vulnerability Joomla, LiteSpeed Vulnerabilities Exploited in Attacks The flaws allow attackers to execute arbitrary PHP code and gain root privileges on shared hosting servers. The post Joomla, LiteSpeed Vulnerabilities Exploited in Attacks appeared first on SecurityWeek . SecurityWeek · Jun 17, 2026 CVE-2026-48907CVE-2026-54420
data-breach Kodak confirms data breach claimed by ShinyHunters extortion gang Kodak has confirmed that it's working with external cybersecurity experts to investigate a security breach after hackers gained access to some of the company's data. BleepingComputer · Jun 17, 2026 High
vulnerability 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs Recent analysis reveals that three previously patched Fortinet FortiSandbox vulnerabilities – CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089 – are actively being exploited in the wild. A significant number of comprom… SecurityWeek · Jun 17, 2026 High CVE-2026-39808CVE-2026-39813CVE-2026-25089USINALvulnerabilitypatchingexploitation
vulnerability CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution CISA has added a critical vulnerability, CVE-2026-48907, to its Known Exploited Vulnerabilities catalog affecting the Widget Factory Joomla Content Editor (JCE) due to improper access control. This flaw allows for PHP co… The Hacker News · Jun 17, 2026 Critical CVE-2026-48907TUjoomlaphpcode execution
threat-intel ISC Stormcast For Wednesday, June 17th, 2026 https://isc.sans.edu/podcastdetail/9976, (Wed, Jun 17th) The SANS Internet Storm Center's Stormcast for June 17th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The broadcast detailed heightened activity related to phishing cam… SANS Internet Storm Center · Jun 17, 2026 Medium phishingvulnerabilitythreat intelligence
supply-chain GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say A supply-chain worm, dubbed Shai-Hulud, is exploiting design flaws in GitHub to infect hundreds of software packages and developer accounts worldwide. The vulnerabilities, initially flagged by Deep Specter Research, were… The Record · Jun 16, 2026 High GBFRsupply chainvulnerabilitygithub
India's Telegram ban draws criticism from Durov as company challenges order in court To prevent cheating, Indian authorities ordered Telegram to restrict access nationwide ahead of a major medical entrance exam. The Record · Jun 16, 2026
malware Fileless Phantom Stealer Targets Browser Credentials A new fileless malware, Phantom Stealer, is being deployed through targeted phishing campaigns against banks and high-value organizations. The malware focuses on stealing browser credentials and session cookies, utilizin… Dark Reading · Jun 16, 2026 High GBDEFRcredential theftbrowser securityfileless malware
threat-intel Security Community Slams US Ban on Exporting Mythos, Fable The US government recently imposed an export control order restricting access to Anthropic's Claude Fable 5 and Mythos 5 large language models (LLMs) for foreign nationals, citing national security concerns, particularly… Dark Reading · Jun 16, 2026 High USCHllmaiexport control
threat-intel Malicious JetBrains Marketplace plugins steal AI API keys from developers A coordinated malware campaign involving 15 malicious plugins for the JetBrains Marketplace was discovered, designed to steal AI API keys from developers. These plugins, disguised as AI coding assistants and code review… BleepingComputer · Jun 16, 2026 High USapi-keycredential-theftide
malware New Rokarolla Android malware targets 217 banking, crypto apps A new Android banking trojan, Rokarolla, is targeting 217 banking and cryptocurrency applications through deceptive app distribution and sophisticated data theft techniques. The malware leverages Accessibility permission… BleepingComputer · Jun 16, 2026 High androidbanking trojandata theft
supply-chain Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting A vulnerability in the Google Cloud Vertex AI SDK allowed attackers to hijack model uploads by exploiting predictable bucket naming conventions. Attackers could create a temporary bucket in their own project, intercept t… The Hacker News · Jun 16, 2026 High CVE-2026-2473USbucket squattingmodel uploadcloud storage
malware Steam Workshop abused to spread malware via Wallpaper Engine app Threat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push various malware hidden in wallpaper packages. BleepingComputer · Jun 16, 2026 Medium
threat-intel SprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detection A new Windows variant of the SprySOCKS Linux backdoor, developed by the nation-state threat actor FishMonger (also known as Earth Lusca and Aquatic Panda), has been discovered targeting government organizations in Hondur… Dark Reading · Jun 16, 2026 High HNTWTHkernel-driveraptbackdoor
threat-intel ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures ClickFix campaigns are expanding their malware delivery tactics with new loaders, including BabaDeda Loader, Lorem Ipsum Loader, and Storage Crypter, targeting education and financial organizations. These attacks utilize… The Hacker News · Jun 16, 2026 High RUBYsocial engineeringloaderpayload
malware Rokarolla Android Trojan Levels Up to Full Device Control, Persistence The Rokarolla Android Trojan has evolved to offer full device control and persistence, moving beyond typical banking Trojan capabilities. Distributed through fake Chrome and TikTok downloads, the malware steals credentia… Dark Reading · Jun 16, 2026 High USandroidbanking trojandevice control
threat-intel India temporarily blocks Telegram over medical exam cheating fears India temporarily blocked access to the Telegram messaging app due to concerns about cheating during a nationwide rerun of the NEET-UG medical entrance exam. Authorities cited instances of scammers using Telegram to dist… The Record · Jun 16, 2026 Medium INtelegramexamcheating
threat-intel 'Lorem Ipsum' Malware Pivots to ClickFix Delivery The 'Lorem Ipsum' malware campaign, initially delivered via Trojanized Microsoft Teams installers, has shifted its tactics following Microsoft's disruption of the Fox Tempest malware-signing-as-a-service provider. Now, t… Dark Reading · Jun 16, 2026 High USclickfixwordpressshellcode
iRhythm Confirms Data Stolen in Hack The digital health company said it learned of the breach on June 8 and the attackers demanded a ransom. The post iRhythm Confirms Data Stolen in Hack appeared first on SecurityWeek . SecurityWeek · Jun 16, 2026
threat-intel UK to require ID or face scan before you can make social media accounts The UK government is implementing new regulations to restrict social media access for under-16s, requiring platforms to verify users' ages through ID uploads or facial scans. This follows a model established in Australia… BleepingComputer · Jun 16, 2026 Medium GBage-verificationsocial-mediaprivacy