no alarms and no surprises please..

  • Let’s Encrypt Unveils Merkle Tree Certificates to Secure the Web Against Quantum Threats

    Let’s Encrypt Unveils Merkle Tree Certificates to Secure the Web Against Quantum Threats Let’s Encrypt has announced its roadmap for post-quantum Web PKI, centering on a novel approach called Merkle Tree Certificates (MTCs), a design that delivers quantum-resistant authentication without bloating TLS handshakes or breaking the web’s performance expectations. Traditional X.509 certificate chains require significant…

  • Microsoft Edge Vulnerability Allows Remote Attackers to Execute Arbitrary Code

    Microsoft Edge Vulnerability Allows Remote Attackers to Execute Arbitrary Code Microsoft has released a security update addressing a critical vulnerability in Microsoft Edge that could allow remote attackers to execute arbitrary code on vulnerable systems. Tracked as CVE-2026-45495 and reported by Orange Tsai of DEVCORE, the flaw carries a CVSS v3 score of 7.5 and…

  • Dashlane Details How Hackers Managed to Download Encrypted Password Vaults

    Dashlane Details How Hackers Managed to Download Encrypted Password Vaults Dashlane has disclosed that threat actors successfully brute-forced two-factor authentication (2FA) protections to register unauthorized devices and download encrypted password vaults belonging to fewer than 20 personal plan users, with a completed investigation confirming no broader impact on its internal systems. Beginning Sunday, May 31,…

  • PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

    PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network The threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to create a covert SMTP email relay network. “Compromised business servers across the U.S., Europe, and Asia were quietly converted…

  • Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public

    Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root. It is tracked as CVE-2026-20230, and proof-of-concept exploit code is already public. Cisco’s PSIRT says it…

  • Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

    Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories A security researcher found a flaw in Anthropic’s Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because Anthropic’s own action repo used the same workflow, a working attack…

  • Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It

    Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It Over the past several weeks, the cybersecurity community has been reminded how quickly frontier and agentic AI in defense networks can challenge our assumptions. When Anthropic’s Claude Mythos model was made available to a limited set of organizations as a technical preview,…

  • ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories

    ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories It got stupid again. The internet still feels held together with tape. Bad plugins, old bugs, fake tools, trusted apps doing shady things. Same mess, new wrapper. And now the weird stuff is normal. Forums go down and…

  • You do surprise me.exe: An unexpected executable in Hola Browser

    You do surprise me.exe: An unexpected executable in Hola Browser <p>Following a certification test, Sophos X-Ops found an unexpected guest had hitched a ride</p> Categories: Threat Research Tags: Crypto mining, Supply chain Go to sophos

  • Hacking Meta’s AI Chatbot

    Hacking Meta’s AI Chatbot Hackers are convincing Meta’s AI support chatbot to let them take over other peoples’ accounts: A video posted on X showed the step-by-step process to hack someone’s Instagram account. The hacker allegedly used a VPN to spoof the targets’ presumed location to avoid triggering Instagram’s automated account protections. Then, the hacker…

  • ISC Stormcast For Friday, June 5th, 2026 https://isc.sans.edu/podcastdetail/9960, (Fri, Jun 5th)

    ISC Stormcast For Friday, June 5th, 2026 https://isc.sans.edu/podcastdetail/9960, (Fri, Jun 5th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu

  • Microsoft’s Coreutils for Windows, (Thu, Jun 4th)

    Microsoft’s Coreutils for Windows, (Thu, Jun 4th) I’ve been using the GnuWin32 CoreUtils for Windows for many years now (it gives you many *nix core commands on Windows). Microsoft has just released their coreutils version for Windows. You can install them with a winget command (winget install Microsoft.Coreutils) or with the installer released on GitHub. It…

  • Meta’s own AI chatbot to blame for Instagram accounts being stolen in seconds

    Meta’s own AI chatbot to blame for Instagram accounts being stolen in seconds Hackers have been hijacking Instagram accounts at scale by exploiting Meta’s AI support chatbot. And, as if that weren’t bad enough, the technique required no technical skill whatsoever. Read more in my article on the Fortra blog. Graham Cluley Go to grahamcluley

  • Rust-Written IronWorm Hits NPM Supply Chain

    Rust-Written IronWorm Hits NPM Supply Chain Like Shai-Hulud, the campaign targets developers to steal credentials and reuses them to propagate across the software supply channel. Jai Vijayan Go to gbhackers.com

