malware WordPress malware campaign hides payloads in Steam profiles A WordPress malware campaign has infected nearly 2,000 websites by hiding command-and-control (C2) data within Steam Community profile comments. The attackers utilize invisible Unicode characters to encode malicious payl… BleepingComputer · Jun 1, 2026 High USwordpresssteemunicode
threat-intel Race Against Time: Why Faster Vulnerability Alerts Matter This article highlights the critical importance of rapid vulnerability alerts in cybersecurity, emphasizing the increasing speed at which vulnerabilities are being discovered and exploited. The average time to exploitati… BleepingComputer · Jun 1, 2026 High USvulnerabilityexploitationcybersecurity
threat-intel ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More This Hacker News recap details several ongoing cyber threats, including an active exploitation of a PAN-OS GlobalProtect authentication bypass vulnerability, a critical zero-day vulnerability in the Gogs Git service, and… The Hacker News · Jun 1, 2026 High CVE-2026-0257CVE-2026-8732CVE-2026-27771RUvulnerabilityauthenticationc2
threat-intel China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan A new cyber espionage campaign, dubbed Operation Dragon Weave, is targeting government, research, and financial institutions in the Czech Republic and Taiwan using spear-phishing emails and a Rust-based loader to deploy… The Hacker News · Jun 1, 2026 High CZTWINspear-phishingc2azure
threat-intel Containers on fire: from container escapes to supply chain attacks This Securelist article examines the evolving threat landscape targeting container environments, highlighting key attack vectors used by groups like TeamPCP. The analysis focuses on vulnerabilities, supply chain attacks… Securelist · Jun 1, 2026 High CVE-2019-5736CVE-2022-0492CVE-2024-21626UScontainerskubernetessupply chain
supply-chain OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack A supply chain attack targeting OpenAI Codex developers has been discovered through a malicious npm package named ‘codexui-android’. The package, developed by ‘friuns’ (Igor Levochkin) and promoted by ‘BrutalStrike’, sil… The Hacker News · Jun 1, 2026 High USsupply chainauthenticationtokens
threat-intel OpenClaw: risks for agent users and how to mitigate them This Securelist article highlights the significant security risks associated with OpenClaw, a popular AI agent ecosystem used globally for automating tasks. The system’s widespread adoption, combined with a large marketp… Securelist · Jun 1, 2026 High USai agentsautomationsupply chain
vulnerability Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks Palo Alto Networks is warning of an actively exploited vulnerability (CVE-2026-0257) in its GlobalProtect VPN software, allowing attackers to bypass authentication and establish unauthorized VPN connections. The flaw, in… BleepingComputer · May 30, 2026 High CVE-2026-0257USvpnauthenticationcookie
threat-intel Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say As a result of sanctions and the ongoing war in Ukraine, Russian intelligence agencies are intensifying their efforts to steal Western technology and defense secrets. This includes targeting advanced machine tools, resea… SecurityWeek · May 30, 2026 High RUSEFIsanctionsespionagecyberattack
vulnerability New CIFSwitch Linux flaw gives root on multiple distributions A newly discovered vulnerability, dubbed 'CIFSwitch,' in the Linux kernel allows attackers to escalate privileges to root by forging CIFS authentication key descriptions. The flaw, present since 2007, affects multiple Li… BleepingComputer · May 30, 2026 High CVE-2026-46243linuxkernelprivilege escalation
malware ChatGPT share links abused to host fake outage pages to deliver malware Threat actors are exploiting ChatGPT's content-sharing feature to host convincing fake outage pages designed to trick users into downloading malware. This 'LLMShare' campaign leverages Google ads and a legitimate OpenAI… BleepingComputer · May 29, 2026 High aimalwarephishing
data-breach California AG sues 23andMe over 2023 breach exposing health data 23andMe faced a significant data breach in 2023, exposing the personal and genetic information of nearly 7 million customers, including a large number in California. The breach stemmed from a credential-stuffing attack a… BleepingComputer · May 29, 2026 High USdata breachgenetic datacredential stuffing
threat-intel ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface A vulnerability, dubbed ChatGPhish, has been discovered in OpenAI’s ChatGPT that allows attackers to leverage the AI’s summarization feature to create phishing attacks. By appending malicious content to a webpage, attack… The Hacker News · May 29, 2026 High CVE-2026-25592CVE-2026-26030USprompt injectionphishingai
threat-intel In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks This week’s cybersecurity news highlights a range of incidents, including a data breach affecting Trump Mobile customers, ongoing Russian government intrusion into US Treasury systems, and vulnerabilities in popular soft… SecurityWeek · May 29, 2026 High UNCHdata breachsupply chainphishing
data-breach Charter Communications Data Breach Could Impact Nearly 5 Million The notorious ShinyHunters extortion group leaked over 42 million records allegedly stolen from Charter in April. The post Charter Communications Data Breach Could Impact Nearly 5 Million appeared first on SecurityWeek . SecurityWeek · May 29, 2026 High
threat-intel Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit An unknown threat actor exploited CVE-2026-39987 in Marimo to gain initial access, subsequently using a large language model (LLM) agent to conduct post-exploitation activities, including stealing credentials and exfiltr… The Hacker News · May 29, 2026 High CVE-2026-39987CNllmpost-exploitationcredential theft
threat-intel Asia's Cyber Insurance Market Shows Signs of Life The Asian cyber insurance market has historically lagged behind other regions due to low penetration rates, particularly among larger organizations and small businesses. However, a recent report indicates a potential shi… Dark Reading · May 29, 2026 High CHJASIcyberinsuranceransomwareapac
ddos From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market This article reports on the increasing commercialization of Distributed Denial-of-Service (DDoS) attacks, now offered as a ‘DDoS-as-a-Service’ (DDoSaaS) model. The trend shows a shift from fragmented, DIY attack methods… BleepingComputer · May 29, 2026 High USddosbotnetcloudflare
threat-intel Microsoft calls zero-day releases ‘never justifiable’ as researcher threatens to drop more Microsoft is responding to a weeks-long campaign by a pseudonymous researcher, ‘Nightmare Eclipse,’ who released uncoordinated zero-day vulnerabilities in Windows. The researcher, motivated by grievances against Microsof… The Record · May 29, 2026 High zero-dayvulnerabilitydisclosure
threat-intel With Complex Cloud Integrations, Small Errors Lead to Major Compromises This article details a near-breach at Zapier, a popular low-code automation service, highlighting the risks associated with complex cloud integrations and inadequate security practices. Researchers at Token Security disc… Dark Reading · May 29, 2026 High UScloud-securitysecretspermissions