<?xml version="1.0" encoding="UTF-8" standalone="no"?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:gd="http://schemas.google.com/g/2005" xmlns:georss="http://www.georss.org/georss" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:thr="http://purl.org/syndication/thread/1.0"><id>tag:blogger.com,1999:blog-4802841478634147276</id><updated>2026-06-06T09:57:00.593+05:30</updated><title type="text">The Hacker News</title><subtitle type="html">The Hacker News has been internationally recognized as a leading news source dedicated to promoting awareness for security experts and hackers</subtitle><link href="https://thehackernews.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml"/><link href="https://thehackernews.com/feeds/posts/default?redirect=false" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/" rel="alternate" type="text/html"/><link href="http://pubsubhubbub.appspot.com/" rel="hub"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default?start-index=26&amp;max-results=25&amp;redirect=false" rel="next" type="application/atom+xml"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><generator uri="http://www.blogger.com" version="7.00">Blogger</generator><openSearch:totalResults>16502</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-6202654507864018641</id><published>2026-06-06T09:49:28.689+05:30</published><updated>2026-06-06T09:57:00.593+05:30</updated><title type="text">Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available</title><summary type="html">
Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation.

The vulnerability, tracked as CVE-2026-20245, carries a CVSS score of 7.8 out of a maximum of 10.0. It affects the following deployment types -


  On-Prem Deployment
  Cisco SD-WAN Cloud-Pro
  Cisco SD-WAN Cloud (Cisco Managed)
  Cisco SD-WAN for Government (FedRAMP)

"A </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6202654507864018641" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6202654507864018641" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html" rel="alternate" title="Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYckKvOFV_Xz1o-nUKCcjlMQmOxdFC6FMzIjMnE4GSPPJ9kQxDLqOmK9WhofViemB5grKkMJDV_KPnQAuLci5RtV3sCOei2Fzk31qOdIk3Jeroj_6NVxoa0VX0Bw5nwwzffBp4o3hoDysRntjOxTR7akhfDV_1ZIpmcQKFMsxdvb00KYypSv7daJTqYHXb/s260-e100/cisco-exploit.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-7930161542953610397</id><published>2026-06-05T23:35:30.490+05:30</published><updated>2026-06-05T23:35:30.491+05:30</updated><title type="text">IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks</title><summary type="html">


Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm, respectively.

According to JFrog, the information stealer "scrapes every secret it can find on a developer's machine, hides behind an eBPF kernel rootkit, and </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7930161542953610397" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7930161542953610397" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/ironworm-and-new-miasma-worm-variant.html" rel="alternate" title="IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFimSGBOnvlCj_r6fiLdzK6V8DLTIQYjROKxHgQH8QxyRVIL3NDpQe9lBISjqCSjcZNl6VPhHVFtdJ8gPe2FfNjR9kGND1GSZmgx9T_32_Aii5nf_fMLkmBxwkKrJKbmZpcAG8xyj868aHfZ9RePlwlPDfMbI4uDlOCknlGH62Ifdf-nak6qmy4u-9i7X3/s260-e100/npm-worm.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-2126091376926743517</id><published>2026-06-05T20:23:40.252+05:30</published><updated>2026-06-05T20:23:40.252+05:30</updated><title type="text">Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps</title><summary type="html">
Arabic-speaking users have emerged as the target of a new Android spyware codenamed Asin, according to findings from ESET.

The Slovakian cybersecurity company said it first detected the malware spread via multiple campaigns in early 2025, with each attack wave making use of distinct websites mimicking utilities, war-related updates, and a government news source:


  govlens[.]net, which </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2126091376926743517" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2126091376926743517" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/android-spyware-asin-targets-arabic.html" rel="alternate" title="Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimTj2SdhVr1jj9e2RqrAOW9dIsBmuMZJsqWGt6weL0DOfhwYQF_6Hp5B-sYt6ZZEGQB_YPTOW6Xb2x5JygleEwCp8FQFmKDBIfQlCP1QVLGuVGPboCcbXy8LB0oUDSwA-3w6Vqc9QQFiRAaQKqQ2m2EdPopVIWcp7RHtdXbrd9ucWSfEG4D3h2bu1d9dN3/s260-e100/android-war.png" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1997809581832515394</id><published>2026-06-05T18:03:38.889+05:30</published><updated>2026-06-05T19:19:50.440+05:30</updated><title type="text">New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework</title><summary type="html">
Cybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 (where "OP" stands for "opponent") that has been observed&amp;nbsp;targeting Microsoft Internet Information Services (IIS) servers to deploy a bespoke web shell framework.

