no alarms and no surprises please..
-
Scope of Salesforce Attacks Expands as Icarus Leaks Data
Scope of Salesforce Attacks Expands as Icarus Leaks Data More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers’ Salesforce data. Rob Wright Go to gbhackers.com
-
‘Cordyceps’: Mushrooming Malicious Pull Requests Threaten Developer Workflows
‘Cordyceps’: Mushrooming Malicious Pull Requests Threaten Developer Workflows The CI/CD workflow weakness affects Microsoft’s Azure Sentinel, Google’s AI Agent Development Kit, Apache’s Doris analytics database, Cloudflare’s Workers SDK, and Python Software Foundation’s Black. Alexander Culafi Go to gbhackers.com
-
SocGholish Takedown Highlights Malicious TDS Threats
SocGholish Takedown Highlights Malicious TDS Threats SocGholish uses traffic distribution systems (TDSs) to provide initial access into victims’ networks for cybercrime groups such as the notorious Evil Corp. Rob Wright Go to gbhackers.com
-
FortiBleed Attackers Turn Firewalls Into Credentials Stealers as Heist Persists
FortiBleed Attackers Turn Firewalls Into Credentials Stealers as Heist Persists The threat actors engineered a Golang-based sniffer to target 430,000 FortiGate firewalls and identify 110 million credentials in the ongoing global campaign. Elizabeth Montalbano Go to gbhackers.com
-
DifyTap Bugs Let Attackers ‘Wiretap’ AI Chat Histories
DifyTap Bugs Let Attackers ‘Wiretap’ AI Chat Histories Four vulnerabilities allow attackers to exploit Dify, a platform for AI application building and management, to silently access and exfiltrate sensitive data. Alexander Culafi Go to gbhackers.com
-
Tata Electronics Data Breach Exposes 200,000+ Files Linked to Apple and Tesla, Hackers Claim
Tata Electronics Data Breach Exposes 200,000+ Files Linked to Apple and Tesla, Hackers Claim Tata Electronics has reported a cybersecurity incident following claims from a ransomware-linked threat group that it has exfiltrated and published over 200,000 files related… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Uncovers Parallel Threat Activity From Two Cyberattackers in Single Intrusion
Microsoft Uncovers Parallel Threat Activity From Two Cyberattackers in Single Intrusion Microsoft’s latest incident write-up shows that a single intrusion can mask two parallel threat activity streams, one tied to Storm-2603 and another to an… Delivered by PolitePaul service Go to gbhackers.com
-
Critical libssh2 Vulnerability Lets Remote Attackers Execute Code via Crafted SSH Packets
Critical libssh2 Vulnerability Lets Remote Attackers Execute Code via Crafted SSH Packets A critical security vulnerability has been identified in libssh2, a widely used client-side SSH library. This flaw allows remote attackers to execute code by… Delivered by PolitePaul service Go to gbhackers.com
-
Cybercriminals Abuse TDS Infrastructure to Bypass Firewalls and Hide Malicious Destinations
Cybercriminals Abuse TDS Infrastructure to Bypass Firewalls and Hide Malicious Destinations Cybercriminals are increasingly abusing traffic distribution systems (TDSs) to evade defenses, conceal malicious destinations, and funnel victims into phishing, fraud, and malware campaigns. Once… Delivered by PolitePaul service Go to gbhackers.com
-
Critical FFmpeg Vulnerability Lets Hackers Execute Remote Code via Malicious Media Files
Critical FFmpeg Vulnerability Lets Hackers Execute Remote Code via Malicious Media Files A critical memory corruption vulnerability in FFmpeg has been disclosed, allowing for remote code execution through specially crafted media files. This flaw, tracked as… Delivered by PolitePaul service Go to gbhackers.com
-
WhatsApp phishing attack uses fake business docs to hack PCs
WhatsApp phishing attack uses fake business docs to hack PCs An ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote system access. […] Bill Toulas Go to bleepingcomputer
-
JaredFromSubway MEV bot hacked in $15 million crypto theft
JaredFromSubway MEV bot hacked in $15 million crypto theft The JaredFromSubway Ethereum MEV (Maximal Extractable Value) bot suffered a $15 million loss after an attacker manipulated the opportunity-detection logic by creating fake cryptocurrency trading opportunities. […] Bill Toulas Go to bleepingcomputer
-
FFmpeg fixes PixelSmash flaw in widely used video decoder
