IT Security News

Cybersecurity news and articles about information security, vulnerabilities, exploits, hacks, laws, spam, viruses, malware, breaches.

Main menu

Skip to content
  • Advertising
  • Contact
  • Legal and Contact information
  • Opt-out preferences
  • Privacy Policy
  • Social Media
    • Telegram Channel
EN, Unit 42

Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

2026-06-16 12:06

Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more. The post Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE appeared first on…

Read more →

EN, GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Ghostwriter APT Uses Fake Gmail Login Panels to Steal Passwords and 2FA Codes

2026-06-16 12:06

Ghostwriter (UNC1151) has escalated its long-standing phishing operations by deploying convincing fake Gmail login panels that harvest both passwords and two-factor authentication (2FA) codes, CERT Polska reports. The group historically focused on Polish email providers such as Onet, Wirtualna Polska…

Read more →

EN, securityweek

Cybersecurity Executives Urge the Trump Administration to Ease Restrictions on Anthropic AI Models

2026-06-16 12:06

A group of cybersecurity executives and experts is asking the Trump administration to lift its directive preventing the use of Anthropic’s latest artificial intelligence models by foreign nationals, saying the move could help U.S. adversaries more than it hurts them.…

Read more →

EN, Help Net Security

Crypto scammers are sending couriers to victims’ homes to collect cash

2026-06-16 12:06

Scammers behind cryptocurrency investment schemes are dispatching couriers to pick up cash from victims in person, the FBI warns. According to the agency, scammers usually approach victims through social media, text messages, or fake investment personas, luring them into cryptocurrency…

Read more →

EN, Help Net Security

Cisco discloses second exploited SD-WAN vulnerability in two weeks (CVE-2026-20262)

2026-06-16 12:06

Cisco has revealed another Catalyst SD-WAN Manager vulnerability (CVE-2026-20262) that its Product Security Incident Response Team observed being exploited by attackers. But the associated security advisory also states that “the vulnerability was found during internal security testing”, raising the question…

Read more →

EN, Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses

Reverse Shell Explained: Setup, Attack Chain, and Detection

2026-06-16 12:06

A reverse shell makes the target machine initiate the connection back to the attacker, bypassing firewalls that only filter inbound traffic. This guide walks through how attackers set one up, what they do after landing it, and how defenders can…

Read more →

EN, securityweek

Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure

2026-06-16 12:06

Over two dozen organizations built a shared platform to triage vulnerabilities, fix them, and secure the software before patches arrive. The post Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure appeared first on SecurityWeek. This article has been indexed…

Read more →

hourly summary

IT Security News Hourly Summary 2026-06-16 12h : 4 posts

2026-06-16 12:06

4 posts were published in the last hour 9:34 : Hackers Abuse Microsoft OAuth Device Code Flow to Take Over Microsoft 365 Accounts 9:34 : U.S. CISA adds Cisco Catalyst and LiteSpeed cPanel plugin flaws to its Known Exploited Vulnerabilities…

Read more →

EN, GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Hackers Abuse Microsoft OAuth Device Code Flow to Take Over Microsoft 365 Accounts

2026-06-16 11:06

An active campaign in which attackers are abusing Microsoft’s OAuth 2.0 Device Authorization Grant (device code) flow to take over Microsoft 365 accounts. Rather than capturing credentials with a fake login page, the threat actors persuade victims to complete a…

Read more →

EN, Security Affairs

U.S. CISA adds Cisco Catalyst and LiteSpeed cPanel plugin flaws to its Known Exploited Vulnerabilities catalog

2026-06-16 11:06

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst and LiteSpeed cPanel plugin flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco Catalyst and LiteSpeed cPanel plugin flaws to its Known Exploited…

Read more →

EN, Help Net Security

Software supply chains are heading for a transparency test

2026-06-16 11:06

Software supply chain visibility is becoming part of product security work as the EU Cyber Resilience Act (CRA) moves toward application in December 2027. ENISA’s SBOM Adoption State of Play 2026 shows organizations preparing for CRA obligations through SBOM tooling,…

Read more →

EN, Securelist

Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk

2026-06-16 11:06

Since late 2025, malware has been spreading rapidly through the Steam Workshop, the gaming platform’s built-in service for players to create and share custom content. The attackers are primarily targeting gamers in China and Russia. This article has been indexed…

Read more →

EN, Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses

LiteLLM Vulnerability Chain: What Security Teams Running AI Gateways Need to Do Now

2026-06-16 10:06

A three-CVE chain lets any default LiteLLM user escalate to admin and get a shell on the gateway server. A separate RCE is already in CISA’s KEV. Here’s what to check and how to patch. LiteLLM Vulnerability Chain: What Security…

Read more →

EN, Silicon UK

Zhipu AI Sees Stock Price Jump Amid Anthropic Disruption

2026-06-16 10:06

Beijing-based start-up touts new GLM-5.2 model as stable alternative after White House orders Claude model restrictions This article has been indexed from Silicon UK Read the original article: Zhipu AI Sees Stock Price Jump Amid Anthropic Disruption

Read more →

EN, GBHackers Security | #1 Globally Trusted Cyber Security News Platform

OptinMonster Plugin Vulnerability Exposes 1.2 Million WordPress Sites to Cyberattacks

