threat-intel ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm A sprawling Android botnet called Popa, used for advertising fraud, account takeovers, and data scraping, has been linked to NetNut, a residential proxy provider operated by Alarum Technologies Ltd. Researchers discovere… Krebs on Security · Jun 18, 2026 High ISbotnetproxyandroid
threat-intel Salesforce Data Thefts Continue via Klue App Compromise A series of data thefts targeting Salesforce instances have been linked to a new threat actor group, Icarus, following a compromise of Klue's Battlecards app. The attacks leveraged compromised OAuth tokens and Python scr… Dark Reading · Jun 18, 2026 High USoauthsaasdata exfiltration
threat-intel ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories This week’s ThreatDay Bulletin highlights several concerning security incidents, including browser extension abuse, macOS malware attacks, AI-powered malware delivery, and a global phishing campaign targeting travel book… The Hacker News · Jun 18, 2026 High CVE-2026-20127CVE-2026-49975USCNJPbrowser extensionsmacos malwareai abuse
malware Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 Microsoft has detailed a new Windows-based malware campaign, dubbed Windows Clipper, that leverages USB LNK files and a Tor-based command-and-control infrastructure to steal cryptocurrency data. The clipper silently moni… The Hacker News · Jun 18, 2026 High clipboardtorusb
ransomware Australian sugar producer works to restore operations as ransomware group claims attack Mackay Sugar, a major Australian sugar producer, experienced a significant disruption due to a ransomware attack claimed by the Gentlemen group. The attack impacted their operations, halting sugar production in Queenslan… The Record · Jun 18, 2026 High AUransomwareaustraliasugar
data-breach Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks A recent breach at Klue, a market intelligence platform, allowed the "Icarus" threat actor to steal Salesforce CRM data from multiple organizations, triggering an ongoing extortion campaign. The attackers leveraged stole… BleepingComputer · Jun 18, 2026 High USoauthsalesforcedata theft
ransomware INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023 INC ransomware has grown into a significant RaaS threat, impacting over 830 organizations since August 2023. The group leverages a combination of established techniques, including credential dumping from Veeam backups an… The Hacker News · Jun 18, 2026 High CVE-2023-3519CVE-2025-5777CVE-2023-48788USransomware-as-a-servicecredential dumpinglateral movement
threat-intel 5 reasons Microsoft 365 backup isn’t enough for business data protection This article highlights the limitations of relying solely on Microsoft 365’s built-in backup and retention policies for business data protection. It argues that organizations need a third-party solution to adequately add… BleepingComputer · Jun 18, 2026 High ransomwarebackupdata protection
ransomware DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic A U.S. services firm was targeted by the DragonForce ransomware group, who utilized a custom Go-based RAT, Backdoor.Turn, to conceal C2 traffic within Microsoft Teams relay infrastructure. The attackers leveraged a BYOVD… The Hacker News · Jun 18, 2026 High CVE-2023-52271CVE-2025-61155CVE-2025-1055USturnbyovdghost calls
malware Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group. BleepingComputer · Jun 18, 2026 High
supply-chain Accenture to Acquire Majority Stake in Dragos, All of runZero, NetRise in $4.1 Billion OT Cybersecurity Push Accenture is undertaking a significant investment in operational technology (OT) cybersecurity through a series of acquisitions, totaling approximately $4.1 billion. This includes a majority stake in Dragos, along with t… SecurityWeek · Jun 18, 2026 High USot securityindustrial control systemsasset discovery
threat-intel Get Out of Security Debt by Tackling the Exposure Problem This Dark Reading article discusses the growing problem of ‘security debt’ – vulnerabilities that remain open in systems for extended periods. It argues that organizations need to shift their focus from simply tracking a… Dark Reading · Jun 18, 2026 High risk managementvulnerability managementsecurity debt
supply-chain ShapedPlugin update flow hacked to infect WordPress sites A supply-chain attack targeting WordPress plugins from ShapedPlugin resulted in malicious updates containing a backdoor designed to steal sensitive data from affected websites. The attack exploited a compromised build pi… BleepingComputer · Jun 18, 2026 High CVE-2026-10735CVE-2026-49777wordpresssupply chainbackdoor
Apple fixes Beats Studio Buds flaw that let hackers spy on conversations Apple has released security updates to patch a high-severity flaw affecting the Beats Studio Buds wireless earbuds that could allow attackers in Bluetooth range to spy on users' conversations. BleepingComputer · Jun 18, 2026 High CVE-2025-20701CVE-2025-20700CVE-2025-20702
vulnerability Schneider Electric EasyLogic T150 and Saitel DP This advisory details a vulnerability (CVE-2026-6865) affecting Schneider Electric’s EasyLogic T150 and Saitel DP Remote Terminal Units & Controllers. The vulnerability, a CWE-22 ‘Path Traversal’ flaw, allows an attacker… CISA Advisories · Jun 18, 2026 High CVE-2026-6865FRpath traversalfirmwareremote terminal unit
vulnerability Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT This CISA advisory details a vulnerability in the Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT, specifically version 0x0110_v1.1.0. The device is susceptible to unauthorized interception of sensitive health… CISA Advisories · Jun 18, 2026 High CVE-2026-50034CVE-2026-52866INbluetoothbleglucose
vulnerability Mitsubishi Electric MELSEC iQ-F Series This advisory from CISA details a vulnerability (CVE-2026-8805) in the Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module. The vulnerability, stemming from an integer overflow, allows a remote attacker to… CISA Advisories · Jun 18, 2026 High CVE-2026-8805JPethernet/ipdenial of serviceinteger overflow
vulnerability AzeoTech DAQFactory This advisory details a Type Confusion vulnerability (CVE-2026-12390) in AzeoTech DAQFactory versions up to 21.1, allowing for potential arbitrary code execution via specially crafted .ctl files. The vulnerability affect… CISA Advisories · Jun 18, 2026 High CVE-2026-12390UStype confusioncwe843code execution
vulnerability Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products Schneider Electric has identified a vulnerability (CVE-2026-4827) in several of its industrial automation products, including Easergy, EcoStruxture, PowerLogic, and Saitel systems. The vulnerability, a CWE-331 Insufficie… CISA Advisories · Jun 18, 2026 High CVE-2026-4827upsindustrial controlsession management
vulnerability Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module This advisory from CISA details a denial-of-service (DoS) vulnerability in Mitsubishi Electric's MELSEC iQ-F Series FX5-ENET/IP Ethernet Module. The vulnerability, CVE-2026-8806, allows a remote attacker to overwhelm the… CISA Advisories · Jun 18, 2026 High CVE-2026-8806JPdenial-of-serviceethernetcve-2026-8806