FFmpeg fixes PixelSmash flaw in widely used video decoder A newly disclosed FFmpeg flaw dubbed ‘PixelSmash’ could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. […] Bill Toulas Go to bleepingcomputer
-
FortiBleed campaign used custom FortiGate sniffer to steal credentials
FortiBleed campaign used custom FortiGate sniffer to steal credentials Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal credentials. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft says Windows 11 26H2 is coming soon, details upgrade process
Microsoft says Windows 11 26H2 is coming soon, details upgrade process Microsoft has confirmed that Windows 11 version 26H2 will be the next feature update and that devices running Windows 11 24H2 and 25H2 will be able to upgrade using a small enablement package. […] Lawrence Abrams Go to bleepingcomputer
-
Researcher Earns $148,337 for Google Cloud Production RCE Vulnerability
Researcher Earns $148,337 for Google Cloud Production RCE Vulnerability A researcher has earned a total of 148,337 USD from Google for uncovering a set of flaws in Google Cloud’s Application Integration service that escalated into remote code execution (RCE) in Google Cloud production. The core bug is now tracked as CVE‑2026‑2031. The researcher Arvin Shivram…
-
Tata Electronics Data Breach Exposes Confidential Apple and Tesla Documents
Tata Electronics Data Breach Exposes Confidential Apple and Tesla Documents Indian electronics manufacturing giant Tata Electronics confirmed a “cybersecurity incident” on Monday after ransomware group World Leaks published over 200,000 files totaling more than 630 gigabytes on the dark web, allegedly containing proprietary and confidential documents belonging to Apple and Tesla. World Leaks, a ransomware…
-
New Phishing Attack Abuses Outlook and Microsoft 365 Groups Features to Attack Users
New Phishing Attack Abuses Outlook and Microsoft 365 Groups Features to Attack Users Phishing attacks have grown more sophisticated, and attackers are no longer relying on clunky fake emails or obvious scam messages. A newly identified campaign shows how threat actors are turning everyday Microsoft 365 tools into weapons, hiding their attacks inside the very…
-
Critical libssh2 Vulnerability Allows Attackers to Execute Remote Code Via Malicious SSH packets
Critical libssh2 Vulnerability Allows Attackers to Execute Remote Code Via Malicious SSH packets A critical security vulnerability has been identified in the widely used libssh2 library, allowing remote attackers to execute arbitrary code through specially crafted SSH packets. The flaw, tracked as CVE-2026-55200, carries a CVSS score of 9.2 and is classified under CWE-680 (Integer…
-
Critical FFmpeg Vulnerability Allows Attackers to Weaponize Media Files
Critical FFmpeg Vulnerability Allows Attackers to Weaponize Media Files A critical vulnerability has been disclosed in FFmpeg’s MagicYUV decoder that allows attackers to weaponize seemingly harmless media files and, in some scenarios, achieve remote code execution (RCE). The flaw, tracked as CVE-2026-8461 and dubbed “PixelSmash,” is a heap out-of-bounds write in FFmpeg’s libavcodec component, with…
-
WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of legitimate Remote Monitoring and Management (RMM) software. Per findings from Kaspersky, the active campaign is targeting users of WhatsApp Desktop and WhatsApp…
-
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws OpenAI on Monday said it’s releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative the artificial intelligence (AI) company announced last month. Calling GPT‑5.5‑Cyber its “strongest model yet for finding and helping patch software vulnerabilities,” OpenAI said…
-
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. “Attackers compromised the vendor’s build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official…
-
Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily read artificial intelligence (AI) conversions from other customers’ applications without requiring authentication. The vulnerabilities have…
-
29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests
29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests A heap over-read in the Squid web proxy can leak another user’s cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy. The bug traces to a 1997 FTP-parsing change and is still…
