- Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Commentsby info@thehackernews.com (The Hacker News) on June 17, 2026
An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez, according to new […]
- Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Developmentby info@thehackernews.com (The Hacker News) on June 17, 2026
Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability has now been […]
- Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offlineby info@thehackernews.com (The Hacker News) on June 17, 2026
A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials. Ordinary stuff, until […]
- FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.by Lawrence Abrams on June 17, 2026
A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs […]
- Adversarial Exposure Validation Turns Security Visibility into Confident Prioritizationby info@thehackernews.com (The Hacker News) on June 17, 2026
For security teams, the findings never stop, but confidence in knowing which ones matter is becoming harder to maintain. The problem is no longer visibility. […]
- Why Account Takeovers Are Rising and How to Stop Themby Sponsored by Specops Software on June 17, 2026
Account takeovers are rising as attackers bypass traditional defenses through phishing, session hijacking, and MFA fatigue. Specops Software explores how […]
- Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chatsby info@thehackernews.com (The Hacker News) on June 17, 2026
Cybersecurity researchers have flagged a "coordinated malware campaign" on the JetBrains Marketplace that has published no less than 15 malicious plugins […]
- India's Telegram ban hit the UAE too. Here's how to get around itby Ax Sharma on June 17, 2026
India has banned Telegram until June 22 after the app was used to circulate leaked exam papers. CEO Pavel Durov accuses telecom Reliance of BGP hijacking that […]
- Microsoft confirms Office apps launch issues after June updatesby Sergiu Gatlan on June 17, 2026
Microsoft is investigating a new issue preventing third-party applications from launching Microsoft Office applications or opening documents on up-to-date […]
- The Top 10 Attack Surface Exposures in 2026by info@thehackernews.com (The Hacker News) on June 17, 2026
Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a […]
- CISA orders feds to patch max severity Joomla plugin flaw by Fridayby Sergiu Gatlan on June 17, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity flaw in the Widget Factory Joomla […]
- Microsoft working on Defender patch for RoguePlanet zero-dayby Sergiu Gatlan on June 17, 2026
Microsoft confirmed that it's working on a security patch for a Defender zero-day vulnerability named "RoguePlanet," disclosed one week ago. [...]
- 144 Mastra npm Packages Compromised via Hijacked Contributor Accountby info@thehackernews.com (The Hacker News) on June 17, 2026
As many as 144 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for building […]
- Kodak confirms data breach claimed by ShinyHunters extortion gangby Sergiu Gatlan on June 17, 2026
Kodak has confirmed that it's working with external cybersecurity experts to investigate a security breach after hackers gained access to some of the company's […]
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Executionby info@thehackernews.com (The Hacker News) on June 17, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Content […]
- Malicious JetBrains Marketplace plugins steal AI API keys from developersby Lawrence Abrams on June 16, 2026
At least 15 malicious plugins found on the JetBrains Marketplace were designed to steal AI API keys from developers. [...]
- New Rokarolla Android malware targets 217 banking, crypto appsby Bill Toulas on June 16, 2026
A new Android banking trojan named Rokarolla is targeting 217 banking and cryptocurrency applications using an extensive set of 137 commands. [...]
- Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squattingby info@thehackernews.com (The Hacker News) on June 16, 2026
A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning model upload and […]
- Steam Workshop abused to spread malware via Wallpaper Engine appby Bill Toulas on June 16, 2026
Threat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push various malware hidden in wallpaper packages. […]
- ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Luresby info@thehackernews.com (The Hacker News) on June 16, 2026
Cybersecurity researchers have flagged multiple ClickFix campaigns that deliver three malware loaders called BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, […]
- UK to require ID or face scan before you can make social media accountsby Ax Sharma on June 16, 2026
Opening a new social media account in the UK will soon mean proving you're over 16 with an ID upload or a facial age scan, under a government ban on under-16s […]
- GhostTree Attack Abused Recursive Windows Junctions to Hide Malwareby Sponsored by Varonis on June 16, 2026
GhostTree uses recursive NTFS junctions to generate vast numbers of valid Windows file paths. Varonis explains how the technique could cause Microsoft Defender […]
- FTC warns of record $3.5 billion losses to imposter scams in 2025by Sergiu Gatlan on June 16, 2026
The U.S. Federal Trade Commission (FTC) warned that Americans lost $3.5 billion to imposter scams in 2025, with reported losses nearly tripling since 2020. […]
- New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Fundsby info@thehackernews.com (The Hacker News) on June 16, 2026
Security researchers at Zimperium's zLabs have documented a new Android banking trojan, Rokarolla, that targets 217 banking and cryptocurrency apps and packs […]
- Survey: 94% of Incidents Involve Anonymized Infrastructure. Teams Are Still Reactiveby info@thehackernews.com (The Hacker News) on June 16, 2026
Security teams have never had more IP data at their disposal. Every day, analysts ingest enrichment feeds, geolocation data, reputation scores, telemetry, and […]
- CISA warns of another cPanel plugin flaw exploited in attacksby Sergiu Gatlan on June 16, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively […]
- Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Weekby info@thehackernews.com (The Hacker News) on June 16, 2026
Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on […]
- Ransomware gang abuses Microsoft Teams relays to hide malicious trafficby Bill Toulas on June 16, 2026
DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure. [...]
- China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealthby info@thehackernews.com (The Hacker News) on June 16, 2026
Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. "The […]
- FishMonger’s arsenal upgraded: SprySOCKS for Windowson June 16, 2026
ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness
- Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malwareby info@thehackernews.com (The Hacker News) on June 16, 2026
The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account […]
- Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flawby info@thehackernews.com (The Hacker News) on June 16, 2026
Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild. The […]
- CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalationby info@thehackernews.com (The Hacker News) on June 16, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited […]
- Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emailsby info@thehackernews.com (The Hacker News) on June 15, 2026
A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive […]
- North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channelsby info@thehackernews.com (The Hacker News) on June 15, 2026
Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster known as […]
- LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Serversby info@thehackernews.com (The Hacker News) on June 15, 2026
A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at […]
- One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codesby info@thehackernews.com (The Hacker News) on June 15, 2026
A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise […]
- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and Moreby info@thehackernews.com (The Hacker News) on June 15, 2026
Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This […]
- The Onboarding Password Mistake That Creates Unnecessary Riskby info@thehackernews.com (The Hacker News) on June 15, 2026
Employee onboarding is a busy time for IT teams. New starters need devices, accounts, access permissions, and passwords, all delivered within a tight […]
- 152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Trafficby info@thehackernews.com (The Hacker News) on June 15, 2026
Cybersecurity researchers have discovered a network of 152 Google Chrome extensions that act as new tab live wallpaper add-ons to distribute a potentially […]
- Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sitesby info@thehackernews.com (The Hacker News) on June 15, 2026
An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to […]
- EvilTokens: A phishing attack that doesn’t steal your passwordon June 15, 2026
A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login […]
- Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alertsby info@thehackernews.com (The Hacker News) on June 15, 2026
Cybersecurity researchers have disclosed details of fraudulent activity targeting users across the Middle East and North Africa by employing various fraudulent […]
- Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flawby info@thehackernews.com (The Hacker News) on June 15, 2026
Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain […]
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authenticationby info@thehackernews.com (The Hacker News) on June 13, 2026
Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file […]
- U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationalsby info@thehackernews.com (The Hacker News) on June 13, 2026
Anthropic said on Friday it will "abruptly disable" its most advanced artificial intelligence (AI) models, Claude Fable 5 and Mythos 5, for all users after the […]
- Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkitby info@thehackernews.com (The Hacker News) on June 12, 2026
Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any […]
- Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishingby info@thehackernews.com (The Hacker News) on June 12, 2026
Google on Friday said it's pursuing legal action against a Chinese cybercrime network, accusing it of using its Gemini artificial intelligence (AI) agent to […]
- China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decadeby info@thehackernews.com (The Hacker News) on June 12, 2026
Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system […]
- CISA Instructs Federal Agencies to Adopt Risk-Based Approach for Vulnerability Remediationby Steve Alder on June 12, 2026
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive (BOD 26-04) establishing new deadlines for […]
































