threat-intel Reporting from Vegas: Networking, AI, and good boys This Cisco Talos Threat Source newsletter highlights the ongoing challenges of managing data at scale in an AI-driven world, particularly during large technology conferences like Cisco Live. It details Talos’ expansion o… Cisco Talos · Jun 4, 2026 High USRUaithreat huntingc2
data-breach UN food agency discloses breach affecting 600,000 Gaza households The World Food Programme (WFP) has disclosed a breach of its self-registration application (SRA) used in Gaza, resulting in the theft of personal data from approximately 600,000 Palestinian households. This incident high… BleepingComputer · Jun 4, 2026 High PSgazadata breachhumanitarian
supply-chain New IronWorm malware hits 36 packages in npm supply-chain attack A new supply-chain attack leveraging the IronWorm malware has compromised 36 npm packages, targeting developers and CI environments with infostealer capabilities. The malware utilizes stolen credentials and a sophisticat… BleepingComputer · Jun 4, 2026 High supply chainnpmrust
threat-intel Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories A security researcher discovered a flaw in Anthropic's Claude Code GitHub Action that allowed attackers to take over vulnerable public repositories by exploiting a permissive trigger check and prompt injection techniques… The Hacker News · Jun 4, 2026 High prompt-injectiongithub-actionsai-security
threat-intel Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It The article highlights the increasing use of agentic AI in defense and intelligence networks, emphasizing the potential risks associated with its deployment. A recent incident involving Anthropic's Claude Mythos model de… The Hacker News · Jun 4, 2026 High aiagentic aidefense
threat-intel Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook This article details a trend of underground forums sharing a tutorial designed to guide novice hackers through the process of identifying, exploiting, and monetizing vulnerabilities. The ‘Hercules’ thread, popular across… BleepingComputer · Jun 4, 2026 High USvulnerabilityexploitmonetization
threat-intel ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories This bulletin highlights several ongoing cyber threats, including a high-severity SSRF vulnerability in Cisco Unified Communications Manager, a large-scale spyware operation targeting Russian officials by foreign intelli… The Hacker News · Jun 4, 2026 High CVE-2026-20230CVE-2022-0492CVE-2019-5736RUIRUSssrfspywarekeylogger
threat-intel Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process A security researcher, Ammar Askar, released a GitHub token-stealing exploit for Microsoft's VS Code, citing frustration with the company's vulnerability disclosure process. This follows a recent breach of GitHub reposit… The Record · Jun 4, 2026 High githubvulnerabilitydisclosure
threat-intel Five Eyes warn Chinese spies are using job sites to recruit insiders The Five Eyes intelligence alliance has issued a joint warning about Chinese military intelligence services using online job platforms to recruit individuals with access to sensitive information. This tactic, described a… The Record · Jun 4, 2026 High CHAUCArecruitmentespionagecybersecurity
threat-intel Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting This article details Cisco Talos' approach to threat hunting, which differs from traditional alert-based detection. Instead of waiting for alerts, Talos analysts formulate hypotheses about adversary behavior based on tel… Cisco Talos · Jun 4, 2026 High USthreat huntingaicorrelation
vulnerability Hitachi Energy MACH HiDraw A buffer overflow vulnerability has been identified in Hitachi Energy’s MACH HiDraw product versions up to 9.22. Exploitation of this flaw could lead to denial-of-service attacks and potential arbitrary code execution, i… CISA Advisories · Jun 4, 2026 High CVE-2026-7310USbuffer overflowxml parserindustrial control systems
vulnerability Hitachi Energy ITT600 Explorer Hitachi Energy has identified vulnerabilities in its ITT600 Explorer product, specifically versions prior to 2.1 SP6, which could lead to Denial of Service (DoS) attacks. The vulnerabilities stem from a stack overflow in… CISA Advisories · Jun 4, 2026 High CVE-2024-8176CVE-2025-59375SWiec61850denial of servicelibexpat
vulnerability B&R PPT30 Operating System A vulnerability, CVE-2025-11482, has been identified in B&R PPT30 Operating System versions prior to 1.8.0, specifically within the OPC-UA Server. An unauthenticated network-based attacker could exploit this flaw to perm… CISA Advisories · Jun 4, 2026 High CVE-2025-11482WOopcuafirmwarenetwork-based
threat-intel Chinese Cybercrime Group in Spotlight for Record Campaign Pace A Chinese cybercrime group, TA4922, is experiencing a record surge in campaign activity, utilizing sophisticated social engineering tactics to target organizations globally. The group’s primary objectives involve data th… SecurityWeek · Jun 4, 2026 High GBDEITsocial engineeringcredential phishingremote access
malware FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads A new macOS malvertising campaign, dubbed Operation FlutterBridge, is utilizing FlutterShell, a backdoor that spreads adware via malicious Google and YouTube ads. The campaign, traced back to the CL-CRI-1089 threat actor… The Hacker News · Jun 4, 2026 High USCAAUmalvertisingmacoswebview
phishing Hacking Meta’s AI Chatbot Meta's AI chatbot, the Meta AI Support Assistant, was exploited by hackers to gain unauthorized access to Instagram accounts. The attackers leveraged the chatbot's ability to generate verification codes and reset passwor… Schneier on Security · Jun 4, 2026 High aichatbotphishing
Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown Law enforcement and tech companies disrupted infrastructure linked to scammers operating across Southeast Asia. The post Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown appeared first on SecurityWeek . SecurityWeek · Jun 4, 2026 High
malware Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS A sophisticated operation is impersonating popular open-source and freeware tools like Ghidra and dnSpy to lure users to malicious websites via a Traffic Distribution System (TDS). This TDS then delivers malware, includi… The Hacker News · Jun 4, 2026 High TRPLBRtdsmalware-as-a-serviceclick interception
threat-intel Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months An unknown attacker gained unauthorized access to the Outlook mailbox of a senior executive at a major stock exchange for over five months, copying the inbox in small batches and utilizing cloud services like Dropbox and… The Hacker News · Jun 4, 2026 High USespionagemailboxcloud
vulnerability Cisco Warns of Available PoC for Critical Unified CM Vulnerability The high-severity flaw can be exploited remotely, without authentication, in server-side request forgery (SSRF) attacks. The post Cisco Warns of Available PoC for Critical Unified CM Vulnerability appeared first on Secur… SecurityWeek · Jun 4, 2026 High CVE-2026-20230