threat-intel AI-Generated Workflows Are a Silent Security Disaster This article highlights a growing security risk stemming from the use of AI-generated workflows within Microsoft 365 environments. Developers and users are leveraging AI assistants to automate tasks like document approva… Dark Reading · Jun 30, 2026 Medium aiautomationpermissions
data-breach Aflac Japan Data Breach Impacts 4.38 Million Hackers accessed the insurance giant’s policyholder portal multiple times between June 15 and June 25. The post Aflac Japan Data Breach Impacts 4.38 Million appeared first on SecurityWeek . SecurityWeek · Jun 30, 2026 High
The Realities of AI Video Surveillance The Financial Times has a good article on how AI is changing the capabilities of video surveillance, with information from both Israel/Iran and Russia. I wrote about this sort of thing a few years ago, how AI enables mas… Schneier on Security · Jun 30, 2026
vulnerability StoneFly Storage Concentrator This report details a critical vulnerability affecting StoneFly Storage Concentrator versions prior to 8.0.4.29, exposing the system to significant risks including unauthorized access, command execution, and data theft.… CISA Advisories · Jun 30, 2026 Critical CVE-2026-56415CVE-2026-55721CVE-2026-50040UScredentialcommand injectionsql injection
vulnerability XZ Utils vulnerability impacting B&R Products This advisory details a critical vulnerability (CVE-2025-31115) affecting versions of XZ Utils used in B&R Industrial Automation products, specifically the PPC3100, C50, C80, FT50, MT50, T30, T80, and T50. The vulnerabil… CISA Advisories · Jun 30, 2026 Critical CVE-2025-31115CHxzmemory corruptionheap
vulnerability Delta Electronics DVP12SE PLC This advisory details a critical vulnerability in Delta Electronics’ DVP12SE PLC, exposing it to unauthorized remote access and control. The PLC’s Modbus TCP service lacks authentication, allowing attackers to potentiall… CISA Advisories · Jun 30, 2026 Critical CVE-2026-12819CVE-2026-12818TWplcmodbusiot
threat-intel Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat This article details the unconventional career path of Chris Thompson, a former IBM X-Force Red head and now CEO of RemoteThreat, tracing his journey from a teenage game hacker to a respected security professional. Thomp… SecurityWeek · Jun 30, 2026 Medium UKCAhackerred teamingai
vulnerability Schneider Electric EcoStruxure IT Data Center Expert This report details a vulnerability discovered in Schneider Electric’s EcoStruxure IT Data Center Expert software, specifically versions up to 9.1.1. The vulnerability, classified as CWE-611, is an Improper Restriction o… CISA Advisories · Jun 30, 2026 Medium CVE-2026-8045FRxmlcwe-611data center
vulnerability Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M This advisory details a vulnerability (CVE-2025-53816, CVE-2025-53817, CVE-2025-55188, CVE-2025-11001) within the Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M software. The vulnerability, a heap-based buffer o… CISA Advisories · Jun 30, 2026 High CVE-2025-53816CVE-2025-53817CVE-2025-55188JPbuffer overflowheapdenial of service
vulnerability Frangoteam FUXA SCADA/HMI This advisory details a critical vulnerability in Frangoteam FUXA SCADA/HMI software versions up to 1.3.1, allowing unauthenticated remote attackers to enumerate user accounts and role assignments. The vulnerability stem… CISA Advisories · Jun 30, 2026 Critical CVE-2026-13207WOauthentication bypassscadahmi
vulnerability Schneider Electric EasyLogic T150 and Saitel DP RTU This advisory details vulnerabilities in Schneider Electric's EasyLogic T150 and Saitel DP RTU devices, specifically versions through 11.06.37. These vulnerabilities, classified as CWE-522 and CWE-732, allow for unauthor… CISA Advisories · Jun 30, 2026 Medium CVE-2026-9650CVE-2026-9651FRcredentialsfirmwareiot
vulnerability OFFIS DCMTK Toolkit This CISA advisory details vulnerabilities within the OFFIS DCMTK Toolkit (<=3.7.0) that could allow an attacker to perform actions like file writing, unauthorized data access, memory exhaustion, and system crashes. The… CISA Advisories · Jun 30, 2026 High CVE-2026-50003CVE-2026-50254CVE-2026-35505DEpath traversalmemory leakcve-2026-50003
Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History The ruling was made in the case of a bank robber whose identity was discovered through a geofence warrant. The post Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History appear… SecurityWeek · Jun 30, 2026
threat-intel What the Numbers Say About FIFA 2026 Cyber Risk This report from Check Point Research reveals a significant pre-emptive cyber threat landscape surrounding the FIFA World Cup 2026, with attackers already establishing infrastructure months in advance. The primary target… The Hacker News · Jun 30, 2026 High RUemailspoofingfraud
vulnerability Exploitation of Recent Oracle E-Business Suite Vulnerability Begins The critical-severity defect allows unauthenticated attackers to take over the E-Business Suite’s Payments product. The post Exploitation of Recent Oracle E-Business Suite Vulnerability Begins appeared first on SecurityW… SecurityWeek · Jun 30, 2026 Medium CVE-2026-46817
threat-intel Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer An attacker exploited a critical vulnerability (CVE-2026-48558) in SimpleHelp’s OpenID Connect (OIDC) flow to deploy the TaskWeaver and Djinn Stealer malware. This allowed for unauthorized access to authenticated ‘Techni… The Hacker News · Jun 30, 2026 Critical CVE-2026-48558USoidccredential theftai
malware USB drives carrying China-linked malware infected Japanese military networks for nearly a year Japanese military networks, specifically the Ground Self-Defense Force (JGSDF), were compromised by a year-long campaign utilizing counterfeit USB drives loaded with malware. The incident, discovered in February 2025, in… Graham Cluley · Jun 30, 2026 High JACHusb drivesmalwarejapan
threat-intel ToddyCat: your hidden email assistant. Part 2 This report details the tactics employed by the ToddyCat APT group, focusing on a new technique dubbed ‘Shadow Token via Remote Debug’ (STRD) to compromise Gmail accounts. The group utilized a tool named Umbrij to gain a… Securelist · Jun 30, 2026 High UScredential_accessgoogle_apioauth2
threat-intel The AI Token Costs That Can Break Cybersecurity This article highlights a growing concern within the cybersecurity industry: the unexpectedly high costs associated with utilizing AI-powered security platforms, particularly those leveraging generative and agentic AI mo… SecurityWeek · Jun 30, 2026 High aitokenizationcost
data-breach June 2026 Apple Updates, (Tue, Jun 30th) Apple released updates for iOS/iPadOS, macOS, and Safari on Monday. There have been no updates for other Apple operating systems (visionOS, watchOS, tvOS). Usually, Apple updates all products at the same time. SANS Internet Storm Center · Jun 30, 2026 Medium CVE-2026-39868CVE-2026-43676CVE-2026-43700