phishing Order-tracking app Shop abused to push callback phishing attacks Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access softwar… BleepingComputer · Jun 25, 2026 Medium
threat-intel Local Police Collusion Hampers Crackdown on Asian Scam Centers This article reports on the ongoing challenge of combating cybercrime, specifically online scams, centered in Southeast Asia, particularly Cambodia, Myanmar, and the Philippines. Despite international pressure and arrest… Dark Reading · Jun 25, 2026 High KHUSCNcybercrimescamcorruption
threat-intel DHS chief says president has met with potential CISA nominee; agency plans to hire 600 The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) is seeking to rebuild its workforce following significant layoffs and a prolonged period without a Senate-confirmed direc… The Record · Jun 25, 2026 Medium CHUScisacybersecurityhomeland security
threat-intel Microsoft quietly extends free Windows 10 ESU support to October 2027 Microsoft has unexpectedly extended the free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, pushing the end-of-support date to October 12, 2027. This decision provides users with… BleepingComputer · Jun 25, 2026 Low windows 10esusecurity updates
threat-intel Beyond IOCs: AI-enabled threat intelligence This article from Cisco Talos discusses the potential of large language models (LLMs) to revolutionize threat intelligence management. Currently, the industry relies heavily on indicators of compromise (IOCs) and struggl… Cisco Talos · Jun 25, 2026 Medium UKaillmcom
threat-intel AI and Liability A German court ruled that Google is liable for its AI-generated search summaries, marking a significant shift in how internet publishers are held accountable. The ruling established that AI-generated content, particularl… Schneier on Security · Jun 25, 2026 Medium DEailiabilitygoogle
threat-intel New macOS malware embeds fake errors to confuse AI analysis tools A new macOS malware, dubbed "Gaslight," has been discovered that employs a deceptive tactic to mislead AI-powered malware analysis tools. The malware embeds fabricated error messages and debugging data within its Rust bi… BleepingComputer · Jun 25, 2026 Medium NOmacosai analysisprompt injection
PirloTV sports piracy network disrupted as 44 domains seized A major sports piracy ring linked to the illegal PirloTV streaming platform has been disrupted in an action that targeted 44 domains. BleepingComputer · Jun 25, 2026
phishing Bluekit phishing kit adopts browser-in-the-middle for login theft Bluekit, a phishing-as-a-service platform, has evolved by incorporating browser-in-the-middle (BitM) capabilities, allowing it to steal login credentials more effectively. The platform utilizes the rrweb JavaScript libra… BleepingComputer · Jun 25, 2026 High USphishingbitmbrowser-in-the-middle
Another Russian dairy producer reportedly disrupted by cyberattack A dairy products manufacturer in Russia's republic of Bashkortostan is the latest such company to have its operations snarled by a cyberattack. The Record · Jun 25, 2026
threat-intel Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability A popular Google Chrome ad blocker extension, Adblock for YouTube, with over 10 million installs, has been found to contain a dormant script injection capability. Researchers discovered the extension’s architecture allow… The Hacker News · Jun 25, 2026 High USadblockjavascriptprivacy
threat-intel The Four Elevations of Effective Fraud Prevention This article discusses a multi-layered approach to fraud prevention, emphasizing the importance of monitoring across all customer touchpoints – from individual transactions to platform-wide activity. It advocates for col… BleepingComputer · Jun 25, 2026 High fraudaccount-takeoverauthentication
Runlayer Raises $30 Million in Series A Funding The startup’s platform functions as a secure control layer, aiming to secure AI tools across enterprises. The post Runlayer Raises $30 Million in Series A Funding appeared first on SecurityWeek . SecurityWeek · Jun 25, 2026
threat-intel ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories This article reports on several security vulnerabilities and trends, including a privacy-preserving protocol from Cloudflare, six vulnerabilities in the curl library, a critical security flaw in Hoppscotch allowing unaut… The Hacker News · Jun 25, 2026 High CVE-2026-8932CVE-2026-50160USKRsmart tvproxywareiot
Ukraine's state postal operator reports app disruption after cyberattack Ukraine's state-owned postal operator said it was experiencing disruptions to some of its app services due to a suspected cyberattack, but did not say who was behind it. The Record · Jun 25, 2026
threat-intel Russia used Cellebrite phone-hacking tool to crack down on dissident after firm cut off country This article reports that Russian authorities continued to use Cellebrite’s phone-hacking tool, the UFED, to access the devices of dissident political activist Andrey Pivovarov after Cellebrite announced it was ending it… The Record · Jun 25, 2026 High RUDEsurveillancephone-hackingdissident
Webinar: Why account takeovers remain one of the hardest threats to stop Account takeover attacks continue to challenge security teams because attackers often operate through legitimate accounts and trusted services. This webinar explores how behavioral AI can help organizations identify comp… BleepingComputer · Jun 25, 2026
Cal Water Finds No Evidence of OT Activity After Hackers Claimed They Could Disrupt Water Supply Mandiant has helped the California water utility investigate the cyberattack launched by Iranian hacker group Handala. The post Cal Water Finds No Evidence of OT Activity After Hackers Claimed They Could Disrupt Water Su… SecurityWeek · Jun 25, 2026
vulnerability H.VIEW HV-500S6 IP Camera This CISA advisory details a critical vulnerability in H.VIEW HV-500S6 IP cameras, specifically version IPCAM_V4.06.88.251229. The vulnerability allows authenticated users to upload malicious files and execute arbitrary… CISA Advisories · Jun 25, 2026 Critical CVE-2026-55975CVE-2026-56414CHcertificateinput validationcommand injection
vulnerability Horner Automation Cscape This advisory details a critical vulnerability in Horner Automation’s Cscape software, specifically versions prior to 10.2_SP3. The vulnerability allows for out-of-bounds reads, potentially leading to information disclos… CISA Advisories · Jun 25, 2026 Critical CVE-2026-12897UScscapeout-of-boundsvulnerability