threat-intel Hacker Conversations: Isira Adithya, the Evolution of an Ethical Hacker This article details the story of Isira Adithya, a young Sri Lankan-born ethical hacker who developed a passion for understanding technology from a young age. Starting with tinkering with electronics and computer games,… SecurityWeek · Jun 16, 2026 Low UKLKethical hackingbug bountycybersecurity
threat-intel GhostTree Attack Abused Recursive Windows Junctions to Hide Malware Security researchers have discovered a novel technique, dubbed "GhostTree," used by attackers to evade detection by security tools. This method leverages recursive loops created using NTFS junctions to hide malicious fil… BleepingComputer · Jun 16, 2026 High USjunctionsntfsrecursion
phishing FTC warns of record $3.5 billion losses to imposter scams in 2025 The U.S. Federal Trade Commission (FTC) reported a record $3.5 billion in losses attributed to imposter scams in 2025, representing a significant increase from 2020. These scams, primarily leveraging social media, target… BleepingComputer · Jun 16, 2026 High USscamsfraudsocial media
Magnitude Emerges From Stealth Mode With $10 Million in Funding The company is enhancing third-party risk management (TPRM) through autonomous AI agents. The post Magnitude Emerges From Stealth Mode With $10 Million in Funding appeared first on SecurityWeek . SecurityWeek · Jun 16, 2026
threat-intel AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask This SecurityWeek article explores the current landscape of artificial intelligence (AI) within cybersecurity, focusing on its diverse applications and potential risks. It examines key AI technologies like generative AI… SecurityWeek · Jun 16, 2026 Medium aigenerative-aimachine-learning
malware New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds A new Android banking trojan, Rokarolla, has been identified by Zimperium, targeting over 200 banking and cryptocurrency apps. The malware utilizes techniques like fake login pages and Accessibility abuse to steal sensit… The Hacker News · Jun 16, 2026 High androidbanking trojanpin theft
Endpoint Security Startup Ent Emerges From Stealth With $100 Million Seed Round Ent has developed an intent-aware platform designed to interpret user and agent behavior before risky actions are carried out. The post Endpoint Security Startup Ent Emerges From Stealth With $100 Million Seed Round appe… SecurityWeek · Jun 16, 2026
Cybercrime Group Claims Novo Nordisk Hack The hack-and-leak group FulcrumSec claims to have stolen 1.3TB of data from the pharmaceutical giant. The post Cybercrime Group Claims Novo Nordisk Hack appeared first on SecurityWeek . SecurityWeek · Jun 16, 2026
threat-intel Can CISOs Trust Their Applications? TrustCloud Wants to Replace the Questionnaire This article discusses the challenges CISOs face when assessing the trust and security of their enterprise applications, highlighting the manual and time-consuming nature of traditional questionnaire-based approaches. Tr… SecurityWeek · Jun 16, 2026 Medium GBautomationaiapplication security
vulnerability Rockwell Automation FLEX I/O EtherNet/IP Adapters This CISA advisory details vulnerabilities within Rockwell Automation’s FLEX I/O EtherNet/IP Adapters (versions 2.012) that could allow unauthorized access and potential loss of device availability. The issues include a… CISA Advisories · Jun 16, 2026 High CVE-2026-0646CVE-2026-0647USethernet/ipcontrol systemsmemory corruption
vulnerability Rockwell Automation CompactLogix Rockwell Automation has issued a security advisory regarding vulnerabilities in its CompactLogix 5370 L1, L2, and L3 controllers. These vulnerabilities, stemming from improper validation of sequence numbers and source IP… CISA Advisories · Jun 16, 2026 Medium CVE-2025-11694CVE-2026-9307UScipdenial-of-serviceindustrial-control-systems
threat-intel Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP Rockwell Automation has identified a denial-of-service vulnerability (CVE-2026-11317) affecting several versions of its Logix 5370 and 5570 controllers. The vulnerability stems from a fault triggered by crafted CIP messa… CISA Advisories · Jun 16, 2026 High CVE-2026-11317USdenial-of-serviceciprockwell automation
vulnerability Rockwell Automation RSLinx Rockwell Automation has issued a security advisory regarding a vulnerability in its RSLinx Classic software. The flaw, a stack-based buffer overflow (CVE-2020-13573), allows for remote code execution and could lead to de… CISA Advisories · Jun 16, 2026 High CVE-2020-13573WObuffer overflowremote code executioncve-2020-13573
vulnerability Rockwell Automation FactoryTalk Analytics PavilionX This advisory from CISA details a critical vulnerability in Rockwell Automation’s FactoryTalk Analytics PavilionX software, specifically versions below 7.01. The flaw, stemming from improper authorization enforcement in… CISA Advisories · Jun 16, 2026 Critical CVE-2025-14272UScveauthorizationapi
data-breach Cal Water Investigating Iranian Hackers’ Claims California Water Service (Cal Water) is currently investigating claims of a hack by the Iran-linked threat actor Handala, who allegedly stole and leaked sensitive data from the utility’s systems. The incident, potentiall… SecurityWeek · Jun 16, 2026 High USwater sectorcyberattackdata breach
White House Issues Memo to Bolster NSS Cybersecurity NSPM-12 establishes a clear structure for NSS cybersecurity governance and accountability and reestablishes CNSS. The post White House Issues Memo to Bolster NSS Cybersecurity appeared first on SecurityWeek . SecurityWeek · Jun 16, 2026
threat-intel Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive A recent study by Spur Intelligence found that anonymized infrastructure, primarily through VPNs and residential proxies, is now a dominant factor in nearly every security incident. Despite the abundance of IP data avail… The Hacker News · Jun 16, 2026 High USanonymizationip intelligencevpn
other Flock Cameras Are Being Used for Stalking Flock Cameras, a manufacturer of residential security cameras, is facing scrutiny due to reports of law enforcement agencies using their systems for excessive and potentially unlawful surveillance. Multiple cases across… Schneier on Security · Jun 16, 2026 High USsurveillanceprivacypolice
supply-chain Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages Arch Linux suspended account registrations in response to the wave of malicious packages being uploaded to AUR. The post Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages appeared first on SecurityWeek . SecurityWeek · Jun 16, 2026
vulnerability CISA warns of another cPanel plugin flaw exploited in attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical vulnerability (CVE-2026-48172) in the LiteSpeed cPanel user-end plugin, which is currently being actively exploited.… BleepingComputer · Jun 16, 2026 Critical CVE-2026-54420CVE-2026-48172cpanelvulnerabilityprivilege escalation