threat-intel Why Identity Security Is Your Cyber Career Entry Point This Dark Reading article, part of their ‘Heard It From a CISO’ video series, discusses the evolving landscape of cybersecurity career entry points. It highlights that while AI is automating certain tasks, human oversigh… Dark Reading · Jun 30, 2026 Medium aicybersecurityidentity security
threat-intel ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More This week’s security news highlights several concerning vulnerabilities and attacks, including a DirtyClone Linux kernel flaw, exploitation of PTC Windchill vulnerabilities, and the emergence of new malware like Gaslight… The Hacker News · Jun 29, 2026 High CVE-2026-43503CVE-2026-12569CVE-2026-47729UKRUlinuxkernelai
threat-intel OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review This article reports on a significant shift in the release strategy of AI models ChatGPT and Anthropic’s Claude, driven by a government-led cybersecurity review initiated by the Trump administration. OpenAI is restrictin… SecurityWeek · Jun 29, 2026 High USaicybersecuritygovernment
threat-intel OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards OpenAI is releasing a preview of GPT-5.6 Sol, a powerful AI model with enhanced cybersecurity capabilities, to a limited group of companies and the U.S. government. The model is designed for legitimate vulnerability rese… The Hacker News · Jun 27, 2026 High USaicybersecurityvulnerability research
supply-chain Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack A sophisticated supply chain attack, spearheaded by the Miasma malware family (linked to Mini Shai-Hulud and Hades), is targeting npm packages and GitHub Actions workflows. The attackers are leveraging compromised npm pa… The Hacker News · Jun 26, 2026 High RUsupply chainnpmgithub actions
threat-intel Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools This Securelist article details Kaspersky's 2026 threat analysis for small and medium-sized businesses (SMBs), highlighting a significant increase in cyberattacks disguised as artificial intelligence (AI) tools, particul… Securelist · Jun 25, 2026 High USaismbmalware
threat-intel Tenet Security Emerges From Stealth With $6 Million Seed Funding Tenet Security, a new cybersecurity firm originating in Israel, has secured $6 million in seed funding to address the emerging threat of "agentic behavior" in AI agents. The company’s technology focuses on real-time dete… SecurityWeek · Jun 17, 2026 High ISUSaiautonomous agentsagentjacking
ransomware The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm The Gentlemen ransomware group, initially operating as the affiliate-focused Phantom Mantis, has evolved into an independent RaaS operation led by the cybercriminal LARVA-368 (aka hastalamuerte). The group, responsible… The Hacker News · Jun 11, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073RUTHUKransomware-as-a-servicedouble extortionaffiliate program
threat-intel Why AI-driven threats are exposing the limits of MSP security stacks This article highlights how artificial intelligence (AI) is dramatically accelerating the pace and scale of cyberattacks, exposing the vulnerabilities of fragmented security stacks, particularly for Managed Service Provi… BleepingComputer · Jun 11, 2026 High USaiautomationmsps
supply-chain Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks A new wave of Shai-Hulud supply chain attacks has impacted over 471 NPM and PyPI packages, utilizing variants named Miasma and Hades. The attacks, originating from TeamPCP, involve credential harvesting and self-replicat… SecurityWeek · Jun 9, 2026 High supply chainnpmpypi
threat-intel Cybercriminals: the 'auditors' you never hired This article explores the psychological phenomenon of ‘normalcy bias’ – our tendency to underestimate risk and assume things will always go as they have in the past – and how it contributes to a persistent rise in cybera… WeLiveSecurity · Jun 9, 2026 High UKIRcognitive biasnormalcy biascybersecurity
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th) This report details the ongoing TeamPCP supply chain campaign, which has recently seen increased activity and expanded impact. CISA has formally acknowledged and addressed the campaign, adding vulnerabilities to its Know… SANS Internet Storm Center · Jun 8, 2026 High CVE-2026-45321CVE-2026-48027CVE-2026-8398USsupply chainnpmgithub
vulnerability CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers CISA has issued a warning about hackers actively exploiting a recently patched vulnerability in SolarWinds Serv-U, a file transfer software, to crash servers. This vulnerability, CVE-2026-28318, stems from uncontrolled r… BleepingComputer · Jun 5, 2026 High CVE-2026-28318CVE-2021-35211CVE-2024-28995UNdenial-of-servicepatchingfile transfer
threat-intel Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP) This article discusses the growing problem of ‘identity dark matter’ – unseen identity activity within enterprise systems due to fragmented IAM and a lack of visibility. Gartner has introduced the Identity Visibility and… The Hacker News · Jun 3, 2026 Medium identity managementvisibilityanalytics
threat-intel In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks This week’s cybersecurity news highlights a range of incidents, including a data breach affecting Trump Mobile customers, ongoing Russian government intrusion into US Treasury systems, and vulnerabilities in popular soft… SecurityWeek · May 29, 2026 High UNCHdata breachsupply chainphishing
supply-chain Supply Chain Compromises Impact Nx Console and GitHub Repositories CISA is responding to multiple supply chain attacks targeting developer ecosystems, specifically CI/CD pipelines. A malicious Nx Console VS Code extension compromised a GitHub employee, leading to data exfiltration, and… CISA Advisories · May 28, 2026 High CVE-2026-48027supply chainci/cdgithub
threat-intel ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos This week’s security news highlights a significant GitHub breach orchestrated by TeamPCP, stemming from a compromised developer’s device and leveraging vulnerabilities exposed by the TanStack supply chain attack. Simulta… The Hacker News · May 25, 2026 High CVE-2026-46333CVE-2026-41091CVE-2026-45498USGBsupply-chainlinuxgithub
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th) TeamPCP, a threat actor, launched a sophisticated supply chain campaign involving the trojanization of multiple software packages, impacting GitHub, Microsoft, OpenAI, Grafana Labs, and Mistral AI. The campaign utilized… SANS Internet Storm Center · May 25, 2026 High CVE-2026-45321supply chain attackcredential theftpublisher badge
supply-chain Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer A sophisticated supply chain attack targeting Laravel-Lang PHP packages has been identified, involving the mass modification of Git tags to inject a cross-platform credential-stealing framework. The attacker leveraged co… The Hacker News · May 23, 2026 Critical USsupply-chaincredential-stealingphp
threat-intel CISA to allow researchers to report vulnerabilities to exploited bugs catalog CISA has launched a new nomination form to allow external researchers, vendors, and industry partners to report exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. This initiative aims to enha… The Record · May 23, 2026 Medium USvulnerability disclosurethreat intelligencecybersecurity