Agentic AI SaaS Security4 Min Read June 19, 2026 Forget Data Leakage: Shadow AI's Real Threat Is Access Control The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security teams responded…
3 Min Read June 19, 2026 Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data Salesforce has revealed that it disabled the Klue Battlecards app… Cloud Security Data Breach
3 Min Read June 19, 2026 Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone Apple has updated its Beats Studio Buds wireless earbuds to patch a… Mobile Security Vulnerability
2 Min Read June 18, 2026 F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution F5 has released security updates to address two critical security flaws… Cloud Security Vulnerability
AI Security Data Security2 Min Read June 18, 2026 Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network If an autonomous AI agent interacts with your company's core intellectual property today, can your security team instantly name the person who…
Cybersecurity News Hacking News15 Min Read June 18, 2026 ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons.…
Compliance Payment Security2 Min Read June 18, 2026 The Scripts on Your Checkout Page Are Now a PCI DSS Problem An independent PCI assessor tested Reflectiz against the new PCI DSS rules. Here is the verdict: See the full QSA assessment here → When…
Malware Social Engineering2 Min Read June 17, 2026 Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez,…
Endpoint Security Vulnerability1 Min Read June 17, 2026 Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability…
Cyber Attack Malware4 Min Read June 17, 2026 Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials.…
Adversarial Exposure Validation5 Min Read June 17, 2026 Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization For security teams, the findings never stop, but confidence in knowing which ones matter is becoming harder to maintain. The problem is no…
Attack Surface Management3 Min Read June 17, 2026 The Top 10 Attack Surface Exposures in 2026 Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But…
AI Security Supply Chain Security3 Min Read June 17, 2026 Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats Cybersecurity researchers have flagged a "coordinated malware campaign" on the JetBrains Marketplace that has published no less than 15…
Cryptocurrency Malware3 Min Read June 17, 2026 144 Mastra npm Packages Compromised via Hijacked Contributor Account As many as 144 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for…
Supply Chain Attack Vulnerability2 Min Read June 17, 2026 CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory…
Cloud Security machine learning3 Min Read June 16, 2026 Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning…
Endpoint Security Malware6 Min Read June 16, 2026 ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures Cybersecurity researchers have flagged multiple ClickFix campaigns that deliver three malware loaders called BabaDeda Loader, Lorem Ipsum…
Malware Mobile Security2 Min Read June 16, 2026 New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds Security researchers at Zimperium's zLabs have documented a new Android banking trojan, Rokarolla, that targets 217 banking and…
Threat Intelligence Zero Trust4 Min Read June 16, 2026 Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive Security teams have never had more IP data at their disposal. Every day, analysts ingest enrichment feeds, geolocation data, reputation…
Threat Intelligence Vulnerability1 Min Read June 16, 2026 Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In…
Cyber Espionage Malware4 Min Read June 16, 2026 China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called…
Cyber Attack Malware3 Min Read June 16, 2026 Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating…
Network Security Vulnerability2 Min Read June 16, 2026 Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in…
Server Security Vulnerability2 Min Read June 16, 2026 CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known…
Cyber Espionage Email Security3 Min Read June 15, 2026 Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly…
Malware Supply Chain Attack7 Min Read June 15, 2026 North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster…
Artificial Intelligence Vulnerability4 Min Read June 15, 2026 LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities,…
Enterprise Security Vulnerability3 Min Read June 15, 2026 One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365…
Cybersecurity Hacking13 Min Read June 15, 2026 ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running…
Critical Infrastructure Password Security4 Min Read June 15, 2026 The Onboarding Password Mistake That Creates Unnecessary Risk Employee onboarding is a busy time for IT teams. New starters need devices, accounts, access permissions, and passwords, all delivered within…
Enterprise Software Vulnerability2 Min Read June 13, 2026 Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct…
Artificial Intelligence National Security3 Min Read June 13, 2026 U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals Anthropic said on Friday it will "abruptly disable" its most advanced artificial intelligence (AI) models, Claude Fable 5 and Mythos 5, for…
Linux Supply Chain Attack5 Min Read June 12, 2026 Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential…
Artificial Intelligence Cybercrime4 Min Read June 12, 2026 Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing Google on Friday said it's pursuing legal action against a Chinese cybercrime network, accusing it of using its Gemini artificial intelligence…
Linux Network Security3 Min Read June 12, 2026 China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux…
Artificial Intelligence Vulnerability3 Min Read June 12, 2026 Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code Cybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into…
Endpoint Security SOC Automation9 Min Read June 12, 2026 Rethinking MDR as Attackers and Defenders Embrace AI For most of the past decade, managed detection and response was the answer to a real problem. Security teams couldn't staff around the clock,…
AI Security Vulnerability2 Min Read June 12, 2026 LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability…
Cybercrime Phishing2 Min Read June 12, 2026 INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator An INTERPOL-led operation last month resulted in the disruption of Sniper Dz, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB…
Cybercrime Dark Web3 Min Read June 12, 2026 Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs Authorities in Europe have disrupted AudiA6, a cryptocurrency laundering service used by ransomware gangs and cybercriminal networks. Europol,…
Data Breach Vulnerability3 Min Read June 11, 2026 ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand…
AI Security Data Security5 Min Read June 11, 2026 New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets Two security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run…
Endpoint Security Vulnerability2 Min Read June 11, 2026 New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day…
Cybercrime Ransomware5 Min Read June 11, 2026 The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate…
Cybersecurity Innovations and Excellence1 Min Read June 11, 2026 Cybersecurity Stars Awards 2026: Winners Announced Across 95 Categories Most good security work is invisible by design. Today is the exception. The 2026 Cybersecurity Stars Awards winners are announced across 95…
Cybersecurity News Hacking News18 Min Read June 11, 2026 ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories It's been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there's…