Ad Fraud Browser Security3 Min Read June 29, 2026 Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts Microsoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary image and font files,…
3 Min Read June 29, 2026 Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw A public proof-of-concept is now out for CVE-2026-55200, a critical flaw… Open Source Vulnerability
3 Min Read June 29, 2026 Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer Cybersecurity researchers have uncovered two hijacked npm packages and a… Cryptocurrency Supply Chain Attack
2 Min Read June 27, 2026 Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials The Security Service of Ukraine (SSU) said it, together with the U.S.… Cyber Espionage Messaging Security
Artificial Intelligence Vulnerability Research3 Min Read June 27, 2026 OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards OpenAI on Friday released three versions of GPT-5.6, called Sol, Terra, and Luna, as a limited preview to a small number of companies as part…
Secure Messaging Social Engineering2 Min Read June 26, 2026 FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys The FBI and CISA have updated their March warning about Russian intelligence phishing Signal accounts, and the operators have added…
Malware Windows Security4 Min Read June 26, 2026 New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as…
Cyber Espionage Malware3 Min Read June 26, 2026 Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks…
Linux Vulnerability3 Min Read June 26, 2026 New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries A flaw in the Linux kernel's traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331,…
AI Security Vulnerability3 Min Read June 26, 2026 Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was…
Software Security Vulnerability2 Min Read June 26, 2026 CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting…
Linux Vulnerability3 Min Read June 26, 2026 New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit…
AI Security Identity Governance13 Min Read June 26, 2026 Guardian Agents: The Next Layer of Identity Governance AI agents are moving through enterprise environments, inheriting permissions, traversing systems, and executing decisions at machine speed…
Developer Security Supply Chain Attack3 Min Read June 26, 2026 Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades…
Malware Phishing2 Min Read June 26, 2026 Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using…
Digital Forensics Mobile Security3 Min Read June 26, 2026 Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff Russian authorities used Cellebrite's UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June…
Cyber Espionage Malware4 Min Read June 26, 2026 Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that…
Browser Security Malware4 Min Read June 25, 2026 Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code.…
Cybersecurity News Hacking News11 Min Read June 25, 2026 ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old…
Artificial Intelligence Threat Hunting4 Min Read June 25, 2026 Surviving the Mythos Era: Richard Bejtlich on the Case for NDR Despite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during…
AI Security Malware2 Min Read June 25, 2026 New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to…
Initial Access Broker Ransomware3 Min Read June 25, 2026 New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new, stealthy backdoor named Mistic has been deployed as part of suspected financially motivated attacks aimed at multiple organizations…
Threat Intelligence Vulnerability3 Min Read June 25, 2026 Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two…
Network Security Vulnerability2 Min Read June 24, 2026 CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw…
Cybercrime Law Enforcement5 Min Read June 24, 2026 Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft,…
Open Source Supply Chain Security2 Min Read June 24, 2026 Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise…
Network Security Vulnerability Management4 Min Read June 24, 2026 Dawn of the Apex Agentic Adversary We are standing at the end of an era we never thought to mourn: the era of human-speed threats. For years, cybersecurity moved to a rhythm…
Cybercrime Money Laundering3 Min Read June 24, 2026 DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by subsidiaries of…
Network Security Vulnerability2 Min Read June 24, 2026 Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM)…
Firewall Security Initial Access Broker6 Min Read June 23, 2026 FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation…
Enterprise Security Supply Chain Security4 Min Read June 23, 2026 Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it…
Cryptography Quantum Computing3 Min Read June 23, 2026 Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration President Trump signed an executive order on June 22 setting hard deadlines for federal agencies to move high-value assets and…
Software Supply Chain Workflow Security3 Min Read June 23, 2026 GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the…
Cybersecurity Training Offensive AI7 Min Read June 23, 2026 Agentic AI: The Weapon That No Longer Needs a Warrior Every weapon begins as an extension of the hand that holds it. The spear lengthened the reach of the arm. The bow sent the point flying…
Developer Security Supply Chain Attack3 Min Read June 23, 2026 Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan…
Malware Social Engineering2 Min Read June 23, 2026 WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of…
Artificial Intelligence Codex Security4 Min Read June 23, 2026 OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak…
Malware Supply Chain Attack2 Min Read June 22, 2026 ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the…
AI Security Vulnerability2 Min Read June 22, 2026 Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than…
Server Security Vulnerability3 Min Read June 22, 2026 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it…
Endpoint Security Malvertising2 Min Read June 22, 2026 New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware…
Mobile Security Open Source3 Min Read June 22, 2026 Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries Google has set September 30, 2026, as the day it begins enforcing Android developer verification in the first four countries, and…
AI Security Exposure Management5 Min Read June 22, 2026 Stop Your Legacy Infrastructure from Hijacking Your AI Agents Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not…
Cybersecurity Hacking18 Min Read June 22, 2026 ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More It’s Monday again. This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites,…
Cyber Espionage IoT Security3 Min Read June 22, 2026 Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and…
IoT Security Vulnerability3 Min Read June 22, 2026 AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices…