Archive
All articles, newest first. Page 15.

ZDI-26-393: Stack Buffer Overflow in X.Org Server XKB Subsystem Enables Local Root Escalation
The Zero Day Initiative disclosed ZDI-26-393 on June 24, 2026, detailing a local privilege escalation vulnerability in X.Org Server. A…

CVE-2026-12957: Cloud Credential Theft via Amazon Q Developer
A high-severity vulnerability (CVSS 8.5) in the Amazon Q Developer extension for VS Code allowed automatic execution of malicious MCP…

SBU and FBI Expose Russian Social-Engineering Campaign Targeting Signal and WhatsApp Accounts
Ukraine's SBU and the FBI disclosed a long-running Russian operation that uses morning-timed SMS phishing to steal verification codes…

Unit 42 Uncovers Universal Bucket Hijacking Across Multiple Clouds
Unit 42/Palo Alto Networks research: globally unique bucket names in Google Cloud, AWS, and Azure allow data-flow hijacking without co…

Masquerading Linux: When ps Lies and eBPF Exposes the Truth
A SANS ISC post demonstrates how prctl and argv overwriting make ps and top unreliable on Linux, and why only eBPF tools like Kunai ca…

Klue Supply Chain Compromised, Icarus Hacked, Data in Circulation
The Klue-Salesforce supply chain breach now spans roughly two dozen confirmed victims. The extortion group Icarus, which claimed respo…

Miasma: The Malware Turning npm Into a Developer Trap
Miasma compromised 109 npm packages and GitHub Actions using Phantom Gyp and the Bun runtime. It extracts CI/CD secrets from memory an…

Polymarket Loses $3M in Frontend Supply-Chain Attack
On June 25, 2026, Polymarket lost roughly $3 million after a third-party vendor compromise injected malicious JavaScript into its fron…

SharkLoader: The Malware That Bypasses Loader Lock to Hide Cobalt Strike
Kaspersky has identified SharkLoader, a new loader that exploits Perfect DLL Hijacking to bypass Windows Loader Lock and deploy Cobalt…

CL-STA-1062: From Taiwanese Web Hosting to Power Plants with TinyRCT Backdoor
Unit 42 reveals CL-STA-1062's escalation: from web hosting to state energy infrastructure in Southeast Asia with a custom .NET backdoo…

Turla's STOCKSTAY Backdoor Has Targeted Ukraine Since 2022
Google Threat Intelligence Group disclosed STOCKSTAY, a multi-component backdoor from the Turla APT active since December 2022 against…

CVE-2026-46331: Linux 'pedit COW' Exploit Gains Root in 24 Hours
A Linux kernel bug corrupts the page cache of setuid binaries such as /bin/su without touching disk, bypassing all integrity checks.

DirtyClone: The Fourth Variant in the DirtyFrag Family
CVE-2026-43503, the fourth variant in the DirtyFrag family, exploits cloned packets to corrupt file-backed memory. JFrog published a f…

Linux Foundation Launches Akrites: A Shared SIRT for Open Source Software
Akrites brings 19 tech giants under one shared SIRT for open source vulnerabilities. A 5% patch rate and Dolan's admission: the road a…

Synology MailPlus: Three Critical CVEs, 2,100+ Servers Exposed
Synology released MailPlus Server 4.0.1-31663 to fix three critical vulnerabilities enabling arbitrary file read/write and internal se…

PTC Windchill: First In-the-Wild Exploitation of a PLM System
CVE-2026-12569 is the first PTC vulnerability added to the CISA KEV catalog. Active exploitation with persistent JSP webshells, patche…

Burnyard: Local Malware Analysis Beats Cloud on Speed, But Accuracy Remains Unverified
Ohio State University's Burnyard project challenges VirusTotal and Sophos Intelix with user-space emulation on local hardware, deliver…

Ex-Huntress Analyst Accuses Company of Covering Up Insider Who Allegedly Fed FBI Data to DevMan Ransomware Gang
A former SOC analyst claims Huntress concealed an insider who passed U.S. law enforcement communications to the DevMan ransomware grou…

Shopify's Shop App Abused for Callback Phishing, 50 Million Users at Risk
Fake invoices with phone numbers are being injected into the Shopify Shop app. Researchers say the insertion mechanism remains unknown…

Beyond IOCs: Talos Unveils Vision for LLMs in Threat Intelligence
Cisco Talos explores how large language models transcend traditional indicators of compromise by indexing strategic reports in natural…

Ransomware: Europe Overtakes US as Top Target With 55% Surge in Attacks
Black Kite's first Europe-focused report reveals 684 ransomware attacks in the first four months of 2026, a 55.1% year-over-year incre…

'Snoopy' Sentenced: 18 Months for the Massive DraftKings Hack
Nathan Austad, known as 'Snoopy,' received an 18-month federal prison sentence for orchestrating the November 2022 credential-stuffing…

ThreatsDay June 2026: Miasma Toolkit Leaked, Claude Code Patched, AI Agent Phishing
The June 2026 ThreatsDay Bulletin, published June 11 by Rescana, is an aggregated cyber threat digest. This analysis relies primarily…

Gaslight: macOS Malware Tricks AI Analyzers with Prompt Injection
SentinelOne researchers have documented Gaslight, a previously unknown Rust-based macOS implant that embeds a prompt-injection payload…