threat-intel Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat This article details the unconventional career path of Chris Thompson, a former IBM X-Force Red head and now CEO of RemoteThreat, tracing his journey from a teenage game hacker to a respected security professional. Thomp… SecurityWeek · Jun 30, 2026 Medium UKCAhackerred teamingai
Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History The ruling was made in the case of a bank robber whose identity was discovered through a geofence warrant. The post Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History appear… SecurityWeek · Jun 30, 2026
vulnerability Exploitation of Recent Oracle E-Business Suite Vulnerability Begins The critical-severity defect allows unauthenticated attackers to take over the E-Business Suite’s Payments product. The post Exploitation of Recent Oracle E-Business Suite Vulnerability Begins appeared first on SecurityW… SecurityWeek · Jun 30, 2026 Medium CVE-2026-46817
threat-intel The AI Token Costs That Can Break Cybersecurity This article highlights a growing concern within the cybersecurity industry: the unexpectedly high costs associated with utilizing AI-powered security platforms, particularly those leveraging generative and agentic AI mo… SecurityWeek · Jun 30, 2026 High aitokenizationcost
data-breach Nissan Employee Data Breached in Oracle PeopleSoft Hack Only a handful of the 100 organizations targeted in the PeopleSoft campaign have been confirmed. The post Nissan Employee Data Breached in Oracle PeopleSoft Hack appeared first on SecurityWeek . SecurityWeek · Jun 30, 2026 High CVE-2026-35273
vulnerability Critical SimpleHelp Vulnerability Exploited for Malware Delivery A critical vulnerability (CVE-2026-48558) in SimpleHelp RMM software allowed unauthorized access and subsequent malware deployment. The flaw, related to OpenID Connect authentication, enabled attackers to gain full techn… SecurityWeek · Jun 30, 2026 Critical CVE-2026-48558USoidcauthenticationmalware
Quantifind Raises $200 Million for AI-Native Risk Intelligence Quantifind will accelerate international expansion and extend its platform’s localized risk intelligence capabilities. The post Quantifind Raises $200 Million for AI-Native Risk Intelligence appeared first on SecurityWee… SecurityWeek · Jun 30, 2026
vulnerability New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking CISA has published an advisory to inform organizations about three vulnerabilities found by a researcher in Daktronics controllers. The post New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking appe… SecurityWeek · Jun 30, 2026
WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy An optional ‘username key’ adds another layer by requiring a secondary credential before someone can message users. The post WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy appeared first on Securit… SecurityWeek · Jun 29, 2026
New Attack Abuses Claude Code and Harmless-Looking Repositories to Hijack Developer Machines Indirect prompts hidden in a repository can lead to Claude Code spawning a reverse shell on the developer’s machine. The post New Attack Abuses Claude Code and Harmless-Looking Repositories to Hijack Developer Machines a… SecurityWeek · Jun 29, 2026
Straiker Raises $64 Million for AI Security Platform The startup’s platform can identify AI agents and provide visibility into their access, behavior, and risks. The post Straiker Raises $64 Million for AI Security Platform appeared first on SecurityWeek . SecurityWeek · Jun 29, 2026
Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack The ShinyHunters extortion group claims to have stolen 3.1 TB of data from the organization. The post Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack appeared first on SecurityWeek . SecurityWeek · Jun 29, 2026 CVE-2026-35273
vulnerability ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access A critical vulnerability, dubbed ‘DirtyClone,’ has been identified in the Linux kernel, allowing local users to gain root access. This flaw, similar to previous ‘DirtyFrag’ and ‘Fragnesia’ vulnerabilities, stems from how… SecurityWeek · Jun 29, 2026 Critical CVE-2026-43503CVE-2026-43284CVE-2026-43500linuxkernelroot
threat-intel OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review This article reports on a significant shift in the release strategy of AI models ChatGPT and Anthropic’s Claude, driven by a government-led cybersecurity review initiated by the Trump administration. OpenAI is restrictin… SecurityWeek · Jun 29, 2026 High USaicybersecuritygovernment
US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve UNC5792 and UNC4221 have been targeting US government officials, military leaders, and allied personnel. The post US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve appeared first on S… SecurityWeek · Jun 29, 2026
OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI The company says Sol matches competing systems like Mythos Preview while using only a third of the output tokens. The post OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI appeared first on SecurityWeek . SecurityWeek · Jun 29, 2026
Chinese Framework Powers 200,000 Scam Sites Threat actors are selling investment scam templates created using the legitimate DCloud Uni-App toolkit. The post Chinese Framework Powers 200,000 Scam Sites appeared first on SecurityWeek . SecurityWeek · Jun 27, 2026
vulnerability Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories A high-severity vulnerability was discovered in the Amazon Q Developer extension for Visual Studio Code, allowing attackers to steal cloud credentials through malicious code repositories. The extension’s automatic execut… SecurityWeek · Jun 26, 2026 Critical CVE-2026-12957CVE-2026-12958USaivscodecredentials
More Klue Breach Victims Identified as Hackers Get Hacked Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact. The post More Klue Breach Victims Identified as Hackers Get Hacked appeared first on SecurityWeek . SecurityWeek · Jun 26, 2026 High
threat-intel In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs This week’s cybersecurity news includes a Russian government operation utilizing Cellebrite software to target an opposition activist, a Scattered Spider group breach of Transport for London, and a significant data leak… SecurityWeek · Jun 26, 2026 High RUUKINaicyberespionagesupply chain