
APT73 Bashe Ransomware Claims Armenia’s Ministry of Internal Affairs
APT73 (Bashe), a LockBit-linked RaaS, posted Armenia’s elections.mia.gov.am as a victim, threatening voter registration and electoral administration data.

APT73 (Bashe), a LockBit-linked RaaS, posted Armenia’s elections.mia.gov.am as a victim, threatening voter registration and electoral administration data.

Russia’s FSB claimed foreign spies installed surveillance malware on senior officials’ smartphones, naming Cloudflare and Fastly as alleged C2 infrastructure.

Europol’s seven-month Operation KRATOS 2 arrested 29 suspects, targeted 4,370 piracy domains, and removed 27,000 illegal streaming URLs across 13

CVE-2026-8206 in the Kirki WordPress plugin is under active attack, with Wordfence detecting 222 exploitation attempts targeting admin account takeover.

CVE-2026-0826 allows unauthenticated root-level RCE on HP Poly VVX and Trio VoIP phones via a crafted SIP INVITE request targeting

Sophos discovered a criminal ransomware framework using Claude Opus 4.5 and multi-agent AI pipelines to build and test 80 evasion-optimized

CISA confirmed active exploitation of Oracle WebLogic CVE-2024-21182, giving federal agencies a June 4 deadline to patch the unauthenticated data-access

CVE-2026-49975 HTTP/2 Bomb exploit achieves 5,700:1 amplification against Envoy, crashing 32 GB of server memory with a single residential connection.

Researcher Ammar Askar publicly disclosed a VS Code zero-day that lets malicious extensions steal GitHub OAuth tokens, granting full repository

Google confirmed CVE-2025-48595, a no-interaction privilege escalation flaw in Android 14–16, is under active targeted attack. Patches arrive June 5.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.