vulnerability DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories A series of vulnerabilities, dubbed "DifyTap," have been discovered in the Dify AI application building platform, allowing attackers to potentially access and exfiltrate sensitive data, including AI chat histories. The f… Dark Reading · Jun 22, 2026 High CVE-2026-41947CVE-2026-41948CVE-2026-41949aisecurityvulnerability
threat-intel FFmpeg fixes PixelSmash flaw in widely used video decoder A vulnerability, dubbed ‘PixelSmash’ (CVE-2026-8461), has been identified in FFmpeg’s MagicYUV decoder, allowing for remote code execution (RCE) on vulnerable systems. The flaw stems from an out-of-bounds write in the de… BleepingComputer · Jun 22, 2026 High CVE-2026-8461USsupply-chainremote-code-executionheap-overflow
threat-intel Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign A sophisticated cybercrime campaign, orchestrated by unknown threat actors, is utilizing a multi-channel approach to distribute a cross-platform clipboard hijacker designed to steal cryptocurrency. The campaign leverages… Dark Reading · Jun 22, 2026 High USclipboard hijackingreputation manipulationcrypto theft
threat-intel He Thought He Was Secure; His Phone Number Got Stolen Anyway This article details a real-world incident where cybersecurity expert Torsten George was targeted by a SIM swap attack, highlighting the vulnerability of relying solely on one-time passwords (OTPs) for security. The atta… Dark Reading · Jun 22, 2026 High USUKAUsim swapotpsocial engineering
threat-intel A Glimpse into the “Search Your Target” Market for Stolen Credentials This report details a growing underground market where threat actors are offering ‘search your target’ services, leveraging massive collections of stolen credentials. Researchers analyzed 470 forum posts revealing a serv… BleepingComputer · Jun 22, 2026 High UScredential theftinfostealerunderground market
threat-intel Stop Your Legacy Infrastructure from Hijacking Your AI Agents This article highlights a significant security risk: attackers leveraging legacy infrastructure to compromise AI agent environments. Despite organizations investing heavily in securing AI workloads against direct attacks… The Hacker News · Jun 22, 2026 High CVE-2025-24813USailegacypermissions
threat-intel What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks Recent breaches attributed to the ShinyHunters cybercrime collective, including attacks on organizations like University of Nottingham and Medtronic, highlight a shift in cyberattack tactics. Attackers are increasingly t… SecurityWeek · Jun 22, 2026 High UKidentity-theftcredential-theftmfa
malware A VBScript campaign distributed through WhatsApp deploying RMM software A WhatsApp-distributed malware campaign, active as of June 2026, leverages deceptive VBScript files disguised as financial documents to trick users into executing malicious code. This code ultimately installs legitimate… Securelist · Jun 22, 2026 High MYBRINsocial engineeringvbswhatsapp
threat-intel Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices Canadian spy agency, CSIS, utilized a novel court-ordered warrant to neutralize two foreign-run botnets operating within Canada. The operation targeted infected servers, SOHO routers, and IoT devices like Ring doorbells… The Hacker News · Jun 22, 2026 High CAUSbotnetiotcybersecurity
threat-intel INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific A new INTERPOL report highlights a significant surge in cybercrime across the Asia-Pacific region, driven by factors like digitalization and evolving criminal tactics. Phishing remains the most prevalent threat, alongsid… The Hacker News · Jun 22, 2026 High UKCALAphishingransomwareai
data-breach Texas Parks & Wildlife Data Breach Affects 3 Million Individuals Hackers stole personal information after breaching the systems of a third-party license vendor serving TPWD. The post Texas Parks & Wildlife Data Breach Affects 3 Million Individuals appeared first on SecurityWeek . SecurityWeek · Jun 22, 2026 High
malware AryStinger botnet infected thousands of D-Link routers worldwide A new botnet, named AryStinger, has been discovered compromising over 4,000 outdated D-Link routers worldwide, turning them into proxies for malicious traffic. The malware utilizes multiple vulnerabilities to perform sca… BleepingComputer · Jun 21, 2026 High CVE-2013-3307CVE-2016-5681CVE-2025-11837KRCNSErouterbotnetdns
ransomware New Prinz Eugen ransomware prioritizes recent files for encryption A new ransomware variant, Prinz Eugen, is targeting organizations with a focus on encrypting recently modified files to maximize disruption. The group employs a hands-on-keyboard approach, utilizing legitimate RMM tools… BleepingComputer · Jun 20, 2026 High GBransomwarerdpencryption
supply-chain Microsoft links Mastra AI supply chain attack to North Korean hackers Microsoft has attributed a recent supply chain attack targeting over 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. The attack involved compromising an npm maintainer account… BleepingComputer · Jun 20, 2026 High KPsupply-chainnpmcryptocurrency
supply-chain Klue OAuth breach victim list grows as Icarus hackers claim attack A security breach at Klue, a market intelligence platform, has resulted in the theft of OAuth tokens used to connect to customer Salesforce environments. The attack, attributed to the ‘Icarus’ extortion group, impacted m… BleepingComputer · Jun 19, 2026 High USoauthsalesforcedata breach
threat-intel Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain Researchers at Paradigm Shift have developed ‘usbliter8’, an exploit that allows arbitrary code execution within the SecureROM of Apple’s A12 and A13 chips. The exploit leverages a hardware flaw in the Synopsys DWC2 USB… The Hacker News · Jun 19, 2026 High USsecureromusbdfu
ransomware The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes The Gentlemen ransomware-as-a-service (RaaS) operation is utilizing a sophisticated suite of EDR-terminating tools, centered around the GentleKiller framework, to disable security defenses before deploying ransomware. Th… The Hacker News · Jun 19, 2026 High RUSOWEransomware-as-a-serviceedr-killingbyovd
data-breach Texas govt data breach exposes over 3 million driver’s licenses The Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its license system vendor that exposed personal information for more than three million individuals. BleepingComputer · Jun 19, 2026 High
threat-intel AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Researchers at Microsoft have identified a vulnerability, dubbed AutoJack, within the AutoGen Studio prototyping interface for their AutoGen multi-agent framework. The flaw allows an attacker to hijack an AI browsing age… The Hacker News · Jun 19, 2026 High CVE-2026-26030CVE-2026-25592remote code executionai agentlocalhost
vulnerability In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum This week’s cybersecurity news highlights several significant vulnerabilities and attacks across various platforms and industries. A critical phpBB flaw enabled session hijacking, while vulnerabilities in Chrome extensio… SecurityWeek · Jun 19, 2026 High CVE-2025-20701CHISsession hijackingchrome extensionssupply chain attack