data-breach Scope of Salesforce Attacks Expands as Icarus Leaks Data A series of attacks originating from the Icarus extortion group have expanded the scope of breaches affecting Salesforce customers. Initially targeting Klue’s OAuth tokens, attackers leveraged this access to steal custom… Dark Reading · Jun 23, 2026 High USsalesforceoauthdata breach
threat-intel Trump directs federal agencies to protect US data from quantum threats President Trump issued two executive orders focused on bolstering U.S. cybersecurity against future threats from quantum computing. One order prioritizes accelerating the development and practical application of quantum… The Record · Jun 23, 2026 Medium USUKquantum computingcryptographycybersecurity
threat-intel Scattered Spider Hackers Plead Guilty on Day 1 of Trial Two key members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, have pleaded guilty to criminal charges related to attacks against Transport for London and other organizations. The group, led by… Krebs on Security · Jun 23, 2026 High UKUSGBphishingransomwaresim swapping
threat-intel Compromise kids online safety bill unveiled by House leaders, with key omission A revised version of the Kids Online Safety Act (KOSA) has been unveiled by the House Energy and Commerce Committee, aiming for bipartisan support. However, a key element – a ‘duty of care’ provision requiring platforms… The Record · Jun 23, 2026 Medium USonline safetychildren's privacyai regulation
threat-intel Anthropic’s Fable 5 Model Jailbroken Within Days Anthropic’s Fable 5 model, designed as a safer alternative to their Mythos Preview, was quickly compromised by researchers. The model’s built-in safeguards against generating malicious code were bypassed within a short t… Schneier on Security · Jun 23, 2026 High aijailbreakmodel
phishing ISC Stormcast For Monday, June 22nd, 2026 https://isc.sans.edu/podcastdetail/9980, (Mon, Jun 22nd) The SANS Internet Storm Center's June 22nd, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observ… SANS Internet Storm Center · Jun 22, 2026 Medium phishingemailthreat
threat-intel French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation This article reports on a discussion at the G7 summit regarding the regulation of advanced artificial intelligence (AI) systems, particularly focusing on the U.S. government’s restriction on access to Anthropic’s latest… SecurityWeek · Jun 20, 2026 Medium FRUNCAaiartificial intelligenceregulation
threat-intel Stressors, AI Forcing Changes to Cybersecurity Teams This article reports on a recent survey highlighting the increasing difficulties faced by Chief Information Security Officers (CISOs) due to the proliferation of cyber threats, the complexities introduced by AI, and conc… Dark Reading · Jun 19, 2026 Medium aicybersecuritycios
threat-intel ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories This week’s ThreatDay Bulletin highlights several concerning security incidents, including browser extension abuse, macOS malware attacks, AI-powered malware delivery, and a global phishing campaign targeting travel book… The Hacker News · Jun 18, 2026 High CVE-2026-20127CVE-2026-49975USCNJPbrowser extensionsmacos malwareai abuse
data-breach Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks A recent breach at Klue, a market intelligence platform, allowed the "Icarus" threat actor to steal Salesforce CRM data from multiple organizations, triggering an ongoing extortion campaign. The attackers leveraged stole… BleepingComputer · Jun 18, 2026 High USoauthsalesforcedata theft
ransomware INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023 INC ransomware has grown into a significant RaaS threat, impacting over 830 organizations since August 2023. The group leverages a combination of established techniques, including credential dumping from Veeam backups an… The Hacker News · Jun 18, 2026 High CVE-2023-3519CVE-2025-5777CVE-2023-48788USransomware-as-a-servicecredential dumpinglateral movement
threat-intel ISC Stormcast For Thursday, June 18th, 2026 https://isc.sans.edu/podcastdetail/9978, (Thu, Jun 18th) The SANS Internet Storm Center's June 18th, 2026 Stormcast reported a heightened level of online threats and unusual network activity across various sectors. The broadcast highlighted several emerging trends, including i… SANS Internet Storm Center · Jun 18, 2026 Medium phishingdnsthreat-monitoring
ransomware INC Ransomware Thrives by Mastering the Basics The INC ransomware group has emerged as a significant threat, particularly thriving through a focus on established ransomware-as-a-service (RaaS) tactics and targeting sectors with high pressure to pay, such as healthcar… Dark Reading · Jun 17, 2026 High CVE-2025-5777CVE-2024-57727CVE-2023-3519UKraasransomwareextortion
threat-intel UK Social Media Ban for Minors Has Privacy Experts Worried The UK is implementing a ban on user-to-user social media platforms for individuals under 16, following similar legislation in Canada and Australia, driven by concerns about the impact of social media on young people. Th… Dark Reading · Jun 17, 2026 Medium UKCAAUsocial mediaage verificationprivacy
malware Fileless Phantom Stealer Targets Browser Credentials A new fileless malware, Phantom Stealer, is being deployed through targeted phishing campaigns against banks and high-value organizations. The malware focuses on stealing browser credentials and session cookies, utilizin… Dark Reading · Jun 16, 2026 High GBDEFRcredential theftbrowser securityfileless malware
threat-intel Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure The Athena coalition, comprised of numerous tech and fintech firms, has been established to proactively identify and mitigate vulnerabilities in open-source software (OSS) before public disclosure. This initiative addres… SecurityWeek · Jun 16, 2026 High ossvulnerabilityai
threat-intel Windows version of SprySOCKS Linux malware used to attack govt orgs Windows variants of the SprySOCKS Linux malware, previously linked to the Earth Lusca threat actor, have been used to target government organizations in Taiwan, Thailand, Pakistan, and Honduras. These variants offer adva… BleepingComputer · Jun 16, 2026 High CVE-2023-24932TWTHPKlinuxstealthbackdoor
threat-intel North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels North Korean threat actors, operating under the UNK_DeadDrop campaign, are employing a sophisticated phishing technique targeting developers across numerous sectors, including finance and cryptocurrency, using malicious… The Hacker News · Jun 15, 2026 High USGBAUdevelopergithubvscode
threat-intel Most CISOs Report Pressure to Bury Bad Security News This Dark Reading article examines the significant pressure faced by CISOs to suppress or delay disclosing security findings, particularly regarding vulnerabilities and breaches. The primary drivers of this pressure stem… Dark Reading · Jun 15, 2026 Medium cisospressuredisclosure
threat-intel Ex-school district employee jailed for hacks on former employer A former IT employee, Ezekiel Dean Potter, was sentenced to prison for a prolonged cyberattack against the Saydel Community School District. Potter exploited his previous access to disrupt operations, steal data, and cau… BleepingComputer · Jun 13, 2026 High UScyberattackdata-breachaccount-compromise