What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,042 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 3d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 4d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 5d ago
-
American Tower: 216,601 accounts breached
Data exposed: Email addresses, Job titles, Names, Phone numbers, Physical addresses. In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign . …
-
What’s the Average Cost of a Data Breach in 2025? | Huntress
Learn what the average cost of a data breach is and how factors like industry and location impact it. Plus, learn how to protect yourself from costly breaches.
-
The Coming Divide: AI-Native or Left Behind
The Coming Divide: AI-Native or Left Behind/images/blog/ai-native-divide/header.webp/images/blog/ai-native-divide/header.webp I'm getting more worried, and more frustrated, about this new phase of AI disillusionment. Some of it is…
-
How to Spot a Client in the DoD Industrial Base That Handles CUI
Learn how MSPs/MSSPs can identify if a client is a DoD contractor handling CUI.
-
Voluptuous volcanoes – in Yakutia.
After my Korean interlude, it s back to tales from the deep-frozen Siberian side; namely – a continuation of our drive along the winter road between the villages of Khonuu and Sasyr. The first installment is here. We d wrapped up …
-
27 Biggest Data Breaches in History: Famous Examples
Learn about the biggest data breaches of the past 20 years, how they happened, and how you can better protect your organization from major threats.
-
The 36 Most Common Cyberattacks (2026) | Huntress
Learn about some of the most common cyberattacks, how threat actors access computers and networks, and how to lower future risks.
-
CVE-2026-12569: PTC Windchill and FlexPLM — PTC Windchill and FlexPLM Improper Input Validation Vulnerability
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.
-
CVE-2026-20230: Cisco Unified Communications Manager — Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated,…
-
Ireland’s EU Presidency Will Put Cyber Risk in the Spotlight. Are Irish Boards Ready?
As Ireland prepares to assume the Presidency of the Council of the European Union, many organisations are understandably focused on the opportunities that come with having Ireland at the centre of European policymaking for six mon…
-
Madison Square Garden Sports: 9,796,738 accounts breached
Data exposed: Customer service records, Email addresses, Names, Phone numbers, Physical addresses. In June 2026, the sports and entertainment company Madison Square Garden Sports was the target of a ShinyHunters "pay or leak" exto…
-
After Seoul pleasantries – something somber: prison history to remember.
After our walk around central Seoul – next up: something wholly unusual: a prison! And this particular prison tells a very sad tale… From 1910 to 1945, Korea was occupied by Japan, which was extremely heavy-handed in Korean territ…
-
From Code to Coverage (Part 6): What netlogon.log Sees That Event 1644 Never Will
ldapnomnom claims it leaves no Windows audit logs. This post shows why Event 1644 misses LDAP Ping and where defenders can still catch it.
-
Weekly Update 509
I know enough about home cinema audiovisual to know there s a lot I don t know. It s conscious incompetence, if you like, which is different to the unconscious incompetence most people have on the topic. That s not to sound deroga…
-
Hacking et cybersécurité pour les Nuls 2e édition: New Edition of French Book on Hacking and CyberSecurity
Hacking et cybersécurité pour les Nuls 2e édition, a new second edition of the French versions of the latest editions of both the best selling CyberSecurity for Dummies by Joseph Steinberg, and Hacking For Dummies by Kevin Beaver,…
-
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London …
-
Wiley Profiles Cybersecurity Expert Witness And Author Joseph Steinberg
Wiley, a 218-year-old American multinational publishing company that focuses on academic publishing and instructional materials, and that publishes the For Dummies series of self-help books, recently profiled cybersecurity expert …
-
CVE-2025-67038: Lantronix EDS5000 — Lantronix EDS5000 Code Injection Vulnerability
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
-
CVE-2026-34910: Ubiquiti UniFi OS — Ubiquiti UniFi OS Improper Input Validation Vulnerability
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
-
CVE-2026-34909: Ubiquiti UniFi OS — Ubiquiti UniFi OS Path Traversal Vulnerability
Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
-
CVE-2026-34908: Ubiquiti UniFi OS — Ubiquiti UniFi OS Improper Access Control Vulnerability
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
-
We Need to Talk About Device Code Phishing
During the June Tradecraft Tuesday, Huntress researchers looked at device code phishing variations and why threat actors love this attack so much.
-
Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress
Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users with Huntress SAT.
