threat-intel The Beginning of the End of Social Engineering This article discusses a significant shift in cybersecurity driven by the integration of AI-native operating systems, particularly Google's Gemini and Apple's Apple Intelligence. Operating systems are evolving to activel… Dark Reading · Jun 15, 2026 High USaisocial engineeringauthentication
threat-intel Chinese hackers breach REDCap servers, steal medical research A Chinese espionage campaign, attributed to UNC6508, targeted a North American medical research institution by exploiting vulnerabilities in the REDCap platform. The attackers deployed the custom malware, ‘Infinitered,’… BleepingComputer · Jun 15, 2026 High CHUSCAespionagecredential_theftredcap
threat-intel ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More This week’s cybersecurity recap highlights several active exploits and attacks, including a Chrome 0-day being actively leveraged, a ShinyHunters gang exploiting a PeopleSoft zero-day for lateral movement and data exfilt… The Hacker News · Jun 15, 2026 High CVE-2026-11645CVE-2026-2441CVE-2026-3909UNCHzero-dayphishingsupply-chain
threat-intel US Cracks Down on Anthropic AI Models Amid Abuse Concerns Anthropic has suspended access to its Fable 5 and Mythos 5 AI models following a US government export control directive, aimed at preventing foreign nationals from utilizing them. This action stems from growing concerns… Dark Reading · Jun 15, 2026 High CHRUUKaicybersecuritythreat intelligence
phishing FBI disrupts massive AI-powered phishing service using a million URLs The FBI, in collaboration with Google and Black Lotus Labs, successfully disrupted a large-scale Chinese phishing-as-a-service operation called Outsider Enterprise. This operation utilized AI to generate and distribute p… BleepingComputer · Jun 14, 2026 High CHphishingaisms
threat-intel Ex-school district employee jailed for hacks on former employer A former IT employee, Ezekiel Dean Potter, was sentenced to prison for a prolonged cyberattack against the Saydel Community School District. Potter exploited his previous access to disrupt operations, steal data, and cau… BleepingComputer · Jun 13, 2026 High UScyberattackdata-breachaccount-compromise
phishing Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing Google has filed a lawsuit against a Chinese cybercrime network, Outsider, for using its Gemini AI agent to conduct massive smishing attacks targeting Americans. The network operates a phishing-as-a-service (PhaaS) platf… The Hacker News · Jun 12, 2026 High CHUSaiphishingsmishing
threat-intel In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine This week’s cybersecurity news includes allegations of cover-ups by IBM and AT&T regarding foreign government-linked hacks, a data breach impacting the University of Oxford’s CareerConnect platform, and layoffs within Go… SecurityWeek · Jun 12, 2026 High CVE-2026-42271SOUNEUdata breachcyberattackddos
threat-intel Industry Reactions to Claude Fable 5: Feedback Friday The release of Anthropic’s Claude Fable 5 AI model has sparked industry discussion regarding its potential misuse in cybersecurity and other high-risk areas. The model incorporates safeguards that automatically downgrade… SecurityWeek · Jun 12, 2026 High aicybersecuritythreat intelligence
vulnerability Ivanti Sentry Exploitation Attempts Hitting Honeypots A recently patched vulnerability in Ivanti Sentry, CVE-2026-10520, has been observed attempting exploitation on honeypots, according to Ivanti and CISA. The flaw allows for remote code execution with root privileges via… SecurityWeek · Jun 12, 2026 High CVE-2026-10520USvulnerabilitycommand injectionroot privilege
vulnerability Oracle mitigates PeopleSoft zero-day exploited in data theft attacks A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools has been exploited by the ShinyHunters ransomware gang to steal data from numerous organizations. Oracle has released mitigations, but t… BleepingComputer · Jun 11, 2026 Critical CVE-2026-35273zero-daydata theftpeoplesoft
threat-intel New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets A research report highlighted vulnerabilities in OpenClaw, a popular self-hosted AI agent, revealing that attackers could trick the agent into running malicious code or leaking sensitive data by embedding instructions wi… The Hacker News · Jun 11, 2026 High USaiagentprompt injection
supply-chain The ‘Miasma’ worm source code briefly leaked on GitHub The source code for the Miasma credential-stealing worm framework, previously linked to supply-chain attacks targeting open-source ecosystems, was briefly leaked on GitHub. This leak, mirroring the earlier Shai-Hulud wor… BleepingComputer · Jun 10, 2026 High USsupply chaincredential theftopen source
vulnerability CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation CISA has added three newly exploited vulnerabilities to its KEV catalog, impacting Cisco, Google Chrome, and Arista Networks. These vulnerabilities – one in Cisco SD-WAN Manager, another in Chrome’s V8 engine, and a thir… The Hacker News · Jun 10, 2026 High CVE-2026-20245CVE-2026-11645CVE-2026-7473cvesd-wanchrome
vulnerability Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs Microsoft released a significant security update addressing 206 vulnerabilities across its software portfolio, including multiple critical Remote Code Execution (RCE) flaws and several zero-days. The update focuses on pa… The Hacker News · Jun 10, 2026 Critical CVE-2025-10263CVE-2026-8863CVE-2026-45657USzero-dayrcebitlocker
vulnerability Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS Six vulnerabilities, dubbed Proto6, have been identified in protobuf.js, a JavaScript implementation of Protocol Buffers. These flaws could lead to remote code execution (RCE) and denial-of-service (DoS) attacks, primari… The Hacker News · Jun 10, 2026 High CVE-2026-44289CVE-2026-44290CVE-2026-44291node.jsprotobufrce
threat-intel A Record-Breaking Patch Tuesday for June 2026 Microsoft released a record-breaking 200 security patches on June 2026, addressing numerous vulnerabilities across its operating systems and software. Several critical flaws, including those identified by the security re… Krebs on Security · Jun 9, 2026 High CVE-2026-49160CVE-2026-45586CVE-2026-50507USzero-daypatch tuesdayai
threat-intel Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility This article from Palo Alto Unit 42 details how attackers are exploiting cloud logging services, specifically AWS CloudTrail and Google Cloud Logging, to evade detection and gain continuous visibility into target environ… Palo Alto Unit 42 · Jun 9, 2026 High cloud securityloggingevasion
threat-intel OpenClaw AI agent found falling for phishing attacks, spills user data An OpenClaw AI agent, designed to monitor email and perform automated tasks, was successfully tricked by phishing attacks, highlighting vulnerabilities in AI systems’ ability to discern malicious intent. Researchers at V… BleepingComputer · Jun 9, 2026 High aiphishingcredentials
supply-chain Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories A sophisticated supply chain attack, orchestrated by the Miasma worm (a variant of Shai-Hulud), targeted 73 Microsoft GitHub repositories, primarily within the Azure organization. The attack, initially discovered through… Dark Reading · Jun 9, 2026 High supply chaingithubazure