should install updates because the flaw could undermine access controls in tools used for security operations and response. Even without known active exploitation, these are widely deployed enterprise products and should be patched before attackers can weaponize the bugs.
Sources
Ionut Arghire 2026.06.11 100%
This article establishes a separate Palo Alto patch event around CVE-2026-0274 in Cortex XSOAR and Cortex XSIAM rather than updating an existing tracked story.
Full page
China-linked JDY botnet grows and expands reconnaissance targeting of U.S. military networks
MalwareThreat Actors & APTsGovernmentDefense & AerospaceTechnology & SoftwareConsumers & General PublicTelecommunicationsCiscoUbiquitiDrayTekHikvisionLinksysFortinetLumenFBICISA
Researchers say the China-linked JDY botnet has grown to more than 1,500 compromised small-office/home-office and internet-connected devices and is increasingly used to probe U.S. military and related networks. Black Lotus Labs says JDY is tied to China-nexus activity previously associated with Volt Typhoon and is used for distributed scanning, banner grabbing, TLS certificate collection, and fingerprinting to find vulnerable systems soon after flaws are disclosed, including scans for FortiClient EMS bug CVE-2026-35616. The botnet uses infected routers and IoT devices from vendors including Cisco, Ubiquiti, DrayTek, Hikvision, Linksys, Araknis, and Mimosa, with command-and-control routed through Tor hidden services.
Why it matters: This matters because compromised routers and IoT gear are being used to quietly map weak points in networks tied to sensitive U.S. targets, helping follow-on intrusions. Organizations should patch exposed network devices quickly, reduce internet-facing services, and watch for scanning and unusual activity from SOHO and IoT infrastructure.
Sources
2026.06.11 95%
This article directly summarizes and advances the same underlying event reported by Lumen: the JDY cluster tied to Volt Typhoon has persisted after the KV-botnet takedown, grown to more than 1,500 compromised routers and IoT devices, and is being used to rapidly scan for newly disclosed vulnerabilities with notable focus on U.S. military-related infrastructure.
info@thehackernews.com (The Hacker News) 2026.06.10 98%
The article appears to cover the same underlying event: expansion of the China-linked JDY botnet to more than 1,500 devices and its use for reconnaissance focused on U.S. military networks.
Bill Toulas 2026.06.10 100%
This article establishes a distinct story about the JDY botnet's expansion, its China-linked reconnaissance role, and its specific focus on U.S. military-associated targets rather than a single already-tracked exploit or policy event.
Full page
OpenAI says China-linked influence operators used ChatGPT to push anti-AI datacenter narratives on social media
Disinformation & Influence OpsConsumers & General PublicEnergy & UtilitiesTechnology & SoftwareOpenAIX
OpenAI says it removed accounts likely tied to China that used ChatGPT to generate posts and images for a covert influence campaign aimed at Americans. The operation focused on social-media content claiming AI datacenters drive up electricity demand and household power costs, then posted the material through likely fake X accounts alongside links to real news stories; OpenAI said the campaign showed limited authentic engagement.
Why it matters: This is a concrete example of AI tools being used to support state-linked influence operations, even when the campaign gains little traction. It matters for platforms, policymakers, and the public because real debates can be manipulated with synthetic content, so readers should scrutinize coordinated posts and image-driven narratives around contentious policy issues.
Sources
2026.06.11 100%
The article establishes a distinct, reportable event: OpenAI publicly attributed and disrupted a China-linked covert influence operation that used its models to generate propaganda around AI datacenters and power costs.
Full page
Red Hat says more than 30 npm packages were backdoored to steal developer and cloud credentials
Breaches & Data LeaksSupply ChainMalwareTechnology & SoftwareRed HatGitHubnpmJFrog
More than 30 npm packages in Red Hat's @redhat-cloud-services namespace were compromised and used to deliver credential-stealing malware to developers who installed them. Researchers say attackers likely took over a Red Hat employee GitHub account, added malicious GitHub Actions workflows, and abused npm trusted publishing to release 96 backdoored package versions. The malware, a new Shai-Hulud variant dubbed Miasma, targeted GitHub Actions secrets, cloud credentials, SSH keys, package publishing tokens, Vault tokens, Kubernetes service-account tokens, Docker credentials, GPG keys, and .env files.
Why it matters: Developers and organizations that installed the affected packages may have had sensitive keys and tokens stolen, which can lead to wider compromise of code, cloud systems, and build pipelines. This is urgent: identify affected installs, remove the packages, and rotate all credentials and secrets that were present on impacted machines or CI/CD systems.
Sources
Bill Toulas 2026.06.10 67%
The article says Miasma was previously linked to the Red Hat npm package compromise and provides new technical context on the malware family behind that event, including credential theft from build environments, cloud services, and CI/CD pipelines and its self-propagating package poisoning behavior.
Ionut Arghire 2026.06.09 86%
The piece explicitly identifies the Red Hat npm package incident as the first June 1 Miasma wave, adding that it was part of a broader coordinated Shai-Hulud outbreak affecting dozens more npm and PyPI packages.
2026.06.02 98%
This article is a direct update on the same Red Hat package compromise, adding that 32 affected packages were being downloaded about 117,000 times per week, that Red Hat traced distribution to a compromised GitHub account, removed the packages, and linked the malware to a Mini Shai-Hulud variant dubbed Miasma.
Ionut Arghire 2026.06.02 98%
This article covers the same Red Hat npm supply-chain attack and adds specifics on the timing and scale of publication (96 malicious versions across 32 packages in 72 seconds), suspected access path (CI/CD or npm scope credentials), links to the Mini Shai-Hulud-style worm, and evidence that at least 210 repositories may contain stolen credentials.
2026.06.01 98%
This directly updates the same Red Hat npm supply-chain compromise, adding that at least 32 package releases in the @redhat-cloud-services namespace were infected with a Mini Shai-Hulud variant, tied by Wiz to a compromised Red Hat employee GitHub account, with package download volume around 80,000 per week and expanded Azure/GCP credential theft behavior.
Lawrence Abrams 2026.06.01 100%
This article establishes a distinct supply-chain incident centered on compromised Red Hat npm packages and a Miasma/Shai-Hulud credential-stealing payload, not the same underlying event as the existing @antv Mini Shai-Hulud story or other tracked package compromises.
Full page
Google patches exploited Chrome zero-day CVE-2026-11645 in Chrome 149
Urgent PatchesZero-Days & CVEsTechnology & SoftwareConsumers & General PublicGoogle
Google released a Chrome 149 security update that fixes an actively exploited browser flaw, putting Chrome users at risk until they update. The zero-day, CVE-2026-11645, is a high-severity out-of-bounds read/write bug in the V8 JavaScript engine that can let a remote attacker run code inside Chrome’s sandbox via a specially crafted HTML page; exploitation likely requires chaining with a separate sandbox-escape flaw for full compromise. Google said the bug was reported in late April by an anonymous researcher.
Why it matters: Anyone using Chrome should update promptly because this flaw is already being used in real attacks. Even though the code runs inside Chrome’s sandbox, browser zero-days are high-priority because attackers often combine them with other bugs to fully compromise devices.
Sources
info@thehackernews.com (The Hacker News) 2026.06.10 90%
This article appears to advance the same Chrome event by reporting CISA has added the actively exploited Chrome flaw CVE-2026-11645 to KEV, reinforcing that exploitation is confirmed and that affected users and enterprises should prioritize updating Chrome 149 or later.
2026.06.09 97%
This article is a direct update on the same event, adding that CVE-2026-11645 is an out-of-bounds memory access bug in Chrome's V8 JavaScript engine, that Google paid a $55,000 bounty for the report, and that it is the fifth exploited Chrome zero-day fixed in 2026.
info@thehackernews.com (The Hacker News) 2026.06.09 99%
It covers the same underlying event: Google's patch for the actively exploited Chrome V8 zero-day CVE-2026-11645, reinforcing the urgency to update affected Chrome installations.
Sergiu Gatlan 2026.06.09 98%
This article reports the same underlying event: Google's emergency fix for CVE-2026-11645, an in-the-wild exploited Chrome zero-day in Chrome 149, and adds rollout version details for Windows, macOS, and Linux plus technical context that the flaw is an out-of-bounds read/write bug in the V8 engine reachable via crafted HTML.
Eduard Kovacs 2026.06.09 100%
This article establishes a new tracked event centered on CVE-2026-11645, a distinct Chrome zero-day that Google says was exploited in the wild and patched in Chrome 149.
Full page
Arista says exploited EOS flaw CVE-2026-7473 will not be patched and affected switch owners must use mitigations
Urgent PatchesZero-Days & CVEsTechnology & SoftwareTelecommunicationsAristaCISA
Arista says hackers have exploited a flaw in its EOS network operating system, and some affected switch platforms will not get a software fix. The issue, CVE-2026-7473, affects certain Arista devices configured as tunnel endpoints and can cause them to accept and decapsulate unconfigured tunnel traffic sent to the same IP address. Arista says impacted products include 7020R, 7280R/R2, and 7500R/R2 series, with some IPv6 decapsulation scenarios also affecting 7280R3, 7500R3, and 7800R3. CISA has added the bug to its Known Exploited Vulnerabilities list.
Why it matters: Organizations using affected Arista switches may be exposed right now, and there is no vendor patch planned, so this is a mitigation-or-replace situation rather than a routine update. Network defenders should identify affected tunnel configurations immediately, apply Arista's workarounds, and prioritize review because CISA says the flaw is being actively exploited.
Sources
info@thehackernews.com (The Hacker News) 2026.06.10 88%
This article updates that event by noting CISA has now added Arista EOS CVE-2026-7473 to the KEV catalog, confirming federal prioritization of the actively exploited flaw and increasing urgency for organizations that must rely on mitigations because some platforms will not receive a patch.
Ionut Arghire 2026.06.10 100%
This article establishes a new tracked story because it centers on a distinct exploited Arista EOS vulnerability, CVE-2026-7473, with no patch planned and fresh KEV action, which is not the same underlying event as any existing tracked story.
Full page
Claroty finds critical remote-attack flaws in Vertiv UPS cards and Trane Tracer SC+ HVAC controllers used in data centers
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareVertivTrane
Researchers found critical vulnerabilities in Vertiv UPS network cards and Trane Tracer SC+ HVAC controllers that could let hackers remotely disrupt power protection and cooling systems in data centers and other facilities. Claroty reported authentication-bypass and remote-code-execution flaws in Vertiv cards, and authentication bypass, remote code execution, denial-of-service, and sensitive-information exposure issues in Trane Tracer SC+ building-management controllers; the vendors have issued patches, but the article does not list CVE IDs or affected versions.
Why it matters: These products help keep servers powered and cool, so successful attacks could cause outages, hardware damage, or forced shutdowns. Organizations using Vertiv UPS management cards or Trane Tracer SC+ should identify exposed systems and apply vendor patches and mitigations quickly.
Sources
Eduard Kovacs 2026.06.10 100%
This article appears to be the first tracked item establishing the disclosure of these specific Claroty-reported vulnerabilities in Vertiv UPS cards and Trane Tracer SC+ controllers.
Full page
ServiceNow says attackers exploited an unauthenticated API flaw to access data in some customer instances
Zero-Days & CVEsBreaches & Data LeaksServiceNow
ServiceNow told affected customers that attackers accessed data from some hosted customer instances through a flaw in an API endpoint. The company said it applied a security update on June 5, 2026 to require authentication for the affected endpoint, reportedly /api/now/related_list_edit/create, after detecting anomalous activity. ServiceNow has not yet assigned a CVE, and says the issue mainly affects customers on the Australia release or older releases with certain configuration changes.
Why it matters: Organizations using affected ServiceNow instances may have exposed sensitive ticket, employee, asset, and incident-response data, including credentials or tokens pasted into support workflows. This is urgent for affected customers: review logs and exposed records immediately, check for requests to the vulnerable endpoint, and rotate any secrets that may have been accessible.
Sources
Eduard Kovacs 2026.06.10 98%
This is the same underlying event: ServiceNow patched the flaw in hosted instances on June 5, said exploitation allowed unauthenticated users in some cases to gain greater access and query instance tables, noted affected customers were notified, and added detail that Australia platform release users or customers with specific configuration changes were affected. It also reports the company is still evaluating a CVE assignment and that some reports claim ServiceNow had known of the issue since April 7.
info@thehackernews.com (The Hacker News) 2026.06.10 99%
This article covers the same underlying event: exploitation of a ServiceNow flaw to gain unauthorized access to customer instances, reinforcing the incident details and affected scope already tracked.
Lawrence Abrams 2026.06.09 100%
This article appears to be the first concrete reporting of the ServiceNow incident, including exploitation details, affected release scope, the likely endpoint, and operational guidance for defenders.
Full page
UK scales back planned telecom cybersecurity rules introduced after Salt Typhoon espionage campaign
Policy & RegulationThreat Actors & APTsTelecommunicationsGovernment
The UK has weakened proposed telecom security requirements that were drafted after the China-linked Salt Typhoon spying campaign against telecom networks. Recorded Future News reports the government dropped or delayed several measures after industry objections, including a proposed independent signalling intrusion detection system meant to detect abuse of telecom signalling traffic. The updated code takes effect in mid-July unless Parliament blocks it, and operators can still be judged against it under existing telecom security duties.
Why it matters: This affects how well UK phone and internet providers may detect and contain state-backed intrusions into core communications networks. Telecom operators, regulators, and enterprise customers should review the final code now because the changes may leave weaker safeguards against the kinds of access used for large-scale espionage.
Sources
2026.06.09 100%
The article establishes a distinct UK policy story: the government’s rollback of telecom security measures specifically developed in response to Salt Typhoon-style telecom espionage.
Full page
Public zero-day in VS Code and github.dev can steal GitHub tokens and expose private repositories
Zero-Days & CVEsUrgent PatchesSupply ChainTechnology & SoftwareMicrosoftGitHub
A newly disclosed Visual Studio Code flaw can let attackers steal a victim’s GitHub sign-in token with a single click on a malicious link, potentially exposing all private repositories that account can access. Researcher Ammar Askar published proof-of-concept exploit code on June 3, 2026; no CVE has been assigned and no official patch is available. The bug abuses message passing between sandboxed webviews and the main editor in github.dev, allowing a malicious extension to be installed and extract a broad GitHub OAuth token.
Why it matters: Developers, maintainers, and employees who use github.dev or VS Code-linked GitHub workflows could have source code and other private repository data exposed before a fix is available. Until Microsoft and GitHub ship a patch, users should treat github.dev links cautiously and clear github.dev cookies/site data so unexpected extension sign-in prompts appear.
Sources
BrianKrebs 2026.06.09 53%
Krebs notes Microsoft also patched a zero-day in Visual Studio Code that can steal GitHub tokens, which appears to be the same underlying VS Code/github.dev token-theft flaw tracked separately.
2026.06.04 95%
This article is a direct update on that same VS Code/github.dev token-theft zero-day, adding that researcher Ammar Askar publicly released a working exploit, said he bypassed Microsoft’s reporting process, and that GitHub received about one hour’s notice before disclosure while Microsoft has not clarified crediting, CVE assignment, or exposure scope.
Eduard Kovacs 2026.06.04 99%
This article covers the same underlying event: Ammar Askar’s public disclosure of a one-click VS Code/github.dev zero-day that steals GitHub tokens via a malicious Jupyter notebook and extension install. It adds that Microsoft patched github.dev on June 3, notes the desktop VS Code path appears to remain unpatched, and reiterates the remote-code-execution risk on desktop.
2026.06.03 97%
This article is a direct report on the same underlying event: Ammar Askar's public disclosure of a VS Code/github.dev flaw that abuses Workspace Recommendations and a Jupyter Notebook Webview trick to auto-install a malicious extension and steal GitHub OAuth tokens. It adds detail on the disclosure timeline, Askar's decision to publish within an hour of notifying a GitHub contact, and his stated dispute with MSRC over prior VS Code vulnerability handling.
info@thehackernews.com (The Hacker News) 2026.06.03 96%
The article appears to cover the same underlying event: a one-click attack in GitHub Dev/github.dev related to VS Code that can steal full GitHub OAuth tokens and expose private repositories.
Sergiu Gatlan 2026.06.03 100%
This article appears to be the first major report establishing a distinct public zero-day affecting VS Code/github.dev, with exploit code and immediate defender action needed.
Full page
Check Point patches exploited VPN authentication-bypass zero-day CVE-2026-50751 tied to Qilin ransomware activity
Urgent PatchesRansomwareZero-Days & CVEsGovernmentTechnology & SoftwareCheck PointCISA
Check Point says attackers used a zero-day flaw to break into some of its VPN systems, and at least one confirmed follow-on intrusion was linked to the Qilin ransomware operation. The main issue, CVE-2026-50751, is an unauthenticated authentication-bypass bug affecting Remote Access VPN, Mobile Access / SSL VPN, and Spark gateways when configured with deprecated IKEv1, legacy clients, and no mandatory machine certificate; Check Point also disclosed CVE-2026-50752, an IKEv1 certificate-validation flaw that could enable man-in-the-middle attacks on site-to-site VPNs. Exploitation began May 7 and has hit a few dozen organizations globally.
Why it matters: Organizations using affected Check Point VPN setups could be exposed to break-ins without valid credentials, with ransomware risk if attackers get in. This is urgent: apply Check Point's updates immediately or disable IKEv1, require machine certificates, and follow the vendor's mitigations.
Sources
Arctic Wolf 2026.06.09 97%
This article covers the same underlying event: active exploitation of Check Point VPN authentication-bypass flaw CVE-2026-50751. It adds operational detail on the affected products and versions, the IKEv1 certificate-validation logic flaw, exploitation timing dating back to May 7, CISA KEV inclusion, and concrete mitigation and detection guidance including hotfix SK185033 and monitoring recommendations.
Ionut Arghire 2026.06.09 99%
This article is a direct report on the same underlying event, adding specifics that exploitation began on May 7, affected a few dozen targeted organizations globally, involved deprecated IKEv1 certificate-validation logic, and that CISA added CVE-2026-50751 to KEV with a June 11 federal patch deadline; it also notes a second flaw, CVE-2026-50752, enabling site-to-site VPN man-in-the-middle attacks but not observed exploited.
Sergiu Gatlan 2026.06.09 96%
This article is a direct update on the same CVE-2026-50751 zero-day, adding that CISA placed it in the KEV catalog and ordered U.S. federal agencies to patch by June 11 under BOD 22-01, while reiterating exploitation details and mitigations for affected Check Point Remote Access VPN, Mobile Access, and Spark deployments using IKEv1.
2026.06.08 98%
This article is a direct update on the same Check Point VPN zero-day event, adding that exploitation began as early as May 7, that attackers had about a month-long head start before the fix, that several dozen organizations were targeted globally, and that Check Point also disclosed a related second flaw, CVE-2026-50752, affecting IKEv1 site-to-site VPN certificate validation.
Sergiu Gatlan 2026.06.08 100%
This article establishes a new tracked event centered on Check Point's disclosure and patching of CVE-2026-50751 as an exploited zero-day, plus the attribution of at least one post-compromise case to a Qilin ransomware affiliate.
Full page
Adobe patches 123 security flaws across Experience Manager, ColdFusion, Acrobat, Campaign Classic and other products
Urgent PatchesZero-Days & CVEsTechnology & SoftwareConsumers & General PublicAdobe
Adobe released security updates fixing 123 vulnerabilities across 11 products, affecting organizations and users running Experience Manager, ColdFusion, Acrobat Reader and other Adobe software. The biggest group is 57 flaws in Adobe Experience Manager, while ColdFusion and Campaign Classic include the highest-priority issues, with two Campaign Classic remote-code-execution bugs rated CVSS 10. Adobe said it has no evidence of in-the-wild exploitation and did not list CVE IDs in this report, but marked the ColdFusion and Campaign Classic issues as priority 1, meaning exploitation is more likely.
Why it matters: Organizations using Adobe server products should review and apply these updates promptly, especially for ColdFusion and Campaign Classic, because remote-code-execution bugs can let attackers take over systems. End users should update Acrobat and Reader through normal patch channels.
Sources
Eduard Kovacs 2026.06.09 100%
This article establishes a distinct June 2026 Adobe patch cycle story covering a large set of vulnerabilities across multiple Adobe products, with especially important fixes in ColdFusion and Campaign Classic.
Full page
OpenSSL patches high-severity PKCS#7 verification flaw CVE-2026-45447 and 17 other vulnerabilities
Urgent PatchesZero-Days & CVEsTechnology & SoftwareOpenSSL
OpenSSL released new versions to fix a high-severity bug that can crash applications and may allow remote code execution when they verify a specially crafted signed message. The main issue, CVE-2026-45447, is a heap use-after-free in PKCS7_verify() triggered by a malformed PKCS#7 or S/MIME SignedData digestAlgorithms field; OpenSSL also patched 17 other flaws ranging from low to moderate severity affecting certificate handling, encryption integrity, denial of service, and possible code execution paths.
Why it matters: OpenSSL is embedded in many servers, appliances, and applications, so this can affect far more systems than organizations realize. Teams should identify where OpenSSL is deployed and apply the new releases promptly, especially in products or services that process S/MIME or PKCS#7 signed content.
Sources
Eduard Kovacs 2026.06.09 100%
This article appears to be the first item here establishing the OpenSSL June 2026 patch event centered on CVE-2026-45447 and the broader batch of 18 fixed vulnerabilities.
Full page
Veeam patches critical Backup & Replication flaw CVE-2026-44963 that lets domain users run code on backup servers
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareVeeam
Veeam released fixes for a critical flaw in its Backup & Replication software that could let a low-privilege domain user take over a backup server. The issue, CVE-2026-44963, affects Veeam Backup & Replication 12.3.2.4465 and all earlier version 12 builds when the backup server is joined to a Windows domain; it was fixed in version 12.3.2.4854, and Veeam says version 13.x is not affected due to architectural changes.
Why it matters: Backup servers are high-value targets because attackers and ransomware gangs use them to steal data and destroy recovery options. Organizations running affected Veeam versions should update immediately and review whether backup servers are unnecessarily joined to a domain.
Sources
info@thehackernews.com (The Hacker News) 2026.06.09 99%
This article appears to report the same Veeam Backup & Replication remote-code-execution issue, centered on CVE-2026-44963 and its impact on domain-joined environments, adding another source covering the same vendor patch and risk details.
Sergiu Gatlan 2026.06.09 100%
This article establishes a new story around Veeam's disclosure and patching of CVE-2026-44963, a newly reported critical RCE flaw affecting domain-joined Veeam Backup & Replication servers.
Full page
SiribClone uses fake romance and aid lures on Telegram to spy on Russian soldiers with SafeLoveStealer and SiribGrabber malware
Threat Actors & APTsMalwareSocial Engineering & PhishingDefense & AerospaceTechnology & SoftwareConsumers & General PublicTelegram
Hackers posing as women seeking relationships or volunteers offering help tricked Russian military personnel into installing spyware or surrendering their Telegram accounts. Researchers at F6 say the previously undocumented SiribClone group has operated since at least summer 2025, targeting troops in border regions and combat zones with Android spyware dubbed SafeLoveStealer, desktop malware called SiribGrabber, and phishing sites masquerading as Telegram logins, invite pages, medical portals, and other services to steal messages, files, location data, and microphone audio.
Why it matters: This is an active espionage campaign aimed at people in combat zones and shows how romance lures and fake support offers can turn personal chats into battlefield surveillance. Anyone in sensitive roles should treat unsolicited Telegram contacts, app downloads, and login pages as high risk, avoid sideloading apps, and use phishing-resistant account protections where possible.
Sources
2026.06.09 100%
The article is the first concrete report here tying the SiribClone operation to specific lures, malware families, and Telegram account theft tactics against Russian military targets.
Full page
UK orders Apple, Google and other device makers to add controls that block nude images for children
Policy & RegulationSurveillance & PrivacyGovernmentTechnology & SoftwareConsumers & General PublicAppleGoogleUK Home OfficeSignal
The UK government says Apple, Google and other tech companies have three months to enable device-level controls on smartphones and tablets that detect and block nude images for children. The Home Office says the controls must work across apps and services by default and only be disabled through age assurance, with possible legislation, fines, and potential executive liability if companies do not comply. Officials also say adults would need age verification to access nude content on devices.
Why it matters: This is a major security-and-privacy policy development because it pushes on-device content scanning and age checks beyond individual apps into phones and tablets themselves. Device makers, app platforms, privacy advocates, parents, and UK users may all be affected, and companies now face a short deadline to respond or prepare for regulation.
Sources
2026.06.09 95%
This is a direct follow-up on the same UK child-safety device-scanning initiative, adding Signal's response that on-device scanning and age-verification requirements would weaken privacy, threaten encrypted messaging, and create infrastructure that could be repurposed for censorship and state surveillance.
2026.06.08 100%
This article appears to be the first concrete report here on the UK government's three-month demand for device-level nude-image blocking and age-assurance controls on smartphones and tablets.
Full page
Another NHS trust says the Qilin attack on Synnovis exposed patient records two years after the breach
Breaches & Data LeaksRansomwareHealthcareSynnovisMid and South Essex NHS Foundation TrustNHS
Mid and South Essex NHS Foundation Trust says the 2024 Qilin ransomware attack on pathology provider Synnovis exposed about 2,380 records tied to specialist diagnostic testing, and the total may rise as records are matched to individual patients. The incident is the same long-running data theft and service-disruption event that hit NHS pathology services in southeast London on June 3, 2024; patient data was later published after failed extortion, and affected trusts are still identifying who must be notified.
Why it matters: This shows the fallout from a major healthcare ransomware breach is still growing years later, with more patients and hospitals discovering exposed records. Affected NHS organizations need to keep tracing exposed data and notifying people, while patients contacted about past diagnostic testing should treat breach notices seriously and watch for scams or misuse of their information.
Sources
2026.06.09 100%
The article establishes a trackable development in the Synnovis/Qilin NHS breach by adding a newly confirmed affected trust and record count, showing the incident's victim scope is still expanding.
Full page
EFF says Meta smart glasses app contains active facial-recognition code that can identify people from stored faceprints
Surveillance & PrivacyTechnology & SoftwareConsumers & General PublicMeta
EFF and Wired report that Meta has shipped facial-recognition code in the software for its always-on smart glasses, potentially affecting people both using the glasses and those seen by them. EFF says static analysis confirmed code that stores faceprints as 2,048-value templates and compares newly seen faces against a local database; researchers also showed the feature could be triggered in testing by manually adding a face in debug mode, though it is not yet exposed as a consumer setting.
