threat-intel FortiBleed campaign used custom FortiGate sniffer to steal credentials The FortiBleed campaign, targeting Fortinet FortiGate devices, utilized a custom Golang tool called "FortigateSniffer" to steal credentials from compromised firewalls. This campaign, active since at least February 2026,… BleepingComputer · Jun 22, 2026 Critical UScredential theftfirewallgpu cracking
supply-chain ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack A supply chain attack compromised multiple WordPress plugins from ShapedPlugin, injecting backdoor code into Pro plugin releases distributed through official update channels. The malicious plugins, affecting versions of… The Hacker News · Jun 22, 2026 Critical CVE-2026-49777CVE-2026-10735wordpresssupply chainbackdoor
threat-intel Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants Researchers have identified four critical vulnerabilities in the open-source Dify agentic workflow platform, dubbed DifyTap, allowing unauthorized access to AI conversations and data across tenants. These flaws include a… The Hacker News · Jun 22, 2026 Critical CVE-2024-5846CVE-2026-41947CVE-2026-41948aivulnerabilitytenant
threat-intel Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign A sophisticated cybercrime campaign, orchestrated by unknown threat actors, is utilizing a multi-channel approach to distribute a cross-platform clipboard hijacker designed to steal cryptocurrency. The campaign leverages… Dark Reading · Jun 22, 2026 High USclipboard hijackingreputation manipulationcrypto theft
threat-intel Stop Your Legacy Infrastructure from Hijacking Your AI Agents This article highlights a significant security risk: attackers leveraging legacy infrastructure to compromise AI agent environments. Despite organizations investing heavily in securing AI workloads against direct attacks… The Hacker News · Jun 22, 2026 High CVE-2025-24813USailegacypermissions
malware A VBScript campaign distributed through WhatsApp deploying RMM software A WhatsApp-distributed malware campaign, active as of June 2026, leverages deceptive VBScript files disguised as financial documents to trick users into executing malicious code. This code ultimately installs legitimate… Securelist · Jun 22, 2026 High MYBRINsocial engineeringvbswhatsapp
threat-intel AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network A new malware family, dubbed AryStinger, is exploiting vulnerabilities in older Realtek RTL819X routers to create a reconnaissance network. Approximately 4,300 routers, primarily D-Link models, have been infected, scanni… The Hacker News · Jun 22, 2026 Medium CVE-2013-3307CVE-2016-5681CVE-2025-11837KRCNSEreconnaissanceproxyiot
vulnerability Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys A vulnerability in the Gravity SMTP WordPress plugin has been exploited by attackers, allowing them to extract sensitive data such as API keys and configuration details from approximately 100,000 sites. The flaw, tracked… The Hacker News · Jun 20, 2026 Medium CVE-2026-4020USwordpressapicredentials
vulnerability Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin Hackers are actively exploiting a vulnerability in the Gravity SMTP WordPress plugin, allowing them to access sensitive information such as API keys and email service credentials. This flaw, tracked as CVE-2026-4020, has… BleepingComputer · Jun 19, 2026 Medium CVE-2026-4020CVE-2026-8713wordpressapicredentials
threat-intel AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Researchers at Microsoft have identified a vulnerability, dubbed AutoJack, within the AutoGen Studio prototyping interface for their AutoGen multi-agent framework. The flaw allows an attacker to hijack an AI browsing age… The Hacker News · Jun 19, 2026 High CVE-2026-26030CVE-2026-25592remote code executionai agentlocalhost
vulnerability In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum This week’s cybersecurity news highlights several significant vulnerabilities and attacks across various platforms and industries. A critical phpBB flaw enabled session hijacking, while vulnerabilities in Chrome extensio… SecurityWeek · Jun 19, 2026 High CVE-2025-20701CHISsession hijackingchrome extensionssupply chain attack
threat-intel Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way This article highlights a growing security risk within organizations due to the widespread adoption of AI agents. Traditional identity security models, built around controlling employee and service accounts, are being by… BleepingComputer · Jun 19, 2026 High aiartificial intelligenceidentity management
threat-intel From Assistive to Agentic: The AI Shift That's Redefining Threat Management This article discusses the shift in cybersecurity necessitated by the rapid advancements in AI, particularly frontier AI models. Traditional security architectures, reliant on manual processes and siloed tools, are strug… The Hacker News · Jun 19, 2026 High USaictemthreat intelligence
threat-intel Forget Data Leakage: Shadow AI's Real Threat Is Access Control This article highlights a shift in the security landscape surrounding AI, moving beyond simple data leakage concerns to a more critical issue of access control. Employees are increasingly deploying custom AI agents acros… The Hacker News · Jun 19, 2026 High USaishadow itaccess control
threat-intel Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone A vulnerability in Apple’s Beats Studio Buds firmware allowed nearby attackers to potentially eavesdrop on users via the device’s microphone. The flaw, tracked as CVE-2025-20701, stemmed from incorrect authorization with… The Hacker News · Jun 19, 2026 Critical CVE-2025-20701CVE-2025-20700CVE-2025-20702GEbluetoothmicrophonesecurerom
threat-intel Get Out of Security Debt by Tackling the Exposure Problem This Dark Reading article discusses the growing problem of ‘security debt’ – vulnerabilities that remain open in systems for extended periods. It argues that organizations need to shift their focus from simply tracking a… Dark Reading · Jun 18, 2026 High risk managementvulnerability managementsecurity debt
threat-intel EU Gets a Head Start in Developing 6G Network Security The EU is launching the "Shield-6G" project, a collaborative initiative funded by the EU, to proactively develop cybersecurity measures for the upcoming 6G network. This project, involving 19 organizations, aims to addre… Dark Reading · Jun 18, 2026 Medium EU6gaicybersecurity
threat-intel Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments A threat actor is employing deceptive tactics to promote a cryptocurrency clipboard hijacker, leveraging fake reviews, AI-generated content, and manipulated reputation systems across multiple online platforms. The campai… The Hacker News · Jun 17, 2026 High USfake reviewsreputation managementai
threat-intel Why Account Takeovers Are Rising and How to Stop Them This article discusses the rising trend of account takeover attacks, driven by increased complexity in organizational identity management due to hybrid work, BYOD, and expanded cloud services. Attackers are leveraging cr… BleepingComputer · Jun 17, 2026 High USaccount takeovercredential theftmfa fatigue
threat-intel Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats A coordinated malware campaign targeting JetBrains Marketplace plugins has emerged, with 15 malicious plugins designed to steal AI API keys from users. These plugins, posing as AI coding assistants, exfiltrate keys to a… The Hacker News · Jun 17, 2026 High USaiapimalware