US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve UNC5792 and UNC4221 have been targeting US government officials, military leaders, and allied personnel. The post US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve appeared first on S… SecurityWeek · Jun 29, 2026
threat-intel Inside the inbox: Why cybercriminals want to break into your email account Cybercriminals are increasingly targeting email accounts due to the wealth of personal and business information contained within them, including access to other accounts and potential blackmail material. Phishing attacks… WeLiveSecurity · Jun 29, 2026 High phishingsocial engineeringbec
malware Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts Microsoft removed 119 malicious Edge extensions from its add-on store that employed steganography to hide malware, including credential theft and ad fraud capabilities. The operation, dubbed StegoAd, had been active sinc… The Hacker News · Jun 29, 2026 High CHsteganographycredential theftad fraud
OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI The company says Sol matches competing systems like Mythos Preview while using only a third of the output tokens. The post OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI appeared first on SecurityWeek . SecurityWeek · Jun 29, 2026
vulnerability Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw A critical vulnerability, CVE-2026-55200, has been discovered in libssh2, a client-side SSH library embedded in various applications like curl, Git, and PHP. The flaw allows for code execution via an integer overflow, po… The Hacker News · Jun 29, 2026 Critical CVE-2026-55200CVE-2019-3855CVE-2026-55199GBsshlibssh2code execution
threat-intel Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer A sophisticated cyberattack has been uncovered involving hijacked npm and Go packages designed to deploy a Python-based information stealer. Attackers leveraged a VS Code task trigger to execute malicious code disguised… The Hacker News · Jun 29, 2026 High KPvscodenpmfont-file
phishing ISC Stormcast For Monday, June 29th, 2026 https://isc.sans.edu/podcastdetail/9986, (Mon, Jun 29th) The SANS Internet Storm Center's June 29th, 2026 Stormcast reported a heightened level of online threats, primarily focusing on phishing campaigns and malicious email activity. The report highlighted an increase in obser… SANS Internet Storm Center · Jun 29, 2026 Medium phishingemailthreat intelligence
data-breach Data breach exposes up to 14.2 million email logins at six ISPs Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. BleepingComputer · Jun 28, 2026 High
YARA-X 1.18.0 and 1.19.0 Release, (Sun, Jun 28th) YARA-X&#;x26;#;39;s 1.18.0 release brings 3 improvements and 2 bugfixes. SANS Internet Storm Center · Jun 28, 2026
Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials The Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a long-running campaign orchestrated by Russian intelligence services to break into the messaging acc… The Hacker News · Jun 27, 2026
malware Clean GitHub repo tricks AI coding agents into running malware An agentic coding tool tasked with running a seemingly benign GitHub repository could execute a malicious payload that is invisible to both security agents and human reviewers. BleepingComputer · Jun 27, 2026 Medium
threat-intel OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards OpenAI is releasing a preview of GPT-5.6 Sol, a powerful AI model with enhanced cybersecurity capabilities, to a limited group of companies and the U.S. government. The model is designed for legitimate vulnerability rese… The Hacker News · Jun 27, 2026 High USaicybersecurityvulnerability research
Chinese Framework Powers 200,000 Scam Sites Threat actors are selling investment scam templates created using the legitimate DCloud Uni-App toolkit. The post Chinese Framework Powers 200,000 Scam Sites appeared first on SecurityWeek . SecurityWeek · Jun 27, 2026
ransomware Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk Recent breaches targeting educational institutions, including ransomware attacks on Oracle E-Business Suite and Instructure's Canvas platform, highlight the vulnerability of the sector due to legacy technology, understaf… Dark Reading · Jun 27, 2026 High USthird-party riskransomwareeducation
threat-intel FBI: Russian hackers now target Signal backup recovery keys The FBI and CISA are warning about a phishing campaign orchestrated by Russian Intelligence Services (RIS) targeting Signal users. Attackers are now specifically seeking Signal Backup Recovery Keys to gain access to vict… BleepingComputer · Jun 26, 2026 High USRUUKphishingsignalrecovery key
The Chinese Control the Majority of Argentina’s Squid Fleet Chinese companies control nearly two-thirds of Argentina’s own squid fleet. Schneier on Security · Jun 26, 2026
vulnerability CISA sets urgent deadline to fix Cisco flaw exploited in attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. BleepingComputer · Jun 26, 2026 Critical CVE-2026-20230CVE-2026-12569
threat-intel FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys The FBI and CISA have issued an updated advisory warning about Russian intelligence actors targeting Signal users, expanding their tactics to include obtaining Signal Backup Recovery Keys. This allows attackers to fully… The Hacker News · Jun 26, 2026 High USRUNEsignalphishingrecovery key
threat-intel AI Decline? Confidence in Autonomous Penetration Testing Falls The confidence in fully autonomous AI systems for penetration testing has significantly declined after initial optimism. A report by Cobalt found that only 9% of organizations now rely on AI-powered testing, down from 29… Dark Reading · Jun 26, 2026 Medium aipentestingautomation
malware New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks A new cyberattack campaign, dubbed StrikeShark, is utilizing a previously undocumented malware family called SharkLoader to deploy Cobalt Strike Beacon. The campaign has targeted diplomatic organizations in Indonesia and… The Hacker News · Jun 26, 2026 High CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikedll hijackingexploit