  • China’s TA4922 Expands Cybercrime Attacks Globally

    China’s TA4922 Expands Cybercrime Attacks Globally One of the world’s most diverse, least-focused cybercrime groups is enlarging its footprint beyond East Asia. Nate Nelson Go to gbhackers.com

  • 4 Critical Threats Where Attackers Have the Advantage

    4 Critical Threats Where Attackers Have the Advantage Gartner analysts issued a call to action to bolster defenses against several emerging critical threats, such as deepfakes and prompt injections. Rob Wright Go to gbhackers.com

  • Bugcrowd Launches EU Data Residency Option For Evolving Data Sovereignty Needs

    Bugcrowd Launches EU Data Residency Option For Evolving Data Sovereignty Needs Organizations are growing serious about what nation’s rules apply to their data. Experts point to geopolitical tensions as a main contributing factor. Arielle Waldman Go to gbhackers.com

  • IronWorm npm Attack Steals Developer Secrets

    IronWorm npm Attack Steals Developer Secrets A newly uncovered supply chain attack dubbed “IronWorm” is leveraging malicious npm packages to compromise developer environments, steal sensitive credentials, and propagate itself across… Delivered by PolitePaul service Go to gbhackers.com

  • Stock Exchange Executive’s Outlook Targeted in Credential Theft Attack

    Stock Exchange Executive’s Outlook Targeted in Credential Theft Attack A prolonged and highly targeted espionage campaign has been uncovered involving the compromise of a senior executive’s Microsoft Outlook account at a major global… Delivered by PolitePaul service Go to gbhackers.com

  • PoC Exploit Released for Cisco Unified Communications Manager Security Vulnerability

    PoC Exploit Released for Cisco Unified Communications Manager Security Vulnerability A proof-of-concept (PoC) exploit has been released for a critical server-side request forgery (SSRF) vulnerability impacting Cisco Unified Communications Manager (Unified CM) and Unified… Delivered by PolitePaul service Go to gbhackers.com

  • Proofpoint: TA4922 Deploys New RAT and Loader Arsenal

    Proofpoint: TA4922 Deploys New RAT and Loader Arsenal A rapidly evolving threat cluster tracked as TA4922, a Chinese-speaking cybercriminal actor deploying a diverse and expanding malware arsenal that now includes Atlas RAT,… Delivered by PolitePaul service Go to gbhackers.com

  • Phishing Attacks Pivot to Infostealer Malware Over Fake Login Pages

    Phishing Attacks Pivot to Infostealer Malware Over Fake Login Pages Cybercriminal tactics are evolving as phishing campaigns increasingly shift away from fake login pages toward infostealer malware designed to quietly harvest sensitive data from… Delivered by PolitePaul service Go to gbhackers.com

  • Chinese hackers use new Atlas RAT malware in European cyberattacks

    Chinese hackers use new Atlas RAT malware in European cyberattacks A Chinese-speaking cybercrime group has expanded its targeting to the European space, deploying previously undocumented malware and the Atlas backdoor. […] Bill Toulas Go to bleepingcomputer

  • U.S. sanctions Nobitex crypto exchange used by Iranian ransomware actors

    U.S. sanctions Nobitex crypto exchange used by Iranian ransomware actors The U.S. Treasury’s Office of Foreign Assets Control (OFAC) has announced sanctions against Nobitex, Iran’s largest cryptocurrency exchange, for facilitating payments related to terrorist activities. […] Bill Toulas Go to bleepingcomputer

  • CISA warns of cyberattacks targeting fuel tank monitoring systems

    CISA warns of cyberattacks targeting fuel tank monitoring systems CISA, the FBI, the NSA, the Department of Energy, and other US government partners are warning that hackers are targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks across various critical infrastructure sectors. […] Lawrence Abrams Go to bleepingcomputer

  • New ‘HTTP/2 Bomb’ DoS attack crashes web servers in under a minute

    New ‘HTTP/2 Bomb’ DoS attack crashes web servers in under a minute A new denial-of-service (DoS) attack dubbed HTTP/2 Bomb can be launched from a single machine to take down web servers within seconds. […] Bill Toulas Go to bleepingcomputer