-
Professional Athletes and Wearables
Professional Athletes and Wearables I haven’t thought about the privacy issues surrounding professional athletes and wearables. Wearables present serious privacy issues for “Average Joe” consumers, who are entrusting tech companies to safely store and protect their biometric data. Imagine the stakes for a professional athlete, whose entire livelihood could be affected by a single biometric…
-
CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd)
CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd) The vulnerability In August 2024 SonicWall published advisory SNWLID-2024-0015 for CVE-2024-40766. It is an improper access control vulnerability in SonicOS. CVSS 9.3. It affects the management interface and the SSLVPN service on Gen 5, Gen 6 and Gen 7 firewalls. Each generation…
-
ISC Stormcast For Tuesday, June 23rd, 2026 https://isc.sans.edu/podcastdetail/9982, (Tue, Jun 23rd)
ISC Stormcast For Tuesday, June 23rd, 2026 https://isc.sans.edu/podcastdetail/9982, (Tue, Jun 23rd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Webshells Remain Popular, (Mon, Jun 22nd)
Webshells Remain Popular, (Mon, Jun 22nd) Webshells have been popular for a long time. We already covered this topic across multiple diaries[1][2]. I spent some time to track them[3] and slighly paid less attention to them but today I found another one. It seems to be a new player (pushed on Github two months ago). …
-
ISC Stormcast For Monday, June 22nd, 2026 https://isc.sans.edu/podcastdetail/9980, (Mon, Jun 22nd)
ISC Stormcast For Monday, June 22nd, 2026 https://isc.sans.edu/podcastdetail/9980, (Mon, Jun 22nd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)
eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th) I detected an interesting phishing email this morning. It targets a major Belgian bank: The phishing in itself is a classic one, not relevant but the malicious link is interesting: hxxp://[::ffff:5511:74be]/kWC5PHA1 The technique used by the attacker is to bypass simple security controls trying to…
-
Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign
Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign Attackers are using multiple online channels — including GitHub, YouTube, and VirusTotal — to build an illusion of trust to spread a cross-platform clipboard hijacker. Elizabeth Montalbano Go to gbhackers.com
-
282 iOS Apps Found Leaking LLM API Credentials in Network Traffic
282 iOS Apps Found Leaking LLM API Credentials in Network Traffic Researchers have uncovered a systemic LLM credential exposure problem in the iOS ecosystem, with 282 AI‑powered apps leaking exploitable API credentials and backend access… Delivered by PolitePaul service Go to gbhackers.com
-
LACUNA Chain Ghost Frames Technique Bypasses EDR Call-Stack Detection
LACUNA Chain Ghost Frames Technique Bypasses EDR Call-Stack Detection The LACUNA Chain’s “Ghost Frames” technique introduces a new method for manipulating call stacks that effectively bypasses modern Endpoint Detection and Response (EDR) systems,… Delivered by PolitePaul service Go to gbhackers.com
-
Attackers Can Poison AI Research Agents Using Reddit and Wikipedia Content
Attackers Can Poison AI Research Agents Using Reddit and Wikipedia Content Attackers can now manipulate AI “deep-research” agents by discreetly editing Reddit threads and Wikipedia pages. They can insert as little as a 13-word snippet,… Delivered by PolitePaul service Go to gbhackers.com
-
AryStinger Botnet Uses Intranet Scanning and Traffic Tunneling to Hide Attacker Activity
AryStinger Botnet Uses Intranet Scanning and Traffic Tunneling to Hide Attacker Activity A newly analyzed botnet family, AryStinger, weaponizes long‑neglected routers and NAS appliances to build a stealthy reconnaissance and relay infrastructure that helps attackers obscure… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Confirms Windows 11 26H2 Upgrade via Enablement Package for Faster Deployment
Microsoft Confirms Windows 11 26H2 Upgrade via Enablement Package for Faster Deployment Microsoft has announced that the upcoming Windows 11 version 26H2 will be delivered using an enablement package model. This approach aligns with their goal… Delivered by PolitePaul service Go to gbhackers.com
-
AryStinger botnet infected thousands of D-Link routers worldwide
