// 1 CRITICAL · 6 ZERO-DAY · 10 CVE · 11 EXPLOIT · 1 ADVISORY IN THE LAST 24H
ransomware

Prinz Eugen: The Ransomware That Encrypts the Newest Files First

Threatdown researchers have documented Prinz Eugen, a Go-based ransomware that prioritizes recently modified files, leaves no ransom n…

Jun 20, 2026views - 944

cybersec

Microsoft Attributes Mastra Supply-Chain Attack to North Korean Sapphire Sleet

Microsoft assesses with high confidence that the supply-chain compromise of more than 140 @mastra npm packages was carried out by the…

Jun 20, 2026views - 1.5k

CYBERSEC

Attack Surface 2026: 42% of Companies Have Databases Exposed to the Internet

Intruder's report on 3,000 organizations reveals the midmarket paradox: growing companies with enterprise-scale attack surfaces and SM…

Jun 20, 2026views - 1.5k

ransomware

GentleKiller: The EDR-Killer Framework Built Into the Gentlemen RaaS

The Gentlemen ransomware-as-a-service operation equips affiliates with GentleKiller, an in-house BYOVD framework spanning eight-plus v…

Jun 20, 2026views - 1.4k

CYBERSEC

TPWD Breach Exposes 3 Million Driver's Licenses and Passports; Vendor Remains Undisclosed

The Texas Parks and Wildlife Department confirms a breach via an unnamed third-party vendor affecting 3,087,721 hunting and fishing li…

Jun 20, 2026views - 991

VULNEXPLOIT

Gravity SMTP: 17M Attacks Exploit Info-Disclosure Bug

CVE-2026-4020 in the WordPress Gravity SMTP plugin is under active exploitation, exposing email credentials and infrastructure bluepri…

Jun 19, 2026views - 761

VULNZERO-DAY

ZDI-26-358: Allegra Patches XSS in downloadAttachment Method

The ZDI-26-358 advisory from Trend Micro's Zero Day Initiative discloses a cross-site scripting vulnerability in Allegra's downloadAtt…

Jun 19, 2026views - 737

CYBERSECEXPLOIT

usbliter8: Unpatchable Exploit Hits Apple A12/A13 SecureROM

Paradigm Shift releases usbliter8, an unpatchable hardware exploit achieving arbitrary EL1 execution in Apple A12/A13 SecureROM via th…

Jun 19, 2026views - 1.2k

VULNCVE

X.Org Server UAF CVE-2026-34001: Local Root Escalation on Linux

ZDI-26-335 discloses a use-after-free in X.Org Server's SyncTriggerList: CVSS 7.8, local attack with no user interaction, X.Org patch…

Jun 19, 2026views - 1k

aiCRITICAL

AutoJack: A Single Web Page Hijacks AI Agents to Execute Code on the Host

Microsoft Security has disclosed AutoJack, a three-vulnerability chain in AutoGen Studio that turns browsing-capable AI agents into ve…

Jun 19, 2026views - 1k

CYBERSEC

Crypto-Clipper: The Fake Reputation Economy Becomes a Weapon

Cybercriminals have weaponized stars, downloads, and reviews to distribute a Rust-based clipper across GitHub, YouTube, and even legit…

Jun 19, 2026views - 1.2k

phishing

Tax Scam Impersonates the State: Adaptive Phishing Targets Crypto and Bank Accounts

CERT-AGID has detected active phishing campaigns abusing the name, logo, and branding of Italy's Agenzia delle Entrate to trick victim…

Jun 19, 2026views - 842

CYBERSEC

Agentic AI Replaces Assistive AI in Threat Management

Agentic AI is turning Gartner's CTEM framework from a strategic document into a continuous operational cycle. The shift, documented Ju…

Jun 19, 2026views - 1.3k

CYBERSEC

Shadow AI: The Real Threat Is Access Control, Not Data Leakage

The shadow AI problem has shifted from browser-based chatbots to enterprise systems: autonomous agents running with live credentials,…

Jun 19, 2026views - 994

phishing

Banking Phishing: Evasion via IPv4-Mapped IPv6

A phishing campaign targeting Belgian e-banking exploits compressed IPv4-mapped IPv6 syntax to bypass regex-based security checks and…

Jun 19, 2026views - 943

CYBERSEC

Log Discard: 86% of Security Logs End Up in the Trash

A Dynatrace survey of 450 senior IT leaders at large enterprises reveals that half of organizations discard or fail to collect an aver…

Jun 19, 2026views - 1.2k

CYBERSEC

Interpol: $40 Billion Scam Economy in Asia, Cybercrime Tops 30% of All Crime

Interpol's 2025/2026 assessment documents a nearly $40 billion organized scam economy in Asia-Pacific, with cybercrime exceeding 30% o…

Jun 19, 2026views - 1.3k

CYBERSEC

June 2026 ThreatsDay Bulletin: When Claude’s Shared Chat Becomes a Malware Vector

The June 2026 ThreatsDay Bulletin documents the abuse of Anthropic Claude’s shared chat feature to distribute the MacSync credential s…

Jun 18, 2026views - 894

CYBERSEC

Novo Nordisk: Exposed GitHub Token Leads to 1.3 TB Theft Over Two Months

A GitHub personal access token exposed in client-side JavaScript opened a two-month dwell window: roughly 1.3 TB of data, AI models, a…

Jun 18, 2026views - 932

ransomwareCRITICAL

Mackay Sugar Ransomware Attack Halts Mills, 1,300 Farms Frozen at Harvest Start

The Gentlemen ransomware group struck Australia's second-largest sugar producer on June 10, 2026, idling two of three mills and forcin…

Jun 18, 2026views - 905

CYBERSEC

Klue Breach: Dormant OAuth Credential Opens Multi-Victim Door to Salesforce

The Icarus extortion group exfiltrated CRM data from Klue customers by abusing stolen OAuth tokens. Cybersecurity vendor Huntress conf…

Jun 18, 2026views - 1.1k

malware

Operation Endgame Dismantles SocGholish: Nearly 15,000 Sites Cleaned

On June 18, 2026, the international Operation Endgame coalition took down 106 servers and domains linked to SocGholish and cleaned 14,…

Jun 18, 2026views - 995

malwareCRITICAL

CryptoBandits: The USB Clipper-Worm That Adds RCE via Tor

Microsoft disclosed an active Windows clipper malware campaign running since February 2026 that uses malicious LNK files distributed v…

Jun 18, 2026views - 866

infostealer

The 'robase' Malware Empties Entire Roblox Games: From Hat Theft to Digital Business Seizure

A malware campaign using the Python package 'robase' steals authenticated session tokens from Roblox developers via Discord social eng…

Jun 18, 2026views - 808