threat-intel DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act The U.S. Department of Justice seized the CFAKE.com and SOCFAKE.com websites, which hosted deepfake nude images and videos of public figures, under the TAKE IT DOWN Act. This marks the first public use of the legislation… BleepingComputer · Jun 15, 2026 High USITFRdeepfakeaipornography
vulnerability SimpleHelp bug lets hackers create rogue remote support accounts A critical vulnerability (CVE-2026-48558) in SimpleHelp remote management software allows unauthorized users to create privileged technician accounts via OpenID Connect (OIDC) authentication. This flaw, combined with spe… BleepingComputer · Jun 15, 2026 Critical CVE-2026-48558oidcremote managementauthentication
threat-intel Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails A China-linked espionage group, UNC6508, gained access to North American medical, academic, and military research networks via a backdoor on REDCap servers, stealing sensitive research and defense emails. The attackers e… The Hacker News · Jun 15, 2026 High CHUSCAespionageredcapgoogle workspace
threat-intel North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels North Korean threat actors, operating under the UNK_DeadDrop campaign, are employing a sophisticated phishing technique targeting developers across numerous sectors, including finance and cryptocurrency, using malicious… The Hacker News · Jun 15, 2026 High USGBAUdevelopergithubvscode
threat-intel HTTP/2 Bomb Attacks Put Telcos, Healthcare Orgs at Risk This article reports on the ‘HTTP/2 Bomb’ vulnerability, a denial-of-service exploit leveraging features within the HTTP/2 protocol to amplify junk traffic and cause widespread disruptions. The vulnerability affects a si… Dark Reading · Jun 15, 2026 High CVE-2026-49975UShttp2ddosamplification
threat-intel Copilot 'SearchLeak' Attack Allows 1-Click Data Theft A critical vulnerability, dubbed ‘SearchLeak,’ has been discovered in Microsoft Copilot that allows attackers to silently steal user data through a novel prompt injection technique. The attack leverages a race condition… Dark Reading · Jun 15, 2026 Critical CVE-2026-42824prompt injectionai securitymicrosoft copilot
data-breach Maine closes data breach portal to the public after fake reports Maine is still allowing companies to report breaches, but won’t make the portal easily available to the public until after it completes an audit of its procedures to stop such incidents, according to a press release from… The Record · Jun 15, 2026 High
supply-chain OptinMonster WordPress plugin hacked in CDN supply-chain attack A supply-chain attack targeting the Awesome Motive CDN compromised WordPress plugins OptinMonster, TrustPulse, and PushEngage. Attackers gained access through a vulnerability in the UpdraftPlus plugin, leveraging the CDN… BleepingComputer · Jun 15, 2026 High UScdnwordpresssupply chain
vulnerability Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks Cisco has released a security update to address a critical zero-day vulnerability (CVE-2026-20262) in its SD-WAN vManage software, allowing attackers to gain root privileges. The flaw stems from improper input validation… BleepingComputer · Jun 15, 2026 Critical CVE-2026-20262CVE-2026-20133CVE-2026-20128zero-dayroot privilegefile upload
threat-intel China-Nexus Actor Spied on US Researchers Undetected for a Year Google’s Threat Intelligence Group (GTIG) discovered and disrupted a year-long espionage campaign by the China-Nexus threat actor, UNC6508, targeting US academic, medical, and military research institutions. The actor ut… Dark Reading · Jun 15, 2026 High CHUScyber espionageintel gatheringcredential theft
threat-intel Most CISOs Report Pressure to Bury Bad Security News This Dark Reading article examines the significant pressure faced by CISOs to suppress or delay disclosing security findings, particularly regarding vulnerabilities and breaches. The primary drivers of this pressure stem… Dark Reading · Jun 15, 2026 Medium cisospressuredisclosure
vulnerability LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers A critical vulnerability chain in LiteLLM, an open-source AI gateway, allows low-privilege users to escalate their permissions to full administrator and execute arbitrary code on the server. Researchers at Obsidian Secur… The Hacker News · Jun 15, 2026 Critical CVE-2026-47101CVE-2026-47102CVE-2026-40217USaiproxyprivilege escalation
data-breach Council of Europe investigates ShinyHunters data breach claims The Council of Europe, the continent's oldest intergovernmental body, is probing claims of a data breach made by the ShinyHunters extortion group over the weekend. BleepingComputer · Jun 15, 2026 High
FBI: Fraudsters use couriers to steal money in crypto scams The U.S. Federal Bureau of Investigation (FBI) warned that criminals are using couriers to collect money from victims of cryptocurrency investment scams, also known as pig butchering or romance baiting. BleepingComputer · Jun 15, 2026
ransomware Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer Mackay Sugar, Australia's second-largest raw sugar producer, experienced a ransomware attack that disrupted operations at two of its cane-processing mills. The attack, attributed to the Gentlemen ransomware group (Storm-… SecurityWeek · Jun 15, 2026 High AUransomwareaustraliasugar
threat-intel One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes A vulnerability, dubbed SearchLeak, was discovered in Microsoft 365 Copilot Enterprise Search that allowed attackers to exfiltrate sensitive data like emails, calendar details, and MFA codes through a single click. The f… The Hacker News · Jun 15, 2026 High CVE-2026-42824CVE-2025-32711UScommand injectionprompt injectionbing
threat-intel The Beginning of the End of Social Engineering This article discusses a significant shift in cybersecurity driven by the integration of AI-native operating systems, particularly Google's Gemini and Apple's Apple Intelligence. Operating systems are evolving to activel… Dark Reading · Jun 15, 2026 High USaisocial engineeringauthentication
other Cyberattack on Russian tech firm Astral disrupts business, government services for week A cyberattack disrupted the operations of Russian tech firm Kaluga Astral for approximately a week, impacting its customers who rely on its software for various business and government services. The company is undergoing… The Record · Jun 15, 2026 Medium RUcyberattackdisruptionrussian
Chinese Hackers Target Medical, Military, and AI Research in North America Google’s Threat Intelligence Group has been tracking the cyberespionage group as UNC6508 since early 2025. The post Chinese Hackers Target Medical, Military, and AI Research in North America appeared first on SecurityWee… SecurityWeek · Jun 15, 2026
threat-intel Vibe coders are gonna vibe code: How CISOs are tackling code sprawl This article discusses the growing challenge of "code sprawl" driven by the increasing accessibility of AI coding tools like Claude and Lovable. Organizations are struggling to maintain visibility and control as employee… BleepingComputer · Jun 15, 2026 Medium aicode-sprawlautomation