vulnerability F5 Patches Critical, High-Severity NGINX Vulnerabilities Critical flaws in NGINX could allow remote, unauthenticated attackers to cause a restart and potentially execute arbitrary code. The post F5 Patches Critical, High-Severity NGINX Vulnerabilities appeared first on Securit… SecurityWeek · Jun 18, 2026 Critical CVE-2026-42530CVE-2026-42055CVE-2026-11311
SailPoint to Acquire Entro in Reported $200 Million Deal Israel-based Entro specializes in non-human identity and credential security solutions, and it will enable SailPoint to enhance its products. The post SailPoint to Acquire Entro in Reported $200 Million Deal appeared fir… SecurityWeek · Jun 18, 2026
data-breach Kodak Admits Data Breach After ShinyHunters Hack Claims Kodak told SecurityWeek it believes there is no threat to its systems or operations as a result of the cybersecurity incident. The post Kodak Admits Data Breach After ShinyHunters Hack Claims appeared first on SecurityWe… SecurityWeek · Jun 18, 2026 High
threat-intel EU Gets a Head Start in Developing 6G Network Security The EU is launching the "Shield-6G" project, a collaborative initiative funded by the EU, to proactively develop cybersecurity measures for the upcoming 6G network. This project, involving 19 organizations, aims to addre… Dark Reading · Jun 18, 2026 Medium EU6gaicybersecurity
threat-intel ISC Stormcast For Thursday, June 18th, 2026 https://isc.sans.edu/podcastdetail/9978, (Thu, Jun 18th) The SANS Internet Storm Center's June 18th, 2026 Stormcast reported a heightened level of online threats and unusual network activity across various sectors. The broadcast highlighted several emerging trends, including i… SANS Internet Storm Center · Jun 18, 2026 Medium phishingdnsthreat-monitoring
threat-intel The Behavior of Coordinated SSH Brute Force Attacks over the last three months [Guest Diary], (Wed, Jun 17th) This report details a three-month analysis of coordinated SSH brute-force attacks conducted using a honeypot system, highlighting a correlation between attack activity and geopolitical events, law enforcement actions, an… SANS Internet Storm Center · Jun 18, 2026 High USIRILsshbrute-forcehoneypot
Leak confirms OpenAI is testing a ChatGPT for Science subscription OpenAI appears to be testing a new subscription and experience for science use cases, but it's unclear if it'll be available to everyone regardless of their background. BleepingComputer · Jun 18, 2026
vulnerability Multiples vulnérabilités dans Mattermost Desktop App (18 juin 2026) Multiple vulnerabilities have been discovered in the Mattermost Desktop App, potentially allowing for remote denial-of-service attacks and an unspecified security issue. These vulnerabilities affect older versions of the… CERT-FR · Jun 18, 2026 Medium CVE-2026-8075CVE-2026-9602vulnerabilitymattermostdesktop app
threat-intel Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed This Smashing Security podcast episode discusses a concerning trend: the potential for AI coding assistants to be exploited for password leakage. The discussion highlights how AI tools, particularly those like ProtonPass… Graham Cluley · Jun 17, 2026 High SWaipasswordcredential
threat-intel Google to use UK and EU user IP addresses for ad personalization Google plans to begin using IP addresses from August 3, 2026, across the EEA, UK, and Switzerland for ad measurement and personalization. This shift is driven by regulatory changes regarding personal data, particularly u… BleepingComputer · Jun 17, 2026 Medium GBEUCHprivacygdprconsent
ransomware INC Ransomware Thrives by Mastering the Basics The INC ransomware group has emerged as a significant threat, particularly thriving through a focus on established ransomware-as-a-service (RaaS) tactics and targeting sectors with high pressure to pay, such as healthcar… Dark Reading · Jun 17, 2026 High CVE-2025-5777CVE-2024-57727CVE-2023-3519UKraasransomwareextortion
threat-intel Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments A threat actor is employing deceptive tactics to promote a cryptocurrency clipboard hijacker, leveraging fake reviews, AI-generated content, and manipulated reputation systems across multiple online platforms. The campai… The Hacker News · Jun 17, 2026 High USfake reviewsreputation managementai
threat-intel Hostile states behind three-quarters of attacks on Britain's critical infrastructure, cyber chief warns This article reports that the UK’s cyber chief, Richard Horne, has shifted the government’s approach to cybersecurity, framing it as a ‘contest’ against hostile state actors rather than a ‘risk’ to be managed. He reveale… The Record · Jun 17, 2026 High CHUKstate-sponsoredcritical infrastructurecyber conflict
vulnerability Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability has now been assigned the CVE identifier CVE-2026-50656 (CVSS score: 7.8), wit… The Hacker News · Jun 17, 2026 Critical CVE-2026-50656CVE-2026-33825CVE-2026-45498
threat-intel EU grants Ukraine access to cybersecurity reserve for major attacks The European Union has granted Ukraine access to its cybersecurity reserve, a pool of private cybersecurity firms, to bolster the country's defenses against ongoing cyberattacks, primarily from Russia. This move signifie… The Record · Jun 17, 2026 High UKEURUcyberattackcyberdefenseeu cybersecurity
threat-intel The browser blind spot: Why your security tool may not be blocking what you think it is [Guest Diary], (Wed, Jun 17th) This article highlights a significant security gap in Cloud Access Security Broker (CASB) deployments due to the increasing use of the QUIC protocol. CASBs, traditionally designed to inspect TCP traffic, fail to detect w… SANS Internet Storm Center · Jun 17, 2026 High quiccasbssl
threat-intel Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline A junior hacker, identified as ‘Poisson,’ infiltrated a French automotive business by exploiting vulnerabilities and establishing persistent access after his command-and-control server was taken down. He utilized OpenSSH… The Hacker News · Jun 17, 2026 Medium FRDEpersistenceremote-accessssh
data-breach FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. A significant data leak, dubbed "FortiBleed," has exposed approximately 73,932 Fortinet VPN credentials for firewall URLs across numerous organizations worldwide. The leak, discovered by Bob Diachenko, reveals a multi-op… BleepingComputer · Jun 17, 2026 High USGBJPvpncredentialsbreach
Webinar Today: How Modern Breaches Bypass MFA and Evade Detection Attendees will learn how attackers evade conventional detection methods, why legacy MFA alone is no longer sufficient, and how organizations can strengthen their defenses. The post Webinar Today: How Modern Breaches Bypa… SecurityWeek · Jun 17, 2026
threat-intel Why Account Takeovers Are Rising and How to Stop Them This article discusses the rising trend of account takeover attacks, driven by increased complexity in organizational identity management due to hybrid work, BYOD, and expanded cloud services. Attackers are leveraging cr… BleepingComputer · Jun 17, 2026 High USaccount takeovercredential theftmfa fatigue