AryStinger botnet infected thousands of D-Link routers worldwide A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic. […] Bill Toulas Go to bleepingcomputer
-
Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data to Enable State Operations
Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data to Enable State Operations China’s cyber operations have evolved far beyond what most people imagine when they picture a state-sponsored hacker. Instead of lone government agents breaking into servers, the country now runs an intricate web of private companies, contractors, and data brokers that collectively carry…
-
North Korean Hackers Abuse Mastra npm Supply Chain to Target Developers and CI/CD Pipelines
North Korean Hackers Abuse Mastra npm Supply Chain to Target Developers and CI/CD Pipelines North Korean hackers have turned a widely used developer tool into a weapon, quietly poisoning more than 140 software packages that developers across the world rely on every day. The campaign is sophisticated, stealthy, and far-reaching, raising urgent questions about the…
-
13-Word Reddit Comment Can Poison ChatGPT and Gemini AI Search Results
13-Word Reddit Comment Can Poison ChatGPT and Gemini AI Search Results A newly published academic paper has revealed a critical vulnerability in AI-powered deep-research systems, including those underpinning commercial tools like OpenAI’s Deep Research and Google’s Gemini Deep Research, that allows a single short Reddit comment to manipulate the reports these agents generate for thousands…
-
Hackers Impersonate Node.js Installer in Google Ads to Deploy Infostealer Malware
Hackers Impersonate Node.js Installer in Google Ads to Deploy Infostealer Malware Hackers are using fake Google Ads to push a brand-new malware loader that disguises itself as the popular Node.js installer. The campaign has been actively targeting Windows users in the United States, silently dropping a dangerous infostealer onto their machines after just a single…
-
Hackers Compromised 10,000+ GitHub Repositories to Inject Malicious Script
Hackers Compromised 10,000+ GitHub Repositories to Inject Malicious Script A large-scale malware campaign has been uncovered on GitHub after a researcher identified more than 10,000 repositories distributing Trojan-laced archives, raising concerns about abuse of the platform’s trust model and limitations in automated detection. The investigation began when the researcher noticed a cloned version of their…
-
INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific
INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific A new report from INTERPOL has revealed a “dramatic increase” in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration, new technologies, organized criminal networks, and a disparity in cybersecurity maturity. According to INTERPOL’s 2025/2026 Asia and South Pacific Cyberthreat…
-
New Prinz Eugen ransomware prioritizes recent files for encryption
New Prinz Eugen ransomware prioritizes recent files for encryption A new ransomware operation named ‘Prinz Eugen’ prioritizes recently modified files for encryption and leaves no ransom note on the system. […] Bill Toulas Go to bleepingcomputer
-
Microsoft links Mastra AI supply chain attack to North Korean hackers
Microsoft links Mastra AI supply chain attack to North Korean hackers Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. […] Lawrence Abrams Go to bleepingcomputer
-
GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes
GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes A highly sophisticated EDR-killing framework, dubbed GentleKiller, was used by the Gentlemen ransomware-as-a-service (RaaS) gang to systematically disable endpoint security tools before deploying its ransomware payload. The findings by ESET, published on June 17, 2026, detail how Gentlemen, one of the most active ransomware…
-
CyberSentinel AI with 33 Security Tools, Including Nmap, SQLMap, ZAP, and uses Claude, GPT
CyberSentinel AI with 33 Security Tools, Including Nmap, SQLMap, ZAP, and uses Claude, GPT A new open-source cybersecurity platform called CyberSentinel AI v3.0 has emerged as a significant development in autonomous security tooling, combining 33 real-world penetration testing and threat intelligence tools with a provider-agnostic AI engine that supports Claude, GPT-4o, OpenRouter, and fully offline…
