threat-intel ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm A sprawling Android botnet called Popa, used for advertising fraud, account takeovers, and data scraping, has been linked to NetNut, a residential proxy provider operated by Alarum Technologies Ltd. Researchers discovere… Krebs on Security · Jun 18, 2026 High ISbotnetproxyandroid
threat-intel Google to use UK and EU user IP addresses for ad personalization Google plans to begin using IP addresses from August 3, 2026, across the EEA, UK, and Switzerland for ad measurement and personalization. This shift is driven by regulatory changes regarding personal data, particularly u… BleepingComputer · Jun 17, 2026 Medium GBEUCHprivacygdprconsent
vulnerability CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution CISA has added a critical vulnerability, CVE-2026-48907, to its Known Exploited Vulnerabilities catalog affecting the Widget Factory Joomla Content Editor (JCE) due to improper access control. This flaw allows for PHP co… The Hacker News · Jun 17, 2026 Critical CVE-2026-48907TUjoomlaphpcode execution
threat-intel ISC Stormcast For Tuesday, June 16th, 2026 https://isc.sans.edu/podcastdetail/9974, (Tue, Jun 16th) The SANS Internet Storm Center's June 16th, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observ… SANS Internet Storm Center · Jun 16, 2026 Medium phishingddosbotnet
policy UK to ban social media access for children under 16 The UK government is planning to ban social media access for individuals under 16, mirroring a similar measure implemented in Australia. This initiative aims to protect children online by restricting access to user-to-us… The Record · Jun 16, 2026 Medium UKAUSPsocial mediachildrenonline safety
malware 152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic A network of 152 Chrome extensions, collectively installed over 105,000 times, has been discovered distributing a potentially unwanted program (PUP) that generates fake traffic and logs user data. These extensions, masqu… The Hacker News · Jun 15, 2026 High TRadwarefake trafficprivacy
phishing Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts A coordinated phishing campaign, spearheaded by the now-disrupted Sniper Dz platform, targeted users in the Middle East and North Africa (MENA) through deceptive Facebook offers. The campaign leveraged browser notificati… The Hacker News · Jun 15, 2026 High DZALAEphishingsocial engineeringbrowser notifications
phishing ISC Stormcast For Monday, June 15th, 2026 https://isc.sans.edu/podcastdetail/9972, (Mon, Jun 15th) The SANS Internet Storm Center's June 15th, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observ… SANS Internet Storm Center · Jun 15, 2026 Medium phishingbotnetddos
threat-intel How has use of framing protection security headers changed in the past 3 years?, (Wed, Jun 10th) This SANS Internet Storm Center article analyzes the adoption of framing protection security headers (X-Frame-Options and CSP frame-ancestors) across the top million most popular websites over a three-year period. The an… SANS Internet Storm Center · Jun 10, 2026 Medium framingcspx-frame-options
malware Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models Researchers at the University of Toronto have developed a novel AI-driven computer worm that operates autonomously by leveraging locally hosted, open-weight large language models. The worm dynamically generates attack st… The Hacker News · Jun 9, 2026 Critical CVE-2026-39987CVE-2026-31431CVE-2026-43284GBaiwormllm
threat-intel UK gives big tech 3 months to create device controls to block nude images of kids The UK government is mandating that major tech companies, including Apple and Google, implement device controls within three months to block nude images of children from smartphones and tablets. This initiative aims to c… The Record · Jun 8, 2026 High UKchild sexual abuseonline safetydevice security
threat-intel Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI A researcher has discovered that Bright Data, a company providing residential proxy services, is utilizing its iOS SDK embedded in free smart TV apps to turn these devices into web-scraping proxies for the AI industry. T… The Hacker News · Jun 6, 2026 Medium UZOMsmart tvresidential proxyai scraping
malware AI Worm Researchers have developed a functional prototype of an AI-powered internet worm, leveraging a large language model (LLM) within the worm itself. The worm exploits compromised systems to host and execute the LLM, mirrori… Schneier on Security · Jun 5, 2026 High aiwormllm
threat-intel In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA This week’s cybersecurity news highlights a range of threats, including AI-powered attacks targeting computing power, ongoing Grandoreiro banking trojan campaigns, and a self-propagating ransomware group utilizing obfusc… SecurityWeek · Jun 5, 2026 High IRUSairansomwaresupply chain
threat-intel Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook This article details a trend of underground forums sharing a tutorial designed to guide novice hackers through the process of identifying, exploiting, and monetizing vulnerabilities. The ‘Hercules’ thread, popular across… BleepingComputer · Jun 4, 2026 High USvulnerabilityexploitmonetization
malware FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads A new macOS malvertising campaign, dubbed Operation FlutterBridge, is utilizing FlutterShell, a backdoor that spreads adware via malicious Google and YouTube ads. The campaign, traced back to the CL-CRI-1089 threat actor… The Hacker News · Jun 4, 2026 High USCAAUmalvertisingmacoswebview
threat-intel ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds A new ‘HTTP/2 Bomb’ exploit has been discovered that leverages existing vulnerabilities in HTTP/2 implementations to cause widespread denial-of-service attacks against web servers. The exploit combines compression and fl… SecurityWeek · Jun 3, 2026 High CVE-2016-6581CVE-2025-53020CVE-2016-8740USdoshttp2compression
supply-chain Red Hat removes tainted packages after software pipeline compromise Red Hat removed numerous software packages from its distribution pipeline after a compromised GitHub account was used to distribute credential-stealing malware. The attack, utilizing a variant of the Mini Shai-Hulud worm… The Record · Jun 2, 2026 High NOUKsupply chaingithubmalware
malware WordPress malware campaign hides payloads in Steam profiles A WordPress malware campaign has infected nearly 2,000 websites by hiding command-and-control (C2) data within Steam Community profile comments. The attackers utilize invisible Unicode characters to encode malicious payl… BleepingComputer · Jun 1, 2026 High USwordpresssteemunicode
threat-intel Sextortionist sentenced to 33 years for targeting 145 children A Canadian man, Ramanan Pathmanathan, has been sentenced to 33 years in prison for a long-running sextortion scheme targeting over 145 children, primarily in the United States. The scheme involved blackmailing victims wi… BleepingComputer · May 28, 2026 Critical CAUSsextortionchild_exploitationonline_abuse