threat-intel Exposed Fuel Tank Gauges Under Attack in the US Internet-exposed fuel tank gauges in the United States are being targeted by cyberattacks, posing a significant risk to gas stations and industrial facilities. The Cybersecurity and Infrastructure Security Agency (CISA)… Dark Reading · Jun 5, 2026 High USCAAUindustrial control systemscybersecuritytank gauges
apt Chinese APT deploys new malware to keep access to hacked networks A Chinese Advanced Persistent Threat (APT) group, tracked as UNC5221 (VerdantBamboo), has been conducting a prolonged espionage campaign targeting organizations in the United States, primarily leveraging the Brickstorm b… BleepingComputer · Jun 5, 2026 High CNespionagebackdoorpersistence
supply-chain IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks A sophisticated supply chain attack targeting the npm ecosystem has resulted in the deployment of both IronWorm, a Rust-based information stealer with self-replicating capabilities, and a new variant of the Miasma worm.… The Hacker News · Jun 5, 2026 High USsupply-chainnpmrust
policy Dark web Nemesis Market vendor gets 26 years for selling drugs A California man was sentenced to more than 26 years in federal prison for trafficking fentanyl and methamphetamine through Nemesis Market, one of the world's largest dark web marketplaces. BleepingComputer · Jun 5, 2026
threat-intel Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 A joint bulletin from the FBI, MI5, ASIO, CSIS, and NZSIS warns of a Chinese intelligence operation targeting Western professionals via LinkedIn and other job platforms. The operation involves posing as recruitment firms… Graham Cluley · Jun 5, 2026 High CHUNAUrecruitmentintelligencelinkedin
threat-intel OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds This article discusses the launch of CVE Lite CLI, an open-source command-line security scanner developed by Sonu Kapoor to address the challenges of managing vulnerabilities within JavaScript and Typescript projects usi… SecurityWeek · Jun 5, 2026 Medium dependency-scanningvulnerabilityjavascript
malware Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps Arabic-speaking users have emerged as the target of a new Android spyware codenamed Asin, according to findings from ESET. The Slovakian cybersecurity company said it first detected the malware spread via multiple campai… The Hacker News · Jun 5, 2026 High
threat-intel Over 900 US gas station tank gauge systems exposed to attacks Over 900 US gas station tank gauge systems are vulnerable to ongoing attacks due to internet exposure and security flaws. Threat actors are exploiting these systems to potentially alter settings and cause operational dis… BleepingComputer · Jun 5, 2026 High USatgindustrial control systemscybersecurity
threat-intel Adaptive, Agentic AI Worms Loom as Next Enterprise Threat This article discusses the emerging threat of adaptive, agentic AI worms, which are designed to autonomously seek out and exploit vulnerabilities in systems, similar to traditional worms but with the added capability of… Dark Reading · Jun 5, 2026 High CAUSaiwormadaptive
threat-intel Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 Palo Alto Networks Unit 42 has identified active exploitation of CVE-2026-0257, a PAN-OS vulnerability related to GlobalProtect authentication, by an unidentified threat actor. The vulnerability allows unauthorized VPN c… Palo Alto Unit 42 · Jun 5, 2026 High CVE-2026-0257vpnauthenticationvulnerability
threat-intel What 2026 DBIR Confirms: Attacks Are Living in the Browser The 2026 Verizon DBIR highlights a significant shift in cyberattacks, with a growing reliance on browser-based activities, particularly the unauthorized use of AI tools like ChatGPT and Gemini. Employees are increasingly… BleepingComputer · Jun 5, 2026 High USbrowseraicredential theft
threat-intel EU unveils tech sovereignty package to cut reliance on US, Chinese suppliers The European Commission has unveiled a comprehensive tech sovereignty package designed to reduce the EU’s reliance on foreign technology suppliers, particularly the US and China. This initiative includes legislation focu… The Record · Jun 5, 2026 Medium EUUSCHtech sovereigntyeuropean unionsemiconductors
malware AI Worm Researchers have developed a functional prototype of an AI-powered internet worm, leveraging a large language model (LLM) within the worm itself. The worm exploits compromised systems to host and execute the LLM, mirrori… Schneier on Security · Jun 5, 2026 High aiwormllm
threat-intel In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA This week’s cybersecurity news highlights a range of threats, including AI-powered attacks targeting computing power, ongoing Grandoreiro banking trojan campaigns, and a self-propagating ransomware group utilizing obfusc… SecurityWeek · Jun 5, 2026 High IRUSairansomwaresupply chain
threat-intel Trump AI Order Seeks Voluntary Frontier Model Testing This executive order from the Trump administration aims to bolster federal cybersecurity and prepare for the risks associated with frontier AI models like Anthropic’s Claude Mythos. The order establishes a voluntary fram… Dark Reading · Jun 5, 2026 Medium aicybersecurityfrontier models
threat-intel New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework A new threat cluster, OP-512, is targeting Microsoft IIS servers with a custom web shell framework, exhibiting sophisticated evasion techniques and centralized management capabilities. ReliaQuest has linked the activity… The Hacker News · Jun 5, 2026 High CNiisweb shellespionage
Hackers Leak DentaQuest Information Impacting 2.6 Million The ShinyHunters extortion group leaked roughly 234 GB of data allegedly stolen from the dental benefits administrator. The post Hackers Leak DentaQuest Information Impacting 2.6 Million appeared first on SecurityWeek . SecurityWeek · Jun 5, 2026
threat-intel Only 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to Deliver This Hacker News article analyzes the underwhelming adoption of AI within Security Operations Centers (SOCs) based on the SOC-CMM 2026 Maturity Report. Despite significant investment in AI-powered security tools, only a… The Hacker News · Jun 5, 2026 Medium aisocmaturity
vulnerability Chrome 149 Patches 429 Vulnerabilities Over 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws. The post Chrome 149 Patches 429 Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 5, 2026 High CVE-2026-10881CVE-2026-10882CVE-2026-10883
threat-intel Industry Reactions to New Trump AI Cybersecurity Executive Order: Feedback Friday This article reports on President Trump’s new executive order establishing a voluntary framework for assessing the cybersecurity risks of advanced AI models before their public release. The order aims to bolster national… SecurityWeek · Jun 5, 2026 Medium USaicybersecuritynational security