Why it matters: This is a significant surveillance and privacy story because it suggests consumer wearables may already contain hidden person-identification features before any public rollout. People considering Meta glasses should weigh the privacy risk, and policymakers and civil-society groups may press Meta for transparency, safeguards, or limits before deployment.
Sources
Rindala Alajaji 2026.06.08 97%
This is a direct update to the same underlying event: after the earlier reporting that Meta's smart-glasses app contained active facial-recognition code, EFF now says Meta's June 5 app update removed the face-recognition components, including recognition alerts, biometric-signature handling, and related models/databases.
Cooper Quintin 2026.06.04 100%
This article establishes a new story by documenting previously unreported facial-recognition functionality in Meta's smart-glasses software, with independent technical confirmation rather than merely opinion or advocacy.
Full page
Suspected North Korean phishing campaign sends fake developer job offers to steal credentials and cryptocurrency
Social Engineering & PhishingMalwareThreat Actors & APTsScams & FraudTechnology & SoftwareCryptocurrency & BlockchainGitHubVisual Studio CodeCursor
A likely North Korean-linked group sent more than 250 fake job and code-review emails to developers at nearly 100 organizations, mainly in the United States, to steal login credentials and cryptocurrency wallets. Proofpoint tracks the activity as UNK_DeadDrop and says the attackers used spoofed company brands and attacker-controlled GitHub repositories posing as coding tests or crypto projects; victims were told to clone and open the repos in tools such as Visual Studio Code or Cursor, triggering cross-platform malware on macOS, Linux, and Windows.
Why it matters: Developers and the companies that employ them are the direct targets, and a single successful lure can expose source code, cloud access, and crypto assets. Organizations should warn staff about unsolicited recruiting emails, scrutinize GitHub-based coding tests, and isolate or block unknown repositories and scripts.
Sources
2026.06.08 100%
This article appears to be the first tracked report establishing Proofpoint's UNK_DeadDrop campaign as a distinct, likely DPRK-linked operation using fake job offers and code-review lures against developers.
Full page
NFCShare Android malware uses fake banking app updates on GitHub to steal payment card data from European bank customers
MalwareSocial Engineering & PhishingScams & FraudFinance & BankingTechnology & SoftwareConsumers & General PublicGitHubAndroid
Attackers are tricking bank customers into installing fake Android banking app updates from GitHub so they can steal card data and PINs. D3Lab says newer NFCShare variants, seen since May 14, target banks mainly in Italy and Spain after victims visit phishing sites impersonating real banks. The malware abuses near-field communication (NFC) on Android to read card details via IsoDep and EMV commands, then sends the data to command-and-control servers over WebSocket.
Why it matters: This can lead directly to payment-card fraud because victims are persuaded to hand over both card details and their PIN during a fake security check. Android users should only install banking apps from Google Play and treat any request to scan a bank card with their phone or sideload an update from GitHub as suspicious.
Sources
Bill Toulas 2026.06.08 100%
This article establishes a concrete, current NFCShare campaign expansion, including new GitHub-hosted delivery infrastructure, broader bank targeting in Europe, and updated technical details on how the malware steals card data.
Full page
SoFi says a third-party vendor breach exposed customer data at its Hong Kong securities unit
Breaches & Data LeaksFinance & BankingSoFiSoFi Securities (Hong Kong)
SoFi says hackers got into a database used by SoFi Securities (Hong Kong) Limited through a third-party vendor, potentially exposing customer information. The company said it detected the unauthorized access on April 30, 2026 and is still investigating what data and how many customers were affected. SoFi has not named the vendor, disclosed the attack method, or said whether extortion was involved.
Why it matters: Customers of SoFi Hong Kong could face phishing, fraud, or account-targeting attempts even though the full scope is still unknown. Affected users should be cautious of unsolicited messages, change passwords, enable two-factor authentication where available, and closely monitor financial accounts.
Sources
Lawrence Abrams 2026.06.08 100%
This article appears to be the first tracked report confirming SoFi's disclosure of the vendor-related breach at its Hong Kong subsidiary and establishing the core facts of the incident.
Full page
Russia-linked Matryoshka disinformation campaign targeted Armenia’s 2026 election with fake news, bot networks, and hoax bomb threats
Disinformation & Influence OpsGovernmentMedia & EntertainmentConsumers & General PublicGovernment of Armenia
Researchers and Armenian authorities say a large Russia-linked influence operation targeted Armenia’s parliamentary election with fake stories, manipulated videos, bot amplification, and false bomb threats at polling stations. Antibot4Navalny and the Institute for Strategic Dialogue linked the activity to the Matryoshka campaign, described as part of Russia’s broader Doppelganger operation, which impersonates trusted media and government sources to spread propaganda and election-related falsehoods over an eight-month period.
Why it matters: This is the kind of coordinated deception campaign that can mislead voters, intimidate the public, and erode trust in elections even without hacking voting machines. Platforms, journalists, election officials, and civil society groups should watch for cloned media sites, impersonation, bot-driven amplification, and hybrid tactics such as hoax threats around major votes.
Sources
2026.06.08 100%
The article establishes a distinct, concrete election interference event in Armenia tied to the Matryoshka/Doppelganger Russia-linked influence apparatus, with specific tactics, timing, and impact.
Full page
Zcash fixes critical Orchard privacy-pool flaw that could have let attackers create fake ZEC
Zero-Days & CVEsUrgent PatchesCryptocurrency & BlockchainConsumers & General PublicZcash
Zcash fixed a critical vulnerability in its Orchard shielded transaction system that could have allowed attackers to generate counterfeit ZEC while transactions still appeared valid. Security researcher Taylor Hornby found the issue on May 29 while auditing Orchard; the bug was a failed transaction-input validation check in the zero-knowledge proof workflow, affecting the Orchard privacy pool introduced in 2022. No CVE is cited, and it is unclear whether the flaw was exploited before the fix.
Why it matters: This is the kind of bug that can undermine trust in a cryptocurrency by allowing undetectable fraudulent coin creation. Zcash users, exchanges, and infrastructure operators should confirm they are running the patched software and watch for any follow-up guidance on possible past exploitation.
Sources
Bruce Schneier 2026.06.08 100%
This article establishes a new tracked story because it reports the discovery and remediation of a previously unknown, critical Zcash protocol vulnerability with potential ecosystem-wide financial impact, and no existing tracked story covers this event.
Full page
Ransomware attack shuts Evanston Township High School in Illinois and disrupts summer programs
RansomwareEducationEvanston Township High SchoolFBI
A ransomware attack forced Evanston Township High School in Illinois to close for at least two days, canceling summer school, sports camps, and other on-campus activities. The school said phone systems are down and staff have limited access to email, Google accounts, and other network systems including eSchool. External forensics specialists and breach counsel were engaged, and the FBI is involved. No ransomware group has publicly claimed responsibility yet.
Why it matters: This is a real-world operational disruption affecting students, families, and staff, not just an IT outage. Schools and local governments should review incident response readiness, offline recovery options, and communications plans, while affected families should watch for follow-up notices about any data exposure.
Sources
2026.06.08 100%
The article establishes a distinct incident at Evanston Township High School with confirmed ransomware, active recovery, and school closures.
Full page
Powys Council says cyberattack affected 13 schools in Wales and exposed some staff and pupil data
Breaches & Data LeaksGovernmentEducationPowys County Council
A separate cyberattack in Powys, Wales affected systems used by 13 schools, and the council says personal data belonging to staff and pupils was accessed. Current information indicates data was taken from one of the affected schools, but officials have not named the schools involved, the number of people affected, or the exact data types because of the sensitivity of the incident. The council has not confirmed ransomware or identified the attacker.
Why it matters: This affects children, school staff, and families, and may carry identity-fraud and privacy risks even though schools remain open. People connected to Powys schools should monitor official notifications and be cautious about phishing or scam messages that use school-related details.
Sources
2026.06.08 100%
The article introduces a separate, clearly scoped Wales school-sector breach with confirmed unauthorized access to personal data and no matching tracked story.
Full page
Russia updates SORM surveillance rules to expand automated tracking of citizens' online activity
Surveillance & PrivacyPolicy & RegulationGovernmentTechnology & SoftwareTelecommunicationsConsumers & General PublicRoskomnadzor
Russia has updated the technical rules for its SORM surveillance system, expanding how authorities can search and connect people's internet and communications data. The new regulations require broader collection, processing, and transmission of identifiers including names, passport and tax numbers, addresses, usernames, domains, URLs, device identifiers, and geolocation data. The rules apply beyond telecom carriers to other online service operators and increase compliance burdens on providers.
Why it matters: This matters because it strengthens Russia's ability to monitor individuals without shutting the internet off, making targeted repression and self-censorship easier while pressuring providers to integrate with state surveillance systems. The impact is immediate for people and companies operating in Russia, especially telecom and internet services that may need to change infrastructure or face regulatory penalties.
Sources
2026.06.08 100%
The article centers on a specific new regulatory change published by Russia's Ministry of Digital Development that upgrades SORM's data-search and integration requirements, establishing a distinct surveillance-policy story not represented in the existing tracked items.
Full page
Attackers exploit Everest Forms Pro WordPress plugin flaw CVE-2026-3300 to take over sites
Zero-Days & CVEsTechnology & SoftwareConsumers & General PublicWordPressEverest Forms
Hackers are actively exploiting a critical bug in the Everest Forms Pro WordPress plugin to seize control of vulnerable websites. The flaw, CVE-2026-3300, affects Everest Forms Pro 1.9.12 and earlier and allows unauthenticated remote code execution through the plugin’s Complex Calculation feature, which unsafely passes form input into PHP eval(). Wordfence says attacks began by April 13 and are creating rogue administrator accounts, including one named “diksimarina.”
Why it matters: Affected WordPress sites can be fully hijacked without a login, allowing attackers to add admin users, install backdoors, and alter site content. Site owners should update immediately, review administrator accounts and logs for suspicious activity, and check for indicators tied to the reported campaign.
Sources
Ionut Arghire 2026.06.08 98%
This article is the same underlying event and adds detail that exploitation began on April 13, Defiant blocked over 29,000 attempts, the attacks often created an admin account named 'diksimarina', and the bug stems from unsafe handling in the Complex Calculation feature despite a March patch in version 1.9.13.
Bill Toulas 2026.06.06 100%
This article establishes a distinct new story around active exploitation of CVE-2026-3300 in Everest Forms Pro, including affected versions, exploitation details, attacker behavior, and defender guidance.
Full page
Lansing Community College says 174,000 people were affected by a 2025 breach using compromised credentials
Breaches & Data LeaksEducationConsumers & General PublicLansing Community College
Lansing Community College says hackers got into some of its systems in February 2025 and exposed personal information belonging to more than 174,000 people. The school says the intrusion began with compromised credentials and affected data can include names, addresses, dates of birth, driver's license details, and Social Security numbers, with the exact data varying by person. LCC says it found the incident about a week after the access began and has not identified the threat actor publicly.
Why it matters: This is a large education-sector breach involving identity data that can be used for fraud, tax scams, and account takeover. Affected people should watch for notice letters, enroll in credit monitoring, and consider fraud alerts or credit freezes.
Sources
Ionut Arghire 2026.06.08 100%
This article appears to be the initial broad public reporting of Lansing Community College's disclosure, including victim count, attack timing, access method, and the categories of personal data exposed.
Full page
FBI warns Silent Ransom Group is sending fake IT workers in person to law firms to plug in USB drives and steal data
Threat Actors & APTsRansomwareScams & FraudSocial Engineering & PhishingBreaches & Data LeaksLegal & Professional ServicesFBI
The FBI says Silent Ransom Group is targeting U.S. law firms by pretending to be IT support, then stealing data and extorting victims without encrypting files. In 2026 attacks, the group reportedly used callback phishing emails, phone-based social engineering, remote desktop access, and in some cases sent an operative on site to insert a USB or external drive after a failed remote-access attempt; the attackers then used tools such as WinSCP and Rclone to exfiltrate data.
Why it matters: Law firms and other organizations should treat unsolicited IT calls, emails, and in-person support visits as potential attack vectors, not just remote phishing. The warning is urgent because the attackers use legitimate admin tools and leave few traces, so organizations should verify IT identities, restrict external-drive use, and harden remote-access workflows now.
Sources
Ionut Arghire 2026.06.08 84%
This updates the same underlying Silent Ransom Group campaign targeting U.S. law firms. It adds new reporting that the group is using DNS fast flux infrastructure, with compromised IoT/CPE devices across 18 countries and domains including ep6pheij[.]com and business-data-leaks[.]com, alongside the previously reported vishing, remote-access, and in-person USB tactics.
Lawrence Abrams 2026.06.07 96%
This article covers the same Silent Ransom Group campaign against U.S. law firms and adds Mandiant’s technical details on the attack chain: invoice-themed precursor emails, follow-up fake IT support calls, use of Teams/Zoom/Quick Assist/Terminal Services, deployment of remote-management tools like AnyDesk and Zoho Assist, phishing domain patterns, use of Privnote, and rapid data theft and extortion timelines.
2026.06.05 96%
This article covers the same underlying Silent Ransom Group/UNC3753 campaign and adds Mandiant reporting that dozens of banks, law firms, and professional-services firms were targeted from January through May 2026, that the group is also tracked as Luna Moth and Chatty Spider, and that Mandiant observed very rapid operations with data theft and extortion sometimes beginning within an hour.
2026.05.27 97%
This article is a direct report on the same FBI advisory, adding detail that fresh in-person incidents were reported in Spring 2026 and describing the crew's tactics, including impersonating IT staff, using callback phishing, remote desktop access, WinSCP, disguised Rclone, and cloud file-sharing services to steal data for extortion.
2026.05.27 98%
This article directly reports the same FBI advisory on Silent Ransom Group (also Luna Moth/UNC3753) targeting U.S. law firms with phishing, fake help-desk calls, remote-access social engineering, and in-person visits to copy data onto USB or hard drives. It adds context that the group is linked to the defunct Conti syndicate, has targeted law firms since 2023, and uses trusted tools and cloud services like OneDrive and Google Drive to blend in.
Sergiu Gatlan 2026.05.27 99%
This article is the same underlying event: the FBI flash alert on Silent Ransom Group's in-person and remote social-engineering attacks against U.S. law firms. It adds detail that SRG first tries phone and phishing lures to obtain remote desktop access, then may dispatch someone on-site to connect USB or external drives if that fails, and reiterates links to Luna Moth/UNC3753 and prior callback-phishing activity.
Ionut Arghire 2026.05.27 100%
This article appears to establish a distinct FBI-tracked development in Silent Ransom Group tradecraft: in-person operatives physically inserting devices to support data theft and extortion targeting law firms.
Full page
CISA says attackers are exploiting SolarWinds Serv-U denial-of-service flaw CVE-2026-28318
Urgent PatchesZero-Days & CVEsTechnology & SoftwareSolarWindsCISA
CISA says hackers are now actively exploiting a recently patched SolarWinds Serv-U bug to crash exposed file-transfer servers. The flaw, CVE-2026-28318, affects SolarWinds Serv-U MFT and FTP software on Windows and Linux and can be triggered without authentication using specially crafted POST requests with Content-Encoding: deflate; SolarWinds fixed it in Serv-U 15.5.4 Hotfix 1 and advised admins who cannot patch to restrict access and block such requests.
Why it matters: Organizations running internet-exposed Serv-U servers could face service outages right now, including federal agencies ordered to remediate by June 19. If you use Serv-U, patch immediately or apply SolarWinds' temporary filtering and access restrictions while checking for signs of attempted abuse.
Sources
Ionut Arghire 2026.06.08 98%
This is the same underlying event: active exploitation of SolarWinds Serv-U CVE-2026-28318. The article adds patch timing details, notes the fix is Serv-U 15.5.4 Hotfix 1, explains the unauthenticated specially crafted POST request with the 'Content-Encoding: deflate' header, and reiterates affected/EoL versions and CISA's June 19 federal patch deadline.
info@thehackernews.com (The Hacker News) 2026.06.06 99%
It covers the same underlying event: CISA adding the actively exploited SolarWinds Serv-U flaw CVE-2026-28318 to the Known Exploited Vulnerabilities catalog, reinforcing the exploitation status and remediation urgency for affected organizations.
Sergiu Gatlan 2026.06.05 100%
This article establishes a new tracked story because it is the first item here tying SolarWinds Serv-U CVE-2026-28318 to active exploitation and CISA KEV inclusion.
Full page
Attackers used Meta’s Instagram AI support bot to reset passwords and hijack accounts
Breaches & Data LeaksSocial Engineering & PhishingGovernmentDefense & AerospaceTechnology & SoftwareConsumers & General PublicMetaInstagramObama White HouseU.S. Space Force
Attackers used Meta’s automated Instagram support assistant to take over accounts, including the Obama White House account and the U.S. Space Force chief master sergeant account, and briefly deface them with pro-Iran messages. According to KrebsOnSecurity and Telegram posts cited in the report, the abuse involved the password-recovery flow: attackers asked the AI bot to add a new email address to a target account, then used the one-time code sent there to reset the password. No CVE is given, Meta reportedly pushed an emergency patch, and accounts with multi-factor authentication enabled were said to resist the takeover.
Why it matters: This matters because it shows AI-driven customer support can become a new social-engineering path to account takeover even without a backend database breach. Instagram users, especially high-value or public-facing accounts, should enable multi-factor authentication now and review account recovery email addresses and recent login activity.
Sources
Eduard Kovacs 2026.06.08 98%
This is the same underlying event: abuse of Meta’s AI-powered Instagram account recovery/support workflow to reset passwords and hijack accounts. It adds Meta’s disclosure that 20,225 accounts were potentially affected, the discovery date (May 31), a precise explanation of the email-verification bug in the High Touch Support tool, and remediation steps including disabling the tool, invalidating reset links, and forcing security checkpoints.
Sergiu Gatlan 2026.06.08 99%
This is the same underlying event: abuse of Meta's High Touch Support AI-assisted Instagram recovery flow to issue password reset links and hijack accounts. The article adds Meta's breach disclosure, an estimated impact of over 20,000 stolen accounts, timeline details including discovery on May 31 and breach activity dating to April 17, and Meta's response steps such as disabling HTS, invalidating reset links, and requiring account re-authentication.
Bruce Schneier 2026.06.04 98%
This is the same underlying event: attackers abused Meta’s Instagram AI support assistant to add attacker-controlled email addresses, receive verification codes, and trigger password resets for victim accounts; this source adds that Meta spokesperson Andy Stone said the issue was fixed.
Bill Toulas 2026.06.02 99%
This is the same underlying event: attackers abused Meta’s AI-powered Instagram support and recovery process to change account email addresses, bypass recovery safeguards including selfie verification and reportedly 2FA, and hijack high-value accounts such as the Obama White House account. This source adds reporting on victims being trapped in AI-only recovery loops, claims that AI-generated animated selfies were accepted for identity checks, and Meta communications VP Andy Stone’s statement that the issue was resolved and impacted accounts were being secured.
Ionut Arghire 2026.06.02 99%
This article covers the same underlying event and adds specifics on the attack path: a confused-deputy logic flaw in Meta’s AI-powered recovery assistant let attackers relink victim accounts to new email addresses, use VPNs to mimic victims’ locations, sometimes submit AI-modified selfies, and then reset passwords without effective 2FA blocking. It also says Meta has now fixed the issue.
BrianKrebs 2026.06.01 100%
This article appears to be the first concrete report tying a specific Meta AI support-bot recovery flaw to real Instagram account hijackings and visible defacements.
Full page
C0XMO Gafgyt botnet exploits DD-WRT router flaw CVE-2021-27137 to spread across routers and IoT devices
MalwareThreat Actors & APTsZero-Days & CVEsTechnology & SoftwareTelecommunicationsConsumers & General PublicDD-WRT
A new botnet called C0XMO is infecting DD-WRT routers and other internet-connected devices so they can be used in denial-of-service attacks. Fortinet says the malware exploits CVE-2021-27137, an unauthenticated buffer overflow in DD-WRT, and also brute-forces Telnet and SSH logins while carrying binaries for multiple CPU architectures including ARM, MIPS, PowerPC, x86, and x86_64. The botnet establishes persistence with cron jobs and startup-file changes, then removes rival malware and tooling from infected systems.
Why it matters: Organizations and users with exposed routers, DVRs, and similar devices may be silently pulled into a botnet and used in attacks. Patch affected firmware where available, disable unnecessary remote administration, and change weak or reused device credentials immediately.
Sources
Bill Toulas 2026.06.07 100%
This article appears to be the first tracked item establishing the C0XMO botnet campaign and its use of CVE-2021-27137 in DD-WRT devices.
Full page
Polyfill.io remnants trigger rogue login prompts on Toshiba, Muji and other websites
Supply ChainSocial Engineering & PhishingManufacturingRetail & E-CommerceTechnology & SoftwareConsumers & General PublicToshibaMujiPolyfill.io
Toshiba and Muji warned that visitors to some of their web pages saw unexpected browser sign-in prompts that could trick people into entering credentials. The prompts were tied to lingering references to the compromised polyfill.io JavaScript content delivery network (CDN), which began responding with HTTP 401 authentication challenges in late May 2026; affected companies removed or suspended the service, and no confirmed credential theft has been reported so far.
Why it matters: People who entered usernames or passwords into these pop-ups should change them, and website owners should remove any remaining polyfill.io code immediately. This matters because it shows how a long-abandoned third-party script can still create phishing risk years after an earlier supply-chain compromise.
Sources
Bill Toulas 2026.06.05 100%
This article establishes a distinct 2026 follow-on event from the earlier Polyfill compromise: dormant polyfill.io inclusions on live sites caused browser credential prompts on major websites, creating a fresh user-facing phishing risk.
Full page
China-linked UNC5221 used Brickstorm, Plenet and AgentPSD malware to keep long-term access to victim networks and Microsoft 365
Threat Actors & APTsMalwareTechnology & SoftwareLegal & Professional ServicesMicrosoftEgnyteNetgateSynology
A China-linked espionage group kept access to a victim organization and its managed services provider for at least 18 months, using multiple backdoors to return even after cleanup. Volexity says UNC5221, also tracked as VerdantBamboo, used Brickstorm on Egnyte Storage Sync, pfSense, Synology NAS and a retired Linux email server, then used Plenet (also called Grimbolt) and AgentPSD to maintain persistence and reach the victim’s Microsoft 365 environment through stolen credentials and SSL VPN access. No new CVE is named in this report.
Why it matters: Organizations using Microsoft 365, MSPs, and internet-facing edge devices should treat this as a reminder that sophisticated attackers can survive remediation and re-enter through trusted providers. Review VPN and firewall changes, hunt for Brickstorm/Plenet/AgentPSD, audit MSP access paths, and rotate credentials and tokens tied to compromised systems.
Sources
Bill Toulas 2026.06.05 100%
This article establishes a distinct incident report on UNC5221/VerdantBamboo intrusions, adding newly documented malware and concrete details about persistence through an MSP and Microsoft 365 access rather than updating one of the existing tracked stories.
Full page
Suspected Iranian hackers accessed internet-exposed gas station tank monitors across multiple U.S. states
Policy & RegulationInformation FreedomUrgent PatchesThreat Actors & APTsEnergy & UtilitiesRetail & E-CommerceCISA
U.S. officials believe suspected Iranian hackers broke into fuel-tank monitoring systems at gas stations in several states. The attackers targeted automatic tank gauges, or ATG systems, that were exposed online without passwords and changed displayed readings but reportedly could not alter actual fuel volumes. No physical damage has been reported, but officials warned the access could potentially hide leaks or create other safety and critical-infrastructure risks.
Why it matters: Gas stations and operators using older internet-connected monitoring gear may be at risk right now, especially if devices are reachable online without authentication. Operators should immediately remove ATG systems from direct internet exposure, require passwords, and review logs and display anomalies.
Sources
Sergiu Gatlan 2026.06.05 96%
This is a direct update on the same ATG gas-station tank-monitoring intrusion wave, adding the joint CISA/FBI/NSA advisory, details on likely attack methods, and Shadowserver's count of 1,061 exposed ATG systems globally, including 909 in the U.S.
SecurityWeek News 2026.06.05 76%
It ties the broader multi-agency U.S. warning on exposed Automatic Tank Gauge systems to the previously reported Iran-linked compromises of gas-station tank monitors and reiterates the immediate mitigation guidance to disconnect exposed systems from the internet.
Lawrence Abrams 2026.06.03 94%
This is a direct government follow-up to the same tank-monitoring intrusion activity previously reported by CNN, adding an official multi-agency advisory, broader sector impact beyond gas stations, and specific attack methods and mitigations. It also notes the activity remains unattributed in the advisory despite earlier reporting pointing to suspected Iranian involvement.
SecurityWeek News 2026.05.22 100%
This article establishes a distinct critical-infrastructure intrusion story involving suspected Iranian access to exposed gas station ATG systems across multiple states.
Full page
European Commission proposes tech sovereignty package covering chips, cloud, AI and open-source security
Policy & RegulationSupply ChainGovernmentTechnology & SoftwareManufacturingEuropean Commission
The European Commission unveiled a new tech sovereignty package meant to reduce the European Union's dependence on U.S. and Chinese technology suppliers. The package includes draft laws for semiconductors and cloud and AI infrastructure, plus an Open Source Strategy that would fund maintenance and security for critical open-source components and push public-sector procurement toward open technologies as part of broader digital resilience planning.
Why it matters: This matters to governments, public-sector buyers, vendors, and defenders because it could reshape which technologies Europe relies on for critical systems and how security funding is directed, especially for open-source components that underpin widely used infrastructure. Organizations should watch the legislative process, procurement changes, and any resulting security requirements for cloud, AI, and software supply chains.
Sources
2026.06.05 100%
This article establishes a new story around the EU's specific 2026 tech sovereignty legislative package and strategy rollout, rather than updating an existing tracked event.