-
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that’s installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data,…
-
Texas TPWD Vendor Breach Exposes 3 Million Customer Records
Texas TPWD Vendor Breach Exposes 3 Million Customer Records Texas Cyber Command has disclosed a massive third-party data breach affecting the Texas Parks and Wildlife Department (TPWD), exposing the personal records of exactly… Delivered by PolitePaul service Go to gbhackers.com
-
Vidar Infostealer Bypasses Google Chrome’s ABE Encryption via APC Injection
Vidar Infostealer Bypasses Google Chrome’s ABE Encryption via APC Injection A sophisticated evasion technique developed by Vidar infostealer operators successfully bypasses Google Chrome’s Application-Bound Encryption (ABE). Introduced in 2024, ABE was designed to protect… Delivered by PolitePaul service Go to gbhackers.com
-
Gentlemen RaaS Unifies HexKiller, ThrottleBlood, and HavocKiller in New Evasion Suite
Gentlemen RaaS Unifies HexKiller, ThrottleBlood, and HavocKiller in New Evasion Suite An analysis of the Gentlemen ransomware-as-a-service (RaaS) operation has revealed a sophisticated, centralized approach to neutralizing endpoint detection and response (EDR) solutions. This unified defense… Delivered by PolitePaul service Go to gbhackers.com
-
AutoJack Exploit Chain Hits Microsoft AutoGen Studio With Zero-Click RCE Attack
AutoJack Exploit Chain Hits Microsoft AutoGen Studio With Zero-Click RCE Attack A critical exploit chain dubbed AutoJack that allows a single malicious web page to hijack Microsoft’s AutoGen Studio browsing agent and silently execute arbitrary code on… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Chrome Extension Vulnerabilities Let Attackers Easily Compromise Browsers
Critical Chrome Extension Vulnerabilities Let Attackers Easily Compromise Browsers A critical security flaws in widely used Chrome extensions, exposing millions of users to the risk of full browser compromise. The vulnerabilities, named “MaXSS”… Delivered by PolitePaul service Go to gbhackers.com
-
Klue OAuth breach victim list grows as Icarus hackers claim attack
Klue OAuth breach victim list grows as Icarus hackers claim attack Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers’ Salesforce environments, as the new “Icarus” extortion group publicly claims the attack. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites. […] Bill Toulas Go to bleepingcomputer
-
Texas govt data breach exposes over 3 million driver’s licenses
Texas govt data breach exposes over 3 million driver’s licenses The Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its license system vendor that exposed personal information for more than three million individuals. […] Bill Toulas Go to bleepingcomputer
-
Every AI Agent Is an Identity. Most Organizations Don’t Treat Them That Way
Every AI Agent Is an Identity. Most Organizations Don’t Treat Them That Way AI agents can access data, trigger workflows, deploy code, and interact with critical business systems, often with little oversight. Token Security breaks down why AI agents are becoming a new identity and governance challenge. […] Sponsored by Token Security Go to bleepingcomputer
-
Webinar: How attackers bypass MFA and how defenders can respond
Webinar: How attackers bypass MFA and how defenders can respond Modern phishing attacks, including Device Code phishing, can undermine MFA protections and grant attackers access to corporate accounts without stealing passwords. This webinar explores how behavioral AI can help security teams detect compromised accounts faster and automate response workflows. […] BleepingComputer Go to bleepingcomputer
-
AutoJack – A Single Web Page Can Hijack Your AI Agent to Execute Malicious Code
AutoJack – A Single Web Page Can Hijack Your AI Agent to Execute Malicious Code A critical exploit chain dubbed AutoJack that allows a single malicious web page to hijack Microsoft’s AutoGen Studio browsing agent and execute arbitrary code on the host machine without any user interaction beyond submitting a URL. AutoJack is a three-vulnerability…
-
CISA Adds LiteSpeed cPanel Plugin Vulnerability to KEV List Following Active Exploitation
