vulnerability CISA: Splunk Enterprise flaw actively exploited, patch by Sunday CISA has urged U.S. federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks. BleepingComputer · Jun 19, 2026 Critical CVE-2026-20253
threat-intel Forget Data Leakage: Shadow AI's Real Threat Is Access Control This article highlights a shift in the security landscape surrounding AI, moving beyond simple data leakage concerns to a more critical issue of access control. Employees are increasingly deploying custom AI agents acros… The Hacker News · Jun 19, 2026 High USaishadow itaccess control
supply-chain Cybersecurity Firms Impacted by Klue Supply Chain Attack A supply chain attack targeting the Klue market intelligence platform resulted in the unauthorized harvesting of customer data from various integrations, including Salesforce and HubSpot. The attack, attributed to a new… SecurityWeek · Jun 19, 2026 High supply-chainoauthcrm
threat-intel Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data Salesforce disabled the Klue Battlecards app integration following a security incident where the Icarus extortion group exploited compromised credentials to access customer data via Salesforce. The attackers leveraged a… The Hacker News · Jun 19, 2026 High USoauthcredentialdata-exfiltration
threat-intel NY man charged after harassing college student with AI-generated nudes A New York man, Anthony Belford, has been charged with cyberstalking after using AI-generated nude images and fabricated messages to harass a college student following a transfer. The investigation revealed the use of nu… BleepingComputer · Jun 19, 2026 High USGAILaicyberstalkingharassment
Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC WideField will accelerate Agentic SOC capabilities by expanding the lens on threat investigation to include identity, credentials, sessions, and blast radius. The post Cisco to Acquire WideField Security to Boost Splunk’… SecurityWeek · Jun 19, 2026
phishing eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th) I detected an interesting phishing email this morning. It targets a major Belgian bank: SANS Internet Storm Center · Jun 19, 2026 Medium
threat-intel CISA warns Fortinet users to secure devices after FortiBleed leak CISA has issued a warning to Fortinet customers regarding the "FortiBleed" data leak, which exposed nearly 74,000 firewall and VPN credentials. Threat actors are exploiting these compromised credentials to target interne… BleepingComputer · Jun 19, 2026 High USRUCNcredentialsvpnfirewall
malware 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame. The post 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown appeared first on SecurityWe… SecurityWeek · Jun 19, 2026 High
threat-intel Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone A vulnerability in Apple’s Beats Studio Buds firmware allowed nearby attackers to potentially eavesdrop on users via the device’s microphone. The flaw, tracked as CVE-2025-20701, stemmed from incorrect authorization with… The Hacker News · Jun 19, 2026 Critical CVE-2025-20701CVE-2025-20700CVE-2025-20702GEbluetoothmicrophonesecurerom
vulnerability Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution. The post Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosu… SecurityWeek · Jun 19, 2026 High CVE-2026-20253
ransomware Gentlemen ransomware uses multiple EDR killers to disable defenses The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. BleepingComputer · Jun 18, 2026 High
threat-intel Novo Nordisk Breach Exposes Software Development Pipeline Risk A breach at Novo Nordisk, facilitated by a leaked GitHub token, exposed a significant amount of sensitive data, including patient clinical trial information, healthcare professional records, and proprietary drug developm… Dark Reading · Jun 18, 2026 High DKgithubsecretssupply-chain
threat-intel Bulgaria allowed surveillance tech firm to sell products to repressive regimes, report says A report by Human Rights Watch revealed that Bulgaria allowed a surveillance technology firm, Circles, to sell its products – including Pixcell, Landmark, and Voice Over Location Enabler software – to repressive regimes… The Record · Jun 18, 2026 High BUELUAsurveillancespywareexport control
apt Operation Escaneo Signals Shift in LatAm Threat Landscape Operation Escaneo, a coordinated cyber campaign led by the MexicanMafia/PanchoVilla threat actor, represents a significant shift in the threat landscape of Latin America. The campaign, spanning 2025-2026, targeted critic… Dark Reading · Jun 18, 2026 High CVE-2022-42475CVE-2023-27997CVE-2024-21762MXECPTlatin americareconnaissancedata exfiltration
data-breach Nintendo confirms data stolen in WebMD subsidiary cyberattack Nintendo of America experienced a data breach following a cyberattack on its internal employee survey platform, TinyPulse, operated by WebMD’s subsidiary. Threat actor Shadowbyt3$ stole survey data and employee personal… BleepingComputer · Jun 18, 2026 High USemployee datasurvey dataransomware
threat-intel FIFA Bug Exposed World Cup Streams to Remote Takeover A vulnerability in FIFA's Microsoft Entra environment allowed an ethical hacker, "BobDaHacker," to gain unauthorized access to global World Cup streams, match management systems, and related data platforms. The issue ste… Dark Reading · Jun 18, 2026 High USFRCOaccess-controlvulnerabilityauthentication
threat-intel Close Encounters of the Human Kind This article from Cisco Talos details a novel approach to reverse engineering that leverages AI agents alongside traditional tools like the VB6 disassembler. The key innovation is exposing the disassembler's parsed data… Cisco Talos · Jun 18, 2026 High GBFRUSreverse engineeringaiautomation
threat-intel ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm A sprawling Android botnet called Popa, used for advertising fraud, account takeovers, and data scraping, has been linked to NetNut, a residential proxy provider operated by Alarum Technologies Ltd. Researchers discovere… Krebs on Security · Jun 18, 2026 High ISbotnetproxyandroid
vulnerability F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution F5 has released security patches to address two critical vulnerabilities (CVE-2026-42530 and CVE-2026-42055) in its NGINX Open Source and NGINX Plus products. These vulnerabilities, which allow for remote code execution,… The Hacker News · Jun 18, 2026 Critical CVE-2026-42530CVE-2026-42055CVE-2026-42945nginxcode executionremote vulnerability