threat-intel An intelligence budget 'super user' job is now in the hands of Russ Vought This article reports that Russ Vought, Donald Trump’s former budget chief, has taken over managing the classified spending plans of major U.S. intelligence agencies, including the CIA and NSA. This shift follows the depa… The Record · Jun 30, 2026 Medium USpoliticalbudgetintelligence
threat-intel AI-Generated Workflows Are a Silent Security Disaster This article highlights a growing security risk stemming from the use of AI-generated workflows within Microsoft 365 environments. Developers and users are leveraging AI assistants to automate tasks like document approva… Dark Reading · Jun 30, 2026 Medium aiautomationpermissions
vulnerability Schneider Electric EcoStruxure IT Data Center Expert This report details a vulnerability discovered in Schneider Electric’s EcoStruxure IT Data Center Expert software, specifically versions up to 9.1.1. The vulnerability, classified as CWE-611, is an Improper Restriction o… CISA Advisories · Jun 30, 2026 Medium CVE-2026-8045FRxmlcwe-611data center
threat-intel Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat This article details the unconventional career path of Chris Thompson, a former IBM X-Force Red head and now CEO of RemoteThreat, tracing his journey from a teenage game hacker to a respected security professional. Thomp… SecurityWeek · Jun 30, 2026 Medium UKCAhackerred teamingai
vulnerability Schneider Electric EasyLogic T150 and Saitel DP RTU This advisory details vulnerabilities in Schneider Electric's EasyLogic T150 and Saitel DP RTU devices, specifically versions through 11.06.37. These vulnerabilities, classified as CWE-522 and CWE-732, allow for unauthor… CISA Advisories · Jun 30, 2026 Medium CVE-2026-9650CVE-2026-9651FRcredentialsfirmwareiot
vulnerability Exploitation of Recent Oracle E-Business Suite Vulnerability Begins The critical-severity defect allows unauthenticated attackers to take over the E-Business Suite’s Payments product. The post Exploitation of Recent Oracle E-Business Suite Vulnerability Begins appeared first on SecurityW… SecurityWeek · Jun 30, 2026 Medium CVE-2026-46817
data-breach June 2026 Apple Updates, (Tue, Jun 30th) Apple released updates for iOS/iPadOS, macOS, and Safari on Monday. There have been no updates for other Apple operating systems (visionOS, watchOS, tvOS). Usually, Apple updates all products at the same time. SANS Internet Storm Center · Jun 30, 2026 Medium CVE-2026-39868CVE-2026-43676CVE-2026-43700
threat-intel Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs Apple released a significant security update addressing over 30 vulnerabilities across its iOS, macOS, and Safari platforms. Notably, several WebKit vulnerabilities were identified using AI tools, highlighting a new tren… The Hacker News · Jun 30, 2026 Medium CVE-2026-43707CVE-2026-43716CVE-2026-43745webkitaivulnerability
threat-intel NIST Enrichment Reductions Impact CVE Coverage, Accuracy This article reports on a reduction in in-depth analysis of vulnerabilities by the National Institute of Standards and Technology (NIST), impacting the National Vulnerability Database (NVD). Research by Volerion revealed… Dark Reading · Jun 29, 2026 Medium CVE-2026-8856vulnerabilitynistcvss
threat-intel Can Clothes Make You Invisible to Facial Recognition? This Dark Reading article details a research project spearheaded by Bill Swearingen aimed at developing clothing designs to evade facial recognition technology. Swearingen’s approach focuses on exploiting weaknesses in f… Dark Reading · Jun 29, 2026 Medium USfacial recognitionsurveillanceai
malware Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel. Acroni… The Hacker News · Jun 29, 2026 Medium
phishing ISC Stormcast For Monday, June 29th, 2026 https://isc.sans.edu/podcastdetail/9986, (Mon, Jun 29th) The SANS Internet Storm Center's June 29th, 2026 Stormcast reported a heightened level of online threats, primarily focusing on phishing campaigns and malicious email activity. The report highlighted an increase in obser… SANS Internet Storm Center · Jun 29, 2026 Medium phishingemailthreat intelligence
malware Clean GitHub repo tricks AI coding agents into running malware An agentic coding tool tasked with running a seemingly benign GitHub repository could execute a malicious payload that is invisible to both security agents and human reviewers. BleepingComputer · Jun 27, 2026 Medium
threat-intel AI Decline? Confidence in Autonomous Penetration Testing Falls The confidence in fully autonomous AI systems for penetration testing has significantly declined after initial optimism. A report by Cobalt found that only 9% of organizations now rely on AI-powered testing, down from 29… Dark Reading · Jun 26, 2026 Medium aipentestingautomation
phishing Cybersecurity firms targeted by fraudulent OpenAI organization invites Cybersecurity firms are being targeted by a sophisticated phishing campaign where attackers create fraudulent OpenAI organizations, mimicking legitimate companies and inviting employees to join them. These invitations, a… BleepingComputer · Jun 26, 2026 Medium phishingopenaicredential_harvesting
threat-intel Meta Is Testing Facial Recognition for Police and Military Meta is reportedly developing facial recognition technology, initially for use by law enforcement and the military. This development involves a prototype being tested with a Pentagon supplier, raising concerns about the… Schneier on Security · Jun 26, 2026 Medium facial recognitionsurveillancemeta
threat-intel AI Won't Wipe-Out Entry-Level Cybersecurity Jobs This Dark Reading article discusses the evolving role of entry-level cybersecurity professionals in the age of AI. Rather than eliminating these positions, AI is shifting the focus towards more strategic and analytical t… Dark Reading · Jun 26, 2026 Medium aiautomationcybersecurity
threat-intel Your First GRC Agent: A Red Teamer's Walkthrough This BleepingComputer article discusses the emerging concept of "agentic" GRC (Governance, Risk, and Compliance) systems, driven by the increasing dynamism of modern IT environments. It explains how agents, unlike tradit… BleepingComputer · Jun 26, 2026 Medium grcaiautomation
threat-intel Russia accuses Apple of ‘political censorship’ after VK apps removed from App Store Following the removal of VK apps from the Apple App Store, Russia has accused Apple of political censorship and a lack of trust, citing sanctions compliance. The move has sparked a diplomatic backlash from Russian offici… The Record · Jun 26, 2026 Medium RUsanctionscensorshiprussia
phishing Russian Intelligence Services Continue to Target Commercial Messaging Applications The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have issued a new PSA highlighting ongoing cyberattacks by Russian Intelligence Services (RIS) targeting commercial messaging applications. These at… CISA Advisories · Jun 26, 2026 Medium RUphishingcredential theftrussian intelligence