ReliaQuest has assessed with moderate to high confidence that the espionage-focused activity is linked to China.

"OP-512 was highly </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1997809581832515394" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1997809581832515394" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/new-threat-cluster-op-512-targets.html" rel="alternate" title="New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiab_7FEmO4woH_bG4spUNJRFCFvvmpF9ggnhOlkIf7f0Ma7z4oEwL0MxFSe4CstBBQRLFsYxObArJESQWOkwOPIQgO7m17DQFE997ZPe9hBnUPWiY-rabco7Q_OE2LYgp5UuqDfSxk8jvCJvLriBKb6OQAN9ovQbqSTOGD13SWnU3P12FTLgfvMe5sTgPN/s260-e100/chinese.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-9049836845114861905</id><published>2026-06-05T16:50:00.000+05:30</published><updated>2026-06-05T16:50:00.110+05:30</updated><title type="text">Only 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to Deliver</title><summary type="html">
Eighteen months ago, the AI SOC was a marketing line. Today it's a budget item. The category has crossed over from interesting to inevitable, with billions of dollars now flowing into AI-powered security operations platforms, agentic SOC tools, and AI co-pilots built into every layer of the security stack. The data shows SOCs are buying, deploying, and standing up AI capabilities at the fastest </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/9049836845114861905" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/9049836845114861905" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/only-10-of-socs-say-theyre-getting.html" rel="alternate" title="Only 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to Deliver" type="text/html"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjsdgNCJHCuVqNf4dGZYDAmzpytkCd3NBt-TKUtEo-bSBKeuqJzzk7CGB5l-JxHyIz5mVjHRn7csD0zZNm4MipX2Kwhfx8gB_Qdk8XcMg6kuoOaiBvcZT1LGlmfRGsC2avDBRtTWb9I-hzENpGkSFRouv7YSUiKHAXZ7qmYEbTdwe9dsVQCj_RRxUnaSyE/s260-e100/main.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-3282307390441798914</id><published>2026-06-05T14:08:59.945+05:30</published><updated>2026-06-05T14:08:59.946+05:30</updated><title type="text">Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites</title><summary type="html">
Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise.

The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a remote code execution bug impacting all versions of the plugin up to, and including, 1.9.12. A patch for the flaw was </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3282307390441798914" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3282307390441798914" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/hackers-exploit-critical-everest-forms.html" rel="alternate" title="Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgKOwHRwFSrcOI7vBYVGbebtc3DwR3w7SYc9l7FUXp1yXc_N2MbNNlEXtfRjVneU4wz2YB8PqC_k54o_6ZpB2oKZKhVBlK7IC-CGU05B5GgE7qS26MBxKIWLZTC2rNhVf2vufJcwh7RK4zuH-twWCcd_eZtNm25Pmn-pQyOXcB7N_C9918yOP7C1K4KrNz/s260-e100/wordpress.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-2930983707119567921</id><published>2026-06-05T12:31:41.748+05:30</published><updated>2026-06-05T12:31:41.749+05:30</updated><title type="text">FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins</title><summary type="html">
Security researchers and the FBI are warning that a wave of FIFA-themed fraud is already hitting World Cup 2026 fans, days before the June 11 kickoff.

Recent reports describe thousands of lookalike FIFA domains, banking malware hidden inside pirate streaming apps, and at least one operation that copies FIFA's login page well enough to take over real accounts.

