AI Security Malware2 Min Read June 25, 2026 New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware …
3 Min Read June 25, 2026 New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new, stealthy backdoor named Mistic has been deployed as part of… Initial Access Broker Ransomware
3 Min Read June 25, 2026 Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access An unknown threat actor exploited a recently disclosed high-severity… Threat Intelligence Vulnerability
2 Min Read June 24, 2026 CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on… Network Security Vulnerability
Cybercrime Law Enforcement5 Min Read June 24, 2026 Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft,…
Cybercrime Money Laundering3 Min Read June 24, 2026 DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by subsidiaries of…
Network Security Vulnerability2 Min Read June 24, 2026 Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM)…
Firewall Security Initial Access Broker6 Min Read June 23, 2026 FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation…
Enterprise Security Supply Chain Security4 Min Read June 23, 2026 Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it…
Cryptography Quantum Computing3 Min Read June 23, 2026 Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration President Trump signed an executive order on June 22 setting hard deadlines for federal agencies to move high-value assets and…
Software Supply Chain Workflow Security3 Min Read June 23, 2026 GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the…
Cybersecurity Training Offensive AI7 Min Read June 23, 2026 Agentic AI: The Weapon That No Longer Needs a Warrior Every weapon begins as an extension of the hand that holds it. The spear lengthened the reach of the arm. The bow sent the point flying…
Developer Security Supply Chain Attack3 Min Read June 23, 2026 Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan…
Malware Social Engineering2 Min Read June 23, 2026 WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of…
Artificial Intelligence Codex Security4 Min Read June 23, 2026 OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak…
Malware Supply Chain Attack2 Min Read June 22, 2026 ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the…
AI Security Vulnerability2 Min Read June 22, 2026 Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than…
Server Security Vulnerability3 Min Read June 22, 2026 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it…
Endpoint Security Malvertising2 Min Read June 22, 2026 New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware…
Mobile Security Open Source3 Min Read June 22, 2026 Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries Google has set September 30, 2026, as the day it begins enforcing Android developer verification in the first four countries, and…
AI Security Exposure Management5 Min Read June 22, 2026 Stop Your Legacy Infrastructure from Hijacking Your AI Agents Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not…
Cybersecurity Hacking18 Min Read June 22, 2026 ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More It’s Monday again. This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites,…
Cyber Espionage IoT Security3 Min Read June 22, 2026 Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and…
IoT Security Vulnerability3 Min Read June 22, 2026 AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices…
Artificial Intelligence Cybercrime2 Min Read June 22, 2026 INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific A new report from INTERPOL has revealed a "dramatic increase" in cybercrime in Asia and the South Pacific, fueled by rapid digitalization,…
Vulnerability Web Security2 Min Read June 20, 2026 Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000…
Hardware Security Vulnerability3 Min Read June 19, 2026 Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code…
Endpoint Security Ransomware3 Min Read June 19, 2026 The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR)…
Software Supply Chain Vulnerability3 Min Read June 19, 2026 AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote…
Malware Threat Intelligence5 Min Read June 19, 2026 Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure…
Firewall Security Threat Intelligence3 Min Read June 19, 2026 CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps…
Agentic AI Enterprise Security4 Min Read June 19, 2026 From Assistive to Agentic: The AI Shift That's Redefining Threat Management Introduction The average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset…
Agentic AI SaaS Security4 Min Read June 19, 2026 Forget Data Leakage: Shadow AI's Real Threat Is Access Control The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security…
Cloud Security Data Breach3 Min Read June 19, 2026 Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting…
Mobile Security Vulnerability3 Min Read June 19, 2026 Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to…
Cloud Security Vulnerability2 Min Read June 18, 2026 F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution…
AI Security Data Security2 Min Read June 18, 2026 Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network If an autonomous AI agent interacts with your company's core intellectual property today, can your security team instantly name the person who…
Cybersecurity News Hacking News15 Min Read June 18, 2026 ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons.…
Cryptocurrency Malware2 Min Read June 18, 2026 Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign that has targeted users since February 2026 with…
Enterprise Security Vulnerability3 Min Read June 18, 2026 INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023 Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most…
Ransomware Remote Access Trojan3 Min Read June 18, 2026 DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called…
Compliance Payment Security2 Min Read June 18, 2026 The Scripts on Your Checkout Page Are Now a PCI DSS Problem An independent PCI assessor tested Reflectiz against the new PCI DSS rules. Here is the verdict: See the full QSA assessment here → When…
Malware Social Engineering2 Min Read June 17, 2026 Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez,…
Endpoint Security Vulnerability1 Min Read June 17, 2026 Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability…
Cyber Attack Malware4 Min Read June 17, 2026 Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials.…
Adversarial Exposure Validation5 Min Read June 17, 2026 Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization For security teams, the findings never stop, but confidence in knowing which ones matter is becoming harder to maintain. The problem is no…