Full page
Microsoft links GPU cryptojacking malware campaign to poisoned search results and AI chatbot software recommendations
Social Engineering & PhishingMalwareScams & FraudTechnology & SoftwareCryptocurrency & BlockchainConsumers & General PublicMicrosoft
Attackers are tricking people looking for popular PC utilities into installing malware that secretly uses their graphics cards to mine cryptocurrency. Microsoft says the campaign uses search-engine optimization (SEO) poisoning and, in some cases, attacker-controlled links surfaced in AI chatbot responses for tools such as CrystalDiskInfo, HWMonitor, FurMark, K-Lite Codec Pack, PDFgear, and Display Driver Uninstaller. The fake downloads bundle a legitimate program with a malicious dynamic-link library (DLL), install ScreenConnect for remote access, add multiple Windows persistence mechanisms, evade Microsoft Defender, and then deploy GPU miners including gminer, lolMiner, and SRBMiner-MULTI.
Why it matters: This campaign targets owners of powerful Windows systems and can leave victims with both hijacked hardware and a remote-access backdoor for follow-on attacks. Users and defenders should avoid downloading software from AI-generated or unfamiliar links, verify vendor domains, and hunt for the listed indicators of compromise and unauthorized ScreenConnect installs.
Sources
SecurityWeek News 2026.06.05 91%
It summarizes Microsoft’s findings that attackers are abusing both SEO poisoning and AI chatbot recommendations to deliver fake utilities, then using ScreenConnect and process hollowing to deploy GPU-focused cryptominers.
Ionut Ilascu 2026.05.27 100%
This article establishes a distinct Microsoft-documented malware campaign centered on SEO poisoning and AI chatbot link manipulation to deliver GPU-mining malware and persistent remote access.
Full page
Sophos says ransomware operator used AI agents from Cursor and Claude to build EDR-evasion and Active Directory attack tools
MalwareThreat Actors & APTsRansomware
Sophos says it found a ransomware attack toolkit in a customer environment that was built with help from AI coding agents and used to hide from security software and map a victim's Windows network. The framework included Cobalt Strike traffic-masking profiles, Telegram-based command and control, a Cloudflare Worker redirector, and Python tools that generated Rust and Go payloads for evasion and execution. Sophos found operator logs referencing a ransom note and organizations listed on a ransomware leak site, indicating criminal use rather than legitimate red-team testing.
Why it matters: This shows AI tools are being used to speed up real ransomware tradecraft, especially defense evasion and internal network discovery. Defenders should review detections for Telegram and Cloudflare-backed command channels, unusual payload loaders, and suspicious Active Directory reconnaissance, and treat AI-assisted malware development as an operational threat rather than a theory.
Sources
SecurityWeek News 2026.06.05 62%
It adds reporting on Microsoft’s tracking of Storm-2697 and The Gentlemen ransomware-as-a-service, including the Go-based encryptor’s self-propagation via scheduled tasks with SYSTEM privileges.
Bill Toulas 2026.06.02 100%
This article appears to be the first tracked report establishing this specific Sophos-documented ransomware toolkit and its AI-assisted development workflow.
Full page
Hola Browser for Windows supply-chain compromise delivered a Monero cryptominer to some users
MalwareSupply ChainTechnology & SoftwareConsumers & General PublicCryptocurrency & BlockchainHolaMicrosoft
Hola says its Windows browser installer was compromised and, in some cases, delivered hidden mining malware to users. AppEsteem certification checks and analysis by Sophos found an undeclared executable, 'me.exe,' installed under the Hola program folder; the binary was unsigned, obfuscated, added a Microsoft Defender exclusion, copied itself as 'HolaMonitorService.exe,' created the 'hola_monitor_svc' Windows service for persistence, and appeared to mine Monero when the PC was idle. Hola said about 0.1% of users were affected and that it rebuilt its distribution pipeline after separately confirming the compromise with Sygnia.
Why it matters: People who installed Hola Browser on Windows may have unknowingly run malware that abuses their computer for cryptocurrency mining and weakens local defenses. Affected users and admins should treat this as urgent: verify installations, look for the named files and service, remove Hola if necessary, and reinstall only from a trusted, verified build.
Sources
SecurityWeek News 2026.06.05 69%
The roundup explicitly notes the Hola Browser miner bundling as one of the week’s notable items, reinforcing that compromise as a tracked security event.
Bill Toulas 2026.06.04 100%
This article establishes a distinct supply-chain attack on Hola Browser for Windows, including malware behavior, limited scope claims, and vendor confirmation of the compromise.
Full page
DentaQuest breach exposed personal and health-insurance data for about 2.6 million accounts after ShinyHunters leak
Breaches & Data LeaksHealthcareInsuranceConsumers & General PublicDentaQuest
DentaQuest says hackers accessed part of its network, and leaked data reviewed by Have I Been Pwned indicates about 2.6 million accounts were exposed. The company was listed by the ShinyHunters extortion group, which claimed to have stolen more than 234 GB of data and later leaked it publicly; exposed fields reportedly include email addresses, full names, phone numbers, dates of birth, gender, government-issued IDs, and health-insurance information.
Why it matters: This is a major breach affecting customers of one of the largest U.S. dental benefits administrators, and the exposed identity and insurance data can fuel phishing, impersonation, and fraud. Affected people should watch for breach notices, be wary of calls or emails claiming to be from insurers or providers, and monitor accounts and insurance activity.
Sources
Ionut Arghire 2026.06.05 99%
This article covers the same DentaQuest/ShinyHunters breach and adds that SecurityWeek reported the leak size at 234 GB, that DentaQuest confirmed unauthorized access to a limited portion of its network, and reiterates the affected data types and approximate 2.6 million account count from Have I Been Pwned.
Bill Toulas 2026.06.04 100%
This article establishes a distinct breach event: DentaQuest confirmed unauthorized network access, and external analysis tied the public leak to 2.6 million exposed records.
Full page
City of York Council email error exposed hundreds of Blue Badge holders and revealed their disability status
Breaches & Data LeaksSurveillance & PrivacyGovernmentConsumers & General PublicCity of York CouncilInformation Commissioner's Office
City of York Council accidentally exposed the email addresses of hundreds of Blue Badge holders by sending messages without using blind carbon copy (BCC). Because the list was for Blue Badge-related communications, recipients could also infer that others on the list were disabled or had mobility impairments, making the breach especially sensitive. The council said it triggered its breach procedures, warned recipients to watch for suspicious messages, and the UK Information Commissioner's Office said it received a breach report and closed the case with advice.
Why it matters: This is a meaningful privacy breach because it exposed not just contact details but sensitive status information about disabled residents. Affected people should be alert for phishing or harassment, and public-sector organizations should review bulk-email controls and handling of special-category personal data.
Sources
2026.06.05 100%
This article establishes a distinct local-government data breach event involving City of York Council's mistaken disclosure of Blue Badge holders' email addresses and inferred disability status.
Full page
RCI Hospitality says breach tied to web-server access flaw exposed data on about 40,000 people
Breaches & Data LeaksHospitality & TravelConsumers & General PublicTechnology & SoftwareRCI HospitalityRCI Internet ServicesMicrosoft
RCI Hospitality says a cyberattack exposed sensitive personal data belonging to roughly 40,000 people. The company previously disclosed that its RCI Internet Services subsidiary found an insecure direct object reference, or IDOR, flaw on an IIS web server on March 23 that allowed unauthorized access to personal information, and it later determined files were stolen. Exposed data included names, contact details, dates of birth, Social Security numbers, and driver’s license numbers.
Why it matters: People affected face a real risk of identity theft because the stolen files included high-value personal data. Organizations should review web applications for IDOR-style authorization flaws, and affected individuals should watch for fraud and consider credit monitoring or freezes.
Sources
Eduard Kovacs 2026.06.05 100%
This article appears to be the first clear impact update establishing the RCI Hospitality breach as a trackable story, adding the concrete figure of roughly 40,000 affected individuals and confirming file theft.
Full page
Magecart campaign uses Google Tag Manager and Stripe API to steal payment cards from Magento checkout pages
Scams & FraudSocial Engineering & PhishingMalwareRetail & E-CommerceConsumers & General PublicTechnology & SoftwareMagentoAdobeGoogleStripe
Researchers say a new Magecart card-skimming campaign is stealing shoppers’ payment details from compromised online stores and hiding both its malware and stolen data inside trusted Google Tag Manager and Stripe services. Sansec says the skimmer targets Magento and Adobe Commerce checkout pages, pulls JavaScript from a Google Tag Manager container, retrieves payload code from Stripe customer metadata tied to customer ID cus_TfFjAAZQNOYENR, and exfiltrates stolen card, billing, email, and phone data by creating fake Stripe customer records; a variant uses Google Firestore instead of Stripe. The Stripe record was reportedly created on December 24, 2025, suggesting the campaign may have been active for months.
Why it matters: This matters because stores may allow traffic to Google Tag Manager and Stripe by default, letting the skimmer blend in and evade common security controls while stealing card data from real customers. Online retailers using Magento or Adobe Commerce should urgently inspect GTM containers, Stripe API activity, and checkout-page scripts for unauthorized changes.
Sources
Bill Toulas 2026.06.04 100%
This article appears to be the initial report on a distinct Magecart payment-card theft campaign that abuses Stripe and Google Tag Manager as trusted infrastructure, not an update to an existing tracked story.
Full page
Russia moves to label Belarusian Cyber Partisans and Silent Crow as extremist groups after anti-Kremlin cyberattacks
Information FreedomCensorshipPolicy & RegulationThreat Actors & APTsGovernmentTransportation & LogisticsAeroflotRussia Supreme Court
Russia is asking its Supreme Court to ban Belarusian Cyber Partisans and Silent Crow as extremist organizations, a designation that can outlaw their activities, block their websites and channels, and expose associates to criminal penalties. The move follows the groups' claimed attacks on Russian and Belarusian government and infrastructure targets, including the July 2025 Aeroflot disruption that canceled more than 100 flights and allegedly involved data theft and destruction of airline IT systems. No CVE or software flaw is cited; this is a state action tied to politically motivated hacking and online speech.
Why it matters: This matters because Russia is using an extremism label against online groups tied to cyber operations, which can expand censorship and criminalize access to related information channels. People following these groups, especially in Russia, may face blocking or legal risk, while defenders and researchers should watch for knock-on effects on threat visibility and attribution.
Sources
2026.06.04 100%
The article establishes a distinct new story: a formal Russian legal effort to classify two named anti-Kremlin hacking groups as extremist organizations, rather than reporting a previously tracked breach, vulnerability, or malware event.
Full page
U.S. Supreme Court upholds FCC fines against AT&T, Verizon and T-Mobile over sharing customers’ phone location data
Surveillance & PrivacyPolicy & RegulationTelecommunicationsGovernmentConsumers & General PublicAT&TVerizonT-MobileSprintFCCU.S. Supreme Court
The U.S. Supreme Court ruled that the FCC lawfully fined major wireless carriers for sharing access to customers’ location data without proper consent. In an 8-1 decision, the Court said the FCC’s forfeiture process did not violate the companies’ jury-trial rights, leaving in place penalties of roughly $47 million for Verizon, $57 million for AT&T, and $92 million for T-Mobile and Sprint. The underlying FCC case alleged the carriers sold location access to aggregators and data brokers and failed to take reasonable steps to protect that sensitive data.
Why it matters: This matters because it reinforces that mobile carriers can be punished for letting precise location data flow to third parties without meaningful consent. It is important for users concerned about surveillance and for companies handling sensitive data, even though there is no immediate patch or user action beyond reviewing privacy choices and carrier practices.
Sources
2026.06.04 100%
This article establishes a new trackable story because it is a fresh Supreme Court ruling that definitively upholds the FCC’s enforcement action over telecom location-data sharing, rather than an update to any existing tracked item.
Full page
IronWorm malware backdoors 36 npm packages to steal cloud, AI, and developer credentials
Supply ChainMalwareTechnology & SoftwareCryptocurrency & BlockchainnpmOpenAIAnthropicAWS
Attackers uploaded 36 malicious npm packages carrying a new malware strain called IronWorm, putting developers and continuous integration systems at risk if they installed the poisoned versions. JFrog says the Rust-based malware steals 86 environment variables and 20 credential-file types, including AWS, OpenAI, Anthropic, npm, SSH, vault, and crypto-wallet data; it was first linked to the compromised npm account 'asteroiddao' and can self-propagate by abusing stolen npm publishing and Trusted Publishing secrets to push trojanized package updates.
Why it matters: This can spread from one compromised developer or build system into many other packages and organizations, making it a high-priority software supply-chain threat. Developers and defenders should identify any affected package versions, upgrade to clean releases, rotate exposed credentials, review GitHub Actions and npm publishing tokens, and enforce two-factor authentication.
Sources
Bill Toulas 2026.06.04 100%
The article establishes a distinct npm supply-chain incident centered on the newly identified IronWorm malware and a specific set of 36 compromised packages, rather than merely revisiting the earlier Shai-Hulud or other npm package hijacking events.
Full page
Claude Code GitHub Action flaw let a malicious GitHub issue take over repositories running the workflow
Supply ChainZero-Days & CVEsTechnology & SoftwareAnthropicGitHub
A flaw in Anthropic's Claude Code GitHub Action could let an attacker use one malicious GitHub issue or comment to hijack affected repositories. The issue affected the GitHub Action integration for Claude Code, where untrusted issue content could be turned into dangerous workflow commands and expose repository secrets or enable unauthorized code changes in automation runs; the article does not provide a CVE in the supplied text.
Why it matters: Projects using the Claude Code GitHub Action may have been exposed to repository takeover through normal issue-tracker interactions, making this a high-priority supply-chain and automation risk. Maintainers should review Anthropic's fix guidance, restrict workflow permissions, rotate exposed secrets, and treat issue-triggered automation as untrusted until patched.
Sources
info@thehackernews.com (The Hacker News) 2026.06.04 100%
This article appears to establish a distinct newly disclosed vulnerability in Anthropic's Claude Code GitHub Action, not the previously tracked Claude Code sandbox bypass or the broader SymJack agent-manipulation research.
Full page
Google patched Gemini voice assistant flaw that let messaging notifications inject hidden commands
Zero-Days & CVEsSocial Engineering & PhishingTechnology & SoftwareConsumers & General PublicGoogleWhatsAppSlackZoom
Researchers say attackers could have manipulated Google’s Gemini voice assistant through ordinary message notifications from apps such as WhatsApp, Slack, and SMS. SafeBreach calls the technique “Fake Context Alignment”: hidden instructions embedded in notification content were silently pulled into Gemini’s context when users asked it to read messages aloud, potentially enabling actions such as controlling Google Home devices, starting Zoom calls, sending deceptive messages, and poisoning long-term memory. Google was notified in August 2025 and patched the issue in November 2025 with content-classifier changes.
Why it matters: This matters because it shows how everyday messages could be turned into a hands-free attack path against AI assistants that are connected to calls, messages, and smart-home controls. Users and organizations relying on Gemini should make sure current protections are in place and treat unsolicited messages as a potential trigger for AI-assisted actions.
Sources
Eduard Kovacs 2026.06.04 100%
This article establishes a distinct security story about a notification-based indirect prompt injection flaw in Google Gemini, separate from existing tracked stories about ChatGPT prompt injection, Gemini API key exposure, or other AI model security issues.
Full page
Proofpoint says TA4922 is targeting European organizations with new Atlas RAT malware and phishing lures
Threat Actors & APTsMalwareScams & FraudSocial Engineering & PhishingMicrosoftWhatsAppLINE
A Chinese-speaking cybercrime group is using new malware and localized phishing messages to break into organizations in Europe and beyond. Proofpoint says TA4922, linked to activity overlaps with Silver Fox and Void Arachne, has targeted entities in Germany, Italy, the United Kingdom, South Africa, and parts of Southeast Asia since March 2026 using payroll, tax, VAT, invoice, and HR lures sent by email and messaging apps including WhatsApp, LINE, and Microsoft Teams. The campaigns deploy Atlas RAT, RomulusLoader, SilentRunLoader, and Winos4.0/ValleyRAT for remote access, file theft, credential theft, keylogging, screenshots, and webcam or audio capture.
Why it matters: Organizations in the targeted regions should treat this as an active intrusion and phishing threat, especially finance, HR, and compliance teams that may receive convincing local-language messages. Defenders should hunt for the named malware families and remote-management tools, tighten phishing controls, and warn staff to verify unexpected payroll, tax, invoice, or compliance messages across email and chat platforms.
Sources
info@thehackernews.com (The Hacker News) 2026.06.04 96%
This appears to be the same underlying Proofpoint-reported TA4922 campaign, adding that the China-linked actor has expanded phishing targeting to the UK, Germany, Italy, and South Africa and continuing use of Atlas RAT with localized lures.
Ionut Arghire 2026.06.04 97%
This article is a direct follow-up on the same TA4922 campaign cluster, adding that Proofpoint now views the actor as operating at the highest campaign tempo in its cybercrime tracking, expanding from Asia into the UK, Germany, Italy, South Africa, and using HR, payroll, invoicing, customer-service, and out-of-band messaging lures with Atlas RAT, RomulusLoader, SilentRunLoader, ValleyRAT, and RMM tools such as AnyDesk and SyncFuture.
Bill Toulas 2026.06.03 100%
This article appears to be the first tracked item establishing Proofpoint's reporting on TA4922's expanded European campaigns and its use of the newly identified Atlas RAT and related loaders.
Full page
UK court orders former RAC workers to repay £118,000 after selling crash victims' personal data
Breaches & Data LeaksSurveillance & PrivacyPolicy & RegulationTransportation & LogisticsConsumers & General PublicRACInformation Commissioner's Office
Two former RAC employees in the UK were ordered to repay more than £118,000 after illegally selling personal data belonging to car crash victims. The Information Commissioner's Office said the pair were previously convicted under the Computer Misuse Act 1990 and Data Protection Act 2018 after about 29,500 records were copied from RAC systems and shared over WhatsApp with an unknown buyer; one defendant now faces 18 months in prison if she does not repay the proceeds within three months.
Why it matters: This matters because insiders abused access to sensitive data from people involved in road accidents, showing how personal information can be monetized after a breach from inside an organization. For defenders and regulated firms, it underscores the need for monitoring, least-privilege access, and rapid response to suspicious data exports.
Sources
2026.06.04 100%
The article establishes a trackable story by providing a substantive legal outcome in a real insider data-theft case involving RAC crash-victim records and the use of UK privacy and computer-misuse laws to recover criminal proceeds.
Full page
Espionage hackers spent 150 days inside a senior executive’s email at a major global stock exchange
MalwareThreat Actors & APTsBreaches & Data LeaksFinance & BankingMicrosoftDropbox
Hackers secretly monitored and stole email data from a senior executive at a major global stock exchange for about five months. Broadcom’s Symantec and Carbon Black teams said the intrusion began in October 2025 and lasted until March 2026, with malware on the victim’s device disguised as Adobe and OneDrive software, scheduled-task persistence masked as Adobe, Lenovo, and OneDrive services, and exfiltration of Outlook mailbox data in small archives via Dropbox and OneDrive. The initial access method and the victim exchange were not disclosed, but investigators published indicators of compromise.
Why it matters: This is a high-impact espionage case because a stock exchange executive’s mailbox can expose market-moving information, internal deliberations, contacts, and travel details. Financial institutions and other high-value targets should hunt for the published indicators, review executive mailbox and endpoint activity, and scrutinize cloud-storage exfiltration and suspicious scheduled tasks.
Sources
info@thehackernews.com (The Hacker News) 2026.06.04 99%
This article is another report on the same underlying incident: an espionage intrusion in which attackers maintained access to a senior executive’s Outlook mailbox at a major global stock exchange for roughly five months.
Eduard Kovacs 2026.06.03 100%
This article appears to be the first tracked report of this specific espionage intrusion against a global stock exchange executive mailbox.
Full page
U.S. sanctions Iran’s Nobitex crypto exchange over ransomware- and IRGC-linked transactions
RansomwareThreat Actors & APTsPolicy & RegulationGovernmentCryptocurrency & BlockchainNobitexOFACWallexBitpinRamzinexIRGC
The U.S. sanctioned Nobitex, Iran’s largest cryptocurrency exchange, saying it helped process transactions tied to ransomware actors and Iran’s Islamic Revolutionary Guard Corps. The Treasury’s Office of Foreign Assets Control also designated Nobitex executives and targeted other Iranian exchanges including Wallex, Bitpin, and Ramzinex as part of its "Economic Fury" campaign, alleging sanctions evasion and terrorist-financing support rather than a software flaw or CVE-tracked vulnerability.
Why it matters: This matters because ransomware groups and state-linked actors depend on payment channels to move money, and sanctions can disrupt those routes while raising compliance risk for exchanges, companies, and users who interact with them. Organizations handling crypto exposure should review sanctions screening and watch for links to designated wallets and entities.
Sources
Bill Toulas 2026.06.03 100%
This article establishes a distinct new story about OFAC’s sanctions action against Nobitex and related Iranian exchanges for allegedly facilitating ransomware- and IRGC-linked crypto activity.
Full page
Google fixes actively exploited Android zero-day CVE-2025-48595 in June 2026 security update
Urgent PatchesZero-Days & CVEsTechnology & SoftwareConsumers & General PublicGoogleQualcomm
Google released Android security updates that fix an actively exploited flaw affecting devices running Android 14 and later. The zero-day, CVE-2025-48595, is a high-severity Android Framework vulnerability that Google says has seen limited targeted exploitation and can let a local attacker achieve code execution and privilege escalation. The June 2026 bulletins also patch 124 vulnerabilities in total, including 18 critical issues across Framework, System, Qualcomm components, and other closed-source and kernel-related parts.
Why it matters: People and organizations using Android devices may be exposed to a flaw already being used in real attacks, even if only in targeted cases. Apply the June 2026 Android security update as soon as your device vendor makes it available, with particular urgency for Pixel users and higher-risk targets.
Sources
Bill Toulas 2026.06.03 98%
This article updates the same underlying event around CVE-2025-48595 by adding that CISA has now placed the Android privilege-escalation flaw in the KEV catalog and set a June 5 remediation deadline for federal agencies.
info@thehackernews.com (The Hacker News) 2026.06.02 97%
This article appears to cover the same June 2026 Android security release, adding that Google patched 124 total flaws in the update while including the actively exploited zero-day CVE-2025-48595.
Eduard Kovacs 2026.06.02 99%
This article reports the same June 2026 Android security update and the same exploited zero-day, CVE-2025-48595, adding that the release patches 124 vulnerabilities total, including 18 critical issues and one additional remote code execution bug, CVE-2026-0059.
Sergiu Gatlan 2026.06.02 100%
This article establishes a new tracked story because it is the first item here about Google's June 2026 Android patch cycle and the actively exploited Android zero-day CVE-2025-48595.
Full page
CISA warns Linux kernel container-escape flaw CVE-2022-0492 is being exploited in the wild
Urgent PatchesThreat Actors & APTsZero-Days & CVEsGovernmentTechnology & SoftwareCISALinux
CISA says attackers are now exploiting a Linux kernel bug that can let someone break out of a container and gain root-level control on the host system. The flaw, CVE-2022-0492, is an improper authentication issue in Linux cgroups v1 that allows modification of the release_agent mechanism, enabling privilege escalation and container escape; CISA added it to the Known Exploited Vulnerabilities catalog after Kaspersky reported real-world exploitation, and federal agencies were told to patch by June 5.
Why it matters: Organizations running Linux containers could be at risk of full host compromise if affected systems are unpatched. This is urgent for cloud, server, and platform teams: identify systems using cgroups v1, apply available kernel fixes, and review container hardening and isolation settings immediately.
Sources
Bill Toulas 2026.06.03 99%
This is effectively the same event: CISA's KEV addition for CVE-2022-0492, the Linux kernel cgroups v1 container-escape and privilege-escalation flaw, with the article restating affected kernel ranges and patch guidance.
Ionut Arghire 2026.06.03 100%
This article establishes a distinct tracked event: the first formal CISA KEV warning and public confirmation of in-the-wild exploitation for Linux kernel flaw CVE-2022-0492.
Full page
Attackers exploit Kirki WordPress plugin flaw CVE-2026-8206 to hijack administrator accounts
Zero-Days & CVEsTechnology & SoftwareConsumers & General PublicWordPress
Attackers are exploiting a critical flaw in the Kirki WordPress plugin that can let them take over administrator accounts on affected websites. CVE-2026-8206 affects Kirki versions 6.0.0 through 6.0.6 and abuses a password-reset REST API endpoint so an unauthenticated attacker can send a valid reset link for any user to an attacker-controlled email address. Wordfence says it blocked more than 222 exploit attempts in 24 hours, and the fix shipped in version 6.0.7.
Why it matters: Sites using affected Kirki versions can be quickly hijacked, letting attackers change content, install malicious plugins, or plant persistent backdoors. This is urgent for WordPress administrators: update to 6.0.7 immediately or disable the plugin, and review privileged accounts for suspicious password resets or changes.
Sources
Ionut Arghire 2026.06.03 96%
This article updates the Kirki exploitation story with Defiant's observation that thousands of attacks were blocked in the past 24 hours, estimates roughly 150,000 sites may still be running vulnerable Kirki versions 6.0.0 to 6.0.6, and reiterates patching to 6.0.7+.
Bill Toulas 2026.06.02 100%
This article establishes a distinct new exploitation story centered on CVE-2026-8206 in the Kirki plugin, with active in-the-wild attacks and specific remediation guidance.
Full page
Attackers exploit Burst Statistics WordPress plugin flaw to create administrator accounts on vulnerable sites
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareConsumers & General PublicBurst StatisticsWordPress
Attackers are targeting a flaw in the Burst Statistics WordPress plugin that can let outsiders take over websites by creating administrator accounts. Defiant says versions 3.4.0 to 3.4.1.1 contain an authentication bypass in application-password validation for REST API requests, allowing unauthenticated attackers to impersonate an admin for a request and use admin-level functions. Users should update to version 3.4.2 or newer.
Why it matters: Sites using Burst Statistics may be vulnerable to full website takeover, so this is urgent for WordPress administrators and hosting providers. Check plugin versions now, update immediately, and review for unexpected administrator accounts or suspicious REST API activity.
Sources
Ionut Arghire 2026.06.03 100%
The article establishes a distinct exploited-plugin event separate from the already tracked Kirki story by identifying active attacks against Burst Statistics, the affected versions, the attack method, and the patched version.
