data-breach Maine Disables Data Breach Portal Due to Fake Submissions Someone posted fake VRChat and Discord data breach reports on the system, prompting the Maine AG to take action. The post Maine Disables Data Breach Portal Due to Fake Submissions appeared first on SecurityWeek . SecurityWeek · Jun 15, 2026 High
malware Evil MSI Background: BASE64 Statistical Analysis, (Mon, Jun 15th) This report details the analysis of the "Evil MSI Background" file, a suspicious JPEG containing a hidden payload. The analysis, conducted by Didier Stevens, utilized tools like `byte-stats.py` and `base64dump.py` to unc… SANS Internet Storm Center · Jun 15, 2026 Medium base64reverse engineeringobfuscation
phishing Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts A coordinated phishing campaign, spearheaded by the now-disrupted Sniper Dz platform, targeted users in the Middle East and North Africa (MENA) through deceptive Facebook offers. The campaign leveraged browser notificati… The Hacker News · Jun 15, 2026 High DZALAEphishingsocial engineeringbrowser notifications
vulnerability Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability… The Hacker News · Jun 15, 2026 Medium CVE-2026-0257
phishing ISC Stormcast For Monday, June 15th, 2026 https://isc.sans.edu/podcastdetail/9972, (Mon, Jun 15th) The SANS Internet Storm Center's June 15th, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observ… SANS Internet Storm Center · Jun 15, 2026 Medium phishingbotnetddos
vulnerability Multiples vulnérabilités dans les produits Mattermost (15 juin 2026) Multiple vulnerabilities have been discovered in Mattermost Server, potentially allowing an attacker to cause a security issue not specified by the vendor. These vulnerabilities could lead to data integrity and confident… CERT-FR · Jun 15, 2026 Medium CVE-2026-10085CVE-2026-10103CVE-2026-10106vulnerabilitymattermostsecurity
phishing Belarus-linked hackers target Gmail accounts of Polish public figures and their families A Belarus-linked hacking group, GhostWriter (UNC1151/Storm-0257), has expanded its phishing operations to target the personal Gmail accounts of Polish public figures and their families. The group’s tactics involve creati… The Record · Jun 14, 2026 High PLBYUAphishingpolandbelarus
phishing FBI disrupts massive AI-powered phishing service using a million URLs The FBI, in collaboration with Google and Black Lotus Labs, successfully disrupted a large-scale Chinese phishing-as-a-service operation called Outsider Enterprise. This operation utilized AI to generate and distribute p… BleepingComputer · Jun 14, 2026 High CHphishingaisms
threat-intel Ex-school district employee jailed for hacks on former employer A former IT employee, Ezekiel Dean Potter, was sentenced to prison for a prolonged cyberattack against the Saydel Community School District. Potter exploited his previous access to disrupt operations, steal data, and cau… BleepingComputer · Jun 13, 2026 High UScyberattackdata-breachaccount-compromise
supply-chain NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks By default, npm install will no longer execute scripts from dependencies, unless explicitly allowed. The post NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks appeared first on SecurityWeek . SecurityWeek · Jun 13, 2026
apt Chinese hackers hijack auth flow, spy on isolated network for a decade Chinese cyber espionage group Velvet Ant conducted a decade-long operation, gaining persistent access to a large organization’s isolated critical infrastructure network by hijacking its authentication flow. The attackers… BleepingComputer · Jun 13, 2026 Critical CHespionageauthenticationpersistence
vulnerability Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication A critical vulnerability (CVE-2026-20253) has been identified in Splunk Enterprise versions below 10.2.4 and 10.0.7, allowing unauthenticated users to execute arbitrary code and potentially gain remote access. The flaw s… The Hacker News · Jun 13, 2026 Critical CVE-2026-20253USremote code executionauthenticationpostgresql
threat-intel US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos Anthropic has temporarily blocked access to its Fable 5 and Mythos 5 AI models following a directive from the US government citing national security concerns. The order restricts access to these models by foreign nationa… BleepingComputer · Jun 13, 2026 Medium USUKaijailbreaknational security
Anthropic Says It Has Taken Its Latest AI Models Offline to Comply With New Export Controls Anthropic takes Fable 5 and Mythos 5 offline to comply with a directive from the Trump administration to prevent use by foreign nationals. The post Anthropic Says It Has Taken Its Latest AI Models Offline to Comply With… SecurityWeek · Jun 13, 2026
threat-intel U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals Following a U.S. government order, Anthropic has been instructed to temporarily suspend access to its advanced AI models, Claude Fable 5 and Mythos 5, for all foreign nationals due to national security concerns. The orde… The Hacker News · Jun 13, 2026 Medium USaijailbreakcybersecurity
threat-intel Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered Palo Alto Unit 42 has discovered a new Biome stream, ‘App.MenuItem,’ in macOS Tahoe 26 that logs specific menu selections made by users. This artifact provides a detailed record of user actions, offering valuable context… Palo Alto Unit 42 · Jun 12, 2026 Medium biomemacosforensics
Friday Squid Blogging: Squid-Inspired Fluid Pump This fluid pump was inspired by the way squids propel themselves through the water. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy… Schneier on Security · Jun 12, 2026
ransomware ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed A ShinyHunters ransomware group exploited a zero-day vulnerability in Oracle's PeopleSoft software suite to compromise over 300 instances across more than 100 organizations, primarily targeting higher education instituti… Dark Reading · Jun 12, 2026 High CVE-2026-35273USUKzero-daypeoplesoftransomware
data-breach Maine disables data breach notification portal after fake disclosures Maine has taken its public data breach reporting portal offline after fraudulent breach disclosures were published on the state's website, prompting a review of procedures to prevent abuse in the future. BleepingComputer · Jun 12, 2026 High
malware Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is a Rust binary built to… The Hacker News · Jun 12, 2026 Medium