Developer Security Supply Chain Attack3 Min Read June 23, 2026 Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan (RAT). The lis…
2 Min Read June 23, 2026 WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool Direct messages sent via WhatsApp are being used to distribute malicious… Malware Social Engineering
4 Min Read June 23, 2026 OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws OpenAI on Monday said it's releasing an improved version of its… Artificial Intelligence Codex Security
2 Min Read June 22, 2026 ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack Multiple WordPress plugins from ShapedPlugin were compromised in a… Malware Supply Chain Attack
AI Security Vulnerability2 Min Read June 22, 2026 Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than…
Cyber Espionage IoT Security3 Min Read June 22, 2026 Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and…
IoT Security Vulnerability3 Min Read June 22, 2026 AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices…
Artificial Intelligence Cybercrime2 Min Read June 22, 2026 INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific A new report from INTERPOL has revealed a "dramatic increase" in cybercrime in Asia and the South Pacific, fueled by rapid digitalization,…
Vulnerability Web Security2 Min Read June 20, 2026 Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000…
Hardware Security Vulnerability3 Min Read June 19, 2026 Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code…
Endpoint Security Ransomware3 Min Read June 19, 2026 The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR)…
Software Supply Chain Vulnerability3 Min Read June 19, 2026 AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote…
Malware Threat Intelligence5 Min Read June 19, 2026 Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure…
Firewall Security Threat Intelligence3 Min Read June 19, 2026 CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps…
Agentic AI Enterprise Security4 Min Read June 19, 2026 From Assistive to Agentic: The AI Shift That's Redefining Threat Management Introduction The average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset…
Agentic AI SaaS Security4 Min Read June 19, 2026 Forget Data Leakage: Shadow AI's Real Threat Is Access Control The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security…
Cloud Security Data Breach3 Min Read June 19, 2026 Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting…
Mobile Security Vulnerability3 Min Read June 19, 2026 Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to…
Cloud Security Vulnerability2 Min Read June 18, 2026 F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution…
AI Security Data Security2 Min Read June 18, 2026 Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network If an autonomous AI agent interacts with your company's core intellectual property today, can your security team instantly name the person who…
Cybersecurity News Hacking News15 Min Read June 18, 2026 ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons.…
Cryptocurrency Malware2 Min Read June 18, 2026 Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign that has targeted users since February 2026 with…
Enterprise Security Vulnerability3 Min Read June 18, 2026 INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023 Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most…
Ransomware Remote Access Trojan3 Min Read June 18, 2026 DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called…
Compliance Payment Security2 Min Read June 18, 2026 The Scripts on Your Checkout Page Are Now a PCI DSS Problem An independent PCI assessor tested Reflectiz against the new PCI DSS rules. Here is the verdict: See the full QSA assessment here → When…
Malware Social Engineering2 Min Read June 17, 2026 Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez,…
Endpoint Security Vulnerability1 Min Read June 17, 2026 Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability…
Cyber Attack Malware4 Min Read June 17, 2026 Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials.…
Adversarial Exposure Validation5 Min Read June 17, 2026 Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization For security teams, the findings never stop, but confidence in knowing which ones matter is becoming harder to maintain. The problem is no…
Attack Surface Management3 Min Read June 17, 2026 The Top 10 Attack Surface Exposures in 2026 Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But…
AI Security Supply Chain Security3 Min Read June 17, 2026 Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats Cybersecurity researchers have flagged a "coordinated malware campaign" on the JetBrains Marketplace that has published no less than 15…
Cryptocurrency Malware3 Min Read June 17, 2026 144 Mastra npm Packages Compromised via Hijacked Contributor Account As many as 144 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for…
Supply Chain Attack Vulnerability2 Min Read June 17, 2026 CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory…
Cloud Security machine learning3 Min Read June 16, 2026 Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning…
Endpoint Security Malware6 Min Read June 16, 2026 ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures Cybersecurity researchers have flagged multiple ClickFix campaigns that deliver three malware loaders called BabaDeda Loader, Lorem Ipsum…
Malware Mobile Security2 Min Read June 16, 2026 New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds Security researchers at Zimperium's zLabs have documented a new Android banking trojan, Rokarolla, that targets 217 banking and…
Threat Intelligence Zero Trust4 Min Read June 16, 2026 Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive Security teams have never had more IP data at their disposal. Every day, analysts ingest enrichment feeds, geolocation data, reputation…
Threat Intelligence Vulnerability1 Min Read June 16, 2026 Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In…
Cyber Espionage Malware4 Min Read June 16, 2026 China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called…
Cyber Attack Malware3 Min Read June 16, 2026 Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating…
Network Security Vulnerability2 Min Read June 16, 2026 Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in…
Server Security Vulnerability2 Min Read June 16, 2026 CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known…
Cyber Espionage Email Security3 Min Read June 15, 2026 Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly…
Malware Supply Chain Attack7 Min Read June 15, 2026 North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster…
Artificial Intelligence Vulnerability4 Min Read June 15, 2026 LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities,…
Enterprise Security Vulnerability3 Min Read June 15, 2026 One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365…