threat-intel Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Palo Alto Unit 42 researchers have identified a new supply chain threat: "phantom squatting," where large language models (LLMs) hallucinate web domains that adversaries can then register to intercept traffic generated b… Palo Alto Unit 42 · Jul 1, 2026 High USllmaisupply chain
threat-intel China-Linked Group Targets Southeast Asia Critical Systems A China-linked cyber threat group, CL-STA-1062 (formerly UAT-7237), has been targeting critical infrastructure providers in Southeast Asia over the past year, deploying a new backdoor tool called TinyRCT. The group has s… Dark Reading · Jul 1, 2026 High CNMYTHchinaaptbackdoor
threat-intel Fake Bug Report Hijacks AI Coding Agents at Scale A research report by Tenet Security has revealed a critical vulnerability in AI coding agents, demonstrating how a simple, fabricated error report submitted to a bug tracking service (Sentry) can be used to hijack these… Dark Reading · Jun 30, 2026 Critical aiagentjackingerror-tracking
phishing Scammers race to cash in on Venezuelan earthquake disaster Following a devastating earthquake in Venezuela, a surge of newly registered domain names emerged, many referencing aid and rescue efforts. Researchers discovered that a significant portion of these domains lacked identi… Graham Cluley · Jun 30, 2026 Medium VEdisasterfraudscams
threat-intel Attackers Hijack Exposed AI Endpoints to Power Offensive Ops Researchers at Zenity discovered attackers are exploiting exposed AI endpoints, specifically Ollama and LiteLLM, to power offensive operations. Attackers leverage these AI agents – such as Strix and HexStrike AI – withou… Dark Reading · Jun 30, 2026 High FRaillmendpoint
threat-intel Why Identity Security Is Your Cyber Career Entry Point This Dark Reading article, part of their ‘Heard It From a CISO’ video series, discusses the evolving landscape of cybersecurity career entry points. It highlights that while AI is automating certain tasks, human oversigh… Dark Reading · Jun 30, 2026 Medium aicybersecurityidentity security
CIA chief highlights major shifts in agency’s tech approach CIA Director John Ratcliffe said artificial intelligence capabilities are "akin to digital nuclear weapons.” The Record · Jun 30, 2026
threat-intel Phishers Gain Persistence at EU, Asia Hospitality Orgs Phishing campaigns targeting hospitality organizations in Europe and Asia are utilizing malicious zip files containing disguised image files to install persistent malware. These attacks, observed by Microsoft and Trend M… Dark Reading · Jun 30, 2026 High GBJPphishingpersistencesocial engineering
threat-intel Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data This report details a new security vulnerability impacting AI agent-based systems, specifically leveraging the Model Context Protocol (MCP). Attackers can inject malicious instructions into tool descriptions used by AI a… The Hacker News · Jun 30, 2026 High N/aiagentsupply-chain
malware RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS A new botnet, RustDuck, is leveraging Rust programming to hijack routers, IP cameras, and servers for DDoS attacks. Developed by QiAnXin's XLab, the botnet utilizes a two-stage approach, exploiting vulnerabilities in dev… The Hacker News · Jun 30, 2026 High CVE-2017-17215CVE-2025-29635CVE-2024-1781CNddosbotnetrust
threat-intel House passes kids’ online safety bill, but Senate approval unlikely The House of Representatives passed the Kids Internet and Digital Safety (KIDS) Act, aiming to bolster online safety for children, but the bill faced criticism for lacking key provisions like a ‘duty of care’ and strong… The Record · Jun 30, 2026 Medium USonline safetychildrenprivacy
ransomware Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints A critical Remote Code Execution (RCE) vulnerability (CVE-2026-33017) in Langflow is being exploited by threat actors to deploy a Monero cryptocurrency miner on exposed AI application endpoints. The campaign, active from… The Hacker News · Jun 30, 2026 Critical CVE-2026-33017CVE-2025-3248NOrcemoneroai
malware Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses A new browser extension campaign, dubbed Silent Swap by McAfee Labs, is targeting cryptocurrency users by stealthily replacing wallet addresses during transactions. The malicious extension, disguised as a Google Notes ut… The Hacker News · Jun 30, 2026 High INUSBRclipboardwalletcrypto
threat-intel This month in security with Tony Anscombe – June 2026 edition This month’s security roundup highlights a critical CISA policy demanding rapid patching of vulnerabilities for federal agencies, a targeted cyberattack campaign against US-based Automatic Tank Gauges (ATGs), a surge in… WeLiveSecurity · Jun 30, 2026 Medium USUKCAvulnerabilitycyberattacksocial media
threat-intel GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks A research report by Adversa AI has revealed a significant security vulnerability in ten popular open-source AI coding agents, including GuardFall, which allows attackers to bypass safety checks and execute shell command… The Hacker News · Jun 30, 2026 High aishellsecurity
ransomware BlueHammer Vulnerability Exploited in Ransomware Attacks The Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released. The post BlueHammer Vulnerability Exploited in Ransomware Attacks appeared first on SecurityWeek . SecurityWeek · Jun 30, 2026 Critical CVE-2026-33825
threat-intel An intelligence budget 'super user' job is now in the hands of Russ Vought This article reports that Russ Vought, Donald Trump’s former budget chief, has taken over managing the classified spending plans of major U.S. intelligence agencies, including the CIA and NSA. This shift follows the depa… The Record · Jun 30, 2026 Medium USpoliticalbudgetintelligence
threat-intel 282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study Researchers at Wake Forest University discovered that nearly two-thirds (282 out of 444) of AI chatbot apps for iOS exposed API keys and open access to AI proxy services through network traffic. This vulnerability, dubbe… The Hacker News · Jun 30, 2026 High USapiaiiot
threat-intel Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks A research report by Adversa AI has identified a significant security vulnerability in several popular open-source AI coding agents, dubbed ‘GuardFall’. This flaw stems from the agents’ reliance on Bash shell tricks, spe… SecurityWeek · Jun 30, 2026 High bashai agentssupply chain
threat-intel AI-Generated Workflows Are a Silent Security Disaster This article highlights a growing security risk stemming from the use of AI-generated workflows within Microsoft 365 environments. Developers and users are leveraging AI assistants to automate tasks like document approva… Dark Reading · Jun 30, 2026 Medium aiautomationpermissions