CISA Adds LiteSpeed cPanel Plugin Vulnerability to KEV List Following Active Exploitation CISA has added a critical LiteSpeed cPanel Plugin vulnerability, tracked as CVE-2026-54420, to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation in the wild. The flaw affects shared hosting environments and poses a significant risk to servers running CloudLinux with…
-
Chrome Extensions’ Critical Flaws Let Attackers Easily Compromise Millions of Browsers
Chrome Extensions’ Critical Flaws Let Attackers Easily Compromise Millions of Browsers Critical security flaws discovered in widely used Chrome extensions SiderAI and MaxAI are putting millions of users at risk, enabling attackers to fully compromise browser sessions and potentially access sensitive data across websites and local systems. Security researchers at Rebora Security uncovered vulnerabilities dubbed…
-
Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections
Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections Luxembourg, Luxembourg, June 19th, 2026, CyberNewswire Gcore’s Network Layer DDoS Protection helped Ucom maintain service continuity and operational readiness for critical public-facing broadcast services Gcore, the global edge AI, cloud, network, and security solutions provider, supported Ucom, one of Armenia’s leading telecommunications providers,…
-
Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks
Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks A critical security vulnerability in the widely used Avada (Fusion) Builder WordPress plugin has exposed over 1 million websites to arbitrary file-deletion attacks, potentially leading to full-site compromise and remote code execution. The flaw, tracked as CVE-2026-8713 with a CVSS score of 9.1,…
-
Unpatchable ‘usbliter8’ Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
Unpatchable ‘usbliter8’ Exploit Breaks Apple A12 and A13 SecureROM Boot Chain Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple’s A12 and A13 chips. That code is burned into the silicon at manufacture. No software update can reach it. Affected devices will carry this flaw…
-
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor. This mature portfolio of EDR-terminating tools is centered around a framework…
-
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent to load an attacker’s web page, and that page’s JavaScript can reach a privileged local service on…
-
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites. “With these actions we deprive cybercriminals of access to infected computer systems,” Maikel Rollman of the Netherlands…
-
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps to secure against ongoing malicious activity aimed at thousands of internet-accessible devices. The sweeping campaign, believed to be the work of Russian-speaking threat actors, has been…
-
Friday Squid Blogging: Victims of Unregulated Squid Fishing
Friday Squid Blogging: Victims of Unregulated Squid Fishing Dolphins, sharks, turtles, and human workers are all victims of unregulated squid fishing fleets. Another news article. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. Bruce Schneier Go to bruce…
-
Anthropic’s Fable and the State of AI
Anthropic’s Fable and the State of AI On June 9th, Anthropic released its Fable generative AI model. Three days later, the US government classified it as a dangerous munition, and used its export-control authority to prohibit any foreign nationals from accessing it. Unable to differentiate between Americans and foreigners, the company shut off access for…
-
Imposter scams cost Americans $3.5 billion in 2025 – and it’s getting worse
Imposter scams cost Americans $3.5 billion in 2025 – and it’s getting worse Someone is pretending to be your bank, your government, or your local planning office. And according to the FTC, they’re making billions doing it. Read more in my article on the Fortra blog. Graham Cluley Go to grahamcluley
-
Stressors, AI Forcing Changes to Cybersecurity Teams
Stressors, AI Forcing Changes to Cybersecurity Teams As threats proliferate and AI complicates cybersecurity, CISOs say the job is getting harder, but more companies still want cybersecurity expertise, if even on a part-time basis. Robert Lemos Go to gbhackers.com
-
UEFI DBX Update Guidance Targets Vulnerable Vendor-Signed Boot Applications
