What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,043 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 3d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 4d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 5d ago
-
Onyxia Accepted into Anthropic’s Cyber Verification Program
We're excited to announce that Onyxia Cyber has been accepted into Anthropic's Cyber Verification Program (CVP) — a designation reserved for security organizations using advanced AI capabilities strictly for defensive purposes.
-
The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed
A compromised terminal server became a phishing stager. A fake Boots survey aimed at 8.9 million inboxes, with the payload on a hacked Bolivian government site.
-
15th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 15th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The University of Nottingham, a UK research university, has suffered a data breach …
-
We Just Gave Software Its Anti-Lock Brakes But Has This Made Us Safer?
Last week I argued that cybersecurity may be solving the wrong problem i.e. that instead of chasing perfect prevention, we should change the conditions around the problem: build for resilience, make compromise matter less, design …
-
Weekly Update 508
Light switches. How on earth is it so hard to find decent light switches?! It sounds ridiculous until you actually spend enough time looking for ones that meet two simple criteria: Aren t stateful (switch is up or down, has to be …
-
Berkadia: 305,216 accounts breached
Data exposed: Email addresses, Employers, Names, Phone numbers, Physical addresses. In March 2026, the commercial real estate finance company Berkadia was the target of a ShinyHunters "pay or leak" extortion campaign . The group s…
-
Infinite Campus: 137,123 accounts breached
Data exposed: Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Support tickets, Usernames. In March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak"…
-
Boss Magazine Profiles Cybersecurity Expert Joseph Steinberg
Boss magazine this week features a profile of CyberSecurity Expert Joseph Steinberg, and discusses Steinberg s prowess for determining if evidence produced in lawsuits has been modified or misrepresented, and how Steinberg has hel…
-
CVE-2026-54420: LiteSpeed cPanel Plugin — LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.
-
CVE-2026-20262: Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.
-
14 Tips For Browsing The Web Securely
Modern web browsers are incredibly powerful, but their features — including security-related features such as saving passwords or keeping you logged in to a particular site or sites — can become vulnerabilities if not properly uti…
-
Weekly Cyber Update: 12 June 2026
Exploited vulnerabilities in Ivanti, ServiceNow, Exchange Server, Oracle PeopleSoft and ServiceNow; and commercial spyware vendor NSO Group targets WhatsApp users again The Cyber Threat Intelligence Briefing is a weekly round-up o…
-
Akira, LimeWire, and the Sour Taste of Data Exfiltration
A recent investigation uncovered an Akira affiliate abusing a website owned by file-sharing app LimeWire for data exfiltration. Here's how the attack unfolded.
-
CVE-2026-35273: Oracle PeopleSoft Enterprise PeopleTools — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
-
Inside Kali365, a Device Code Phishing Ecosystem | Huntress
Huntress traced device code phishing from Tencent Cloud to Kali365, a Microsoft 365 kit that steals tokens and keeps access even after MFA or password resets.
-
From SQLi to RCE – Exploiting LangGraph’s Checkpointer
By Yarden Porat AI agents need memory. Frameworks like LangGraph provide it through checkpointers persistence layers that store execution state. But what happens when that persistence layer isn t locked down? Key Points Background…
-
How threat hunting evolves at scale
We offer a practical roadmap for evolving informal, ad hoc threat hunting practices into a mature, scalable program
-
CVE-2026-10520: Ivanti Sentry — Ivanti Sentry OS Command Injection Vulnerability
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully…
-
University of Nottingham: 454,635 accounts breached
Data exposed: Academic records, Citizenship statuses, Dates of birth, Disabilities, Email addresses, Ethnicities, Genders, IP addresses, Names, Passport numbers, Phone numbers, Physical addresses, Purchases, Salutations, Usernames…
-
Who Runs the Ransomware Group ‘The Gentlemen?’
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 …
-
Deceptive Installers: How Fake Apps Target macOS
Deceptive installers disguised as legit macOS software deliver infostealers that grab passwords, cookies, and crypto wallets. Learn how to detect them.
-
People, Psychology, and Privacy Principles: Cybercrime, Scams, and AI Through a Human Lens
Cybercrime and data protection might be technical disciplines, but people and psychology are key to a deeper understanding. From the gangs responsible for cybercrime, to their victims, and to everyone whose right to privacy and di…
-
Weekly Update 507
1,000 breaches is one hell of a milestone. It s not just the process of getting data, verifying it, loading it, sending notifications etc, it s all the other stuff that goes into keeping the whole thing afloat. Legal docs. Tradema…
-
The Most Durable Human Value
A maker offering a small glowing hand-built world to another person leaning in to receive it/images/the-most-durable-human-value.webp/images/the-most-durable-human-value.webp I think one of the most human and durable things will b…
-
Basecamp Briefing: June 9, 2026
InfoSec + Data Privacy news along with tools and resources for your professional climb. InfoSecSherpa Sherpa Intelligence : Your Guides Up a Mountain of Information! Industry News 🏭📰 Laos pledges all-out offensive against cyber sc…
-
Agentic Threats: How to Manage a Problem Like OpenClaw
OpenClaw promises productivity gains, but its autonomy, access and growing shadow AI footprint could make it a security team s next major challenge OpenClaw has rapidly emerged as one of the most popular agentic AI tools in the wo…
-
Gartner Security Summit 2026: Huntress 5 Key Takeaways
Resilience, identity, and practical AI led the conversation at Gartner Security & Risk Management Summit 2026. Here are five key takeaways security leaders should act on.
