Cyber Security
Alleged ShinyHunters Leader ‘Rey’ Reportedly Held in Jordan
Nikkei Discloses M365 Breach, 9,000 Spoofed Emails Sent
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Critical FortiMail Zero-Day Exploited With No Patch Yet
Police Dismantle KillSec Ransomware Gang, Nab Teen Leader
Kiteworks Patches Second Max-Severity Flaw in a Week
Self-Healing WordPress Backdoor Defies Standard Removal
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
MetaMask Discloses Incident, Exits Ethereum Validators
TeamViewer Patches Critical Access-Control Bypass Flaw
WatchGuard Patches Critical Root Code Execution Flaw
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
Teen Researcher’s AI Tool Gains Admin on Microsoft Titan
OpenSSL Patches High-Severity DTLS Memory Leak Flaw
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
Chrome, Firefox Patch Over 100 Flaws in Joint Update
Pentagon Records Agency Breach Exposes Data on 3 Million
France Tax Agency Breached Seven Weeks via Stolen Passwords
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
FBI Tells ShinyHunters Members to Turn Themselves In
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
101 Malicious npm Packages Add Developers to WhatsApp Groups
Glow Security Finds 13,000 Exposed AI Agent Screenshots
Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
Ex-Air Force Members Sentenced to 189 Months for BEC Scams
Cybersecurity
Novo Nordisk Discloses Breach of Clinical Trials Patient Data
Novo Nordisk disclosed a breach of clinical trials patient data, triggering GDPR, GCP, and clinical research regulatory obligations across global operations.
Cybersecurity
Europol Dismantles AudiA6 Crypto Laundering Service
Europol dismantled AudiA6, a cryptocurrency laundering service that processed over $380 million in ransomware extortion proceeds for criminal networks.
Application Security
Three LangGraph Flaws Chain to Remote Code Execution
Three patched LangGraph vulnerabilities chain from SQL injection to remote code execution on self-hosted AI agent framework deployments, researchers disclosed.
Cybersecurity
OnyxC2 Stealer Targets 200+ Apps for $250 Per Month
OnyxC2, a new MaaS information stealer priced at $250 per month, targets 200-plus applications using DLL sideloading and encryption to evade detection.
Cybersecurity
Maine AG Portal Abused to Post Fabricated Breach Notices
Threat actors filed fraudulent breach notices through Maine's AG portal, publishing false disclosures on a government site; VRChat denied the fabricated claim.
Application Security
Fortinet FortiSandbox CVE-2026-25089 Allows Unauthenticated RCE
Fortinet patched CVE-2026-25089, a CVSS 9.1 OS command injection in FortiSandbox's Web UI exploitable by unauthenticated attackers via crafted HTTP requests.
Application Security
OpenSSL Patches 16 Flaws Including Heap Use-After-Free RCE Risk
OpenSSL released 16 security fixes, led by CVE-2026-45447, a HIGH severity heap use-after-free in PKCS7_verify() that may enable RCE via crafted S/MIME messages.
Cybersecurity
Akira Claims Industrial Finisher, NJ Country Club, Architecture Firm
Akira ransomware posted three US victims on June 9: Spray Equipment with 26GB of W-2 records and engineering drawings, Rockaway River Country Club, and SMPC ...
Cybersecurity
Chaos Ransomware Lists Airespring as Iranian False-Flag History Looms
Chaos ransomware listed US telecom provider Airespring on its leak site. Rapid7 documented Chaos as a MuddyWater Iranian APT false-flag tool, complicating attribution.
Application Security
Shai-Hulud Hades Wave Poisons 29 Bioinformatics PyPI Packages
The Shai-Hulud Hades variant targeted ~29 bioinformatics and ML PyPI packages in a second wave, introducing a loader-payload split and bringing the campaign past 100 ...
Application Security
Oracle PeopleSoft CVE-2026-35273: ShinyHunters Breaches 100+ Orgs
Oracle issued emergency mitigations for CVE-2026-35273, an RCE flaw in PeopleSoft, after ShinyHunters breached 300 instances across more than 100 organizations.
Cybersecurity
Nottingham University Breach Exposes Data on 454,600 Students
ShinyHunters posted 40GB of stolen data on 454,600 University of Nottingham students, exposing passport numbers, disability data, and credit card details.
Cybersecurity
FBI Seizes 13 Chinese Spy Sites Targeting U.S. Clearance Holders
The FBI and DOJ seized 13 websites used by Chinese intelligence services to recruit current and former U.S. government workers who hold security clearances.
Cybersecurity
China-Linked JDY Botnet Hits 1,500 Devices Targeting U.S. Military
Black Lotus Labs tracked the JDY botnet's growth to 1,500-plus compromised devices, with U.S. military networks identified as the primary target sector.
CVE Vulnerability Alerts
CISA BOD 26-04 Mandates 3-Day Patch Window for Federal Agencies
CISA BOD 26-04 requires all federal civilian agencies to patch critical KEV-listed exploited vulnerabilities within three days, cutting the two-week timeline.
Cybersecurity
RoguePlanet Zero-Day Gives Attackers SYSTEM on Patched Windows
Security researcher Nightmare Eclipse dropped RoguePlanet, an unpatched LPE zero-day in Microsoft Defender that grants SYSTEM on fully patched Windows.
CVE Vulnerability Alerts
Ivanti Sentry CVE-2026-10520 Actively Exploited, Devices Backdoored
Ivanti Sentry CVE-2026-10520 is a CVSS 10.0 unauthenticated root RCE under active exploitation. Two instances were confirmed backdoored on disclosure day.
