supply-chain 144 Mastra npm Packages Compromised via Hijacked Contributor Account A software supply chain attack, dubbed ‘easy-day-js,’ compromised 144 npm packages within the Mastra namespace by hijacking a contributor account. The attack leveraged a malicious dependency, ‘easy-day-js,’ to deploy a c… The Hacker News · Jun 17, 2026 High supply chainnpmjavascript
vulnerability 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs Recent analysis reveals that three previously patched Fortinet FortiSandbox vulnerabilities – CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089 – are actively being exploited in the wild. A significant number of comprom… SecurityWeek · Jun 17, 2026 High CVE-2026-39808CVE-2026-39813CVE-2026-25089USINALvulnerabilitypatchingexploitation
threat-intel Malicious JetBrains Marketplace plugins steal AI API keys from developers A coordinated malware campaign involving 15 malicious plugins for the JetBrains Marketplace was discovered, designed to steal AI API keys from developers. These plugins, disguised as AI coding assistants and code review… BleepingComputer · Jun 16, 2026 High USapi-keycredential-theftide
supply-chain Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting A vulnerability in the Google Cloud Vertex AI SDK allowed attackers to hijack model uploads by exploiting predictable bucket naming conventions. Attackers could create a temporary bucket in their own project, intercept t… The Hacker News · Jun 16, 2026 High CVE-2026-2473USbucket squattingmodel uploadcloud storage
malware Rokarolla Android Trojan Levels Up to Full Device Control, Persistence The Rokarolla Android Trojan has evolved to offer full device control and persistence, moving beyond typical banking Trojan capabilities. Distributed through fake Chrome and TikTok downloads, the malware steals credentia… Dark Reading · Jun 16, 2026 High USandroidbanking trojandevice control
threat-intel GhostTree Attack Abused Recursive Windows Junctions to Hide Malware Security researchers have discovered a novel technique, dubbed "GhostTree," used by attackers to evade detection by security tools. This method leverages recursive loops created using NTFS junctions to hide malicious fil… BleepingComputer · Jun 16, 2026 High USjunctionsntfsrecursion
threat-intel DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act The U.S. Department of Justice seized the CFAKE.com and SOCFAKE.com websites, which hosted deepfake nude images and videos of public figures, under the TAKE IT DOWN Act. This marks the first public use of the legislation… BleepingComputer · Jun 15, 2026 High USITFRdeepfakeaipornography
threat-intel HTTP/2 Bomb Attacks Put Telcos, Healthcare Orgs at Risk This article reports on the ‘HTTP/2 Bomb’ vulnerability, a denial-of-service exploit leveraging features within the HTTP/2 protocol to amplify junk traffic and cause widespread disruptions. The vulnerability affects a si… Dark Reading · Jun 15, 2026 High CVE-2026-49975UShttp2ddosamplification
threat-intel Copilot 'SearchLeak' Attack Allows 1-Click Data Theft A critical vulnerability, dubbed ‘SearchLeak,’ has been discovered in Microsoft Copilot that allows attackers to silently steal user data through a novel prompt injection technique. The attack leverages a race condition… Dark Reading · Jun 15, 2026 Critical CVE-2026-42824prompt injectionai securitymicrosoft copilot
supply-chain OptinMonster WordPress plugin hacked in CDN supply-chain attack A supply-chain attack targeting the Awesome Motive CDN compromised WordPress plugins OptinMonster, TrustPulse, and PushEngage. Attackers gained access through a vulnerability in the UpdraftPlus plugin, leveraging the CDN… BleepingComputer · Jun 15, 2026 High UScdnwordpresssupply chain
vulnerability LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers A critical vulnerability chain in LiteLLM, an open-source AI gateway, allows low-privilege users to escalate their permissions to full administrator and execute arbitrary code on the server. Researchers at Obsidian Secur… The Hacker News · Jun 15, 2026 Critical CVE-2026-47101CVE-2026-47102CVE-2026-40217USaiproxyprivilege escalation
threat-intel One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes A vulnerability, dubbed SearchLeak, was discovered in Microsoft 365 Copilot Enterprise Search that allowed attackers to exfiltrate sensitive data like emails, calendar details, and MFA codes through a single click. The f… The Hacker News · Jun 15, 2026 High CVE-2026-42824CVE-2025-32711UScommand injectionprompt injectionbing
threat-intel The Beginning of the End of Social Engineering This article discusses a significant shift in cybersecurity driven by the integration of AI-native operating systems, particularly Google's Gemini and Apple's Apple Intelligence. Operating systems are evolving to activel… Dark Reading · Jun 15, 2026 High USaisocial engineeringauthentication
threat-intel ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More This week’s cybersecurity recap highlights several active exploits and attacks, including a Chrome 0-day being actively leveraged, a ShinyHunters gang exploiting a PeopleSoft zero-day for lateral movement and data exfilt… The Hacker News · Jun 15, 2026 High CVE-2026-11645CVE-2026-2441CVE-2026-3909UNCHzero-dayphishingsupply-chain
threat-intel New attack turned Microsoft 365 Copilot into 1-click data theft tool A critical vulnerability, dubbed SearchLeak, has been discovered in Microsoft 365 Copilot Enterprise, allowing attackers to steal sensitive data from user mailboxes, OneDrive, and SharePoint accounts via a specially craf… BleepingComputer · Jun 15, 2026 Critical CVE-2026-42824prompt injectionssrfhtml injection
malware 152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic A network of 152 Chrome extensions, collectively installed over 105,000 times, has been discovered distributing a potentially unwanted program (PUP) that generates fake traffic and logs user data. These extensions, masqu… The Hacker News · Jun 15, 2026 High TRadwarefake trafficprivacy
malware Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites A security incident has been discovered affecting over 1.2 million WordPress sites using the PushEngage, OptinMonster, and TrustPulse plugins. An attacker tampered with the plugins' JavaScript files, creating backdoors t… The Hacker News · Jun 15, 2026 High CVE-2026-10795USwordpresscdnbackdoor
vulnerability Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication A critical vulnerability (CVE-2026-20253) has been identified in Splunk Enterprise versions below 10.2.4 and 10.0.7, allowing unauthenticated users to execute arbitrary code and potentially gain remote access. The flaw s… The Hacker News · Jun 13, 2026 Critical CVE-2026-20253USremote code executionauthenticationpostgresql
malware Over 400 Arch Linux packages compromised to push rootkit, infostealer Over 400 Arch Linux packages within the AUR repository have been compromised, distributing a Linux rootkit and infostealer malware designed to steal developer credentials and access tokens. The attack involved a maliciou… BleepingComputer · Jun 12, 2026 High USrootkitinfostealeraur
threat-intel Claude Fable 5 Doesn't Change the Mythos Security Story This article discusses Anthropic's release of Claude Fable 5 and Mythos 5 AI models, highlighting concerns about their potential to exploit vulnerabilities in software. While Anthropic has implemented safeguards like saf… Dark Reading · Jun 12, 2026 High USaicybersecurityvulnerability