“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited [email protected] (The Hacker News)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 26, 2026. The vulnerability in question is CVE-2025-67038 (CVSS score: 9.8), a code injection flaw that could result…
-

Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered [email protected] (The Hacker News)
A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. “The main common goal was to disrupt the ‘assembly lines’ cybercriminals use to launch ransomware, financial fraud, and attacks on critical infrastructure,” Europol said inRead More
-
As Q-Day looms, 90% of systems are unprepared for PQC
Quantum computing could break encryption in the next several years, and research suggests that few organizations are ready. Experts say CISOs must act now.Read More
-

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks [email protected] (The Hacker News)
Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains. The “critical exploitable pattern” has been codenamed Cordyceps by Novee Security. The issue can allow full attacker control of repositories at dozens of the largest organizations worldwide, including Microsoft, Google, Apache, andRead More
-

Dawn of the Apex Agentic Adversary [email protected] (The Hacker News)
We are standing at the end of an era we never thought to mourn: the era of human-speed threats. For years, cybersecurity moved to a rhythm organizations could follow. A researcher found a bug, a CVE was cataloged, a vendor navigated a patch cycle, and weeks or even months later, a fix was deployed. In…
-

DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering [email protected] (The Hacker News)
The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by subsidiaries of Cambodia-based corporate conglomerate HuiOne Group, as the Treasury unveiled fresh sanctions against nine individuals and 26 entities linked to Prince Group. “These subsidiaries are alleged to have assisted individuals and organizations in transferring…
-

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root [email protected] (The Hacker News)
Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input validation for specific HTTP requests that could allow an unauthenticated, remoteRead More
-
Oracle PeopleSoft Zero-Day
What is the Attack? Google Threat Intelligence Group (GTIG) and Mandiant have identified an active compromise and extortion campaign attributed to ShinyHunters (tracked as UNC6240) targeting Oracle PeopleSoft environments. The attackers exploited a previously unknown remote code execution vulnerability, CVE-2026-35273, before Oracle released an advisory and patches, making this a true zero-day attack. The campaign…
-

FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation [email protected] (The Hacker News)
A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as FortiBleed that has targeted over 430,000 FortiGate firewalls globally. The campaign, active since February 2026, involves collecting credential lists, searching for exposed services, brute-forcing accessible systems, and deploying bespokeRead More
-

Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents [email protected] (The Hacker News)
Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts. Every skill security scanner the firm tested it against marked it safe. The payload was harmless by design: it collected the user’s email address and…
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
