malware NFCShare Android malware spreads via fake banking app updates on GitHub A new variant of the NFCShare Android malware is spreading through fake updates for banking apps hosted on GitHub, targeting financial institutions across Europe. The malware leverages NFC technology to steal payment car… BleepingComputer · Jun 8, 2026 High ITSPGEnfcandroidbanking
vulnerability Critical UniFi OS bug lets hackers gain root without authentication A critical vulnerability in UniFi OS Server versions 5.0.6 and earlier allows attackers to gain root access without authentication by chaining three previously identified flaws. This vulnerability, detailed by Bishop Fox… BleepingComputer · Jun 8, 2026 Critical CVE-2026-34908CVE-2026-34909CVE-2026-34910remote code executionroot accessauthentication bypass
vulnerability Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups Check Point has identified and warned of a critical vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access products, allowing unauthenticated attackers to bypass password authentication when using the… The Hacker News · Jun 8, 2026 Critical CVE-2026-50751CVE-2026-50752GLikev1vpncertificate
threat-intel AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload This article discusses the increasing challenge of AI-powered phishing attacks overwhelming Security Operations Centers (SOCs). Attackers are leveraging AI to create more convincing and varied phishing campaigns, leading… The Hacker News · Jun 8, 2026 High USphishingaisoc
threat-intel Anthropic Urges Industry Coordination to Allow for a ‘Pause’ in AI Development if Risks Grow Anthropic is advocating for a global pause in the development of advanced AI systems due to concerns about rapidly increasing capabilities and the potential for losing control. The company proposes coordinated action amo… SecurityWeek · Jun 8, 2026 High CAartificial intelligenceai safetycybersecurity
threat-intel AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs This article details a significant surge in vulnerability discovery, driven largely by autonomous AI agents. Depthfirst identified 21 zero-days in FFmpeg using their AI agent, while Google patched 429 bugs in Chrome 149,… The Hacker News · Jun 6, 2026 High CVE-2026-39210CVE-2026-39218CVE-2026-10881USaivulnerabilityzero-day
vulnerability Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available A high-severity vulnerability, CVE-2026-20245, in Cisco Catalyst SD-WAN Manager has been actively exploited by threat actors. The flaw, stemming from insufficient input validation, allows authenticated attackers to execu… The Hacker News · Jun 6, 2026 Critical CVE-2026-20245CVE-2026-20182CVE-2026-20127sd-wancvezero-day
threat-intel Suspicious Polyfill login prompts pop up on Toshiba, Muji websites Toshiba and Muji websites were temporarily affected by malicious login prompts generated by the polyfill[.]io service, which injected malicious code into their scripts. The issue stemmed from the domain being acquired by… BleepingComputer · Jun 5, 2026 Medium JACHcdnjavascriptlogin
threat-intel Adaptive, Agentic AI Worms Loom as Next Enterprise Threat This article discusses the emerging threat of adaptive, agentic AI worms, which are designed to autonomously seek out and exploit vulnerabilities in systems, similar to traditional worms but with the added capability of… Dark Reading · Jun 5, 2026 High CAUSaiwormadaptive
threat-intel What 2026 DBIR Confirms: Attacks Are Living in the Browser The 2026 Verizon DBIR highlights a significant shift in cyberattacks, with a growing reliance on browser-based activities, particularly the unauthorized use of AI tools like ChatGPT and Gemini. Employees are increasingly… BleepingComputer · Jun 5, 2026 High USbrowseraicredential theft
threat-intel In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA This week’s cybersecurity news highlights a range of threats, including AI-powered attacks targeting computing power, ongoing Grandoreiro banking trojan campaigns, and a self-propagating ransomware group utilizing obfusc… SecurityWeek · Jun 5, 2026 High IRUSairansomwaresupply chain
ransomware Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin has been exploited by threat actors, allowing for remote code execution and potential site compromise. Attackers have been actively targe… The Hacker News · Jun 5, 2026 Critical CVE-2026-3300MDwordpressvulnerabilityremote code execution
malware The Evil MSI Background is Back!, (Fri, Jun 5th) This report details a recent cyberattack utilizing a classic MSI-branded JPEG payload, a technique previously documented by the SANS Internet Storm Center. The attack began with a phishing email containing a WeTransfer l… SANS Internet Storm Center · Jun 5, 2026 High USphishingmalwarepowershell
vulnerability Cisco warns of unpatched SD-WAN zero-day exploited in attacks Cisco has issued a warning about a previously unknown zero-day vulnerability (CVE-2026-20245) in its Cisco Catalyst SD-WAN Manager software, which is being actively exploited to gain root privileges. The flaw, stemming f… BleepingComputer · Jun 5, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127zero-daysd-wanroot privilege
supply-chain Rust-Written IronWorm Hits NPM Supply Chain A new Rust-written malware campaign, dubbed "IronWorm," is targeting developers through compromised npm publishing workflows, stealing credentials like API keys and cloud credentials to spread across the software supply… Dark Reading · Jun 4, 2026 High USsupply chaincredential theftebpf
threat-intel 4 Critical Threats Where Attackers Have the Advantage This Dark Reading article highlights four critical cybersecurity threats identified by Gartner: deepfakes, software supply chain risks, prompt injections, and AI application compromises. Gartner analysts contend that cur… Dark Reading · Jun 4, 2026 High deepfakesai securitysupply chain
threat-intel Reporting from Vegas: Networking, AI, and good boys This Cisco Talos Threat Source newsletter highlights the ongoing challenges of managing data at scale in an AI-driven world, particularly during large technology conferences like Cisco Live. It details Talos’ expansion o… Cisco Talos · Jun 4, 2026 High USRUaithreat huntingc2
threat-intel Winning the cyber marathon with Tony Giandomenico This article discusses Cisco Talos Senior Director of Product Management, Tony Giandomenico’s perspective on the evolving cybersecurity landscape, particularly the increasing capabilities of AI and frontier models. He hi… Cisco Talos · Jun 4, 2026 Medium aithreat huntingcybersecurity
vulnerability B&R PPT30 Operating System A vulnerability, CVE-2025-11482, has been identified in B&R PPT30 Operating System versions prior to 1.8.0, specifically within the OPC-UA Server. An unauthenticated network-based attacker could exploit this flaw to perm… CISA Advisories · Jun 4, 2026 High CVE-2025-11482WOopcuafirmwarenetwork-based
malware Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS A sophisticated operation is impersonating popular open-source and freeware tools like Ghidra and dnSpy to lure users to malicious websites via a Traffic Distribution System (TDS). This TDS then delivers malware, includi… The Hacker News · Jun 4, 2026 High TRPLBRtdsmalware-as-a-serviceclick interception