threat-intel Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets Russia-linked APT Turla has been deploying a new .NET backdoor, dubbed StockStay, to conduct ongoing cyber espionage against Ukrainian government and military organizations, as well as entities with interests in Italian… SecurityWeek · Jun 26, 2026 High CVE-2025-8088UKRUITespionagebackdoorphishing
threat-intel Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff This report details how Russian authorities utilized Cellebrite's UFED forensic tools to access Andrey Pivovarov's iPhone 12 in June 2021, despite Cellebrite's subsequent announcement of a sales cutoff to Russia and Bela… The Hacker News · Jun 26, 2026 High RUGBJOforensiciphonecustody
vulnerability First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog. The post First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild appeared first on Securi… SecurityWeek · Jun 26, 2026 High CVE-2026-12569CVE-2026-4681
threat-intel New Enterprise-Ready MCP Specification Brings New Security Challenges The Model Context Protocol (MCP) is evolving from a single-user AI tool to an enterprise-ready platform designed for cloud-native AI usage, with a major update slated for July 28, 2026. This transition introduces new sec… SecurityWeek · Jun 26, 2026 High aistatelesssecurity
threat-intel Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks Google Threat Intelligence Group (GTIG) has identified a new backdoor, STOCKSTAY, developed and deployed by the Russian state-sponsored threat actor Turla. This multi-component backdoor, built using .NET and leveraging a… The Hacker News · Jun 26, 2026 High CVE-2025-8088UKITNEespionagebackdoorrussia
threat-intel CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Palo Alto Unit 42 has identified a sustained cyber threat campaign, CL-STA-1062, targeting government and critical infrastructure entities in Southeast Asia since at least March 2022. The group, linked to UAT-7237, utili… Palo Alto Unit 42 · Jun 25, 2026 High VNeast asiasoutheast asiabackdoor
threat-intel Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses The Russian cyber espionage group Gamaredon (also known as Aqua Blizzard) has significantly upgraded its arsenal and tactics, becoming a more effective threat actor, particularly in support of the war in Ukraine. The gro… Dark Reading · Jun 25, 2026 High RUUKaptespionagec2
threat-intel EdTech Attackers Shift From Schools to Their Software Suppliers This article reports a concerning shift in cyberattacks targeting the education sector, with attackers now focusing on edtech software suppliers like Instructure and Oracle rather than individual schools. The Shiny Hunte… Dark Reading · Jun 25, 2026 High edtechsupply chainransomware
threat-intel Local Police Collusion Hampers Crackdown on Asian Scam Centers This article reports on the ongoing challenge of combating cybercrime, specifically online scams, centered in Southeast Asia, particularly Cambodia, Myanmar, and the Philippines. Despite international pressure and arrest… Dark Reading · Jun 25, 2026 High KHUSCNcybercrimescamcorruption
phishing Bluekit phishing kit adopts browser-in-the-middle for login theft Bluekit, a phishing-as-a-service platform, has evolved by incorporating browser-in-the-middle (BitM) capabilities, allowing it to steal login credentials more effectively. The platform utilizes the rrweb JavaScript libra… BleepingComputer · Jun 25, 2026 High USphishingbitmbrowser-in-the-middle
threat-intel Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability A popular Google Chrome ad blocker extension, Adblock for YouTube, with over 10 million installs, has been found to contain a dormant script injection capability. Researchers discovered the extension’s architecture allow… The Hacker News · Jun 25, 2026 High USadblockjavascriptprivacy
threat-intel The Four Elevations of Effective Fraud Prevention This article discusses a multi-layered approach to fraud prevention, emphasizing the importance of monitoring across all customer touchpoints – from individual transactions to platform-wide activity. It advocates for col… BleepingComputer · Jun 25, 2026 High fraudaccount-takeoverauthentication
threat-intel ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories This article reports on several security vulnerabilities and trends, including a privacy-preserving protocol from Cloudflare, six vulnerabilities in the curl library, a critical security flaw in Hoppscotch allowing unaut… The Hacker News · Jun 25, 2026 High CVE-2026-8932CVE-2026-50160USKRsmart tvproxywareiot
threat-intel Russia used Cellebrite phone-hacking tool to crack down on dissident after firm cut off country This article reports that Russian authorities continued to use Cellebrite’s phone-hacking tool, the UFED, to access the devices of dissident political activist Andrey Pivovarov after Cellebrite announced it was ending it… The Record · Jun 25, 2026 High RUDEsurveillancephone-hackingdissident
vulnerability Schneider Electric PowerLogic P7 Schneider Electric has identified and addressed vulnerabilities within its PowerLogic™ P7 protection and control platform. Specifically, the product is susceptible to CWE-476 (NULL Pointer Dereference), CWE-78 (Improper… CISA Advisories · Jun 25, 2026 High CVE-2026-9716CVE-2026-9717CVE-2026-9718FRcwefirmwareindustrial control
threat-intel EVoke Systems Charging Station Management System This advisory details a vulnerability in the EVoke Systems Charging Station Management System (CSMS) due to a lack of proper authentication mechanisms in its WebSocket endpoints. Attackers could exploit this to gain unau… CISA Advisories · Jun 25, 2026 High CVE-2026-40702CVE-2026-50176CVE-2026-54479USwebsocketocppauthentication
vulnerability OHIF Viewers DICOM This advisory details a vulnerability in the OHIF Viewers DICOM framework, specifically versions up to v3.12.0, that allows attackers to steal authenticated user tokens via crafted links. The vulnerability stems from unc… CISA Advisories · Jun 25, 2026 High CVE-2026-12473USssrfdicomweboidc
vulnerability Delta Electronics DTM Soft A vulnerability has been identified in Delta Electronics’ DTM Soft software, allowing for potential arbitrary code execution via deserialization of untrusted data. This poses a risk to critical manufacturing operations g… CISA Advisories · Jun 25, 2026 High CVE-2026-12578WOdeserializationcwe-502critical manufacturing
Interesting Paper Exploring Prompt Injection This is a fascinating explotation of how LLMs fall for prompt injection attacks. It turns out that they learn to recognize the style of text in different role/instruction blocks, and not just the tags. Their conclusion:… Schneier on Security · Jun 25, 2026 High
vulnerability GitLab Patches Code Execution, Information Disclosure Vulnerabilities The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects. The post GitLab Patches Code Execution, Information Disclosure Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 25, 2026 High CVE-2026-10086CVE-2026-10712CVE-2026-12053