ransomware The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm The Gentlemen ransomware group, initially operating as the affiliate-focused Phantom Mantis, has evolved into an independent RaaS operation led by the cybercriminal LARVA-368 (aka hastalamuerte). The group, responsible… The Hacker News · Jun 11, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073RUTHUKransomware-as-a-servicedouble extortionaffiliate program
threat-intel British high school sends students home following cyberattack Great Marlow School in Buckinghamshire, England, experienced a cybersecurity incident that forced the closure of the school for a second day, impacting students and staff. The incident, potentially linked to ransomware a… The Record · Jun 11, 2026 Medium UKUScyberattackschoolransomware
threat-intel Why AI-driven threats are exposing the limits of MSP security stacks This article highlights how artificial intelligence (AI) is dramatically accelerating the pace and scale of cyberattacks, exposing the vulnerabilities of fragmented security stacks, particularly for Managed Service Provi… BleepingComputer · Jun 11, 2026 High USaiautomationmsps
threat-intel ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories This week’s threat intelligence bulletin highlights several concerning developments, including a large-scale leak of identity records facilitated by infostealers, the emergence of a sophisticated MaaS RAT named SilabRAT… The Hacker News · Jun 11, 2026 High CVE-2026-49494USCHNOinfostealersmaas ratcredential theft
malware OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month The OnyxC2 stealer, offered as a "Malware-as-a-Service" (MaaS) product for $250-$500 per month, is a sophisticated tool designed for enterprise-level credential theft. Developed by BlackFog, it boasts a wide range of tar… SecurityWeek · Jun 11, 2026 High USstealercredential theftmalware-as-a-service
threat-intel Naxclow IoT Platform This CISA advisory details a critical vulnerability in the Naxclow IoT Platform, specifically affecting versions of the Smart Doorbell X3, X Smart Home, V720, and ix cam devices. The flaw allows an attacker to impersonat… CISA Advisories · Jun 11, 2026 Critical CVE-2026-42947CVE-2026-50108CVE-2026-50101USiotcredential theftauthentication
threat-intel AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS. The rapid advancement of AI, particularly through tools like Anthropic's Claude Mythos Preview, has dramatically reduced the time it takes to discover and exploit vulnerabilities in software. This has collapsed the tradi… The Hacker News · Jun 11, 2026 High USGBaivulnerabilityexploitation
threat-intel FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers The FBI has taken down thirteen websites used by Chinese intelligence operatives to target and recruit U.S. government employees with access to sensitive information. These websites impersonated consulting firms offering… SecurityWeek · Jun 11, 2026 High USCNespionagerecruitmentcybersecurity
threat-intel Smashing Security podcast #471: This AI worm just rewrote its own rules This episode of Smashing Security discusses an AI worm that is capable of rewriting its own rules, highlighting a concerning trend of AI systems exhibiting unexpected and potentially malicious behavior. The conversation… Graham Cluley · Jun 10, 2026 High USaiartificial intelligenceworm
supply-chain The ‘Miasma’ worm source code briefly leaked on GitHub The source code for the Miasma credential-stealing worm framework, previously linked to supply-chain attacks targeting open-source ecosystems, was briefly leaked on GitHub. This leak, mirroring the earlier Shai-Hulud wor… BleepingComputer · Jun 10, 2026 High USsupply chaincredential theftopen source
threat-intel CISA to require federal agencies to patch some cyber vulnerabilities within 3 days CISA has issued a new binding operational directive requiring federal civilian agencies to patch critical cybersecurity vulnerabilities within a tight 72-hour timeframe, prioritizing those exposed to the internet and sus… The Record · Jun 10, 2026 High USvulnerabilitypatchingai
threat-intel Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet A disgruntled researcher known as Nightmare-Eclipse has released another proof-of-concept (PoC) exploit, dubbed RoguePlanet, targeting a Windows Defender vulnerability. This follows a series of similar disclosures aimed… Dark Reading · Jun 10, 2026 High CVE-2026-33825USzero-dayexploitwindows
threat-intel China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance A China-linked botnet, dubbed JDY, has significantly expanded its operations, now comprising over 1,500 compromised SOHO and IoT devices. Initially a component of the KV-botnet, the JDY botnet is being used for large-sca… The Hacker News · Jun 10, 2026 High CVE-2026-35616USBRDEiotreconnaissancebotnet
vulnerability Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE A critical vulnerability, CVE-2026-5027, in the Langflow low-code platform has been actively exploited, allowing for remote code execution due to a lack of input sanitization. This flaw, combined with unauthenticated aut… The Hacker News · Jun 10, 2026 Critical CVE-2026-5027CVE-2026-0770CVE-2026-33017USCAlow-codeairemote code execution
threat-intel China-linked JDY botnet expands targeting of U.S. military networks A Chinese-linked botnet, JDY, has significantly expanded its targeting of U.S. military networks and associated infrastructure. The botnet, previously associated with Volt Typhoon, utilizes reconnaissance techniques like… BleepingComputer · Jun 10, 2026 High CVE-2026-35616USbotnetreconnaissanceapt
ransomware Why schools remain one of cybercriminals’ favourite targets Schools continue to be a prime target for cyberattacks, particularly ransomware, as evidenced by recent incidents at Evanston Township High School and Powys County Council. These attacks disrupt operations and compromise… Graham Cluley · Jun 10, 2026 High USGBschoolsransomwarecyberattack
vulnerability New Windows Zero-Day Exploit ‘RoguePlanet’ Released A new Windows zero-day exploit, dubbed RoguePlanet, has been released by the threat actor Nightmare Eclipse, targeting Microsoft Defender and potentially leading to local privilege escalation and BitLocker bypass. This f… SecurityWeek · Jun 10, 2026 High CVE-2026-45586CVE-2026-50507CVE-2026-41091USzero-daylocal privilege escalationbitlocker
vulnerability Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs Microsoft released a significant security update addressing 206 vulnerabilities across its software portfolio, including multiple critical Remote Code Execution (RCE) flaws and several zero-days. The update focuses on pa… The Hacker News · Jun 10, 2026 Critical CVE-2025-10263CVE-2026-8863CVE-2026-45657USzero-dayrcebitlocker
vulnerability Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows A security researcher, Chaotic Eclipse (MSNightmare), has released a proof-of-concept exploit, RoguePlanet, targeting a zero-day vulnerability in Microsoft Defender, granting SYSTEM-level access on updated Windows 11 and… The Hacker News · Jun 10, 2026 High CVE-2026-33825CVE-2026-45498CVE-2026-41091USzero-dayexploitmicrosoft defender
threat-intel A Record-Breaking Patch Tuesday for June 2026 Microsoft released a record-breaking 200 security patches on June 2026, addressing numerous vulnerabilities across its operating systems and software. Several critical flaws, including those identified by the security re… Krebs on Security · Jun 9, 2026 High CVE-2026-49160CVE-2026-45586CVE-2026-50507USzero-daypatch tuesdayai