JaredFromSubway MEV bot hacked in $15 million crypto theft The JaredFromSubway Ethereum MEV (Maximal Extractable Value) bot suffered a $15 million loss after an attacker manipulated the opportunity-detection logic by creating fake cryptocurrency trading opportunities. BleepingComputer · Jun 22, 2026
vulnerability DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories A series of vulnerabilities, dubbed "DifyTap," have been discovered in the Dify AI application building platform, allowing attackers to potentially access and exfiltrate sensitive data, including AI chat histories. The f… Dark Reading · Jun 22, 2026 High CVE-2026-41947CVE-2026-41948CVE-2026-41949aisecurityvulnerability
threat-intel FFmpeg fixes PixelSmash flaw in widely used video decoder A vulnerability, dubbed ‘PixelSmash’ (CVE-2026-8461), has been identified in FFmpeg’s MagicYUV decoder, allowing for remote code execution (RCE) on vulnerable systems. The flaw stems from an out-of-bounds write in the de… BleepingComputer · Jun 22, 2026 High CVE-2026-8461USsupply-chainremote-code-executionheap-overflow
threat-intel FortiBleed campaign used custom FortiGate sniffer to steal credentials The FortiBleed campaign, targeting Fortinet FortiGate devices, utilized a custom Golang tool called "FortigateSniffer" to steal credentials from compromised firewalls. This campaign, active since at least February 2026,… BleepingComputer · Jun 22, 2026 Critical UScredential theftfirewallgpu cracking
supply-chain ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack A supply chain attack compromised multiple WordPress plugins from ShapedPlugin, injecting backdoor code into Pro plugin releases distributed through official update channels. The malicious plugins, affecting versions of… The Hacker News · Jun 22, 2026 Critical CVE-2026-49777CVE-2026-10735wordpresssupply chainbackdoor
Microsoft says Windows 11 26H2 is coming soon, details upgrade process Microsoft has confirmed that Windows 11 version 26H2 will be the next feature update and that devices running Windows 11 24H2 and 25H2 will be able to upgrade using a small enablement package. BleepingComputer · Jun 22, 2026
vulnerability Microsoft fixes AutoGen Studio flaw that enabled code execution A vulnerability, dubbed AutoJack, was discovered in Microsoft’s AutoGen Studio, a framework for building multi-agent AI systems. The flaw allowed attackers to execute arbitrary commands on a host system by manipulating a… BleepingComputer · Jun 22, 2026 Medium aiagentremote code execution
threat-intel Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants Researchers have identified four critical vulnerabilities in the open-source Dify agentic workflow platform, dubbed DifyTap, allowing unauthorized access to AI conversations and data across tenants. These flaws include a… The Hacker News · Jun 22, 2026 Critical CVE-2024-5846CVE-2026-41947CVE-2026-41948aivulnerabilitytenant
threat-intel Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign A sophisticated cybercrime campaign, orchestrated by unknown threat actors, is utilizing a multi-channel approach to distribute a cross-platform clipboard hijacker designed to steal cryptocurrency. The campaign leverages… Dark Reading · Jun 22, 2026 High USclipboard hijackingreputation manipulationcrypto theft
vulnerability 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests A 29-year-old vulnerability, dubbed Squidbleed (CVE-2026-47729), exists in the Squid web proxy due to a heap over-read. This allows an attacker with proxy access to leak cleartext HTTP requests, including credentials and… The Hacker News · Jun 22, 2026 Medium CVE-2026-47729CVE-2026-50012heap_overflowhttpftp
threat-intel He Thought He Was Secure; His Phone Number Got Stolen Anyway This article details a real-world incident where cybersecurity expert Torsten George was targeted by a SIM swap attack, highlighting the vulnerability of relying solely on one-time passwords (OTPs) for security. The atta… Dark Reading · Jun 22, 2026 High USUKAUsim swapotpsocial engineering
Webshells Remain Popular, (Mon, Jun 22nd) Webshells have been popular for a long time. We already covered this topic across multiple diaries[ 1 ][ 2 ]. I spent some time to track them[ 3 ] and slighly paid less attention to them but today I found another one. It… SANS Internet Storm Center · Jun 22, 2026
Suspected cyberattack triggers false emergency alerts across parts of Brazil The incident occurred early Saturday when at least a dozen unauthorized alerts were sent through Brazil's Civil Defense Alert system, a platform designed to warn residents about imminent threats such as floods, landslide… The Record · Jun 22, 2026
threat-intel A Glimpse into the “Search Your Target” Market for Stolen Credentials This report details a growing underground market where threat actors are offering ‘search your target’ services, leveraging massive collections of stolen credentials. Researchers analyzed 470 forum posts revealing a serv… BleepingComputer · Jun 22, 2026 High UScredential theftinfostealerunderground market
vulnerability Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data Squidbleed, discovered with the aid of Claude Mythos Preview, has been described as a Heartbleed-style vulnerability. The post Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data appeared first on SecurityWeek… SecurityWeek · Jun 22, 2026 Medium CVE-2026-47729
malware New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer A new malware loader, dubbed OXLOADER, is being used to distribute the CastleStealer information stealer through malicious Google Ads. The campaign, codenamed REF8372, leverages deceptive advertising and PowerShell execu… The Hacker News · Jun 22, 2026 Medium RUUAgoogle adsmalware loadercastlestealer
threat-intel Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries Google is implementing a new Android developer verification system, starting September 30, 2026, in Brazil, Indonesia, Singapore, and Thailand, to combat app scams and malware. This will block installations of apps from… The Hacker News · Jun 22, 2026 Medium BRIDSGapp scamsdeveloper verificationopen source
threat-intel Stop Your Legacy Infrastructure from Hijacking Your AI Agents This article highlights a significant security risk: attackers leveraging legacy infrastructure to compromise AI agent environments. Despite organizations investing heavily in securing AI workloads against direct attacks… The Hacker News · Jun 22, 2026 High CVE-2025-24813USailegacypermissions
Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data. The post Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data appeared first on Security… SecurityWeek · Jun 22, 2026 CVE-2026-4020
supply-chain North Korean Hackers Blamed for Mastra NPM Supply Chain Attack A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions. The post North Korean Hackers Blamed for Mastra NPM Supply Chain Attack appeared first on Secu… SecurityWeek · Jun 22, 2026