threat-intel DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets The U.S. Department of Justice, in collaboration with numerous international law enforcement agencies and private sector companies, disrupted a network of cybercrime groups operating out of Southeast Asia that were defra… The Hacker News · Jun 4, 2026 High USTHAUcryptocurrencyfraudscam
apt Pakistan Spies on Afghan Finance Ministry With Xeno RAT A Pakistani advanced persistent threat (APT) group, identified as SideCopy and linked to the Transparent Tribe (APT 36), has been conducting espionage against Afghanistan's finance ministry since at least May 2025. The g… Dark Reading · Jun 4, 2026 High AFPKspear-phishingremote-accesspashto
threat-intel Chinese hackers use new Atlas RAT malware in European cyberattacks A Chinese cybercrime group, tracked as TA4922, is expanding its operations with the deployment of new malware, including the Atlas RAT and RomulusLoader, targeting organizations across Europe and Southeast Asia. The grou… BleepingComputer · Jun 3, 2026 High CHGEITphishingremote access trojanmalware loader
threat-intel Attackers Use AI to Automate EDR Evasion Testing Attackers are leveraging artificial intelligence to automate the process of testing and developing malware designed to evade endpoint detection and response (EDR) systems. Sophos researchers discovered a sophisticated re… Dark Reading · Jun 3, 2026 High aiedrred teaming
ransomware The U.S. sanctions Nobitex crypto exchange used by ransomware The U.S. Treasury's Office of Foreign Assets Control (OFAC) has announced sanctions against Nobitex, Iran's largest cryptocurrency exchange, for facilitating payments related to terrorist activities. BleepingComputer · Jun 3, 2026 High
threat-intel Tropical Blend: Cyber & Politics Ramp Up Across Latin America This report details a surge in cyber espionage activities targeting Latin American nations, primarily driven by China-linked Advanced Persistent Threat (APT) groups. These groups, including FamousSparrow and NegativeGlim… Dark Reading · Jun 3, 2026 High CHVEPAaptcyber espionagelatin america
threat-intel WhatsApp, Slack Notifications Could Hijack Google Gemini on Android This article details a vulnerability in Google Gemini on Android that allows malicious notifications from apps like WhatsApp, Slack, or SMS to hijack the voice assistant and perform actions such as opening windows, launc… The Hacker News · Jun 3, 2026 High voice assistantprompt injectionandroid
ddos New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute A new denial-of-service (DoS) attack, dubbed ‘HTTP/2 Bomb,’ has been identified that can cripple web servers within seconds by exploiting vulnerabilities in default HTTP/2 configurations of popular web servers like Nginx… BleepingComputer · Jun 3, 2026 High CVE-2026-49975doshttp2compression
threat-intel Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover A coding error in several Microsoft 365 Android applications, specifically Excel, Word, PowerPoint, OneNote, Loop, and Microsoft 365 Copilot, exposed user accounts to potential compromise. The issue stemmed from a disabl… Dark Reading · Jun 3, 2026 High CVE-2026-41100CVE-2026-41101CVE-2026-41102authenticationtokensandroid
malware Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT A new malspam campaign is leveraging Google's DoubleClick domain to deliver the DesckVB RAT, a .NET-based remote access trojan. The campaign’s scalability and cost-effectiveness stem from its ability to dynamically perso… The Hacker News · Jun 3, 2026 High USmalspamratdoubleclick
vulnerability Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag A vulnerability in Microsoft 365 Android apps allowed unauthorized apps to steal user account tokens, potentially granting access to sensitive data like emails and calendar information. The flaw, discovered by Enclave, s… The Hacker News · Jun 3, 2026 High CVE-2026-41100CVE-2026-41101CVE-2026-41102androidtokenspoofing
threat-intel What 345 Days of Untested Exposure Looks Like at a Bank This article details a significant security vulnerability stemming from a bank’s reliance on an annual penetration testing schedule, highlighting the risks associated with infrequent assessments. A VPN vulnerability, exp… BleepingComputer · Jun 3, 2026 High USvulnerabilityapitenant_id
vulnerability Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479) A 2-year-old remote code execution (RCE) vulnerability, CVE-2026-23479, was discovered in Redis 7.2.0 by an autonomous AI security tool, Team Xint Code. The flaw, stemming from a use-after-free issue in the `unblockClien… The Hacker News · Jun 3, 2026 High CVE-2026-23479UKuse-after-freerceredis
threat-intel Security of 100 AI Agents Tested and Ranked – What You Need to Know A recent analysis by Adversa AI tested and ranked 100 AI agents, revealing a concerning trend: nearly all agents possess a dangerous combination of excessive power, trust, and a lack of control – what they term the ‘leth… SecurityWeek · Jun 3, 2026 High aiagentsecurity
data-breach IMA Diligence Services Data Breach Impacts 525,000 People The affected individuals’ personal information was stolen from a legacy server managed by a third party. The post IMA Diligence Services Data Breach Impacts 525,000 People appeared first on SecurityWeek . SecurityWeek · Jun 3, 2026 High
threat-intel Malicious Notifications Could Trick Google Gemini Users A SafeBreach research report, "Gemini's Secret Affair," details a prompt injection flaw in Google Gemini's voice assistant that allows attackers to trick users into executing malicious commands through seemingly harmless… Dark Reading · Jun 3, 2026 High prompt-injectionllmvoice-assistant
threat-intel ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds A new ‘HTTP/2 Bomb’ exploit has been discovered that leverages existing vulnerabilities in HTTP/2 implementations to cause widespread denial-of-service attacks against web servers. The exploit combines compression and fl… SecurityWeek · Jun 3, 2026 High CVE-2016-6581CVE-2025-53020CVE-2016-8740USdoshttp2compression
Police dismantles 9 crime groups in illegal streaming crackdown European and international law enforcement agencies have dismantled nine organized crime groups and arrested 29 suspects in a major crackdown on illegal streaming operations. BleepingComputer · Jun 3, 2026 High
threat-intel New cyber force would cost up to $11 billion to start, commission says This article reports on a commission’s recommendation for the U.S. to establish a dedicated cyber warfare force, estimated to cost up to $11 billion and staffed by approximately 30,000 personnel. The proposal stems from… The Record · Jun 3, 2026 High UNRUCHcybersecuritymilitarydefense
threat-intel Global Stock Exchange Hit by Monthslong Email Campaign A global stock exchange was targeted by a sophisticated threat actor who gained near-continuous access to a senior executive’s Microsoft Outlook mailbox over a five-month period. The attacker utilized legitimate Windows… Dark Reading · Jun 3, 2026 High UKemail espionagelateral movementdata exfiltration