It is an obvious target. More than</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2930983707119567921" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2930983707119567921" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html" rel="alternate" title="FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMkj_adwzUUFP7yWyIFVKIKKQGDjqfvPuxKoR4mrrJ_SX3EACoJ3toLV3ZkYmePeA-nKWWfVC-90aOa5yjepuVYNy2lc820-onK23EJN4JU9G9e6QR471FTzPvByhyI7-bkGntT7hLxGXyTqSi7TpLMGqhfiKTQz01jN461HvEGxYY075LsqsB_tqEprcN/s260-e100/fifa-2026-scams.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-5984513621532939618</id><published>2026-06-05T11:04:19.011+05:30</published><updated>2026-06-05T11:04:19.012+05:30</updated><title type="text">PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network</title><summary type="html">
The threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to create a covert SMTP email relay network.

"Compromised business servers across the U.S., Europe, and Asia were quietly converted into SMTP proxies, verified for mail relay capability, and synced to a downstream consumer every five minutes," Hunt.io said in</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5984513621532939618" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5984513621532939618" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/pcpjack-hijacks-230-aws-google-cloud.html" rel="alternate" title="PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEibu0mX9Tusu3siXFJzPskfA1ZYZ2OdRJTegsJFkffBc9cBBPGWguTUAI3PPAaFy-WIjziA9PIrMrZNVuFVNmbFhOSPLv6mMBPvjWnR-WQGBD2fvGFTJT358yWFFTxeFSS87aQ_fj30G2VdsGlBjy2KJiby4CS-k3X9FjjpyTGxljOo373cUaZKhdBvWZ_a/s260-e100/cloud-emails.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-7910205518740417332</id><published>2026-06-04T22:25:51.562+05:30</published><updated>2026-06-04T22:25:51.563+05:30</updated><title type="text">Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public</title><summary type="html">
Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root.

It is tracked as CVE-2026-20230, and proof-of-concept exploit code is already public. Cisco's PSIRT says it has not seen the flaw used in attacks yet. The PoC shortens that runway.

The flaw is a server-side request forgery. </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7910205518740417332" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7910205518740417332" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/cisco-patches-cve-2026-20230-in-unified.html" rel="alternate" title="Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6_xkmI_c8KreZ4cr2oC9gHJERU9xWsLGDrCNCaB11IQVGmJ-r0MYUjqGllvOFc0IVwGYBqnzLJl96WBTSVXUr5Z8KRym9SsnoUlNN6oEditbTFqW3kTfOhujPEPN-KIzGJmxaJGh9mCvY1TadCVfJJfIBoTjbXn2TCcbQE8NHsKhe8ld53YHYsG5MTYg/s260-e100/cisco-flaw.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-2576845914749250230</id><published>2026-06-04T20:45:26.561+05:30</published><updated>2026-06-04T20:54:18.831+05:30</updated><title type="text">Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories</title><summary type="html">

A security researcher found a flaw in Anthropic's Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because Anthropic's own action repo used the same workflow, a working attack could have pushed malicious code into the action itself and onto the projects downstream that pull it.

RyotaK of GMO</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2576845914749250230" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2576845914749250230" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/claude-code-github-action-flaw-let-one.html" rel="alternate" title="Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhiaBF9jAklPh1ncr_eVPGnV229BSTNgAjkScVm-yTXAn4IcBjjZoLIglasRdu1XEPafCxJhqVZrC3zkNWilyAhN-6Ox8z2HBRjNg2D4aqJsDiRDg02BgAy4zgwU2100ZLIO8yTOtarI0Vxa3AGUQk0GZq1_zKSFQOhNiNoyVsP2AldJZoW8ZJ1rY936ZI/s260-e100/claude-code-hack.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-8485121957220354199</id><published>2026-06-04T20:40:00.000+05:30</published><updated>2026-06-04T21:50:20.173+05:30</updated><title type="text">Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It</title><summary type="html">

