“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution [email protected] (The Hacker News)
Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent to load an attacker’s web page, and that page’s JavaScript can reach a privileged local service on the same machine and spawn a process on the host. No credentials, no…
-

Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites [email protected] (The Hacker News)
Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites. “With these actions we deprive cybercriminals of access to infected computer systems,” Maikel Rollman of the Netherlands National High Tech Crime Unit said. “This preventsRead More
-

CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices [email protected] (The Hacker News)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps to secure against ongoing malicious activity aimed at thousands of internet-accessible devices. The sweeping campaign, believed to be the work of Russian-speaking threat actors, has been codenamed FortiBleed. The number of compromised devices stands atRead More
-

From Assistive to Agentic: The AI Shift That’s Redefining Threat Management [email protected] (The Hacker News)
Introduction The average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset data. But often, these tools are working in siloes, generating (overlapping) alerts and data. And yet, breach dwell times remain stubbornly long (~43 days), response windows keep closing before teams can act, and…
-

Forget Data Leakage: Shadow AI’s Real Threat Is Access Control [email protected] (The Hacker News)
The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security teams responded with usage policies, domain blocks, and data loss prevention rules. That response made sense at the time. It doesn’t fit the problem anymore. Shadow AI has shifted from a data leakage concern…
-

Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data [email protected] (The Hacker News)
Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026. To that end, organizations will be unable to connect to Salesforce via the app until further notice, the American cloud-based software company noted in an alert…
-

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone [email protected] (The Hacker News)
Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users. The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorrect authorization impacting the Airoha Bluetooth audio SDK that makes it possible to pair a Bluetooth audio…
-
Most security pros say their culture is ‘just average’
‘The Life and Times of Cybersecurity Professionals’ survey assessed how workers feel about defending against constant threats, as well as what’s getting better and what is not.Read More
-

F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution [email protected] (The Hacker News)
F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems. The vulnerabilities are listed below – CVE-2026-42530 (CVSS v4 score: 9.2) – A use-after-free vulnerability in the ngx_http_v3_module that could be triggered by a remote unauthenticated attacker when NGINX…
-

ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories [email protected] (The Hacker News)
The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. Cloud agents looked like helpers until attackers treated them like open shells. Add exposed…
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
