threat-intel Meeting Trump's 2030 Quantum Deadline Will be Expensive, Complex This article discusses the US government's accelerated efforts to prepare for the advent of quantum computing, driven by executive orders focused on post-quantum cryptography (PQC). The government is mandating a transiti… Dark Reading · Jun 26, 2026 High USquantum computingpost-quantum cryptographypqc
apt Turla group adds more malware to Russia’s espionage efforts against Ukraine The Turla group, a long-standing Russian cyber-espionage team, has expanded its operations against Ukraine by deploying a new malware strain called StockStay. This malware, developed since December 2022, targets Ukrainia… The Record · Jun 26, 2026 High UKITNEcyberespionagerussiaukraine
threat-intel Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant A phishing campaign targeting hotels and hospitality organizations is underway, utilizing deceptive ZIP files containing Node.js implants to gain access to front-desk machines. The campaign, discovered by Microsoft, empl… The Hacker News · Jun 26, 2026 High GBJPDKphishingnode.jston
threat-intel Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets Russia-linked APT Turla has been deploying a new .NET backdoor, dubbed StockStay, to conduct ongoing cyber espionage against Ukrainian government and military organizations, as well as entities with interests in Italian… SecurityWeek · Jun 26, 2026 High CVE-2025-8088UKRUITespionagebackdoorphishing
threat-intel Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks Google Threat Intelligence Group (GTIG) has identified a new backdoor, STOCKSTAY, developed and deployed by the Russian state-sponsored threat actor Turla. This multi-component backdoor, built using .NET and leveraging a… The Hacker News · Jun 26, 2026 High CVE-2025-8088UKITNEespionagebackdoorrussia
threat-intel EdTech Attackers Shift From Schools to Their Software Suppliers This article reports a concerning shift in cyberattacks targeting the education sector, with attackers now focusing on edtech software suppliers like Instructure and Oracle rather than individual schools. The Shiny Hunte… Dark Reading · Jun 25, 2026 High edtechsupply chainransomware
threat-intel DHS chief says president has met with potential CISA nominee; agency plans to hire 600 The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) is seeking to rebuild its workforce following significant layoffs and a prolonged period without a Senate-confirmed direc… The Record · Jun 25, 2026 Medium CHUScisacybersecurityhomeland security
threat-intel AI and Liability A German court ruled that Google is liable for its AI-generated search summaries, marking a significant shift in how internet publishers are held accountable. The ruling established that AI-generated content, particularl… Schneier on Security · Jun 25, 2026 Medium DEailiabilitygoogle
threat-intel Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability A popular Google Chrome ad blocker extension, Adblock for YouTube, with over 10 million installs, has been found to contain a dormant script injection capability. Researchers discovered the extension’s architecture allow… The Hacker News · Jun 25, 2026 High USadblockjavascriptprivacy
threat-intel ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories This article reports on several security vulnerabilities and trends, including a privacy-preserving protocol from Cloudflare, six vulnerabilities in the curl library, a critical security flaw in Hoppscotch allowing unaut… The Hacker News · Jun 25, 2026 High CVE-2026-8932CVE-2026-50160USKRsmart tvproxywareiot
threat-intel Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access A zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN was exploited by an unknown threat actor, gaining root access to a communications service provider’s network. The attack involved anti-forensic technique… The Hacker News · Jun 25, 2026 Critical CVE-2026-20245CVE-2026-20127CVE-2026-20182zero-daysd-wanroot access
threat-intel Google releases new privacy controls for activity history, personalization Google is releasing new privacy controls for its Search services and Google Play, allowing users to manage their saved history and personalized recommendations more granularly. The changes separate these functions into d… BleepingComputer · Jun 24, 2026 Low privacysearchpersonalization
threat-intel When Information Becomes the Attack Surface – Understanding AI Agent Traps This article discusses a new security risk related to AI agents – "traps" – where malicious information can be injected into the data sources an agent uses, leading it to make incorrect decisions or take unintended actio… SecurityWeek · Jun 24, 2026 High aiagentsecurity
ransomware Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered A coordinated international law enforcement operation, involving Bitdefender, Bitsight, ESET, Microsoft, and Europol, successfully disrupted the Amadey and StealC malware networks, recovering 27 million stolen credential… The Hacker News · Jun 24, 2026 High NLCADEmaascredential theftransomware
supply-chain Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks A new vulnerability, dubbed 'Cordyceps,' has been discovered in CI/CD workflows, allowing unauthorized access and control over hundreds of GitHub repositories across major tech companies. The flaw stems from overly permi… The Hacker News · Jun 24, 2026 Critical cicdsupply chaingithub
supply-chain Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking A new vulnerability, dubbed ‘Cordyceps,’ has been identified within CI/CD workflows across numerous open-source projects, allowing unauthorized access and control over developer repositories. The flaws, primarily found i… SecurityWeek · Jun 24, 2026 High ci/cdsupply chaingithub actions
supply-chain 'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows A new vulnerability, dubbed "Cordyceps," is targeting CI/CD workflows across several open-source projects, including Azure Sentinel, Doris, Workers SDK, and Black. Attackers can exploit weak automated processes within th… Dark Reading · Jun 23, 2026 High cicdsupply chainpull requests
malware New macOS ClickFix attack silently mounts DMGs to push infostealer A new macOS ClickFix campaign is using Terminal commands to silently deploy the Atomic macOS Stealer (AMOS) infostealer, targeting users through fake CAPTCHA pages. The malware steals sensitive data like browser credenti… BleepingComputer · Jun 23, 2026 High USmacosclickfixinfostealer
threat-intel Compromise kids online safety bill unveiled by House leaders, with key omission A revised version of the Kids Online Safety Act (KOSA) has been unveiled by the House Energy and Commerce Committee, aiming for bipartisan support. However, a key element – a ‘duty of care’ provision requiring platforms… The Record · Jun 23, 2026 Medium USonline safetychildren's privacyai regulation
threat-intel Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents This article details an experiment conducted by AIR Security to demonstrate the vulnerabilities within current skill-scanning methods for AI agent skills within popular marketplaces. The firm created a seemingly harmless… The Hacker News · Jun 23, 2026 Medium USaiagentskills