data-breach 174,000 Impacted by Lansing Community College Data Breach Hackers accessed personal information stored on certain Lansing Community College systems in February 2025. The post 174,000 Impacted by Lansing Community College Data Breach appeared first on SecurityWeek . SecurityWeek · Jun 8, 2026 High
data-breach Oxford University discloses data breach after careers platform hack The University of Oxford disclosed a new data breach last week after being informed by its third-party provider, Group GTI, that its CareerConnect career services platform had been compromised. BleepingComputer · Jun 8, 2026 High
ransomware Silent Ransom Group Uses DNS Fast Flux in Attacks Focusing on hacking law firms in the US, the ransomware group relies on fast flux to hide its C&C infrastructure. The post Silent Ransom Group Uses DNS Fast Flux in Attacks appeared first on SecurityWeek . SecurityWeek · Jun 8, 2026 High
threat-intel VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances A China-based cyber espionage group, VerdantBamboo, deployed a BSD variant of the BRICKSTORM backdoor and the PLENET malware family on Linux appliances to target a victim organization. The attack involved exploiting vuln… The Hacker News · Jun 8, 2026 High CVE-2026-22769CHlinuxbackdoorespionage
threat-intel From cause to cash: a cross-border look at hacktivist activity This Securelist article details a cross-border hacktivist campaign led by groups including 4BID, with a broadened geographic scope impacting organizations in Kazakhstan, the UAE, Syria, and Egypt. The campaign utilized t… Securelist · Jun 8, 2026 High CVE-2023-44976KZAESYproxyshellransomwarehacktivism
threat-intel Anthropic Urges Industry Coordination to Allow for a ‘Pause’ in AI Development if Risks Grow Anthropic is advocating for a global pause in the development of advanced AI systems due to concerns about rapidly increasing capabilities and the potential for losing control. The company proposes coordinated action amo… SecurityWeek · Jun 8, 2026 High CAartificial intelligenceai safetycybersecurity
threat-intel UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign UNC3753, also known as Chatty Spider and the Silent Ransom Group, is a threat actor engaged in a financially motivated data theft and extortion campaign targeting organizations in the U.S. between January and May 2026. T… The Hacker News · Jun 8, 2026 High USvishingsocial engineeringdata exfiltration
threat-intel Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse Meta has reported that approximately 20,000 Instagram accounts were compromised due to abuse of its AI-powered account recovery tool, High Touch Support (HTS). Hackers exploited a vulnerability in the tool to reset passw… SecurityWeek · Jun 8, 2026 High aiaccount recoverypassword reset
data-breach Over 20,000 Instagram accounts stolen in Meta AI support hack Over 20,000 Instagram accounts were compromised due to a vulnerability in Meta’s AI-powered support system, High Touch Support (HTS). Attackers exploited the system to reset passwords, gaining unauthorized access to user… BleepingComputer · Jun 8, 2026 High IEaipasswordaccount takeover
malware C0XMO botnet spreads via DD-WRT router flaw, kills rival malware A new botnet, C0XMO, leveraging a DD-WRT router vulnerability (CVE-2021-27137) is spreading across various device architectures, including routers, DVRs, and Android devices. This botnet, developed by the Gafgyt group, i… BleepingComputer · Jun 7, 2026 High CVE-2021-27137DEJPddosbotnetexploit
threat-intel Silent Ransom Group targets law firms with fake IT support calls The Silent Ransom Group is aggressively targeting U.S. law firms through sophisticated social engineering attacks, primarily involving fake IT support calls. These attacks begin with phishing emails and escalate to remot… BleepingComputer · Jun 7, 2026 High USsocial engineeringphishingremote access
threat-intel AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs This article details a significant surge in vulnerability discovery, driven largely by autonomous AI agents. Depthfirst identified 21 zero-days in FFmpeg using their AI agent, while Google patched 429 bugs in Chrome 149,… The Hacker News · Jun 6, 2026 High CVE-2026-39210CVE-2026-39218CVE-2026-10881USaivulnerabilityzero-day
supply-chain Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack A sophisticated supply chain attack, dubbed Miasma, has compromised 73 Microsoft GitHub repositories, including several within the Azure and Microsoft organizations. The attack leverages a re-compromised PyPI package, du… The Hacker News · Jun 6, 2026 High supply chaingithubopen source
vulnerability CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers CISA has issued a warning about hackers actively exploiting a recently patched vulnerability in SolarWinds Serv-U, a file transfer software, to crash servers. This vulnerability, CVE-2026-28318, stems from uncontrolled r… BleepingComputer · Jun 5, 2026 High CVE-2026-28318CVE-2021-35211CVE-2024-28995UNdenial-of-servicepatchingfile transfer
threat-intel Exposed Fuel Tank Gauges Under Attack in the US Internet-exposed fuel tank gauges in the United States are being targeted by cyberattacks, posing a significant risk to gas stations and industrial facilities. The Cybersecurity and Infrastructure Security Agency (CISA)… Dark Reading · Jun 5, 2026 High USCAAUindustrial control systemscybersecuritytank gauges
apt Chinese APT deploys new malware to keep access to hacked networks A Chinese Advanced Persistent Threat (APT) group, tracked as UNC5221 (VerdantBamboo), has been conducting a prolonged espionage campaign targeting organizations in the United States, primarily leveraging the Brickstorm b… BleepingComputer · Jun 5, 2026 High CNespionagebackdoorpersistence
supply-chain IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks A sophisticated supply chain attack targeting the npm ecosystem has resulted in the deployment of both IronWorm, a Rust-based information stealer with self-replicating capabilities, and a new variant of the Miasma worm.… The Hacker News · Jun 5, 2026 High USsupply-chainnpmrust
threat-intel Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 A joint bulletin from the FBI, MI5, ASIO, CSIS, and NZSIS warns of a Chinese intelligence operation targeting Western professionals via LinkedIn and other job platforms. The operation involves posing as recruitment firms… Graham Cluley · Jun 5, 2026 High CHUNAUrecruitmentintelligencelinkedin
malware Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps Arabic-speaking users have emerged as the target of a new Android spyware codenamed Asin, according to findings from ESET. The Slovakian cybersecurity company said it first detected the malware spread via multiple campai… The Hacker News · Jun 5, 2026 High
threat-intel Over 900 US gas station tank gauge systems exposed to attacks Over 900 US gas station tank gauge systems are vulnerable to ongoing attacks due to internet exposure and security flaws. Threat actors are exploiting these systems to potentially alter settings and cause operational dis… BleepingComputer · Jun 5, 2026 High USatgindustrial control systemscybersecurity