2026-06-16 10:06

A large-scale supply chain attack targeting the popular OptinMonster WordPress plugin has exposed more than 1.2 million websites to active compromise. The campaign also affects the TrustPulse and PushEngage plugins, both developed by Awesome Motive, significantly amplifying the attack surface…

Read more →

EN, Security Affairs

China-linked actor spent two years inside medical research networks

2026-06-16 10:06

China’s UNC6508 hid in North American medical research networks for 2 years, stealing credentials and forwarding emails to Gmail Google’s Threat Intelligence Group published a report this week on UNC6508, a China-linked cyberespionage group that breached North American medical and…

Read more →

EN, Help Net Security

Planning a trip? Fake travel sites are multiplying this summer

2026-06-16 10:06

Cyberattacks against hospitality, travel, and recreation organizations rose 24% year over year, reaching an average of 2,291 incidents per organization each week in May 2026, according to Check Point. (Source: Check Point) “The sector has more than doubled its attack…

Read more →

EN, The Hacker News

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

2026-06-16 10:06

The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called NarwhalRAT. “The attack email contained a message impersonating an MS account security alert,” the…

Read more →

EN, www.infosecurity-magazine.com

FBI Warns Courier Cash Pickups Are Driving Crypto Scams

2026-06-16 10:06

The FBI claims couriers are being used to circumvent bank transfers in crypto investment schemes This article has been indexed from www.infosecurity-magazine.com Read the original article: FBI Warns Courier Cash Pickups Are Driving Crypto Scams

Read more →

EN, Silicon UK

Judge Dismisses xAI Trade Secrets Claim Against OpenAI

2026-06-16 10:06

US federal judge says xAI failed to show indications that OpenAI induced former xAI engineer to disclose trade secrets This article has been indexed from Silicon UK Read the original article: Judge Dismisses xAI Trade Secrets Claim Against OpenAI

Read more →

Cyber Security News, EN

Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen

2026-06-16 10:06

The global ransomware landscape shifted noticeably in the first quarter of 2026, as former operators from well-known criminal groups began launching their own competing programs. Data leak sites tracked 2,122 new victims during Q1 2026, making it the second-highest first-quarter…

Read more →

Cyber Security News, EN

OptinMonster Plugin Hack Exposes 1.2 Million WordPress Sites to Cyberattack

2026-06-16 10:06

A large-scale supply chain attack targeting widely used WordPress plugins has exposed more than 1.2 million websites to potential compromise after attackers injected malicious code into legitimate JavaScript files distributed through trusted CDN infrastructure. Security researchers at Sansec discovered an…

Read more →

EN, SANS Internet Storm Center, InfoCON: green

From a VHDX File to a Remcos RAT, (Tue, Jun 16th)

2026-06-16 09:06

Yesterday, a reader reported to us a malicious ZIP archive (SHA256: a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094[1]). Once unzipped, it contains a VHDX file that discloses a malicious JavaScript after being mounted (which is automatic on modern Windows OSs): This article has been indexed from…

Read more →

EN, Silicon UK

UK Government Plans Youth Social Media Ban For Next Year

2026-06-16 09:06

Government aims to pass legislation before Christmas to ban platforms for under-16s, amid growing international pressure for action This article has been indexed from Silicon UK Read the original article: UK Government Plans Youth Social Media Ban For Next Year

Read more →

Page 16 of 5575
« 1 … 14 15 16 17 18 … 5,575 »

Pages

  • Advertising
  • Contact
  • Legal and Contact information
  • Opt-out preferences
  • Privacy Policy
  • Social Media
    • Telegram Channel

Recent Posts

  • Privilege Escalation: The Step Between Foothold and Full Compromise June 18, 2026
  • What Successful Exposure Management Deployments Had in Common in 2026 June 18, 2026
  • No Exploits Required June 18, 2026
  • 74,000 Fortinet firewall credentials exposed in FortiBleed data leak June 18, 2026
  • Cybercriminals Are Worried About AI Taking Their Jobs Too June 18, 2026
  • Critical Command Execution Flaw Patched in Cisco ISE June 18, 2026
  • Aztec suffers $2.1M exploit in second attack June 18, 2026
  • EU Develops Shield-6G Network Security June 18, 2026
  • South Korea arrests 23 in USDT laundering case June 18, 2026
  • Google launches Agentic Resource Discovery standard June 18, 2026
  • Dropping Elephant Hackers Use China-Themed Loader Chain to Deploy In-Memory RAT June 18, 2026
  • Retro gaming fans are the new target for fake GitHub malware June 18, 2026
  • Welcome to your new telco job – here’s sudo access to a database with full customer info stored in the clear June 18, 2026
  • Dream Raises $260 Million at $3 Billion Valuation June 18, 2026
  • AWS Launches Continuum to Detect and Fix Code Vulnerabilities at Machine Speed June 18, 2026
  • How to Watch the Knicks Parade on NYC Traffic Surveillance Cameras June 18, 2026
  • Embedding Forbidden Text in Spyware to Discourage AI Analysis June 18, 2026
  • The Scripts on Your Checkout Page Are Now a PCI DSS Problem June 18, 2026
  • LATAM Infrastructure Hit by Fortinet and Ivanti Exploits June 18, 2026
  • Hackers Exploit WordPress SMTP Plugin With 100,000+ Installs to Steal Sensitive Data June 18, 2026

Copyright © 2026 IT Security News. All Rights Reserved. The Magazine Basic Theme by bavotasan.com.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}