vulnerability Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE A critical vulnerability, CVE-2026-5027, in the Langflow low-code platform has been actively exploited, allowing for remote code execution due to a lack of input sanitization. This flaw, combined with unauthenticated aut… The Hacker News · Jun 10, 2026 Critical CVE-2026-5027CVE-2026-0770CVE-2026-33017USCAlow-codeairemote code execution
threat-intel Anthropic Urges Industry Coordination to Allow for a ‘Pause’ in AI Development if Risks Grow Anthropic is advocating for a global pause in the development of advanced AI systems due to concerns about rapidly increasing capabilities and the potential for losing control. The company proposes coordinated action amo… SecurityWeek · Jun 8, 2026 High CAartificial intelligenceai safetycybersecurity
threat-intel Exposed Fuel Tank Gauges Under Attack in the US Internet-exposed fuel tank gauges in the United States are being targeted by cyberattacks, posing a significant risk to gas stations and industrial facilities. The Cybersecurity and Infrastructure Security Agency (CISA)… Dark Reading · Jun 5, 2026 High USCAAUindustrial control systemscybersecuritytank gauges
threat-intel Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 A joint bulletin from the FBI, MI5, ASIO, CSIS, and NZSIS warns of a Chinese intelligence operation targeting Western professionals via LinkedIn and other job platforms. The operation involves posing as recruitment firms… Graham Cluley · Jun 5, 2026 High CHUNAUrecruitmentintelligencelinkedin
threat-intel Adaptive, Agentic AI Worms Loom as Next Enterprise Threat This article discusses the emerging threat of adaptive, agentic AI worms, which are designed to autonomously seek out and exploit vulnerabilities in systems, similar to traditional worms but with the added capability of… Dark Reading · Jun 5, 2026 High CAUSaiwormadaptive
threat-intel Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities The Five Eyes intelligence alliance has issued an alert warning of a sophisticated Chinese espionage campaign targeting government and military personnel through fake job opportunities on platforms like LinkedIn. This ta… SecurityWeek · Jun 5, 2026 High CHUNAUespionagesocial-engineeringrecruitment
threat-intel FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins A wave of fraudulent activity targeting FIFA World Cup 2026 fans is underway, involving fake websites, banking malware, and stolen login credentials. The operation, spearheaded by the Chinese-speaking group ‘GHOST STADIU… The Hacker News · Jun 5, 2026 High USCAMXfraudphishingmalware
threat-intel Five Eyes warn Chinese spies are using job sites to recruit insiders The Five Eyes intelligence alliance has issued a joint warning about Chinese military intelligence services using online job platforms to recruit individuals with access to sensitive information. This tactic, described a… The Record · Jun 4, 2026 High CHAUCArecruitmentespionagecybersecurity
malware FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads A new macOS malvertising campaign, dubbed Operation FlutterBridge, is utilizing FlutterShell, a backdoor that spreads adware via malicious Google and YouTube ads. The campaign, traced back to the CL-CRI-1089 threat actor… The Hacker News · Jun 4, 2026 High USCAAUmalvertisingmacoswebview
threat-intel DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets The U.S. Department of Justice, in collaboration with numerous international law enforcement agencies and private sector companies, disrupted a network of cybercrime groups operating out of Southeast Asia that were defra… The Hacker News · Jun 4, 2026 High USTHAUcryptocurrencyfraudscam
malware Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content A new malware campaign, dubbed Weedhack, is targeting Minecraft players through YouTube and malicious websites, distributing a MaaS (Malware-as-a-Service) tool. The campaign, active since January 2026, utilizes SEO poiso… The Hacker News · Jun 3, 2026 High USDEINminecraftmalwareyoutube
threat-intel As Global Powers Explore Humanoid Robots, Cyber-Risk Looms This article discusses the emerging cybersecurity risks associated with the rapid development and deployment of embodied AI, particularly humanoid robots. The core concern is that these systems, currently being developed… Dark Reading · May 28, 2026 High CHRUCAembodied aicyberespionagerobotics
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
threat-intel Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans A Chinese-speaking fraud gang, dubbed GHOST STADIUM, is impersonating FIFA's official website to steal credentials and payment details from fans seeking tickets for the 2026 World Cup. The operation, involving over 300 f… The Record · May 28, 2026 High CNUSCAfraudphishingworld cup
threat-intel 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface This analysis from Palo Alto Unit 42 assesses the significant cyber threat landscape surrounding the 2026 FIFA World Cup, highlighting the expanded attack surface created by the event's scale and complexity. The report i… Palo Alto Unit 42 · May 28, 2026 High USIRRUmega-eventcybersecuritythreat intelligence
threat-intel Sextortionist sentenced to 33 years for targeting 145 children A Canadian man, Ramanan Pathmanathan, has been sentenced to 33 years in prison for a long-running sextortion scheme targeting over 145 children, primarily in the United States. The scheme involved blackmailing victims wi… BleepingComputer · May 28, 2026 Critical CAUSsextortionchild_exploitationonline_abuse
threat-intel Smashing Security podcast #469: What your Oura ring won’t tell you This podcast episode, "Smashing Security" #469, discusses cybersecurity concerns, primarily focusing on the potential vulnerabilities of wearable devices like the Oura ring and broader issues within the cybersecurity ind… Graham Cluley · May 27, 2026 Medium CARUwearablesiotmalware
phishing FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required The FBI has issued a warning about Kali365, a phishing-as-a-service kit that allows attackers to compromise Microsoft 365 accounts without needing passwords, even when MFA is enabled. This kit leverages device code flow,… Graham Cluley · May 26, 2026 High USCAGBmfadevice-code-flowphishing
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups A global operation, dubbed Operation Saffron, led by France and the Netherlands, successfully dismantled the First VPN service, a virtual private network specifically designed for criminal use. The service was utilized b… The Hacker News · May 22, 2026 High USFRNLvpnransomwareanonymity