Russia seeks to label two anti-Kremlin hacker groups as ‘extremist’ The groups have previously claimed responsibility for cyberattacks targeting critical infrastructure and government institutions in Russia and Belarus. The Record · Jun 4, 2026
threat-intel Reporting from Vegas: Networking, AI, and good boys This Cisco Talos Threat Source newsletter highlights the ongoing challenges of managing data at scale in an AI-driven world, particularly during large technology conferences like Cisco Live. It details Talos’ expansion o… Cisco Talos · Jun 4, 2026 High USRUaithreat huntingc2
policy Supreme Court rules FCC fines punishing telecom giants for sharing location data were legal The Supreme Court has ruled in favor of the Federal Communications Commission (FCC), upholding its authority to impose significant fines on telecom giants like AT&T and Verizon for sharing consumer location data without… The Record · Jun 4, 2026 Medium USprivacydata-sharingregulation
vulnerability Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root. It is tracked as CVE-2026-20230, and proof-of-concept… The Hacker News · Jun 4, 2026 CVE-2026-20230CVE-2025-20309CVE-2026-20045
data-breach UN food agency discloses breach affecting 600,000 Gaza households The World Food Programme (WFP) has disclosed a breach of its self-registration application (SRA) used in Gaza, resulting in the theft of personal data from approximately 600,000 Palestinian households. This incident high… BleepingComputer · Jun 4, 2026 High PSgazadata breachhumanitarian
supply-chain New IronWorm malware hits 36 packages in npm supply-chain attack A new supply-chain attack leveraging the IronWorm malware has compromised 36 npm packages, targeting developers and CI environments with infostealer capabilities. The malware utilizes stolen credentials and a sophisticat… BleepingComputer · Jun 4, 2026 High supply chainnpmrust
threat-intel Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories A security researcher discovered a flaw in Anthropic's Claude Code GitHub Action that allowed attackers to take over vulnerable public repositories by exploiting a permissive trigger check and prompt injection techniques… The Hacker News · Jun 4, 2026 High prompt-injectiongithub-actionsai-security
threat-intel Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It The article highlights the increasing use of agentic AI in defense and intelligence networks, emphasizing the potential risks associated with its deployment. A recent incident involving Anthropic's Claude Mythos model de… The Hacker News · Jun 4, 2026 High aiagentic aidefense
threat-intel Offroad Emerges From Stealth With $7 Million to Tackle Enterprise Identity Risk Offroad, a new cybersecurity firm, has launched with $7 million in funding to address the growing risk of identity-related vulnerabilities in enterprise environments. The company utilizes AI-powered agents to proactively… SecurityWeek · Jun 4, 2026 Medium USILISoauthidentity riskai
vulnerability CISA directive for AI executive order to be released this week, Andersen says The binding operational directive will focus in part on “vulnerability alleviation and vulnerability management,” Andersen said in remarks delivered at the TechNet Cyber conference in Baltimore. The Record · Jun 4, 2026 Medium
Webinar Today: Third-Party Risk in Practice – Where Programs Break Down and How to Respond Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. The post Webinar Today: Third-Party Risk in Practice… SecurityWeek · Jun 4, 2026
Willow Raises $7 Million for Securing Autonomous AI Agents Willow (formerly Webrix) emerged from stealth mode with an access platform designed to secure enterprise AI agents. The post Willow Raises $7 Million for Securing Autonomous AI Agents appeared first on SecurityWeek . SecurityWeek · Jun 4, 2026
threat-intel Bugcrowd Launches EU Data Residency Option For Evolving Data Sovereignty Needs This article reports on Bugcrowd’s launch of a new Data Residency Option specifically tailored for organizations operating within or with business dealings in the European Union. The move addresses growing concerns about… Dark Reading · Jun 4, 2026 Medium USEUdata residencydata sovereigntyeu regulations
threat-intel Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook This article details a trend of underground forums sharing a tutorial designed to guide novice hackers through the process of identifying, exploiting, and monetizing vulnerabilities. The ‘Hercules’ thread, popular across… BleepingComputer · Jun 4, 2026 High USvulnerabilityexploitmonetization
threat-intel ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories This bulletin highlights several ongoing cyber threats, including a high-severity SSRF vulnerability in Cisco Unified Communications Manager, a large-scale spyware operation targeting Russian officials by foreign intelli… The Hacker News · Jun 4, 2026 High CVE-2026-20230CVE-2022-0492CVE-2019-5736RUIRUSssrfspywarekeylogger
UN food agency investigates breach exposing data of Gaza aid recipients In a message sent to aid recipients via Telegram over the weekend, the World Food Programme (WFP) said that "unauthorized parties" had accessed data stored in its self-registration application in Gaza. The Record · Jun 4, 2026
Microsoft blames unexpected Windows driver updates on caching issue On Wednesday, Microsoft fixed an issue that caused some Windows devices to install driver updates without notice despite policies configured to prevent auto-updates. BleepingComputer · Jun 4, 2026
threat-intel Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process A security researcher, Ammar Askar, released a GitHub token-stealing exploit for Microsoft's VS Code, citing frustration with the company's vulnerability disclosure process. This follows a recent breach of GitHub reposit… The Record · Jun 4, 2026 High githubvulnerabilitydisclosure
threat-intel Five Eyes warn Chinese spies are using job sites to recruit insiders The Five Eyes intelligence alliance has issued a joint warning about Chinese military intelligence services using online job platforms to recruit individuals with access to sensitive information. This tactic, described a… The Record · Jun 4, 2026 High CHAUCArecruitmentespionagecybersecurity
Gemini Voice Assistant Hijacked via Messaging Notifications Attackers could have triggered dangerous actions, including controlling smart home devices via Google Home and starting Zoom video calls. The post Gemini Voice Assistant Hijacked via Messaging Notifications appeared firs… SecurityWeek · Jun 4, 2026