threat-intel ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More This Hacker News recap details several ongoing cyber threats, including an active exploitation of a PAN-OS GlobalProtect authentication bypass vulnerability, a critical zero-day vulnerability in the Gogs Git service, and… The Hacker News · Jun 1, 2026 High CVE-2026-0257CVE-2026-8732CVE-2026-27771RUvulnerabilityauthenticationc2
Dragos Acquires xIoT Security Firm Phosphorus Dragos said customers will soon gain expanded asset visibility and integrated device intelligence, with automated remediation workflows and a unified platform experience to follow. The post Dragos Acquires xIoT Security… SecurityWeek · Jun 1, 2026
threat-intel Critical Windows Netlogon RCE flaw now exploited in attacks A critical Remote Code Execution (RCE) vulnerability (CVE-2026-41089) in Windows Netlogon is now being actively exploited in attacks, according to Belgium's national cybersecurity authority, the Centre for Cybersecurity… BleepingComputer · Jun 1, 2026 Critical CVE-2026-41089CVE-2026-45585CVE-2026-33825BErcenetlogonwindows
threat-intel Microsoft says it will not pursue security researchers after zero-day backlash Microsoft retracted a controversial blog post condemning security researchers who disclose zero-day vulnerabilities, stating it has no intention to pursue legal action against them. The initial statement, perceived as a… The Record · Jun 1, 2026 Medium UKzero-dayvulnerabilityresponsible disclosure
Webinar tomorrow: From alert to resolution in network incident response Network incidents are often detected quickly, but investigations and coordination can delay resolution. Join our webinar tomorrow to learn how automation and AI-assisted workflows can help IT teams accelerate incident re… BleepingComputer · Jun 1, 2026
threat-intel China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan A new cyber espionage campaign, dubbed Operation Dragon Weave, is targeting government, research, and financial institutions in the Czech Republic and Taiwan using spear-phishing emails and a Rust-based loader to deploy… The Hacker News · Jun 1, 2026 High CZTWINspear-phishingc2azure
threat-intel As the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge Caution This article reports on the U.S. Department of Defense's push to integrate artificial intelligence into military operations, particularly within the Special Operations Command, while facing concerns from tech companies a… SecurityWeek · Jun 1, 2026 Medium UNartificial intelligenceaimilitary
Microsoft fixes outage affecting MFA setup, MySignIn service Microsoft is working to address an ongoing incident preventing customers from setting up multi-factor authentication (MFA) or accessing the My Sign-Ins platform. BleepingComputer · Jun 1, 2026
Microsoft confirms outage affecting MFA, My Sign-Ins platform Microsoft is working to address an ongoing incident preventing customers from setting up multi-factor authentication (MFA) or accessing the My Sign-Ins platform. BleepingComputer · Jun 1, 2026
threat-intel The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools This article discusses the evolution of cybersecurity solutions for Managed Service Providers (MSPs), highlighting the shift from ‘vCISO’ platforms to ‘Security Growth Platforms’. The traditional vCISO tools were designe… The Hacker News · Jun 1, 2026 Medium mspcybersecuritysmb
vulnerability 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access proof-of-concept (PoC) exploit code has been released for the CIFSwitch flaw, which allows low-privileged users to escalate to root on vulnerable Linux systems. The post 19-Year-Old Linux Kernel Vulnerability Exposes Sys… SecurityWeek · Jun 1, 2026 Medium
Microsoft fixes KB5089549 Windows security update install issues Microsoft has resolved a known issue causing installation failures and 0x800f0922 errors when deploying the May 2026 Windows 11 security update (KB5089549). BleepingComputer · Jun 1, 2026
threat-intel Containers on fire: from container escapes to supply chain attacks This Securelist article examines the evolving threat landscape targeting container environments, highlighting key attack vectors used by groups like TeamPCP. The analysis focuses on vulnerabilities, supply chain attacks… Securelist · Jun 1, 2026 High CVE-2019-5736CVE-2022-0492CVE-2024-21626UScontainerskubernetessupply chain
vulnerability Recent Palo Alto Networks Vulnerability Exploited for Weeks Hackers began exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS, four days after public disclosure. The post Recent Palo Alto Networks Vulnerability Exploited for Weeks appeared first on Sec… SecurityWeek · Jun 1, 2026 Medium CVE-2026-0257
supply-chain OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack A supply chain attack targeting OpenAI Codex developers has been discovered through a malicious npm package named ‘codexui-android’. The package, developed by ‘friuns’ (Igor Levochkin) and promoted by ‘BrutalStrike’, sil… The Hacker News · Jun 1, 2026 High USsupply chainauthenticationtokens
vulnerability Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts A critical security flaw (CVE-2026-8732) in the WP Maps Pro WordPress plugin has been actively exploited to create administrator accounts on vulnerable websites. The vulnerability stems from a flaw in the plugin's tempor… The Hacker News · Jun 1, 2026 Critical CVE-2026-8732wordpresspluginvulnerability
threat-intel OpenClaw: risks for agent users and how to mitigate them This Securelist article highlights the significant security risks associated with OpenClaw, a popular AI agent ecosystem used globally for automating tasks. The system’s widespread adoption, combined with a large marketp… Securelist · Jun 1, 2026 High USai agentsautomationsupply chain
phishing ISC Stormcast For Monday, June 1st, 2026 https://isc.sans.edu/podcastdetail/9952, (Mon, Jun 1st) The SANS Internet Storm Center's June 1st, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observe… SANS Internet Storm Center · Jun 1, 2026 Medium phishingemailthreat intelligence
malware Unidentified RAT pushes NetSupport RAT, (Mon, Jun 1st) Introduction SANS Internet Storm Center · Jun 1, 2026 Medium
Unknown hacker group targeted Russian maritime universities, diplomats for nearly two years More than half of the attacks observed over the past year targeted educational institutions, particularly maritime universities and schools that train personnel for Russia's shipping, inland waterway and fishing industri… The Record · May 31, 2026