UEFI DBX Update Guidance Targets Vulnerable Vendor-Signed Boot Applications A recently disclosed vulnerability inc, which affects UEFI applications signed by multiple vendors, has prompted urgent recommendations to update the UEFI Forbidden Signature Database… Delivered by PolitePaul service Go to gbhackers.com
-
SmartApeSG Hackers Abuse Okendo Reviews Widget in E-Commerce Supply Chain Attack
SmartApeSG Hackers Abuse Okendo Reviews Widget in E-Commerce Supply Chain Attack A supply-chain style compromise in the Okendo Reviews widget that enabled the SmartApeSG threat actor to deliver staged JavaScript loaders across a wide e-commerce… Delivered by PolitePaul service Go to gbhackers.com
-
HazyBeacon Abuses AWS Lambda Function URLs for Stealthy Command-and-Control Operations
HazyBeacon Abuses AWS Lambda Function URLs for Stealthy Command-and-Control Operations HazyBeacon is a stealthy cloud-native malware campaign identified as CL-STA-1020. It is exploiting Amazon Web Services (AWS) Lambda Function URLs to create covert command-and-control… Delivered by PolitePaul service Go to gbhackers.com
-
CISA Issues Alert on Critical Splunk Enterprise Bug Under Active Exploitation
CISA Issues Alert on Critical Splunk Enterprise Bug Under Active Exploitation CISA has issued an urgent alert regarding a critical vulnerability in Splunk Enterprise, tracked as CVE-2026-20253, which is now listed in the Known Exploited… Delivered by PolitePaul service Go to gbhackers.com
-
Node.js Releases Security Updates for 12 Vulnerabilities, Two Rated High Severity
Node.js Releases Security Updates for 12 Vulnerabilities, Two Rated High Severity Node.js has announced critical security updates that address 12 vulnerabilities across its supported release lines. Among these, two high-severity flaws could lead to denial-of-service… Delivered by PolitePaul service Go to gbhackers.com
-
NY man charged after harassing college student with AI-generated nudes
NY man charged after harassing college student with AI-generated nudes A New York man faces cyberstalking charges after allegedly sharing AI-generated nude images and fabricated racist messages using fake social media profiles to harass a Georgia college student. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA warns Fortinet users to secure devices after FortiBleed leak
CISA warns Fortinet users to secure devices after FortiBleed leak The U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged Fortinet customers to secure their devices after nearly 74,000 firewall and VPN credentials were exposed in a data leak dubbed “FortiBleed.” […] Sergiu Gatlan Go to bleepingcomputer
-
Gentlemen ransomware uses multiple EDR killers to disable defenses
Gentlemen ransomware uses multiple EDR killers to disable defenses The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. […] Bill Toulas Go to bleepingcomputer
-
Nintendo confirms data stolen in WebMD subsidiary cyberattack
Nintendo confirms data stolen in WebMD subsidiary cyberattack Nintendo of America has confirmed to BleepingComputer that threat actors stole survey data from the third-party TinyPulse service used internally, but its systems were not compromised. […] Bill Toulas Go to bleepingcomputer
-
USB worm spreads crypto-stealing malware via Windows shortcut files
USB worm spreads crypto-stealing malware via Windows shortcut files Threat actors targeting cryptocurrency wallets have been distributing clipboard-stealing malware with self-spreading capabilities and using the Tor network to conceal communication. […] Bill Toulas Go to bleepingcomputer
-
China-Linked Showboat Malware Uses Linux Persistence to Target Telecom Companies
China-Linked Showboat Malware Uses Linux Persistence to Target Telecom Companies A sophisticated China-linked malware framework has been quietly targeting telecom companies across the Middle East for nearly four years. Showboat is a Linux-based tool that stayed completely hidden from antivirus systems until April 2026, raising serious concerns about the security of critical communications infrastructure worldwide.…
-
CISA Warns of Splunk Enterprise Critical Function Vulnerability Actively Exploited in Attacks
CISA Warns of Splunk Enterprise Critical Function Vulnerability Actively Exploited in Attacks CISA has issued a high-priority alert warning organizations about a critical vulnerability in Splunk Enterprise that is actively being exploited in the wild. The flaw, tracked as CVE-2026-20253, has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, signaling immediate risk to enterprise…