Application Security
Langflow CVE-2026-5027: Path Traversal Becomes Unauthenticated RCE
CVE-2026-5027 in Langflow allows unauthenticated attackers to write arbitrary files via path traversal, achieving RCE on 7,000 publicly exposed AI instances.
Cybersecurity
WorldLeaks Claims Apple Supplier Tata Electronics and Two More Firms
WorldLeaks, the rebranded Hunters International group, posted three new victims: Tata Electronics, First Federal Savings & Loan, and India's Reliance Group.
What Is Cloud Detection and Response (CDR) and How Does It Work
Blog
What is Cloud Detection and Response (CDR) and How Does it Work
Cloud detection and response (CDR) delivers real-time threat visibility across cloud workloads. Learn how CDR works and how to implement it.
Application Security
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Cybersecurity
Police Dismantle KillSec Ransomware Gang, Nab Teen Leader
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Application Security
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Cybersecurity
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
Cybersecurity
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
OnyxC2 Stealer Targets 200+ Apps for $250 Per Month
OnyxC2, a new MaaS information stealer priced at $250 per month, targets 200-plus applications using DLL sideloading and encryption to evade detection.
Maine AG Portal Abused to Post Fabricated Breach Notices
Threat actors filed fraudulent breach notices through Maine's AG portal, publishing false disclosures on a government site; VRChat denied the fabricated claim.
Fortinet FortiSandbox CVE-2026-25089 Allows Unauthenticated RCE
Fortinet patched CVE-2026-25089, a CVSS 9.1 OS command injection in FortiSandbox's Web UI exploitable by unauthenticated attackers via crafted HTTP requests.
OpenSSL Patches 16 Flaws Including Heap Use-After-Free RCE Risk
OpenSSL released 16 security fixes, led by CVE-2026-45447, a HIGH severity heap use-after-free in PKCS7_verify() that may enable RCE via crafted S/MIME messages.
Akira Claims Industrial Finisher, NJ Country Club, Architecture Firm
Akira ransomware posted three US victims on June 9: Spray Equipment with 26GB of W-2 records and engineering drawings, Rockaway River Country Club, and SMPC ...
Chaos Ransomware Lists Airespring as Iranian False-Flag History Looms
Chaos ransomware listed US telecom provider Airespring on its leak site. Rapid7 documented Chaos as a MuddyWater Iranian APT false-flag tool, complicating attribution.
Shai-Hulud Hades Wave Poisons 29 Bioinformatics PyPI Packages
The Shai-Hulud Hades variant targeted ~29 bioinformatics and ML PyPI packages in a second wave, introducing a loader-payload split and bringing the campaign past 100 ...
Oracle PeopleSoft CVE-2026-35273: ShinyHunters Breaches 100+ Orgs
Oracle issued emergency mitigations for CVE-2026-35273, an RCE flaw in PeopleSoft, after ShinyHunters breached 300 instances across more than 100 organizations.
Nottingham University Breach Exposes Data on 454,600 Students
ShinyHunters posted 40GB of stolen data on 454,600 University of Nottingham students, exposing passport numbers, disability data, and credit card details.
FBI Seizes 13 Chinese Spy Sites Targeting U.S. Clearance Holders
The FBI and DOJ seized 13 websites used by Chinese intelligence services to recruit current and former U.S. government workers who hold security clearances.
China-Linked JDY Botnet Hits 1,500 Devices Targeting U.S. Military
Black Lotus Labs tracked the JDY botnet's growth to 1,500-plus compromised devices, with U.S. military networks identified as the primary target sector.
CISA BOD 26-04 Mandates 3-Day Patch Window for Federal Agencies
CISA BOD 26-04 requires all federal civilian agencies to patch critical KEV-listed exploited vulnerabilities within three days, cutting the two-week timeline.
RoguePlanet Zero-Day Gives Attackers SYSTEM on Patched Windows
Security researcher Nightmare Eclipse dropped RoguePlanet, an unpatched LPE zero-day in Microsoft Defender that grants SYSTEM on fully patched Windows.
Ivanti Sentry CVE-2026-10520 Actively Exploited, Devices Backdoored
Ivanti Sentry CVE-2026-10520 is a CVSS 10.0 unauthenticated root RCE under active exploitation. Two instances were confirmed backdoored on disclosure day.
Langflow CVE-2026-5027: Path Traversal Becomes Unauthenticated RCE
CVE-2026-5027 in Langflow allows unauthenticated attackers to write arbitrary files via path traversal, achieving RCE on 7,000 publicly exposed AI instances.
WorldLeaks Claims Apple Supplier Tata Electronics and Two More Firms
WorldLeaks, the rebranded Hunters International group, posted three new victims: Tata Electronics, First Federal Savings & Loan, and India's Reliance Group.
What is Cloud Detection and Response (CDR) and How Does it Work
Cloud detection and response (CDR) delivers real-time threat visibility across cloud workloads. Learn how CDR works and how to implement it.
Google Patches 5th Chrome Zero-Day; V8 Flaw Chains for OS Access
Google patched CVE-2026-11645, a V8 out-of-bounds flaw being chained with a sandbox escape to achieve OS code execution. The fifth Chrome zero-day of 2026.
LiteLLM CVE-2026-42271 Added to CISA KEV: AI API Keys at Risk
CISA added BerriAI LiteLLM CVE-2026-42271 to the KEV catalog. The command injection flaw enables OS access and theft of all configured AI provider API keys.
France’s Tchap Messaging App Breached, 643K Messages Exposed
ANSSI detected attackers who used a hijacked account and hardcoded LDAP credentials to breach Tchap, exposing 643,000 messages across 73,000 accounts.