Over the past several weeks, the cybersecurity community has been reminded how quickly frontier and agentic AI in defense networks can challenge our assumptions. When Anthropic's Claude Mythos model was made available to a limited set of organizations as a technical preview, it was reported that an unauthorized group claimed that it had gained access within hours. The incident, if true, was </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/8485121957220354199" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/8485121957220354199" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/agentic-ai-is-transforming-defense-but.html" rel="alternate" title="Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It" type="text/html"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6i36LXqSESJrnuYOf6ULo2Hijp9l8i9UTGbRzCLuWImPpfPJ6cKQgBFGhS8yx3_qn8IoM0MgY0pmL4mZfzegatvhQWDKV5OQ3MfOWvPzYIokXaFDUvBM3EYsMOqtQoxx0AmeiakeocpBIlaNeCiBkPcnK1OW8abfIz0_8zuybqKQvWuriVC97Ir259Sw/s260-e100/agentic-ai.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-6323913368425126081</id><published>2026-06-04T19:30:49.704+05:30</published><updated>2026-06-04T19:30:49.704+05:30</updated><title type="text">ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors &amp; 20+ New Stories</title><summary type="html">

It got stupid again.

The internet still feels held together with tape. Bad plugins, old bugs, fake tools, trusted apps doing shady things. Same mess, new wrapper. And now the weird stuff is normal. Forums go down and come back worse. Cheap hackers get better toys. AI starts breaking real systems. Great.

Read the whole thing before it ruins your week anyway.








  
  
    Unauthenticated </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6323913368425126081" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6323913368425126081" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/threatsday-bulletin-ai-agents-gone.html" rel="alternate" title="ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors &amp; 20+ New Stories" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOsPH2SzhBWTxhXi2KCJw0YY29azn2hLkDQwQhyrjmwaRIXQfCAPNIjej3_TBd6VJm1JqWSs2EoI2jiWyVHENmhtd1alqSEqlJC8WxUk4b5zWUqszQ8akhGzRmCHf8OL7wMTZiWLYZDzHRXY8unPcsh2QMTfyTH0XeRszrwCunK2DazuZIF9oNKQUFxlqN/s260-e100/thh.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-4295270740000116586</id><published>2026-06-04T17:52:25.463+05:30</published><updated>2026-06-04T21:58:05.035+05:30</updated><title type="text">China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa</title><summary type="html">
A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa.

These efforts have been complemented by a "rapid operational tempo" and a continually evolving malware arsenal comprising known families like ValleyRAT (aka Winos 4.0) and Atlas RAT (aka AtlasCross RAT), as well as previously </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4295270740000116586" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4295270740000116586" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html" rel="alternate" title="China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhq_JkP80d1IA8rz-SoYEBmuGqK_K7OpGrqiki4vB1ShMW5mFBVSMvl8H5MnYylZMl3AWeqdAmp19oZIL_7amYErNxBGiUAJqrOqGO0zjHH2jxCKCNdiGH_nqjHlksD9dlu4QGCq9KzMRfnWAi7YnPQQ86pnCypNupFDn_h-hSJdfhWT0Y4s01w6Cw-s6Od/s260-e100/phishing-hook.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-3741500718895292518</id><published>2026-06-04T16:49:53.677+05:30</published><updated>2026-06-04T21:57:32.021+05:30</updated><title type="text">FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads</title><summary type="html">
Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called FlutterShell.

According to Palo Alto Networks Unit 42, the campaign is said to be the next stage of a previously reported activity cluster dubbed JSCoreRunner (aka FileRipple) in late August 2025. The cybercrime group behind the two attack chains is </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3741500718895292518" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3741500718895292518" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/fluttershell-backdoor-spreads-to-macos.html" rel="alternate" title="FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwFQkJElJQpI5ODTBzh1EzrxsRYamFN0ntC9V6vF4b4FfEJ0svPhI_1TnKm960eIsewSFT-DR1RtNk3M511OQK6I-k3UQNNLut1f_fjM9wB4NHxdvJzJQ3VvhIGO9ja0hNIzRAOZLVMngS4R8hQxXfV-_DO71x0CU0YSnxpclCnV0DGX6TdNmr32ongewk/s260-e100/macos.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1255329627427862941</id><published>2026-06-04T15:21:28.192+05:30</published><updated>2026-06-04T15:21:28.193+05:30</updated><title type="text">Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS</title><summary type="html">
Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families like Remus Stealer, AnimateClipper, and the SessionGate framework.

