threat-intel In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine This week’s cybersecurity news includes allegations of cover-ups by IBM and AT&T regarding foreign government-linked hacks, a data breach impacting the University of Oxford’s CareerConnect platform, and layoffs within Go… SecurityWeek · Jun 12, 2026 High CVE-2026-42271SOUNEUdata breachcyberattackddos
threat-intel Industry Reactions to Claude Fable 5: Feedback Friday The release of Anthropic’s Claude Fable 5 AI model has sparked industry discussion regarding its potential misuse in cybersecurity and other high-risk areas. The model incorporates safeguards that automatically downgrade… SecurityWeek · Jun 12, 2026 High aicybersecuritythreat intelligence
threat-intel Iranian Cyber Group Handala Claims Cal Water Hack The Iranian cyber threat actor Handala has claimed responsibility for a data breach targeting California Water Service (Cal Water), resulting in the theft of 5GB of data including customer information and credentials. Th… SecurityWeek · Jun 12, 2026 High USIRirandata breachcyber espionage
vulnerability Ivanti Sentry Exploitation Attempts Hitting Honeypots A recently patched vulnerability in Ivanti Sentry, CVE-2026-10520, has been observed attempting exploitation on honeypots, according to Ivanti and CISA. The flaw allows for remote code execution with root privileges via… SecurityWeek · Jun 12, 2026 High CVE-2026-10520USvulnerabilitycommand injectionroot privilege
vulnerability Chrome 149 Update Patches 28 Vulnerabilities The browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs. The post Chrome 149 Update Patches 28 Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 12, 2026 High
Anthropic Disputes Fable 5 AI Jailbreak An AI hacker claims to have achieved a prompt-based jailbreak shortly after Fable 5’s launch, but Anthropic says it’s not a real jailbreak. The post Anthropic Disputes Fable 5 AI Jailbreak appeared first on SecurityWeek… SecurityWeek · Jun 12, 2026
vulnerability Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters Oracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation. The post Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters appeared first on S… SecurityWeek · Jun 12, 2026 Critical CVE-2026-35273
vulnerability Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks Oracle has released a patch for CVE-2026-35273, but it has not said whether it’s a zero-day exploited in ShinyHunters attacks. The post Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks appeared… SecurityWeek · Jun 11, 2026 Critical CVE-2026-35273
threat-intel Alert Fatigue Is Becoming a Security Threat of Its Own This article highlights the growing threat of alert fatigue within Security Operations Centers (SOCs). The overwhelming volume of alerts generated by security tools, often lacking context and prioritization, is leading t… SecurityWeek · Jun 11, 2026 High alert fatiguesocai
threat-intel CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk CISA has issued Binding Operational Directive 26-04, requiring federal agencies to prioritize patching security vulnerabilities based on risk, building upon previous efforts established in 2021. This directive focuses on… SecurityWeek · Jun 11, 2026 High vulnerabilitypatchingrisk
malware OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month The OnyxC2 stealer, offered as a "Malware-as-a-Service" (MaaS) product for $250-$500 per month, is a sophisticated tool designed for enterprise-level credential theft. Developed by BlackFog, it boasts a wide range of tar… SecurityWeek · Jun 11, 2026 High USstealercredential theftmalware-as-a-service
vulnerability Hackers Exploit Langflow Vulnerability for Remote Code Execution Disclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system. The post Hackers Exploit Langflow Vulnerability for Remote Code Execution appeared first on S… SecurityWeek · Jun 11, 2026 High CVE-2026-5027
malware Siemens Says Desigo CC Files Flagged as Malware by Security Engines A PowerShell script included in patch files appears to be triggering false positives by multiple security engines. The post Siemens Says Desigo CC Files Flagged as Malware by Security Engines appeared first on SecurityWe… SecurityWeek · Jun 11, 2026 Medium
threat-intel FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers The FBI has taken down thirteen websites used by Chinese intelligence operatives to target and recruit U.S. government employees with access to sensitive information. These websites impersonated consulting firms offering… SecurityWeek · Jun 11, 2026 High USCNespionagerecruitmentcybersecurity
vulnerability Splunk, Palo Alto Networks Patch Severe Vulnerabilities The security defects could allow attackers to create or modify arbitrary files and access and modify protected resources. The post Splunk, Palo Alto Networks Patch Severe Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 11, 2026 High CVE-2026-0274CVE-2026-20253
vulnerability ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker The PoC exploits Microsoft Defender’s offline scan to spawn a SYSTEM shell when rebooting in Recovery Mode. The post ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker appeared first on SecurityWeek . SecurityWeek · Jun 11, 2026 Critical
University of Nottingham Confirms Breach After Hackers Leak Data The ShinyHunters hacker group has taken credit for the attack, leaking more than 450,000 email addresses and other information. The post University of Nottingham Confirms Breach After Hackers Leak Data appeared first on… SecurityWeek · Jun 11, 2026
vulnerability Microsoft Patches Exploited Exchange Server Vulnerability The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14. The post Microsoft Patches Exploited Exchange Server Vulnerability appeared first on SecurityWeek . SecurityWeek · Jun 11, 2026 Critical CVE-2026-42897
threat-intel Infostealers Turn Millions of Devices Into Credential Theft Machines This report details a significant increase in the use of infostealers as a primary method for attackers to steal credentials and gain unauthorized access to networks. Over 11.1 million devices were infected in 2025, resu… SecurityWeek · Jun 10, 2026 High IRinfostealerscredentialsmalware-as-a-service
Cyera Raises $600 Million at $12 Billion Valuation Cyera is positioned as one of the most valuable privately held cybersecurity firms in the world with total funding topping $2 billion. The post Cyera Raises $600 Million at $12 Billion Valuation appeared first on Securit… SecurityWeek · Jun 10, 2026