  • CISA warns of active attacks exploiting Android, Linux bugs

    CISA warns of active attacks exploiting Android, Linux bugs The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system. […] Bill Toulas Go to bleepingcomputer

  • Acer Working to Patch Wave 7 Router 0-day Vulnerability

    Acer Working to Patch Wave 7 Router 0-day Vulnerability Acer is preparing a firmware update to address a critical zero-day vulnerability affecting its Wave 7 routers, following disclosure by independent security researcher Gergo Pap. The issue affects devices running firmware versions earlier than and poses a significant risk due to unauthenticated remote exploitation. According to…

  • Fake Claude Code Installer Via Google Sites Deliver Credential-Stealing Malware

    Fake Claude Code Installer Via Google Sites Deliver Credential-Stealing Malware Cybercriminals have found a new and clever way to exploit the growing popularity of AI developer tools. A recently identified campaign uses fake pages mimicking Claude Code and OpenAI Codex, hosted on trusted Google Sites infrastructure, to trick users into running commands that quietly steal…

  • Bots Surpass Humans in Global Web Traffic for the First Time in Internet History

    Bots Surpass Humans in Global Web Traffic for the First Time in Internet History For the first time ever, automated bots have officially overtaken human users in global internet traffic, and the shift is accelerating faster than even industry leaders predicted. Bots Surpass Humans in Web Traffic According to data from Cloudflare Radar, bots now…

  • Microsoft Unveils Always-On AI Agent Scout to Integrate With Teams, Outlook, and More

    Microsoft Unveils Always-On AI Agent Scout to Integrate With Teams, Outlook, and More Microsoft has officially introduced Microsoft Scout, its first-ever “Autopilot” AI agent, a persistent, always-on autonomous assistant designed to operate continuously across Microsoft 365 apps without waiting to be prompted. Unveiled at Microsoft Build 2026 on June 2, Scout represents a fundamental shift…

  • New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS

    New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS A new class of indirect prompt injection (IPI) attacks targets Google Gemini’s voice assistant, allowing attackers to silently hijack the AI through malicious payloads delivered via everyday messaging apps, including WhatsApp, Slack, Signal, SMS, Instagram, and Messenger. The research, led by Or…

  • Lessons for life: Why children’s data is a long-term identity risk

    Lessons for life: Why children’s data is a long-term identity risk Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe. Go to eset

  • DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets

    DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets The U.S. Department of Justice (DoJ) on Wednesday announced the results of a sweeping action undertaken by government authorities and private sector companies to combat cyber-enabled and cryptocurrency fraud targeting Americans. The “Disruption Week” operation began May 18, 2026, leading to the takedown…

  • WhatsApp, Slack Notifications Could Hijack Google Gemini on Android

    WhatsApp, Slack Notifications Could Hijack Google Gemini on Android A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini’s voice assistant on Android and made it open a victim’s connected windows, fake a message from their boss, push the phone into a Zoom call, or quietly poison its…

  • Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT

    Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT Cybersecurity researchers have flagged a new malspam campaign that makes use of Google’s DoubleClick domain as a way to evade detection and ultimately deliver a remote access trojan (RAT) named DesckVB RAT. “Before the victim ever reaches attacker-controlled infrastructure, the lure routes through DoubleClick,…

  • Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore

    Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore Assume the breach. Zero-days keep shipping, AI is writing exploits faster than anyone patches, and “patch everything in time” stopped working years ago. Stop betting the org on winning that race. You don’t control which bug lands. You control what it…

  • Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

    Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits account-token sharing to trusted Microsoft apps. Any other app on the same phone could ask for the signed-in user’s token and…

  • AI Used to Decrypt Medieval Ciphers

    AI Used to Decrypt Medieval Ciphers Researchers are using machine learning algorithms to decrypt historical pencil-and-paper ciphers. Bruce Schneier Go to bruce schneier

  • Pakistan Spies on Afghan Finance Ministry With Xeno RAT

    Pakistan Spies on Afghan Finance Ministry With Xeno RAT Despite broadly connected digital infrastructure, standard fare TTPs are enough to cause trouble for Afghanistan’s porous cybersecurity. Nate Nelson Go to gbhackers.com

  • ISC Stormcast For Thursday, June 4th, 2026 https://isc.sans.edu/podcastdetail/9958, (Thu, Jun 4th)