"The sites are well-designed and often look like legitimate project portals at a glance, sometimes referencing </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1255329627427862941" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1255329627427862941" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/fake-sites-mimicking-open-source-tools.html" rel="alternate" title="Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiM7j9PG_c741so0RmX7eIB48xO-ndyZSF0pIU5j2anTqxJNj8A3XVstoIjq3iMnuQxhgyhl3LKP5laenFIj7IT0V8SOJ0lK7-Ywdsr5yBioNKF60SegkvR3SkfaSkPqZxN3rak0J-sZbvjxGDozCupAP3wraZjk0XU6-ZA590Q42cPaHXrdg7PJFGk1Ss/s260-e100/site.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-4152153360263539081</id><published>2026-06-04T15:03:57.714+05:30</published><updated>2026-06-04T15:03:57.715+05:30</updated><title type="text">Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months</title><summary type="html">
Unknown attackers spent at least five months inside the Outlook mailbox of a senior executive at a major global stock exchange, copying the inbox out in small, repeated batches and routing it through Dropbox and OneDrive so the traffic blended into normal cloud activity.

Symantec and Carbon Black's Threat Hunter Team reported the campaign this week. This points to espionage, not a money grab: </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4152153360263539081" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4152153360263539081" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html" rel="alternate" title="Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpg8pBdHkENT_CKClsSR7f4Rb7BQpM27ynGrkRdJg-bbUfI2NIHQ_rFmkOVHjK8RggTD-XMvVdGGI_qrYyIx-Ml1sfwbRkbjaNo8Fz40cWg8wFWK8h5-f-FaB58HryMM5AYlUHI2uO7x12VFvAB6N3w1gobWmzGgp8xXqHfWMERFh7hVS9lBHxfdu71Xs/s260-e100/stock-emails.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-6447322712427931307</id><published>2026-06-04T11:36:25.341+05:30</published><updated>2026-06-04T11:36:25.341+05:30</updated><title type="text">DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets</title><summary type="html">
The U.S. Department of Justice (DoJ) on Wednesday announced the results of a sweeping action undertaken by government authorities and private sector companies to combat cyber-enabled and cryptocurrency fraud targeting Americans.

The "Disruption Week" operation began May 18, 2026, leading to the takedown of millions of social media, email, and internet access accounts used by transnational </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6447322712427931307" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6447322712427931307" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/doj-disrupts-southeast-asia-crypto.html" rel="alternate" title="DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTf5wAHnoXtVauiln2MwlVvLc4LxcL8SBTLuW648LfFhUd8QyuOUfjmg0Hd91QlksmWF2u-PQhxHDTDmseMIG64V4Fo2I2lXXGO1o0BncbL_UTeBrGztErg66yXAm0trYlWxqGbE-sKb5VjXjqeyNiCMkxbdcxwX1BDRGexhP-b0s3dZl0lNRpY9u6nsTQ/s260-e100/police-crypto.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-7201496806344087992</id><published>2026-06-04T00:41:15.805+05:30</published><updated>2026-06-04T00:54:39.211+05:30</updated><title type="text">WhatsApp, Slack Notifications Could Hijack Google Gemini on Android</title><summary type="html">

A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini's voice assistant on Android and made it open a victim's connected windows, fake a message from their boss, push the phone into a Zoom call, or quietly poison its long-term memory.

No malicious app on the phone is required. The assistant just had to treat a hostile </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7201496806344087992" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7201496806344087992" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/whatsapp-slack-notifications-could.html" rel="alternate" title="WhatsApp, Slack Notifications Could Hijack Google Gemini on Android" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCJpW9I-QTgQOkP7AV3rwUtEOEs96ek2ySR06Go-xq5AThZV84qY3mDN1Dkh0oQ-94jZHc7zB21ax9ljU0dW2LtsSW5p7xuuX9ARsvoIZQTGaMSkESGxTjl-PgTy8hrnsI8ucVZpENLEuMa9QzoUYVmfp4aug4OnEZq3XeL3ZELNZVELSegpS398l8vKg/s260-e100/gemini-prompt.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-610964168909252871</id><published>2026-06-03T23:28:00.000+05:30</published><updated>2026-06-04T17:22:20.092+05:30</updated><title type="text">One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens</title><summary type="html">
Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user's GitHub token.

