vulnerability Schneider Electric PowerLogic P7 Schneider Electric has identified and addressed vulnerabilities within its PowerLogic™ P7 protection and control platform. Specifically, the product is susceptible to CWE-476 (NULL Pointer Dereference), CWE-78 (Improper… CISA Advisories · Jun 25, 2026 High CVE-2026-9716CVE-2026-9717CVE-2026-9718FRcwefirmwareindustrial control
ransomware Europe Evolves Into Ransomware's Favorite Region Ransomware attacks in Europe have dramatically increased, representing a significant shift from previous trends. Black Kite researchers report a 55% rise in ransomware attacks across the continent through the first four… Dark Reading · Jun 25, 2026 High UKGEFRransomwaresupply-chainai
threat-intel Russian Initial Access Broker Behind FortiBleed Campaign A Russian initial access broker (IAB) is targeting over 430,000 FortiGate firewalls globally as part of the FortiBleed campaign, harvesting credentials and selling access to other malicious actors. The campaign utilizes… SecurityWeek · Jun 23, 2026 High USGBNLcredential harvestingfirewallsupply chain
threat-intel French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation This article reports on a discussion at the G7 summit regarding the regulation of advanced artificial intelligence (AI) systems, particularly focusing on the U.S. government’s restriction on access to Anthropic’s latest… SecurityWeek · Jun 20, 2026 Medium FRUNCAaiartificial intelligenceregulation
threat-intel Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites An international law enforcement operation, dubbed Operation Endgame, successfully disrupted SocGholish’s infrastructure and removed malware from nearly 15,000 WordPress websites. The takedown, involving agencies from mu… The Hacker News · Jun 19, 2026 High NLCADEbotnetwordpressmalware
threat-intel FIFA Bug Exposed World Cup Streams to Remote Takeover A vulnerability in FIFA's Microsoft Entra environment allowed an ethical hacker, "BobDaHacker," to gain unauthorized access to global World Cup streams, match management systems, and related data platforms. The issue ste… Dark Reading · Jun 18, 2026 High USFRCOaccess-controlvulnerabilityauthentication
threat-intel Close Encounters of the Human Kind This article from Cisco Talos details a novel approach to reverse engineering that leverages AI agents alongside traditional tools like the VB6 disassembler. The key innovation is exposing the disassembler's parsed data… Cisco Talos · Jun 18, 2026 High GBFRUSreverse engineeringaiautomation
vulnerability Schneider Electric EasyLogic T150 and Saitel DP This advisory details a vulnerability (CVE-2026-6865) affecting Schneider Electric’s EasyLogic T150 and Saitel DP Remote Terminal Units & Controllers. The vulnerability, a CWE-22 ‘Path Traversal’ flaw, allows an attacker… CISA Advisories · Jun 18, 2026 High CVE-2026-6865FRpath traversalfirmwareremote terminal unit
ransomware Killing me gently: Inside Gentlemen’s EDR killer framework The Gentlemen ransomware-as-a-service (RaaS) gang has emerged as a significant and technically agile threat, distinguished by its proactive development and maintenance of a comprehensive suite of Endpoint Detection and R… WeLiveSecurity · Jun 18, 2026 High THBRFRransomwareedrrd
threat-intel Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline A junior hacker, identified as ‘Poisson,’ infiltrated a French automotive business by exploiting vulnerabilities and establishing persistent access after his command-and-control server was taken down. He utilized OpenSSH… The Hacker News · Jun 17, 2026 Medium FRDEpersistenceremote-accessssh
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
threat-intel UK Social Media Ban for Minors Has Privacy Experts Worried The UK is implementing a ban on user-to-user social media platforms for individuals under 16, following similar legislation in Canada and Australia, driven by concerns about the impact of social media on young people. Th… Dark Reading · Jun 17, 2026 Medium UKCAAUsocial mediaage verificationprivacy
supply-chain GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say A supply-chain worm, dubbed Shai-Hulud, is exploiting design flaws in GitHub to infect hundreds of software packages and developer accounts worldwide. The vulnerabilities, initially flagged by Deep Specter Research, were… The Record · Jun 16, 2026 High GBFRsupply chainvulnerabilitygithub
malware Fileless Phantom Stealer Targets Browser Credentials A new fileless malware, Phantom Stealer, is being deployed through targeted phishing campaigns against banks and high-value organizations. The malware focuses on stealing browser credentials and session cookies, utilizin… Dark Reading · Jun 16, 2026 High GBDEFRcredential theftbrowser securityfileless malware
threat-intel China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Researchers have identified new Windows variants of the SprySOCKS backdoor, initially linked to the Chinese state-sponsored threat actor Earth Lusca (also known as Aquatic Panda). These variants, designated WIN_DRV and W… The Hacker News · Jun 16, 2026 High CVE-2023-24932CNTWHUbackdoorwindowsstealth
policy UK to ban social media access for children under 16 The UK government is planning to ban social media access for individuals under 16, mirroring a similar measure implemented in Australia. This initiative aims to protect children online by restricting access to user-to-us… The Record · Jun 16, 2026 Medium UKAUSPsocial mediachildrenonline safety
threat-intel DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act The U.S. Department of Justice seized the CFAKE.com and SOCFAKE.com websites, which hosted deepfake nude images and videos of public figures, under the TAKE IT DOWN Act. This marks the first public use of the legislation… BleepingComputer · Jun 15, 2026 High USITFRdeepfakeaipornography
threat-intel North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels North Korean threat actors, operating under the UNK_DeadDrop campaign, are employing a sophisticated phishing technique targeting developers across numerous sectors, including finance and cryptocurrency, using malicious… The Hacker News · Jun 15, 2026 High USGBAUdevelopergithubvscode
threat-intel French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker A breach of the French government’s secure messaging platform, Tchap, has resulted in the theft of personal data for over 70,000 government employees. The incident was initially attributed to a threat actor calling itsel… SecurityWeek · Jun 15, 2026 High FRdata-breachgovernmentcredential theft
data-breach Over 73,000 French govt employees affected in Tchap messenger breach A breach of the French government’s Tchap messaging platform has affected over 73,000 employees within the public sector. The attackers exploited a compromised user account to access public chat room data, including name… BleepingComputer · Jun 12, 2026 High FRmessagingdata breachencryption