-
CVE-2026-11645: Google Chromium V8 — Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utiliz…
-
CVE-2026-7473: Arista Extensible Operating System — Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its…
-
CVE-2026-20245: Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supp…
-
Bill to Create Independent US Cyber Force Wants to Place It Under the US Army
It looks like we're finally making progress towards an independent US Cyber Force: https://www.csis.org/programs/strategic-technologies-program/projects/commission-us-cyber-force-generation However, this bill by Sen Gillibrand to …
-
How to Rate the AI We're All Chasing
A three-axis rating gauge: the customization spoke longest, integration medium, competence shortest/images/customization-beats-competence.webp/images/customization-beats-competence.webp I'm increasingly rating the AI we're all cha…
-
Are We Solving the Wrong Problem in Cybersecurity?
I ve been circling a question all week, and I can t shake it. It surfaced again and again in the conversations I ve been part of — on conference floors, and far more pointedly behind closed doors, where cybersecurity leaders speak…
-
Choosing a Pentesting Company That Thinks Like an Adversary
5 Questions to Vet Any Penetration Testing Company Finding a pentesting partner that can produce a deep dive pentest is harder than knowing what one should look like. When evaluating vendors, seasoned adversarial firms and scanner…
-
Investigating suspicious AI workflows in Microsoft Entra Agent ID: Assistive agents
Assistive AI agents aren't always helpful—it all depends on who they're working on behalf of.
-
8th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 8th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES DentaQuest, a U.S. dental benefits administrator owned by Sun Life, has suffered a d…
-
CVE-2026-42271: BerriAI LiteLLM — BerriAI LiteLLM Command Injection Vulnerability
BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.
-
CVE-2026-50751: Check Point Security Gateway — Check Point Security Gateway Improper Authentication Vulnerability
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection wi…
-
Baker Distributing: 102,935 accounts breached
Data exposed: Email addresses, Names, Phone numbers, Physical addresses, Support tickets. In May 2026, the HVAC/R wholesale distributor Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" …
-
Finding the Middle in AI Narratives
A pendulum swung from a collapsing clock tower to an immovable monolith, its heavy bob now resting at center/images/finding-the-middle-in-ai-narratives.webp/images/finding-the-middle-in-ai-narratives.webp Another major AI vibe shi…
-
Why Huntress Doesn’t Need FedRAMP
Defense contractors can achieve CMMC compliance without the expense or delays of FedRAMP-authorized cloud services. Discover how Huntress uses Sensitive Data Mode for logical separation and cost-effective security.
-
Weekly Cyber Update: 5 June 2026
A new ClickFix campaign; a legacy Oracle flaw to patch; a new DoS attack to mitigate; software supply chain advice from the NCSC; and a warning from the CSA on patching velocity The Cyber Threat Intelligence Briefing is a weekly r…
-
BCD Travel: 396,313 accounts breached
Data exposed: Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Support tickets. In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or l…
-
CVE-2026-28318: SolarWinds Serv-U — SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.
-
Healthcare Compliance, Automated: Onyxia’s New Pre-Built HITRUST Custom Framework
Onyxia’s platform now includes a pre-built HITRUST template within our Custom Compliance Frameworks module. By bridging the gap between high-level compliance and real-time security data, Onyxia empowers healthcare organizations to…
-
DentaQuest: 2,553,599 accounts breached
Data exposed: Dates of birth, Email addresses, Genders, Government issued IDs, Health insurance information, Names, Phone numbers, Physical addresses. In May 2026, the dental benefits administrator DentaQuest was the target of a S…
-
AI Predicts the Text of Answers
A stream of text reasoning its way through a locked room, landing on the one glowing stone/images/ai-predicts-answers.webp/images/ai-predicts-answers.webp There's a common argument about AI that says it doesn't understand anything…
-
Thoughts on AI Adoption Speed
A human figure reaching upward, lifted by rising machinery — magnified, not replaced, by AI/images/ai-adoption-speed.webp/images/ai-adoption-speed.webp One of the most talked about AI topics is the speed of AI adoption in companie…
-
Inside .NET Loader Analysis: From Malspam to In-Memory Loader
A malspam campaign abusing Google's DoubleClick delivers the loader through a five-stage chain that evades detection and blinds Windows telemetry before persisting
-
Welcoming the Philippine Government to Have I Been Pwned
Today, we welcome the 46th government onboarded to Have I Been Pwned s free gov service: the Philippines. The Philippines National CERT, working with the Department of Information and Communications Technology, now has access to m…
Last fetch 6m ago · 0 new · 2 source error(s)