malware Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT A series of malicious npm packages, disguised as PostCSS tools, have been discovered delivering a Windows-based remote access trojan (RAT). These packages, published by 'abdrizak', leveraged legitimate build tooling to d… The Hacker News · Jun 23, 2026 High USnpmsupply-chainrat
threat-intel OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws OpenAI is expanding its Daybreak initiative with GPT-5.5-Cyber, an AI model designed to accelerate vulnerability discovery and patching within software. This expansion includes a new plugin for streamlining the vulnerabi… The Hacker News · Jun 23, 2026 High CVE-2026-47729CVE-2026-4890CVE-2026-4891CAaivulnerabilitypatching
threat-intel The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration This report details a newly discovered bucket hijacking technique impacting major cloud service providers (CSPs) like Google Cloud, AWS, and Microsoft Azure. The vulnerability exploits a shared namespace design where glo… Palo Alto Unit 42 · Jun 22, 2026 High cloud securitydata exfiltrationbucket hijacking
malware New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer A new malware loader, dubbed OXLOADER, is being used to distribute the CastleStealer information stealer through malicious Google Ads. The campaign, codenamed REF8372, leverages deceptive advertising and PowerShell execu… The Hacker News · Jun 22, 2026 Medium RUUAgoogle adsmalware loadercastlestealer
threat-intel Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries Google is implementing a new Android developer verification system, starting September 30, 2026, in Brazil, Indonesia, Singapore, and Thailand, to combat app scams and malware. This will block installations of apps from… The Hacker News · Jun 22, 2026 Medium BRIDSGapp scamsdeveloper verificationopen source
threat-intel French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation This article reports on a discussion at the G7 summit regarding the regulation of advanced artificial intelligence (AI) systems, particularly focusing on the U.S. government’s restriction on access to Anthropic’s latest… SecurityWeek · Jun 20, 2026 Medium FRUNCAaiartificial intelligenceregulation
supply-chain Cybersecurity Firms Impacted by Klue Supply Chain Attack A supply chain attack targeting the Klue market intelligence platform resulted in the unauthorized harvesting of customer data from various integrations, including Salesforce and HubSpot. The attack, attributed to a new… SecurityWeek · Jun 19, 2026 High supply-chainoauthcrm
threat-intel No Exploits Required This article discusses the limitations of relying solely on exploiting vulnerabilities in cybersecurity, arguing that defenders often struggle due to the inherent complexity and interconnectedness of modern networks. The… SecurityWeek · Jun 18, 2026 Medium network securitycybersecurityzero-trust
threat-intel Google to use UK and EU user IP addresses for ad personalization Google plans to begin using IP addresses from August 3, 2026, across the EEA, UK, and Switzerland for ad measurement and personalization. This shift is driven by regulatory changes regarding personal data, particularly u… BleepingComputer · Jun 17, 2026 Medium GBEUCHprivacygdprconsent
threat-intel The browser blind spot: Why your security tool may not be blocking what you think it is [Guest Diary], (Wed, Jun 17th) This article highlights a significant security gap in Cloud Access Security Broker (CASB) deployments due to the increasing use of the QUIC protocol. CASBs, traditionally designed to inspect TCP traffic, fail to detect w… SANS Internet Storm Center · Jun 17, 2026 High quiccasbssl
threat-intel Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats A coordinated malware campaign targeting JetBrains Marketplace plugins has emerged, with 15 malicious plugins designed to steal AI API keys from users. These plugins, posing as AI coding assistants, exfiltrate keys to a… The Hacker News · Jun 17, 2026 High USaiapimalware
threat-intel UK Social Media Ban for Minors Has Privacy Experts Worried The UK is implementing a ban on user-to-user social media platforms for individuals under 16, following similar legislation in Canada and Australia, driven by concerns about the impact of social media on young people. Th… Dark Reading · Jun 17, 2026 Medium UKCAAUsocial mediaage verificationprivacy
malware Fileless Phantom Stealer Targets Browser Credentials A new fileless malware, Phantom Stealer, is being deployed through targeted phishing campaigns against banks and high-value organizations. The malware focuses on stealing browser credentials and session cookies, utilizin… Dark Reading · Jun 16, 2026 High GBDEFRcredential theftbrowser securityfileless malware
threat-intel Security Community Slams US Ban on Exporting Mythos, Fable The US government recently imposed an export control order restricting access to Anthropic's Claude Fable 5 and Mythos 5 large language models (LLMs) for foreign nationals, citing national security concerns, particularly… Dark Reading · Jun 16, 2026 High USCHllmaiexport control
malware New Rokarolla Android malware targets 217 banking, crypto apps A new Android banking trojan, Rokarolla, is targeting 217 banking and cryptocurrency applications through deceptive app distribution and sophisticated data theft techniques. The malware leverages Accessibility permission… BleepingComputer · Jun 16, 2026 High androidbanking trojandata theft
supply-chain Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting A vulnerability in the Google Cloud Vertex AI SDK allowed attackers to hijack model uploads by exploiting predictable bucket naming conventions. Attackers could create a temporary bucket in their own project, intercept t… The Hacker News · Jun 16, 2026 High CVE-2026-2473USbucket squattingmodel uploadcloud storage
malware New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds A new Android banking trojan, Rokarolla, has been identified by Zimperium, targeting over 200 banking and cryptocurrency apps. The malware utilizes techniques like fake login pages and Accessibility abuse to steal sensit… The Hacker News · Jun 16, 2026 High androidbanking trojanpin theft
supply-chain Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE A vulnerability in the Google Cloud Vertex AI Python SDK (versions 1.139.0 - 1.140.0) allowed attackers to hijack model uploads and execute remote code execution (RCE) within a target's Vertex AI serving infrastructure.… Palo Alto Unit 42 · Jun 16, 2026 High sdkrcebucket squatting
threat-intel Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails A China-linked espionage group, UNC6508, gained access to North American medical, academic, and military research networks via a backdoor on REDCap servers, stealing sensitive research and defense emails. The attackers e… The Hacker News · Jun 15, 2026 High CHUSCAespionageredcapgoogle workspace
threat-intel China-Nexus Actor Spied on US Researchers Undetected for a Year Google’s Threat Intelligence Group (GTIG) discovered and disrupted a year-long espionage campaign by the China-Nexus threat actor, UNC6508, targeting US academic, medical, and military research institutions. The actor ut… Dark Reading · Jun 15, 2026 High CHUScyber espionageintel gatheringcredential theft