threat-intel Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain Researchers at Paradigm Shift have developed ‘usbliter8’, an exploit that allows arbitrary code execution within the SecureROM of Apple’s A12 and A13 chips. The exploit leverages a hardware flaw in the Synopsys DWC2 USB… The Hacker News · Jun 19, 2026 High USsecureromusbdfu
ransomware The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes The Gentlemen ransomware-as-a-service (RaaS) operation is utilizing a sophisticated suite of EDR-terminating tools, centered around the GentleKiller framework, to disable security defenses before deploying ransomware. Th… The Hacker News · Jun 19, 2026 High RUSOWEransomware-as-a-serviceedr-killingbyovd
data-breach Texas govt data breach exposes over 3 million driver’s licenses The Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its license system vendor that exposed personal information for more than three million individuals. BleepingComputer · Jun 19, 2026 High
Apple’s Hide My Email tweak leaves privacy fans fuming Apple has long marketed itself as the privacy-first tech giant. So why is it making a change to Hide My Email that will make it easier for websites to block anonymous sign-ups - and harder for you to stay private online?… Graham Cluley · Jun 19, 2026
threat-intel AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Researchers at Microsoft have identified a vulnerability, dubbed AutoJack, within the AutoGen Studio prototyping interface for their AutoGen multi-agent framework. The flaw allows an attacker to hijack an AI browsing age… The Hacker News · Jun 19, 2026 High CVE-2026-26030CVE-2026-25592remote code executionai agentlocalhost
vulnerability In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum This week’s cybersecurity news highlights several significant vulnerabilities and attacks across various platforms and industries. A critical phpBB flaw enabled session hijacking, while vulnerabilities in Chrome extensio… SecurityWeek · Jun 19, 2026 High CVE-2025-20701CHISsession hijackingchrome extensionssupply chain attack
threat-intel Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites An international law enforcement operation, dubbed Operation Endgame, successfully disrupted SocGholish’s infrastructure and removed malware from nearly 15,000 WordPress websites. The takedown, involving agencies from mu… The Hacker News · Jun 19, 2026 High NLCADEbotnetwordpressmalware
threat-intel CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices CISA has issued a warning to Fortinet customers regarding FortiBleed, a campaign targeting 86,644 FortiGate devices globally. The attack, attributed to Russian-speaking threat actors, leverages a two-step approach involv… The Hacker News · Jun 19, 2026 High USINMEcredential_stuffingdefault_credentialspassword_reuse
phishing Imposter scams cost Americans $3.5 billion in 2025 – and it’s getting worse Imposter scams have surged in the United States, resulting in a staggering $3.5 billion in financial losses for consumers in 2025. These scams typically involve fraudulent impersonations of trusted entities like banks an… Graham Cluley · Jun 19, 2026 High USscamsfraudidentity theft
threat-intel Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way This article highlights a growing security risk within organizations due to the widespread adoption of AI agents. Traditional identity security models, built around controlling employee and service accounts, are being by… BleepingComputer · Jun 19, 2026 High aiartificial intelligenceidentity management
threat-intel Stressors, AI Forcing Changes to Cybersecurity Teams This article reports on a recent survey highlighting the increasing difficulties faced by Chief Information Security Officers (CISOs) due to the proliferation of cyber threats, the complexities introduced by AI, and conc… Dark Reading · Jun 19, 2026 Medium aicybersecuritycios
malware Police raid malware network tied to Russia's Evil Corp hacker group An international operation targeted the SocGholish botnet, which has been linked to the Russia-based cybercrime group Evil Corp. The Record · Jun 19, 2026 Medium
phishing Webinar: How attackers bypass MFA and how defenders can respond The article discusses a growing trend in cyberattacks where attackers bypass multi-factor authentication (MFA) through sophisticated phishing techniques, specifically Device Code phishing. These attacks exploit legitimat… BleepingComputer · Jun 19, 2026 High phishingmfaaccount takeover
threat-intel From Assistive to Agentic: The AI Shift That's Redefining Threat Management This article discusses the shift in cybersecurity necessitated by the rapid advancements in AI, particularly frontier AI models. Traditional security architectures, reliant on manual processes and siloed tools, are strug… The Hacker News · Jun 19, 2026 High USaictemthreat intelligence
Microsoft: June 2026 Windows updates break Recycle Bin prompts Microsoft has confirmed a confusing Windows bug that causes different filenames to appear in the confirmation dialog when deleting a file from the Recycle Bin. BleepingComputer · Jun 19, 2026
vulnerability CryptoBandits Malware Doubles as a Backdoor, Abuses Tor CryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution. The post CryptoBandits Malware Doubles as a Backdoor, Abuses Tor appeared first on SecurityWeek . SecurityWeek · Jun 19, 2026 High
other UK's information commissioner resigns over ‘inappropriate humour’ John Edwards, the Information Commissioner of the UK, has resigned following a workplace investigation into inappropriate conduct, specifically concerning his use of humor. This resignation has created a leadership vacuu… The Record · Jun 19, 2026 Low UKNEresignationleadershipgovernance
threat-intel Anthropic’s Fable and the State of AI Anthropic’s Fable AI model, designed to identify vulnerabilities in code, has sparked concern due to its capabilities and the potential for misuse. The US government classified it as a dangerous munition and restricted a… Schneier on Security · Jun 19, 2026 High UKUSCZaivulnerabilitycybersecurity
phishing FortiBleed: 86,000 Fortinet Device Credentials Compromised The large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs. The post FortiBleed: 86,000 Fortinet Device Credentials Compromised appeared first on SecurityWeek . SecurityWeek · Jun 19, 2026
vulnerability CISA: Splunk Enterprise flaw actively exploited, patch by Sunday CISA has urged U.S. federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks. BleepingComputer · Jun 19, 2026 Critical CVE-2026-20253