threat-intel Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone A vulnerability in Apple’s Beats Studio Buds firmware allowed nearby attackers to potentially eavesdrop on users via the device’s microphone. The flaw, tracked as CVE-2025-20701, stemmed from incorrect authorization with… The Hacker News · Jun 19, 2026 Critical CVE-2025-20701CVE-2025-20700CVE-2025-20702GEbluetoothmicrophonesecurerom
threat-intel Novo Nordisk Breach Exposes Software Development Pipeline Risk A breach at Novo Nordisk, facilitated by a leaked GitHub token, exposed a significant amount of sensitive data, including patient clinical trial information, healthcare professional records, and proprietary drug developm… Dark Reading · Jun 18, 2026 High DKgithubsecretssupply-chain
threat-intel Bulgaria allowed surveillance tech firm to sell products to repressive regimes, report says A report by Human Rights Watch revealed that Bulgaria allowed a surveillance technology firm, Circles, to sell its products – including Pixcell, Landmark, and Voice Over Location Enabler software – to repressive regimes… The Record · Jun 18, 2026 High BUELUAsurveillancespywareexport control
threat-intel FIFA Bug Exposed World Cup Streams to Remote Takeover A vulnerability in FIFA's Microsoft Entra environment allowed an ethical hacker, "BobDaHacker," to gain unauthorized access to global World Cup streams, match management systems, and related data platforms. The issue ste… Dark Reading · Jun 18, 2026 High USFRCOaccess-controlvulnerabilityauthentication
threat-intel Close Encounters of the Human Kind This article from Cisco Talos details a novel approach to reverse engineering that leverages AI agents alongside traditional tools like the VB6 disassembler. The key innovation is exposing the disassembler's parsed data… Cisco Talos · Jun 18, 2026 High GBFRUSreverse engineeringaiautomation
threat-intel ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm A sprawling Android botnet called Popa, used for advertising fraud, account takeovers, and data scraping, has been linked to NetNut, a residential proxy provider operated by Alarum Technologies Ltd. Researchers discovere… Krebs on Security · Jun 18, 2026 High ISbotnetproxyandroid
threat-intel Salesforce Data Thefts Continue via Klue App Compromise A series of data thefts targeting Salesforce instances have been linked to a new threat actor group, Icarus, following a compromise of Klue's Battlecards app. The attacks leveraged compromised OAuth tokens and Python scr… Dark Reading · Jun 18, 2026 High USoauthsaasdata exfiltration
threat-intel ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories This week’s ThreatDay Bulletin highlights several concerning security incidents, including browser extension abuse, macOS malware attacks, AI-powered malware delivery, and a global phishing campaign targeting travel book… The Hacker News · Jun 18, 2026 High CVE-2026-20127CVE-2026-49975USCNJPbrowser extensionsmacos malwareai abuse
threat-intel 5 reasons Microsoft 365 backup isn’t enough for business data protection This article highlights the limitations of relying solely on Microsoft 365’s built-in backup and retention policies for business data protection. It argues that organizations need a third-party solution to adequately add… BleepingComputer · Jun 18, 2026 High ransomwarebackupdata protection
threat-intel Get Out of Security Debt by Tackling the Exposure Problem This Dark Reading article discusses the growing problem of ‘security debt’ – vulnerabilities that remain open in systems for extended periods. It argues that organizations need to shift their focus from simply tracking a… Dark Reading · Jun 18, 2026 High risk managementvulnerability managementsecurity debt
threat-intel No Exploits Required This article discusses the limitations of relying solely on exploiting vulnerabilities in cybersecurity, arguing that defenders often struggle due to the inherent complexity and interconnectedness of modern networks. The… SecurityWeek · Jun 18, 2026 Medium network securitycybersecurityzero-trust
threat-intel Telegram admits it couldn't police exam-leak channels, India tells court India's government blocked Telegram access following reports of leaked exam materials for the NEET-UG 2026 medical entrance exam, leading to disruptions for users globally. Telegram initially admitted limitations in proa… BleepingComputer · Jun 18, 2026 Medium INAEexamleakregulatory
threat-intel Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model This article details a technique developed by Cisco Talos for automating reverse engineering of VB6 binaries using AI agents. The approach leverages the COM object model of VBdec, allowing external scripting tools like C… Cisco Talos · Jun 18, 2026 Medium reverse-engineeringaicom
threat-intel EU Gets a Head Start in Developing 6G Network Security The EU is launching the "Shield-6G" project, a collaborative initiative funded by the EU, to proactively develop cybersecurity measures for the upcoming 6G network. This project, involving 19 organizations, aims to addre… Dark Reading · Jun 18, 2026 Medium EU6gaicybersecurity
threat-intel ISC Stormcast For Thursday, June 18th, 2026 https://isc.sans.edu/podcastdetail/9978, (Thu, Jun 18th) The SANS Internet Storm Center's June 18th, 2026 Stormcast reported a heightened level of online threats and unusual network activity across various sectors. The broadcast highlighted several emerging trends, including i… SANS Internet Storm Center · Jun 18, 2026 Medium phishingdnsthreat-monitoring
threat-intel The Behavior of Coordinated SSH Brute Force Attacks over the last three months [Guest Diary], (Wed, Jun 17th) This report details a three-month analysis of coordinated SSH brute-force attacks conducted using a honeypot system, highlighting a correlation between attack activity and geopolitical events, law enforcement actions, an… SANS Internet Storm Center · Jun 18, 2026 High USIRILsshbrute-forcehoneypot
threat-intel Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed This Smashing Security podcast episode discusses a concerning trend: the potential for AI coding assistants to be exploited for password leakage. The discussion highlights how AI tools, particularly those like ProtonPass… Graham Cluley · Jun 17, 2026 High SWaipasswordcredential
threat-intel Google to use UK and EU user IP addresses for ad personalization Google plans to begin using IP addresses from August 3, 2026, across the EEA, UK, and Switzerland for ad measurement and personalization. This shift is driven by regulatory changes regarding personal data, particularly u… BleepingComputer · Jun 17, 2026 Medium GBEUCHprivacygdprconsent
threat-intel Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments A threat actor is employing deceptive tactics to promote a cryptocurrency clipboard hijacker, leveraging fake reviews, AI-generated content, and manipulated reputation systems across multiple online platforms. The campai… The Hacker News · Jun 17, 2026 High USfake reviewsreputation managementai
threat-intel Hostile states behind three-quarters of attacks on Britain's critical infrastructure, cyber chief warns This article reports that the UK’s cyber chief, Richard Horne, has shifted the government’s approach to cybersecurity, framing it as a ‘contest’ against hostile state actors rather than a ‘risk’ to be managed. He reveale… The Record · Jun 17, 2026 High CHUKstate-sponsoredcritical infrastructurecyber conflict