threat-intel Microsoft releases Windows 10 KB5094127 extended security update Microsoft released extended security update KB5094127 for Windows 10, addressing 200 vulnerabilities, including several zero-day flaws, as part of its ongoing Patch Tuesday program. The update also incorporates improveme… BleepingComputer · Jun 9, 2026 High security updatezero-daybitlocker
threat-intel Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs Russian threat actors, including Shadow-Earth-066 (UAC-0226) and Earth Dahu (Primitive Bear, Shuckworm), are continuing to exploit a long-standing vulnerability (CVE-2025-8088) in WinRAR to conduct data theft and cyber e… Dark Reading · Jun 9, 2026 High CVE-2025-8088CVE-2023-38831RUUAwinrarvulnerabilitycyberespionage
threat-intel WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine A vulnerability in WinRAR, first identified in July 2025, is being exploited by Russia-aligned cyber groups to deploy malware targeting Ukrainian organizations. The attackers, including Earth Dahu and SHADOW-EARTH-066, a… The Hacker News · Jun 9, 2026 High CVE-2025-8088RUUAwinrarexploitukraine
data-breach French govt messaging service breached in account hijacking attack The French government’s Tchap messaging service was breached after a compromised user account was used to gain access, leading to the theft of sensitive data including user information and over 13.5GB of files. The attac… BleepingComputer · Jun 9, 2026 High FRsocial engineeringdata theftmessaging
vulnerability CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day The Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive (BOD) 22-01, requiring U.S. federal agencies to patch a critical zero-day vulnerability in Check Point’s Remote Acces… BleepingComputer · Jun 9, 2026 High CVE-2026-50751CVE-2024-24919zero-dayvpnikev1
threat-intel Armenia’s pro-Europe party wins election despite Russia-linked disinformation Armenia’s parliamentary election saw the pro-Europe Civil Contract party secure a significant victory, despite a large-scale disinformation campaign orchestrated by Russia-linked actors. This campaign utilized tactics su… The Record · Jun 8, 2026 Medium RUAMUSdisinformationinfluence_operationcyberattack
threat-intel ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More This week’s security news highlights a series of attacks and vulnerabilities, including a supply chain attack targeting Microsoft GitHub repositories via the Miasma Worm, a zero-day exploit in Android, and ongoing cyberc… The Hacker News · Jun 8, 2026 High CVE-2025-48595CVE-2026-28318CVE-2026-39210CHUSGEsupply-chainzero-daycybercrime
vulnerability Check Point links VPN zero-day attacks to Qilin ransomware gang Check Point identified a zero-day vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access deployments, exploited by the Qilin ransomware gang. The flaw allowed unauthenticated attackers to bypass authen… BleepingComputer · Jun 8, 2026 High CVE-2026-50751CVE-2026-50752ISJAAUzero-dayvpnauthentication
threat-intel Anthropic Urges Industry Coordination to Allow for a ‘Pause’ in AI Development if Risks Grow Anthropic is advocating for a global pause in the development of advanced AI systems due to concerns about rapidly increasing capabilities and the potential for losing control. The company proposes coordinated action amo… SecurityWeek · Jun 8, 2026 High CAartificial intelligenceai safetycybersecurity
vulnerability CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers CISA has issued a warning about hackers actively exploiting a recently patched vulnerability in SolarWinds Serv-U, a file transfer software, to crash servers. This vulnerability, CVE-2026-28318, stems from uncontrolled r… BleepingComputer · Jun 5, 2026 High CVE-2026-28318CVE-2021-35211CVE-2024-28995UNdenial-of-servicepatchingfile transfer
threat-intel Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 A joint bulletin from the FBI, MI5, ASIO, CSIS, and NZSIS warns of a Chinese intelligence operation targeting Western professionals via LinkedIn and other job platforms. The operation involves posing as recruitment firms… Graham Cluley · Jun 5, 2026 High CHUNAUrecruitmentintelligencelinkedin
threat-intel Trump AI Order Seeks Voluntary Frontier Model Testing This executive order from the Trump administration aims to bolster federal cybersecurity and prepare for the risks associated with frontier AI models like Anthropic’s Claude Mythos. The order establishes a voluntary fram… Dark Reading · Jun 5, 2026 Medium aicybersecurityfrontier models
threat-intel New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework A new threat cluster, OP-512, is targeting Microsoft IIS servers with a custom web shell framework, exhibiting sophisticated evasion techniques and centralized management capabilities. ReliaQuest has linked the activity… The Hacker News · Jun 5, 2026 High CNiisweb shellespionage
threat-intel Industry Reactions to New Trump AI Cybersecurity Executive Order: Feedback Friday This article reports on President Trump’s new executive order establishing a voluntary framework for assessing the cybersecurity risks of advanced AI models before their public release. The order aims to bolster national… SecurityWeek · Jun 5, 2026 Medium USaicybersecuritynational security
threat-intel Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities The Five Eyes intelligence alliance has issued an alert warning of a sophisticated Chinese espionage campaign targeting government and military personnel through fake job opportunities on platforms like LinkedIn. This ta… SecurityWeek · Jun 5, 2026 High CHUNAUespionagesocial-engineeringrecruitment
threat-intel Trump considers Palantir exec to lead CISA The Trump administration is considering Shyam Sankar, a top executive at Palantir Technologies, to lead the Cybersecurity and Infrastructure Security Agency (CISA). This nomination follows a period of instability at the… The Record · Jun 4, 2026 Medium aicisapalantir
data-breach UN food agency discloses breach affecting 600,000 Gaza households The World Food Programme (WFP) has disclosed a breach of its self-registration application (SRA) used in Gaza, resulting in the theft of personal data from approximately 600,000 Palestinian households. This incident high… BleepingComputer · Jun 4, 2026 High PSgazadata breachhumanitarian
threat-intel ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories This bulletin highlights several ongoing cyber threats, including a high-severity SSRF vulnerability in Cisco Unified Communications Manager, a large-scale spyware operation targeting Russian officials by foreign intelli… The Hacker News · Jun 4, 2026 High CVE-2026-20230CVE-2022-0492CVE-2019-5736RUIRUSssrfspywarekeylogger
threat-intel Five Eyes warn Chinese spies are using job sites to recruit insiders The Five Eyes intelligence alliance has issued a joint warning about Chinese military intelligence services using online job platforms to recruit individuals with access to sensitive information. This tactic, described a… The Record · Jun 4, 2026 High CHAUCArecruitmentespionagecybersecurity
apt Pakistan Spies on Afghan Finance Ministry With Xeno RAT A Pakistani advanced persistent threat (APT) group, identified as SideCopy and linked to the Transparent Tribe (APT 36), has been conducting espionage against Afghanistan's finance ministry since at least May 2025. The g… Dark Reading · Jun 4, 2026 High AFPKspear-phishingremote-accesspashto