Full page
IMA Diligence Services says breach of third-party-managed legacy server exposed data of 525,000 people
Breaches & Data LeaksRansomwareLegal & Professional ServicesConsumers & General PublicIMA Diligence Services
IMA Diligence Services says attackers stole sensitive personal data from a legacy server managed by a third party, affecting 525,306 people. The company says the intruders accessed the server between December 8 and December 16 and exfiltrated files containing names, addresses, Social Security numbers, driver's license numbers, financial account and credit card data, medical and health insurance information, and in some cases passport and taxpayer ID numbers. SecurityWeek says the Genesis ransomware group previously claimed the attack and said it stole 700 GB of data.
Why it matters: This is a high-impact breach because it exposed the kinds of data that can be used for identity theft, fraud, and medical or financial scams. Affected people should watch for the company's notice, enroll in credit monitoring, and consider fraud alerts or account monitoring, while defenders should review third-party legacy systems and data-retention exposure.
Sources
Ionut Arghire 2026.06.03 100%
No existing tracked story covers this specific IMA Diligence Services breach event; this article appears to be the first concrete disclosure with victim count, data types, timeline, and a possible Genesis ransomware link.
Full page
Acer warns of two maximum-severity zero-days in Wave 7 routers and says fixes are coming by end of June
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareConsumers & General PublicAcer
Acer says two critical security holes in its Wave 7 mesh routers could let attackers break in remotely, and patches are not available yet. The flaws, CVE-2026-49200 and CVE-2026-49201, affect Wave 7 routers running firmware T7c_GBL_1.01.000055 or earlier. One bug exposes plaintext web and Telnet credentials through an unauthenticated web-accessible log file, while the other uses a hardcoded AES key in backup handling to let attackers alter backups and implant persistent backdoor access.
Why it matters: People and organizations using affected Acer Wave 7 routers could face account compromise and long-term unauthorized access if devices are exposed. This is urgent because there is no patch yet; users should disable remote management or restrict it to trusted IP addresses and apply Acer's firmware update as soon as it is released.
Sources
Sergiu Gatlan 2026.06.03 100%
This article appears to be the first clear report establishing Acer's disclosure of CVE-2026-49200 and CVE-2026-49201, the affected Wave 7 firmware versions, interim mitigations, and the expected end-of-June fix window.
Full page
Unpatched Windows Search URI flaw can leak NTLMv2 hashes when users open malicious search links
Zero-Days & CVEsSocial Engineering & PhishingTechnology & SoftwareConsumers & General PublicMicrosoft
A newly reported Windows flaw can expose a user's NTLMv2 password hash, which attackers can try to crack or relay for unauthorized access. The issue affects the Windows Search URI protocol and can be triggered through crafted links or files that cause Windows to connect to an attacker-controlled server. The article indicates the bug is unpatched and enables hash disclosure rather than direct code execution.
Why it matters: Organizations that still rely on NTLM authentication could be exposed to credential theft from a single malicious link or lure, making this a meaningful phishing and lateral-movement risk. Defenders should block or monitor outbound SMB and WebDAV traffic, reduce NTLM use where possible, and warn users not to open unexpected search-related links or files until Microsoft issues a fix.
Sources
info@thehackernews.com (The Hacker News) 2026.06.03 100%
This appears to establish a distinct new story about an unpatched Windows Search URI credential-leak vulnerability, and it does not match any existing tracked story in the list.
Full page
Europol-backed Operation KRATOS 2 dismantles nine illegal streaming crime groups across 13 countries
Scams & FraudMalwareGovernmentMedia & EntertainmentTechnology & SoftwareConsumers & General PublicEuropol
Police in Europe and the United States say they broke up nine organized crime groups running illegal streaming services and arrested 29 suspects. The seven-month Operation KRATOS 2, led by Bulgaria with Europol support, involved 13 countries and led to the removal of more than 27,000 illegal streaming URLs, identification of 18,000 IP addresses tied to illegal services, 4,370 piracy-linked domains, nearly 400,000 additional URLs flagged for suspension, and 126,000 infringing objects. Investigators say the operators split public-facing sites from backend hosting across jurisdictions to evade takedowns.
Why it matters: People using pirate streaming services are not just risking copyright trouble; Europol says these platforms can also expose users to malware, spyware, and theft of personal data. The story matters because it shows the scale and international reach of the criminal infrastructure behind these services, and affected users should avoid such platforms and check devices for suspicious software if they used them.
Sources
Sergiu Gatlan 2026.06.03 100%
This article establishes a distinct new law-enforcement event, Operation KRATOS 2, separate from the previously tracked CINEMAGOAL takedown and other anti-piracy actions because it concerns a broader seven-month multinational crackdown on nine crime groups.
Full page
Google rolls out Android fake-call detection to warn users about AI voice-clone and caller-ID spoofing scams
Scams & FraudSocial Engineering & PhishingTechnology & SoftwareTelecommunicationsConsumers & General PublicGoogle
Google is adding a new Android feature that warns people when a call may be a scammer pretending to be someone they know. The feature, called fake call detection, is rolling out globally this month on Android 12 and later, starting with Pixel devices, and is enabled by default. It works when both parties use Phone by Google, Contacts, and Google Messages with Rich Communication Services (RCS) enabled, using encrypted device-to-device verification to detect spoofed contact calls and trigger an on-screen warning.
Why it matters: This addresses a real-world fraud tactic that combines fake caller ID with AI-generated voice impersonation, which can trick people into sending money or revealing sensitive information. Android users should keep Google's phone and messaging apps updated and treat urgent calls asking for money, codes, or account access with caution.
Sources
Sergiu Gatlan 2026.06.03 100%
This article establishes a new story because it is the rollout announcement for Google's specific Android anti-deepfake-call protection, not an update to an existing tracked event.
Full page
WeedHack malware campaign infects more than 116,000 systems through fake Minecraft mods and cheats
MalwareSocial Engineering & PhishingScams & FraudConsumers & General PublicTechnology & SoftwareMedia & EntertainmentCryptocurrency & BlockchainMinecraftDiscordSteamTelegram
A large malware campaign has infected more than 116,000 computers by tricking Minecraft players into downloading booby-trapped mods, cheat clients, and utilities. McAfee says the WeedHack operation has been active since January 2026, spreads via YouTube links and search-result manipulation, and uses thousands of malicious Java archive (JAR) files. The malware steals browser passwords and cookies, Minecraft session IDs, Discord, Steam and Telegram credentials, and crypto-wallet data, while paid tiers add remote-control features such as keylogging, webcam access, shell access, and file management.
Why it matters: This is a broad consumer-focused infostealer campaign hitting gamers at scale, with stolen passwords, session tokens, and wallet data creating immediate account-takeover and financial risk. Minecraft players and parents should avoid unofficial mod download sites, remove suspicious JAR files, run antivirus scans, and reset passwords for any accounts used on affected devices.
Sources
Bill Toulas 2026.06.02 100%
This article establishes a distinct new malware campaign centered on Minecraft-themed lures, with named actor infrastructure, infection scale, and specific steal-and-remote-access capabilities.
Bill Toulas 2026.06.02 99%
This article is a direct report on the same WeedHack campaign, adding McAfee telemetry, distribution methods via YouTube and SEO poisoning, the malware-as-a-service dashboard details, and the free and premium feature sets used to steal credentials and remotely control victims' systems.
Full page
CISA says attackers are exploiting Oracle WebLogic server flaw CVE-2024-21182
Urgent PatchesZero-Days & CVEsTechnology & SoftwareOracleCISA
A long-patched Oracle WebLogic Server vulnerability is now being exploited in real attacks, putting internet-facing servers at risk if they were not updated. CISA added CVE-2024-21182 to its Known Exploited Vulnerabilities catalog on June 1, 2026. Oracle patched the flaw in July 2024; it can be exploited remotely without authentication against affected WebLogic Server instances, and successful exploitation can expose sensitive data or allow broader server compromise.
Why it matters: Organizations running Oracle WebLogic should treat this as urgent because attackers no longer need valid logins to target exposed systems. Patch immediately, check whether any WebLogic servers are internet-accessible, and hunt for signs of compromise if updates were delayed.
Sources
info@thehackernews.com (The Hacker News) 2026.06.02 98%
This appears to be the same underlying event: active exploitation of Oracle WebLogic CVE-2024-21182 and its addition to the KEV catalog. The article mainly reinforces the KEV status and urgency rather than establishing a separate incident.
Sergiu Gatlan 2026.06.02 99%
This article is the same underlying event and adds operational detail that CISA ordered federal agencies to patch by June 4 under Binding Operational Directive 22-01, while noting affected WebLogic versions and internet exposure counts from Shodan.
Eduard Kovacs 2026.06.02 100%
This article establishes a distinct new tracked event: active exploitation and KEV listing of Oracle WebLogic CVE-2024-21182, not just Oracle's broader monthly patch cycle.
Full page
Russia's FSB says foreign intelligence planted spyware on senior officials' phones
Threat Actors & APTsSurveillance & PrivacyGovernmentTechnology & SoftwareFSB
Russia's domestic security service says foreign intelligence agencies hacked the mobile phones of senior Russian officials to spy on them. The FSB alleges malware on the devices collected correspondence, calls, geolocation, contact lists, and audio and video from the phones and their surroundings, and claims the operation relied on infrastructure from major international technology companies, including content delivery and security providers. No spyware family, infection method, or technical evidence was disclosed.
Why it matters: If true, this would be a significant government-targeted mobile espionage campaign with potential impact on sensitive state communications and surveillance exposure. Defenders should watch for technical indicators or vendor confirmations before taking the claims at face value, but mobile-device compromise at this level is high consequence.
Sources
2026.06.02 100%
This article establishes a distinct new alleged espionage incident from June 2026; while it references the 2023 iPhone-focused Operation Triangulation case, it does not tie the new claims to that same operation and provides a separate event anchor.
Full page
Microsoft Android apps exposed account tokens after debug flag was left enabled in Word, Excel, PowerPoint, OneNote, Loop and Copilot
Zero-Days & CVEsMobile MalwareTechnology & SoftwareConsumers & General PublicMicrosoft
Six Microsoft Android apps could hand Microsoft account tokens to unauthorized apps because a debug setting was left enabled in production code. SecurityWeek reports Enclave found the issue in Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop and OneNote for Android; the flag bypassed checks meant to restrict token sharing to trusted Microsoft apps, allowing any installed app to request reusable FOCI tokens and potentially access account data. No CVE is cited in the report.
Why it matters: People and organizations using these Android apps could have had account access tokens silently stolen by another app on the same phone, potentially enabling long-lived account access. This is urgent for Microsoft mobile users and defenders: watch for Microsoft’s fix, review mobile app trust and update practices, and investigate suspicious Android apps on managed devices.
Sources
Kevin Townsend 2026.06.02 100%
This article appears to be the first reporting on this specific Microsoft Android token-exposure flaw and establishes the underlying event.
Full page
HP patches critical CVE-2026-0826 in Poly VoIP phones that can let attackers remotely take over devices
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareTelecommunicationsHP
HP released fixes for a critical flaw in several Poly Voice VoIP phone models that could let an attacker remotely seize control of a phone and use it as a foothold inside a company network. Rapid7 said CVE-2026-0826 is a stack-based buffer overflow in Session Description Protocol parsing when Interactive Connectivity Establishment is enabled, affecting Poly VVX 150/250/350/450 and Trio 8300/8500/8800 devices; a malicious SIP INVITE can trigger root-level remote code execution, and HP has published patched firmware.
Why it matters: Organizations using these desk and conference phones should treat this as urgent because compromised voice devices often sit on trusted internal networks and typically lack security tooling. Update affected Poly firmware now and disable ICE where it is not needed.
Sources
Ionut Arghire 2026.06.02 100%
This article appears to be the first tracked report establishing the disclosure, affected HP Poly models, CVE-2026-0826 details, attack path, and available mitigations.
Full page
Scammers spoof Northern Ireland police phone number to pose as officers and demand bank details and gift-card payments
Social Engineering & PhishingScams & FraudGovernmentFinance & BankingCryptocurrency & BlockchainConsumers & General PublicPolice Service of Northern Ireland
The Police Service of Northern Ireland warned that scammers spoofed its official switchboard number to call people while pretending to be police officers. In the reported case, the caller falsely claimed the target was tied to a money-transfer investigation, asked for bank-card information, and then requested gift cards and their codes; police said the number display was faked and no suspect has yet been arrested. The same police force also disclosed a separate crypto-investment fraud in which an elderly woman lost more than £250,000 after attackers persuaded her to install malware and took control of her devices.
Why it matters: People may trust a call that appears to come from a real police number, so this scam raises the risk of financial theft even for cautious users. Anyone receiving such a call should hang up, independently verify the number, and never provide banking details or gift-card codes to someone claiming to be law enforcement.
Sources
2026.06.02 100%
This article establishes a discrete, reportable fraud event: official police caller ID was spoofed to support an impersonation scam targeting the public.
Full page
Dashlane temporarily suspended some customer accounts during brute-force login attacks
Breaches & Data LeaksSocial Engineering & PhishingTechnology & SoftwareConsumers & General PublicDashlane
Dashlane says it temporarily locked some customer accounts after attackers repeatedly tried to register new devices and failed the required verification step. The company said the activity began Sunday, triggered automatic protections, and later moved to monitoring after restoring affected accounts. Dashlane said its internal systems were not compromised, but did not disclose how many users were hit or whether any account takeovers succeeded.
Why it matters: Password managers hold access to many other accounts, so even unsuccessful attacks are high-impact for users. Dashlane customers should verify recent login alerts, ensure multi-factor authentication is working, and contact support if their account was suspended or shows unfamiliar device activity.
Sources
Eduard Kovacs 2026.06.02 97%
This is the same underlying Dashlane brute-force campaign and adds the key impact detail that attackers successfully compromised some accounts and downloaded fewer than 20 encrypted personal-plan vaults after brute-forcing 2FA codes to register devices.
info@thehackernews.com (The Hacker News) 2026.06.02 98%
This appears to be the same Dashlane brute-force incident and adds a key update: attackers were able to download encrypted password vaults for fewer than 20 users, refining the scope and impact beyond the earlier account suspensions.
Bill Toulas 2026.06.01 99%
This article is a direct report on the same Dashlane incident, adding vendor confirmation that an external party targeted certain accounts in brute-force attacks, that suspensions were part of built-in protections, and that affected accounts were later unsuspended while additional safeguards were being implemented.
2026.06.01 100%
This article appears to be the first tracked report of Dashlane suspending user accounts in response to an ongoing brute-force campaign targeting customer logins and device registration.
Full page
Spain arrests suspect in doxing campaign that leaked personal data of INCIBE, police, prosecutors and other government employees
Breaches & Data LeaksSurveillance & PrivacyGovernmentLegal & Professional ServicesINCIBENational PoliceCivil GuardState Attorney General's OfficeNational Security Council
Spanish police arrested a suspect accused of leaking sensitive personal data belonging to employees at key state bodies including INCIBE, the National Police, the Civil Guard, the State Attorney General's Office, and the National Security Council. Authorities say the mass publication created immediate security risks for affected staff and institutions. INCIBE previously said its own systems were not directly breached and that the leak appeared to be assembled from older breaches, credential dumps, and open-source intelligence, with some records posted on BreachForums and Doxbin.
Why it matters: This is a real-world exposure of personal data tied to government and security personnel, which can enable harassment, phishing, impersonation, and physical-safety risks. Affected organizations and employees should treat exposed details as compromised, review account security, and watch for targeted social-engineering attempts.
Sources
2026.06.01 99%
This article appears to report the same arrest and underlying doxing campaign, adding that the leaked data was posted across multiple internet platforms and affected officials tied to the National Police, Civil Guard, Attorney General's Office, National Security Council, and INCIBE, with devices seized for forensic analysis.
Bill Toulas 2026.06.01 100%
This article establishes the core event: Spanish authorities arrested the alleged doxer after a mass leak of government employee data, adding law-enforcement confirmation and scope of affected institutions.
Full page
DriveSurge hijacks thousands of legitimate websites to push ClickFix and fake browser update malware
MalwareSocial Engineering & PhishingThreat Actors & APTsConsumers & General PublicTechnology & SoftwareGoogleMozillaMicrosoftApple
A threat actor called DriveSurge has compromised thousands of real websites and is using them to redirect visitors into malware traps. Silent Push says the actor operates as an initial access broker, using the zTDS traffic distribution system to decide whether each visitor sees a ClickFix lure that tricks them into running malicious PowerShell commands or a FakeUpdate page posing as browser updates for Chrome, Firefox, Edge, Safari and others; researchers also found macOS-targeting JavaScript and more than 80 malicious injection domains.
Why it matters: People can get infected just by visiting a legitimate site that has been silently hijacked, so the risk extends beyond obviously shady pages. Organizations should hunt for the identified JavaScript injection patterns and domains, and users should only update browsers through the built-in updater and never paste commands from pop-ups into Terminal or PowerShell.
Sources
Bill Toulas 2026.06.01 100%
This article appears to be the first tracked item establishing Silent Push's reporting on the DriveSurge campaign, its use of zTDS, and its large-scale website hijacking for ClickFix and FakeUpdate malware delivery.
Full page
Inspector general says NIST mismanagement left the National Vulnerability Database with a 27,000-entry backlog
Zero-Days & CVEsPolicy & RegulationGovernmentTechnology & SoftwareNISTCISA
A U.S. watchdog found that NIST’s National Vulnerability Database, a key public source used to track and prioritize software flaws, has become ineffective after mismanagement caused a massive processing backlog. The report says unprocessed vulnerability records grew from about 13,000 in February 2024 to more than 27,000 by the end of 2025, after NIST stopped paying contractors, missed its recovery goals, and duplicated at least 21,000 pieces of work already handled by CISA’s Vulnrichment program.
Why it matters: This matters because companies, government agencies, and security teams rely on NVD data to decide what to fix first, and delays can slow patching and risk decisions across the ecosystem. Affected users are indirect but broad: defenders may need to lean more on vendor advisories, CISA KEV, and other sources until NVD processing becomes reliable again.
Sources
2026.06.01 100%
This article establishes a distinct oversight and infrastructure story about NIST’s vulnerability-processing failures and the operational impact on the National Vulnerability Database, rather than updating a specific CVE or exploit event.
Full page
Researchers track 5,000+ election-themed domains and exposed political credentials ahead of the 2026 U.S. midterms
Social Engineering & PhishingScams & FraudDisinformation & Influence OpsGovernmentNonprofits & NGOsConsumers & General PublicActBlueWinRedGOPDemocrats.orgUSA.gov
Security researchers say more than 5,000 election-themed internet domains were registered in recent weeks ahead of the 2026 U.S. midterms, raising the risk of fake voting sites, donation scams, and impersonation of election officials. Check Point said the registrations increased sharply between April and May and coincided with roughly 17,000 exposed credentials tied to ActBlue, WinRed, GOP, Democrats.org, and USA.gov accounts, creating infrastructure and account access that could support phishing, fraud, or influence operations.
Why it matters: This matters because voters, donors, campaigns, and election workers could be tricked by lookalike sites or targeted through reused or stolen passwords. People should verify election and donation websites carefully, avoid links in unsolicited messages, and reset passwords if they may have been exposed.
Sources
2026.06.01 100%
This article establishes a distinct 2026 midterm-election threat story centered on a surge of election-themed domains and exposed credentials that could be used for phishing, impersonation, fraud, and misinformation.
Full page
Attackers exploit WP Maps Pro WordPress plugin flaw CVE-2026-8732 to create administrator accounts
Urgent PatchesZero-Days & CVEsTechnology & SoftwareConsumers & General PublicWP Maps ProWordPress
Attackers are trying to take over WordPress sites that use the WP Maps Pro plugin by secretly creating their own administrator accounts. The bug, CVE-2026-8732, affects WP Maps Pro 6.1.0 and earlier and stems from an unauthenticated AJAX endpoint tied to a temporary support-access feature; a crafted request can create an admin user and generate a passwordless login link. Wordfence says it blocked more than 3,600 exploitation attempts in 24 hours, and the vendor fixed the issue in version 6.1.1 on May 20, 2026.
Why it matters: Any site running the vulnerable plugin can be fully taken over, letting attackers plant backdoors, change content, or steal data. Users should update WP Maps Pro to 6.1.1 or later immediately and review WordPress admin accounts for unexpected new users.
Sources
Ionut Arghire 2026.06.01 99%
This article is the same underlying event: active exploitation of CVE-2026-8732 in the WP Maps Pro plugin. It adds technical details on the root cause in the AJAX temporary-access callback, notes that version 6.1.1 fixes the issue, and reports Defiant blocked more than 1,700 attack attempts in 24 hours.
info@thehackernews.com (The Hacker News) 2026.06.01 99%
This article covers the same underlying event: active exploitation of the WP Maps Pro flaw CVE-2026-8732 to create rogue admin accounts on vulnerable WordPress sites.
Bill Toulas 2026.05.31 100%
This article establishes a distinct new story: active exploitation of CVE-2026-8732 in the WP Maps Pro plugin, including the flaw details, affected versions, patch release, and observed attack volume.
Full page
Dutch police say they disrupted a botnet of at least 17 million infected devices after tracing 200 servers in the Netherlands
MalwareThreat Actors & APTsGovernmentTechnology & SoftwareTelecommunicationsConsumers & General PublicDutch PoliceNCSC-NL
Dutch police say they helped dismantle a botnet made up of at least 17 million compromised devices, with 200 supporting servers traced to the Netherlands and seized or shut down with help from a hosting provider. Authorities and NCSC-NL did not name the botnet or specify the exact malware family, but said affected devices likely included poorly secured routers, mobile devices, and Internet of Things hardware commonly abused for phishing, distributed denial-of-service attacks, and online fraud.
Why it matters: A botnet this large can be used to hide attacks, knock services offline, and abuse ordinary people's devices without their knowledge. Users and organizations should check internet-connected devices for updates, replace default passwords, and avoid unofficial app sources while defenders watch for follow-on indicators once police release more details.
Sources
Ionut Arghire 2026.06.01 99%
This article is another report on the same Dutch police takedown, adding that authorities seized several command-and-control servers from a Dutch hosting provider, that local reporting identified the targeted service as Asocks, and that the botnet included infected computers, smartphones, and tablets used for residential proxy abuse and cybercrime.
Bill Toulas 2026.05.29 99%
This is the same underlying event: Dutch police and the NCSC disrupting a botnet of at least 17 million infected devices and seizing more than 200 servers in the Netherlands. The article adds attribution reported by local media linking the infrastructure to the Asocks proxy service and notes authorities' view that affected device owners likely did not knowingly participate.
2026.05.29 100%
This article appears to be the first report establishing this specific Dutch police takedown of an unnamed 17 million-device botnet, and it does not match any listed existing tracked story.
Full page
Malware on nearly 2,000 WordPress sites used Steam profiles to hide command data and maintain backdoor access
MalwareTechnology & SoftwareConsumers & General PublicWordPressSteam
A long-running malware campaign infected about 1,980 WordPress websites and hid its command-and-control data inside Steam Community profile comments. GoDaddy says the malware, tracked since July 2025, uses invisible Unicode characters in Steam comments to encode a payload that builds a hello-mywordl[.]info URL, then injects JavaScript disguised as common libraries and installs a PHP backdoor that executes code sent in specially crafted POST requests with a specific cookie. The initial compromise route is unknown but may involve stolen WordPress or FTP credentials, vulnerable themes or plugins, or a supply-chain compromise.
Why it matters: WordPress site owners and hosting teams should treat this as an active website compromise, not just a nuisance script, because it includes a persistent backdoor that can reinfect a site if cleanup is incomplete. Check for outbound requests to Steam from WordPress servers, suspicious JavaScript injections, and restore from a known-good backup where possible.
Sources
Bill Toulas 2026.06.01 100%
This article establishes a distinct malware campaign centered on WordPress infections that conceal payloads in Steam profile comments, with no matching tracked story covering this same operation.
Full page
Attackers are now exploiting Windows Server Netlogon remote-code-execution flaw CVE-2026-41089
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareGovernmentMicrosoftCentre for Cybersecurity Belgium
A critical Windows Server security flaw that can let outsiders run code on domain controllers is now being exploited in real attacks. Belgium's Centre for Cybersecurity said CVE-2026-41089, a stack-based buffer overflow in the Netlogon remote procedure call (RPC) service, is under active exploitation after Microsoft patched it in May 2026. The bug affects supported Windows Server versions including Windows Server 2025 and can be triggered by a specially crafted network request without prior authentication.
Why it matters: Domain controllers are the systems that authenticate users across many business networks, so compromise can put an entire organization at risk. Organizations running Windows Server should treat this as high priority and patch exposed and internal domain controllers immediately.
Sources
Ionut Arghire 2026.06.01 98%
This article is the same underlying event: CCB warning that CVE-2026-41089 in Windows Netlogon is being exploited in the wild. It adds detail that Microsoft patched the stack-based buffer overflow on May 12, that exploitation can occur via crafted network requests against domain controllers without authentication, and that Microsoft had not yet updated its advisory to reflect exploitation.
Sergiu Gatlan 2026.06.01 100%
This article establishes a new tracked story by adding the key development that CVE-2026-41089 has moved from a patched critical flaw to one reportedly being exploited in the wild.
Full page
Atlas Menu cheat service breach exposed 64,000 user records after database was posted to GitHub
Breaches & Data LeaksTechnology & SoftwareMedia & EntertainmentConsumers & General PublicAtlas MenuRockstar GamesValve
Atlas Menu, a cheat service for Grand Theft Auto V and Counter-Strike 2, was breached and data on about 64,000 users was published to GitHub. The leaked database reportedly includes email addresses, usernames, IP addresses, support tickets, signup dates, license keys, Rockstar account identifiers, and passwords stored as bcrypt hashes, along with internal records such as banned-user lists and administrator logs. The attacker claimed access to all Atlas systems.
Why it matters: Affected users face account, privacy, and follow-on phishing risks, especially if they reused passwords elsewhere. Users should reset any reused passwords, watch for scams referencing Atlas or Rockstar accounts, and treat the exposed support and purchase data as potentially sensitive.
Sources
2026.06.01 100%
This article appears to be the first clear report establishing the Atlas Menu breach as a discrete data-leak event with scope, affected data types, and public exposure via GitHub.
