threat-intel Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites An international law enforcement operation, dubbed Operation Endgame, successfully disrupted SocGholish’s infrastructure and removed malware from nearly 15,000 WordPress websites. The takedown, involving agencies from mu… The Hacker News · Jun 19, 2026 High NLCADEbotnetwordpressmalware
threat-intel CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices CISA has issued a warning to Fortinet customers regarding FortiBleed, a campaign targeting 86,644 FortiGate devices globally. The attack, attributed to Russian-speaking threat actors, leverages a two-step approach involv… The Hacker News · Jun 19, 2026 High USINMEcredential_stuffingdefault_credentialspassword_reuse
phishing Imposter scams cost Americans $3.5 billion in 2025 – and it’s getting worse Imposter scams have surged in the United States, resulting in a staggering $3.5 billion in financial losses for consumers in 2025. These scams typically involve fraudulent impersonations of trusted entities like banks an… Graham Cluley · Jun 19, 2026 High USscamsfraudidentity theft
threat-intel Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way This article highlights a growing security risk within organizations due to the widespread adoption of AI agents. Traditional identity security models, built around controlling employee and service accounts, are being by… BleepingComputer · Jun 19, 2026 High aiartificial intelligenceidentity management
phishing Webinar: How attackers bypass MFA and how defenders can respond The article discusses a growing trend in cyberattacks where attackers bypass multi-factor authentication (MFA) through sophisticated phishing techniques, specifically Device Code phishing. These attacks exploit legitimat… BleepingComputer · Jun 19, 2026 High phishingmfaaccount takeover
threat-intel From Assistive to Agentic: The AI Shift That's Redefining Threat Management This article discusses the shift in cybersecurity necessitated by the rapid advancements in AI, particularly frontier AI models. Traditional security architectures, reliant on manual processes and siloed tools, are strug… The Hacker News · Jun 19, 2026 High USaictemthreat intelligence
vulnerability CryptoBandits Malware Doubles as a Backdoor, Abuses Tor CryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution. The post CryptoBandits Malware Doubles as a Backdoor, Abuses Tor appeared first on SecurityWeek . SecurityWeek · Jun 19, 2026 High
threat-intel Anthropic’s Fable and the State of AI Anthropic’s Fable AI model, designed to identify vulnerabilities in code, has sparked concern due to its capabilities and the potential for misuse. The US government classified it as a dangerous munition and restricted a… Schneier on Security · Jun 19, 2026 High UKUSCZaivulnerabilitycybersecurity
threat-intel Forget Data Leakage: Shadow AI's Real Threat Is Access Control This article highlights a shift in the security landscape surrounding AI, moving beyond simple data leakage concerns to a more critical issue of access control. Employees are increasingly deploying custom AI agents acros… The Hacker News · Jun 19, 2026 High USaishadow itaccess control
supply-chain Cybersecurity Firms Impacted by Klue Supply Chain Attack A supply chain attack targeting the Klue market intelligence platform resulted in the unauthorized harvesting of customer data from various integrations, including Salesforce and HubSpot. The attack, attributed to a new… SecurityWeek · Jun 19, 2026 High supply-chainoauthcrm
threat-intel Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data Salesforce disabled the Klue Battlecards app integration following a security incident where the Icarus extortion group exploited compromised credentials to access customer data via Salesforce. The attackers leveraged a… The Hacker News · Jun 19, 2026 High USoauthcredentialdata-exfiltration
threat-intel NY man charged after harassing college student with AI-generated nudes A New York man, Anthony Belford, has been charged with cyberstalking after using AI-generated nude images and fabricated messages to harass a college student following a transfer. The investigation revealed the use of nu… BleepingComputer · Jun 19, 2026 High USGAILaicyberstalkingharassment
threat-intel CISA warns Fortinet users to secure devices after FortiBleed leak CISA has issued a warning to Fortinet customers regarding the "FortiBleed" data leak, which exposed nearly 74,000 firewall and VPN credentials. Threat actors are exploiting these compromised credentials to target interne… BleepingComputer · Jun 19, 2026 High USRUCNcredentialsvpnfirewall
malware 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame. The post 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown appeared first on SecurityWe… SecurityWeek · Jun 19, 2026 High
vulnerability Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution. The post Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosu… SecurityWeek · Jun 19, 2026 High CVE-2026-20253
ransomware Gentlemen ransomware uses multiple EDR killers to disable defenses The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. BleepingComputer · Jun 18, 2026 High
threat-intel Novo Nordisk Breach Exposes Software Development Pipeline Risk A breach at Novo Nordisk, facilitated by a leaked GitHub token, exposed a significant amount of sensitive data, including patient clinical trial information, healthcare professional records, and proprietary drug developm… Dark Reading · Jun 18, 2026 High DKgithubsecretssupply-chain
threat-intel Bulgaria allowed surveillance tech firm to sell products to repressive regimes, report says A report by Human Rights Watch revealed that Bulgaria allowed a surveillance technology firm, Circles, to sell its products – including Pixcell, Landmark, and Voice Over Location Enabler software – to repressive regimes… The Record · Jun 18, 2026 High BUELUAsurveillancespywareexport control
apt Operation Escaneo Signals Shift in LatAm Threat Landscape Operation Escaneo, a coordinated cyber campaign led by the MexicanMafia/PanchoVilla threat actor, represents a significant shift in the threat landscape of Latin America. The campaign, spanning 2025-2026, targeted critic… Dark Reading · Jun 18, 2026 High CVE-2022-42475CVE-2023-27997CVE-2024-21762MXECPTlatin americareconnaissancedata exfiltration
data-breach Nintendo confirms data stolen in WebMD subsidiary cyberattack Nintendo of America experienced a data breach following a cyberattack on its internal employee survey platform, TinyPulse, operated by WebMD’s subsidiary. Threat actor Shadowbyt3$ stole survey data and employee personal… BleepingComputer · Jun 18, 2026 High USemployee datasurvey dataransomware