Endpoint Security Ransomware3 Min Read June 19, 2026 The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR)…
Software Supply Chain Vulnerability3 Min Read June 19, 2026 AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote…
Cybersecurity News Hacking News15 Min Read June 18, 2026 ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons.…
Cryptocurrency Malware2 Min Read June 18, 2026 Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign that has targeted users since February 2026 with…
Ransomware Remote Access Trojan3 Min Read June 18, 2026 DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called…
Endpoint Security Vulnerability1 Min Read June 17, 2026 Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability…
AI Security Supply Chain Security3 Min Read June 17, 2026 Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats Cybersecurity researchers have flagged a "coordinated malware campaign" on the JetBrains Marketplace that has published no less than 15…
Endpoint Security Malware6 Min Read June 16, 2026 ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures Cybersecurity researchers have flagged multiple ClickFix campaigns that deliver three malware loaders called BabaDeda Loader, Lorem Ipsum…
Cyber Espionage Malware4 Min Read June 16, 2026 China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called…
Cyber Attack Malware3 Min Read June 16, 2026 Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating…
Malware Supply Chain Attack7 Min Read June 15, 2026 North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster…
Enterprise Security Vulnerability3 Min Read June 15, 2026 One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365…
Cybersecurity Hacking13 Min Read June 15, 2026 ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running…
Linux Supply Chain Attack5 Min Read June 12, 2026 Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential…
Data Breach Vulnerability3 Min Read June 11, 2026 ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand…
AI Security Data Security5 Min Read June 11, 2026 New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets Two security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run…
Endpoint Security Vulnerability2 Min Read June 11, 2026 New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day…
Cybercrime Ransomware5 Min Read June 11, 2026 The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate…
Cybersecurity News Hacking News18 Min Read June 11, 2026 ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories It's been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there's…
Cyber Espionage Supply Chain Attack3 Min Read June 11, 2026 OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack The Vietnam-aligned threat actor known as OceanLotus has been attributed to two distinct campaigns that targeted domestic entities and stock…
Developer Security Software Supply Chain2 Min Read June 11, 2026 GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks GitHub has announced what it said are "breaking changes" coming to npm version 12, one of which turns off install scripts by default to combat…
Vulnerability Zero-Day4 Min Read June 10, 2026 Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs Microsoft on Tuesday released fixes for a record 206 security vulnerabilities impacting its software portfolio, including three flaws that…
Vulnerability Zero-Day3 Min Read June 10, 2026 Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows The anonymous security researcher going by the name Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit for…
AI Security Software Supply Chain3 Min Read June 9, 2026 Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues Microsoft on Monday confirmed that it temporarily removed some GitHub repositories in response to a recent security incident that led to 73 of…
Cyber Espionage Vulnerability2 Min Read June 9, 2026 WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year…
Browser Security Vulnerability1 Min Read June 9, 2026 Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild – Patch Now Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The…
Malware Supply Chain Attack4 Min Read June 9, 2026 Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19…
Artificial Intelligence Incident Response5 Min Read June 8, 2026 AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload Phishing has always been a numbers game. AI has turned it into a volume machine. Attackers can now create convincing emails, fake login pages,…
Cybersecurity Hacking14 Min Read June 8, 2026 ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More Monday again. The weekend was meant to be quiet. It wasn't. Last week had poisoned packages, a broken AI helper, and a worm tearing through…
Cyber Espionage Malware3 Min Read June 8, 2026 VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other…
Cyber Crime Social Engineering4 Min Read June 8, 2026 UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of…
Malware Software Supply Chain2 Min Read June 8, 2026 VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks Microsoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development…
Malware Supply Chain Attack3 Min Read June 6, 2026 Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack Microsoft's GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The…
Malware Software Supply Chain5 Min Read June 5, 2026 IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50…
Cyber Espionage Threat Intelligence3 Min Read June 5, 2026 New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework Cybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 (where "OP" stands for "opponent") that has…
Cloud Security Threat Intelligence3 Min Read June 5, 2026 PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network The threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to…
AI Security Vulnerability4 Min Read June 4, 2026 Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories A security researcher found a flaw in Anthropic's Claude Code GitHub Action that let an attacker take over vulnerable public repositories…
Cybersecurity News Hacking News13 Min Read June 4, 2026 ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories It got stupid again. The internet still feels held together with tape. Bad plugins, old bugs, fake tools, trusted apps doing shady things.…
Cybercrime Malware2 Min Read June 4, 2026 China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany,…
Cyber Espionage Malware3 Min Read June 4, 2026 Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months Unknown attackers spent at least five months inside the Outlook mailbox of a senior executive at a major global stock exchange, copying the…
Cryptocurrency Law Enforcement3 Min Read June 4, 2026 DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets The U.S. Department of Justice (DoJ) on Wednesday announced the results of a sweeping action undertaken by government authorities and private…
Malware Microsoft Defender3 Min Read June 3, 2026 Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT Cybersecurity researchers have flagged a new malspam campaign that makes use of Google's DoubleClick domain as a way to evade detection and…