threat-intel ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More This week’s security recap highlighted several concerning trends, including a disruption of the NetNut residential proxy network used for botnet operations, a fake Proof-of-Concept (PoC) malware targeting vulnerability r… The Hacker News · Jul 6, 2026 High CVE-2026-48276CVE-2026-48283CVE-2026-48277USESSPbotnetproxymalware
threat-intel Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages A vulnerability in Opera GX allowed malicious websites to silently install browser add-ons that could steal data from visited pages. Researchers demonstrated how a malicious iframe could install a mod, which then injecte… The Hacker News · Jul 6, 2026 High browsercssdata-theft
vulnerability Multiples vulnérabilités dans Roundcube (06 juillet 2026) Multiple vulnerabilities have been discovered in Roundcube Webmail, impacting versions 1.6.x (prior to 1.6.17) and 1.7.x (prior to 1.7.2). These vulnerabilities include denial-of-service attacks, server-side request forg… CERT-FR · Jul 6, 2026 Medium CVE-2026-54432CVE-2026-54433CVE-2026-62641webmailvulnerabilityssrf
threat-intel FBI Seizes NetNut Proxy Platform, Popa Botnet The FBI, in collaboration with industry partners including Google and Lumen, has seized hundreds of domains associated with NetNut, a residential proxy service operated by Alarum Technologies, following findings linking… Krebs on Security · Jul 2, 2026 High USproxybotnetresidential proxy
threat-intel Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices Google, in collaboration with the FBI and Lumen, has significantly reduced the size of the NetNut residential proxy network, which utilizes millions of home devices worldwide as relays for internet traffic. This network,… The Hacker News · Jul 2, 2026 High ISCHproxyresidentialbotnet
threat-intel House passes kids’ online safety bill, but Senate approval unlikely The House of Representatives passed the Kids Internet and Digital Safety (KIDS) Act, aiming to bolster online safety for children, but the bill faced criticism for lacking key provisions like a ‘duty of care’ and strong… The Record · Jun 30, 2026 Medium USonline safetychildrenprivacy
malware Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input A malicious Chrome extension disguised as the Perplexity AI search engine was discovered by Microsoft, intercepting user searches and address bar input. The extension secretly logged this data by routing it through an at… The Hacker News · Jun 29, 2026 High chromeextensiondata collection
malware Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts Microsoft removed 119 malicious Edge extensions from its add-on store that employed steganography to hide malware, including credential theft and ad fraud capabilities. The operation, dubbed StegoAd, had been active sinc… The Hacker News · Jun 29, 2026 High CHsteganographycredential theftad fraud
phishing ISC Stormcast For Monday, June 29th, 2026 https://isc.sans.edu/podcastdetail/9986, (Mon, Jun 29th) The SANS Internet Storm Center's June 29th, 2026 Stormcast reported a heightened level of online threats, primarily focusing on phishing campaigns and malicious email activity. The report highlighted an increase in obser… SANS Internet Storm Center · Jun 29, 2026 Medium phishingemailthreat intelligence
threat-intel Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability A popular Google Chrome ad blocker extension, Adblock for YouTube, with over 10 million installs, has been found to contain a dormant script injection capability. Researchers discovered the extension’s architecture allow… The Hacker News · Jun 25, 2026 High USadblockjavascriptprivacy
threat-intel ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories This article reports on several security vulnerabilities and trends, including a privacy-preserving protocol from Cloudflare, six vulnerabilities in the curl library, a critical security flaw in Hoppscotch allowing unaut… The Hacker News · Jun 25, 2026 High CVE-2026-8932CVE-2026-50160USKRsmart tvproxywareiot
malware What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th) This SANS Internet Storm Center guest diary details an analysis of automated cybercrime activity observed through a honeypot, focusing on the Terrabot IoT botnet. The author, a BACS student, highlights the prevalence of… SANS Internet Storm Center · Jun 25, 2026 Medium CVE-2016-20017CVE-2018-10561CVE-2016-20016USiotbotnetscanning
threat-intel Google releases new privacy controls for activity history, personalization Google is releasing new privacy controls for its Search services and Google Play, allowing users to manage their saved history and personalized recommendations more granularly. The changes separate these functions into d… BleepingComputer · Jun 24, 2026 Low privacysearchpersonalization
ransomware Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered A coordinated international law enforcement operation, involving Bitdefender, Bitsight, ESET, Microsoft, and Europol, successfully disrupted the Amadey and StealC malware networks, recovering 27 million stolen credential… The Hacker News · Jun 24, 2026 High NLCADEmaascredential theftransomware
threat-intel Compromise kids online safety bill unveiled by House leaders, with key omission A revised version of the Kids Online Safety Act (KOSA) has been unveiled by the House Energy and Commerce Committee, aiming for bipartisan support. However, a key element – a ‘duty of care’ provision requiring platforms… The Record · Jun 23, 2026 Medium USonline safetychildren's privacyai regulation
threat-intel OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws OpenAI is expanding its Daybreak initiative with GPT-5.5-Cyber, an AI model designed to accelerate vulnerability discovery and patching within software. This expansion includes a new plugin for streamlining the vulnerabi… The Hacker News · Jun 23, 2026 High CVE-2026-47729CVE-2026-4890CVE-2026-4891CAaivulnerabilitypatching
vulnerability 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests A 29-year-old vulnerability, dubbed Squidbleed (CVE-2026-47729), exists in the Squid web proxy due to a heap over-read. This allows an attacker with proxy access to leak cleartext HTTP requests, including credentials and… The Hacker News · Jun 22, 2026 Medium CVE-2026-47729CVE-2026-50012heap_overflowhttpftp
malware AryStinger botnet infected thousands of D-Link routers worldwide A new botnet, named AryStinger, has been discovered compromising over 4,000 outdated D-Link routers worldwide, turning them into proxies for malicious traffic. The malware utilizes multiple vulnerabilities to perform sca… BleepingComputer · Jun 21, 2026 High CVE-2013-3307CVE-2016-5681CVE-2025-11837KRCNSErouterbotnetdns
vulnerability Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys A vulnerability in the Gravity SMTP WordPress plugin has been exploited by attackers, allowing them to extract sensitive data such as API keys and configuration details from approximately 100,000 sites. The flaw, tracked… The Hacker News · Jun 20, 2026 Medium CVE-2026-4020USwordpressapicredentials
vulnerability In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum This week’s cybersecurity news highlights several significant vulnerabilities and attacks across various platforms and industries. A critical phpBB flaw enabled session hijacking, while vulnerabilities in Chrome extensio… SecurityWeek · Jun 19, 2026 High CVE-2025-20701CHISsession hijackingchrome extensionssupply chain attack