    ISC Stormcast For Thursday, June 4th, 2026 https://isc.sans.edu/podcastdetail/9958, (Thu, Jun 4th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu

  • Continuing Scans for swagger.json, (Wed, Jun 3rd)

    Continuing Scans for swagger.json, (Wed, Jun 3rd) Enterprise applications often still use complex standards like SOAP for web services. The big advantage of SOAP is its tight and extensive standards, which enable interoperability across an enterprise governed by web services. The disadvantage of SOAP: First, while it is de facto usually used over HTTP, it…

  • ISC Stormcast For Wednesday, June 3rd, 2026 https://isc.sans.edu/podcastdetail/9956, (Wed, Jun 3rd)

    ISC Stormcast For Wednesday, June 3rd, 2026 https://isc.sans.edu/podcastdetail/9956, (Wed, Jun 3rd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu

  • New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)

    New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd) For a few days, my SANS ISC mailbox is flooded with emails that delivers SVG files. An SVG (“Scalable Vector Graphic”) is a web-friendly vector file format used for graphics and icons. No URL in the body, just “an image”, that’s the perfect way…

  • Smashing Security podcast #470: This AI security flaw might be impossible to fix

    Smashing Security podcast #470: This AI security flaw might be impossible to fix A website called “UK visa portal” has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were applying through official channels. They weren’t. And when a journalist tried to warn the company, it was lawyers…

  • Welcoming the Philippine Government to Have I Been Pwned

    Welcoming the Philippine Government to Have I Been Pwned Today, we welcome the 46th government onboarded to Have I Been Pwned’s free gov service: the Philippines. The Philippines’ National CERT, working with the Department of Information and Communications Technology, now has access to monitor official government domains against the data in HIBP. This gives their…

  • Attackers Use AI to Automate EDR Evasion Testing

    Attackers Use AI to Automate EDR Evasion Testing Python scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender. Alexander Culafi Go to gbhackers.com

  • Tropical Blend: Cyber & Politics Ramp Up Across Latin America

    Tropical Blend: Cyber & Politics Ramp Up Across Latin America China-linked espionage groups have attacked at least a dozen nations in the region, gathering information on maritime shipping, oil production, and other geopolitical interests. Robert Lemos Go to gbhackers.com

  • Cyber Insurance Rates Are Dropping, but Exclusions Widen

    Cyber Insurance Rates Are Dropping, but Exclusions Widen Cyber insurance coverage is slowly changing, and some policies may not provide coverage for social engineering attacks like ClickFix. Rob Wright Go to gbhackers.com

  • Malicious Notifications Could Trick Google Gemini Users

    Malicious Notifications Could Trick Google Gemini Users A prompt injection flaw in Google Gemini’s voice assistant let attackers hide malicious commands in notifications, enabling social engineering and more. Alexander Culafi Go to gbhackers.com

  • Ivanti ITSM Flaw Could Allow Attackers to Escalate to Admin Access

    Ivanti ITSM Flaw Could Allow Attackers to Escalate to Admin Access Ivanti has patched a high-severity vulnerability in its Ivanti Neurons for ITSM platform that could allow authenticated attackers to escalate privileges and gain full… Delivered by PolitePaul service Go to gbhackers.com

  • Hackers Leverage AI-Powered Tools to Streamline Active Directory Compromise

    Hackers Leverage AI-Powered Tools to Streamline Active Directory Compromise A threat campaign in which attackers leveraged AI-powered tools to streamline Active Directory (AD) compromise and accelerate endpoint detection and response (EDR) evasion testing…. Delivered by PolitePaul service Go to gbhackers.com

  • HazyBeacon Campaign Abuses AWS for Stealthy C2 Communications

    HazyBeacon Campaign Abuses AWS for Stealthy C2 Communications A newly documented cyber espionage operation known as HazyBeacon, tracked as CL-STA-1020, is leveraging Amazon Web Services (AWS) to build stealthy command-and-control (C2) channels… Delivered by PolitePaul service Go to gbhackers.com

  • Windows Search URI Handler Vulnerability Exposes NTLMv2 Hashes to Remote Attackers

    Windows Search URI Handler Vulnerability Exposes NTLMv2 Hashes to Remote Attackers Windows systems are once again exposed to NTLM credential leakage through a newly observed abuse of the search, URI handler, a vulnerability class closely mirroring… Delivered by PolitePaul service Go to gbhackers.com

