threat-intel Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook This article details a trend of underground forums sharing a tutorial designed to guide novice hackers through the process of identifying, exploiting, and monetizing vulnerabilities. The ‘Hercules’ thread, popular across… BleepingComputer · Jun 4, 2026 High USvulnerabilityexploitmonetization
threat-intel Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process A security researcher, Ammar Askar, released a GitHub token-stealing exploit for Microsoft's VS Code, citing frustration with the company's vulnerability disclosure process. This follows a recent breach of GitHub reposit… The Record · Jun 4, 2026 High githubvulnerabilitydisclosure
threat-intel Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover A coding error in several Microsoft 365 Android applications, specifically Excel, Word, PowerPoint, OneNote, Loop, and Microsoft 365 Copilot, exposed user accounts to potential compromise. The issue stemmed from a disabl… Dark Reading · Jun 3, 2026 High CVE-2026-41100CVE-2026-41101CVE-2026-41102authenticationtokensandroid
threat-intel What 345 Days of Untested Exposure Looks Like at a Bank This article details a significant security vulnerability stemming from a bank’s reliance on an annual penetration testing schedule, highlighting the risks associated with infrequent assessments. A VPN vulnerability, exp… BleepingComputer · Jun 3, 2026 High USvulnerabilityapitenant_id
threat-intel ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds A new ‘HTTP/2 Bomb’ exploit has been discovered that leverages existing vulnerabilities in HTTP/2 implementations to cause widespread denial-of-service attacks against web servers. The exploit combines compression and fl… SecurityWeek · Jun 3, 2026 High CVE-2016-6581CVE-2025-53020CVE-2016-8740USdoshttp2compression
threat-intel White House unveils pared-back AI executive order The White House has released a revised executive order addressing artificial intelligence, significantly shortening the mandatory review period for AI model releases from 90 days to 30 days, responding to industry pressu… The Record · Jun 2, 2026 Medium USaicybersecurityregulation
threat-intel Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine The Gamaredon group is exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy a multi-stage malware campaign targeting Ukraine. This campaign utilizes GammaWorm and GammaSteel, designed for data theft and persistenc… The Hacker News · Jun 2, 2026 High CVE-2025-8088CVE-2026-21509RUUAwinrarmalwarevulnerability
threat-intel Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis This SecurityWeek article examines the evolving cybersecurity crisis, highlighting a shift in focus from traditional vulnerability management to the challenges of rapid exploit development and runtime visibility. The rep… SecurityWeek · Jun 2, 2026 High airuntimepatching
vulnerability CISA flags two-year-old Oracle flaw as actively exploited in attacks CISA has identified a two-year-old Oracle WebLogic Server vulnerability (CVE-2024-21182) as actively being exploited in attacks, prompting a directive for federal agencies to immediately patch their systems. The vulnerab… BleepingComputer · Jun 2, 2026 High CVE-2024-21182CVE-2025-61884CVE-2026-21992oracleweblogicvulnerability
threat-intel The Zero-Knowledge Threat Actor and the End of Responsible Disclosure This article discusses the rise of ‘zero-knowledge’ threat actors, empowered by AI, who pose a significant new challenge to cybersecurity. These actors, lacking deep technical expertise, can rapidly discover and exploit… SecurityWeek · Jun 2, 2026 High aivulnerabilityphishing
threat-intel AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It. This article discusses the accelerating pace of vulnerability exploitation driven by the use of AI by both attackers and defenders. The traditional approach of simply ‘patching faster’ is no longer sufficient due to the… The Hacker News · Jun 2, 2026 High INaivulnerabilityexploitation
vulnerability Google fixes one actively exploited Android zero-day, 124 flaws Google has released a significant security update addressing 124 vulnerabilities in Android, including a previously exploited zero-day vulnerability (CVE-2025-48595). This update focuses on mitigating targeted attacks an… BleepingComputer · Jun 2, 2026 High CVE-2025-48595CVE-2025-48633CVE-2025-48572zero-dayandroidvulnerability
threat-intel The Intersection of Encryption and AI This article discusses Bruce Schneier’s longstanding critique of cryptography’s limitations in securing modern networks, arguing that its inherent mathematical advantages favor defenders while attackers constantly adapt.… Schneier on Security · Jun 2, 2026 Medium cryptographyaivulnerability
vulnerability Microsoft Threatening Security Researcher A security researcher known as "Nightmare Eclipse" has been publicly disclosing a series of critical vulnerabilities within Microsoft Windows, including a breach of BitLocker encryption. In response, Microsoft has issued… Schneier on Security · Jun 2, 2026 High securityexploitbitlocker
threat-intel Anthropic to Open Mythos AI to EU's ENISA This article reports that Anthropic is granting access to its Mythos AI model to the European Union’s ENISA as part of the Project Glasswing initiative. Mythos, an AI model capable of autonomously discovering and exploit… Dark Reading · Jun 1, 2026 High EUUSaivulnerabilitycybersecurity
threat-intel Inspector general finds NIST mistakes have made vulnerability database ineffective A recent inspector general report has identified significant mismanagement and strategic failures within the National Institute of Standards and Technology (NIST)’s National Vulnerability Database (NVD), resulting in a m… The Record · Jun 1, 2026 High UNvulnerabilitybacklogmanagement
threat-intel Microsoft's Zero-Day Legal Threats Spark Backlash This article reports on Microsoft's controversial response to a security researcher, "Nightmare-Eclipse," who published several zero-day exploits. Microsoft initially threatened criminal charges against the researcher an… Dark Reading · Jun 1, 2026 High CVE-2026-33825zero-dayvulnerabilityresearcher
threat-intel Race Against Time: Why Faster Vulnerability Alerts Matter This article highlights the critical importance of rapid vulnerability alerts in cybersecurity, emphasizing the increasing speed at which vulnerabilities are being discovered and exploited. The average time to exploitati… BleepingComputer · Jun 1, 2026 High USvulnerabilityexploitationcybersecurity
threat-intel ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More This Hacker News recap details several ongoing cyber threats, including an active exploitation of a PAN-OS GlobalProtect authentication bypass vulnerability, a critical zero-day vulnerability in the Gogs Git service, and… The Hacker News · Jun 1, 2026 High CVE-2026-0257CVE-2026-8732CVE-2026-27771RUvulnerabilityauthenticationc2
threat-intel Critical Windows Netlogon RCE flaw now exploited in attacks A critical Remote Code Execution (RCE) vulnerability (CVE-2026-41089) in Windows Netlogon is now being actively exploited in attacks, according to Belgium's national cybersecurity authority, the Centre for Cybersecurity… BleepingComputer · Jun 1, 2026 Critical CVE-2026-41089CVE-2026-45585CVE-2026-33825BErcenetlogonwindows