threat-intel FortiBleed campaign used custom FortiGate sniffer to steal credentials The FortiBleed campaign, targeting Fortinet FortiGate devices, utilized a custom Golang tool called "FortigateSniffer" to steal credentials from compromised firewalls. This campaign, active since at least February 2026,… BleepingComputer · Jun 22, 2026 Critical UScredential theftfirewallgpu cracking
threat-intel Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants Researchers have identified four critical vulnerabilities in the open-source Dify agentic workflow platform, dubbed DifyTap, allowing unauthorized access to AI conversations and data across tenants. These flaws include a… The Hacker News · Jun 22, 2026 Critical CVE-2024-5846CVE-2026-41947CVE-2026-41948aivulnerabilitytenant
threat-intel He Thought He Was Secure; His Phone Number Got Stolen Anyway This article details a real-world incident where cybersecurity expert Torsten George was targeted by a SIM swap attack, highlighting the vulnerability of relying solely on one-time passwords (OTPs) for security. The atta… Dark Reading · Jun 22, 2026 High USUKAUsim swapotpsocial engineering
phishing Webinar: How attackers bypass MFA and how defenders can respond The article discusses a growing trend in cyberattacks where attackers bypass multi-factor authentication (MFA) through sophisticated phishing techniques, specifically Device Code phishing. These attacks exploit legitimat… BleepingComputer · Jun 19, 2026 High phishingmfaaccount takeover
threat-intel FIFA Bug Exposed World Cup Streams to Remote Takeover A vulnerability in FIFA's Microsoft Entra environment allowed an ethical hacker, "BobDaHacker," to gain unauthorized access to global World Cup streams, match management systems, and related data platforms. The issue ste… Dark Reading · Jun 18, 2026 High USFRCOaccess-controlvulnerabilityauthentication
vulnerability Rockwell Automation FactoryTalk Historian Site Edition This advisory from CISA details vulnerabilities in Rockwell Automation’s FactoryTalk Historian Site Edition software, specifically versions through 11.00. Exploitation could lead to denial-of-service attacks or authentic… CISA Advisories · Jun 18, 2026 Medium CVE-2025-13036CVE-2025-44019CVE-2025-36539USfactorytalkhistorianrockwellautomation
vulnerability Rockwell Automation FLEX I/O EtherNet/IP Adapters This CISA advisory details vulnerabilities within Rockwell Automation’s FLEX I/O EtherNet/IP Adapters (versions 2.012) that could allow unauthorized access and potential loss of device availability. The issues include a… CISA Advisories · Jun 16, 2026 High CVE-2026-0646CVE-2026-0647USethernet/ipcontrol systemsmemory corruption
vulnerability SimpleHelp bug lets hackers create rogue remote support accounts A critical vulnerability (CVE-2026-48558) in SimpleHelp remote management software allows unauthorized users to create privileged technician accounts via OpenID Connect (OIDC) authentication. This flaw, combined with spe… BleepingComputer · Jun 15, 2026 Critical CVE-2026-48558oidcremote managementauthentication
threat-intel The Beginning of the End of Social Engineering This article discusses a significant shift in cybersecurity driven by the integration of AI-native operating systems, particularly Google's Gemini and Apple's Apple Intelligence. Operating systems are evolving to activel… Dark Reading · Jun 15, 2026 High USaisocial engineeringauthentication
apt Chinese hackers hijack auth flow, spy on isolated network for a decade Chinese cyber espionage group Velvet Ant conducted a decade-long operation, gaining persistent access to a large organization’s isolated critical infrastructure network by hijacking its authentication flow. The attackers… BleepingComputer · Jun 13, 2026 Critical CHespionageauthenticationpersistence
vulnerability Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication A critical vulnerability (CVE-2026-20253) has been identified in Splunk Enterprise versions below 10.2.4 and 10.0.7, allowing unauthenticated users to execute arbitrary code and potentially gain remote access. The flaw s… The Hacker News · Jun 13, 2026 Critical CVE-2026-20253USremote code executionauthenticationpostgresql
data-breach South Korea hits Coupang with record $409 million fine over data breach South Korea’s data protection regulator, the PIPC, has levied a record $409 million fine against Coupang, the country’s largest online retailer, following a significant data breach impacting tens of millions of customers… The Record · Jun 12, 2026 High KRdata breachauthenticationcustomer data
data-breach Coupang hit with record $409 million data breach fine in Korea Coupang, a major South Korean e-commerce company, has been hit with a record $409 million fine by the Personal Information Protection Commission (PIPC) due to a massive data breach affecting over 37 million customers. Th… BleepingComputer · Jun 11, 2026 High SOCHdata breachauthenticationdata security
threat-intel Naxclow IoT Platform This CISA advisory details a critical vulnerability in the Naxclow IoT Platform, specifically affecting versions of the Smart Doorbell X3, X Smart Home, V720, and ix cam devices. The flaw allows an attacker to impersonat… CISA Advisories · Jun 11, 2026 Critical CVE-2026-42947CVE-2026-50108CVE-2026-50101USiotcredential theftauthentication
threat-intel Bug Bounty Research Triggers ServiceNow Security Alert ServiceNow experienced a situation where bug bounty research was mistakenly identified as a security breach targeting their customer instances. The issue involved unauthorized access to instance tables, but ServiceNow de… Dark Reading · Jun 10, 2026 Low AUbug bountyresearchsecurity
threat-intel The 5 Best Practices for Secure Identity Verification This article from BleepingComputer highlights key best practices for organizations to strengthen their identity verification processes and improve overall cyber resilience. It emphasizes the growing threat of credential… BleepingComputer · Jun 10, 2026 High UKmfaidentity verificationauthentication
vulnerability SAP fixes critical flaws in NetWeaver and Commerce Cloud SAP has released a security patch addressing 15 vulnerabilities across its NetWeaver and Commerce Cloud platforms. The patch includes four critical flaws, primarily focused on authentication bypass and memory corruption,… BleepingComputer · Jun 9, 2026 Critical CVE-2026-44748CVE-2026-27671CVE-2026-22732samsauthenticationmemory corruption
vulnerability Schneider Electric Modicon Network Managed Switches Schneider Electric has identified a vulnerability (CVE-2024-3596) in its Modicon Network Managed Switches due to a misconfigured RADIUS protocol. Specifically, disabling the RADIUS Server Message Authenticator option mak… CISA Advisories · Jun 9, 2026 High CVE-2024-3596WOradiuscvesecurity
vulnerability Schneider Electric EcoStruxure Panel Server Schneider Electric has identified a vulnerability in its EcoStruxure Panel Server product line, specifically versions prior to 002.006.000. This vulnerability, classified as CWE-1188, allows for potential unauthorized au… CISA Advisories · Jun 9, 2026 High CVE-2026-6866FRcwe-1188firmwareauthentication
vulnerability Siemens KACO Blueplanet Inverters This advisory from CISA details vulnerabilities within Siemens KACO Blueplanet Inverters, a series of industrial inverters used in energy systems. The vulnerabilities, specifically a CRC16-based algorithm for generating… CISA Advisories · Jun 9, 2026 High CVE-2025-40946CVE-2026-41125WOindustrial control systemsvulnerabilityauthentication