vulnerability 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs Recent analysis reveals that three previously patched Fortinet FortiSandbox vulnerabilities – CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089 – are actively being exploited in the wild. A significant number of comprom… SecurityWeek · Jun 17, 2026 High CVE-2026-39808CVE-2026-39813CVE-2026-25089USINALvulnerabilitypatchingexploitation
supply-chain GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say A supply-chain worm, dubbed Shai-Hulud, is exploiting design flaws in GitHub to infect hundreds of software packages and developer accounts worldwide. The vulnerabilities, initially flagged by Deep Specter Research, were… The Record · Jun 16, 2026 High GBFRsupply chainvulnerabilitygithub
malware Fileless Phantom Stealer Targets Browser Credentials A new fileless malware, Phantom Stealer, is being deployed through targeted phishing campaigns against banks and high-value organizations. The malware focuses on stealing browser credentials and session cookies, utilizin… Dark Reading · Jun 16, 2026 High GBDEFRcredential theftbrowser securityfileless malware
threat-intel Security Community Slams US Ban on Exporting Mythos, Fable The US government recently imposed an export control order restricting access to Anthropic's Claude Fable 5 and Mythos 5 large language models (LLMs) for foreign nationals, citing national security concerns, particularly… Dark Reading · Jun 16, 2026 High USCHllmaiexport control
threat-intel Malicious JetBrains Marketplace plugins steal AI API keys from developers A coordinated malware campaign involving 15 malicious plugins for the JetBrains Marketplace was discovered, designed to steal AI API keys from developers. These plugins, disguised as AI coding assistants and code review… BleepingComputer · Jun 16, 2026 High USapi-keycredential-theftide
malware New Rokarolla Android malware targets 217 banking, crypto apps A new Android banking trojan, Rokarolla, is targeting 217 banking and cryptocurrency applications through deceptive app distribution and sophisticated data theft techniques. The malware leverages Accessibility permission… BleepingComputer · Jun 16, 2026 High androidbanking trojandata theft
supply-chain Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting A vulnerability in the Google Cloud Vertex AI SDK allowed attackers to hijack model uploads by exploiting predictable bucket naming conventions. Attackers could create a temporary bucket in their own project, intercept t… The Hacker News · Jun 16, 2026 High CVE-2026-2473USbucket squattingmodel uploadcloud storage
threat-intel SprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detection A new Windows variant of the SprySOCKS Linux backdoor, developed by the nation-state threat actor FishMonger (also known as Earth Lusca and Aquatic Panda), has been discovered targeting government organizations in Hondur… Dark Reading · Jun 16, 2026 High HNTWTHkernel-driveraptbackdoor
threat-intel ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures ClickFix campaigns are expanding their malware delivery tactics with new loaders, including BabaDeda Loader, Lorem Ipsum Loader, and Storage Crypter, targeting education and financial organizations. These attacks utilize… The Hacker News · Jun 16, 2026 High RUBYsocial engineeringloaderpayload
malware Rokarolla Android Trojan Levels Up to Full Device Control, Persistence The Rokarolla Android Trojan has evolved to offer full device control and persistence, moving beyond typical banking Trojan capabilities. Distributed through fake Chrome and TikTok downloads, the malware steals credentia… Dark Reading · Jun 16, 2026 High USandroidbanking trojandevice control
threat-intel 'Lorem Ipsum' Malware Pivots to ClickFix Delivery The 'Lorem Ipsum' malware campaign, initially delivered via Trojanized Microsoft Teams installers, has shifted its tactics following Microsoft's disruption of the Fox Tempest malware-signing-as-a-service provider. Now, t… Dark Reading · Jun 16, 2026 High USclickfixwordpressshellcode
threat-intel GhostTree Attack Abused Recursive Windows Junctions to Hide Malware Security researchers have discovered a novel technique, dubbed "GhostTree," used by attackers to evade detection by security tools. This method leverages recursive loops created using NTFS junctions to hide malicious fil… BleepingComputer · Jun 16, 2026 High USjunctionsntfsrecursion
phishing FTC warns of record $3.5 billion losses to imposter scams in 2025 The U.S. Federal Trade Commission (FTC) reported a record $3.5 billion in losses attributed to imposter scams in 2025, representing a significant increase from 2020. These scams, primarily leveraging social media, target… BleepingComputer · Jun 16, 2026 High USscamsfraudsocial media
malware New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds A new Android banking trojan, Rokarolla, has been identified by Zimperium, targeting over 200 banking and cryptocurrency apps. The malware utilizes techniques like fake login pages and Accessibility abuse to steal sensit… The Hacker News · Jun 16, 2026 High androidbanking trojanpin theft
vulnerability Rockwell Automation FLEX I/O EtherNet/IP Adapters This CISA advisory details vulnerabilities within Rockwell Automation’s FLEX I/O EtherNet/IP Adapters (versions 2.012) that could allow unauthorized access and potential loss of device availability. The issues include a… CISA Advisories · Jun 16, 2026 High CVE-2026-0646CVE-2026-0647USethernet/ipcontrol systemsmemory corruption
threat-intel Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP Rockwell Automation has identified a denial-of-service vulnerability (CVE-2026-11317) affecting several versions of its Logix 5370 and 5570 controllers. The vulnerability stems from a fault triggered by crafted CIP messa… CISA Advisories · Jun 16, 2026 High CVE-2026-11317USdenial-of-serviceciprockwell automation
vulnerability Rockwell Automation RSLinx Rockwell Automation has issued a security advisory regarding a vulnerability in its RSLinx Classic software. The flaw, a stack-based buffer overflow (CVE-2020-13573), allows for remote code execution and could lead to de… CISA Advisories · Jun 16, 2026 High CVE-2020-13573WObuffer overflowremote code executioncve-2020-13573
data-breach Cal Water Investigating Iranian Hackers’ Claims California Water Service (Cal Water) is currently investigating claims of a hack by the Iran-linked threat actor Handala, who allegedly stole and leaked sensitive data from the utility’s systems. The incident, potentiall… SecurityWeek · Jun 16, 2026 High USwater sectorcyberattackdata breach
threat-intel Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactive A recent study by Spur Intelligence found that anonymized infrastructure, primarily through VPNs and residential proxies, is now a dominant factor in nearly every security incident. Despite the abundance of IP data avail… The Hacker News · Jun 16, 2026 High USanonymizationip intelligencevpn
other Flock Cameras Are Being Used for Stalking Flock Cameras, a manufacturer of residential security cameras, is facing scrutiny due to reports of law enforcement agencies using their systems for excessive and potentially unlawful surveillance. Multiple cases across… Schneier on Security · Jun 16, 2026 High USsurveillanceprivacypolice