ransomware Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer Mackay Sugar, Australia's second-largest raw sugar producer, experienced a ransomware attack that disrupted operations at two of its cane-processing mills. The attack, attributed to the Gentlemen ransomware group (Storm-… SecurityWeek · Jun 15, 2026 High AUransomwareaustraliasugar
threat-intel One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes A vulnerability, dubbed SearchLeak, was discovered in Microsoft 365 Copilot Enterprise Search that allowed attackers to exfiltrate sensitive data like emails, calendar details, and MFA codes through a single click. The f… The Hacker News · Jun 15, 2026 High CVE-2026-42824CVE-2025-32711UScommand injectionprompt injectionbing
threat-intel The Beginning of the End of Social Engineering This article discusses a significant shift in cybersecurity driven by the integration of AI-native operating systems, particularly Google's Gemini and Apple's Apple Intelligence. Operating systems are evolving to activel… Dark Reading · Jun 15, 2026 High USaisocial engineeringauthentication
threat-intel Chinese hackers breach REDCap servers, steal medical research A Chinese espionage campaign, attributed to UNC6508, targeted a North American medical research institution by exploiting vulnerabilities in the REDCap platform. The attackers deployed the custom malware, ‘Infinitered,’… BleepingComputer · Jun 15, 2026 High CHUSCAespionagecredential_theftredcap
threat-intel ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More This week’s cybersecurity recap highlights several active exploits and attacks, including a Chrome 0-day being actively leveraged, a ShinyHunters gang exploiting a PeopleSoft zero-day for lateral movement and data exfilt… The Hacker News · Jun 15, 2026 High CVE-2026-11645CVE-2026-2441CVE-2026-3909UNCHzero-dayphishingsupply-chain
data-breach Maine forced to take down data breach portal after fake notices filed with authorities The US state of Maine has taken its public data breach notification portal offline after someone submitted fraudulent breach disclosures impersonating two well-known technology companies. Read more in my article on the H… Graham Cluley · Jun 15, 2026 High
data-breach Infinite Campus data breach affects 137,000 school staff accounts The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in M… BleepingComputer · Jun 15, 2026 High
threat-intel US Cracks Down on Anthropic AI Models Amid Abuse Concerns Anthropic has suspended access to its Fable 5 and Mythos 5 AI models following a US government export control directive, aimed at preventing foreign nationals from utilizing them. This action stems from growing concerns… Dark Reading · Jun 15, 2026 High CHRUUKaicybersecuritythreat intelligence
ransomware Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang. The post Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges appeared first on SecurityWeek . SecurityWeek · Jun 15, 2026 High
threat-intel The Onboarding Password Mistake That Creates Unnecessary Risk This article discusses the significant security risks associated with using temporary onboarding passwords, highlighting how they are frequently shared insecurely and remain active for extended periods. The practice crea… The Hacker News · Jun 15, 2026 High USIRonboardingcredentialssecurity
threat-intel French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker A breach of the French government’s secure messaging platform, Tchap, has resulted in the theft of personal data for over 70,000 government employees. The incident was initially attributed to a threat actor calling itsel… SecurityWeek · Jun 15, 2026 High FRdata-breachgovernmentcredential theft
malware 152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic A network of 152 Chrome extensions, collectively installed over 105,000 times, has been discovered distributing a potentially unwanted program (PUP) that generates fake traffic and logs user data. These extensions, masqu… The Hacker News · Jun 15, 2026 High TRadwarefake trafficprivacy
malware Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites A security incident has been discovered affecting over 1.2 million WordPress sites using the PushEngage, OptinMonster, and TrustPulse plugins. An attacker tampered with the plugins' JavaScript files, creating backdoors t… The Hacker News · Jun 15, 2026 High CVE-2026-10795USwordpresscdnbackdoor
threat-intel EvilTokens: A phishing attack that doesn’t steal your password EvilTokens is a sophisticated phishing-as-a-service (PaaS) kit that bypasses traditional phishing defenses by leveraging the OAuth 2.0 device authorization grant flow. Attackers use convincing lures – often mimicking leg… WeLiveSecurity · Jun 15, 2026 High phishingoath2device-code
data-breach Maine Disables Data Breach Portal Due to Fake Submissions Someone posted fake VRChat and Discord data breach reports on the system, prompting the Maine AG to take action. The post Maine Disables Data Breach Portal Due to Fake Submissions appeared first on SecurityWeek . SecurityWeek · Jun 15, 2026 High
phishing Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts A coordinated phishing campaign, spearheaded by the now-disrupted Sniper Dz platform, targeted users in the Middle East and North Africa (MENA) through deceptive Facebook offers. The campaign leveraged browser notificati… The Hacker News · Jun 15, 2026 High DZALAEphishingsocial engineeringbrowser notifications
phishing Belarus-linked hackers target Gmail accounts of Polish public figures and their families A Belarus-linked hacking group, GhostWriter (UNC1151/Storm-0257), has expanded its phishing operations to target the personal Gmail accounts of Polish public figures and their families. The group’s tactics involve creati… The Record · Jun 14, 2026 High PLBYUAphishingpolandbelarus
phishing FBI disrupts massive AI-powered phishing service using a million URLs The FBI, in collaboration with Google and Black Lotus Labs, successfully disrupted a large-scale Chinese phishing-as-a-service operation called Outsider Enterprise. This operation utilized AI to generate and distribute p… BleepingComputer · Jun 14, 2026 High CHphishingaisms
threat-intel Ex-school district employee jailed for hacks on former employer A former IT employee, Ezekiel Dean Potter, was sentenced to prison for a prolonged cyberattack against the Saydel Community School District. Potter exploited his previous access to disrupt operations, steal data, and cau… BleepingComputer · Jun 13, 2026 High UScyberattackdata-breachaccount-compromise
ransomware ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed A ShinyHunters ransomware group exploited a zero-day vulnerability in Oracle's PeopleSoft software suite to compromise over 300 instances across more than 100 organizations, primarily targeting higher education instituti… Dark Reading · Jun 12, 2026 High CVE-2026-35273USUKzero-daypeoplesoftransomware