phishing Belarus-linked hackers target Gmail accounts of Polish public figures and their families A Belarus-linked hacking group, GhostWriter (UNC1151/Storm-0257), has expanded its phishing operations to target the personal Gmail accounts of Polish public figures and their families. The group’s tactics involve creati… The Record · Jun 14, 2026 High PLBYUAphishingpolandbelarus
threat-intel Ex-school district employee jailed for hacks on former employer A former IT employee, Ezekiel Dean Potter, was sentenced to prison for a prolonged cyberattack against the Saydel Community School District. Potter exploited his previous access to disrupt operations, steal data, and cau… BleepingComputer · Jun 13, 2026 High UScyberattackdata-breachaccount-compromise
vulnerability Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication A critical vulnerability (CVE-2026-20253) has been identified in Splunk Enterprise versions below 10.2.4 and 10.0.7, allowing unauthenticated users to execute arbitrary code and potentially gain remote access. The flaw s… The Hacker News · Jun 13, 2026 Critical CVE-2026-20253USremote code executionauthenticationpostgresql
threat-intel US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos Anthropic has temporarily blocked access to its Fable 5 and Mythos 5 AI models following a directive from the US government citing national security concerns. The order restricts access to these models by foreign nationa… BleepingComputer · Jun 13, 2026 Medium USUKaijailbreaknational security
threat-intel U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals Following a U.S. government order, Anthropic has been instructed to temporarily suspend access to its advanced AI models, Claude Fable 5 and Mythos 5, for all foreign nationals due to national security concerns. The orde… The Hacker News · Jun 13, 2026 Medium USaijailbreakcybersecurity
ransomware ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed A ShinyHunters ransomware group exploited a zero-day vulnerability in Oracle's PeopleSoft software suite to compromise over 300 instances across more than 100 organizations, primarily targeting higher education instituti… Dark Reading · Jun 12, 2026 High CVE-2026-35273USUKzero-daypeoplesoftransomware
phishing Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing Google has filed a lawsuit against a Chinese cybercrime network, Outsider, for using its Gemini AI agent to conduct massive smishing attacks targeting Americans. The network operates a phishing-as-a-service (PhaaS) platf… The Hacker News · Jun 12, 2026 High CHUSaiphishingsmishing
data-breach Privacy own-goal: World Cup blunder leaks Lionel Messi’s passport details A significant security blunder occurred during the Argentina World Cup warm-up match, resulting in the public release of passport details for all players on the squad. This incident highlights a failure to properly redac… Graham Cluley · Jun 12, 2026 Medium USARpassportdata-leakredaction
data-breach Bankruptcy admin approves settlement fund of $47 million for 23andMe data breach victims A bankruptcy court has approved a $46.8 million settlement for approximately 7 million 23andMe customers affected by a 2023 data breach. Hackers accessed sensitive genetic data, including DNA Relatives profiles and Famil… The Record · Jun 12, 2026 High USdata breachdnagenetic data
threat-intel Major US surveillance program poised to lapse after legislative deadlock This article reports on a looming lapse in the US surveillance program, Section 702 of the FISA, due to legislative deadlock in Congress. The program, which allows intelligence agencies to collect communications of forei… The Record · Jun 12, 2026 High USIRCHfisasurveillanceintelligence
malware Over 400 Arch Linux packages compromised to push rootkit, infostealer Over 400 Arch Linux packages within the AUR repository have been compromised, distributing a Linux rootkit and infostealer malware designed to steal developer credentials and access tokens. The attack involved a maliciou… BleepingComputer · Jun 12, 2026 High USrootkitinfostealeraur
threat-intel Claude Fable 5 Doesn't Change the Mythos Security Story This article discusses Anthropic's release of Claude Fable 5 and Mythos 5 AI models, highlighting concerns about their potential to exploit vulnerabilities in software. While Anthropic has implemented safeguards like saf… Dark Reading · Jun 12, 2026 High USaicybersecurityvulnerability
threat-intel Iranian Cyber Group Handala Claims Cal Water Hack The Iranian cyber threat actor Handala has claimed responsibility for a data breach targeting California Water Service (Cal Water), resulting in the theft of 5GB of data including customer information and credentials. Th… SecurityWeek · Jun 12, 2026 High USIRirandata breachcyber espionage
threat-intel LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution A critical vulnerability chain in LangGraph, an open-source AI agent framework, has been disclosed, allowing for remote code execution via SQL injection and unsafe deserialization. The flaws, affecting versions prior to… The Hacker News · Jun 12, 2026 Critical CVE-2025-67644CVE-2026-28277CVE-2026-27022USsql injectionremote code executionai agent
vulnerability Ivanti Sentry Exploitation Attempts Hitting Honeypots A recently patched vulnerability in Ivanti Sentry, CVE-2026-10520, has been observed attempting exploitation on honeypots, according to Ivanti and CISA. The flaw allows for remote code execution with root privileges via… SecurityWeek · Jun 12, 2026 High CVE-2026-10520USvulnerabilitycommand injectionroot privilege
threat-intel Phishing Attack Volume Down 20%, but Risk Still Rising The volume of phishing attacks has decreased by 20% across multiple industries, despite a shift towards more sophisticated attacks utilizing AI. Threat actors are prioritizing targeted campaigns with higher conversion ra… Dark Reading · Jun 12, 2026 High CAESAUphishingaicloud
threat-intel Maine breach portal abused to publish fake data breach disclosures A fraudulent data breach disclosure was falsely submitted to Maine’s official breach portal, attributed to VRChat, and subsequently published before verification. The fake notification detailed a supposed hack impacting… BleepingComputer · Jun 11, 2026 Medium USmisinformationdata breachfraudulent
vulnerability ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities The ShinyHunters extortion group exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft to gain unauthorized access to university systems, resulting in data theft and a demand for payment. Mandiant iden… The Hacker News · Jun 11, 2026 High CVE-2026-35273GBUSzero-dayexploitationuniversity
threat-intel A tale of two eras This article is a reflective piece by a cybersecurity analyst reminiscing about early technology and highlighting a critical shift in the threat landscape. The author uses a personal anecdote about a childhood discovery… Cisco Talos · Jun 11, 2026 High USaivulnerabilitycybersecurity
threat-intel New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets A research report highlighted vulnerabilities in OpenClaw, a popular self-hosted AI agent, revealing that attackers could trick the agent into running malicious code or leaking sensitive data by embedding instructions wi… The Hacker News · Jun 11, 2026 High USaiagentprompt injection