What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,042 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 3d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 4d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 5d ago
-
Moody Bible Institute: 2,303,416 accounts breached
Data exposed: Dates of birth, Email addresses, Genders, Marital statuses, Names, Phone numbers, Physical addresses. In June 2026, Moody Bible Institute was targeted by a ShinyHunters "pay or leak" extortion campaign . Over 2.3M un…
-
On the shortest of Bogotá stays – the curious case of the coffee-bean ashtrays.
It was a short flight from Lima, Peru up to Bogotá – the capital of Colombia. We had just one day here, and it was a strictly business one at that – alas, no tourism this time. No shots of unusual nature or off-the-beaten-path spo…
-
Weekly Cyber Update: 3 July 2026
Oracle EBS customers targeted; ransomware surges in Europe; A massive Microsoft 365 password spraying campaign; OpenAI used for eavesdropping; FortiBleed is linked to two major ransomware groups The Cyber Threat Intelligence Brief…
-
Swimming Pools, Pee, and Trying to Delete Your Data From the Internet
I can t recall if someone else originally came up with this saying or if I said it in some off-the-cuff comment and it just propagated, but since it s often attributed back to me , I ll relay it here regardless: Trying to delete y…
-
FBI Seizes NetNut Proxy Platform, Popa Botnet
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alaru…
-
Guide to Cloud Application Security: Must-Knows and No-No’s | Huntress
Cloud application security keeps threat actors away from your data. We share practical ways to protect your apps and why it matters for your team today.
-
From Cloud to Chaos: Defining Shared Responsibility for AI Security
For 15 years (!), many of us who have touched cloud security have struggled with the shared responsibility model for cloud security. As with many “cyber things,” the theory is simple. Multiple vendors, consulting firms, and indust…
-
The Gentlemen ransomware: what you need to know
Who Are The Gentlemen? Despite the impeccably polite name, there is nothing polite or refined about this particular gang of cybercriminals. Read more in my article on the Fortra blog.
-
LGBT Q&A: How Can I Wipe Online Data That Points To My Queer Identity?
This Pride, we’re answering all your digital rights questions in season two of our initiative, LGBT Q A . You Asked: Is there a way for me to wipe data about me online that could point to my queer identity? EFF’s Answer: You canno…
-
Our analysis of the DPC Annual Report: AI’s growing influence
Privacy professionals and a human-led privacy framework are more necessary than ever at a time when AI tools make it easy for individuals to assert their rights under GDPR. As the volume of data protection cases submitted to the D…
-
EFF and Allies: X’s FTC Petition to Waive Privacy Violation Order Should be Rejected
X Corp. should not be able to escape privacy compliance because it changed its name. On May 15, X Corp. filed a petition before the Federal Trade Commission (FTC) to set aside or modify an order issued in 2022 requiring the compan…
-
Partners – nice to see you; here in sunny Peru!
Hola folks! Lima oceanside walkies – done; next up – our LatAm partner conference, with 220 guests, from 19 countries. So. What? Why?! It all rather straightforward really. Practically any mass-market product is sold not directly …
-
Navigating NIS2 as Ireland’s Cyber Security Bill comes into view
Cybersecurity regulatory expectations have shifted significantly: what used to be primarily an IT concern has evolved into a board-level governance obligation. Directors now need to actively oversee cyber resilience, risk manageme…
-
Celebrating Canada Day with Localized Managed Phishing
Huntress Managed SAT now offers localized phishing simulations for Canada, using familiar, country-specific brands and scenarios to provide more effective security awareness training for your learners.
-
Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?
Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the airport hair…
-
Lateral Movement Attack: Techniques, Detection & Prevention
Huntress explains lateral movement attacks, how attackers move through networks, common techniques like pass-the-hash, and how Managed EDR stops lateral movement.
-
In the Peruvian capital – an urban coastal ramble.
Cities come in all shapes and sizes. There are the standout urban projects – like the island-city-state of Singapore. There are megacities that really lucked out with phenomenal natural beauty all around them – Rio de Janeiro, for…
-
How the RaaS Business Model Actually Works
Ransomware-as-a-Service turned ransomware into a scalable criminal business. Learn how the model works, why it creates so much disruption, and where defenders can shut attacks down before encryption starts.
-
22nd June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Texas Parks and Wildlife Department has been affected by a third-party data breach …
-
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, large language models have reshaped software development, and malware development has followed the same path. Check Point Research has documente…
-
Security Roundup June 2026
Curated advice, guidance, learning and trends in cybersecurity and privacy, as chosen by our consultants. New initiative to foster female cybersecurity leadership comes to Ireland A new initiative aiming to encourage people from d…
-
WhatsApp to begin rolling out usernames
Curated by Sherpa Intelligence : Your Guide Up a Mountain of Information WhatsApp to begin rolling out usernames Summary: WhatsApp users may begin to register a “claim” for their preferred username. Can only be done via app, will …
-
Four days to Yakutsk Airport.
Leaving Zyryanka, it struck me: the nearest airport with regular flights to the capital of our vast and boundless homeland is a full four days away by car! Well, if you really push it and don t sleep at night, you could manage it …
-
CVE-2026-45659: Microsoft SharePoint Server — Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
-
Scammers race to cash in on Venezuelan earthquake disaster
Scammers wasted no time exploiting Venezuela's devastating earthquake, with researchers uncovering 212 newly-registered relief-themed domains in just five days. Read more in my article on the Hot for Security blog.
-
No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack
Huntress is seeing an ongoing password spray attack against Microsoft Azure CLI that originates from an IPv6 address range controlled by LSHIY LLC.