Full page
CIFSwitch Linux kernel flaw can let local users gain root on multiple distributions
Zero-Days & CVEsTechnology & SoftwareConsumers & General Public
A newly disclosed Linux flaw called CIFSwitch can let a normal local user take full control of an affected system. The bug is a local privilege-escalation issue in the Linux kernel CIFS subsystem and cifs-utils, where forged cifs.spnego key requests can make the root-run cifs.upcall helper trust attacker-controlled data and load a malicious NSS module. The researcher says vulnerable combinations affect multiple distributions, published a proof-of-concept exploit, and points to upstream fix commit 3da1fdf.
Why it matters: This matters for multi-user Linux systems and enterprise fleets because a user or attacker who already has limited access may be able to become root. Organizations should identify affected distributions, apply vendor kernel updates, and consider mitigations such as disabling unprivileged user namespaces or removing unused CIFS components.
Sources
Ionut Arghire 2026.06.01 96%
This article is a direct update on the same CIFSwitch Linux kernel privilege-escalation flaw, adding that PoC exploit code has now been released and summarizing affected and non-affected distributions plus the root cause involving the CIFS subsystem and cifs.upcall.
Bill Toulas 2026.05.30 100%
This article appears to establish a new tracked event: the public disclosure of the CIFSwitch Linux privilege-escalation flaw, including affected distributions, mitigation guidance, and a released proof-of-concept.
Full page
UK moves to tighten subsea cable protections after reporting Russian survey activity near British undersea internet infrastructure
Information FreedomPolicy & RegulationGovernmentDefense & AerospaceTelecommunicationsUK governmentRoyal NavyGUGI
The UK says Russian vessels and submarines recently surveyed cable routes near Britain, and the government is preparing stronger legal protections for undersea internet cables. The reported April activity involved a Russian Akula-class submarine and two specialist GUGI deep-sea research vessels, according to the minister's speech. Proposed measures include tougher penalties for reckless cable damage, new security duties for cable operators, and emergency powers allowing the government to compel stronger infrastructure protection.
Why it matters: Subsea cables carry much of the UK's internet and international communications, so interference could disrupt connectivity and critical services. This matters to telecom operators, infrastructure owners, and policymakers because it signals a live hybrid-threat risk and points to forthcoming compliance and resilience requirements.
Sources
2026.06.01 100%
This article establishes a distinct story about suspected Russian reconnaissance of UK subsea communications infrastructure and the UK's resulting legal and operational push to protect cable networks.
Full page
Kaspersky says previously unknown hacking group spent nearly two years phishing Russian maritime universities, diplomats and energy organizations
Threat Actors & APTsSocial Engineering & PhishingEducationGovernmentEnergy & UtilitiesFinance & BankingTransportation & Logistics
A previously unknown hacking group quietly targeted Russian maritime schools, diplomatic missions, energy facilities, government agencies and financial institutions for nearly two years. Kaspersky says the campaign dates back to at least 2024 and used phishing emails with ZIP attachments containing a malicious file disguised as a Microsoft Excel configuration file; recent attacks starting in January 2026 used the Ravage post-compromise framework from GitHub to run commands, move files and capture screenshots. The company did not name the group, provide victim totals, or attribute the activity to a known state or criminal actor.
Why it matters: This is a sustained espionage-style campaign against sensitive Russian sectors, showing that simple phishing attachments are still effective and that publicly available offensive tools are being folded into real operations. Organizations in similar sectors should review email defenses, hunt for Ravage-related activity, and investigate suspicious Excel-launched processes and dormant compromises.
Sources
2026.05.31 100%
This article appears to be the first tracked report establishing this specific, previously unreported multi-year campaign and its targeting pattern.
Full page
Suspected Pakistan-linked SideCopy phishing campaign targets Afghanistan finance officials with XenoRAT malware
Threat Actors & APTsSocial Engineering & PhishingMalwareGovernmentFinance & BankingAfghan Ministry of Finance
Afghan Ministry of Finance and provincial government officials were targeted in a phishing campaign that installed remote-access malware on victims' computers. Seqrite attributed the activity with medium-to-high confidence to the Pakistan-linked SideCopy group, which used Pashto-language lure documents inside ZIP archives and delivered them through compromised Afghan government server infrastructure; opening the file installed XenoRAT, a remote access trojan, which then contacted attacker-controlled servers in Europe.
Why it matters: This matters because it shows a suspected state-linked espionage operation aimed at government financial and provincial officials, using trusted local-language lures and compromised government infrastructure to improve success. Afghan public-sector defenders should investigate suspicious ZIP attachments, review access to government-hosted domains, and hunt for XenoRAT-related activity.
Sources
2026.05.31 100%
This article establishes a distinct campaign: a newly reported suspected SideCopy operation targeting Afghan finance-sector government entities via Pashto-language phishing and XenoRAT.
Full page
European intelligence officials warn Russia is intensifying espionage and cyber intrusions to steal sanctioned Western technology
Threat Actors & APTsPolicy & RegulationGovernmentDefense & AerospaceEnergy & UtilitiesTechnology & SoftwareManufacturing
European intelligence officials say Russia is increasingly using fake companies, middlemen, and cyber operations to steal Western technology, defense know-how, and software restricted by sanctions. The reported targets include defense research, dual-use camera and laser technology, machine-tool software updates, and critical infrastructure reconnaissance in Sweden, Finland, and the U.K. Officials also said Russia-linked actors attempted a destructive intrusion against a Swedish power plant last year but were detected before causing damage.
Why it matters: This matters to companies in defense, manufacturing, research, and critical infrastructure because they may be targeted both for theft and for pre-attack reconnaissance. Organizations should scrutinize customers and intermediaries for sanctions evasion, harden networks used for industrial systems, and watch for state-linked phishing, intrusion, and supply-chain targeting.
Sources
Associated Press 2026.05.30 100%
This article establishes a distinct story by tying sanctions pressure to a broader, ongoing Russian espionage and cyber campaign against Western technology suppliers and infrastructure, rather than reporting on a single previously tracked breach or malware incident.
Full page
Exploit code published for Flowise remote-code-execution flaw CVE-2026-40933 affecting self-hosted servers
Zero-Days & CVEsTechnology & SoftwareFlowise
Public exploit code is now available for a critical Flowise bug that can let attackers take over self-hosted AI workflow servers by getting someone to import a malicious chatflow. The flaw, CVE-2026-40933 (CVSS 9.9), affects Flowise before 3.1.0 and stems from unsafe handling of Anthropic Model Context Protocol (MCP) stdio commands in the MCP adapter. Importing a crafted chatflow can trigger command execution during tool enumeration, leading to operating-system-level code execution with the Flowise process's privileges. Flowise Cloud is not affected because stdio MCP is disabled there.
Why it matters: Organizations running self-hosted Flowise should treat this as urgent because working exploit code lowers the barrier to real attacks and the flaw can expose stored credentials and connected services. Update to 3.1.0 or later and limit who can create or import chatflows, especially where Flowise is connected to databases, APIs, or cloud accounts.
Sources
Ionut Arghire 2026.05.30 100%
This article establishes a distinct escalation in the Flowise CVE-2026-40933 story by reporting that technical details and proof-of-concept code have been published, making the exploit path concrete and actionable for defenders.
Full page
Microsoft says 14 malicious npm packages impersonated OpenSearch and Elasticsearch libraries to steal cloud and CI/CD credentials
Supply ChainMalwareTechnology & SoftwareOpenSearchElasticsearchGitHubHashiCorpnpm
A single attacker published 14 malicious npm packages that pretended to be OpenSearch, Elasticsearch, and related developer tools, putting developers and build systems at risk of secret theft. Microsoft said the packages were uploaded under the alias "vpmdhaj" and used typosquatting, spoofed metadata, and inflated version numbers; on install, preinstall hooks fetched a second-stage credential harvester targeting Amazon Web Services, HashiCorp Vault, GitHub Actions, and npm tokens. The packages were removed after publication.
Why it matters: Anyone who installed or built these packages may have exposed credentials that can be reused to access cloud accounts, code pipelines, and package publishing systems. Organizations should identify affected installs from May 28 onward, rotate AWS Identity and Access Management or Security Token Service credentials, Vault tokens, npm publish tokens, and GitHub Actions secrets, and review for follow-on compromise.
Sources
2026.05.29 100%
This article establishes a distinct npm package supply-chain incident centered on 14 typosquatted packages targeting OpenSearch and Elasticsearch users, not one of the existing tracked package compromises.
Full page
California AB 1856 advances with open-source exemption but would expand age-check requirements to browsers and websites
Surveillance & PrivacyPolicy & RegulationInformation FreedomCensorshipGovernmentTechnology & SoftwareConsumers & General Public
California lawmakers advanced AB 1856, a bill that would exempt open-source operating systems from parts of the state's age-assurance law but broaden age-checking requirements for many internet services. EFF says the amended bill would still extend the age-bracketing regime created by AB 1043 beyond operating systems and app stores to web browsers and websites, increasing pressure to collect users' age data and potentially affecting anonymity, privacy, and access to lawful speech.
Why it matters: If enacted, the bill could force more online services to ask for and retain age information, creating new privacy and security risks for ordinary users while raising compliance burdens for developers and platforms. People and organizations tracking internet freedom and privacy policy should watch the Senate process closely.
Sources
Molly Buckley 2026.05.29 100%
This article establishes a distinct California policy story centered on AB 1856's legislative advance, its new open-source exemption, and its simultaneous expansion of age-gating obligations to browsers and websites.
Full page
ICE awards Bi2 Technologies $25.1 million contract for 1,570 biometric scanners linked to iris, fingerprint, face, and law-enforcement databases
Surveillance & PrivacyPolicy & RegulationGovernmentTechnology & SoftwareConsumers & General PublicICEBi2 Technologies
U.S. Immigration and Customs Enforcement is expanding field use of biometric scanners that can identify people by iris scans, fingerprints, and facial recognition. Contract records show ICE awarded Bi2 Technologies about $25.1 million for 1,570 mobile and stationary devices and access to Bi2's IRIS system, which searches more than five million booking, arrest, and incarceration records across 47 states, along with driver’s license and license-plate data; the deal follows a smaller 200-device deployment under a 2025 contract.
Why it matters: This matters to immigrants, protesters, and the public because it expands real-world government biometric surveillance at scale, with risks of misidentification, bias, and wider tracking. The concrete implication is policy and oversight scrutiny rather than patching: civil-liberties groups, lawmakers, and affected communities should watch how ICE uses the devices and what databases they query.
Sources
2026.05.29 100%
The article establishes a specific new procurement and deployment event: ICE's large-scale purchase of Bi2 biometric devices and database access, distinct from the existing tracked items about other surveillance programs or court cases.
Full page
Attackers abuse ChatGPT share links and Google ads to deliver malware through fake OpenAI outage pages
MalwareSocial Engineering & PhishingTechnology & SoftwareConsumers & General PublicOpenAIGoogle
Attackers are using legitimate ChatGPT share links to show fake OpenAI outage notices that tell people to download a bogus ChatGPT desktop app. Push Security says the LLMShare campaign buys Google ads for ChatGPT searches, serves the lure from chatgpt.com/s/ pages rendered with custom HTML and CSS inside ChatGPT, then redirects victims to openew[.]app, which offers cloaked Windows and macOS malware downloads; the Windows sample checks whether it is running on a real device or a virtual machine.
Why it matters: This matters because the scam is hosted partly on a real OpenAI domain, making it more convincing to ordinary users and harder for defenders to spot. Users should avoid sponsored results for AI tools, download apps only from the official vendor site or app store, and security teams should monitor for chatgpt.com share-link abuse and block the impersonation domain.
Sources
Lawrence Abrams 2026.05.29 100%
This article establishes a distinct campaign centered on abuse of ChatGPT's share-link feature and Google ads to distribute malware via fake outage pages, not the same underlying event as any tracked story.
Full page
Unsealed court records show DOJ tried and failed to get Don Lemon and Georgia Fort YouTube account data
Information FreedomSurveillance & PrivacyPolicy & RegulationGovernmentTechnology & SoftwareMedia & EntertainmentDOJYouTube
A federal judge twice rejected prosecutors’ attempts to obtain YouTube account records tied to journalists Don Lemon and Georgia Fort, including information about their channels and possible viewers. The warrants were sought in a criminal case related to the journalists’ coverage of a protest at a church in St. Paul, Minnesota. Court records show the judge found the applications lacked probable cause and did not comply with the Privacy Protection Act of 1980, which generally limits search warrants targeting journalists and publishers.
Why it matters: This matters to journalists, sources, and viewers because prosecutors sought not just reporter account data but potentially audience information as well. It is a significant press-freedom and privacy issue, and it adds urgency to scrutiny of DOJ warrant practices and proposed updates to journalist-protection laws.
Sources
Freedom of the Press Foundation 2026.05.29 94%
This newsletter directly references the same newly unsealed court records and adds framing from Freedom of the Press Foundation that the rejected warrant applications targeted journalists Don Lemon and Georgia Fort over protest coverage.
Freedom of the Press Foundation 2026.05.27 100%
This article establishes a distinct new story because it is based on newly unsealed warrant records revealing a specific failed DOJ effort to compel YouTube data from named journalists and their audiences.
Full page
Trump Mobile website reportedly exposed customer records through an unsecured API request
Breaches & Data LeaksSurveillance & PrivacyTelecommunicationsConsumers & General PublicTrump Mobile
A Trump Mobile website flaw reportedly let anyone pull customer order records, exposing personal details of people who preordered the company’s phone service and handset. According to The Register and the finder, a simple HTTP POST request to exposed application programming interface (API) endpoints returned batches of records containing names, postal addresses, email addresses, phone numbers, customer numbers, enrollment IDs, and order-channel details; no CVE is assigned, and the issue was reportedly fixed after disclosure attempts.
Why it matters: Affected customers could face phishing, impersonation, or account-targeted fraud if their contact and order data was exposed. Trump Mobile users should watch for suspicious calls, texts, and emails referencing orders or account setup, while the company should clarify scope and notify affected users if exposure is confirmed.
Sources
SecurityWeek News 2026.05.29 95%
This article adds that Trump Mobile confirmed customer names, addresses, email addresses, phone numbers, and other data were exposed, and said a third-party platform provider was responsible for the exposure.
2026.05.22 100%
This article appears to be the first concrete report of the Trump Mobile customer-data exposure event, including the claimed technical access method, categories of data exposed, and estimated scale.
Full page
Charter confirms breach after ShinyHunters claims it stole customer data through a vishing attack
Social Engineering & PhishingBreaches & Data LeaksScams & FraudThreat Actors & APTsTelecommunicationsTechnology & SoftwareConsumers & General PublicCharter CommunicationsMicrosoftSalesforce
Charter Communications says it suffered a security incident after the ShinyHunters extortion group threatened to leak stolen data. The attackers claim they breached Charter on April 1 by using voice phishing (vishing) to compromise an employee's Microsoft Entra account, then used access to Charter's Salesforce environment to export about 40 million customer records, including names, contact details, plan information, support tickets, and some customer proprietary network information (CPNI); Charter disputes that sensitive personal data or CPNI was exfiltrated.
Why it matters: Charter serves tens of millions of customers, so even partial account and service data exposure could create follow-on phishing, fraud, and impersonation risks. Affected users should watch for targeted calls and emails referencing Spectrum or account details, while defenders should review identity-provider protections, help-desk verification, and Salesforce access logs.
Sources
Ionut Arghire 2026.05.29 98%
This is the same Charter/ShinyHunters breach event and adds that the gang has now published the allegedly stolen data, that Have I Been Pwned found about 4.9 million unique email addresses in the leak, and that the dataset includes names, addresses, phone numbers, and roughly 85,000 employee-linked records. It also includes Charter's statement disputing that CPNI or sensitive personal information was released.
2026.05.29 98%
This is the same Charter/ShinyHunters breach event and updates it with reported public leakage of 4.9 million customer records, Have I Been Pwned ingestion details, and Charter's statement that no sensitive PI or CPNI was exfiltrated.
Sergiu Gatlan 2026.05.29 98%
This is the same underlying Charter/ShinyHunters incident and adds key specifics: Have I Been Pwned says 4.9 million unique accounts were affected, the leaked data included names, email addresses, phone numbers, physical addresses, and about 85,000 employee-directory records with job titles, and the intrusion reportedly began with a vishing attack against an employee's Microsoft Entra account followed by theft from Salesforce.
Lawrence Abrams 2026.05.26 100%
This article appears to be the first tracked item establishing Charter's confirmed breach tied to a ShinyHunters extortion claim and a specific vishing-to-SaaS compromise path.
Full page
Google rolls out Chrome device-bound session protection to block stolen cookie account hijacking
Surveillance & PrivacyTechnology & SoftwareConsumers & General PublicGoogle
Google says Chrome's Device Bound Session Credentials feature is now rolling out broadly for personal Google accounts and Google Workspace users to stop attackers from reusing stolen login cookies. The protection cryptographically binds session cookies to a specific device using hardware-backed keys such as TPM on Windows and Secure Enclave on macOS, making stolen cookies far harder to use for account takeover even after multi-factor authentication. Google says it will be enabled by default for Workspace customers and cannot be turned off by admins.
Why it matters: This matters to anyone using Google accounts because session-cookie theft is a common way infostealer malware and phishing campaigns bypass login protections. Users should still remove malware and harden browsers, but this rollout adds an important default defense against account hijacking.
Sources
Sergiu Gatlan 2026.05.29 100%
The article establishes a new trackable security development: Google's general-availability rollout of Chrome Device Bound Session Credentials as a concrete mitigation against session-cookie theft and account takeover.
Full page
Researcher says ChatGPT web-page summaries can be prompt-injected to show phishing links and fake security alerts
Social Engineering & PhishingTechnology & SoftwareConsumers & General PublicOpenAI
A researcher says ChatGPT can be tricked into turning a malicious web page into a phishing message when a user asks it to summarize that page. Permiso's Andi Ahmeti reported that hidden Markdown instructions in attacker-controlled content can make ChatGPT include fake account alerts, attacker links, or QR codes in its response; OpenAI did not confirm a fix, and no CVE is cited in the report.
Why it matters: People using ChatGPT to summarize websites could be shown convincing phishing prompts in the assistant's own voice, including links or QR codes that bypass normal browser safety habits. Until OpenAI confirms a fix, users and defenders should treat AI-generated summaries of untrusted pages as potentially tainted and avoid clicking embedded links or scanning QR codes.
Sources
2026.05.29 100%
This article appears to be the initial report of a distinct ChatGPT prompt-injection phishing technique affecting browser-rendered external content, and it does not match any existing tracked story.
Full page
WithSecure links new Russia-aligned GreyVibe campaign to phishing and malware attacks on Ukrainian targets
Threat Actors & APTsSocial Engineering & PhishingMalwareGovernmentDefense & AerospaceConsumers & General Public
Researchers say a previously undocumented Russia-linked group called GreyVibe has targeted Ukrainian military, government, civilian, and business organizations since August 2025. WithSecure says the actor used at least six spear-phishing campaigns, fake adult-club websites, Telegram and dating-site lures, and file-sharing links to deliver PhantomRelay and LegionRelay malware on Windows and Fallspy on Android; the report also says the group used ChatGPT, Gemini, Ideogram, and other generative artificial intelligence tools across lure creation, malware development, obfuscation, and post-compromise tooling.
Why it matters: This matters because it describes an active espionage-focused campaign against Ukrainian targets and shows how lower-sophistication operators can use generative artificial intelligence to scale convincing phishing and malware operations. Organizations supporting Ukraine should review indicators, harden email and mobile defenses, and warn users about archive-based lures, fake personas, and links delivered over chat and dating platforms.
Sources
2026.05.29 97%
This article is a direct write-up of the same GREYVIBE campaign, adding detail that the operators used ChatGPT, Gemini, and Ideogram AI across lure creation, malware development, infrastructure setup, obfuscation, and post-compromise work, and noting OPSEC mistakes and design flaws in LegionRelay that exposed backend infrastructure.
Bill Toulas 2026.05.28 98%
This article is a direct update on the same GreyVibe campaign, adding detail that the group used ChatGPT, Gemini, and other AI tools to generate lures and likely assist development of custom obfuscators and malware including LegionRelay, PhantomRelay, and FallSpy, alongside more specifics on attack chains such as PhantomMail, PhantomClick, PrincessClub, DroneLink, and Nebo.
Kevin Townsend 2026.05.28 100%
This article appears to be the first tracked item here establishing GreyVibe as a distinct Russia-linked campaign and naming its malware families, targeting, and AI-assisted operating methods.
Full page
U.S. man sentenced for selling personal data of 7 million elderly Americans to Jamaican lottery scammers
Scams & FraudBreaches & Data LeaksConsumers & General Public
A North Carolina man was sentenced to prison for selling elderly Americans' personal information to scammers who used it in lottery fraud schemes. Troy Murray pleaded guilty to conspiracy to commit wire fraud and was sentenced to 121 months after prosecutors said he sold at least 22,000 lead lists between 2016 and 2023 containing names, phone numbers, physical addresses, and email addresses of over 7 million seniors; authorities said the scheme generated more than $5.2 million for him and caused over $9.5 million in victim losses.
Why it matters: This matters because it shows how stolen or traded personal data directly fuels large-scale fraud against older adults. People, especially seniors and their families, should be wary of unsolicited calls or messages about prizes or lotteries, and defenders and policymakers can use the case as a concrete indicator of fraud infrastructure and data-broker abuse.
Sources
Sergiu Gatlan 2026.05.29 100%
This article establishes a distinct law-enforcement milestone in a large elder-fraud operation centered on the sale of lead lists to Jamaican lottery scammers, and it does not match any existing tracked story by the same underlying event.
Full page
Google Chrome 148 update fixes 151 browser vulnerabilities, including 22 critical flaws
Urgent PatchesZero-Days & CVEsTechnology & SoftwareConsumers & General PublicGoogle
Google released a Chrome 148 security update that fixes 151 vulnerabilities, including 22 critical bugs that could help attackers run malicious code through the browser. The most severe issues named are CVE-2026-9872 (out-of-bounds write in GPU), CVE-2026-9873 (use-after-free in Network), CVE-2026-9874 (use-after-free in Dawn), CVE-2026-9875 (out-of-bounds read in WebGL), and CVE-2026-9876 (use-after-free in WebGL). The update is rolling out as 148.0.7778.216/217 for Windows, 148.0.7778.215/216 for macOS, and 148.0.7778.215 for Linux.
Why it matters: Chrome is widely used, so browser flaws with remote-code-execution potential can expose large numbers of people and organizations to drive-by compromise if left unpatched. Users and IT teams should update Chrome promptly across Windows, macOS, and Linux fleets.
Sources
Ionut Arghire 2026.05.29 100%
This article establishes a distinct patch-cycle story centered on Google's Chrome 148 update and the specific set of newly disclosed CVEs it fixes; no existing tracked story covers this same release.
Full page
Pentagon confirms foreign adversaries used commercial smartphone location data to target U.S. troops in the Middle East
Surveillance & PrivacyPolicy & RegulationGovernmentDefense & AerospaceTechnology & SoftwareConsumers & General PublicPentagonDepartment of DefenseU.S. Central Command
The Pentagon says foreign adversaries used commercially available phone-location data to target or surveil U.S. military personnel in active war zones, affecting troops who carried personal or government-issued smartphones. According to DoD responses released by Sen. Ron Wyden, U.S. Central Command received multiple threat reports tied to commercial data-broker purchases sourced from mobile advertising profiles and device ad identifiers; the department said existing guidance to disable geolocation was incomplete, and some DoD-managed phones still allowed ad-targeting data to be exposed.
Why it matters: This is a real-world national security and personal safety risk, not a theoretical privacy problem: location data sold by brokers can expose troop movements and bases. It raises urgency for stricter mobile-device controls, disabling ad IDs and location sharing, and rethinking bring-your-own-device policies in sensitive environments.
Sources
2026.05.28 100%
This article appears to be the first public confirmation, backed by DoD responses to lawmakers, that adversaries exploited commercial geolocation data to target or monitor U.S. troops in theater.
Full page
ESET warns BTMOB Android malware sold as a kit can steal data and remotely control infected phones
MalwareScams & FraudSocial Engineering & PhishingConsumers & General Public
A newly highlighted Android malware family called BTMOB can give criminals broad control over infected phones, including stealing data and taking over the device. ESET says the remote access trojan (RAT) is spread through phishing pages and fake app stores, abuses Android Accessibility Services to gain elevated privileges, and is sold with an APK-building kit that lets buyers customize lures by country and brand. The campaign has mainly been observed in Latin America.
Why it matters: This is more serious than a typical banking trojan because it can turn an Android phone into a remotely controlled spying and theft tool. Android users should avoid app downloads from links in messages or fake stores, and defenders should watch for phishing infrastructure and abuse of Accessibility permissions.
Sources
Bill Toulas 2026.05.28 97%
This is the same underlying ESET-reported BTMOB Android malware story, adding detail that the service includes a builder for custom phishing-themed payloads, is sold via Telegram with subscription pricing, is distributed through fake Google Play pages, and is concentrated in Brazil and Latin America.
Ionut Arghire 2026.05.28 100%
This article appears to be the initial broad reporting on ESET's identification of BTMOB as a distinct Android malware threat sold as a customizable kit and delivered through phishing lures.
Full page
Carnival confirms ShinyHunters-linked data breach affecting nearly 6 million cruise customers
Threat Actors & APTsSocial Engineering & PhishingBreaches & Data LeaksHospitality & TravelConsumers & General PublicCarnivalHolland America
Carnival Corporation says attackers stole customer data after socially engineering an employee and accessing part of its IT systems, affecting 5,995,277 people. The company says the intrusion was identified on April 14, 2026 and data theft was confirmed on April 22; ShinyHunters had claimed the breach in April and said it stole millions of records. Exposed data reportedly includes names, dates of birth, email addresses, gender, location, and loyalty-program details tied to Holland America's Mariner Society.
Why it matters: This is a major consumer data breach involving sensitive personal information that could fuel phishing, impersonation, and account-targeting scams. Affected customers should watch for breach notices, be cautious of unsolicited calls or emails referencing cruises or loyalty programs, and change passwords anywhere they were reused.
Sources
Ionut Arghire 2026.05.28 99%
This is the same underlying Carnival breach: it adds the formal disclosure that 5,995,277 people were affected, says the intrusion was identified April 14 after social engineering compromised an employee account, and specifies categories of stolen personal data and the company's notification and credit-monitoring response.
