Cybercrime Money Laundering3 Min Read June 24, 2026 DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by subsidiaries of Cambodia-based corporate …
2 Min Read June 24, 2026 Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root Threat actors have begun to exploit a recently disclosed critical… Network Security Vulnerability
6 Min Read June 23, 2026 FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation A Russian-speaking initial access broker (IAB) driven by financial gain… Firewall Security Initial Access Broker
4 Min Read June 23, 2026 Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents Security firm AIR built a fake AI agent skill, pushed it… Enterprise Security Supply Chain Security
Developer Security Supply Chain Attack3 Min Read June 23, 2026 Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan…
Malware Social Engineering2 Min Read June 23, 2026 WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of…
Artificial Intelligence Codex Security4 Min Read June 23, 2026 OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak…
Malware Supply Chain Attack2 Min Read June 22, 2026 ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the…
AI Security Vulnerability2 Min Read June 22, 2026 Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than…
Server Security Vulnerability3 Min Read June 22, 2026 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it…
Endpoint Security Malvertising2 Min Read June 22, 2026 New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware…
Mobile Security Open Source3 Min Read June 22, 2026 Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries Google has set September 30, 2026, as the day it begins enforcing Android developer verification in the first four countries, and…
AI Security Exposure Management5 Min Read June 22, 2026 Stop Your Legacy Infrastructure from Hijacking Your AI Agents Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not…
Cyber Espionage IoT Security3 Min Read June 22, 2026 Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and…
IoT Security Vulnerability3 Min Read June 22, 2026 AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices…
Artificial Intelligence Cybercrime2 Min Read June 22, 2026 INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific A new report from INTERPOL has revealed a "dramatic increase" in cybercrime in Asia and the South Pacific, fueled by rapid digitalization,…
Vulnerability Web Security2 Min Read June 20, 2026 Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000…
Hardware Security Vulnerability3 Min Read June 19, 2026 Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code…
Endpoint Security Ransomware3 Min Read June 19, 2026 The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR)…
Software Supply Chain Vulnerability3 Min Read June 19, 2026 AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote…
Malware Threat Intelligence5 Min Read June 19, 2026 Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure…
Firewall Security Threat Intelligence3 Min Read June 19, 2026 CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps…
Agentic AI Enterprise Security4 Min Read June 19, 2026 From Assistive to Agentic: The AI Shift That's Redefining Threat Management Introduction The average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset…
Agentic AI SaaS Security4 Min Read June 19, 2026 Forget Data Leakage: Shadow AI's Real Threat Is Access Control The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security…
Cloud Security Data Breach3 Min Read June 19, 2026 Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting…
Mobile Security Vulnerability3 Min Read June 19, 2026 Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to…
Cloud Security Vulnerability2 Min Read June 18, 2026 F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution…
AI Security Data Security2 Min Read June 18, 2026 Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network If an autonomous AI agent interacts with your company's core intellectual property today, can your security team instantly name the person who…
Cybersecurity News Hacking News15 Min Read June 18, 2026 ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons.…
Cryptocurrency Malware2 Min Read June 18, 2026 Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign that has targeted users since February 2026 with…
Enterprise Security Vulnerability3 Min Read June 18, 2026 INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023 Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most…
Ransomware Remote Access Trojan3 Min Read June 18, 2026 DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called…
Compliance Payment Security2 Min Read June 18, 2026 The Scripts on Your Checkout Page Are Now a PCI DSS Problem An independent PCI assessor tested Reflectiz against the new PCI DSS rules. Here is the verdict: See the full QSA assessment here → When…
Malware Social Engineering2 Min Read June 17, 2026 Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez,…
Endpoint Security Vulnerability1 Min Read June 17, 2026 Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability…
Cyber Attack Malware4 Min Read June 17, 2026 Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials.…
Adversarial Exposure Validation5 Min Read June 17, 2026 Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization For security teams, the findings never stop, but confidence in knowing which ones matter is becoming harder to maintain. The problem is no…
Attack Surface Management3 Min Read June 17, 2026 The Top 10 Attack Surface Exposures in 2026 Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But…
AI Security Supply Chain Security3 Min Read June 17, 2026 Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats Cybersecurity researchers have flagged a "coordinated malware campaign" on the JetBrains Marketplace that has published no less than 15…
Cryptocurrency Malware3 Min Read June 17, 2026 144 Mastra npm Packages Compromised via Hijacked Contributor Account As many as 144 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for…
Supply Chain Attack Vulnerability2 Min Read June 17, 2026 CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory…
Cloud Security machine learning3 Min Read June 16, 2026 Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning…
Endpoint Security Malware6 Min Read June 16, 2026 ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures Cybersecurity researchers have flagged multiple ClickFix campaigns that deliver three malware loaders called BabaDeda Loader, Lorem Ipsum…
Malware Mobile Security2 Min Read June 16, 2026 New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds Security researchers at Zimperium's zLabs have documented a new Android banking trojan, Rokarolla, that targets 217 banking and…
Threat Intelligence Zero Trust4 Min Read June 16, 2026 Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive Security teams have never had more IP data at their disposal. Every day, analysts ingest enrichment feeds, geolocation data, reputation…
Threat Intelligence Vulnerability1 Min Read June 16, 2026 Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In…