threat-intel Copilot 'SearchLeak' Attack Allows 1-Click Data Theft A critical vulnerability, dubbed ‘SearchLeak,’ has been discovered in Microsoft Copilot that allows attackers to silently steal user data through a novel prompt injection technique. The attack leverages a race condition… Dark Reading · Jun 15, 2026 Critical CVE-2026-42824prompt injectionai securitymicrosoft copilot
threat-intel China-Nexus Actor Spied on US Researchers Undetected for a Year Google’s Threat Intelligence Group (GTIG) discovered and disrupted a year-long espionage campaign by the China-Nexus threat actor, UNC6508, targeting US academic, medical, and military research institutions. The actor ut… Dark Reading · Jun 15, 2026 High CHUScyber espionageintel gatheringcredential theft
threat-intel Most CISOs Report Pressure to Bury Bad Security News This Dark Reading article examines the significant pressure faced by CISOs to suppress or delay disclosing security findings, particularly regarding vulnerabilities and breaches. The primary drivers of this pressure stem… Dark Reading · Jun 15, 2026 Medium cisospressuredisclosure
threat-intel One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes A vulnerability, dubbed SearchLeak, was discovered in Microsoft 365 Copilot Enterprise Search that allowed attackers to exfiltrate sensitive data like emails, calendar details, and MFA codes through a single click. The f… The Hacker News · Jun 15, 2026 High CVE-2026-42824CVE-2025-32711UScommand injectionprompt injectionbing
threat-intel The Beginning of the End of Social Engineering This article discusses a significant shift in cybersecurity driven by the integration of AI-native operating systems, particularly Google's Gemini and Apple's Apple Intelligence. Operating systems are evolving to activel… Dark Reading · Jun 15, 2026 High USaisocial engineeringauthentication
threat-intel Vibe coders are gonna vibe code: How CISOs are tackling code sprawl This article discusses the growing challenge of "code sprawl" driven by the increasing accessibility of AI coding tools like Claude and Lovable. Organizations are struggling to maintain visibility and control as employee… BleepingComputer · Jun 15, 2026 Medium aicode-sprawlautomation
threat-intel Chinese hackers breach REDCap servers, steal medical research A Chinese espionage campaign, attributed to UNC6508, targeted a North American medical research institution by exploiting vulnerabilities in the REDCap platform. The attackers deployed the custom malware, ‘Infinitered,’… BleepingComputer · Jun 15, 2026 High CHUSCAespionagecredential_theftredcap
threat-intel ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More This week’s cybersecurity recap highlights several active exploits and attacks, including a Chrome 0-day being actively leveraged, a ShinyHunters gang exploiting a PeopleSoft zero-day for lateral movement and data exfilt… The Hacker News · Jun 15, 2026 High CVE-2026-11645CVE-2026-2441CVE-2026-3909UNCHzero-dayphishingsupply-chain
threat-intel Finland brings charges against cargo ship officers for cutting submarine cables Finnish authorities have brought charges against the captain and bosun of the cargo ship Fitburg for damaging several submarine cables in the Baltic Sea. The incident occurred while the ship was transporting sanctioned s… The Record · Jun 15, 2026 Medium FIRUISsubmarine cablessabotagebaltic sea
threat-intel New attack turned Microsoft 365 Copilot into 1-click data theft tool A critical vulnerability, dubbed SearchLeak, has been discovered in Microsoft 365 Copilot Enterprise, allowing attackers to steal sensitive data from user mailboxes, OneDrive, and SharePoint accounts via a specially craf… BleepingComputer · Jun 15, 2026 Critical CVE-2026-42824prompt injectionssrfhtml injection
threat-intel Anthropic says US government forced it to disable cybersecurity AI models Anthropic, a leading AI developer, was compelled by the U.S. government to disable two of its advanced cybersecurity AI models, dubbed Fable 5 and Mythos 5. This action stemmed from an export control directive restrictin… The Record · Jun 15, 2026 Medium USaiexport controlcybersecurity
threat-intel US Cracks Down on Anthropic AI Models Amid Abuse Concerns Anthropic has suspended access to its Fable 5 and Mythos 5 AI models following a US government export control directive, aimed at preventing foreign nationals from utilizing them. This action stems from growing concerns… Dark Reading · Jun 15, 2026 High CHRUUKaicybersecuritythreat intelligence
threat-intel The Onboarding Password Mistake That Creates Unnecessary Risk This article discusses the significant security risks associated with using temporary onboarding passwords, highlighting how they are frequently shared insecurely and remain active for extended periods. The practice crea… The Hacker News · Jun 15, 2026 High USIRonboardingcredentialssecurity
threat-intel French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker A breach of the French government’s secure messaging platform, Tchap, has resulted in the theft of personal data for over 70,000 government employees. The incident was initially attributed to a threat actor calling itsel… SecurityWeek · Jun 15, 2026 High FRdata-breachgovernmentcredential theft
threat-intel EvilTokens: A phishing attack that doesn’t steal your password EvilTokens is a sophisticated phishing-as-a-service (PaaS) kit that bypasses traditional phishing defenses by leveraging the OAuth 2.0 device authorization grant flow. Attackers use convincing lures – often mimicking leg… WeLiveSecurity · Jun 15, 2026 High phishingoath2device-code
threat-intel Ex-school district employee jailed for hacks on former employer A former IT employee, Ezekiel Dean Potter, was sentenced to prison for a prolonged cyberattack against the Saydel Community School District. Potter exploited his previous access to disrupt operations, steal data, and cau… BleepingComputer · Jun 13, 2026 High UScyberattackdata-breachaccount-compromise
threat-intel US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos Anthropic has temporarily blocked access to its Fable 5 and Mythos 5 AI models following a directive from the US government citing national security concerns. The order restricts access to these models by foreign nationa… BleepingComputer · Jun 13, 2026 Medium USUKaijailbreaknational security
threat-intel U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals Following a U.S. government order, Anthropic has been instructed to temporarily suspend access to its advanced AI models, Claude Fable 5 and Mythos 5, for all foreign nationals due to national security concerns. The orde… The Hacker News · Jun 13, 2026 Medium USaijailbreakcybersecurity
threat-intel Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered Palo Alto Unit 42 has discovered a new Biome stream, ‘App.MenuItem,’ in macOS Tahoe 26 that logs specific menu selections made by users. This artifact provides a detailed record of user actions, offering valuable context… Palo Alto Unit 42 · Jun 12, 2026 Medium biomemacosforensics
threat-intel China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade A China-linked threat actor, identified as Velvet Ant, has been discovered backdooring Linux login software for nearly a decade, gaining persistent access to a network with no direct internet connectivity. The group’s ta… The Hacker News · Jun 12, 2026 CVE-2024-20399