What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,960 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 9h ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 20h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
-
Sasyr > Zyryanka on the Arktika winter road.
Overall, the main items on the wish list for our winter Irkutsk-Yakutsk-Magadan-Yakutsk road-trip had either been checked off (the Indigirka Tube, the naleds and volcanoes of the Moma Valley, the Natalka gold deposit), or only uns…
-
Hate “The Algorithm?” RSS Is One of the Tools You’ve Been Looking For
Poke your head into just about any online social network—or any general conversations about internet culture—and you’ll likely find a boogieman: the algorithm. Since at least the moment Facebook introduced ( and apologized for ) i…
-
How to Spot a Client in the DoD Industrial Base That Handles CUI
Learn how MSPs/MSSPs can identify if a client is a DoD contractor handling CUI.
-
Voluptuous volcanoes – in Yakutia.
After my Korean interlude, it s back to tales from the deep-frozen Siberian side; namely – a continuation of our drive along the winter road between the villages of Khonuu and Sasyr. The first installment is here. We d wrapped up …
-
27 Biggest Data Breaches in History: Famous Examples
Learn about the biggest data breaches of the past 20 years, how they happened, and how you can better protect your organization from major threats.
-
The 36 Most Common Cyberattacks (2026) | Huntress
Learn about some of the most common cyberattacks, how threat actors access computers and networks, and how to lower future risks.
-
Ireland’s EU Presidency Will Put Cyber Risk in the Spotlight. Are Irish Boards Ready?
As Ireland prepares to assume the Presidency of the Council of the European Union, many organisations are understandably focused on the opportunities that come with having Ireland at the centre of European policymaking for six mon…
-
After Seoul pleasantries – something somber: prison history to remember.
After our walk around central Seoul – next up: something wholly unusual: a prison! And this particular prison tells a very sad tale… From 1910 to 1945, Korea was occupied by Japan, which was extremely heavy-handed in Korean territ…
-
From Code to Coverage (Part 6): What netlogon.log Sees That Event 1644 Never Will
ldapnomnom claims it leaves no Windows audit logs. This post shows why Event 1644 misses LDAP Ping and where defenders can still catch it.
-
Weekly Update 509
I know enough about home cinema audiovisual to know there s a lot I don t know. It s conscious incompetence, if you like, which is different to the unconscious incompetence most people have on the topic. That s not to sound deroga…
-
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London …
-
We Need to Talk About Device Code Phishing
During the June Tradecraft Tuesday, Huntress researchers looked at device code phishing variations and why threat actors love this attack so much.
-
Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress
Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users with Huntress SAT.
-
My Updated Definitions of AGI vs. ASI
My Updated Definitions of AGI vs. ASI/images/agi-vs-asi-definitions.webp/images/agi-vs-asi-definitions.webp I've been working on a better way to think and talk about AGI and ASI. I've thought a lot about these terms in the past, b…
-
An update on FortiBleed — what’s happening with victim orgs
An update on FortiBleed — what’s happening with victim orgs Two days ago I wrote something about FortiBleed: FortiBleed — 75k Fortinet firewalls have admin passwords cracked Fortinet told media orgs the data was from prior breache…
-
Intelligence Insights: June 2026
ClearFake is the clear-cut number one again and Kali365 debuts in this month’s edition of Intelligence Insights
-
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, re…
-
Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress
Huntress was one of many vendors impacted by a recent incident at Klue. We dug into the incident to figure out what happened.
-
The dual-use dilemma: Rethinking detection for remote access tool abuse
A comprehensive guide to the most commonly abused RMM tools, including technical guidance for detection and prevention
-
Why Your Organization Needs ISPM
Huntress Managed ISPM finds and closes Microsoft 365 identity gaps before attackers do. Learn why visibility isn't enough and what real identity hardening takes.
-
From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker
Key Points Introduction In this research, we analyze a clipboard hijacker campaign that is hidden inside a collection of “solutions” and “tools” that claim to give users an unfair advantage. These offers include Solana and Pump.fu…
-
Speed Kills
Hitler's blitzkrieg ran on amphetamines and a fantasy of permanent victory. There are signs Washington is flirting with the same logic and that logic has an ending.
-
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack
A ClickFix infection drops Potemkin loader and RMMProject RAT, leading to browser theft, hidden remote desktop, and lateral movement across over 11 hosts.
-
We Just Gave Software Its Anti-Lock Brakes But Has This Made Us Safer?
Last week I argued that cybersecurity may be solving the wrong problem i.e. that instead of chasing perfect prevention, we should change the conditions around the problem: build for resilience, make compromise matter less, design …
-
Weekly Update 508
Light switches. How on earth is it so hard to find decent light switches?! It sounds ridiculous until you actually spend enough time looking for ones that meet two simple criteria: Aren t stateful (switch is up or down, has to be …
-
Akira, LimeWire, and the Sour Taste of Data Exfiltration
A recent investigation uncovered an Akira affiliate abusing a website owned by file-sharing app LimeWire for data exfiltration. Here's how the attack unfolded.
-
Inside Kali365, a Device Code Phishing Ecosystem | Huntress
Huntress traced device code phishing from Tencent Cloud to Kali365, a Microsoft 365 kit that steals tokens and keeps access even after MFA or password resets.