  • HTTP/2 Bomb Remote DoS Exploit Impacts nginx, Apache, IIS, Envoy, and Cloudflare Pingora

    HTTP/2 Bomb Remote DoS Exploit Impacts nginx, Apache, IIS, Envoy, and Cloudflare Pingora A newly disclosed “HTTP/2 Bomb” attack is raising serious concerns across the web infrastructure ecosystem, enabling remote denial-of-service (DoS) conditions against widely deployed servers… Delivered by PolitePaul service Go to gbhackers.com

  • Global Stock Exchange Hit by Monthslong Email Campaign

    Global Stock Exchange Hit by Monthslong Email Campaign A threat actor got a near-continuous view into an influential finance executive’s email inbox, thanks to clever use of legitimate, native Windows tools. Nate Nelson Go to gbhackers.com

  • Google adds Android protection against AI deepfake scam calls

    Google adds Android protection against AI deepfake scam calls Google is introducing a new Android security feature that will detect and flag phone calls in which scammers use artificial intelligence to impersonate a user’s personal contacts. […] Sergiu Gatlan Go to bleepingcomputer

  • VS Code zero-day lets hackers steal GitHub tokens in one click

    VS Code zero-day lets hackers steal GitHub tokens in one click A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft’s Coreutils project brings Linux commands to Windows

    Microsoft’s Coreutils project brings Linux commands to Windows Microsoft announced today at its Build 2026 developer conference the release of Coreutils for Windows, bringing many commonly used Linux command-line utilities to Windows as native applications. […] Lawrence Abrams Go to bleepingcomputer

  • OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models

    OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models OpenAI says it’s rolling out a new update that improves the existing GPT-5.5 Instant model, and this move comes ahead of the scheduled retirement of multiple legacy models, including o3. […] Mayank Parmar Go to bleepingcomputer

  • Critical Kirki flaw exploited to hijack WordPress admin accounts

    Critical Kirki flaw exploited to hijack WordPress admin accounts Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators. […] Bill Toulas Go to bleepingcomputer

  • HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora

    HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora A newly disclosed remote denial-of-service exploit dubbed “HTTP/2 Bomb” targets the default HTTP/2 configurations of the world’s most widely deployed web servers, nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora, enabling a single attacker on a home internet connection to…

  • 1-Click GitHub Token Vulnerability Lets Attackers Steal Users’ OAuth Tokens

    1-Click GitHub Token Vulnerability Lets Attackers Steal Users’ OAuth Tokens A critical security vulnerability in Visual Studio Code’s webview implementation allows attackers to steal GitHub OAuth tokens, including read/write access to private repositories, simply by tricking a victim into clicking a single malicious link. The bug was publicly disclosed on June 2, 2026, by security…

  • WordPress Malware Abuses Steam Community Profiles for C2 Operations

    WordPress Malware Abuses Steam Community Profiles for C2 Operations A newly discovered malware campaign targeting WordPress websites has raised serious concerns across the web security community. Attackers behind this campaign are using an unexpected method to communicate with infected sites, hiding command instructions inside Steam Community profile comments and turning a popular gaming platform into…

  • Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign

    Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign A single threat actor has been running a fake political persona on Telegram for five years, quietly building an audience of over 17,000 subscribers while using stolen AI credentials to power the entire operation. What looks like an American patriot channel is actually…

  • Attackers Abuse AWS, Google Cloud, Cloudflare, and Microsoft Services to Hide Malicious Traffic

    Attackers Abuse AWS, Google Cloud, Cloudflare, and Microsoft Services to Hide Malicious Traffic Cybercriminals are increasingly weaponizing trusted cloud infrastructure, including Amazon Web Services, Google Cloud, Microsoft Azure, Cloudflare, and GitHub, to camouflage malicious traffic, evade detection, and sustain long-lived Command and Control (C2) operations. A recent threat intelligence investigation using ANY.RUN’s Threat Intelligence (TI)…

  • Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content

    Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gaining control of victims’ systems. The Minecraft-focused malware-as-a-service (MaaS) campaign has been codenamed Weedhack by McAfee Labs, stating the activity has been active since January 2026…

  • Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited

    Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active exploitation. Tracked as CVE-2025-48595 (CVSS score: 8.4), the security flaw has…

  • Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

    Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation. Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR, to…

  • Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation

    Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerability, CVE-2024-21182 (CVSS score: 7.5), allows an unauthenticated attacker with network access…

  • AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.

    AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It. AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in the history of enterprise security. As a result, the window between a vulnerability being disclosed and indiscriminate exploitation observed…

  • Pointing a Cursor at evading detection

    Pointing a Cursor at evading detection AI accelerated tool development and testing, but humans drove the workflow Categories: Threat Research Tags: AI, EDR Go to sophos

  • The Intersection of Encryption and AI

    The Intersection of Encryption and AI As part of their 20th Anniversary celebration, Dark Reading asked five cybersecurity industry leaders who wrote blogs or columns for them over the years to select their favorite piece and share their reflections on the topic today. This is my section. Renowned technologist and author Bruce Schneier contributed a…

  • Microsoft Threatening Security Researcher

    Microsoft Threatening Security Researcher An anonymous security researcher called “Nightmare Eclipse” has been publishing a series of significant security exploits against Microsoft Windows—including one that breaks BitLocker. Microsoft has threatened legal action against the researcher. Lots of recriminations are being traded back and forth. Bruce Schneier Go to bruce schneier

  • 175: Bayrob

    175: Bayrob It started with a fake car listing on eBay. What looked like a simple online scam quietly grew, over more than a decade, into one of the most sophisticated cybercrime operations the FBI had ever traced. Custom malware. Opsec off the charts. Fleets of infected computers mining cryptocurrency for someone else. Millions of…

  • Zoom CISO: AI as Security Enabler, Not Role-Replacer

    Zoom CISO: AI as Security Enabler, Not Role-Replacer As Zoom’s CISO, Sandra McLeod, discusses the challenges of securing a global communication platform, the promise of AI-driven security workflows, and advice for aspiring cybersecurity leaders. Kristina Beek Go to gbhackers.com

  • FBI-Flagged Phishing Kit Kali365 Expands Its Reach

    FBI-Flagged Phishing Kit Kali365 Expands Its Reach Once targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing. Jai Vijayan Go to gbhackers.com

  • DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks

    DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks A sneaky, wide-scale IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware. Elizabeth Montalbano Go to gbhackers.com

  • China Uses Dual-Method Cyberattack on Czech Orgs

    China Uses Dual-Method Cyberattack on Czech Orgs China is stealing data from high-value targets via a sneaky, double-layer spear-phishing campaign that includes the Azureveil malware. Alexander Culafi Go to gbhackers.com

  • Securing AI Agents Before They Go Rogue Is Next to Impossible

    Securing AI Agents Before They Go Rogue Is Next to Impossible High-autonomy agents with broad permissions and unfettered access are a recipe for disaster, and enterprises need to act now before they become the next horror story. Rob Wright Go to gbhackers.com

  • Beyond Assume-Breach: How AI-Native Security Will Reshape Enterprise Defense

    Beyond Assume-Breach: How AI-Native Security Will Reshape Enterprise Defense Twenty years after Dark Reading launched, we’re looking ahead at what’s next for enterprise security. Spoiler: It’s hyper-segmented, AI-orchestrated, and way more sophisticated than your dad’s firewall. Fahmida Y. Rashid, Tara Seals Go to gbhackers.com

  • Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks

    Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites. […] Bill Toulas Go to bleepingcomputer

  • Red Hat npm packages compromised to steal developer credentials

    Red Hat npm packages compromised to steal developer credentials More than 30 npm packages under Red Hat’s ‘@redhat-cloud-services’ namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud credential-stealing malware, dubbed “Miasma.” […] Lawrence Abrams Go to bleepingcomputer

  • Spain arrests doxer leaking sensitive data of govt employees

    Spain arrests doxer leaking sensitive data of govt employees The Spanish National Police has arrested an individual for leaking sensitive information related to members of various key state organizations, including the National Cybersecurity Institute (INCIBE). […] Bill Toulas Go to bleepingcomputer

  • Dashlane password manager users locked out by brute force attacks

    Dashlane password manager users locked out by brute force attacks Multiple Dashlane users have been locked out of their accounts following brute-force attacks that attempted logins from distant locations and unknown devices. […] Bill Toulas Go to bleepingcomputer

