Threat Intelligence Vulnerability1 Min Read June 16, 2026 Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post share…
4 Min Read June 16, 2026 China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Cybersecurity researchers have flagged two previously undocumented… Cyber Espionage Malware
3 Min Read June 16, 2026 Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware The North Korean state-sponsored hacking group known as ScarCruft (aka… Cyber Attack Malware
3 Min Read June 15, 2026 Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails A China-linked espionage group hid inside North American medical,… Cyber Espionage Email Security
Malware Supply Chain Attack7 Min Read June 15, 2026 North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster…
Artificial Intelligence Vulnerability4 Min Read June 15, 2026 LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities,…
Enterprise Security Vulnerability3 Min Read June 15, 2026 One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365…
Enterprise Software Vulnerability2 Min Read June 13, 2026 Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct…
Artificial Intelligence National Security3 Min Read June 13, 2026 U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals Anthropic said on Friday it will "abruptly disable" its most advanced artificial intelligence (AI) models, Claude Fable 5 and Mythos 5, for…
Linux Supply Chain Attack5 Min Read June 12, 2026 Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential…
Artificial Intelligence Cybercrime4 Min Read June 12, 2026 Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing Google on Friday said it's pursuing legal action against a Chinese cybercrime network, accusing it of using its Gemini artificial intelligence…
Linux Network Security3 Min Read June 12, 2026 China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux…
Artificial Intelligence Vulnerability3 Min Read June 12, 2026 Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code Cybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into…
Endpoint Security SOC Automation9 Min Read June 12, 2026 Rethinking MDR as Attackers and Defenders Embrace AI For most of the past decade, managed detection and response was the answer to a real problem. Security teams couldn't staff around the clock,…
AI Security Vulnerability2 Min Read June 12, 2026 LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability…
Cybercrime Phishing2 Min Read June 12, 2026 INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator An INTERPOL-led operation last month resulted in the disruption of Sniper Dz, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB…
Cybercrime Dark Web3 Min Read June 12, 2026 Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs Authorities in Europe have disrupted AudiA6, a cryptocurrency laundering service used by ransomware gangs and cybercriminal networks. Europol,…
Data Breach Vulnerability3 Min Read June 11, 2026 ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand…
AI Security Data Security5 Min Read June 11, 2026 New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets Two security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run…
Endpoint Security Vulnerability2 Min Read June 11, 2026 New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day…
Cybercrime Ransomware5 Min Read June 11, 2026 The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate…
Cybersecurity Innovations and Excellence1 Min Read June 11, 2026 Cybersecurity Stars Awards 2026: Winners Announced Across 95 Categories Most good security work is invisible by design. Today is the exception. The 2026 Cybersecurity Stars Awards winners are announced across 95…
Cybersecurity News Hacking News18 Min Read June 11, 2026 ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories It's been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there's…
Artificial Intelligence Threat Intelligence6 Min Read June 11, 2026 AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS. For thirty years, vulnerability management ran on a buffer: the months between when a vulnerability was found and when someone could figure…
Cyber Espionage Supply Chain Attack3 Min Read June 11, 2026 OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack The Vietnam-aligned threat actor known as OceanLotus has been attributed to two distinct campaigns that targeted domestic entities and stock…
Developer Security Software Supply Chain2 Min Read June 11, 2026 GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks GitHub has announced what it said are "breaking changes" coming to npm version 12, one of which turns off install scripts by default to combat…
Botnet Network Security4 Min Read June 10, 2026 China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance Cybersecurity researchers have warned of a "resurgence and expansion" of JDY, a covert network associated with China-nexus state-sponsored…
Patch Management Vulnerability3 Min Read June 10, 2026 Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary…
Open Source Vulnerability2 Min Read June 10, 2026 Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE A high-severity unpatched security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has…
Network Security Vulnerability2 Min Read June 10, 2026 CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new vulnerabilities to its Known Exploited…
Pentesting Security Validation2 Min Read June 10, 2026 Your Automated Pentest Looks Clean. See What It Missed in This Expert Webinar Your pentest report looks clean. That might be the problem. Run automated pentesting long enough, and the new findings start to dry up. By the…
Vulnerability Zero-Day4 Min Read June 10, 2026 Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs Microsoft on Tuesday released fixes for a record 206 security vulnerabilities impacting its software portfolio, including three flaws that…
AI Safety Artificial Intelligence6 Min Read June 10, 2026 Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards On June 9, Anthropic released Claude Fable 5, the most capable model it has ever made, generally available. It also did something unusual: it…
Cyber Attack Vulnerability1 Min Read June 10, 2026 ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances ServiceNow has warned about a security incident in which unknown threat actors exploited a flaw to obtain deeper unauthorized access to…
Vulnerability Zero-Day3 Min Read June 10, 2026 Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows The anonymous security researcher going by the name Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit for…
JavaScript Vulnerability3 Min Read June 10, 2026 Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS Cybersecurity researchers have flagged half a dozen vulnerabilities in protobuf.js, a JavaScript and TypeScript implementation of Protocol…
Artificial Intelligence Privacy2 Min Read June 9, 2026 Meta to Use Off-Site Business Data for Feed and AI Personalization Meta on Tuesday announced that it will use information shared by other businesses to personalize users' feed and responses from its artificial…
Backup Software Vulnerability1 Min Read June 9, 2026 Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code Veeam has released security patches to address a critical flaw in its Backup & Replication software that could result in remote code…
AI Security Software Supply Chain3 Min Read June 9, 2026 Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues Microsoft on Monday confirmed that it temporarily removed some GitHub repositories in response to a recent security incident that led to 73 of…
Cyber Espionage Vulnerability2 Min Read June 9, 2026 WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year…
Artificial Intelligence Network Security6 Min Read June 9, 2026 Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models University of Toronto researchers have built and tested a proof-of-concept AI-driven computer worm that uses a locally hosted open-weight…
Browser Security Vulnerability1 Min Read June 9, 2026 Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild – Patch Now Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The…
Artificial Intelligence Security Automation4 Min Read June 9, 2026 The Hidden Security Risk in Modern Networks: The Work Between Tools Organizations have more visibility than ever. Growing tech stacks provide greater coverage, and network security teams are increasingly…
Browser Security Privacy4 Min Read June 9, 2026 New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing A malicious website can work out which sites you visit and which apps you open, using nothing but JavaScript and the timing of your SSD. The…
Malware Supply Chain Attack4 Min Read June 9, 2026 Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19…
Linux Vulnerability3 Min Read June 8, 2026 One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public Security researchers have published a detailed, working exploit for a Linux kernel use-after-free that lets an unprivileged local user…