threat-intel Rethinking MDR as Attackers and Defenders Embrace AI This article highlights a critical flaw in the current Managed Detection and Response (MDR) model, arguing that it’s no longer sufficient to address the rapidly evolving threat landscape driven by AI. The analysis reveal… The Hacker News · Jun 12, 2026 High GLaithreat intelligencemrd
data-breach Pharma giant Novo Nordisk discloses breach of clinical trials data Danish pharmaceutical giant Novo Nordisk, the world's largest producer of insulin, disclosed a data breach affecting patient information from some clinical trials. BleepingComputer · Jun 12, 2026 High
threat-intel LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution A critical vulnerability chain in LangGraph, an open-source AI agent framework, has been disclosed, allowing for remote code execution via SQL injection and unsafe deserialization. The flaws, affecting versions prior to… The Hacker News · Jun 12, 2026 Critical CVE-2025-67644CVE-2026-28277CVE-2026-27022USsql injectionremote code executionai agent
vulnerability Ivanti Sentry Exploitation Attempts Hitting Honeypots A recently patched vulnerability in Ivanti Sentry, CVE-2026-10520, has been observed attempting exploitation on honeypots, according to Ivanti and CISA. The flaw allows for remote code execution with root privileges via… SecurityWeek · Jun 12, 2026 High CVE-2026-10520USvulnerabilitycommand injectionroot privilege
vulnerability Chrome 149 Update Patches 28 Vulnerabilities The browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs. The post Chrome 149 Update Patches 28 Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 12, 2026 High
phishing INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator INTERPOL, in collaboration with authorities across 13 MENA countries, successfully dismantled the decade-long Sniper Dz phishing-as-a-service (PhaaS) platform, resulting in the arrest of its administrator, Guedz. The ope… The Hacker News · Jun 12, 2026 High ALAEDZphishing-as-a-servicecredential theftsocial engineering
Anthropic Disputes Fable 5 AI Jailbreak An AI hacker claims to have achieved a prompt-based jailbreak shortly after Fable 5’s launch, but Anthropic says it’s not a real jailbreak. The post Anthropic Disputes Fable 5 AI Jailbreak appeared first on SecurityWeek… SecurityWeek · Jun 12, 2026
vulnerability CISA orders feds to patch actively exploited Ivanti flaw by Sunday CISA has issued a Binding Operational Directive (BOD) 26-04, mandating that federal agencies patch an actively exploited vulnerability (CVE-2026-10520) in Ivanti Sentry security gateways within three days. This vulnerabi… BleepingComputer · Jun 12, 2026 Critical CVE-2026-10520patchingcisavulnerability
data-breach Over 73,000 French govt employees affected in Tchap messenger breach A breach of the French government’s Tchap messaging platform has affected over 73,000 employees within the public sector. The attackers exploited a compromised user account to access public chat room data, including name… BleepingComputer · Jun 12, 2026 High FRmessagingdata breachencryption
vulnerability Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters Oracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation. The post Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters appeared first on S… SecurityWeek · Jun 12, 2026 Critical CVE-2026-35273
ransomware Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs Europol, in collaboration with international law enforcement, successfully disrupted AudiA6, a cryptocurrency laundering service used extensively by ransomware gangs and cybercriminals. The operation, resulting in the ar… The Hacker News · Jun 12, 2026 High UKRUGEcryptocurrencyransomwaremoney laundering
threat-intel Phishing Attack Volume Down 20%, but Risk Still Rising The volume of phishing attacks has decreased by 20% across multiple industries, despite a shift towards more sophisticated attacks utilizing AI. Threat actors are prioritizing targeted campaigns with higher conversion ra… Dark Reading · Jun 12, 2026 High CAESAUphishingaicloud
Japanese energy firm loses drive with data of 10.9 million clients Kyushu Electric Power Co., Inc. has disclosed a physical security incident that affects private data of more than 10 million customers. BleepingComputer · Jun 11, 2026
threat-intel Maine breach portal abused to publish fake data breach disclosures A fraudulent data breach disclosure was falsely submitted to Maine’s official breach portal, attributed to VRChat, and subsequently published before verification. The fake notification detailed a supposed hack impacting… BleepingComputer · Jun 11, 2026 Medium USmisinformationdata breachfraudulent
vulnerability ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities The ShinyHunters extortion group exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft to gain unauthorized access to university systems, resulting in data theft and a demand for payment. Mandiant iden… The Hacker News · Jun 11, 2026 High CVE-2026-35273GBUSzero-dayexploitationuniversity
vulnerability Oracle mitigates PeopleSoft zero-day exploited in data theft attacks A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools has been exploited by the ShinyHunters ransomware gang to steal data from numerous organizations. Oracle has released mitigations, but t… BleepingComputer · Jun 11, 2026 Critical CVE-2026-35273zero-daydata theftpeoplesoft
vulnerability Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure A critical vulnerability (CVE-2026-10520) in Ivanti Sentry was exploited within 24 hours of its disclosure, highlighting the speed at which attackers can react to newly released vulnerabilities. The flaw, an OS command i… Dark Reading · Jun 11, 2026 Critical CVE-2026-10520CVE-2026-10523CVE-2026-1340vulnerabilitycommand injectionroot access
threat-intel A tale of two eras This article is a reflective piece by a cybersecurity analyst reminiscing about early technology and highlighting a critical shift in the threat landscape. The author uses a personal anecdote about a childhood discovery… Cisco Talos · Jun 11, 2026 High USaivulnerabilitycybersecurity
threat-intel New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets A research report highlighted vulnerabilities in OpenClaw, a popular self-hosted AI agent, revealing that attackers could trick the agent into running malicious code or leaking sensitive data by embedding instructions wi… The Hacker News · Jun 11, 2026 High USaiagentprompt injection
New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day after they published an exploit for Microsoft Defender. "This was an accident… The Hacker News · Jun 11, 2026 CVE-2026-45585