threat-intel Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash This article reports on a controversy between Microsoft and a security researcher, known as Nightmare Eclipse, regarding the disclosure of several zero-day vulnerabilities affecting Microsoft products. Microsoft initiall… SecurityWeek · Jun 3, 2026 High CVE-2026-41091CVE-2026-45498CVE-2026-33825USzero-dayvulnerability disclosurelegal action
threat-intel Google adds Android protection against AI deepfake scam calls Google is launching a new Android security feature, "fake call detection," to combat increasingly sophisticated scams utilizing AI-generated deepfake calls. The system works by verifying call authenticity in real-time, a… BleepingComputer · Jun 3, 2026 High USdeepfakeaiscam
malware Argamal: Malware hidden in hentai games A new malware campaign, dubbed "Argamal," is targeting users of hentai games. The campaign involves injecting a malicious implant into legitimate game files, leveraging COM hijacking to establish persistence and achieve… Securelist · Jun 3, 2026 High UShentaicom hijackingpersistence
threat-intel Lessons for life: Why children’s data is a long-term identity risk This article highlights the growing risk of child identity theft and the broader vulnerability of children’s data in the digital age. Despite efforts to regulate online content for children, their data is increasingly ex… WeLiveSecurity · Jun 3, 2026 High identity theftdata privacyphishing
ddos New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare Researchers have identified a new HTTP/2 bomb vulnerability affecting web servers like NGINX, Apache, and IIS, allowing for remote denial-of-service attacks. The exploit leverages header compression and connection manage… The Hacker News · Jun 3, 2026 High CVE-2016-6581CVE-2025-53020CVE-2016-8740http2compressiondos
vulnerability VS Code zero-day lets hackers steal GitHub tokens in one click A researcher, Ammar Askar, has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link. The vulne… BleepingComputer · Jun 3, 2026 High zero-daygithubvscode
malware Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content A new malware campaign, dubbed Weedhack, is targeting Minecraft players through YouTube and malicious websites, distributing a MaaS (Malware-as-a-Service) tool. The campaign, active since January 2026, utilizes SEO poiso… The Hacker News · Jun 3, 2026 High USDEINminecraftmalwareyoutube
malware ISC Stormcast For Wednesday, June 3rd, 2026 https://isc.sans.edu/podcastdetail/9956, (Wed, Jun 3rd) The SANS Internet Storm Center's Stormcast for June 3rd, 2026 highlighted a concerning increase in malicious activity across the internet landscape. The broadcast detailed several ongoing threats, including observed phis… SANS Internet Storm Center · Jun 3, 2026 High phishingransomwaremalware
vulnerability Critical Kirki flaw exploited to hijack WordPress admin accounts Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators. BleepingComputer · Jun 2, 2026 High CVE-2026-8206
malware Over 116,000 Mincraft systems infected in WeedHack malware campaign A large-scale malware campaign, dubbed WeedHack, has infected over 116,000 Minecraft systems since January, primarily through malicious mods and clients promoted via YouTube and SEO poisoning. The malware operates as a M… BleepingComputer · Jun 2, 2026 High USDEINminecraftmalwaremaas
threat-intel FBI-Flagged Phishing Kit Kali365 Expands Its Reach The Kali365 phishing-as-a-service platform, initially focused on compromising Microsoft 365 accounts via MFA bypass, has significantly expanded its capabilities and target list. It now actively targets platforms like AWS… Dark Reading · Jun 2, 2026 High USRUphishingdevice-codemfa
threat-intel DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks A sophisticated cybercriminal operation, dubbed DriveSurge, has been hijacking thousands of legitimate websites to distribute malware, primarily through ClickFix and FakeUpdate attacks. The operation utilizes a traffic d… Dark Reading · Jun 2, 2026 High USmalwaretraffic distributionclickfix
ransomware AI-built ransomware toolkit automates EDR evasion, AD discovery A threat actor is utilizing an AI-powered ransomware toolkit to automate Active Directory discovery and evade Endpoint Detection and Response (EDR) solutions. The toolkit, developed with assistance from AI agents like Cu… BleepingComputer · Jun 2, 2026 High RUaiedr evasionactive directory
threat-intel China Uses Dual-Method Cyberattack on Czech Orgs This article details a dual-method cyberattack targeting organizations in the Czech Republic and Taiwan, orchestrated by Chinese nation-state threat actors. The campaign, dubbed "Operation Dragon Weave," utilizes a spear… Dark Reading · Jun 2, 2026 High CZCNTWspear-phishingrustazure
threat-intel Securing AI Agents Before They Go Rogue Is Next to Impossible This article highlights the significant security challenges posed by high-autonomy AI agents, particularly those with broad permissions and access to sensitive data. Gartner research VP Dennis Xu warns that securing thes… Dark Reading · Jun 2, 2026 High aiagentsecurity
threat-intel Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine The Gamaredon group is exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy a multi-stage malware campaign targeting Ukraine. This campaign utilizes GammaWorm and GammaSteel, designed for data theft and persistenc… The Hacker News · Jun 2, 2026 High CVE-2025-8088CVE-2026-21509RUUAwinrarmalwarevulnerability
vulnerability Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of a… The Hacker News · Jun 2, 2026 High CVE-2024-21182CVE-2026-21962
threat-intel Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis This SecurityWeek article examines the evolving cybersecurity crisis, highlighting a shift in focus from traditional vulnerability management to the challenges of rapid exploit development and runtime visibility. The rep… SecurityWeek · Jun 2, 2026 High airuntimepatching
threat-intel Russia claims foreign spy agencies hacked officials' phones Russia's FSB has accused foreign intelligence agencies of conducting a large-scale espionage operation targeting senior Russian officials through the use of malware installed on their mobile devices. The agency alleges t… The Record · Jun 2, 2026 High RUUNEUespionagesurveillanceforeign interference
phishing Instagram users locked out after Meta AI abused to steal accounts Instagram accounts were compromised due to attackers exploiting Meta’s AI-powered support tools to impersonate legitimate owners. Users were tricked into verifying their identities via AI-generated selfies, bypassing tra… BleepingComputer · Jun 2, 2026 High USaisocial mediaaccount takeover