vulnerability Hubbell Aclara Metrum Cellular Web Interface This CISA advisory details a vulnerability in Hubbell Aclara Metrum Cellular Web Interface software, specifically versions prior to 2.1.0.105. The flaw allows unauthorized access to critical device settings, potentially… CISA Advisories · Jun 23, 2026 High CVE-2026-1840USfirmwareauthenticationcritical infrastructure
vulnerability FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances A critical vulnerability, dubbed PixelSmash, has been identified in FFmpeg, a widely used media processing framework. The flaw allows for remote code execution (RCE) via crafted media files, potentially impacting a broad… SecurityWeek · Jun 23, 2026 Critical CVE-2026-8461USUKremote code executionmedia processingheap overflow
threat-intel Agentic AI: The Weapon That No Longer Needs a Warrior This article discusses the rise of "Agentic AI" in offensive cyber operations, where AI systems autonomously execute attacks without direct human control. Previously, AI acted as a tool assisting humans in crafting attac… The Hacker News · Jun 23, 2026 High USaiautomationphishing
threat-intel OpenAI Refocuses Cybersecurity Efforts on Patching Over Discovery OpenAI is shifting its cybersecurity strategy from solely discovering vulnerabilities to accelerating the process of patching them, recognizing the overwhelming volume of findings generated by AI. The company is deployin… SecurityWeek · Jun 23, 2026 Medium USaicybersecuritypatching
threat-intel Russian Initial Access Broker Behind FortiBleed Campaign A Russian initial access broker (IAB) is targeting over 430,000 FortiGate firewalls globally as part of the FortiBleed campaign, harvesting credentials and selling access to other malicious actors. The campaign utilizes… SecurityWeek · Jun 23, 2026 High USGBNLcredential harvestingfirewallsupply chain
malware Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT A series of malicious npm packages, disguised as PostCSS tools, have been discovered delivering a Windows-based remote access trojan (RAT). These packages, published by 'abdrizak', leveraged legitimate build tooling to d… The Hacker News · Jun 23, 2026 High USnpmsupply-chainrat
threat-intel CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd) This report details a significant ongoing cyber threat targeting SonicWall firewalls exploiting CVE-2024-40766, a critical access control vulnerability. Ransomware groups, notably Akira and Fog, have been actively levera… SANS Internet Storm Center · Jun 23, 2026 Critical CVE-2024-40766CVE-2024-12802USGBvpncredential theftransomware
threat-intel FFmpeg fixes PixelSmash flaw in widely used video decoder A vulnerability, dubbed ‘PixelSmash’ (CVE-2026-8461), has been identified in FFmpeg’s MagicYUV decoder, allowing for remote code execution (RCE) on vulnerable systems. The flaw stems from an out-of-bounds write in the de… BleepingComputer · Jun 22, 2026 High CVE-2026-8461USsupply-chainremote-code-executionheap-overflow
threat-intel FortiBleed campaign used custom FortiGate sniffer to steal credentials The FortiBleed campaign, targeting Fortinet FortiGate devices, utilized a custom Golang tool called "FortigateSniffer" to steal credentials from compromised firewalls. This campaign, active since at least February 2026,… BleepingComputer · Jun 22, 2026 Critical UScredential theftfirewallgpu cracking
threat-intel Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign A sophisticated cybercrime campaign, orchestrated by unknown threat actors, is utilizing a multi-channel approach to distribute a cross-platform clipboard hijacker designed to steal cryptocurrency. The campaign leverages… Dark Reading · Jun 22, 2026 High USclipboard hijackingreputation manipulationcrypto theft
threat-intel He Thought He Was Secure; His Phone Number Got Stolen Anyway This article details a real-world incident where cybersecurity expert Torsten George was targeted by a SIM swap attack, highlighting the vulnerability of relying solely on one-time passwords (OTPs) for security. The atta… Dark Reading · Jun 22, 2026 High USUKAUsim swapotpsocial engineering
threat-intel A Glimpse into the “Search Your Target” Market for Stolen Credentials This report details a growing underground market where threat actors are offering ‘search your target’ services, leveraging massive collections of stolen credentials. Researchers analyzed 470 forum posts revealing a serv… BleepingComputer · Jun 22, 2026 High UScredential theftinfostealerunderground market
threat-intel Stop Your Legacy Infrastructure from Hijacking Your AI Agents This article highlights a significant security risk: attackers leveraging legacy infrastructure to compromise AI agent environments. Despite organizations investing heavily in securing AI workloads against direct attacks… The Hacker News · Jun 22, 2026 High CVE-2025-24813USailegacypermissions
threat-intel Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices Canadian spy agency, CSIS, utilized a novel court-ordered warrant to neutralize two foreign-run botnets operating within Canada. The operation targeted infected servers, SOHO routers, and IoT devices like Ring doorbells… The Hacker News · Jun 22, 2026 High CAUSbotnetiotcybersecurity
vulnerability Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys A vulnerability in the Gravity SMTP WordPress plugin has been exploited by attackers, allowing them to extract sensitive data such as API keys and configuration details from approximately 100,000 sites. The flaw, tracked… The Hacker News · Jun 20, 2026 Medium CVE-2026-4020USwordpressapicredentials
supply-chain Klue OAuth breach victim list grows as Icarus hackers claim attack A security breach at Klue, a market intelligence platform, has resulted in the theft of OAuth tokens used to connect to customer Salesforce environments. The attack, attributed to the ‘Icarus’ extortion group, impacted m… BleepingComputer · Jun 19, 2026 High USoauthsalesforcedata breach
threat-intel Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain Researchers at Paradigm Shift have developed ‘usbliter8’, an exploit that allows arbitrary code execution within the SecureROM of Apple’s A12 and A13 chips. The exploit leverages a hardware flaw in the Synopsys DWC2 USB… The Hacker News · Jun 19, 2026 High USsecureromusbdfu
threat-intel Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites An international law enforcement operation, dubbed Operation Endgame, successfully disrupted SocGholish’s infrastructure and removed malware from nearly 15,000 WordPress websites. The takedown, involving agencies from mu… The Hacker News · Jun 19, 2026 High NLCADEbotnetwordpressmalware
threat-intel CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices CISA has issued a warning to Fortinet customers regarding FortiBleed, a campaign targeting 86,644 FortiGate devices globally. The attack, attributed to Russian-speaking threat actors, leverages a two-step approach involv… The Hacker News · Jun 19, 2026 High USINMEcredential_stuffingdefault_credentialspassword_reuse
phishing Imposter scams cost Americans $3.5 billion in 2025 – and it’s getting worse Imposter scams have surged in the United States, resulting in a staggering $3.5 billion in financial losses for consumers in 2025. These scams typically involve fraudulent impersonations of trusted entities like banks an… Graham Cluley · Jun 19, 2026 High USscamsfraudidentity theft