2026.05.28 99%
This article is the same underlying event: Carnival's confirmation that an April compromise of an employee account led to theft of customer data later claimed by ShinyHunters. It adds that the company says copied data includes names, contact details, dates of birth, driver's license numbers, and passport numbers, and cites the Maine filing showing nearly 6 million affected individuals.
2026.05.28 99%
This article is the same underlying event: Carnival's April 14, 2026 social-engineering breach attributed to ShinyHunters. It adds that Carnival's Maine filing lists just under 6 million affected individuals, confirms stolen data types including names, addresses, email addresses, phone numbers, dates of birth, and state identification numbers, and notes that breach notices and two years of credit monitoring are being sent.
Sergiu Gatlan 2026.05.28 100%
This article appears to be the first concrete confirmation and scope disclosure for Carnival's April 2026 breach, tying the incident to a social-engineering attack and a nearly 6 million-person impact.
Full page
Romanian hacker sentenced in U.S. for selling access to Oregon state government network
Breaches & Data LeaksThreat Actors & APTsGovernmentOregon state governmentU.S. Justice Department
A Romanian hacker was sentenced in the United States for breaking into an Oregon state government office and selling that network access to others. Catalin Dragomir admitted hacking the state office in June 2021, selling access for $3,000 in Bitcoin, and trafficking data from at least 10 other U.S. organizations; the Justice Department said the broader activity caused more than $250,000 in losses. He received a 4 year and 8 month prison sentence after extradition from Romania.
Why it matters: This is a reminder that stolen network access to government systems is an active criminal market, not just a one-off intrusion. Public agencies and contractors should review identity controls, monitor for unauthorized remote access, and ensure former or unusual accounts and access paths are investigated quickly.
Sources
Sergiu Gatlan 2026.05.28 99%
This article is the same underlying event and adds the sentencing specifics: Catalin Dragomir received 56 months in prison, forfeited about 23 Monero, and prosecutors said he sold access to the Oregon Department of Emergency Management network and nearly a dozen other U.S. victims, causing at least $250,000 in losses.
2026.05.27 99%
This article is the same underlying event and adds the sentencing outcome: Catalin Dragomir received 56 months in prison after pleading guilty to aggravated identity theft and obtaining information from a protected computer for hacking Oregon’s Office of Emergency Management and selling administrative credentials.
Eduard Kovacs 2026.05.27 100%
The article establishes a distinct law-enforcement milestone tied to the compromise and resale of access to an Oregon state network, and it does not match any existing tracked story in the list.
Full page
CrowdStrike, Google and Shadowserver disrupt GlassWorm botnet targeting Visual Studio, npm, PyPI and GitHub developers
Supply ChainThreat Actors & APTsMalwareTechnology & SoftwareCryptocurrency & BlockchainGoogleMicrosoftGitHubnpmPyPIOpenVSX
Security firms say they disrupted the GlassWorm botnet, a malware operation that infected developers and open source software ecosystems and could be used to steal credentials, cryptocurrency wallet data, and remote access to infected machines. CrowdStrike says GlassWorm spread through trojanized Visual Studio extensions on OpenVSX and later through GitHub and compromised Python projects, while using Solana blockchain transactions, Google Calendar, BitTorrent and VPS-hosted servers as layered command-and-control channels. The malware hid code with Unicode variation selectors and stole npm, GitHub and Git credentials, creating downstream software supply-chain risk.
Why it matters: This matters because a compromise of developers can spread to the software and updates many other organizations rely on. Teams should check for beaconing to 164.92.88[.]210, investigate developer machines and repositories for compromise, rotate exposed credentials, and review software supply-chain protections.
Sources
2026.05.27 99%
This article is another report on the same GlassWorm disruption event, adding operational detail on the takedown timing, the four command-and-control channels hit simultaneously, and specifics on GlassWorm’s use of Solana memos, Google Calendar, BitTorrent DHT, and VPS-hosted payload servers.
Ionut Ilascu 2026.05.27 97%
This is the same underlying event: the coordinated takedown of the GlassWorm botnet. The article adds specific detail on the botnet's resilient command-and-control design across Solana transaction memos, BitTorrent DHT, Google Calendar dead drops, and direct VPS servers, plus a post-takedown beacon IP and mention of published YARA detection rules.
Ionut Arghire 2026.05.27 100%
This article establishes a distinct tracked event: the disruption of the GlassWorm developer-targeting botnet and new details on its multi-channel command-and-control infrastructure, scope across ecosystems, and defender actions.
Full page
Pretalx patched stored XSS flaw CVE-2026-41241 that could let conference organizers' accounts be hijacked
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareEducationMedia & EntertainmentPretalx
Pretalx, an open source platform used by many conferences to manage call-for-proposals and schedules, fixed a flaw that could let a malicious speaker submission run code in an organizer's browser. The issue, CVE-2026-41241, is a stored cross-site scripting (XSS) bug in searchable fields such as submission titles, speaker names, usernames, and email addresses; when an organizer searched for a matching record, attacker-supplied HTML or JavaScript could execute, steal a cross-site request forgery (CSRF) token, submit authenticated actions, or exfiltrate visible data. It was patched in April and fixed in pretalx 2026.1.0.
Why it matters: Conference teams using pretalx could have had proposal data changed or organizer sessions abused simply by viewing malicious submissions, so affected admins should update to pretalx 2026.1.0 or later and review organizer access and stored submissions. Because pretalx is reused across many events, one product bug can affect multiple independent conference systems at once.
Sources
Eduard Kovacs 2026.05.27 97%
This is the same underlying event: disclosure of CVE-2026-41241 in Pretalx and its patch in version 2026.1.0. The article adds clearer detail on the attack chain, explaining that a malicious speaker submission could trigger stored XSS when organizers search submissions, enabling organizer account takeover and abuse across multiple Pretalx-powered conferences.
2026.05.27 100%
This article appears to be the first tracked item establishing the pretalx CVE-2026-41241 disclosure, exploit mechanics, and patched version.
Full page
India CERT-In tells organizations to patch or isolate exploited internet-facing vulnerabilities within 12 hours
Urgent PatchesPolicy & RegulationGovernmentTechnology & SoftwareCERT-In
India's national cyber agency has told organizations to fix, mitigate, or disconnect exposed critical systems within 12 hours when a known-exploited vulnerability affects them. In new CERT-In guidance on defending against AI-assisted attacks, the agency says the half-day target applies where feasible to internet-facing or 'crown jewel' systems with exploited n-day flaws, while other cases such as internal systems generally get a 24-hour target; this is guidance rather than a single-CVE advisory.
Why it matters: This raises the urgency for Indian organizations and anyone tracking national cyber guidance as attackers use artificial intelligence to speed up exploitation. Defenders should review patching and mitigation playbooks now so internet-exposed high-value systems can be patched, shielded, or taken offline quickly when active exploitation is known.
Sources
2026.05.27 100%
This article establishes a new trackable story because it centers on a new CERT-In directive-style guidance change setting a 12-hour response expectation for known-exploited flaws, not on any previously listed breach, CVE, or advisory event.
Full page
Dutch police arrest suspect in Ajax Amsterdam hack that exposed fan accounts and ticketing controls
Breaches & Data LeaksMedia & EntertainmentConsumers & General PublicAjax Amsterdam
Dutch police arrested a 35-year-old man suspected of repeatedly breaking into Ajax Amsterdam's computer systems earlier in 2026. Ajax previously said the attacker exploited vulnerabilities in its IT systems to access data on a few hundred people, while reporting indicated exposed application programming interfaces (APIs) and shared keys could let someone view more than 300,000 accounts, alter 538 supporter stadium bans, and reassign 42,000 season tickets; no CVE was cited.
Why it matters: This matters to Ajax fans and the club because the intrusion reportedly reached both personal data and operational controls like bans and ticket transfers. Anyone affected should watch for account abuse or phishing, and organizations should review exposed APIs, shared credentials, and access controls in customer and ticketing systems.
Sources
2026.05.27 99%
This article covers the same underlying Ajax breach and adds that Dutch police arrested a 35-year-old suspect in Buren, searched his home, and seized digital storage devices; it also reiterates that the intrusion involved an unpatched vulnerability and may have affected far more supporters and season tickets than Ajax initially disclosed.
Sergiu Gatlan 2026.05.27 100%
This article establishes a distinct story by tying the previously disclosed Ajax intrusion to a suspect arrest and restating the scope and impact of the breach on fan data and ticketing systems.
Full page
Researchers link LA Metro cyberattack to Iranian government hackers after disruptive March breach
Threat Actors & APTsMalwareBreaches & Data LeaksTransportation & LogisticsGovernmentLA MetroMicrosoft
Researchers say the March cyberattack on Los Angeles Metro was likely carried out by Iranian state-linked hackers, not just a self-described hacktivist group. LA Metro said the breach caused internal operational disruption and required hundreds of servers to be checked before restoration, while the attackers claimed to have wiped hundreds of terabytes and stolen more than 1 terabyte of data. Gambit linked the operation to infrastructure associated with Black Shadow, a group previously attributed to Iran's Ministry of Intelligence and Security, and said the attackers also accessed systems including virtualization management, Microsoft IIS servers, and a train-monitoring operational technology system.
Why it matters: A breach at a major transit agency raises concern not only about data theft but also about disruption to public services and potential access to operational systems. Transit operators and other public-sector defenders should review exposure of administrative platforms and monitoring systems, hunt for data theft and destructive activity, and treat claimed hacktivist incidents as possible state-backed operations.
Sources
2026.05.27 98%
This is the same underlying event: the March breach of the Los Angeles County Metropolitan Transportation Authority. The article adds that Gambit Security attributes the operation specifically to an Iran MOIS-linked group calling itself Ababil of Minab, describes destructive activity against databases, virtual machines, storage volumes, and backups, and notes additional victims in Israel, Turkey, Saudi Arabia, and other sectors.
Eduard Kovacs 2026.05.27 100%
This article establishes a distinct tracked story by adding substantive attribution and technical context to the previously reported LA Metro breach, tying the incident to Iranian state-linked infrastructure and broader targeting.
Full page
Attackers exploited KnowledgeDeliver zero-day CVE-2026-5426 to install web shells and backdoors on LMS servers
Zero-Days & CVEsMalwareThreat Actors & APTsEducationTechnology & SoftwareDigital Knowledge
Hackers used a previously unknown flaw in Digital Knowledge’s KnowledgeDeliver learning platform to break into servers and plant persistent malware. Mandiant says CVE-2026-5426 affects KnowledgeDeliver deployments before February 24, 2026, because a standardized ASP.NET web.config file contained hardcoded machineKey values, enabling ViewState deserialization attacks for remote code execution. The observed intrusions deployed Godzilla web shells, altered JavaScript to show fake plugin alerts, and ultimately installed a tailored Cobalt Strike backdoor.
Why it matters: Organizations using KnowledgeDeliver, especially enterprise and education users, may already be compromised, not just vulnerable. Admins should urgently rotate machine keys, restrict access to the LMS, hunt for the published indicators of compromise, and check for web shells, modified JavaScript, and follow-on malware.
Sources
Ionut Ilascu 2026.05.26 98%
This article is a direct update on the same Mandiant-reported event, adding technical detail that the unauthenticated flaw was a ViewState deserialization issue caused by shared hardcoded ASP.NET machine keys, and that attackers deployed the Godzilla web shell, altered JavaScript to push a fake 'security authentication plugin,' and delivered Cobalt Strike.
Ionut Arghire 2026.05.26 100%
This article establishes a distinct new incident: in-the-wild exploitation of KnowledgeDeliver zero-day CVE-2026-5426, including the attack chain, malware used, affected versions, and mitigation steps.
Full page
Play ransomware gang lists MyPillow as an alleged victim and threatens to leak stolen company and employee data
RansomwareBreaches & Data LeaksRetail & E-CommerceManufacturingConsumers & General PublicMyPillow
Play ransomware operators have posted MyPillow to their leak site, claiming they stole sensitive internal data and will publish it if the company does not pay. According to the gang’s dark-web extortion post, the alleged haul includes personal and confidential data, client documents, budgets, payroll records, IDs, tax files, and finance information. The article does not provide technical details on the intrusion method, affected systems, or data volume, and MyPillow had not confirmed the breach at publication time.
Why it matters: If the claim is accurate, employees, customers, and business partners could face privacy risks, fraud, or follow-on phishing using stolen records. Defenders should watch for confirmation, review for signs of Play ransomware activity, and prepare incident-response, notification, and credential-reset steps if exposure is verified.
Sources
2026.05.26 100%
This article appears to be the first report in the provided set identifying MyPillow as a new alleged Play ransomware victim, establishing a distinct incident rather than updating an existing tracked story.
Full page
Lithuania investigates leak of more than 600,000 national register records after suspected foreign access using institutional credentials
Breaches & Data LeaksThreat Actors & APTsGovernmentConsumers & General PublicLithuanian Prosecutor General's OfficeCentre of Registers
Lithuania says more than 600,000 entries from national data registers were leaked after someone used login credentials belonging to authorized institutions. Prosecutors said the exposed data mainly came from real-estate and legal-entity registers, authorities suspect a foreign country was involved, and access was tightened by blocking suspected accounts and forcing credential updates.
Why it matters: This is a major government-data exposure with potential risks to ordinary citizens as well as officials, diplomats, and security personnel. Organizations with access to Lithuanian state registers should urgently review account use, rotate credentials, and check for unauthorized queries or data exports.
Sources
2026.05.26 98%
This article is the same underlying event and adds details on the affected registers (Real Estate and Legal Entities), the types of data exposed, the use of institutional login credentials, the timeline of detection and delayed disclosure, account-blocking and credential-reset measures, estimated financial damage, and the resignation of the Centre of Registers chief.
Associated Press 2026.05.26 100%
This article establishes a distinct new story: a large-scale leak from Lithuanian national registers tied to misuse of authorized-access credentials and possible foreign intelligence involvement.
Full page
Iran-linked Nimbus Manticore targets aviation and software companies with new MiniFast backdoor and fake job lures
Threat Actors & APTsMalwareSocial Engineering & PhishingDefense & AerospaceTechnology & SoftwareOnlyOfficeZoomOracle
An Iran-linked hacking group is using fake job offers and trojanized software downloads to break into aviation and software companies, including targets in Saudi Arabia, Australia, and the United States. Check Point says Nimbus Manticore (also known as Bohrium, TA455, and UNC1549) switched from DLL sideloading to AppDomain hijacking, using malicious .NET configuration files to load payloads, and deployed updated MiniJunk malware plus a new Windows DLL backdoor called MiniFast through ZIP files on OnlyOffice, a fake Zoom installer, and a fake SQL Developer site boosted with search-engine optimization.
Why it matters: This campaign shows continued state-linked targeting of sensitive industries during heightened regional tensions, with lures that can fool both job seekers and employees downloading familiar tools. Organizations in aviation, defense-adjacent, and software sectors should warn staff about recruiter and installer lures, review detections for MiniJunk and MiniFast, and hunt for suspicious .config-based AppDomain hijacking activity.
Sources
Ionut Arghire 2026.05.26 100%
The article establishes a distinct new campaign and tooling update for Nimbus Manticore, including a new backdoor, new execution technique, and an apparent expansion toward U.S. targets rather than simply re-reporting a previously tracked event.
Full page
7-Eleven discloses breach of franchisee document systems after ShinyHunters claims
Threat Actors & APTsBreaches & Data LeaksRetail & E-CommerceConsumers & General Public7-ElevenSalesforce
7-Eleven disclosed that attackers accessed systems used to store franchisee documents, with stolen data including names, addresses, and Social Security numbers. The company said it discovered the breach on April 8 and reported it to state regulators in Maine, Vermont, and Massachusetts. The disclosure follows ShinyHunters' late-April claim that it stole 7-Eleven data allegedly stored on Salesforce.
Why it matters: The breach exposes sensitive personal data tied to U.S. franchise operations, creating identity theft and follow-on phishing risk for affected individuals. Defenders and franchisees should watch for extortion fallout, credential abuse, and notices clarifying scope and attack path.
Sources
Ionut Arghire 2026.05.26 98%
This is the same underlying April 2026 7-Eleven breach involving franchise-document systems and ShinyHunters' claimed theft of Salesforce records. The article adds a likely victim count from HaveIBeenPwned (about 185,300 people) and says the leaked data includes names, addresses, email addresses, and dates of birth, with some records containing additional fields.
Sergiu Gatlan 2026.05.26 98%
This is the same April 2026 7-Eleven breach of systems used to store franchisee documents; the new reporting adds an estimated victim count of 185,300 people from Have I Been Pwned and specifies exposed fields including names, dates of birth, email addresses, phone numbers, and physical addresses, while reiterating ShinyHunters' claimed link to a Salesforce-related compromise.
2026.05.20 100%
This article establishes a distinct breach event at 7-Eleven and provides the first concrete confirmation of stolen franchisee data following ShinyHunters' public claims.
Full page
Dutch investigators seize 800 servers tied to Stark Industries hosting network allegedly used for cyberattacks and disinformation
Policy & RegulationDisinformation & Influence OpsThreat Actors & APTsTechnology & SoftwareGovernmentStark IndustriesDutch PoliceDutch Public Prosecution Service
Dutch authorities say they seized 800 servers and arrested two men linked to a hosting operation that allegedly helped cyberattacks, disruption campaigns, and online disinformation. Investigators said the action targeted infrastructure connected to Stark Industries, an EU-sanctioned hosting provider, and two Dutch companies allegedly used to keep its services running after sanctions; reporting links the network to pro-Russian DDoS, or distributed denial-of-service, activity by NoName057(16).
Why it matters: This matters because the seizure hits infrastructure allegedly used to support both cyberattacks and influence operations in Europe. Defenders, hosting providers, and abuse teams should watch for fallout such as service migration, replacement infrastructure, and renewed DDoS activity from the same actors.
Sources
Ionut Arghire 2026.05.26 98%
This article is a direct update on the Stark Industries case, adding that Dutch authorities arrested two administrators of Dutch companies allegedly acting as fronts and infrastructure providers for the sanctioned hosting network, and confirming seizures at data centers and searches tied to Mirhosting and WorkTitans.
2026.05.25 98%
This article is a direct update on the same Dutch/Stark Industries enforcement action, adding that two Dutch IT entrepreneurs were arrested, naming the suspected related firms via reporting, and detailing allegations that the infrastructure was used by the Doppelgänger-linked Reliable Recent News network and in NoName057(16) DDoS attacks while evading EU sanctions.
BrianKrebs 2026.05.25 99%
This article appears to cover the same underlying event: Dutch authorities arrested two operators linked to MIRhosting and WorkTitans, searched multiple sites, and seized more than 800 servers tied to the Stark Industries network allegedly used in Russia-linked cyberattacks and disinformation. It adds names of the suspects, the sanctions-evasion allegations, and reporting tying the infrastructure to attacks on Danish government bodies during the 2025 municipal election period.
Bill Toulas 2026.05.22 100%
This article establishes a distinct new story: a Dutch law-enforcement action against Stark Industries-linked hosting infrastructure allegedly enabling cyberattacks and disinformation, not the previously tracked seizure of the separate First VPN service.
Full page
Drupal announces critical core security update for high-risk vulnerability affecting versions 8 and later
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareDrupal
Drupal announced a core security release for May 20, 2026, warning that exploits could appear within hours of disclosure. The issue affects Drupal core 8+ with patches planned for supported 11.x and 10.x branches, plus hotfixes for end-of-life 9.5 and 8.9 releases. No CVE or technical details were disclosed ahead of release.
Why it matters: Drupal is widely used by government, education, healthcare, and large organizations, so a high-risk core flaw has broad exposure. Defenders should monitor the advisory and be ready to apply updates immediately, especially because Drupal expects rapid exploit development.
Sources
Sergiu Gatlan 2026.05.26 94%
This article updates the same Drupal vulnerability event by adding that the flaw is tracked as CVE-2026-9082, is being actively exploited, has been added to CISA's KEV catalog, and now carries a Binding Operational Directive deadline for U.S. federal agencies to patch by May 27, 2026.
info@thehackernews.com (The Hacker News) 2026.05.23 94%
This appears to update the same Drupal core vulnerability event by adding that the flaw is being actively exploited and has now been added to CISA's KEV catalog, increasing urgency beyond the original critical update notice.
Eduard Kovacs 2026.05.22 96%
This is the direct follow-up to the same Drupal event, adding that CVE-2026-9082 is now seeing exploitation attempts in the wild, that Drupal raised its risk score, and that Imperva observed more than 15,000 attempts targeting nearly 6,000 sites across 65 countries.
Bill Toulas 2026.05.22 98%
This is a direct update to the same Drupal core flaw disclosed earlier in the week, adding the key new fact that exploit attempts for CVE-2026-9082 have now been detected in the wild and reiterating affected branches and upgrade guidance.
Eduard Kovacs 2026.05.21 97%
This article is the follow-up patch release for the same Drupal security event, adding the CVE identifier (CVE-2026-9082), technical details about the PostgreSQL SQL injection flaw, impact including possible unauthenticated RCE, and the fixed version branches.
info@thehackernews.com (The Hacker News) 2026.05.21 97%
This appears to cover the same May 2026 Drupal core security release, adding that the flaw is highly critical, affects PostgreSQL-based Drupal deployments, and can expose affected sites to remote code execution attacks.
Bill Toulas 2026.05.20 100%
This article establishes a new story because it is the initial report of a specific Drupal core security release tied to a high-exploitation-risk vulnerability, and it does not match any existing tracked event.
2026.05.19 98%
This article covers the same pre-disclosure Drupal core security release window for May 20, 2026, adding detail on affected branches including best-effort patches for unsupported 8.9 and 9.5, the advisory's severity characterization, and Drupal's warning to reserve immediate patch time because exploit code could follow quickly.
Full page
Kremlin appoints former Rostec cyber executive reportedly linked to GRU Unit 26165 to Russian Security Council post
Threat Actors & APTsDisinformation & Influence OpsGovernmentDefense & AerospaceTechnology & SoftwareKremlinRussian Security CouncilRostecRT-Information SecurityGRU
Russia has appointed a former cybersecurity executive reportedly tied to a military intelligence hacking unit to a senior Security Council role. The Record reports that Andrei Kozlov, formerly of Rostec's RT-Information Security and a Russian cybersecurity industry association, was named an aide to Security Council Secretary Sergei Shoigu; leaked data cited by The Insider allegedly links him to GRU Military Unit 26165, widely tracked as Fancy Bear or APT28, a group long accused of espionage, credential theft and influence operations.
Why it matters: This matters because it may show direct overlap between Russia's state security leadership and a unit publicly tied to past hacking and disinformation campaigns. Defenders and policymakers should treat it as contextual evidence when tracking future APT28 operations, influence activity and Russian state cyber posture.
Sources
2026.05.25 100%
This article establishes a new story about a Russian state appointment with alleged ties to GRU Unit 26165/Fancy Bear, rather than updating an existing tracked breach, malware campaign, or policy case.
Full page
Attackers exploit Ghost CMS SQL injection flaw CVE-2026-26980 to booby-trap hundreds of websites with ClickFix malware lures
Zero-Days & CVEsSocial Engineering & PhishingMalwareEducationFinance & BankingTechnology & SoftwareMedia & EntertainmentConsumers & General PublicGhost
Attackers are using a Ghost CMS bug to hijack websites and show visitors fake verification prompts that can infect their computers. The campaign abuses CVE-2026-26980, a critical unauthenticated SQL injection flaw affecting Ghost 3.24.0 through 6.19.0, to steal admin API keys and inject malicious JavaScript into article pages; researchers say more than 700 domains were hit, including university, media, fintech, and tech sites. Victims who follow the ClickFix instructions paste commands into Windows that download malware.
Why it matters: This affects both website owners and ordinary visitors: unpatched Ghost sites can be silently turned into malware delivery pages, and people browsing them can be tricked into infecting their own systems. Ghost administrators should update to 6.19.1 or later immediately, rotate exposed keys, and check for injected scripts and suspicious admin API activity.
Sources
Eduard Kovacs 2026.05.25 98%
This source is a direct update on the same underlying event: active exploitation of Ghost CMS CVE-2026-26980 to compromise websites and inject ClickFix-related malicious JavaScript. It adds concrete scope and victim detail, saying more than 700 sites were hacked, including sites tied to DuckDuckGo, Harvard, and Oxford, and notes at least two groups are competing in the poisoning campaign.
Bill Toulas 2026.05.24 100%
This article establishes a distinct security story by tying active, large-scale exploitation of Ghost CMS CVE-2026-26980 to website compromises and downstream ClickFix malware delivery across more than 700 domains.
Full page
Oncology Institute says third-party vendor breach exposed patient data across its cancer-care network
Breaches & Data LeaksSupply ChainHealthcareTechnology & SoftwareThe Oncology InstituteTriZetto Provider SolutionsCognizant
The Oncology Institute says a breach at an outside software services provider affected patient information in its systems. TOI said Kroll notified it on May 20, 2026 that the vendor detected unauthorized access to TOI information systems, including systems containing patient data; the vendor was not named, but the timeline and disclosure process point to Cognizant-owned TriZetto Provider Solutions as a possible match. TOI operates more than 100 clinics across five U.S. states.
Why it matters: Cancer patients and healthcare staff may face privacy risks and follow-on fraud if their information was exposed. Affected users should watch for breach notices and suspicious calls or emails, while healthcare organizations using the same vendor should review exposure and incident-response steps immediately.
Sources
Eduard Kovacs 2026.05.25 100%
This article establishes a distinct victim disclosure tied to a third-party healthcare software provider breach, with TOI newly confirming that patient data was affected.
Full page
Radiology Associates of Richmond says 266,000 people were affected by a breach that exposed medical and personal data
Breaches & Data LeaksHealthcareConsumers & General PublicRadiology Associates of Richmond
Radiology Associates of Richmond disclosed that hackers stole files containing sensitive patient information, affecting 266,183 people. The organization says attackers accessed internal systems on or about July 25, 2025, and a forensic investigation completed in April 2026 found unauthorized acquisition of files with protected health information. State filings indicate exposed data may include names, Social Security numbers, government ID numbers, financial account or payment-card details, and medical and health insurance information.
Why it matters: This is significant because it involves health data plus identity and financial information, raising risks of medical-identity fraud and broader identity theft. Affected people should watch for official notice letters, use offered credit monitoring if eligible, and monitor medical, insurance, and financial accounts for misuse.
