TIB Notification

View in browser

  ClearInfosec Date: Jun 24, 2026
Date: Jun 24, 2026

Cyber Security News

Maine forced to take down data breach portal after fake notices filed with authorities
The US state of Maine has taken its public data breach notification portal offline after someone submitted fraudulent breach disclosures impersonating two well-... Read More...
Copilot SearchLeak Attack Allows 1-Click Data Theft
The critical, three-stage attack is now patched, but it's part of a new group of AI prompt-injection issues that use hidden URLs and other variables. Read More...
INC Ransomware Thrives by Mastering the Basics
And one of those basics is focusing on sectors where a ransomware disruption creates immediate pressure to pay up, like with healthcare. Read More...
Scope of Salesforce Attacks Expands as Icarus Leaks Data
More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers' Salesforce data. Read More...
Hacker hijacks Brazil’s national alert system sending “misanthropy” to millions of phones
Emergency alert systems work because people believe them. Every time one of these systems issues a false alert - whether through negligence or a deliberate atta... Read More...

Best Practices

What are the cyber threats to the 2026 Fifa World Cup?
Dig deeper on some of the security issues facing the 2026 World Cup as the tournament faces unprecedented threat levels and challenges Read More...
Attackers abuse Google Ads GitLab and Claude to deliver malware
Threat actors are abusing trusted platforms, including Google Ads, GitLab pages, and Claude’s shared chat feature, to trick users into ex... Read More...
FortiBleed campaign exposes 75000 Fortinet firewalls worldwide
A massive credential-compromise campaign dubbed “Fortibleed” has been found to expose tens of thousands of Fortinet devices worldwide, wi... Read More...
UK government and Cisco unveil AI digital skills initiative
Networking giant and UK Department for Science, Innovation and Technology announce strategic collaboration to help increase AI adoption and widen access to digi... Read More...
AI is exposing the biggest weakness in cybersecurity: We never built a health model Until now!
For 30 years, cybersecurity has operated like an emergency room. Reactive. Crisis-driven. Always triaging. We are extraordinarily good... Read More...

New Threats and Vulnerabilities

China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. "The Win... Read More...
LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian... Read More...
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails Files and MFA Codes
A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise S... Read More...
Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider
Summary The Cybersecurity and Infrastructure Security Agency (CISA) is releasing this advisory in response to ransomware actors leveraging unpatched instances o... Read More...
Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations
Summary The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint advisory to dissemina... Read More...

Patch Management

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. S... Read More...
Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account se... Read More...
Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild. The vul... Read More...
Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive rese... Read More...
CISA Adds Cisco Chrome and Arista Flaws to KEV Catalog Amid Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog... Read More...

AI and Security

Anthropic recruits army to sell Claude to nonprofits
AI may or may not be pushing lots of people out of the workforce, but Anthropic has good news as the Claude creator is creating temporary positions to promote ... Read More...
Inside the clouds new agentic AI-ready Arm-powered foundation
When Spotify evaluated its cloud compute options, it needed more than incremental improvements. Its recommendation engine delivers real-time suggestions to mil... Read More...