threat-intel DHS chief says president has met with potential CISA nominee; agency plans to hire 600 The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) is seeking to rebuild its workforce following significant layoffs and a prolonged period without a Senate-confirmed direc… The Record · Jun 25, 2026 Medium CHUScisacybersecurityhomeland security
phishing Bluekit phishing kit adopts browser-in-the-middle for login theft Bluekit, a phishing-as-a-service platform, has evolved by incorporating browser-in-the-middle (BitM) capabilities, allowing it to steal login credentials more effectively. The platform utilizes the rrweb JavaScript libra… BleepingComputer · Jun 25, 2026 High USphishingbitmbrowser-in-the-middle
threat-intel Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability A popular Google Chrome ad blocker extension, Adblock for YouTube, with over 10 million installs, has been found to contain a dormant script injection capability. Researchers discovered the extension’s architecture allow… The Hacker News · Jun 25, 2026 High USadblockjavascriptprivacy
threat-intel ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories This article reports on several security vulnerabilities and trends, including a privacy-preserving protocol from Cloudflare, six vulnerabilities in the curl library, a critical security flaw in Hoppscotch allowing unaut… The Hacker News · Jun 25, 2026 High CVE-2026-8932CVE-2026-50160USKRsmart tvproxywareiot
vulnerability Daktronics Controller Firmware This CISA advisory details a vulnerability in Daktronics Controller Firmware versions up to v10.34.x.x, allowing unauthenticated users to gain root-level access and potentially execute arbitrary code due to a lack of pro… CISA Advisories · Jun 25, 2026 Critical CVE-2026-28701CVE-2026-33560CVE-2026-31928USfirmwareroot accessfile upload
vulnerability Horner Automation Cscape This advisory details a critical vulnerability in Horner Automation’s Cscape software, specifically versions prior to 10.2_SP3. The vulnerability allows for out-of-bounds reads, potentially leading to information disclos… CISA Advisories · Jun 25, 2026 Critical CVE-2026-12897UScscapeout-of-boundsvulnerability
threat-intel EVoke Systems Charging Station Management System This advisory details a vulnerability in the EVoke Systems Charging Station Management System (CSMS) due to a lack of proper authentication mechanisms in its WebSocket endpoints. Attackers could exploit this to gain unau… CISA Advisories · Jun 25, 2026 High CVE-2026-40702CVE-2026-50176CVE-2026-54479USwebsocketocppauthentication
vulnerability Yokogawa FAST/TOOLS and CI Server This advisory details a vulnerability in Yokogawa FAST/TOOLS and CI Server software, specifically versions R9.01 to R10.04, that allows an attacker to potentially retrieve CI Server setting information. The vulnerability… CISA Advisories · Jun 25, 2026 Medium CVE-2026-11833USweb servercwe-319vulnerability
vulnerability OHIF Viewers DICOM This advisory details a vulnerability in the OHIF Viewers DICOM framework, specifically versions up to v3.12.0, that allows attackers to steal authenticated user tokens via crafted links. The vulnerability stems from unc… CISA Advisories · Jun 25, 2026 High CVE-2026-12473USssrfdicomweboidc
threat-intel Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools This Securelist article details Kaspersky's 2026 threat analysis for small and medium-sized businesses (SMBs), highlighting a significant increase in cyberattacks disguised as artificial intelligence (AI) tools, particul… Securelist · Jun 25, 2026 High USaismbmalware
threat-intel New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new stealthy backdoor, Mistic (MLTBackdoor), linked to the KongTuke IAB has been used in financially motivated attacks targeting organizations across insurance, education, IT, and professional services since April 2026… The Hacker News · Jun 25, 2026 High USbackdoorremote access trojanclickfix
malware What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th) This SANS Internet Storm Center guest diary details an analysis of automated cybercrime activity observed through a honeypot, focusing on the Terrabot IoT botnet. The author, a BACS student, highlights the prevalence of… SANS Internet Storm Center · Jun 25, 2026 Medium CVE-2016-20017CVE-2018-10561CVE-2016-20016USiotbotnetscanning
vulnerability Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access A Mandiant report details how attackers exploited a zero-day vulnerability (CVE-2026-20245) in Cisco SD-WAN Manager, Controller, and Validator software to gain root access on targeted devices. The attackers initially gai… BleepingComputer · Jun 24, 2026 High CVE-2026-20245CVE-2026-20127CVE-2026-20182USzero-dayprivilege escalationroot access
vulnerability Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure Attackers exploited a critical vulnerability in Cisco Catalyst SD-WAN Controller (CVE-2026-20245) approximately two months before Cisco publicly disclosed it. The vulnerability, stemming from insufficient input validatio… Dark Reading · Jun 24, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127USsd-wanprivilege escalationzero-day
malware Malicious Edge extension abuses Native Messaging as bridge to malware A malicious Microsoft Edge extension, ‘Edgecution,’ was used in a ransomware attack by exploiting Native Messaging to bypass browser security sandboxes and deploy a Python-based backdoor. The attack, linked to the Payout… BleepingComputer · Jun 24, 2026 High USbrowser extensionnative messagingransomware
threat-intel 2026 FIFA World Cup Faces Surge in Cyber Threats The 2026 FIFA World Cup is facing a surge in cyber threats across the US, Canada, and Mexico, driven by a complex threat landscape including financial and nation-state actors. These threats primarily involve social engin… Dark Reading · Jun 24, 2026 High USCAMXcybercrimesocial engineeringfraud
threat-intel More Malicious OpenClaw Skills Threaten AI Supply Chain A recent investigation by Palo Alto Networks' Unit 42 revealed five malicious skills hidden within OpenClaw's ClawHub marketplace, a platform for AI agent skills. These skills, including infostealers, detection evasion t… Dark Reading · Jun 24, 2026 High USaisupply chaininfostealer
ransomware Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered A coordinated international law enforcement operation, involving Bitdefender, Bitsight, ESET, Microsoft, and Europol, successfully disrupted the Amadey and StealC malware networks, recovering 27 million stolen credential… The Hacker News · Jun 24, 2026 High NLCADEmaascredential theftransomware
ransomware Amadey, StealC malware operations disrupted in Operation Endgame action Operation Endgame, a coordinated law enforcement effort involving Microsoft, Europol, and international partners, successfully disrupted infrastructure used by the Amadey and StealC malware operations. The operation resu… BleepingComputer · Jun 24, 2026 High USCADKmalware-as-a-servicecredential theftransomware
data-breach Third DraftKings Hacker Sentenced to 18 Months in Prison A third individual, Nathan Austad, has been sentenced to 18 months in prison for his involvement in a 2022 hacking attack against DraftKings. The attack, utilizing credential stuffing, compromised over 60,000 DraftKings… SecurityWeek · Jun 24, 2026 High USALUAcredential stuffingonline gamblingcybercrime