threat-intel Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls Anthropic has restored access to Claude Fable 5 following the U.S. Commerce Department’s lifting of export controls triggered by a jailbreak vulnerability discovered in the model. The controls, implemented in June, restr… The Hacker News · Jul 1, 2026 High USjailbreakaisecurity
vulnerability Google Patches 382 Chrome Vulnerabilities Fifteen of the newly patched flaws have been rated ‘critical’ and 67 have been rated ‘high severity’. The post Google Patches 382 Chrome Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jul 1, 2026 High
threat-intel Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts A massive, automated password spray attack targeting Microsoft's Azure CLI compromised at least 78 Microsoft accounts across 64 organizations. The attack leveraged a deprecated OAuth flow (ROPC) to bypass Conditional Acc… The Hacker News · Jul 1, 2026 High USCNpassword sprayropcconditional access
malware Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery This report details a concerning trend in malware delivery – the evolution of ClickFix, a technique where users are tricked into running malicious code by hand. Researchers have uncovered a new API-driven approach to gen… The Hacker News · Jul 1, 2026 High RUIRNOmalwarepayloadapi
vulnerability Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service This article details six newly discovered vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway software, potentially allowing for denial-of-service attacks and arbitrary file reads. The vulnerabilities, ranging… The Hacker News · Jul 1, 2026 High CVE-2026-8451CVE-2026-8452CVE-2026-8655samlhttp2memory
threat-intel Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector Palo Alto Unit 42 researchers have identified a new supply chain threat: "phantom squatting," where large language models (LLMs) hallucinate web domains that adversaries can then register to intercept traffic generated b… Palo Alto Unit 42 · Jul 1, 2026 High USllmaisupply chain
threat-intel China-Linked Group Targets Southeast Asia Critical Systems A China-linked cyber threat group, CL-STA-1062 (formerly UAT-7237), has been targeting critical infrastructure providers in Southeast Asia over the past year, deploying a new backdoor tool called TinyRCT. The group has s… Dark Reading · Jul 1, 2026 High CNMYTHchinaaptbackdoor
threat-intel Attackers Hijack Exposed AI Endpoints to Power Offensive Ops Researchers at Zenity discovered attackers are exploiting exposed AI endpoints, specifically Ollama and LiteLLM, to power offensive operations. Attackers leverage these AI agents – such as Strix and HexStrike AI – withou… Dark Reading · Jun 30, 2026 High FRaillmendpoint
threat-intel Phishers Gain Persistence at EU, Asia Hospitality Orgs Phishing campaigns targeting hospitality organizations in Europe and Asia are utilizing malicious zip files containing disguised image files to install persistent malware. These attacks, observed by Microsoft and Trend M… Dark Reading · Jun 30, 2026 High GBJPphishingpersistencesocial engineering
threat-intel Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data This report details a new security vulnerability impacting AI agent-based systems, specifically leveraging the Model Context Protocol (MCP). Attackers can inject malicious instructions into tool descriptions used by AI a… The Hacker News · Jun 30, 2026 High N/aiagentsupply-chain
malware RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS A new botnet, RustDuck, is leveraging Rust programming to hijack routers, IP cameras, and servers for DDoS attacks. Developed by QiAnXin's XLab, the botnet utilizes a two-stage approach, exploiting vulnerabilities in dev… The Hacker News · Jun 30, 2026 High CVE-2017-17215CVE-2025-29635CVE-2024-1781CNddosbotnetrust
malware Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses A new browser extension campaign, dubbed Silent Swap by McAfee Labs, is targeting cryptocurrency users by stealthily replacing wallet addresses during transactions. The malicious extension, disguised as a Google Notes ut… The Hacker News · Jun 30, 2026 High INUSBRclipboardwalletcrypto
threat-intel GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks A research report by Adversa AI has revealed a significant security vulnerability in ten popular open-source AI coding agents, including GuardFall, which allows attackers to bypass safety checks and execute shell command… The Hacker News · Jun 30, 2026 High aishellsecurity
threat-intel 282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study Researchers at Wake Forest University discovered that nearly two-thirds (282 out of 444) of AI chatbot apps for iOS exposed API keys and open access to AI proxy services through network traffic. This vulnerability, dubbe… The Hacker News · Jun 30, 2026 High USapiaiiot
threat-intel Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks A research report by Adversa AI has identified a significant security vulnerability in several popular open-source AI coding agents, dubbed ‘GuardFall’. This flaw stems from the agents’ reliance on Bash shell tricks, spe… SecurityWeek · Jun 30, 2026 High bashai agentssupply chain
data-breach Aflac Japan Data Breach Impacts 4.38 Million Hackers accessed the insurance giant’s policyholder portal multiple times between June 15 and June 25. The post Aflac Japan Data Breach Impacts 4.38 Million appeared first on SecurityWeek . SecurityWeek · Jun 30, 2026 High
vulnerability OFFIS DCMTK Toolkit This CISA advisory details vulnerabilities within the OFFIS DCMTK Toolkit (<=3.7.0) that could allow an attacker to perform actions like file writing, unauthorized data access, memory exhaustion, and system crashes. The… CISA Advisories · Jun 30, 2026 High CVE-2026-50003CVE-2026-50254CVE-2026-35505DEpath traversalmemory leakcve-2026-50003
vulnerability Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M This advisory details a vulnerability (CVE-2025-53816, CVE-2025-53817, CVE-2025-55188, CVE-2025-11001) within the Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M software. The vulnerability, a heap-based buffer o… CISA Advisories · Jun 30, 2026 High CVE-2025-53816CVE-2025-53817CVE-2025-55188JPbuffer overflowheapdenial of service
threat-intel What the Numbers Say About FIFA 2026 Cyber Risk This report from Check Point Research reveals a significant pre-emptive cyber threat landscape surrounding the FIFA World Cup 2026, with attackers already establishing infrastructure months in advance. The primary target… The Hacker News · Jun 30, 2026 High RUemailspoofingfraud
malware USB drives carrying China-linked malware infected Japanese military networks for nearly a year Japanese military networks, specifically the Ground Self-Defense Force (JGSDF), were compromised by a year-long campaign utilizing counterfeit USB drives loaded with malware. The incident, discovered in February 2025, in… Graham Cluley · Jun 30, 2026 High JACHusb drivesmalwarejapan