vulnerability Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed exploitation of CVE-2026-… The Hacker News · Jun 16, 2026 Medium CVE-2026-39813CVE-2026-39808CVE-2026-25089
threat-intel Cybersecurity Executives Urge the Trump Administration to Ease Restrictions on Anthropic AI Models A coalition of cybersecurity executives and experts is urging the Trump administration to reverse its restrictions on Anthropic’s AI models, specifically Fable 5 and Mythos 5. The group argues that limiting access to the… SecurityWeek · Jun 16, 2026 Medium CHUNaiartificial intelligencecybersecurity
ransomware Ransomware gang abuses Microsoft Teams relays to hide malicious traffic DragonForce ransomware utilized a custom malware, Backdoor.Turn, to conceal command-and-control traffic by leveraging Microsoft Teams’ TURN protocol. This technique allowed the attackers to bypass traditional network def… BleepingComputer · Jun 16, 2026 High CVE-2023-52271CVE-2025-61155CVE-2025-1055USteamsturnrat
supply-chain Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE A vulnerability in the Google Cloud Vertex AI Python SDK (versions 1.139.0 - 1.140.0) allowed attackers to hijack model uploads and execute remote code execution (RCE) within a target's Vertex AI serving infrastructure.… Palo Alto Unit 42 · Jun 16, 2026 High sdkrcebucket squatting
threat-intel China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Researchers have identified new Windows variants of the SprySOCKS backdoor, initially linked to the Chinese state-sponsored threat actor Earth Lusca (also known as Aquatic Panda). These variants, designated WIN_DRV and W… The Hacker News · Jun 16, 2026 High CVE-2023-24932CNTWHUbackdoorwindowsstealth
threat-intel Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure The Athena coalition, comprised of numerous tech and fintech firms, has been established to proactively identify and mitigate vulnerabilities in open-source software (OSS) before public disclosure. This initiative addres… SecurityWeek · Jun 16, 2026 High ossvulnerabilityai
vulnerability Critical Fortinet FortiSandbox flaws now exploited in attacks Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused. BleepingComputer · Jun 16, 2026 CVE-2026-39813CVE-2026-39808CVE-2026-25089
threat-intel Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk A widespread campaign involving malicious wallpapers distributed through the Steam Workshop has been identified, targeting gamers primarily in China and Russia. Attackers are exploiting the Wallpaper Engine’s sharing fea… Securelist · Jun 16, 2026 High CNRUsteamwallpapermalware
threat-intel Windows version of SprySOCKS Linux malware used to attack govt orgs Windows variants of the SprySOCKS Linux malware, previously linked to the Earth Lusca threat actor, have been used to target government organizations in Taiwan, Thailand, Pakistan, and Honduras. These variants offer adva… BleepingComputer · Jun 16, 2026 High CVE-2023-24932TWTHPKlinuxstealthbackdoor
threat-intel FishMonger’s arsenal upgraded: SprySOCKS for Windows ESET researchers have discovered two new, undocumented Windows variants of FishMonger's SprySOCKS backdoor, operated by the Chinese threat actor I-SOON (believed to be part of the Winnti Group). These variants, WIN_DRV a… WeLiveSecurity · Jun 16, 2026 High CHHOTAwindowsbackdoorkernel driver
threat-intel Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware North Korean APT37 group utilized a spear-phishing campaign mimicking Microsoft security alerts to deploy NarwhalRAT malware. The campaign leveraged urgency and confusion to trick victims into executing a malicious LNK f… The Hacker News · Jun 16, 2026 High NOSOspear-phishingratnorth korean
ransomware From a VHDX File to a Remcos RAT, (Tue, Jun 16th) A malicious ZIP archive, containing a VHDX file, was discovered utilizing a multi-stage attack chain to deploy the Remcos RAT. The initial delivery involves a JavaScript payload that leverages WMI and PowerShell to execu… SANS Internet Storm Center · Jun 16, 2026 High DEratpowershellwmi
data-breach iRhythm discloses data breach, says hackers stole patient info Digital healthcare company iRhythm Holdings has disclosed a data breach after hackers stole patients' personal and health information stored on third-party-hosted business applications. BleepingComputer · Jun 16, 2026 High
vulnerability Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write. The post Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks appeared first o… SecurityWeek · Jun 16, 2026 Critical CVE-2026-20262CVE-2026-20182CVE-2026-20127
vulnerability Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw A vulnerability (CVE-2026-20262) in Cisco Catalyst SD-WAN Manager has been actively exploited in the wild, allowing authenticated attackers to overwrite files on affected systems. The flaw stems from inadequate input val… The Hacker News · Jun 16, 2026 High CVE-2026-20262CVE-2026-20245CVE-2026-20182USsd-wancvefile-upload
vulnerability CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Bran… The Hacker News · Jun 16, 2026 High CVE-2026-54420
threat-intel ISC Stormcast For Tuesday, June 16th, 2026 https://isc.sans.edu/podcastdetail/9974, (Tue, Jun 16th) The SANS Internet Storm Center's June 16th, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observ… SANS Internet Storm Center · Jun 16, 2026 Medium phishingddosbotnet
policy UK to ban social media access for children under 16 The UK government is planning to ban social media access for individuals under 16, mirroring a similar measure implemented in Australia. This initiative aims to protect children online by restricting access to user-to-us… The Record · Jun 16, 2026 Medium UKAUSPsocial mediachildrenonline safety
threat-intel Inside the Modern SOC: The 72-Minute Race This article, from Palo Alto Unit 42, highlights the increasing speed of cyberattacks and the challenges modern Security Operations Centers (SOCs) face in keeping pace. Attackers are leveraging AI and automation to compr… Palo Alto Unit 42 · Jun 15, 2026 High USaiautomationlateral movement
Estonia to quarantine emails sent from Russian .ru domain before they reach government officials Estonia will require additional security screening for emails sent from Russia’s .ru top-level domain before they reach government officials, according to the country's minister of justice and digital affairs. The Record · Jun 15, 2026