> TODAY'S SUMMARY (11 articles)
Today's cybersecurity landscape highlights several significant threats and trends. Notably, the Warlock ransomware group continues to exploit year-old SharePoint vulnerabilities to target critical infrastructure, affecting essential services globally. Meanwhile, the ShinyHunters group faces increased scrutiny, with a suspect detained in Jordan cooperating with the FBI to identify other members. Additionally, a new China-aligned cyber espionage group, TA419, is actively targeting U.S. AI policy experts through sophisticated phishing campaigns. In the realm of artificial intelligence, former National Intelligence Director Jay Clayton is set to lead a new federal task force aimed at addressing AI-related security challenges. These developments underscore the ongoing risks posed by ransomware, cyber espionage, and the evolving landscape of AI security.
|
// AI-powered summary generated at 16:00
Outsider provided phishing kits and infrastructure for cybercriminals to scam victims with lures claiming they missed packages, had unpaid tolls or parking violations.
The post FBI takes down massive China-based cybercrime network that caused $1.9B in losses appeared first on CyberScoop.
Pro-Iran group Handala breached Cal Water via an exposed GPS tool, reaching billing data for 2M customers. 5GB leaked. On June 11, 2026, the Iran-linked threat group Handala posted a claim on its blog that it had compromised California Water Service, known as Cal Water, and published a 5GB proof-of-...
A disgruntled researcher who has been publishing zero-day Microsoft Windows vulnerabilities for the past several months released a new exploit Thursday that promises to bypass BitLocker encryption on locked devices. A well respected security expert reported that the exploit do...
This fluid pump was inspired by the way squids propel themselves through the water.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy.
Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them.
The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBPF r...
Maine has taken its public data breach reporting portal offline after fraudulent breach disclosures were published on the state's website, prompting a review of procedures to prevent abuse in the future. [...]
Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them.
The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBPF r...
Google on Friday said it's pursuing legal action against a Chinese cybercrime network, accusing it of using its Gemini artificial intelligence (AI) agent to send phishing text messages targeting Americans.
The network is said to be behind the development and management of a phishing-as-a-service (P...
It was discovered that missing input sanitising in the PNM/PBM parser of the reference code implementation of the JPEG XL format could result in denial of service or potentially the execution of arbitrary code if malformed images are processed. For the stable distribution (trixie), this problem has...
Two security vulnberabilities were discovered in librabbitmq, an AMQP client library, which could result in denial of service or potentially the execution of arbitrary code. For the stable distribution (trixie), these problems have been fixed in version 0.15.0-1+deb13u1.
Argentina's World Cup squad had their passport numbers leaked before a ball was kicked - not by hackers, but by someone who failed to redact a document properly. document. It's a mistake that has been made many times in the past...
Read more in my article on the Hot for Security blog.
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)Â added Ivanti Sentry flaw, tracked as CVE-2026-10520 (CVSS score of 10.0), to its Known Exploited Vulne...
The website specialized in non-consensual sexual images of famous women, including politicians, first ladies, royalty, journalists, television presenters, athletes, and entertainers, and others.
The post US, France, and Italian authorities shut down massive deepfake porn site appeared first on Cyber...
Iowan’s scheme undone after misplacing trust in former coworker
A 10-year-old authentication bypass vulnerability discovered in the phpBB forum software allows an attacker to log in as any user, including administrators. [...]
Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system itself.
Sygnia, which tracks the group as Velvet Ant, says it backdoored the PAM and OpenSSH components that decide who is allowed to sign in,...
A Ukrainian national extradited from Ireland to the United States last year has pleaded guilty to conspiracy charges tied to the Conti ransomware operation. [...]
Oleksii Lytvynenko, a 44-year-old Ukrainian national, admitted to joining the prolific cybercrime group in 2021. Officials said he engaged in cybercrime up until his arrest in Ireland in 2023.
The post Conti ransomware group member pleads guilty, faces up to 20 years in prison appeared first on Cybe...
The tech giant said a group called "Outsider Enterprise" used AI to scam hundreds of thousands of victims, sending 2.5 million text messages over a span of two weeks.
About 7 million customers of the genetics testing company had their data stolen by hackers starting in April 2023, and many had their information posted on the dark web.