supply-chain Red Hat npm packages compromised to steal developer credentials A supply-chain attack targeting Red Hat npm packages resulted in the distribution of a new variant of the Shai-Hulud credential-stealing malware, dubbed 'Miasma'. The attackers compromised a Red Hat employee's GitHub acc… BleepingComputer · Jun 1, 2026 High USsupply chaincredential theftgithub
Spain arrests doxer leaking sensitive data of govt employees The Spanish National Police has arrested an individual for leaking sensitive information related to members of various key state organizations, including the National Cybersecurity Institute (INCIBE). BleepingComputer · Jun 1, 2026
threat-intel Anthropic to Open Mythos AI to EU's ENISA This article reports that Anthropic is granting access to its Mythos AI model to the European Union’s ENISA as part of the Project Glasswing initiative. Mythos, an AI model capable of autonomously discovering and exploit… Dark Reading · Jun 1, 2026 High EUUSaivulnerabilitycybersecurity
threat-intel Inspector general finds NIST mistakes have made vulnerability database ineffective A recent inspector general report has identified significant mismanagement and strategic failures within the National Institute of Standards and Technology (NIST)’s National Vulnerability Database (NVD), resulting in a m… The Record · Jun 1, 2026 High UNvulnerabilitybacklogmanagement
threat-intel Microsoft's Zero-Day Legal Threats Spark Backlash This article reports on Microsoft's controversial response to a security researcher, "Nightmare-Eclipse," who published several zero-day exploits. Microsoft initially threatened criminal charges against the researcher an… Dark Reading · Jun 1, 2026 High CVE-2026-33825zero-dayvulnerabilityresearcher
threat-intel NSA selects new leads for key cybersecurity posts The National Security Agency (NSA) has appointed new leadership for key cybersecurity divisions, aiming to stabilize operations following a period of significant upheaval. David Imbordino will serve as chief, with Holly… The Record · Jun 1, 2026 Low UNnsacybersecurityleadership
vulnerability WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites The security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations. The post WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites appeared fir… SecurityWeek · Jun 1, 2026 Medium CVE-2026-8732
Dashlane password manager users locked out by brute force attacks Multiple Dashlane users have been locked out of their accounts following brute-force attacks that attempted logins from distant locations and unknown devices. BleepingComputer · Jun 1, 2026 High
malware Dutch Police Dismantle Massive 17-Million-Device Botnet Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime. The post Dutch… SecurityWeek · Jun 1, 2026
supply-chain Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm A new supply chain attack, dubbed Miasma, has compromised Red Hat npm packages, utilizing a self-propagating worm to steal credentials and secrets from developer machines. The attack, leveraging techniques similar to the… The Hacker News · Jun 1, 2026 High USsupply chain attackcredential theftgithub actions
threat-intel Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts Hackers exploited Meta’s AI support bot on Instagram to gain unauthorized access to accounts, including those belonging to the Obama White House and the U.S. Space Force. The tactic involved tricking the bot into resetti… Krebs on Security · Jun 1, 2026 High IRaichatbotsocial engineering
malware WordPress malware campaign hides payloads in Steam profiles A WordPress malware campaign has infected nearly 2,000 websites by hiding command-and-control (C2) data within Steam Community profile comments. The attackers utilize invisible Unicode characters to encode malicious payl… BleepingComputer · Jun 1, 2026 High USwordpresssteemunicode
vulnerability Vulnerability Disclosure in the Age of AI New article: “ Responsible Disclosure in the Age of AI: A Call for Urgent Action ,” by Melissa Hathaway. Abstract: Artificial intelligence is fundamentally reshaping the balance between vulnerability discovery and remedi… Schneier on Security · Jun 1, 2026 Medium
vulnerability Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs Organizations are advised to patch CVE-2026-41089 as soon as possible, given its severity, the potential ongoing exploitation. The post Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs appeared first on S… SecurityWeek · Jun 1, 2026 Medium CVE-2026-41089
Microsoft investigates Office Apps, Teams file access issues Microsoft says an ongoing incident is preventing users of its Teams collaboration platform and free Office for the web cloud-based productivity suite from opening files. BleepingComputer · Jun 1, 2026
vulnerability Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit A vulnerability in Palo Alto Networks' PAN-OS GlobalProtect VPN technology, tracked as CVE-2026-0257, is currently being actively exploited. Attackers are leveraging a configuration flaw to bypass authentication and gain… Dark Reading · Jun 1, 2026 Critical CVE-2026-0257CVE-2025-0108USvpnauthenticationcookie
threat-intel Race Against Time: Why Faster Vulnerability Alerts Matter This article highlights the critical importance of rapid vulnerability alerts in cybersecurity, emphasizing the increasing speed at which vulnerabilities are being discovered and exploited. The average time to exploitati… BleepingComputer · Jun 1, 2026 High USvulnerabilityexploitationcybersecurity
threat-intel ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More This Hacker News recap details several ongoing cyber threats, including an active exploitation of a PAN-OS GlobalProtect authentication bypass vulnerability, a critical zero-day vulnerability in the Gogs Git service, and… The Hacker News · Jun 1, 2026 High CVE-2026-0257CVE-2026-8732CVE-2026-27771RUvulnerabilityauthenticationc2
Dragos Acquires xIoT Security Firm Phosphorus Dragos said customers will soon gain expanded asset visibility and integrated device intelligence, with automated remediation workflows and a unified platform experience to follow. The post Dragos Acquires xIoT Security… SecurityWeek · Jun 1, 2026
threat-intel Critical Windows Netlogon RCE flaw now exploited in attacks A critical Remote Code Execution (RCE) vulnerability (CVE-2026-41089) in Windows Netlogon is now being actively exploited in attacks, according to Belgium's national cybersecurity authority, the Centre for Cybersecurity… BleepingComputer · Jun 1, 2026 Critical CVE-2026-41089CVE-2026-45585CVE-2026-33825BErcenetlogonwindows