Telegram-based ‘Outsider Enterprise’ accused of sending millions of scam texts and impersonating trusted brands This article has been indexed from www.theregister.com – Articles Read the original article: Google fires sueball at alleged Chinese phishers over AI-powered fraud ops
Industry Reactions to Claude Fable 5: Feedback Friday
Industry professionals comment on various aspects of Fable 5, including dual-use capabilities, safeguards, and tiered access. The post Industry Reactions to Claude Fable 5: Feedback Friday appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original…
Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751)
WatchTowr researchers have disclosed a technical analysis and a “Detection Artefact Generator” for CVE-2026-50751, an authentication bypass flaw in Check Point’s Remote Access VPN and Mobile Access, which the vendor confirmed to be actively exploited. The attacks were limited, but…
Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
Cybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into running arbitrary code on developer machines. Called Agentjacking by Tenet Security, the attack can be triggered by means…
Fake FACEIT pages steal Steam accounts
A sophisticated phishing campaign is targeting competitive gamers through fake FACEIT verification pages designed to steal Steam accounts containing valuable games, in-game items, and payment information. This article has been indexed from CyberMaterial Read the original article: Fake FACEIT pages…
Novo Nordisk discloses clinical trials data breach
Novo Nordisk, the Danish pharmaceutical giant and leading global insulin manufacturer, has disclosed a data breach affecting patient information from clinical trials. This article has been indexed from CyberMaterial Read the original article: Novo Nordisk discloses clinical trials data breach
Rubrik Acquires Strata to Advance Identity Resilience
Cybersecurity firm Rubrik has acquired Strata.io, an identity orchestration company, and introduced two new identity resilience capabilities designed to help organizations maintain operations during identity provider compromises. This article has been indexed from CyberMaterial Read the original article: Rubrik Acquires…
Feds Seize AudiA6 Crypto Laundering Service
Federal authorities have dismantled AudiA6, a major cryptocurrency laundering operation that processed approximately 10,333 Bitcoin (valued at roughly $389 million) since launching in 2021. This article has been indexed from CyberMaterial Read the original article: Feds Seize AudiA6 Crypto Laundering…
NIST and ISO frameworks for AI agent governance
AI agents are moving beyond pilot projects into production environments where they autonomously access sensitive documents, invoke internal APIs, trigger workflows, and make decisions traditionally requiring human judgment. This article has been indexed from CyberMaterial Read the original article: NIST…
US surveillance law to expire for first time after lawmakers reject Trump’s controversial pick to lead spy agencies
The spy law known as Section 702, which authorizes the NSA and FBI’s warrantless surveillance, will all but certainly expire on Friday for the first time. This article has been indexed from Security News | TechCrunch Read the original article:…
Hackers Abuse NinjaOne RMM Agent to Gain Remote Access to Brazilian Organizations
An active phishing campaign that weaponizes a legitimate NinjaOne Remote Monitoring and Management (RMM) agent to gain persistent remote access to Brazilian organizations. Rather than relying on bespoke malware, the operators exploit familiar business workflows and Portuguese-language social engineering to…
Oracle PeopleSoft RCE Flaw Used as Zero-Day in Ongoing ShinyHunters Campaign
ShinyHunters exploited a critical Oracle PeopleSoft zero-day to breach over 100 organizations, mostly universities, before a patch was available. Mandiant and Google’s Threat Intelligence Group published an analysis of an active ShinyHunters campaign on June 11, one day after Oracle…
Bernie Sanders’ AI Sovereign Wealth Fund Plan
Let no one accuse Bernie Sanders of ducking the big questions. Writing in the New York Times last week, the senator asked: “Will the future of humanity be determined by a handful of billionaires who have promoted and developed AI,…
Iranian Cyber Group Handala Claims Cal Water Hack
The hackers published 5GB of data, including customer personal information and credentials for the RTKBase platform. The post Iranian Cyber Group Handala Claims Cal Water Hack appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original…
Rethinking MDR as Attackers and Defenders Embrace AI
For most of the past decade, managed detection and response was the answer to a real problem. Security teams couldn’t staff around the clock, couldn’t hire enough analysts, and needed someone else to handle the alert queue. MDR stepped in.…
Attackers Can Exploit Microsoft Outlook and Word Flaws to Run Malicious Code
Microsoft has disclosed a set of critical remote code execution (RCE) vulnerabilities affecting Outlook and Word that could allow attackers to execute arbitrary code on targeted systems. The flaws, tracked as CVE-2026-45456, CVE-2026-45458, and CVE-2026-47635, were released on June 9,…
Hackers Use Typosquatted npm Packages to Target Web3 Projects and Crypto Wallet Operators
Hackers have been using typosquatting npm packages to weaponize the trust Web3 teams place in open-source dependencies, turning routine installs into a path for wallet theft, secret harvesting, and staged malware delivery. The campaign is especially dangerous because it blends…
Solana FakeFix Campaign Uses 25 Malicious npm and PyPI Packages to Steal Developer Secrets
A newly discovered supply chain campaign is putting Solana developers at serious risk, with attackers hiding malicious code inside fake developer packages on npm and PyPI. The operation, tracked as “Solana FakeFix,” deployed 25 malicious packages designed to steal wallet…
Hackers Use Free Spotify Premium Hacks on TikTok and Instagram to Spread Vidar Infostealer
Hackers are now turning popular social media platforms into malware delivery channels, using the promise of free software to trap unsuspecting users. Short-form video platforms like TikTok and Instagram Reels have become the latest tools in a cybercriminal’s playbook, with…
Authorities Dismantle Cryptocurrency Laundering Services ‘AudiA6’ Used by Ransomware Gangs
Authorities have dismantled a major cryptocurrency laundering service known as “AudiA6,” widely used by ransomware groups and cybercriminal networks to obscure illicit financial flows and cash out stolen digital assets. The international operation targeted what investigators described as an industrial-scale…
Plymouth council exposes hundreds in latest local government email gaffe
Authority admits mass message to home-schooling families revealed recipients’ addresses, prompting ICO report and apology This article has been indexed from www.theregister.com – Articles Read the original article: Plymouth council exposes hundreds in latest local government email gaffe
Cybercriminals are moving away from mass phishing campaigns
Phishing activity declined by roughly 20% in both 2024 and 2025, according to research from Zscaler’s ThreatLabz team. The drop followed years of growth that pushed phishing activity above 2 billion hits in 2023. “Phishing volume measured by blocked emails…
Over 80% of Sports Organizations Targeted by Hackers in the Last Year
As the FIFA World Cup 2026 kicks off, a new Darktrace report warns that sports teams and bodies are a major target for cyber criminals This article has been indexed from www.infosecurity-magazine.com Read the original article: Over 80% of Sports…
Palo Alto PAN-OS Flaw Lets Attackers Run Arbitrary Commands With Root Privileges
Palo Alto Networks has released patches for three new PAN-OS vulnerabilities that could allow authenticated administrators or users to execute arbitrary commands with root privileges or force firewalls into repeated reboots, raising operational and security concerns for enterprises relying on…