threat-intel Chinese hackers breach REDCap servers, steal medical research A Chinese espionage campaign, attributed to UNC6508, targeted a North American medical research institution by exploiting vulnerabilities in the REDCap platform. The attackers deployed the custom malware, ‘Infinitered,’… BleepingComputer · Jun 15, 2026 High CHUSCAespionagecredential_theftredcap
threat-intel ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More This week’s cybersecurity recap highlights several active exploits and attacks, including a Chrome 0-day being actively leveraged, a ShinyHunters gang exploiting a PeopleSoft zero-day for lateral movement and data exfilt… The Hacker News · Jun 15, 2026 High CVE-2026-11645CVE-2026-2441CVE-2026-3909UNCHzero-dayphishingsupply-chain
threat-intel Finland brings charges against cargo ship officers for cutting submarine cables Finnish authorities have brought charges against the captain and bosun of the cargo ship Fitburg for damaging several submarine cables in the Baltic Sea. The incident occurred while the ship was transporting sanctioned s… The Record · Jun 15, 2026 Medium FIRUISsubmarine cablessabotagebaltic sea
data-breach Maine forced to take down data breach portal after fake notices filed with authorities The US state of Maine has taken its public data breach notification portal offline after someone submitted fraudulent breach disclosures impersonating two well-known technology companies. Read more in my article on the H… Graham Cluley · Jun 15, 2026 High
NewCore Emerges From Stealth Mode With $66 Million in Funding The startup has built a security-first identity platform to protect humans, machines, and AI agents. The post NewCore Emerges From Stealth Mode With $66 Million in Funding appeared first on SecurityWeek . SecurityWeek · Jun 15, 2026
threat-intel New attack turned Microsoft 365 Copilot into 1-click data theft tool A critical vulnerability, dubbed SearchLeak, has been discovered in Microsoft 365 Copilot Enterprise, allowing attackers to steal sensitive data from user mailboxes, OneDrive, and SharePoint accounts via a specially craf… BleepingComputer · Jun 15, 2026 Critical CVE-2026-42824prompt injectionssrfhtml injection
data-breach Infinite Campus data breach affects 137,000 school staff accounts The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in M… BleepingComputer · Jun 15, 2026 High
threat-intel Anthropic says US government forced it to disable cybersecurity AI models Anthropic, a leading AI developer, was compelled by the U.S. government to disable two of its advanced cybersecurity AI models, dubbed Fable 5 and Mythos 5. This action stemmed from an export control directive restrictin… The Record · Jun 15, 2026 Medium USaiexport controlcybersecurity
threat-intel US Cracks Down on Anthropic AI Models Amid Abuse Concerns Anthropic has suspended access to its Fable 5 and Mythos 5 AI models following a US government export control directive, aimed at preventing foreign nationals from utilizing them. This action stems from growing concerns… Dark Reading · Jun 15, 2026 High CHRUUKaicybersecuritythreat intelligence
phishing Webinar: How behavioral AI stops phishing and account takeovers Modern phishing, BEC, and account takeover attacks increasingly bypass traditional email defenses and create operational strain for security teams. This webinar explores how behavioral AI can help automate detection, inv… BleepingComputer · Jun 15, 2026 Medium
ransomware Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang. The post Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges appeared first on SecurityWeek . SecurityWeek · Jun 15, 2026 High
threat-intel The Onboarding Password Mistake That Creates Unnecessary Risk This article discusses the significant security risks associated with using temporary onboarding passwords, highlighting how they are frequently shared insecurely and remain active for extended periods. The practice crea… The Hacker News · Jun 15, 2026 High USIRonboardingcredentialssecurity
data-breach Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems The pharmaceutical giant says the attackers gained access to personal data stored on the compromised systems. The post Ozempic Maker Novo Nordisk Says Hackers Breached IT Systems appeared first on SecurityWeek . SecurityWeek · Jun 15, 2026
threat-intel French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker A breach of the French government’s secure messaging platform, Tchap, has resulted in the theft of personal data for over 70,000 government employees. The incident was initially attributed to a threat actor calling itsel… SecurityWeek · Jun 15, 2026 High FRdata-breachgovernmentcredential theft
malware 152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic A network of 152 Chrome extensions, collectively installed over 105,000 times, has been discovered distributing a potentially unwanted program (PUP) that generates fake traffic and logs user data. These extensions, masqu… The Hacker News · Jun 15, 2026 High TRadwarefake trafficprivacy
The FCC Wants to Eliminate Burner Phones A proposed FCC rule would kill burner phones: phones whose accounts are not attached to a particular person. The FCC plans to do this by legally forcing the country’s telecoms to store a wealth of personal information ab… Schneier on Security · Jun 15, 2026
ShinyHunters Claims Council of Europe Hack The extortion group threatens to leak 297 GB of data allegedly stolen from the Council of Europe, including employee personal information. The post ShinyHunters Claims Council of Europe Hack appeared first on SecurityWee… SecurityWeek · Jun 15, 2026
malware Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites A security incident has been discovered affecting over 1.2 million WordPress sites using the PushEngage, OptinMonster, and TrustPulse plugins. An attacker tampered with the plugins' JavaScript files, creating backdoors t… The Hacker News · Jun 15, 2026 High CVE-2026-10795USwordpresscdnbackdoor
phishing FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service The platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses. The post FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service appeared first on… SecurityWeek · Jun 15, 2026 Medium
threat-intel EvilTokens: A phishing attack that doesn’t steal your password EvilTokens is a sophisticated phishing-as-a-service (PaaS) kit that bypasses traditional phishing defenses by leveraging the OAuth 2.0 device authorization grant flow. Attackers use convincing lures – often mimicking leg… WeLiveSecurity · Jun 15, 2026 High phishingoath2device-code