ransomware The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm The Gentlemen ransomware group, initially operating as the affiliate-focused Phantom Mantis, has evolved into an independent RaaS operation led by the cybercriminal LARVA-368 (aka hastalamuerte). The group, responsible… The Hacker News · Jun 11, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073RUTHUKransomware-as-a-servicedouble extortionaffiliate program
Cyber Force not included in Senate defense policy roadmap An amendment by Sen. Kirsten Gillibrand (D-NY) to the chamber’s fiscal 2027 national defense authorization bill that would have created the digital-focused service was defeated 14-13 when the Senate Armed Services Commit… The Record · Jun 11, 2026 High
ransomware Authorities dismantle 'AudiA6' ransomware crypto-laundering service Law enforcement agencies have successfully dismantled the ‘AudiA6’ cryptocurrency service, which was used to launder over $380 million generated from ransomware attacks and other cybercriminal activities. The operation,… BleepingComputer · Jun 11, 2026 High POUKGEcryptocurrencyransomwaremoney laundering
ransomware Silent Ransom Group: what you need to know The Silent Ransom Group is employing a novel and highly disruptive extortion tactic, shifting away from purely digital attacks. They are proactively contacting victims' employees via phone, impersonating IT support, and… Graham Cluley · Jun 11, 2026 High ransomwaresocial-engineeringusb-drive
threat-intel British high school sends students home following cyberattack Great Marlow School in Buckinghamshire, England, experienced a cybersecurity incident that forced the closure of the school for a second day, impacting students and staff. The incident, potentially linked to ransomware a… The Record · Jun 11, 2026 Medium UKUScyberattackschoolransomware
Hacker linked to Void Blizzard faces charges over cyberespionage campaign Denis Obrezko, 36, made his initial appearance in federal court in Boston on Tuesday after being transferred to U.S. custody from Thailand, where he was arrested last November. The Record · Jun 11, 2026
threat-intel Segmentation Works for OT If Operators Are Paying Attention This Dark Reading article highlights the ongoing challenges of operational technology (OT) security, particularly concerning network segmentation. Despite the widely recommended practice of isolating systems to limit dam… Dark Reading · Jun 11, 2026 High ot securitynetwork segmentationcybersecurity
threat-intel Why AI-driven threats are exposing the limits of MSP security stacks This article highlights how artificial intelligence (AI) is dramatically accelerating the pace and scale of cyberattacks, exposing the vulnerabilities of fragmented security stacks, particularly for Managed Service Provi… BleepingComputer · Jun 11, 2026 High USaiautomationmsps
vulnerability Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks Oracle has released a patch for CVE-2026-35273, but it has not said whether it’s a zero-day exploited in ShinyHunters attacks. The post Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks appeared… SecurityWeek · Jun 11, 2026 Critical CVE-2026-35273
University of Nottingham confirms cyber incident as Shiny Hunters group claims data theft According to the university’s statement, it is still working to understand what data has been accessed and said it had already directly contacted affected students and alumni, potentially including those in its foreign c… The Record · Jun 11, 2026
threat-intel Alert Fatigue Is Becoming a Security Threat of Its Own This article highlights the growing threat of alert fatigue within Security Operations Centers (SOCs). The overwhelming volume of alerts generated by security tools, often lacking context and prioritization, is leading t… SecurityWeek · Jun 11, 2026 High alert fatiguesocai
Cybersecurity Stars Awards 2026: Winners Announced Across 95 Categories Most good security work is invisible by design. Today is the exception. The 2026 Cybersecurity Stars Awards winners are announced across 95 subcategories in four main award categories. The reason is simple. Cybersecurity… The Hacker News · Jun 11, 2026
threat-intel ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories This week’s threat intelligence bulletin highlights several concerning developments, including a large-scale leak of identity records facilitated by infostealers, the emergence of a sophisticated MaaS RAT named SilabRAT… The Hacker News · Jun 11, 2026 High CVE-2026-49494USCHNOinfostealersmaas ratcredential theft
threat-intel CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk CISA has issued Binding Operational Directive 26-04, requiring federal agencies to prioritize patching security vulnerabilities based on risk, building upon previous efforts established in 2021. This directive focuses on… SecurityWeek · Jun 11, 2026 High vulnerabilitypatchingrisk
malware OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month The OnyxC2 stealer, offered as a "Malware-as-a-Service" (MaaS) product for $250-$500 per month, is a sophisticated tool designed for enterprise-level credential theft. Developed by BlackFog, it boasts a wide range of tar… SecurityWeek · Jun 11, 2026 High USstealercredential theftmalware-as-a-service
data-breach Coupang hit with record $409 million data breach fine in Korea Coupang, a major South Korean e-commerce company, has been hit with a record $409 million fine by the Personal Information Protection Commission (PIPC) due to a massive data breach affecting over 37 million customers. Th… BleepingComputer · Jun 11, 2026 High SOCHdata breachauthenticationdata security
CISA tells govt agencies to patch critical exploited flaws in 3 days The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced a new Binding Operational Directive, 26-04, that prioritizes security updates for Federal Civilian Executive Branch (FCEB) agencies. BleepingComputer · Jun 11, 2026
vulnerability Brickcom Cameras This CISA advisory details a critical vulnerability in Brickcom cameras (Cube, Dome, Bullet, and Box models, version 3.2.3.5.6) that allows unauthenticated remote attackers to access live video feeds and retrieve sensiti… CISA Advisories · Jun 11, 2026 Critical CVE-2026-50245CVE-2026-50005default credentialsonvifremote access
threat-intel Yarbo Android/iOS Mobile Application and Cloud Infrastructure A CISA advisory details a vulnerability in the Yarbo Android/iOS Mobile Application and Cloud Infrastructure, specifically related to hard-coded MQTT credentials. The application contains credentials that allow unauthori… CISA Advisories · Jun 11, 2026 High CVE-2026-10557CVE-2026-7368WOmqttcredentialsrobotics
threat-intel Naxclow IoT Platform This CISA advisory details a critical vulnerability in the Naxclow IoT Platform, specifically affecting versions of the Smart Doorbell X3, X Smart Home, V720, and ix cam devices. The flaw allows an attacker to impersonat… CISA Advisories · Jun 11, 2026 Critical CVE-2026-42947CVE-2026-50108CVE-2026-50101USiotcredential theftauthentication