-
Debating the Morality of Dario Amodei
https://www.youtube.com/watch?v=0FxXr3enprE My discussion with @ZackKormanhttps://x.com/ZackKorman on whether Dario and Anthropic are good or bad for the world. Some quick post-debate thoughts: I think Zach is very wrong about the…
-
My Updated Definitions of AGI vs. ASI
My Updated Definitions of AGI vs. ASI/images/agi-vs-asi-definitions.webp/images/agi-vs-asi-definitions.webp I've been working on a better way to think and talk about AGI and ASI. I've thought a lot about these terms in the past, b…
-
JCPenney: 368,418 accounts breached
Data exposed: Dates of birth, Email addresses, Government issued IDs, Job titles, Names, Phone numbers, Physical addresses, Usernames. In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or l…
-
An update on FortiBleed — what’s happening with victim orgs
An update on FortiBleed — what’s happening with victim orgs Two days ago I wrote something about FortiBleed: FortiBleed — 75k Fortinet firewalls have admin passwords cracked Fortinet told media orgs the data was from prior breache…
-
The Ultimate Prompt For Businesses Being Pushed Into Using AI
Companies with money but no AI vision burn down while the disciplined few pull away/images/ultimate-ai-prompt-for-businesses.webp/images/ultimate-ai-prompt-for-businesses.webp Absolutely insane to me the damage that multiple compa…
-
Weekly Cyber Update: 18 June 2026
Ransomware actors hide in Teams; a massive Fortinet credential leak; Litespeed users are targeted; and warnings of nation state OT activity and AI data leakage. The Cyber Threat Intelligence Briefing is a weekly round-up of the la…
-
Ralph Lauren: 139,903 accounts breached
Data exposed: Age groups, Email addresses, Genders, Names, Phone numbers. In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published hundreds of g…
-
Operation Endgame 4.0: 4,348,526 accounts breached
Data exposed: Email addresses, Passwords. On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation , a prolific malware distribution network used to compromise systems and facilitate further…
-
Prompts to Run When a New Pinnacle Model Drops
A runner coiled in the starting blocks, looking down a glowing purple lane/images/things-to-do-when-fable-comes-back.webp/images/things-to-do-when-fable-comes-back.webp I originally wrote this for Claude's Fable 5, but the list ap…
-
Intelligence Insights: June 2026
ClearFake is the clear-cut number one again and Kali365 debuts in this month’s edition of Intelligence Insights
-
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, re…
-
‘Fighting Back’ Against AI Audits
If you think AI tools alone can take over managing your ISMS, read on. Jenny Odell, the artist, writer and lecturer at Stanford University, once described the concept of context collapse. This is a modern phenomenon where, thanks …
-
Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress
Huntress was one of many vendors impacted by a recent incident at Klue. We dug into the incident to figure out what happened.
-
CFGI: 248,235 accounts breached
Data exposed: Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses. In March 2026, the financial consulting and advisory firm CFGI was the target of a ShinyHunters "pay-or-leak" extortion campaign . The…
-
CVE-2026-20253: Splunk Enterprise — Splunk Enterprise Missing Authentication for Critical Function Vulnerability
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.
-
A Unified Theory For How AI Will Affect Jobs
The K-shaped bifurcation: thriving behaviors climbing above a rising Employability Line, struggling behaviors sinking below it/images/unified-theory-ai-jobs-k.webp/images/unified-theory-ai-jobs-k.webp Tyler Cowen recently made the…
-
The dual-use dilemma: Rethinking detection for remote access tool abuse
A comprehensive guide to the most commonly abused RMM tools, including technical guidance for detection and prevention
-
FortiBleed — 75k Fortinet firewalls have admin passwords cracked
FortiBleed — 75k Fortinet firewalls have admin passwords cracked An interesting post popped up on LinkedIn at the weekend from Voldymyr Diachenko saying plain text passwords were found in the wild by Hunt Intelligence Inc for Fort…
-
Why Your Organization Needs ISPM
Huntress Managed ISPM finds and closes Microsoft 365 identity gaps before attackers do. Learn why visibility isn't enough and what real identity hardening takes.
-
From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker
Key Points Introduction In this research, we analyze a clipboard hijacker campaign that is hidden inside a collection of “solutions” and “tools” that claim to give users an unfair advantage. These offers include Solana and Pump.fu…
-
AI Autopsy: South Staffordshire Water’s £1m Lesson in Visibility
An ICO incident post-mortem has some useful takeaways for CISOs Carly Page finds out how attackers managed to stay hidden inside the company’s network for two years Read the rest of AI Autopsy: South Staffordshire Water s £1m Less…
-
Speed Kills
Hitler's blitzkrieg ran on amphetamines and a fantasy of permanent victory. There are signs Washington is flirting with the same logic and that logic has an ending.
-
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack
A ClickFix infection drops Potemkin loader and RMMProject RAT, leading to browser theft, hidden remote desktop, and lateral movement across over 11 hosts.
-
EU Cybersecurity Act 2.0: When good regulation goes bad
In a new opinion piece published on Help Net Security, BH Consulting CEO Brian Honan examines why the proposed EU Cybersecurity Act 2.0 risks doing more harm than good, warning that designating vendors as high-risk based on geopol…
-
CVE-2026-48907: Widget Factory Joomla Content Editor — Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
-
June 2026 Stealer Logs: 56,278,397 accounts breached
Data exposed: Email addresses, Passwords. In June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log re…
-
Onyxia Accepted into Anthropic’s Cyber Verification Program
We're excited to announce that Onyxia Cyber has been accepted into Anthropic's Cyber Verification Program (CVP) — a designation reserved for security organizations using advanced AI capabilities strictly for defensive purposes.
Last fetch 19m ago · 0 new · 2 source error(s)