threat-intel Phishing Attack Volume Down 20%, but Risk Still Rising The volume of phishing attacks has decreased by 20% across multiple industries, despite a shift towards more sophisticated attacks utilizing AI. Threat actors are prioritizing targeted campaigns with higher conversion ra… Dark Reading · Jun 12, 2026 High CAESAUphishingaicloud
vulnerability ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities The ShinyHunters extortion group exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft to gain unauthorized access to university systems, resulting in data theft and a demand for payment. Mandiant iden… The Hacker News · Jun 11, 2026 High CVE-2026-35273GBUSzero-dayexploitationuniversity
threat-intel A tale of two eras This article is a reflective piece by a cybersecurity analyst reminiscing about early technology and highlighting a critical shift in the threat landscape. The author uses a personal anecdote about a childhood discovery… Cisco Talos · Jun 11, 2026 High USaivulnerabilitycybersecurity
threat-intel New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets A research report highlighted vulnerabilities in OpenClaw, a popular self-hosted AI agent, revealing that attackers could trick the agent into running malicious code or leaking sensitive data by embedding instructions wi… The Hacker News · Jun 11, 2026 High USaiagentprompt injection
ransomware The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm The Gentlemen ransomware group, initially operating as the affiliate-focused Phantom Mantis, has evolved into an independent RaaS operation led by the cybercriminal LARVA-368 (aka hastalamuerte). The group, responsible… The Hacker News · Jun 11, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073RUTHUKransomware-as-a-servicedouble extortionaffiliate program
Cyber Force not included in Senate defense policy roadmap An amendment by Sen. Kirsten Gillibrand (D-NY) to the chamber’s fiscal 2027 national defense authorization bill that would have created the digital-focused service was defeated 14-13 when the Senate Armed Services Commit… The Record · Jun 11, 2026 High
ransomware Authorities dismantle 'AudiA6' ransomware crypto-laundering service Law enforcement agencies have successfully dismantled the ‘AudiA6’ cryptocurrency service, which was used to launder over $380 million generated from ransomware attacks and other cybercriminal activities. The operation,… BleepingComputer · Jun 11, 2026 High POUKGEcryptocurrencyransomwaremoney laundering
ransomware Silent Ransom Group: what you need to know The Silent Ransom Group is employing a novel and highly disruptive extortion tactic, shifting away from purely digital attacks. They are proactively contacting victims' employees via phone, impersonating IT support, and… Graham Cluley · Jun 11, 2026 High ransomwaresocial-engineeringusb-drive
threat-intel Segmentation Works for OT If Operators Are Paying Attention This Dark Reading article highlights the ongoing challenges of operational technology (OT) security, particularly concerning network segmentation. Despite the widely recommended practice of isolating systems to limit dam… Dark Reading · Jun 11, 2026 High ot securitynetwork segmentationcybersecurity
threat-intel Why AI-driven threats are exposing the limits of MSP security stacks This article highlights how artificial intelligence (AI) is dramatically accelerating the pace and scale of cyberattacks, exposing the vulnerabilities of fragmented security stacks, particularly for Managed Service Provi… BleepingComputer · Jun 11, 2026 High USaiautomationmsps
threat-intel Alert Fatigue Is Becoming a Security Threat of Its Own This article highlights the growing threat of alert fatigue within Security Operations Centers (SOCs). The overwhelming volume of alerts generated by security tools, often lacking context and prioritization, is leading t… SecurityWeek · Jun 11, 2026 High alert fatiguesocai
threat-intel ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories This week’s threat intelligence bulletin highlights several concerning developments, including a large-scale leak of identity records facilitated by infostealers, the emergence of a sophisticated MaaS RAT named SilabRAT… The Hacker News · Jun 11, 2026 High CVE-2026-49494USCHNOinfostealersmaas ratcredential theft
threat-intel CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk CISA has issued Binding Operational Directive 26-04, requiring federal agencies to prioritize patching security vulnerabilities based on risk, building upon previous efforts established in 2021. This directive focuses on… SecurityWeek · Jun 11, 2026 High vulnerabilitypatchingrisk
malware OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month The OnyxC2 stealer, offered as a "Malware-as-a-Service" (MaaS) product for $250-$500 per month, is a sophisticated tool designed for enterprise-level credential theft. Developed by BlackFog, it boasts a wide range of tar… SecurityWeek · Jun 11, 2026 High USstealercredential theftmalware-as-a-service
data-breach Coupang hit with record $409 million data breach fine in Korea Coupang, a major South Korean e-commerce company, has been hit with a record $409 million fine by the Personal Information Protection Commission (PIPC) due to a massive data breach affecting over 37 million customers. Th… BleepingComputer · Jun 11, 2026 High SOCHdata breachauthenticationdata security
threat-intel Yarbo Android/iOS Mobile Application and Cloud Infrastructure A CISA advisory details a vulnerability in the Yarbo Android/iOS Mobile Application and Cloud Infrastructure, specifically related to hard-coded MQTT credentials. The application contains credentials that allow unauthori… CISA Advisories · Jun 11, 2026 High CVE-2026-10557CVE-2026-7368WOmqttcredentialsrobotics
vulnerability Hackers Exploit Langflow Vulnerability for Remote Code Execution Disclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system. The post Hackers Exploit Langflow Vulnerability for Remote Code Execution appeared first on S… SecurityWeek · Jun 11, 2026 High CVE-2026-5027
threat-intel AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS. The rapid advancement of AI, particularly through tools like Anthropic's Claude Mythos Preview, has dramatically reduced the time it takes to discover and exploit vulnerabilities in software. This has collapsed the tradi… The Hacker News · Jun 11, 2026 High USGBaivulnerabilityexploitation
threat-intel FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers The FBI has taken down thirteen websites used by Chinese intelligence operatives to target and recruit U.S. government employees with access to sensitive information. These websites impersonated consulting firms offering… SecurityWeek · Jun 11, 2026 High USCNespionagerecruitmentcybersecurity
Enhanced License Plate Tracking The surveillance company Leonardo wants more data : A surveillance company plans to add sensors to automatic license plate readers (ALPRs) that would mean the devices, as well as capture the license plate of passing vehi… Schneier on Security · Jun 11, 2026 High