other Microsoft confirms Office apps launch issues after June updates Microsoft is investigating a widespread issue affecting third-party applications after June 2026 updates to Windows, preventing them from launching or opening Microsoft Office applications. The problem stems from compati… BleepingComputer · Jun 17, 2026 Medium UScompatibilitywindows updateoffice apps
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
threat-intel AI Use by the US Government This article details the widespread and largely undocumented use of Artificial Intelligence (AI) by the US government under both the Trump and Biden administrations. The Office of Management and Budget (OMB) revealed a m… Schneier on Security · Jun 17, 2026 Medium USaigovernmentautomation
phishing FTC warns of record $3.5 billion losses to imposter scams in 2025 The U.S. Federal Trade Commission (FTC) reported a record $3.5 billion in losses attributed to imposter scams in 2025, representing a significant increase from 2020. These scams, primarily leveraging social media, target… BleepingComputer · Jun 16, 2026 High USscamsfraudsocial media
threat-intel Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails A China-linked espionage group, UNC6508, gained access to North American medical, academic, and military research networks via a backdoor on REDCap servers, stealing sensitive research and defense emails. The attackers e… The Hacker News · Jun 15, 2026 High CHUSCAespionageredcapgoogle workspace
threat-intel HTTP/2 Bomb Attacks Put Telcos, Healthcare Orgs at Risk This article reports on the ‘HTTP/2 Bomb’ vulnerability, a denial-of-service exploit leveraging features within the HTTP/2 protocol to amplify junk traffic and cause widespread disruptions. The vulnerability affects a si… Dark Reading · Jun 15, 2026 High CVE-2026-49975UShttp2ddosamplification
threat-intel China-Nexus Actor Spied on US Researchers Undetected for a Year Google’s Threat Intelligence Group (GTIG) discovered and disrupted a year-long espionage campaign by the China-Nexus threat actor, UNC6508, targeting US academic, medical, and military research institutions. The actor ut… Dark Reading · Jun 15, 2026 High CHUScyber espionageintel gatheringcredential theft
threat-intel Chinese hackers breach REDCap servers, steal medical research A Chinese espionage campaign, attributed to UNC6508, targeted a North American medical research institution by exploiting vulnerabilities in the REDCap platform. The attackers deployed the custom malware, ‘Infinitered,’… BleepingComputer · Jun 15, 2026 High CHUSCAespionagecredential_theftredcap
data-breach Bankruptcy admin approves settlement fund of $47 million for 23andMe data breach victims A bankruptcy court has approved a $46.8 million settlement for approximately 7 million 23andMe customers affected by a 2023 data breach. Hackers accessed sensitive genetic data, including DNA Relatives profiles and Famil… The Record · Jun 12, 2026 High USdata breachdnagenetic data
vulnerability Microsoft ships largest Patch Tuesday on record, with one bug under active attack Microsoft released its largest Patch Tuesday update to date, containing 206 CVEs, driven by the increasing use of AI in vulnerability discovery. A particularly concerning vulnerability, CVE-2026-45657, is described as ‘w… The Record · Jun 10, 2026 Critical CVE-2026-45657CVE-2026-41091CVE-2026-50507UKpatch tuesdayvulnerabilityai
threat-intel Unpacking SMB cyber-readiness – and what makes or breaks it A recent ESET report, alongside Verizon's DBIR, highlights a significant disconnect between SMBs' confidence in their cyber resilience and their actual preparedness. Despite a high percentage (75%) believing they can abs… WeLiveSecurity · Jun 10, 2026 High cybersecurityrisk managementincident response
threat-intel The Invisible Battlefield: How Cyber War Is Reshaping Everyday Life This article, authored by former National Cyber Director Chris Inglis, highlights the evolving nature of cyber warfare, arguing that it’s no longer a technical issue confined to IT departments but a central arena for nat… Dark Reading · Jun 9, 2026 High UScybersecuritycyberwarfarecritical infrastructure
threat-intel Everybody Is Vibe Coding But Nobody Told the Security Team This article discusses the emerging security challenges posed by "vibe coding," a new approach to software development heavily reliant on AI-assisted tools. Rapid, AI-driven application development, particularly using pl… SecurityWeek · Jun 8, 2026 High UKaivibe-codingshadow-ai
vulnerability Check Point links VPN zero-day attacks to Qilin ransomware gang Check Point identified a zero-day vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access deployments, exploited by the Qilin ransomware gang. The flaw allowed unauthenticated attackers to bypass authen… BleepingComputer · Jun 8, 2026 High CVE-2026-50751CVE-2026-50752ISJAAUzero-dayvpnauthentication
threat-intel Anthropic Urges Industry Coordination to Allow for a ‘Pause’ in AI Development if Risks Grow Anthropic is advocating for a global pause in the development of advanced AI systems due to concerns about rapidly increasing capabilities and the potential for losing control. The company proposes coordinated action amo… SecurityWeek · Jun 8, 2026 High CAartificial intelligenceai safetycybersecurity
threat-intel In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA This week’s cybersecurity news highlights a range of threats, including AI-powered attacks targeting computing power, ongoing Grandoreiro banking trojan campaigns, and a self-propagating ransomware group utilizing obfusc… SecurityWeek · Jun 5, 2026 High IRUSairansomwaresupply chain
threat-intel Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP) This article discusses the growing problem of ‘identity dark matter’ – unseen identity activity within enterprise systems due to fragmented IAM and a lack of visibility. Gartner has introduced the Identity Visibility and… The Hacker News · Jun 3, 2026 Medium identity managementvisibilityanalytics
vulnerability Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches A critical vulnerability (CVE-2026-0826) has been identified in HP Poly Voice VoIP phone models, allowing for remote code execution with root privileges. The flaw, triggered by a stack-based buffer overflow when processi… SecurityWeek · Jun 2, 2026 Critical CVE-2026-0826USvoipbuffer overflowremote code execution
data-breach California AG sues 23andMe over 2023 breach exposing health data 23andMe faced a significant data breach in 2023, exposing the personal and genetic information of nearly 7 million customers, including a large number in California. The breach stemmed from a credential-stuffing attack a… BleepingComputer · May 29, 2026 High USdata breachgenetic datacredential stuffing
data-breach California Sues 23andMe, Alleging It Failed to Protect User Data in 2023 Breach California’s Attorney General has filed a lawsuit against 23andMe, alleging a significant data breach in 2023 that exposed the personal information of nearly 7 million users. The lawsuit highlights 23andMe’s lax security… SecurityWeek · May 29, 2026 High USdata breachgenetic datapassword security