-
Node.js Fixes 12 Vulnerabilities, Including 2 High-Severity Authentication Bypasses
Node.js Fixes 12 Vulnerabilities, Including 2 High-Severity Authentication Bypasses Node.js has released a new round of security updates addressing 12 vulnerabilities across its supported release lines, including two high-severity flaws that could lead to authentication bypass and denial-of-service (DoS) attacks. The updates impact Node.js versions 22.x, 24.x, and 26.x, with patched releases now available as…
-
Hackers Use Weaponized Windows Shortcuts to Spread Crypto Clipper Across USB Drives
Hackers Use Weaponized Windows Shortcuts to Spread Crypto Clipper Across USB Drives A newly discovered cryptocurrency clipper malware has been quietly stealing digital assets from victims since February 2026, spreading through a trick that most users would never suspect: weaponized Windows shortcut files on USB drives. The malware is not just a simple thief. It…
-
AI-Powered Public Surveillance and Biometric Data Collection Expand Government Monitoring
AI-Powered Public Surveillance and Biometric Data Collection Expand Government Monitoring Governments are expanding their digital reach in ways unimaginable just a decade ago. A growing wave of AI-powered surveillance, biometric data collection, and commercial spyware is reshaping how states monitor citizens and visitors. The scale of this shift is drawing urgent attention from security professionals…
-
Killing me gently: Inside Gentlemen’s EDR killer framework
Killing me gently: Inside Gentlemen’s EDR killer framework ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen Go to eset
-
Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone
Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users. The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorrect authorization impacting the Airoha…
-
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems. The vulnerabilities are listed below – CVE-2026-42530 (CVSS v4 score: 9.2) – A use-after-free vulnerability in the…
-
Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network
Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network If an autonomous AI agent interacts with your company’s core intellectual property today, can your security team instantly name the person who authorized it? For most enterprises, the answer is a simple no. The rush to adopt internal AI tools has left a…
-
ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories
ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind.…
-
Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2
Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign that has targeted users since February 2026 with clipboard-intercepting malware with self-spreading capabilities and using the Tor anonymity network to hide communication. “The clipper in this campaign relies on Windows Script Host…
-
Embedding Forbidden Text in Spyware to Discourage AI Analysis
Embedding Forbidden Text in Spyware to Discourage AI Analysis At least one malware developer is adding text about nuclear and biological weapons to their spyware, in an effort to stop automatic AI analysis. Details: The _index.js payload begins with a large JavaScript block comment containing fake system instructions and policy-triggering content. Because it is inside…
-
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut,…
-
Novo Nordisk Breach Exposes Software Development Pipeline Risk
Novo Nordisk Breach Exposes Software Development Pipeline Risk A leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem. Jai Vijayan Go to gbhackers.com
-
Operation Escaneo Signals Shift in LatAm Threat Landscape
Operation Escaneo Signals Shift in LatAm Threat Landscape The threat group’s curious business model may combine opportunistic monetization alongside intel collection, without much coordination between the two. Alexander Culafi Go to gbhackers.com
-
FIFA Bug Exposed World Cup Streams to Remote Takeover
FIFA Bug Exposed World Cup Streams to Remote Takeover A hacker could have “Rickrolled” the World Cup — or worse — thanks to FIFA’s unenforced Entra access controls. Nate Nelson Go to gbhackers.com