data-breach Cal Water Investigating Iranian Hackers’ Claims California Water Service (Cal Water) is currently investigating claims of a hack by the Iran-linked threat actor Handala, who allegedly stole and leaked sensitive data from the utility’s systems. The incident, potentiall… SecurityWeek · Jun 16, 2026 High USwater sectorcyberattackdata breach
threat-intel Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive A recent study by Spur Intelligence found that anonymized infrastructure, primarily through VPNs and residential proxies, is now a dominant factor in nearly every security incident. Despite the abundance of IP data avail… The Hacker News · Jun 16, 2026 High USanonymizationip intelligencevpn
other Flock Cameras Are Being Used for Stalking Flock Cameras, a manufacturer of residential security cameras, is facing scrutiny due to reports of law enforcement agencies using their systems for excessive and potentially unlawful surveillance. Multiple cases across… Schneier on Security · Jun 16, 2026 High USsurveillanceprivacypolice
ransomware Ransomware gang abuses Microsoft Teams relays to hide malicious traffic DragonForce ransomware utilized a custom malware, Backdoor.Turn, to conceal command-and-control traffic by leveraging Microsoft Teams’ TURN protocol. This technique allowed the attackers to bypass traditional network def… BleepingComputer · Jun 16, 2026 High CVE-2023-52271CVE-2025-61155CVE-2025-1055USteamsturnrat
threat-intel China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Researchers have identified new Windows variants of the SprySOCKS backdoor, initially linked to the Chinese state-sponsored threat actor Earth Lusca (also known as Aquatic Panda). These variants, designated WIN_DRV and W… The Hacker News · Jun 16, 2026 High CVE-2023-24932CNTWHUbackdoorwindowsstealth
vulnerability Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw A vulnerability (CVE-2026-20262) in Cisco Catalyst SD-WAN Manager has been actively exploited in the wild, allowing authenticated attackers to overwrite files on affected systems. The flaw stems from inadequate input val… The Hacker News · Jun 16, 2026 High CVE-2026-20262CVE-2026-20245CVE-2026-20182USsd-wancvefile-upload
threat-intel Inside the Modern SOC: The 72-Minute Race This article, from Palo Alto Unit 42, highlights the increasing speed of cyberattacks and the challenges modern Security Operations Centers (SOCs) face in keeping pace. Attackers are leveraging AI and automation to compr… Palo Alto Unit 42 · Jun 15, 2026 High USaiautomationlateral movement
threat-intel DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act The U.S. Department of Justice seized the CFAKE.com and SOCFAKE.com websites, which hosted deepfake nude images and videos of public figures, under the TAKE IT DOWN Act. This marks the first public use of the legislation… BleepingComputer · Jun 15, 2026 High USITFRdeepfakeaipornography
threat-intel Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails A China-linked espionage group, UNC6508, gained access to North American medical, academic, and military research networks via a backdoor on REDCap servers, stealing sensitive research and defense emails. The attackers e… The Hacker News · Jun 15, 2026 High CHUSCAespionageredcapgoogle workspace
threat-intel North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels North Korean threat actors, operating under the UNK_DeadDrop campaign, are employing a sophisticated phishing technique targeting developers across numerous sectors, including finance and cryptocurrency, using malicious… The Hacker News · Jun 15, 2026 High USGBAUdevelopergithubvscode
threat-intel HTTP/2 Bomb Attacks Put Telcos, Healthcare Orgs at Risk This article reports on the ‘HTTP/2 Bomb’ vulnerability, a denial-of-service exploit leveraging features within the HTTP/2 protocol to amplify junk traffic and cause widespread disruptions. The vulnerability affects a si… Dark Reading · Jun 15, 2026 High CVE-2026-49975UShttp2ddosamplification
supply-chain OptinMonster WordPress plugin hacked in CDN supply-chain attack A supply-chain attack targeting the Awesome Motive CDN compromised WordPress plugins OptinMonster, TrustPulse, and PushEngage. Attackers gained access through a vulnerability in the UpdraftPlus plugin, leveraging the CDN… BleepingComputer · Jun 15, 2026 High UScdnwordpresssupply chain
threat-intel China-Nexus Actor Spied on US Researchers Undetected for a Year Google’s Threat Intelligence Group (GTIG) discovered and disrupted a year-long espionage campaign by the China-Nexus threat actor, UNC6508, targeting US academic, medical, and military research institutions. The actor ut… Dark Reading · Jun 15, 2026 High CHUScyber espionageintel gatheringcredential theft
vulnerability LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers A critical vulnerability chain in LiteLLM, an open-source AI gateway, allows low-privilege users to escalate their permissions to full administrator and execute arbitrary code on the server. Researchers at Obsidian Secur… The Hacker News · Jun 15, 2026 Critical CVE-2026-47101CVE-2026-47102CVE-2026-40217USaiproxyprivilege escalation
threat-intel One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes A vulnerability, dubbed SearchLeak, was discovered in Microsoft 365 Copilot Enterprise Search that allowed attackers to exfiltrate sensitive data like emails, calendar details, and MFA codes through a single click. The f… The Hacker News · Jun 15, 2026 High CVE-2026-42824CVE-2025-32711UScommand injectionprompt injectionbing
threat-intel The Beginning of the End of Social Engineering This article discusses a significant shift in cybersecurity driven by the integration of AI-native operating systems, particularly Google's Gemini and Apple's Apple Intelligence. Operating systems are evolving to activel… Dark Reading · Jun 15, 2026 High USaisocial engineeringauthentication
threat-intel Chinese hackers breach REDCap servers, steal medical research A Chinese espionage campaign, attributed to UNC6508, targeted a North American medical research institution by exploiting vulnerabilities in the REDCap platform. The attackers deployed the custom malware, ‘Infinitered,’… BleepingComputer · Jun 15, 2026 High CHUSCAespionagecredential_theftredcap
threat-intel Anthropic says US government forced it to disable cybersecurity AI models Anthropic, a leading AI developer, was compelled by the U.S. government to disable two of its advanced cybersecurity AI models, dubbed Fable 5 and Mythos 5. This action stemmed from an export control directive restrictin… The Record · Jun 15, 2026 Medium USaiexport controlcybersecurity
threat-intel The Onboarding Password Mistake That Creates Unnecessary Risk This article discusses the significant security risks associated with using temporary onboarding passwords, highlighting how they are frequently shared insecurely and remain active for extended periods. The practice crea… The Hacker News · Jun 15, 2026 High USIRonboardingcredentialssecurity
malware Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites A security incident has been discovered affecting over 1.2 million WordPress sites using the PushEngage, OptinMonster, and TrustPulse plugins. An attacker tampered with the plugins' JavaScript files, creating backdoors t… The Hacker News · Jun 15, 2026 High CVE-2026-10795USwordpresscdnbackdoor