malware Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts Microsoft removed 119 malicious Edge extensions from its add-on store that employed steganography to hide malware, including credential theft and ad fraud capabilities. The operation, dubbed StegoAd, had been active sinc… The Hacker News · Jun 29, 2026 High CHsteganographycredential theftad fraud
threat-intel Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer A sophisticated cyberattack has been uncovered involving hijacked npm and Go packages designed to deploy a Python-based information stealer. Attackers leveraged a VS Code task trigger to execute malicious code disguised… The Hacker News · Jun 29, 2026 High KPvscodenpmfont-file
data-breach Data breach exposes up to 14.2 million email logins at six ISPs Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. BleepingComputer · Jun 28, 2026 High
threat-intel OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards OpenAI is releasing a preview of GPT-5.6 Sol, a powerful AI model with enhanced cybersecurity capabilities, to a limited group of companies and the U.S. government. The model is designed for legitimate vulnerability rese… The Hacker News · Jun 27, 2026 High USaicybersecurityvulnerability research
ransomware Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk Recent breaches targeting educational institutions, including ransomware attacks on Oracle E-Business Suite and Instructure's Canvas platform, highlight the vulnerability of the sector due to legacy technology, understaf… Dark Reading · Jun 27, 2026 High USthird-party riskransomwareeducation
threat-intel FBI: Russian hackers now target Signal backup recovery keys The FBI and CISA are warning about a phishing campaign orchestrated by Russian Intelligence Services (RIS) targeting Signal users. Attackers are now specifically seeking Signal Backup Recovery Keys to gain access to vict… BleepingComputer · Jun 26, 2026 High USRUUKphishingsignalrecovery key
threat-intel FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys The FBI and CISA have issued an updated advisory warning about Russian intelligence actors targeting Signal users, expanding their tactics to include obtaining Signal Backup Recovery Keys. This allows attackers to fully… The Hacker News · Jun 26, 2026 High USRUNEsignalphishingrecovery key
malware New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks A new cyberattack campaign, dubbed StrikeShark, is utilizing a previously undocumented malware family called SharkLoader to deploy Cobalt Strike Beacon. The campaign has targeted diplomatic organizations in Indonesia and… The Hacker News · Jun 26, 2026 High CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikedll hijackingexploit
threat-intel Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions Cisco is bolstering its security offerings by acquiring Astrix Security and WideField Security, both focused on managing the growing number of non-human identities (NHIs) created by AI agents. This strategy reflects a sh… Dark Reading · Jun 26, 2026 High ainon-human identitiesidentity management
threat-intel New Initiative Tackles Security for End-of-Life Open Source Software This article discusses a new initiative, the Open Source Sustainability Initiative (OSSI), launched by the Commonhaus Foundation to address the growing challenge of managing and securing end-of-life (EOL) open-source sof… Dark Reading · Jun 26, 2026 High USend-of-lifevulnerabilitiesopen source
threat-intel Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign A Chinese-speaking Advanced Persistent Threat (APT) group, CL-STA-1062, has been actively targeting government entities and critical infrastructure in Southeast Asia since 2022, utilizing a new custom backdoor called Tin… The Hacker News · Jun 26, 2026 High VNaptbackdoorsoutheast asia
More Klue Breach Victims Identified as Hackers Get Hacked Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact. The post More Klue Breach Victims Identified as Hackers Get Hacked appeared first on SecurityWeek . SecurityWeek · Jun 26, 2026 High
threat-intel In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs This week’s cybersecurity news includes a Russian government operation utilizing Cellebrite software to target an opposition activist, a Scattered Spider group breach of Transport for London, and a significant data leak… SecurityWeek · Jun 26, 2026 High RUUKINaicyberespionagesupply chain
threat-intel Meeting Trump's 2030 Quantum Deadline Will be Expensive, Complex This article discusses the US government's accelerated efforts to prepare for the advent of quantum computing, driven by executive orders focused on post-quantum cryptography (PQC). The government is mandating a transiti… Dark Reading · Jun 26, 2026 High USquantum computingpost-quantum cryptographypqc
apt Turla group adds more malware to Russia’s espionage efforts against Ukraine The Turla group, a long-standing Russian cyber-espionage team, has expanded its operations against Ukraine by deploying a new malware strain called StockStay. This malware, developed since December 2022, targets Ukrainia… The Record · Jun 26, 2026 High UKITNEcyberespionagerussiaukraine
vulnerability Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk A vulnerability (CVE-2024-2658) has been identified in Schneider Electric’s Floating License Manager (FLM), specifically the FlexNet Publisher component, due to an uncontrolled search path element. This allows a local, n… Securelist · Jun 26, 2026 High CVE-2024-2658USopensslprivilege escalationindustrial control systems
threat-intel FCC votes to toughen rules in bid to better protect undersea cables The FCC has voted to implement stricter regulations for undersea cables, aiming to bolster national security and protect internet traffic. This includes mandating licensing for submarine line terminal equipment (SLTE) an… The Record · Jun 26, 2026 High CHUKUSundersea cablescybersecuritynational security
vulnerability New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets A new vulnerability, CVE-2026-43503, has been discovered in the Linux kernel related to the DirtyClone variant of the DirtyFrag family. This flaw allows local users to gain root access by exploiting a cloned network pack… The Hacker News · Jun 26, 2026 High CVE-2026-43503CVE-2026-31431CVE-2026-43284linuxkernelprivilege escalation
threat-intel Guardian Agents: The Next Layer of Identity Governance This article discusses the emerging threat of ‘guardian agents’ – AI agents operating autonomously within enterprise environments, inheriting permissions and traversing systems at machine speed. The existing identity gov… The Hacker News · Jun 26, 2026 High aiagentic aiidentity governance
vulnerability Linux Foundation Unveils New Open Source Security Project Akrites It will provide the tools and channels to report, patch, and disclose open source software vulnerabilities. The post Linux Foundation Unveils New Open Source Security Project Akrites appeared first on SecurityWeek . SecurityWeek · Jun 26, 2026 High