Webinar Today: Modern Exposure Validation in the AI Era The exploit timeline collapsed. Make sure your validation didn't. The post Webinar Today: Modern Exposure Validation in the AI Era appeared first on SecurityWeek . SecurityWeek · Jun 24, 2026
vulnerability Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME).… The Hacker News · Jun 24, 2026 Medium CVE-2026-20230CVE-2026-20262
threat-intel Linux Process Name Masquerading, (Wed, Jun 24th) This SANS Internet Storm Center diary details a technique used by attackers, specifically the Velvet Ant Chinese group, to mask process names in Linux systems. Attackers modify the ‘comm’ and ‘cmdline’ entries in the /pr… SANS Internet Storm Center · Jun 24, 2026 Medium CHprocess_namemasqueradinglinux
vulnerability Hackers Exploiting Cisco Unified CM Vulnerability Cisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June. The post Hackers Exploiting Cisco Unified CM Vulnerability appeared first on SecurityWeek . SecurityWeek · Jun 24, 2026 Medium CVE-2026-20230CVE-2026-20045
threat-intel Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says Anthropic’s Mythos AI model identified vulnerabilities within several U.S. government computer systems during a testing exercise conducted in collaboration with intelligence agencies. While the model quickly detected wea… SecurityWeek · Jun 24, 2026 High UNaivulnerabilitysecurity
threat-intel ISC Stormcast For Wednesday, June 24th, 2026 https://isc.sans.edu/podcastdetail/9984, (Wed, Jun 24th) The SANS Internet Storm Center's Stormcast for June 24th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The broadcast detailed ongoing campaigns involving phishing attack… SANS Internet Storm Center · Jun 24, 2026 Medium phishingmalwarethreat-intelligence
supply-chain OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat This report details a significant supply chain attack leveraging OpenClaw’s Skill Marketplace, highlighting the emerging threat of AI agentic software. Malicious skills, including infostealers and evasion techniques, wer… Palo Alto Unit 42 · Jun 23, 2026 High USaiagenticsupply chain
vulnerability Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks A high-severity Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-20230, in Cisco Unified Communications Manager is currently being actively exploited by threat actors. This allows attackers to gain root privile… BleepingComputer · Jun 23, 2026 High CVE-2026-20230ssrfcve-2026-20230root
Tata Electronics confirms cyberattack as hackers leak data Tata Electronics has confirmed in a statement to BleepingComputer that it was the target of a cyberattack that impacted parts of its IT infrastructure. BleepingComputer · Jun 23, 2026
data-breach Scope of Salesforce Attacks Expands as Icarus Leaks Data A series of attacks originating from the Icarus extortion group have expanded the scope of breaches affecting Salesforce customers. Initially targeting Klue’s OAuth tokens, attackers leveraged this access to steal custom… Dark Reading · Jun 23, 2026 High USsalesforceoauthdata breach
threat-intel Windows 11 KB5095093 update rolls out new Point-in-Time restore feature This article reports on the release of Microsoft's KB5095093 preview cumulative update for Windows 11, introducing a new Point-in-Time Restore feature. The update focuses on enhancing system reliability and usability, al… BleepingComputer · Jun 23, 2026 Low windows 11point-in-time restorefeature update
data-breach Healthtech firm Xolis suffers data breach impacting 1.4 million people Healthcare technology company Xsolis says that sensitive data belonging to nearly 1.4 million individuals was compromised in a phishing attack that gave attackers access to its network. BleepingComputer · Jun 23, 2026 High
supply-chain 'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows A new vulnerability, dubbed "Cordyceps," is targeting CI/CD workflows across several open-source projects, including Azure Sentinel, Doris, Workers SDK, and Black. Attackers can exploit weak automated processes within th… Dark Reading · Jun 23, 2026 High cicdsupply chainpull requests
threat-intel Five Eyes agencies sound alarm about AI’s threat to cybersecurity Five Eyes intelligence agencies are issuing a stark warning about the rapidly escalating threat posed by artificial intelligence (AI) to cybersecurity. They believe AI will dramatically accelerate both offensive and defe… The Record · Jun 23, 2026 High USUKCAaicybersecuritythreat intelligence
malware New macOS ClickFix attack silently mounts DMGs to push infostealer A new macOS ClickFix campaign is using Terminal commands to silently deploy the Atomic macOS Stealer (AMOS) infostealer, targeting users through fake CAPTCHA pages. The malware steals sensitive data like browser credenti… BleepingComputer · Jun 23, 2026 High USmacosclickfixinfostealer
threat-intel FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation A Russian-speaking threat actor, dubbed FortiBleed, is conducting a large-scale credential harvesting operation targeting over 430,000 FortiGate firewalls globally. The campaign, active since February 2026, utilizes a Go… The Hacker News · Jun 23, 2026 High USINRUcredential harvestingfirewallactive directory
Feds seize alleged cyber-scam infrastructure connected to Southeast Asian company The Department of Justice announced the “seizure of a cloud computing account” used by subsidiaries of the Huione Group, a conglomerate severed from the U.S. financial system last year. The Record · Jun 23, 2026
Dragos Unveils AI for OT Security Named EmberAI, the new capability is built on Dragos’ massive operational technology cybersecurity dataset. The post Dragos Unveils AI for OT Security appeared first on SecurityWeek . SecurityWeek · Jun 23, 2026
threat-intel Trump directs federal agencies to protect US data from quantum threats President Trump issued two executive orders focused on bolstering U.S. cybersecurity against future threats from quantum computing. One order prioritizes accelerating the development and practical application of quantum… The Record · Jun 23, 2026 Medium USUKquantum computingcryptographycybersecurity
threat-intel Scattered Spider Hackers Plead Guilty on Day 1 of Trial Two key members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, have pleaded guilty to criminal charges related to attacks against Transport for London and other organizations. The group, led by… Krebs on Security · Jun 23, 2026 High UKUSGBphishingransomwaresim swapping