threat-intel ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing ClickLock Stealer, a new macOS malware, bypasses macOS security through social engineering and aggressive process killing to steal sensitive data, including browser data, cryptocurrency wallets, and password manager information. Researchers have identified over 100 victims across 33 countries, primarily in Europe, with… SecurityWeek · Jul 16, 2026 High DEFRITmacossocial engineeringprocess killing
threat-intel EU takes member states to court over unimplemented cybersecurity law The European Commission has filed legal action against Ireland, Spain, France, and the Netherlands for failing to implement the NIS2 Directive, a cybersecurity law designed to improve security for critical infrastructure… The Record · Jul 9, 2026 Medium IEESFRcybersecurityeu lawcritical infrastructure
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
data-breach Over 20,000 Instagram accounts stolen in Meta AI support hack Over 20,000 Instagram accounts were compromised due to a vulnerability in Meta’s AI-powered support system, High Touch Support (HTS). Attackers exploited the system to reset passwords, gaining unauthorized access to user… BleepingComputer · Jun 8, 2026 High IEaipasswordaccount takeover
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa