| |
|
Date: Jun 03, 2026 |
|
|
|
Date: Jun 03, 2026
|
| |
|
Cyber Security News
|  |
Chinas Webworm Uses Discord Microsoft Graphs to Hack EU Governments
The advanced persistent threat group also relied on SOCKS proxies like SoftEther VPN, tunneling tools that act as a middleman between victim and attacker. Read More...
| |
|  |
Google API Keys Remain Active After Deletion
A security researcher discovered the API keys can still be used for up to 23 minutes after deletion, even though the cloud provider claims deletion is immediate... Read More...
| |
|  |
Fake Android Apps Commit Carrier Billing Fraud for Premium Services
The disguised apps use WebView automation, JavaScript injection, and OTP interception to avoid detection and complete fraudulent subscriptions. Read More...
| |
|  |
BTMOB RAT Spreads Across Brazil LatAm via MaaS Model
An advanced remote access Trojan is propagating online. Notably, it's delivered via an operator licensing model and features a no-code malware-development inter... Read More...
| |
|  |
Ransomware Actors Show Up In Person to Steal Law Firm Data
The FBI warned that the extortion gang Silent Ransom Group is targeting law firms and social-engineering its way into servers and databases. Read More...
| |
|
Best Practices
|  |
Why DDoS attacks have become a permanent threat for Gulf enterprises
AI-powered attacks and regional tensions are driving a new era of persistent cyber disruption across the Middle East Read More...
| |
|  |
Glassworm botnet that targeted OS devs smashed to pieces
CrowdStrike, Google and the Shadowserver Foundation worked together to take down a botnet that poisoned over 300 GitHub repositories, risking widespread supply ... Read More...
| |
|  |
Microsoft disrupts malware code-signing service used by ransomware gangs
Microsoft has disrupted the infrastructure powering the largest malware code-signing service used to help ransomware groups and other cyb... Read More...
| |
|  |
GitHub admits major source code leak after 3800 internal repositories breached
Microsoft’s GitHub has suffered what appears to be its biggest ever security breach after confirming that attackers exfiltrated code from... Read More...
| |
|  |
Vulnerability exploitation now primary origin of data breaches
Verizon’s annual cyber report reveals a major change in how data breaches originate, highlighting the impact of artificial intelligence Read More...
| |
|
New Threats and Vulnerabilities
|  |
Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations
Summary
The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint advisory to dissemina... Read More...
| |
|  |
FBI-Flagged Phishing Kit Kali365 Expands Its Reach
Once targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing. Read More...
| |
|  |
Microsofts Zero-Day Legal Threats Spark Backlash
After a disgruntled security researcher published several zero-day exploits in recent weeks, Microsoft seemingly indicated criminal charges were in order. Read More...
| |
| _Sergey_Tarasov_Alamy.png?width=1280&auto=webp&quality=80&disable=upscale) |
Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit
Exploiting the PAN-OS GlobalProtect VPN vulnerability requires certain conditions, but adversaries have done so in two attack waves that started in mid-May. Read More...
| |
|
Patch Management
|  |
Claude Mythos AI Finds 10000 High-Severity Flaws in Widely Used Software
Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "sys... Read More...
| |
|  |
Cisco Patches CVSS 100 Secure Workload REST API Flaw Enabling Data Access
Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensi... Read More...
| |
|  |
MFA Prompt Bombing: Why Your Second Factor Isnt Saving You
Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account credential... Read More...
| |
|  |
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following t... Read More...
| |
|
AI and Security
|  |
SAP customers warned AI agents could put costs on autopilot
Gartner has warned that SAP users adopting its AI agents could face spiraling costs as the vendor moves to a new commercial model. Last week, the German ERP gi... Read More...
| |
|  |
Cisco used AI to write security incident reports with mixed results
Cisco tested AI’s ability to write an accurate report on a tabletop security incident response exercise, and found that while the tech can save time, many risk... Read More...
| |
|  |
AI is getting expensive but relief is on the way - just not for you
Generative AI apps and services are getting more expensive by the day as model devs grapple with surging infrastructure costs. A new generation of GPUs and AI ... Read More...
| |
|
|
|
|
|