-
How threat hunting evolves at scale
We offer a practical roadmap for evolving informal, ad hoc threat hunting practices into a mature, scalable program
-
Deceptive Installers: How Fake Apps Target macOS
Deceptive installers disguised as legit macOS software deliver infostealers that grab passwords, cookies, and crypto wallets. Learn how to detect them.
-
Weekly Update 507
1,000 breaches is one hell of a milestone. It s not just the process of getting data, verifying it, loading it, sending notifications etc, it s all the other stuff that goes into keeping the whole thing afloat. Legal docs. Tradema…
-
The Most Durable Human Value
A maker offering a small glowing hand-built world to another person leaning in to receive it/images/the-most-durable-human-value.webp/images/the-most-durable-human-value.webp I think one of the most human and durable things will b…
-
Basecamp Briefing: June 9, 2026
InfoSec + Data Privacy news along with tools and resources for your professional climb. InfoSecSherpa Sherpa Intelligence : Your Guides Up a Mountain of Information! Industry News 🏭📰 Laos pledges all-out offensive against cyber sc…
-
Bill to Create Independent US Cyber Force Wants to Place It Under the US Army
It looks like we're finally making progress towards an independent US Cyber Force: https://www.csis.org/programs/strategic-technologies-program/projects/commission-us-cyber-force-generation However, this bill by Sen Gillibrand to …
-
Are We Solving the Wrong Problem in Cybersecurity?
I ve been circling a question all week, and I can t shake it. It surfaced again and again in the conversations I ve been part of — on conference floors, and far more pointedly behind closed doors, where cybersecurity leaders speak…
-
Weekly Cyber Update: 5 June 2026
A new ClickFix campaign; a legacy Oracle flaw to patch; a new DoS attack to mitigate; software supply chain advice from the NCSC; and a warning from the CSA on patching velocity The Cyber Threat Intelligence Briefing is a weekly r…
-
Inside .NET Loader Analysis: From Malspam to In-Memory Loader
A malspam campaign abusing Google's DoubleClick delivers the loader through a five-stage chain that evades detection and blinds Windows telemetry before persisting
-
Welcoming the Philippine Government to Have I Been Pwned
Today, we welcome the 46th government onboarded to Have I Been Pwned s free gov service: the Philippines. The Philippines National CERT, working with the Department of Information and Communications Technology, now has access to m…
-
Basecamp Briefing: June 2, 2026
InfoSec + Data Privacy news with a side order of tools, resources, as well as community and vendor happenings. InfoSecSherpa Sherpa Intelligence : Your Guides Up a Mountain of Information! InfoSec Data Privacy Industry News 🔒📰 Dat…
-
Unpatched NTLM Leakage in Windows search: URI Handler, Same Bug, No CVE, No Fix
The same NTLM leakage primitive that got patched in the Snipping Tool exists in Windows Explorer's search: handler. No CVE. No fix. If your patching relies on CVE coverage, you have a blind spot.
-
Red Canary CFP tracker: June 2026
Red Canary's monthly roundup of upcoming security conferences and call for papers (CFP) submission deadlines June 2026
-
Paid, Hidden, and Legal: Covert Political Sponsorship Between FARA and the FEC
U.S. election law catches covert paid influence only when a foreign principal is involved. A narrow federal statute can close the gap without becoming a censorship regime.
-
Weekly Update 506
I m finding it quite fascinating to watch the current spate of ShinyHunters breaches and dumps. There s the obvious criminality of it all, but then there s also the response from organisations (or lack thereof, as it relates to di…
-
Grading on a curve: How to assess a pentest
Defenders don’t need to detect every adversary action to prevent a threat. Here’s a more realistic, optimized approach to testing.
-
Your Profile Is a Dossier. Here's Who's Reading It.
Your social media profiles are an attacker's dossier. Learn how attackers use public data to build attack playbooks and what you can do to give them less to work with.
-
Before Your MSP Chases CMMC, Take an Honest Look at Your Operations
CMMC is an operating model, not a checklist. Before chasing defense work, audit your MSP's internal operations, including access controls and data handling, to ensure you’re ready for the scrutiny.
-
From Cookies to Keys: The Threat of Session Hijacking
See how session hijacking reshaped cyber threats. Learn how stolen tokens enable rapid breaches, bypass security, and impact enterprise protection.
-
Welcoming the Bhutanese Government to Have I Been Pwned
Today, we welcome the 45th government onboarded to Have I Been Pwned s free gov service: Bhutan. The Bhutan Computer Incident Response Team, BtCIRT, now has access to monitor Bhutanese government domains against the data in HIBP. …
-
What Fostering A Difficult Rescue Dog Taught Me About Cybersecurity Awareness
I didn t expect to learn anything about cybersecurity last week from a dog. I was fostering a rescue Podenco called Robbie. He’d arrived from Spain via a circuitous route — starvation as a hunting dog, abandoned and left as a stra…
-
How Huntress Uses Managed SIEM to Detect Threats Faster
See how Huntress uses Managed SIEM to detect threats faster, hunt smarter, and deliver comprehensive protection across endpoints, identities, and infrastructure.
Last fetch 6m ago · 1 new · 2 source error(s)