vulnerability Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw A critical vulnerability, CVE-2026-55200, has been discovered in libssh2, a client-side SSH library embedded in various applications like curl, Git, and PHP. The flaw allows for code execution via an integer overflow, po… The Hacker News · Jun 29, 2026 Critical CVE-2026-55200CVE-2019-3855CVE-2026-55199GBsshlibssh2code execution
threat-intel New Initiative Tackles Security for End-of-Life Open Source Software This article discusses a new initiative, the Open Source Sustainability Initiative (OSSI), launched by the Commonhaus Foundation to address the growing challenge of managing and securing end-of-life (EOL) open-source sof… Dark Reading · Jun 26, 2026 High USend-of-lifevulnerabilitiesopen source
threat-intel SMB cyber readiness: the road to resilience starts here A recent ESET report reveals that while small and medium-sized businesses (SMBs) are increasingly confident in their cybersecurity budgets and preparedness, a significant number still struggle with implementing effective… WeLiveSecurity · Jun 26, 2026 Medium cybersecuritysmbphishing
threat-intel In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw A critical vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager (CUCM) has been rapidly weaponized by attackers within 24 hours of a proof-of-concept release. The SSRF flaw allows unauthenticated remote… Dark Reading · Jun 25, 2026 Critical CVE-2026-20230USssrfprivilege escalationcisco
vulnerability OHIF Viewers DICOM This advisory details a vulnerability in the OHIF Viewers DICOM framework, specifically versions up to v3.12.0, that allows attackers to steal authenticated user tokens via crafted links. The vulnerability stems from unc… CISA Advisories · Jun 25, 2026 High CVE-2026-12473USssrfdicomweboidc
threat-intel Scattered Spider Hackers Plead Guilty on Day 1 of Trial Two key members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, have pleaded guilty to criminal charges related to attacks against Transport for London and other organizations. The group, led by… Krebs on Security · Jun 23, 2026 High UKUSGBphishingransomwaresim swapping
threat-intel Scattered Spider members plead guilty to hacking Transport for London Two members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, have pleaded guilty to hacking the Transport for London (TfL) systems in 2024, resulting in significant operational disruptions and fi… BleepingComputer · Jun 23, 2026 High UKcyberattackcritical infrastructuredata breach
threat-intel SocGholish Takedown Highlights Malicious TDS Threats A coordinated international law enforcement operation, part of Operation Endgame, successfully disrupted SocGholish, a decade-old malware framework used as an initial-access broker by cybercriminal groups like Evil Corp.… Dark Reading · Jun 23, 2026 High NLtdssmalwareaffiliate
threat-intel Two Scattered Spider members plead guilty over cyberattack that crippled London transit Two members of the Scattered Spider cybercrime gang have pleaded guilty to a prolonged cyberattack against London's transport authority, resulting in significant disruption and data exposure. The attack, which occurred i… The Record · Jun 23, 2026 High UKUScyberattacklondondata breach
threat-intel What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks Recent breaches attributed to the ShinyHunters cybercrime collective, including attacks on organizations like University of Nottingham and Medtronic, highlight a shift in cyberattack tactics. Attackers are increasingly t… SecurityWeek · Jun 22, 2026 High UKidentity-theftcredential-theftmfa
phishing ISC Stormcast For Monday, June 22nd, 2026 https://isc.sans.edu/podcastdetail/9980, (Mon, Jun 22nd) The SANS Internet Storm Center's June 22nd, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observ… SANS Internet Storm Center · Jun 22, 2026 Medium phishingemailthreat
threat-intel Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites An international law enforcement operation, dubbed Operation Endgame, successfully disrupted SocGholish’s infrastructure and removed malware from nearly 15,000 WordPress websites. The takedown, involving agencies from mu… The Hacker News · Jun 19, 2026 High NLCADEbotnetwordpressmalware
phishing Webinar: How attackers bypass MFA and how defenders can respond The article discusses a growing trend in cyberattacks where attackers bypass multi-factor authentication (MFA) through sophisticated phishing techniques, specifically Device Code phishing. These attacks exploit legitimat… BleepingComputer · Jun 19, 2026 High phishingmfaaccount takeover
threat-intel CISA warns Fortinet users to secure devices after FortiBleed leak CISA has issued a warning to Fortinet customers regarding the "FortiBleed" data leak, which exposed nearly 74,000 firewall and VPN credentials. Threat actors are exploiting these compromised credentials to target interne… BleepingComputer · Jun 19, 2026 High USRUCNcredentialsvpnfirewall
threat-intel Novo Nordisk Breach Exposes Software Development Pipeline Risk A breach at Novo Nordisk, facilitated by a leaked GitHub token, exposed a significant amount of sensitive data, including patient clinical trial information, healthcare professional records, and proprietary drug developm… Dark Reading · Jun 18, 2026 High DKgithubsecretssupply-chain
ransomware INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023 INC ransomware has grown into a significant RaaS threat, impacting over 830 organizations since August 2023. The group leverages a combination of established techniques, including credential dumping from Veeam backups an… The Hacker News · Jun 18, 2026 High CVE-2023-3519CVE-2025-5777CVE-2023-48788USransomware-as-a-servicecredential dumpinglateral movement
threat-intel 5 reasons Microsoft 365 backup isn’t enough for business data protection This article highlights the limitations of relying solely on Microsoft 365’s built-in backup and retention policies for business data protection. It argues that organizations need a third-party solution to adequately add… BleepingComputer · Jun 18, 2026 High ransomwarebackupdata protection
vulnerability Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT This CISA advisory details a vulnerability in the Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT, specifically version 0x0110_v1.1.0. The device is susceptible to unauthorized interception of sensitive health… CISA Advisories · Jun 18, 2026 High CVE-2026-50034CVE-2026-52866INbluetoothbleglucose
threat-intel EU Gets a Head Start in Developing 6G Network Security The EU is launching the "Shield-6G" project, a collaborative initiative funded by the EU, to proactively develop cybersecurity measures for the upcoming 6G network. This project, involving 19 organizations, aims to addre… Dark Reading · Jun 18, 2026 Medium EU6gaicybersecurity
ransomware INC Ransomware Thrives by Mastering the Basics The INC ransomware group has emerged as a significant threat, particularly thriving through a focus on established ransomware-as-a-service (RaaS) tactics and targeting sectors with high pressure to pay, such as healthcar… Dark Reading · Jun 17, 2026 High CVE-2025-5777CVE-2024-57727CVE-2023-3519UKraasransomwareextortion