threat-intel In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine This week’s cybersecurity news includes allegations of cover-ups by IBM and AT&T regarding foreign government-linked hacks, a data breach impacting the University of Oxford’s CareerConnect platform, and layoffs within Go… SecurityWeek · Jun 12, 2026 High CVE-2026-42271SOUNEUdata breachcyberattackddos
data-breach South Korea hits Coupang with record $409 million fine over data breach South Korea’s data protection regulator, the PIPC, has levied a record $409 million fine against Coupang, the country’s largest online retailer, following a significant data breach impacting tens of millions of customers… The Record · Jun 12, 2026 High KRdata breachauthenticationcustomer data
threat-intel ISC Stormcast For Wednesday, June 10th, 2026 https://isc.sans.edu/podcastdetail/9966, (Wed, Jun 10th) The SANS Internet Storm Center's Stormcast for June 10th, 2026 highlighted several emerging threats and ongoing activity across the internet landscape. The broadcast detailed observed trends in malicious campaigns, vulne… SANS Internet Storm Center · Jun 10, 2026 Medium stormcastthreat-intelligencephishing
vulnerability Critical Everest Forms Pro flaw exploited to take over WordPress sites A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin is being actively exploited by attackers to gain complete control over affected websites. This flaw allows for arbitrary code execution,… BleepingComputer · Jun 6, 2026 Critical CVE-2026-3300wordpresspluginvulnerability
ransomware Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin has been exploited by threat actors, allowing for remote code execution and potential site compromise. Attackers have been actively targe… The Hacker News · Jun 5, 2026 Critical CVE-2026-3300MDwordpressvulnerabilityremote code execution
threat-intel Credit card theft campaign abuses Stripe to host stolen payment info A Magecart campaign is exploiting Stripe's infrastructure to steal credit card data from online stores. The attackers leverage Google Tag Manager to deliver the malicious code, bypassing standard security measures. This… BleepingComputer · Jun 4, 2026 High magecartcredit card theftstripe
threat-intel Beyond Assume-Breach: How AI-Native Security Will Reshape Enterprise Defense This Dark Reading article discusses the evolving landscape of enterprise security, predicting a shift towards AI-native defenses driven by dynamic threats and increasing complexity. The article highlights the move away f… Dark Reading · Jun 2, 2026 High aimicrospheressecurity fabric
vulnerability Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts A critical security flaw (CVE-2026-8732) in the WP Maps Pro WordPress plugin has been actively exploited to create administrator accounts on vulnerable websites. The vulnerability stems from a flaw in the plugin's tempor… The Hacker News · Jun 1, 2026 Critical CVE-2026-8732wordpresspluginvulnerability
threat-intel Why Chargebacks are Just One Piece of the Fraud Puzzle This BleepingComputer article discusses the limitations of solely relying on chargeback rates to measure fraud performance. It highlights that focusing solely on chargebacks obscures a broader range of fraud impacts, inc… BleepingComputer · May 22, 2026 High account takeoverfraud detectionchargebacks
data-breach Ukraine probes teen suspect in cyber theft scheme targeting California online shoppers Ukrainian authorities are investigating an 18-year-old suspect linked to a cybercrime operation targeting California online shoppers. The scheme involved compromising nearly 30,000 customer accounts of a U.S.-based retai… The Record · May 20, 2026 High UKcybercrimedata-theftonline-shopping
threat-intel [GUEST DIARY] Tearing apart website fraud to see how it works., (Wed, May 13th) This article, a guest diary by an ISC intern, details an investigation into a fraudulent marketplace operation. The author discovered a website using SEO poisoning to lure victims into purchasing goods from a fake market… SANS Internet Storm Center · May 13, 2026 High INseo poisoningfraudmarketplace
threat-intel Websites with an undefined trust level: avoiding the trap This Securelist article discusses the growing threat of websites with an "undefined trust level," which are not traditional phishing sites but still pose significant risks to users. These sites, often mimicking legitimat… Securelist · May 6, 2026 Medium AFLARUscamfraudonline scams