-
Anton’s Security Blog Quarterly Q2 2026
My Anton’s Security Blog Quarterly covers both Anton on Security and my posts from Google Cloud blog , Google Cloud community blog , and our Cloud Security Podcast ( subscribe on Spotify, now with VIDEO ). Top 10 posts with the mo…
-
What Does a Pentest Report Look Like? Inside the Results
If your last pentest report was a spreadsheet of CVE numbers with color-coded severity ratings, here is an uncomfortable truth: you did not get a penetration test. You got a vulnerability scan with a cover page.
-
Weekly Update 510: Live From Mallorca with Scott Helme
How s the view?! Back to business, it s now 8 years ago that Scott and I thought it would be a cool idea to build Why no HTTPS? We used the site to shame companies for not implementing their transport later security property, and …
-
Microsoft 365 Hardening and Huntress Managed ISPM
Most Microsoft 365 environments are missing more than half of the recommended security controls, even with tooling in place. Here's why that happens and what Huntress Managed ISPM does about it.
-
Train, triage, repeat: The AI agent changing how we fight phishing
Learn how Red Canary engineered a super agent—blending ML, a rules engine, similarity, agentic AI, and LLMs—to classify phishing emails.
-
LGBT Q&A: What Data Are Companies in the UK Collecting When Verifying My Age?
This Pride, we’re answering all your digital rights questions in season two of our initiative, LGBT Q A . You Asked: I live in the UK, and we have age verification now on a bunch of websites (including Reddit) and now on iPhones. …
-
The Top CISO Stories from Around the Web: June 2026
Between tight post-quantum deadlines and hackers turning lookalike AI tools into dangerous new entry points, today's CISOs are facing an unprecedented operational squeeze. This month, we dive into the fundamental questions securit…
-
Stop Building a 2003 SOC with AI: A Modern People & Process Framework (Part 1)
One particular aspect of an agentic or AI-powered SOC (but NOT “humanless SOC ”) has bothered me over the last few months: specifically, the people and process side of such a SOC. If you recall my blog posts ( part 1 , part 2 and …
-
I heard a lovely new bit of music today, pleasant, heartfelt, expressive. Asked Siri what it was, and after tw…
I heard a lovely new bit of music today, pleasant, heartfelt, expressive. Asked Siri what it was, and after two failed attempts it hit me — It's AI. Well, crap then...
-
EFF to Gov. Pritzker: Veto Illinois’ HB 5511
The Illinois legislature recently passed House Bill 5511 , which imposes a sweeping, device-level age-gating framework across nearly all internet-enabled hardware, operating systems, and online services. This well-intentioned but …
-
Victory! Supreme Court Says Constitution Protects People’s Location Data
You have an expectation of privacy in location data that reveals your movements in the physical world, and even short-term surveillance of these movements is a search subject to the Fourth Amendment, the U.S. Supreme Court ruled t…
-
Tracking Costs, Time and Mistakes On An AI Project
Recent articles and a GitHub Repo for tracking AI vibe coding results If you haven’t noticed yet I have a new blog so my posts here are a bit sporadic. You can find the most up to date information here: Teri Radichel :: Security a…
-
29th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Polymarket, a large cryptocurrency-based prediction market, has confirmed a supply …
-
The Hacker's 2026 Playbook: Dark Web Tactics Targeting You
Cybercriminals are hijacking Microsoft 365 accounts in seconds. Learn the 2026 hacker tactics, including ConsentFix, that bypass security training and exploit normal user behavior.
-
These Recent Insider Threat Allegations
-
Defence Impairment Olympics
Huntress analyzed a credential dumping attack where threat actors disabled Defender, killed monitoring tools, and used Mimikatz to steal credentials.
-
CVE-2026-48558: SimpleHelp SimpleHelp — SimpleHelp Authentication Bypass Vulnerability
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signatur…
-
Sysco: 2,691,852 accounts breached
Data exposed: Customer feedback, Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Usernames. In June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion…
-
The Crash-Test Problem & Why Safer Software Won’t Come From Goodwill
Last week I argued that AI has just handed our industry an enormous safety dividend, and that risk homeostasis warns us we will quietly spend almost all of it on speed unless we deliberately choose otherwise. I ended by asking you…
-
Sasyr > Zyryanka on the Arktika winter road.
Overall, the main items on the wish list for our winter Irkutsk-Yakutsk-Magadan-Yakutsk road-trip had either been checked off (the Indigirka Tube, the naleds and volcanoes of the Moma Valley, the Natalka gold deposit), or only uns…
-
EFF to Grindr: This Pride Month, Put Safety and Privacy Over Profits
This Pride month, we’re calling on the dating app Grindr to prioritize LGBTQ+ user safety by making privacy the default across its platform. That means no more sharing personal data with advertisers or training AI on private infor…
-
Hate “The Algorithm?” RSS Is One of the Tools You’ve Been Looking For
Poke your head into just about any online social network—or any general conversations about internet culture—and you’ll likely find a boogieman: the algorithm. Since at least the moment Facebook introduced ( and apologized for ) i…
-
Weekly Cyber Update: 26 June 2026
More warnings over frontier AI; another OAuth supply chain breach; maximum severity Ubiquiti flaws are exploited; and a phishing awareness exercise goes badly wrong The Cyber Threat Intelligence Briefing is a weekly round-up of th…
-
An Unemotional Analysis of This AI Regulation Situation
An Unemotional Analysis of This AI Regulation Situation/images/ai-regulation-unemotional-analysis.webp/images/ai-regulation-unemotional-analysis.webp Here's a more logical and less emotional way to look at what's happening with th…
Last fetch 4m ago · 0 new · 2 source error(s)