  • WordPress malware campaign hides payloads in Steam profiles

    WordPress malware campaign hides payloads in Steam profiles Nearly 2,000 WordPress websites were infected with malware that relies on Steam Community profile comments to hide command-and-control (C2) data. […] Bill Toulas Go to bleepingcomputer

  • Nimbus Manticore APT Abuses Fake Recruitment Portal to Deliver Custom Malware

    Nimbus Manticore APT Abuses Fake Recruitment Portal to Deliver Custom Malware A state-linked hacking group has been caught running a carefully crafted fake recruitment operation to push custom malware onto unsuspecting victims. The group, known as Nimbus Manticore and also tracked as UNC1549 and Smoke Sandstorm, has a long history of targeting professionals in the…

  • Android 0-Day Vulnerability Exploited in Attacks to Gain Complete Device Control

    Android 0-Day Vulnerability Exploited in Attacks to Gain Complete Device Control A critical Android zero-day vulnerability is being actively exploited in targeted attacks, allowing threat actors to gain near-complete control over affected devices without any user interaction. The flaw, tracked as CVE-2025-48595, was highlighted in the June 2026 Android Security Bulletin, where Google confirmed limited…

  • Critical StrongDM Vulnerability Allows Attackers to Steal and Reuse Authentication

    Critical StrongDM Vulnerability Allows Attackers to Steal and Reuse Authentication A critical authentication flaw in StrongDM’s desktop application has been identified that allows attackers to hijack user sessions by reusing locally stored authentication material, potentially exposing sensitive enterprise infrastructure. The issue, tracked as CVE-2026-4387, was discovered by SpecterOps during a security assessment and has been…

  • Dashlane Password Manager User Accounts Locked Following Brute-Force Attacks

    Dashlane Password Manager User Accounts Locked Following Brute-Force Attacks Dashlane has disclosed a security incident involving a large-scale brute-force attack targeting user accounts, beginning on May 31, 2026. According to the company, an external threat actor attempted to bypass two-factor authentication (2FA) protections by repeatedly guessing authentication codes to register unauthorized devices on victims’ accounts.…

  • Gamaredon APT Hides Malware in Windows Features and Abuses Cloud Platforms for C2

    Gamaredon APT Hides Malware in Windows Features and Abuses Cloud Platforms for C2 Gamaredon, a Russian state-backed espionage group, is deploying a new VBScript worm that hides inside native Windows features while using popular cloud services as covert command-and-control (C2) channels in an ongoing campaign against Ukrainian targets. The operation showcases a modular toolset built…

  • Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

    Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded Password manager Dashlane has disclosed that “fewer than” 20 users on the personal subscription plan had their encrypted vaults downloaded following a brute-force attack launched by an unknown party. On May 31, 2026, the company said an “external” threat actor launched a brute-force…

  • Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

    Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. “This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution,…

  • ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

    ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some “patched-ish” thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing…

  • China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan

    China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent. According to Seqrite Labs, targets of the campaign include government, research, academic, technology, and financial services…

  • The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools

    The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools Three years ago, the practical question for an MSP building a cybersecurity practice was which “vCISO platform” to buy. The term was good shorthand for the work at the time: assessments, advisory, reporting, maybe a compliance module bolted on the side. The work has…

  • Vulnerability Disclosure in the Age of AI

    Vulnerability Disclosure in the Age of AI New article: “Responsible Disclosure in the Age of AI: A Call for Urgent Action,” by Melissa Hathaway. Abstract: Artificial intelligence is fundamentally reshaping the balance between vulnerability discovery and remediation. Frontier AI models are now capable of autonomously identifying exploitable software vulnerabilities at unprecedented speed and scale. This…

  • ISC Stormcast For Tuesday, June 2nd, 2026 https://isc.sans.edu/podcastdetail/9954, (Tue, Jun 2nd)

    ISC Stormcast For Tuesday, June 2nd, 2026 https://isc.sans.edu/podcastdetail/9954, (Tue, Jun 2nd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu

  • Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

    Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta’s “AI support assistant” bot into…

  • 1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever

    1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever Today, I loaded the 1,000th data breach into Have I Been Pwned. Reflecting on that milestone number, I pondered how to mark the occasion in writing, and what immediately came to mind was a very simple question: why is it still needed? Especially considering…