Archive
All articles, newest first. Page 14.

Citrix Patches Six NetScaler Flaws: The Trap Is Manual
Citrix released patches on June 30, 2026 for six vulnerabilities in NetScaler ADC and NetScaler Gateway, including a new CitrixBleed i…

Phantom Squatting: When AI Generates Your Next Supply-Chain Threat
Unit 42 documents a novel attack vector: adversaries proactively register domains hallucinated by LLMs to intercept traffic from AI-in…

Agentjacking: Fake Bug Report Hijacks AI Coding Agents, 85% Success Rate
Tenet Security researchers demonstrated on June 12, 2026 that a poisoned Sentry error report can hijack Claude Code, Cursor, and Codex…

BioShocking: How a Game Tricks Agentic AI into Stealing Credentials
LayerX researchers demonstrated BioShocking, a prompt injection attack that manipulates agentic AI browsers into exfiltrating sensitiv…

RustDuck: The IoT Botnet Rewritten in Rust Challenges Researchers
QiAnXin XLab has tracked RustDuck since February 2026: a two-stage malware rewritten in Rust with enterprise-grade encryption and anti…

Langflow RCE Exploited for Miner Worm: 19-Day Campaign
CVE-2026-33017: Commodity operators exploit exposed AI endpoints to deploy Lambsys, an SSH worm that compromises entire enterprise inf…

Health Card Phishing: €6.39 to Steal Your Identity
CERT-AGID exposes the funnel of an active phishing campaign impersonating the Italian Ministry of Health, using a fake mandatory healt…

Aflac Japan Confirms 4.38 Million Records Breached; U.S. Systems Unaffected
Aflac Life Insurance Japan Ltd. disclosed a ten-day intrusion from June 15–25, 2026, affecting 4.38 million customers and agents and e…

Blackfield Demands $2 Million from Nidec: Inside the Ransomware Price Menu
The Blackfield ransomware gang has claimed an attack on Nidec's Taiwanese subsidiary, Chaun Choung Technology, demanding $2 million to…

CISA Confirms: BlueHammer Now Exploited by Ransomware
CISA has elevated CVE-2026-33825 to a confirmed ransomware vector. Microsoft has not updated its advisory, creating an intelligence ga…

Nissan Payroll Breach via Oracle PeopleSoft Zero-Day CVE-2026-35273
Nissan Americas confirmed a breach exposing employee payroll data and Social Security numbers across four countries through CVE-2026-3…

Mustang Panda Turns Zoho WorkDrive Into Covert C2 Channel Against Indian Government
The Mustang Panda APT group ran two espionage campaigns in June 2026 targeting the Indian government and hydroelectric infrastructure,…

CVE-2026-48558: Djinn Stealer Exploited In-the-Wild on SimpleHelp
Threat actors exploit CVE-2026-48558 to deploy Djinn Stealer and TaskWeaver. The new infostealer targets AI and cloud credentials. Rou…

CVE-2026-46817: Oracle EBS Under Attack, 450+ Servers Exposed
Defused detects active exploitation of CVE-2026-46817 on Oracle EBS honeypots. CVSS 9.8, patch available since May, over 450 instances…

Gamaredon 2025: 35 Spear-Phishing Campaigns and 6 PowerShell Tools Target Ukraine
The Gamaredon APT group, attributed by Ukraine's SSU to the FSB's 18th Center for Information Security, launched 35 distinct spear-phi…

Microsoft Removes 119 Edge Extensions Hiding Malware in Images and Fonts
Microsoft purged 119 Edge extensions that concealed StegoAd malware inside PNG, WebP, and WOFF2 font files, reaching a combined instal…

Public PoC for CVE-2026-55200: libssh2 at Risk of RCE
A working proof-of-concept for CVE-2026-55200, a critical CVSS 9.2 vulnerability in libssh2, was released on June 23, 2026. The pre-au…

DarkMoon: Open-Source AI Pentesting at $10 a Scan — and the Hard Limit of Vendor LLM Classifiers
DarkMoon separates LLM reasoning from execution via MCP to bypass Anthropic's safety classifiers. At roughly $10 per web-app scan, the…

Amadey/StealC: 27M Credentials Recovered, $47M in Crypto Seized
Operation Endgame dismantled two malware-as-a-service networks. Here's why the RICO legal theory changes the game and what it means fo…

OpenClaw: 5 Malicious Skills Evade AI Scanners for Months
Unit 42 reveals evasive skills on ClawHub exploiting semantic instruction hijacking. 80% of 49,943 skills analyzed show behavioral dev…

Claude Code Tricked: Clean Repo Opens Reverse Shell
Mozilla 0DIN demonstrates that Claude Code executes malware from clean GitHub repositories by exploiting its own proactivity: a fabric…

KDDI Breach Exposes 14.2 Million Credentials Across Six Japanese ISPs
KDDI Corporation disclosed unauthorized access to a shared email platform serving six Japanese telecom operators on June 17, 2026. The…

ATEN Unizon: Authenticated Bug Deletes Files, CVSS 5.5 Understates Risk
Directory traversal in ATEN Unizon's uploadSSL lets an authenticated attacker delete arbitrary files. The CVSS 5.5 rating masks real o…

ZDI-26-397: Use-After-Free in X.Org Server Opens Door to Local Privilege Escalation
A Use-After-Free flaw in X.Org Server's CreateSaverWindow function (CVE-2026-50263) lets a local low-privilege attacker leak sensitive…