threat-intel 282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study Researchers at Wake Forest University discovered that nearly two-thirds (282 out of 444) of AI chatbot apps for iOS exposed API keys and open access to AI proxy services through network traffic. This vulnerability, dubbe… The Hacker News · Jun 30, 2026 High USapiaiiot
threat-intel What the Numbers Say About FIFA 2026 Cyber Risk This report from Check Point Research reveals a significant pre-emptive cyber threat landscape surrounding the FIFA World Cup 2026, with attackers already establishing infrastructure months in advance. The primary target… The Hacker News · Jun 30, 2026 High RUemailspoofingfraud
threat-intel Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer An attacker exploited a critical vulnerability (CVE-2026-48558) in SimpleHelp’s OpenID Connect (OIDC) flow to deploy the TaskWeaver and Djinn Stealer malware. This allowed for unauthorized access to authenticated ‘Techni… The Hacker News · Jun 30, 2026 Critical CVE-2026-48558USoidccredential theftai
threat-intel 'Djinn' Stealer Targets Cloud, AI Credentials The ‘Djinn’ stealer, delivered via a SimpleHelp vulnerability (CVE-2026-48558), is targeting cloud and AI credentials, specifically focusing on developer and administrator environments. Blackpoint Cyber’s APG tracked an… Dark Reading · Jun 29, 2026 High CVE-2026-48558DKaicredentialsstealer
threat-intel 236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers A report by Infoblox has identified over 236,000 websites utilizing the DCloud Uni-App framework, many of which are being exploited for cryptocurrency scams, phishing attacks, and wallet draining operations. These sites,… The Hacker News · Jun 29, 2026 High ARUSGBscamphishingcrypto
threat-intel Amazon Q VS Extension Flaw Leads to Cloud Credential Theft A vulnerability in the Amazon Q VS Extension has been discovered, allowing attackers to steal cloud credentials by exploiting the Model Context Protocol (MCP). The flaw stems from the extension’s automatic execution of M… Dark Reading · Jun 29, 2026 High CVE-2026-12957CVE-2025-59536CVE-2026-21852aimcpcredentials
threat-intel Why Post-Quantum Cryptography Starts With Credentials This article discusses the growing threat posed by quantum computing to current encryption methods, particularly public-key cryptography used to protect credentials. The article highlights the ‘Harvest Now, Decrypt Later… The Hacker News · Jun 29, 2026 High USquantum computingcryptographycredentials
vulnerability Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw A critical vulnerability, CVE-2026-55200, has been discovered in libssh2, a client-side SSH library embedded in various applications like curl, Git, and PHP. The flaw allows for code execution via an integer overflow, po… The Hacker News · Jun 29, 2026 Critical CVE-2026-55200CVE-2019-3855CVE-2026-55199GBsshlibssh2code execution
ransomware Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk Recent breaches targeting educational institutions, including ransomware attacks on Oracle E-Business Suite and Instructure's Canvas platform, highlight the vulnerability of the sector due to legacy technology, understaf… Dark Reading · Jun 27, 2026 High USthird-party riskransomwareeducation
phishing Cybersecurity firms targeted by fraudulent OpenAI organization invites Cybersecurity firms are being targeted by a sophisticated phishing campaign where attackers create fraudulent OpenAI organizations, mimicking legitimate companies and inviting employees to join them. These invitations, a… BleepingComputer · Jun 26, 2026 Medium phishingopenaicredential_harvesting
threat-intel New Initiative Tackles Security for End-of-Life Open Source Software This article discusses a new initiative, the Open Source Sustainability Initiative (OSSI), launched by the Commonhaus Foundation to address the growing challenge of managing and securing end-of-life (EOL) open-source sof… Dark Reading · Jun 26, 2026 High USend-of-lifevulnerabilitiesopen source
threat-intel Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs A critical vulnerability was discovered in Amazon Q Developer, allowing attackers to execute arbitrary code and steal developer credentials by leveraging Model Context Protocol (MCP) configurations within a cloned reposi… The Hacker News · Jun 26, 2026 Critical CVE-2026-12957CVE-2026-12958CVE-2025-59536mcpcloud securitydeveloper credentials
threat-intel New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries A vulnerability, dubbed "pedit COW," has been discovered in the Linux kernel's traffic-control subsystem, allowing unprivileged users to gain root access by poisoning cached binaries. The exploit, demonstrated with a wor… The Hacker News · Jun 26, 2026 Critical CVE-2026-46331USGBlinuxkernelexploit
vulnerability Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk A vulnerability (CVE-2024-2658) has been identified in Schneider Electric’s Floating License Manager (FLM), specifically the FlexNet Publisher component, due to an uncontrolled search path element. This allows a local, n… Securelist · Jun 26, 2026 High CVE-2024-2658USopensslprivilege escalationindustrial control systems
vulnerability CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue CISA has added a critical remote code execution (RCE) vulnerability, CVE-2026-12569, affecting PTC Windchill PDMlink and FlexPLM to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, stemming from imp… The Hacker News · Jun 26, 2026 Critical CVE-2026-12569rcewindchillweb shell
vulnerability New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets A new vulnerability, CVE-2026-43503, has been discovered in the Linux kernel related to the DirtyClone variant of the DirtyFrag family. This flaw allows local users to gain root access by exploiting a cloned network pack… The Hacker News · Jun 26, 2026 High CVE-2026-43503CVE-2026-31431CVE-2026-43284linuxkernelprivilege escalation
threat-intel In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw A critical vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager (CUCM) has been rapidly weaponized by attackers within 24 hours of a proof-of-concept release. The SSRF flaw allows unauthenticated remote… Dark Reading · Jun 25, 2026 Critical CVE-2026-20230USssrfprivilege escalationcisco
threat-intel Local Police Collusion Hampers Crackdown on Asian Scam Centers This article reports on the ongoing challenge of combating cybercrime, specifically online scams, centered in Southeast Asia, particularly Cambodia, Myanmar, and the Philippines. Despite international pressure and arrest… Dark Reading · Jun 25, 2026 High KHUSCNcybercrimescamcorruption
threat-intel Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability A popular Google Chrome ad blocker extension, Adblock for YouTube, with over 10 million installs, has been found to contain a dormant script injection capability. Researchers discovered the extension’s architecture allow… The Hacker News · Jun 25, 2026 High USadblockjavascriptprivacy
threat-intel ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories This article reports on several security vulnerabilities and trends, including a privacy-preserving protocol from Cloudflare, six vulnerabilities in the curl library, a critical security flaw in Hoppscotch allowing unaut… The Hacker News · Jun 25, 2026 High CVE-2026-8932CVE-2026-50160USKRsmart tvproxywareiot