Sources
Ionut Arghire 2026.05.25 100%
The article establishes a distinct breach event at Radiology Associates of Richmond with its own victim count, timeline, and disclosure details; it does not match any existing tracked story.
Full page
Laravel Lang Composer packages hijacked through rewritten Git tags to deliver credential-stealing malware
Breaches & Data LeaksSupply ChainMalwareTechnology & SoftwareCryptocurrency & BlockchainConsumers & General PublicLaravel LangGitHub
Attackers compromised Laravel Lang localization packages and made legitimate-looking Composer installs fetch malware instead. The attackers rewrote existing GitHub release tags across laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and possibly laravel-lang/actions to point to malicious commits in a fork, affecting hundreds of historical versions; the payload drops a PHP stealer that targets cloud keys, CI/CD secrets, SSH keys, browser data, crypto wallets, and on Windows launches a helper executable dubbed DebugElevator to decrypt Chromium-based browser credentials.
Why it matters: Developers and organizations that installed these packages could have had passwords, cloud credentials, and deployment secrets stolen without realizing it. Treat this as urgent: identify affected installs, remove compromised versions, rotate any exposed secrets, and review developer and build systems for follow-on access.
Sources
Ionut Arghire 2026.05.25 99%
This article covers the same Laravel-Lang package compromise and adds concrete details on the attack timeline, the four affected packages, the use of rewritten Git tags pointing to commits in a malicious fork, the C2 domain flipboxstudio[.]info, and the breadth of targeted secrets that defenders should rotate.
Lawrence Abrams 2026.05.23 100%
This article establishes a distinct supply-chain attack centered on the Laravel Lang package ecosystem, with a specific compromise method (Git tag rewriting) and malware payload, and it does not match any existing tracked story.
Full page
DocketWise says breach of third-party repositories exposed sensitive law firm and immigration case data for 143,000 people
Breaches & Data LeaksTechnology & SoftwareLegal & Professional ServicesConsumers & General PublicDocketWise
DocketWise says hackers accessed data tied to more than 143,000 people after cloning third-party partner repositories used in its data migration pipeline. The exposed records may include names, addresses, dates of birth, Social Security numbers, passport and driver's license data, financial account and payment card information, tax IDs, health insurance details, and medical condition or treatment information. The company says it began investigating in October 2025 and later determined some cloned repositories contained DocketWise law firm records.
Why it matters: People whose information was exposed face a real risk of identity theft, account fraud, and targeted scams, especially because the stolen data includes government IDs, financial details, and medical information. Affected users should watch for notice letters, enable fraud alerts or credit freezes where appropriate, and be cautious of messages claiming to help with immigration or legal matters.
Sources
Ionut Arghire 2026.05.25 100%
This article appears to be the first concrete disclosure here of the DocketWise breach, including the victim count, the type of data exposed, and the stated attack path through cloned third-party repositories.
Full page
Megalodon campaign poisons more than 5,500 GitHub repositories to steal CI/CD and cloud credentials
Breaches & Data LeaksSupply ChainMalwareTechnology & SoftwareGitHubBitbucketAmazon Web ServicesGoogle CloudMicrosoftTiledesk
A new automated attack dubbed Megalodon pushed malicious commits to more than 5,500 GitHub repositories, putting developers and organizations that merge those changes at risk of credential theft. Researchers say the malware runs in continuous integration and continuous delivery (CI/CD) pipelines after a poisoned commit is merged, then steals GitHub, Bitbucket, AWS, Google Cloud, Azure, SSH, Docker, Kubernetes, Vault, and Terraform secrets and can spread further; SafeDep also linked backdoored Tiledesk npm releases 2.18.6 through 2.18.12 to a compromised GitHub repository rather than a stolen npm account.
Why it matters: This can turn a routine code merge into a cloud-account and source-code compromise, especially for organizations that automatically build code from GitHub. Repo maintainers and security teams should review recent pull requests and commits, block suspicious automation, rotate CI/CD and cloud secrets, and check whether affected packages or repositories were used.
Sources
Ionut Arghire 2026.05.25 98%
This article is a direct report on the same Megalodon event, adding specifics on the attack window (May 18 over six hours), the 5,718 malicious commits across 5,561 repositories, the use of GitHub Actions workflows including workflow_dispatch for dormant backdoors, and the link to compromised Tiledesk npm package releases published from poisoned source code.
2026.05.22 100%
The article establishes a distinct new supply-chain campaign, separate from the tracked TeamPCP and Mini Shai-Hulud incidents, with a different actor, larger scope, and specific poisoned GitHub repos and Tiledesk package versions.
Full page
Italy dismantles CINEMAGOAL app operation that stole Netflix, Disney+, Sky, DAZN and Spotify access codes
Scams & FraudMedia & EntertainmentConsumers & General PublicGovernmentNetflixDisney+SkyDAZNSpotifyEurojust
Italian authorities say they dismantled CINEMAGOAL, a piracy app operation that let customers watch paid streaming services by using stolen or fraudulently obtained access credentials. Investigators say the system used virtual machines in Italy to capture valid authentication and decryption codes from legitimate subscriptions every three minutes, then redistributed them through servers seized in France and Germany. The probe, coordinated with Eurojust, included 100 searches, identified more than 70 resellers, and also disrupted a related IPTV service.
Why it matters: This matters because it was not just copyright infringement but a large-scale unauthorized-access and fraud scheme built around stolen streaming credentials and infrastructure designed to hide users. Streaming providers and affected subscribers should watch for fraudulent account creation and abuse, while defenders should note the use of virtual machines, foreign servers, crypto payments, and fake identities to operate the service.
Sources
Bill Toulas 2026.05.23 100%
The article establishes a distinct new enforcement story centered on the CINEMAGOAL app and its method of harvesting and redistributing valid streaming authentication codes.
Full page
Underminr CDN routing flaw lets attackers disguise malicious traffic as connections to trusted domains
Zero-Days & CVEsMalwareThreat Actors & APTsTechnology & SoftwareTelecommunicationsGovernment
Researchers say attackers are exploiting a weakness in shared content delivery network (CDN) infrastructure to make malicious connections look like they are going to legitimate websites. The technique, dubbed Underminr, is described as a variant of domain fronting that abuses mismatches between DNS lookups, server name indication (SNI), HTTP Host headers, edge IP addresses, and CDN tenant routing; ADAMnetworks says it affects roughly 88 million domains and has been used to bypass Protective DNS filtering, conceal command-and-control traffic, and tunnel VPN or proxy connections over TCP port 443.
Why it matters: Organizations that rely on DNS filtering or allowlists could miss malicious outbound traffic that appears to be headed to trusted domains. Defenders should review CDN egress controls, correlate DNS, SNI, Host header, and destination IP telemetry, and watch for guidance or mitigations from affected providers.
Sources
Ionut Arghire 2026.05.23 100%
This article appears to be the first tracked report establishing Underminr as a distinct, named CDN abuse technique with active exploitation and broad defensive implications.
Full page
CISA contractor exposed AWS GovCloud and internal agency credentials in public GitHub repository
Breaches & Data LeaksSupply ChainGovernmentTechnology & SoftwareCISAAmazon Web Services
KrebsOnSecurity reports that a public GitHub repository maintained by a CISA contractor exposed sensitive internal files, plaintext passwords, tokens, and administrative credentials for three AWS GovCloud accounts and other CISA systems. Researchers said some credentials were valid and could authenticate to high-privilege GovCloud environments, and the repository also exposed internal software build and artifactory access details.
Why it matters: This is a major breach-risk event affecting a U.S. federal cybersecurity agency, with potential impact on internal systems, software supply-chain integrity, and government cloud environments. Affected parties need credential rotation, repository auditing, and investigation of possible unauthorized access.
Sources
BrianKrebs 2026.05.22 99%
This is a direct follow-up on the same CISA 'Private-CISA' GitHub exposure, adding that congressional lawmakers are demanding answers and that CISA was still trying to revoke exposed credentials days after notification, including a reportedly still-valid RSA key tied to a GitHub app with broad access to CISA repositories and CI/CD secrets.
SecurityWeek News 2026.05.22 96%
This roundup directly recaps the same incident, adding that the public repository was named "Private-CISA," that the exposure lasted for months, and that the leaked material included administrative keys for multiple AWS GovCloud accounts and plaintext passwords that could have enabled lateral movement or software-package tampering.
Bruce Schneier 2026.05.22 99%
This is the same underlying event: a CISA contractor's public GitHub repository exposing privileged AWS GovCloud credentials and internal CISA deployment and system details; it mainly amplifies the severity and points readers to the reported leak.
2026.05.19 98%
This is the same underlying GitHub exposure event and adds specifics from The Register and GitGuardian on the repository contents, file names, duration of exposure, disclosure timeline, and CISA's response.
BrianKrebs 2026.05.18 100%
This article appears to be the first tracked report establishing the underlying event: a public GitHub leak of valid CISA internal and GovCloud credentials.
Full page
Former C.A. Cloud executives plead guilty to helping tech-support scam networks route and hide fraudulent calls
Scams & FraudSocial Engineering & PhishingPolicy & RegulationTechnology & SoftwareTelecommunicationsConsumers & General PublicC.A. CloudMicrosoftApple
Two former executives of call-tracking firm C.A. Cloud pleaded guilty to concealing a years-long tech-support scam operation that targeted victims worldwide. Prosecutors say the company knowingly provided phone numbers, call forwarding, recordings, and rotating number pools to fraudsters behind fake malware-warning pop-ups, including scammers impersonating Microsoft and Apple; the pair also allegedly ran a Tunisia call center where employees carried out similar fraud through remote computer access and false invoices.
Why it matters: This matters because it shows the infrastructure behind tech-support scams is being targeted, not just the callers themselves, and the scams often hit older and vulnerable people. Users should be wary of pop-ups or calls claiming their computer is infected, especially if they demand remote access or immediate payment.
Sources
Sergiu Gatlan 2026.05.22 100%
The article establishes a distinct enforcement story about C.A. Cloud executives admitting they knowingly supported tech-support fraud infrastructure, rather than a generic trend piece or a duplicate of an existing tracked case.
Full page
Canadian police arrest alleged Kimwolf botnet operator over record-scale DDoS attacks
Policy & RegulationMalwareThreat Actors & APTsTechnology & SoftwareConsumers & General PublicGovernmentU.S. Department of Justice
Canadian authorities arrested Ottawa resident Jacob Butler, alleged online as “Dort,” and U.S. prosecutors unsealed charges accusing him of running the Kimwolf Internet-of-Things botnet that hijacked millions of connected devices. The complaint says Kimwolf infected devices such as cameras and digital photo frames, issued more than 25,000 attack commands, powered distributed denial-of-service attacks measured at nearly 30 terabits per second, and was also rented to other criminals; the case follows March seizures of Kimwolf infrastructure and related botnets Aisuru, JackSkid, and Mossad.
Why it matters: This matters to internet providers, enterprises, and anyone running exposed connected devices because it shows how insecure Internet-of-Things products can be turned into large-scale attack infrastructure. Defenders should keep internet-facing devices patched, disable unnecessary exposure, and review mitigations tied to the exploitation path Kimwolf used to spread.
Sources
2026.05.22 98%
This is the same underlying event: the arrest of Ottawa resident Jacob Butler, alleged to be 'Dort,' over operating the KimWolf DDoS-for-hire botnet. The article adds specifics from the unsealed U.S. complaint, including the charge of aiding and abetting computer intrusion, the claim that KimWolf infected more than 1 million devices, issued over 25,000 attack commands, generated attacks approaching 30 Tbps, and was linked to attacks including one against Department of Defense IP space.
Eduard Kovacs 2026.05.22 99%
This article is the same underlying event: the arrest of Ottawa resident Jacob Butler ('Dort') as the alleged Kimwolf botnet operator, with added detail from the Justice Department on the extradition request, the specific aiding-and-abetting computer intrusion charge, and seizure warrants targeting services supporting 45 DDoS-for-hire platforms linked to the botnet.
Sergiu Gatlan 2026.05.22 99%
This article covers the same underlying event: the arrest and charging of Jacob Butler, allegedly known as "Dort," as the suspected KimWolf botnet administrator. It adds details from the unsealed U.S. complaint, the extradition posture, the specific aiding-and-abetting charge, losses to victims, and related seizures of 45 DDoS-for-hire platforms tied to the broader disruption effort.
BrianKrebs 2026.05.21 100%
This article establishes a distinct story because it is the first item here centered on the arrest and cross-border criminal charges against the alleged operator of the Kimwolf IoT botnet.
Full page
CISA opens public reporting channel for Known Exploited Vulnerabilities catalog nominations
Zero-Days & CVEsPolicy & RegulationGovernmentTechnology & SoftwareCISA
CISA has launched a new public form and email pathway for researchers, vendors, and industry partners to submit vulnerabilities for possible inclusion in its Known Exploited Vulnerabilities (KEV) catalog. The change affects no single CVE or product; instead it creates a formal process for reporting suspected exploited-in-the-wild flaws to CISA, with submitters asked to provide vulnerability details and evidence of active exploitation so the agency can validate and potentially add them to KEV.
Why it matters: The KEV catalog is one of the main lists defenders use to decide what to patch first, so a faster path for outside researchers to report exploitation could speed warnings and remediation across government and private networks. Security teams should expect KEV to remain a key prioritization source and monitor for any changes in how quickly new exploited bugs are added.
Sources
SecurityWeek News 2026.05.22 88%
The article notes CISA's new KEV nomination form as one of the week's items, which is the same policy/process update about opening a public channel for Known Exploited Vulnerabilities submissions.
2026.05.22 100%
This article establishes a distinct story about CISA changing the KEV intake process itself, rather than adding any specific vulnerability already tracked.
Full page
Huawei enterprise router zero-day caused a nationwide telecom blackout in Luxembourg
Zero-Days & CVEsInformation FreedomTelecommunicationsConsumers & General PublicHuaweiPOST Luxembourg
A zero-day flaw in Huawei enterprise router software was blamed for a July 2025 outage that knocked out landline, 4G, and 5G service across Luxembourg for more than three hours. POST Luxembourg said specially crafted network traffic forced the routers into a reboot loop, causing a denial-of-service condition and disrupting emergency communications for hundreds of thousands of residents. No CVE is provided, and it remains unclear whether Huawei has issued a patch.
Why it matters: This shows how a single unpatched network-device flaw can interrupt phone and mobile service for an entire country, including emergency calls. Organizations using Huawei enterprise routers should urgently seek vendor guidance, limit exposure, and prepare mitigations because patch status is still unclear.
Sources
SecurityWeek News 2026.05.22 100%
The article provides a concrete new event: a previously undisclosed Huawei router vulnerability linked to a real-world national telecom outage.
Full page
TrendAI patches exploited Apex One zero-day CVE-2026-34926 in on-premises servers
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareGovernmentTrend MicroCISA
TrendAI says attackers exploited a flaw in its Apex One security software before a patch was available, putting organizations that run the on-premises server at risk. The bug, CVE-2026-34926, is a directory traversal vulnerability in Apex One on-premise that can let an attacker alter a key server table and inject malicious code for deployment to agents; TrendAI says admin credentials to the server are required, and CISA has added the CVE to its Known Exploited Vulnerabilities catalog.
Why it matters: Organizations using Apex One on-premises should treat this as urgent because the flaw was exploited in real attacks and could let attackers push malicious code from the management server to protected endpoints. Apply TrendAI's update immediately and review who has administrative and remote access to the Apex One server.
Sources
Sergiu Gatlan 2026.05.22 98%
This article covers the same underlying event: Trend Micro's patch and warning for the actively exploited Apex One on-premises zero-day CVE-2026-34926. It adds concrete detail that the bug is a directory traversal issue allowing code injection to agents from the server, notes Trend observed at least one in-the-wild exploit attempt, and mentions CISA's KEV listing and June 4 federal patch deadline.
Eduard Kovacs 2026.05.22 100%
This article appears to be the first tracked item here for CVE-2026-34926, covering the vendor patch, in-the-wild exploitation, affected product scope, and CISA KEV inclusion.
Full page
Ubiquiti patches five UniFi OS flaws, including three maximum-severity bugs that can be exploited remotely
Urgent PatchesZero-Days & CVEsTechnology & SoftwareConsumers & General PublicUbiquiti
Ubiquiti released security updates for UniFi OS after disclosing five vulnerabilities that could let attackers tamper with devices, read files, or run commands. The issues include CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, all rated maximum severity, plus CVE-2026-33000 and CVE-2026-34911. They affect UniFi OS on UniFi Consoles that run UniFi Network, Protect, Access, Talk, and Connect; the flaws involve improper access control, path traversal, command injection, and information disclosure. Ubiquiti says the bugs can be exploited with low complexity and nearly 100,000 internet-exposed endpoints have been observed.
Why it matters: Organizations and home or small-business users running UniFi OS may be exposed to remote compromise if their management devices are reachable online. This is an update-now issue: apply Ubiquiti's patches promptly and reduce internet exposure of UniFi management interfaces where possible.
Sources
Sergiu Gatlan 2026.05.22 100%
This article appears to be the first clear report of Ubiquiti's May 2026 UniFi OS patch release covering CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-33000, and CVE-2026-34911, which is distinct from the previously tracked March 2026 UniFi Network Application flaws.
Full page
Grafana GitHub breach traced to missed token rotation after TanStack npm supply-chain attack
Threat Actors & APTsSupply ChainBreaches & Data LeaksTechnology & SoftwareGrafanaGitHubTanStack
Grafana says attackers gained access to its private GitHub repositories after a GitHub workflow token was missed during rotation following the TanStack npm supply-chain attack. The malicious TanStack package executed in Grafana's CI/CD environment, exfiltrated workflow tokens, and led to theft of source code plus some operational business contact information. Grafana says no customer production systems or cloud data were affected.
Why it matters: This matters to defenders because it shows how downstream victims of an npm supply-chain compromise can remain exposed if token rotation is incomplete. Organizations using GitHub Actions and affected TanStack packages should review CI/CD secrets, token scope, and repository access logs.
Sources
Ionut Arghire 2026.05.22 99%
This article is a direct update on the same Grafana incident, adding that Grafana attributes the intrusion to the TanStack/Mini Shai-Hulud supply-chain attack, says attackers downloaded public and private source code plus internal operational and business-contact data, and notes the attackers sent a ransom demand that Grafana refused to pay.
Sergiu Gatlan 2026.05.21 74%
The article connects GitHub’s breach to the same underlying TanStack npm supply-chain campaign that also affected Grafana, providing additional context on the broader attack chain, Nx Console compromise, and TeamPCP-linked activity.
Bill Toulas 2026.05.20 100%
The article provides substantive new facts about the Grafana breach itself, specifically tying the intrusion to the TanStack package compromise and a missed GitHub token rotation, and it does not match any listed existing tracked story.
2026.05.18 73%
This is the same underlying TanStack/Shai-Hulud supply-chain event referenced in the Grafana story, and adds specific root-cause and mitigation details from TanStack: abuse of pull_request_target, GitHub Actions cache poisoning, removal of that workflow pattern, cache disabling, SHA pinning, stronger 2FA, and discussion of invitation-only PRs.
Full page
House Democrats warn Trump budget cuts would reduce CISA and state-local cybersecurity funding
Policy & RegulationGovernmentCISADepartment of Homeland SecurityMulti-State Information Sharing and Analysis Center
U.S. House Democrats said the Trump administration is pushing major cuts to federal cybersecurity spending that would hit state and local governments. At a Homeland Security subcommittee hearing, lawmakers and state officials pointed to a proposed $707 million cut to the Cybersecurity and Infrastructure Security Agency (CISA), earlier cuts of about $135 million and roughly 1,000 staff, uncertainty around reauthorizing the State and Local Cybersecurity Grant Program, and the loss of federally supported Multi-State Information Sharing and Analysis Center services.
Why it matters: This matters because local governments run emergency services, schools, utilities, and courts, and many rely on federal cyber grants and shared defenses they cannot afford on their own. The practical implication is policy-focused rather than immediate patching: public-sector defenders and watchdogs should track the budget fight closely because fewer staff, grants, and shared services can increase exposure to ransomware and other attacks.
Sources
2026.05.21 100%
This article establishes a distinct policy story centered on proposed U.S. federal cybersecurity funding cuts and their impact on CISA and state/local cyber defense capacity, rather than a specific breach, CVE, or previously tracked legislative fight.
Full page
German hospitals disclose patient-data breach after attack on billing provider Unimed
Breaches & Data LeaksSurveillance & PrivacyHealthcareInsuranceUnimedUniversity Hospital CologneUniversity Hospital FreiburgHeidelberg University HospitalUniversity Hospital TübingenUlm University Hospital
Several German university hospitals say hackers stole patient and billing data after breaching Unimed, an external provider used to process invoices for privately insured and self-paying patients. Disclosures from Cologne, Freiburg, Heidelberg, Tübingen, Ulm and Mannheim say the intrusion occurred in mid-April and exposed names, addresses, physician details, and in some cases diagnosis, treatment, communications, and limited bank or payment data. Hospitals said their own clinical systems were not breached and patient care was not disrupted.
Why it matters: This affects highly sensitive medical data, including some diagnosis and treatment information, so impacted patients may face privacy harms, impersonation attempts, or fraud. Affected hospitals have stopped sending data to Unimed; patients should watch for breach notices and be cautious of unsolicited calls, emails, or billing messages referencing their care.
Sources
2026.05.21 100%
This article establishes a distinct new breach event centered on Unimed's compromise and the resulting exposure of patient and billing records across multiple German hospitals.
Full page
Researchers say deleted Google API keys can remain usable for up to 23 minutes, enabling Gemini data access and billing abuse
Surveillance & PrivacyTechnology & SoftwareGoogle
Security researchers found that Google API keys may keep working for up to 23 minutes after a user deletes them, leaving developers and organizations exposed during what they believe is a safe shutdown period. Aikido says revocation propagates unevenly across Google's infrastructure, allowing repeated authenticated requests to still succeed against some backend servers; if Gemini is enabled, attackers could access uploaded files and cached conversation context, and abuse automatic billing tier increases to run up large charges.
Why it matters: Anyone using Google APIs, especially Gemini, could still be exposed after deleting a leaked key. Treat key deletion alone as insufficient: rotate credentials quickly, restrict key permissions, watch for ongoing usage and billing spikes, and disable affected projects or services if abuse is underway.
Sources
2026.05.21 100%
This article establishes a distinct security story about delayed revocation of Google API keys and its concrete impact on unauthorized access and financial abuse, rather than updating an existing tracked event.
Full page
Ofcom says Snapchat, Meta and Roblox will change UK child-safety features, while TikTok and YouTube resist new commitments
Surveillance & PrivacyPolicy & RegulationSocial Engineering & PhishingGovernmentTechnology & SoftwareMedia & EntertainmentConsumers & General PublicOfcomSnapMetaRobloxTikTokYouTube
Britain’s online-safety regulator said several major platforms have promised product changes aimed at better protecting children in the UK. Ofcom said Snap will adopt its recommended anti-grooming measures, including tighter limits on adult contact with children; Roblox will let parents disable direct messages for under-16s; and Meta will hide teens’ connection lists by default on Instagram and use artificial intelligence to detect likely sexualized adult-teen direct messages. Ofcom said TikTok and YouTube did not commit to significant new changes.
Why it matters: This matters to UK families, teens and platform operators because it signals concrete safety and privacy changes tied to regulatory pressure, especially around grooming risks and minors’ visibility online. Users and parents should watch for new default settings and controls, while companies should expect closer enforcement under the UK’s online-safety regime.
Sources
2026.05.21 100%
This article establishes a distinct story about Ofcom extracting specific child-safety and anti-grooming platform commitments from major tech companies, with named product changes and a clear enforcement hook.
Full page
Google accidentally exposed details of an unfixed Chromium flaw that can keep malicious code running after the browser is closed
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareConsumers & General PublicGoogleMicrosoftBraveOperaVivaldiThe Browser Company
Google briefly made public the technical details of an unfixed Chromium security flaw that affects Chrome and other Chromium-based browsers including Edge, Brave, Opera, Vivaldi, and Arc. Researcher Lyra Rebane says a malicious website can abuse a Service Worker to keep JavaScript running after the browser is closed, potentially enabling stealthy botnet-style abuse such as proxying traffic or launching distributed denial-of-service attacks; no CVE is listed in the report, and the bug was reportedly marked fixed in tracking systems even though current dev builds still appeared vulnerable.
Why it matters: This matters because simply visiting a malicious site once may be enough to leave a browser doing work in the background without the user's knowledge. Users and defenders should watch for an emergency browser update from Google and other Chromium-based vendors and apply it quickly once available.
Sources
Bill Toulas 2026.05.21 100%
This article establishes a new story because it centers on a distinct Chromium flaw whose accidental public exposure increased near-term exploitation risk before a real fix was shipped.
Full page
Two Americans plead guilty to helping India-based tech-support scam call centers target U.S. victims
Scams & FraudSocial Engineering & PhishingTelecommunicationsConsumers & General Public
Two U.S. men pleaded guilty to helping India-based tech-support scam centers steal millions from Americans, including elderly and disabled victims. Prosecutors said they provided phone numbers, call routing, tracking, and forwarding services for fake malware pop-up scams from 2016 to 2022, continued after learning customers were fraudulent, and advised scammers to rotate large pools of numbers to evade detection; some victims also gave remote access to their devices, leading to financial theft.
Why it matters: This shows how large tech-support scam operations rely on telecom and call-routing support inside the U.S., not just overseas call centers. People should be wary of pop-ups telling them to call for urgent computer help, and providers and defenders can use the case details to spot number rotation and call-forwarding tactics tied to fraud.
Sources
2026.05.21 100%
This article establishes a distinct enforcement-focused story around guilty pleas tied to the infrastructure that enabled an India-based tech-support scam network, rather than updating any listed breach, malware, or policy story.
Full page
Access Now backs WhatsApp in Ninth Circuit appeal over NSO Pegasus spyware injunction
Surveillance & PrivacyPolicy & RegulationTechnology & SoftwareTelecommunicationsNonprofits & NGOsConsumers & General PublicWhatsAppMetaNSO GroupAccess Now
Access Now and other civil society groups asked the Ninth Circuit to keep a court order blocking NSO Group from using WhatsApp to target users with Pegasus spyware. The filing concerns NSO’s appeal after WhatsApp and Meta won a permanent injunction and jury verdict in a case over Pegasus being delivered through WhatsApp’s servers to more than 1,400 people in 20 countries, including journalists, activists, and human rights defenders.
