threat-intel ISC Stormcast For Wednesday, June 17th, 2026 https://isc.sans.edu/podcastdetail/9976, (Wed, Jun 17th) The SANS Internet Storm Center's Stormcast for June 17th, 2026 highlighted a concerning increase in several active threats across the internet landscape. The broadcast detailed heightened activity related to phishing cam… SANS Internet Storm Center · Jun 17, 2026 Medium phishingvulnerabilitythreat intelligence
threat-intel AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask This SecurityWeek article explores the current landscape of artificial intelligence (AI) within cybersecurity, focusing on its diverse applications and potential risks. It examines key AI technologies like generative AI… SecurityWeek · Jun 16, 2026 Medium aigenerative-aimachine-learning
threat-intel Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive A recent study by Spur Intelligence found that anonymized infrastructure, primarily through VPNs and residential proxies, is now a dominant factor in nearly every security incident. Despite the abundance of IP data avail… The Hacker News · Jun 16, 2026 High USanonymizationip intelligencevpn
threat-intel Windows version of SprySOCKS Linux malware used to attack govt orgs Windows variants of the SprySOCKS Linux malware, previously linked to the Earth Lusca threat actor, have been used to target government organizations in Taiwan, Thailand, Pakistan, and Honduras. These variants offer adva… BleepingComputer · Jun 16, 2026 High CVE-2023-24932TWTHPKlinuxstealthbackdoor
vulnerability Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw A vulnerability (CVE-2026-20262) in Cisco Catalyst SD-WAN Manager has been actively exploited in the wild, allowing authenticated attackers to overwrite files on affected systems. The flaw stems from inadequate input val… The Hacker News · Jun 16, 2026 High CVE-2026-20262CVE-2026-20245CVE-2026-20182USsd-wancvefile-upload
threat-intel HTTP/2 Bomb Attacks Put Telcos, Healthcare Orgs at Risk This article reports on the ‘HTTP/2 Bomb’ vulnerability, a denial-of-service exploit leveraging features within the HTTP/2 protocol to amplify junk traffic and cause widespread disruptions. The vulnerability affects a si… Dark Reading · Jun 15, 2026 High CVE-2026-49975UShttp2ddosamplification
vulnerability Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks Cisco has released a security update to address a critical zero-day vulnerability (CVE-2026-20262) in its SD-WAN vManage software, allowing attackers to gain root privileges. The flaw stems from improper input validation… BleepingComputer · Jun 15, 2026 Critical CVE-2026-20262CVE-2026-20133CVE-2026-20128zero-dayroot privilegefile upload
threat-intel The Beginning of the End of Social Engineering This article discusses a significant shift in cybersecurity driven by the integration of AI-native operating systems, particularly Google's Gemini and Apple's Apple Intelligence. Operating systems are evolving to activel… Dark Reading · Jun 15, 2026 High USaisocial engineeringauthentication
threat-intel Finland brings charges against cargo ship officers for cutting submarine cables Finnish authorities have brought charges against the captain and bosun of the cargo ship Fitburg for damaging several submarine cables in the Baltic Sea. The incident occurred while the ship was transporting sanctioned s… The Record · Jun 15, 2026 Medium FIRUISsubmarine cablessabotagebaltic sea
phishing Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts A coordinated phishing campaign, spearheaded by the now-disrupted Sniper Dz platform, targeted users in the Middle East and North Africa (MENA) through deceptive Facebook offers. The campaign leveraged browser notificati… The Hacker News · Jun 15, 2026 High DZALAEphishingsocial engineeringbrowser notifications
phishing Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing Google has filed a lawsuit against a Chinese cybercrime network, Outsider, for using its Gemini AI agent to conduct massive smishing attacks targeting Americans. The network operates a phishing-as-a-service (PhaaS) platf… The Hacker News · Jun 12, 2026 High CHUSaiphishingsmishing
threat-intel Major US surveillance program poised to lapse after legislative deadlock This article reports on a looming lapse in the US surveillance program, Section 702 of the FISA, due to legislative deadlock in Congress. The program, which allows intelligence agencies to collect communications of forei… The Record · Jun 12, 2026 High USIRCHfisasurveillanceintelligence
threat-intel Iranian Cyber Group Handala Claims Cal Water Hack The Iranian cyber threat actor Handala has claimed responsibility for a data breach targeting California Water Service (Cal Water), resulting in the theft of 5GB of data including customer information and credentials. Th… SecurityWeek · Jun 12, 2026 High USIRirandata breachcyber espionage
vulnerability Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure A critical vulnerability (CVE-2026-10520) in Ivanti Sentry was exploited within 24 hours of its disclosure, highlighting the speed at which attackers can react to newly released vulnerabilities. The flaw, an OS command i… Dark Reading · Jun 11, 2026 Critical CVE-2026-10520CVE-2026-10523CVE-2026-1340vulnerabilitycommand injectionroot access
threat-intel A tale of two eras This article is a reflective piece by a cybersecurity analyst reminiscing about early technology and highlighting a critical shift in the threat landscape. The author uses a personal anecdote about a childhood discovery… Cisco Talos · Jun 11, 2026 High USaivulnerabilitycybersecurity
threat-intel China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance A China-linked botnet, dubbed JDY, has significantly expanded its operations, now comprising over 1,500 compromised SOHO and IoT devices. Initially a component of the KV-botnet, the JDY botnet is being used for large-sca… The Hacker News · Jun 10, 2026 High CVE-2026-35616USBRDEiotreconnaissancebotnet
threat-intel UK weakens proposed telecoms defenses against Chinese hackers after industry pushback The UK government has weakened proposed cybersecurity protections for its telecoms networks in response to pushback from telecom companies regarding the cost and practicality of implementing measures designed to counter… The Record · Jun 9, 2026 High UKCHespionagetelecomscybersecurity
threat-intel CISA to transform how it assesses cyber vulnerabilities and risks, Andersen says CISA is undergoing a significant transformation in its approach to cybersecurity vulnerability assessment, shifting from a blanket patching strategy to a risk-based prioritization model. This change, driven by increasing… The Record · Jun 9, 2026 Medium risk-basedvulnerability managementcybersecurity
threat-intel WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine A vulnerability in WinRAR, first identified in July 2025, is being exploited by Russia-aligned cyber groups to deploy malware targeting Ukrainian organizations. The attackers, including Earth Dahu and SHADOW-EARTH-066, a… The Hacker News · Jun 9, 2026 High CVE-2025-8088RUUAwinrarexploitukraine
threat-intel The Hidden Security Risk in Modern Networks: The Work Between Tools This article highlights a critical operational challenge facing modern network security teams: the ‘work between tools.’ Despite advancements in technology and AI, organizations struggle with fragmented workflows when re… The Hacker News · Jun 9, 2026 Medium workflowautomationalerting