Why it matters: This matters because the appeal could shape how strongly U.S. courts can curb commercial spyware used against encrypted messaging users. It is especially relevant to people at risk of surveillance and to companies defending messaging platforms from spyware abuse.
Sources
Natalia Krapiva, Esq. 2026.05.21 100%
This article establishes a distinct legal and surveillance story about NSO’s active appeal of the WhatsApp/Pegasus injunction, with a new amicus filing urging the Ninth Circuit to preserve protections for encrypted communications.
Full page
Researchers report macOS kernel memory-corruption exploit affecting Apple M5 systems
Zero-Days & CVEsTechnology & SoftwareConsumers & General PublicAppleAnthropic
A newly reported exploit targets a memory-corruption flaw in the macOS kernel on Apple M5 hardware. The source says a group used Anthropic's Mythos AI model to help find the vulnerability and develop an exploit; the brief post does not provide a CVE, affected macOS versions, or details on whether the flaw is patched or exploited in the wild.
Why it matters: A kernel exploit can potentially give attackers deep control over a device, so this is important for Mac users and enterprise defenders even though technical details are still limited. Track for Apple advisories and be ready to apply patches quickly once the vulnerability is formally identified.
Sources
Bruce Schneier 2026.05.21 100%
This article establishes a distinct new vulnerability story: a separately reported macOS kernel memory-corruption exploit on Apple M5, not one of the existing tracked events.
Full page
UK Computer Misuse Act reform proposal would give only narrow legal protection to a small fraction of security researchers
Policy & RegulationGovernmentTechnology & SoftwareLegal & Professional ServicesUK governmentUK Cyber Security Council
The UK government’s planned cybercrime-law reform would protect very few security researchers from prosecution, according to sources briefed on the proposal. The reported changes to the Computer Misuse Act 1990 would create a statutory defense mainly for scanning internet-facing systems, require researchers to stop once they identify a flaw, and limit eligibility to British nationals with UK Cyber Security Council accreditation—reportedly only about 300 people.
Why it matters: This could leave most bug hunters, academics, and security teams exposed to legal risk for good-faith testing, which may discourage vulnerability discovery and responsible disclosure. Organizations and researchers in the UK should watch the legislation closely because it could shape what defensive testing is legally safe to perform.
Sources
2026.05.21 100%
This article appears to be the first concrete reporting on the scope and limits of the UK’s planned Computer Misuse Act reform, adding specific details about who would and would not be protected.
Full page
China-linked Calypso hackers target telecom providers with Showboat Linux malware and JFMBackdoor for Windows
Threat Actors & APTsMalwareTelecommunications
A China-linked hacking group has been targeting telecommunications providers in Asia Pacific and parts of the Middle East with new malware for both Linux and Windows systems. Researchers at Lumen Black Lotus Labs and PwC attributed the campaign to Calypso, also called Red Lamassu, and say it has been active since at least mid-2022. The Linux implant, Showboat, is a modular post-compromise framework used for persistence, file transfer, and SOCKS5 proxying to move through victim networks, while the Windows implant, JFMBackdoor, uses DLL sideloading and supports remote commands, file operations, registry changes, screenshots, and anti-forensics.
Why it matters: Telecom providers are high-value targets because they sit in the middle of sensitive communications and critical infrastructure. Organizations in the sector should hunt for these malware families and related telecom-themed impersonation domains, review persistence mechanisms and proxy activity, and check Linux and Windows systems for signs of long-term intrusion.
Sources
Bill Toulas 2026.05.21 100%
This article appears to be the first tracked item establishing this specific Calypso/Red Lamassu telecom espionage campaign and the newly reported Showboat and JFMBackdoor malware families.
Full page
Cisco patches critical Cisco Secure Workload API flaw CVE-2026-20223 enabling Site Admin access
Urgent PatchesZero-Days & CVEsTechnology & SoftwareCisco
Cisco released fixes for CVE-2026-20223, a critical 10.0 vulnerability in Cisco Secure Workload Cluster Software caused by insufficient validation and authentication in internal REST API endpoints. The flaw affects SaaS and on-prem deployments and can let remote attackers read sensitive information and modify configurations across tenant boundaries with Site Admin privileges. Patched versions are 3.10.8.3 and 4.0.3.17.
Why it matters: Organizations using Cisco Secure Workload face high-impact administrative compromise and cross-tenant exposure if unpatched. Defenders should prioritize updates because exploitation requires only a crafted API request and no in-the-wild activity is needed for urgency at this severity.
Sources
Sergiu Gatlan 2026.05.21 98%
This article covers the same Cisco Secure Workload event: disclosure and patching of CVE-2026-20223, an unauthenticated flaw in internal REST APIs that can grant Site Admin privileges across tenant boundaries. It adds affected/fixed versions, notes there are no workarounds, and says Cisco has not seen in-the-wild exploitation.
Ionut Arghire 2026.05.21 100%
This article establishes a distinct new story centered on Cisco's disclosure and patching of CVE-2026-20223 in Secure Workload; it does not match any existing tracked event.
2026.05.21 99%
This article covers the same Cisco Secure Workload vulnerability disclosure and patch event for CVE-2026-20223, adding reporting detail on cross-tenant impact, affected fixed versions (3.10.8.3 and 4.0.3.17), lack of workarounds, and that Cisco SaaS deployments were already patched.
Full page
Myspace93 2021 breach exposed plaintext passwords of more than 46,000 users
Breaches & Data LeaksTechnology & SoftwareMedia & EntertainmentConsumers & General PublicMyspace93Have I Been Pwned
The Register reports that data from a January 2021 breach of the Myspace93 parody social-network site has now been ingested by Have I Been Pwned, with more than 46,000 accounts affected. Exposed data included plaintext usernames and passwords, email addresses, and IP addresses. The site's co-creator said trusted community members abused access to a beta app to download server files and an unencrypted credential store.
Why it matters: Affected users face credential-stuffing and account-takeover risk anywhere they reused passwords, especially because the passwords were stored in plaintext. The story also highlights severe password-handling failures and a delayed public accounting of the breach.
Sources
2026.05.21 100%
This article establishes a distinct breach story centered on the 2021 compromise of Myspace93 and the newly surfaced scope and sensitivity of the leaked user data.
Full page
Dormant former employee account enabled intrusion into U.S. city network and water utility controls
Breaches & Data LeaksGovernmentEnergy & Utilities
The Register reports that attackers compromised an American city's network by using a long-active account belonging to a former employee, "Greg from Auditing," whose privileges reportedly included domain admin, SCADA operator, and help desk access. The intruders moved through municipal systems, manipulated conference-room devices, and changed water utility settings by turning multiple controls off.
Why it matters: This is a real-world critical-infrastructure compromise caused by basic identity and access management failures, with potential public-safety impact. Municipal and ICS operators should review dormant accounts, privilege assignments, and password reuse risks immediately.
Sources
2026.05.21 100%
This article is the first item here establishing the specific incident: a city-network intrusion and water-system control access enabled by an undeleted ex-employee account.
Full page
GitHub confirms breach of roughly 3,800 internal repositories via malicious VS Code extension
Supply ChainBreaches & Data LeaksThreat Actors & APTsTechnology & SoftwareGitHubMicrosoft
GitHub confirmed that an employee device was compromised after installing a trojanized VS Code extension, leading to exfiltration of roughly 3,800 internal repositories. The company says it removed the malicious extension from the VS Code Marketplace, isolated the endpoint, and found no evidence that customer data stored outside the affected repos was impacted. TeamPCP claimed responsibility and advertised the stolen code for sale.
Why it matters: This is a significant source-code breach at a core software development platform, with potential downstream supply-chain and trust implications. GitHub users and defenders should watch for follow-on disclosures about exposed secrets, internal tooling, or abuse tied to the stolen repositories.
Sources
Sergiu Gatlan 2026.05.21 98%
This directly updates the same GitHub breach, adding that the malicious extension was Nx Console 18.95.0 and that GitHub links the compromise path to last week’s TanStack npm supply-chain attack; it also adds details on secret rotation and TeamPCP’s claims.
info@thehackernews.com (The Hacker News) 2026.05.21 98%
The article appears to describe the same underlying GitHub intrusion and adds the specific lure/extension name, identifying the malicious VS Code extension as Nx Console.
info@thehackernews.com (The Hacker News) 2026.05.20 99%
The article appears to cover the same GitHub breach event: an employee device compromise tied to a trojanized VS Code extension that led to exfiltration of about 3,800 internal repositories.
2026.05.20 98%
This article covers the same underlying GitHub breach event, reiterating that a poisoned VS Code extension led to exfiltration of about 3,800 internal repositories and adding GitHub's public statements about ongoing log analysis, secret rotation validation, and no current indication of customer data exposure.
Ionut Arghire 2026.05.20 99%
This article is the same underlying event: GitHub confirms that a poisoned VS Code extension on an employee device led to exfiltration affecting about 3,800 internal repositories, adding details on TeamPCP's claim, attempted sale of stolen data, and GitHub's secret-rotation response.
Sergiu Gatlan 2026.05.20 100%
This article establishes GitHub's confirmation of the repo breach, the initial scope of ~3,800 internal repositories, and the reported intrusion vector of a malicious VS Code extension.
Sergiu Gatlan 2026.05.20 94%
This article is the initial report on the same GitHub internal-repository breach later confirmed by GitHub; its update notes the confirmation and adds TeamPCP's public sale claims and early GitHub statements that customer data outside internal repositories was not yet known to be affected.
Full page
China and Russia pledge expanded cooperation on cybersecurity, internet governance, AI and satellite internet
Policy & RegulationInformation FreedomCensorshipSurveillance & PrivacyGovernmentDefense & AerospaceTechnology & SoftwareTelecommunicationsChinaRussiaBeiDouGLONASS
At a Beijing summit, Xi Jinping and Vladimir Putin issued a joint statement promising deeper cooperation on information security, cyber-threat response, internet regulation, AI, satellite internet, IoT, and interoperability between China's BeiDou and Russia's GLONASS systems. The statement also emphasized joint software and open-source development to reduce dependence on Western technology and endorsed stronger state control over domestic internet environments.
Why it matters: The agreement signals closer alignment between two major authoritarian states on cyber policy, digital infrastructure and 'internet sovereignty,' with implications for censorship, surveillance, and state-backed cyber operations. It matters to policymakers, civil-society groups and defenders tracking how geopolitical blocs may reshape internet governance and security ecosystems.
Sources
2026.05.20 100%
This article establishes a distinct state-level cyber policy development: a new formal Sino-Russian pledge to coordinate on cybersecurity, internet governance, AI and satellite systems.
Full page
Ukraine identifies infostealer operator linked to theft of 28,000 online store accounts
Breaches & Data LeaksThreat Actors & APTsMalwareRetail & E-CommerceConsumers & General PublicGovernmentCryptocurrency & BlockchainUkrainian Cyberpolice
Ukrainian cyberpolice, working with U.S. law enforcement, identified an 18-year-old suspect from Odesa as a central operator in an infostealer campaign that stole browser sessions and credentials from users of a California online store between 2024 and 2025. Authorities say 28,000 accounts were compromised, 5,800 were used for unauthorized purchases totaling about $721,000, and devices and crypto-related evidence were seized in searches.
Why it matters: The case highlights ongoing risk from infostealers and stolen session tokens, which can enable account takeover and sometimes bypass MFA. Online retailers, fraud teams, and users should treat session theft as a significant threat and review account security, monitoring, and token invalidation practices.
Sources
Bill Toulas 2026.05.20 100%
This article establishes a distinct law-enforcement and threat-activity story centered on a specific infostealer operation, identified suspect, and quantified impact on victim accounts.
2026.05.20 99%
This is the same underlying law-enforcement case: Ukrainian authorities identifying an 18-year-old Odesa suspect tied to an infostealer operation that stole about 28,000-30,000 online store accounts and used thousands of them for fraudulent purchases. The article adds that the targeted retailer was based in California, cites 5,800 abused accounts, $721,000 in unauthorized purchases, and notes Telegram-based resale plus seized evidence.
Full page
Attackers exploit SonicWall Gen6 SSL-VPN MFA bypass CVE-2024-12802 after incomplete remediation
Zero-Days & CVEsUrgent PatchesRansomwareThreat Actors & APTsSonicWall
ReliaQuest and SonicWall say attackers exploited CVE-2024-12802 on SonicWall Gen6 SSL-VPN appliances to bypass MFA when admins installed patched firmware but did not complete required LDAP reconfiguration steps. Intrusions observed from February to March involved brute-forced credentials, internal reconnaissance, RDP access, and attempted deployment of Cobalt Strike and a BYOVD tool across multiple sectors and geographies.
Why it matters: Organizations using SonicWall Gen6 SSL-VPN may still be exposed even if they believe they are patched, because firmware updates alone do not fully mitigate the flaw. Defenders should verify the manual remediation, hunt for listed indicators, and treat exposed Gen6 devices as potentially compromised.
Sources
Bill Toulas 2026.05.20 100%
This article establishes a distinct tracked story by tying CVE-2024-12802 to first reported in-the-wild exploitation, clarifying that incomplete patching left Gen6 SonicWall VPNs vulnerable and enabled follow-on intrusion activity.
Full page
FTC warns major tech platforms over Take It Down Act compliance failures
Surveillance & PrivacyPolicy & RegulationTechnology & SoftwareMedia & EntertainmentConsumers & General PublicGovernmentFTCAlphabetAmazonAppleMetaMicrosoft
The FTC said it sent warning letters to major tech firms including Alphabet, Amazon, Apple, Discord, Meta, Microsoft, Reddit, Snapchat, TikTok and X, alleging they are not complying with the Take It Down Act. The law requires covered platforms to provide a removal process for nonconsensual intimate images and delete reported content within 48 hours, with potential fines for violations.
Why it matters: The action puts large platforms on notice that U.S. regulators are actively enforcing rapid takedown requirements for abusive intimate imagery. Security, trust-and-safety, and privacy teams may need to implement reporting workflows, hashing, and cross-platform sharing processes to avoid penalties and better protect victims.
Sources
2026.05.20 100%
This article establishes a distinct enforcement event: the FTC's first public warning to major platforms over alleged noncompliance with the Take It Down Act.
Full page
Discord enables end-to-end encryption by default for voice and video messages
Surveillance & PrivacyTechnology & SoftwareConsumers & General PublicDiscord
Discord announced that end-to-end encryption for voice and video communications is now enabled by default for all users across supported platforms, with stage channels excluded. The company said it spent nearly three years building the system after beginning experiments in 2023 and rolling out an audited protocol for audio and video in 2024.
Why it matters: The change improves confidentiality for hundreds of millions of users and is notable as a major platform expanding, rather than retreating from, default encrypted communications. It matters to users, privacy advocates, and policymakers tracking the availability of strong encryption on mainstream services.
Sources
2026.05.20 100%
This article establishes a new story about Discord's platform-wide rollout of default end-to-end encryption for voice and video communications.
Full page
FBI reports $388 million in 2025 losses tied to cryptocurrency ATM scams in the U.S.
Policy & RegulationSurveillance & PrivacyCryptocurrency & BlockchainConsumers & General PublicGovernmentFBIIC3
The FBI said IC3 received more than 13,400 complaints in 2025 involving cryptocurrency kiosks, with reported losses exceeding $388 million, up 58% from 2024. Texas led reported losses at nearly $57 million, followed by Florida at $32.7 million. The report ties the kiosks to fraud schemes including investment, tech-support, and romance scams, and comes amid state bans and lawsuits against kiosk operators.
Why it matters: The figures show large-scale consumer harm through a payment channel increasingly used in fraud, especially against older victims. The story matters for defenders, fraud investigators, and policymakers because it points to a growing abuse ecosystem and potential regulatory or enforcement action.
Sources
2026.05.20 100%
This article establishes a distinct story centered on the FBI's 2025 IC3 cryptocurrency ATM scam-loss data and the resulting enforcement and legislative response, not an update to any tracked breach, CVE, or existing policy story.
Full page
PoC exploit released for PinTheft Arch Linux local root escalation flaw in Linux RDS
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareConsumers & General PublicArch LinuxLinux
Researchers disclosed a public proof-of-concept for PinTheft, a recently patched Linux local privilege-escalation flaw in the kernel's RDS zerocopy send path that can yield root on Arch Linux systems. The bug has not yet received a CVE ID. Exploitation requires the RDS module to be loaded, io_uring enabled, and other specific conditions; Arch is reportedly the only common distro tested with RDS enabled by default.
Why it matters: Public exploit code raises the risk of real-world abuse on exposed systems, especially where patching lags. Defenders should prioritize kernel updates or disable/unload the RDS modules as a mitigation.
Sources
Sergiu Gatlan 2026.05.20 100%
This article establishes a distinct story about the PinTheft Linux kernel privilege-escalation flaw and the release of exploit code, not the same underlying event as the tracked Drupal, SonicWall, Grafana, CISA GitHub, or Ukraine infostealer stories.
Full page
Meta geo-blocks human rights and researcher accounts in Saudi Arabia and the UAE after government requests
Information FreedomCensorshipTechnology & SoftwareNonprofits & NGOsGovernmentConsumers & General PublicMetaFacebookInstagramSaudi Arabian governmentUAE government
Access Now and other groups say Meta has made Facebook and Instagram accounts of NGOs, researchers, and civil-society figures unavailable in Saudi Arabia and the UAE since late April 2026. Meta's transparency reporting indicates more than 100 Facebook pages and Instagram accounts were restricted since March 2026, citing local legal requirements and cybercrime laws in both countries.
Why it matters: This affects access to information and the safety and reach of human-rights advocacy in highly restrictive states. It is relevant to censorship tracking because a major platform is enforcing government takedown and geo-blocking demands against lawful speech.
Sources
Wajd 2026.05.20 100%
This article establishes a distinct event involving Meta's compliance with Saudi and UAE geo-blocking requests against specific human-rights and research accounts; it does not match an existing tracked story.
Alexia Skok 2026.05.20 91%
This directly updates the same underlying event by adding broader context around the Gulf crackdown after strikes on Iran, and specifies that since March 2026 more than 100 Facebook and Instagram accounts/pages were reportedly restricted alongside X account blocking and arrests for filming or sharing attack footage.
Full page
FOI reveals London Metropolitan Police made more than 700,000 communications-data requests in 2025
Surveillance & PrivacyPolicy & RegulationGovernmentTechnology & SoftwareTelecommunicationsConsumers & General PublicMetropolitan PoliceLycaMobileProton MailProtonVPNSignal
The Register reports that London’s Metropolitan Police made more than 700,000 requests for communications data from tech companies in 2025, according to FOI disclosures. The figures include requests involving platforms such as LycaMobile and claims of data acquisition from privacy-focused services including Proton Mail, ProtonVPN, and Signal, though Proton and Signal disputed parts of the police account.
Why it matters: The disclosures highlight the scale of police metadata surveillance and raise transparency and oversight questions around access to communications data from mainstream and privacy-oriented services. It matters to UK users, privacy defenders, and policymakers assessing lawful access powers and safeguards for sensitive professions such as journalists and lawyers.
Sources
2026.05.20 100%
This article establishes a distinct surveillance-policy story centered on FOI-revealed Metropolitan Police access requests and disputes over what privacy services can or did provide.
Full page
ChromaDB CVE-2026-45829 exposes internet-facing Python API servers to unauthenticated RCE
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareChroma
Researchers disclosed CVE-2026-45829, a maximum-severity flaw in ChromaDB's Python FastAPI server that can let unauthenticated attackers force the server to fetch and execute a malicious Hugging Face model. The bug affects the Python API code introduced in ChromaDB 1.0.0 and was reportedly still present in 1.5.8; it was unclear at publication whether 1.5.9 fixed it. HiddenLayer said about 73% of internet-exposed instances were running vulnerable versions.
Why it matters: Organizations exposing ChromaDB's Python API over HTTP could face full server compromise without authentication. Defenders should immediately restrict exposure, prefer the Rust frontend where possible, and verify whether deployed versions are patched.
Sources
Bill Toulas 2026.05.19 100%
This article appears to be the initial tracked report for CVE-2026-45829 in ChromaDB and does not match any existing story in the list.
Full page
Microsoft disrupts Fox Tempest code-signing service used by ransomware and malware operators
MalwareRansomwareThreat Actors & APTsTechnology & SoftwareMicrosoft
Microsoft said it seized domains and hundreds of VMs tied to Fox Tempest, a criminal service that abused Microsoft Artifact Signing using more than 580 fraudulent accounts created with fake identities. The operation allegedly sold code-signing certificates used to sign malware including Oyster, Lumma, Vidar, and Rhysida, and was linked to ransomware actors including Vanilla Tempest as well as INC, Qilin, and Akira affiliates.
Why it matters: Trusted code-signing helps malware bypass user suspicion and some security controls, so this service likely enabled broader, more effective intrusions. Defenders should review detections and hunting for suspicious signed binaries and malware families named by Microsoft.
Sources
2026.05.19 100%
This article establishes a distinct story about Microsoft's takedown of Fox Tempest and the abuse of Artifact Signing to provide code-signing-as-a-service to ransomware and malware operators.
Full page
CISA warns ScadaBR 1.2.0 flaws can enable unauthenticated remote code execution in ICS environments
Zero-Days & CVEsUrgent PatchesEnergy & UtilitiesManufacturingTransportation & LogisticsCISAScadaBR
CISA published ICS advisory ICSA-26-139-03 for ScadaBR 1.2.0, detailing CVE-2026-8602, CVE-2026-8603, CVE-2026-8604, and CVE-2026-8605. The flaws include missing authentication, OS command injection, CSRF, and hard-coded credentials, and could allow unauthenticated attackers to inject sensor readings, gain admin access, or execute commands on the SCADA system. CISA said ScadaBR had not responded to mitigation requests.
Why it matters: ScadaBR is used in critical infrastructure sectors including energy, water, chemical, dams, and manufacturing, so these bugs present serious operational risk. Defenders should urgently identify exposed ScadaBR 1.2.0 systems and apply mitigations or isolate them, especially given the lack of a vendor response noted by CISA.
Sources
CISA 2026.05.19 100%
This article establishes a distinct new vulnerability story: a newly published CISA ICS advisory covering four specific ScadaBR CVEs with critical impact on industrial control systems.
Full page
SentinelOne details Reaper macOS stealer variant that steals credentials and crypto wallets and installs a persistent backdoor
MalwareThreat Actors & APTsTechnology & SoftwareCryptocurrency & BlockchainConsumers & General PublicAppleWeChatMiroTelegram
SentinelOne documented Reaper, an updated SHub macOS infostealer delivered via fake WeChat and Miro installer sites spoofing trusted brands and abusing Script Editor instead of Terminal. The malware steals passwords, browser and Keychain data, Telegram sessions, and cryptocurrency wallet data, injects some wallet apps for continued theft, and installs a LaunchAgent-backed backdoor that beacons to C2 and can execute attacker-supplied code.
Why it matters: macOS users are being targeted with a more evasive stealer that bypasses recent Apple defenses against Terminal-based social engineering. Defenders should block the typosquatted infrastructure, hunt for the fake GoogleUpdate persistence path and LaunchAgent, and warn users about malicious installer lures.
Sources
2026.05.18 100%
This article appears to be the initial reporting on the newly documented Reaper/SHub macOS campaign and its updated tradecraft, rather than an update to an existing tracked event.
Full page
Linux kernel CVE-2026-46333 lets local unprivileged users read root-only files
Zero-Days & CVEsUrgent PatchesTechnology & SoftwareConsumers & General PublicLinux
CVE-2026-46333 is a Linux kernel local information-disclosure flaw that can let unprivileged users read files normally restricted to root, including SSH keys and other sensitive credentials. The issue affects multiple LTS kernel lines from 5.10 upward, and a fix has landed upstream in commit 31e62c2 adjusting ptrace get_dumpable logic.
Why it matters: Multi-user Linux systems and servers running affected kernels may allow low-privilege users to access highly sensitive secrets and escalate further compromise. Defenders should identify affected kernel versions and apply the upstream fix or vendor updates promptly.
Sources
2026.05.18 100%
This article establishes a distinct vulnerability story centered on CVE-2026-46333, its impact across Linux LTS kernels, and the availability of a fix.
Full page
DOJ subpoenas Wall Street Journal and other outlets for journalist records in Iran war leak investigation
Information FreedomSurveillance & PrivacyPolicy & RegulationGovernmentMedia & EntertainmentDOJThe Wall Street Journal
The Department of Justice sent grand jury subpoenas to The Wall Street Journal seeking records related to its journalists' reporting on the lead-up to the war in Iran, and other media outlets reportedly received similar demands. The move is framed by press-freedom advocates as an effort to identify confidential sources through leak investigations.
Why it matters: This has direct implications for source protection, newsroom security, and government surveillance of journalists. News organizations and reporters may need to harden communications and prepare for legal demands targeting records and metadata.
Sources
Freedom of the Press Foundation 2026.05.15 100%
The article identifies a specific new government action—DOJ subpoenas to news outlets for journalist records in a leak probe—rather than commentary on a previously tracked event.
Full page
Google Project Zero publishes Pixel 10 zero-click exploit chain combining Dolby bug CVE-2025-54957 with VPU kernel flaw
Zero-Days & CVEsTechnology & SoftwareConsumers & General PublicMedia & EntertainmentGoogleDolby
Google Project Zero disclosed a zero-click exploit chain for Pixel 10 that adapts the Dolby decoder vulnerability CVE-2025-54957 and chains it with a local privilege-escalation flaw in the Pixel 10 VPU driver. The writeup says unpatched devices with December 2025 security patch level or earlier are vulnerable, and the VPU mmap bug can expose physical memory and enable kernel code execution.
Why it matters: A published zero-click-to-root chain is high-impact because it lowers the bar for attackers and confirms severe exposure on unpatched Pixel 10 devices. Affected users and enterprise defenders should verify Android security patch levels and prioritize remediation.
Sources
Seth Jenkins 2026.05.13 100%
This article establishes the story by newly documenting the specific Pixel 10 exploit chain, the reused CVE-2025-54957 entry point, and a distinct VPU kernel flaw used for privilege escalation.
Full page
No stories match your search.