"Just by clicking a link, it's possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones," security researcher Ammar Askar said.

GitHub supports a feature called GitHub.dev that runs as</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/610964168909252871" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/610964168909252871" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html" rel="alternate" title="One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeHvqmNHvAhdxgoBLbfFWsFBMdvH5SbJovunxx8AYHRkq7HOQ2l6I_ZaJGi_PF5WHKOlHEQHK4HyPBhmzOpYNhPS4HJSna2uLVlEwUV9i2j5YuRqGOLUqgKIrhx2ndFm1OSME7usiLk_ohtIBYyR5Xpq5Pzc2eHAjCK0OA_89JwPNxVrrBVDbTDRVbRG6e/s260-e100/github.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-2414431584752431156</id><published>2026-06-03T22:10:00.000+05:30</published><updated>2026-06-04T17:21:52.975+05:30</updated><title type="text">Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)</title><summary type="html">
Redis has  patched  a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an autonomous AI tool built to hunt bugs in large codebases.
Tracked as CVE-2026-23479, the flaw was introduced in Redis 7.2.0 and remained in every stable branch until the May 5 fixes, unnoticed for over two years. </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2414431584752431156" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2414431584752431156" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html" rel="alternate" title="Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjTV6zPqD9KC3Rc5Mz9c8XENLiJntboDT6LIoD3L2FXlTUVC3rsWZ_3YLfe_jmhhyphenhyphenjb5RCwkTsdoyypD9VXxYgj_2GYaAupNMlOyZkycm94qr7XiarmBCpYQdZDN_Gwq6KrOmomzx1dmbz4hpUkw4OZparqEbydJneNKaWQI0fcP5tctpKxsZ7kFP5FCv0/s260-e100/redis-db.png" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-4204511418669006126</id><published>2026-06-03T22:00:00.000+05:30</published><updated>2026-06-04T17:23:02.424+05:30</updated><title type="text">CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog</title><summary type="html">


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

The vulnerability, tracked as CVE-2026-45247 (CVSS score: 9.8), is a case of deserialization of untrusted </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4204511418669006126" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4204511418669006126" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/cisa-adds-exploited-magento-rce-flaw.html" rel="alternate" title="CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8P5o_wfJsxsTaxY4OONIm2y5N5x9heoFeLchfLU13YA36tGQGJtu00tOCQSKhCTBFobAAWfhXLtNGMu8ZCG7ozeLVggi1tnQVRK_1mJHd6eq1YSb5AlRZq5eDp3rGDL2Uli_b3aBPMBsLfMJ5QEm_XW1MF43_dcCf64rSbVrhsUakhaOAn5-GOmuLiq0s/s260-e100/mag.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-3945230289666940301</id><published>2026-06-03T21:59:16.831+05:30</published><updated>2026-06-03T21:59:16.831+05:30</updated><title type="text">Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT</title><summary type="html">
Cybersecurity researchers have flagged a new malspam campaign that makes use of Google's DoubleClick domain as a way to evade detection and ultimately deliver a remote access trojan (RAT) named DesckVB RAT.

"Before the victim ever reaches attacker-controlled infrastructure, the lure routes through DoubleClick, a legitimate Google-owned domain that many security tools are less likely to treat as</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3945230289666940301" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3945230289666940301" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html" rel="alternate" title="Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpQ6QXxFH4zkfeHGdcm1WXVcNXMpyJm-1dlZLbFCdp6rKDRhuwICzYaKaR-rCpn61qod6A1F98PZejZbmYuxaUXPJLXQffoaniCkqgyqR1-p7gClpj4PYibjzIDHk8_Vw4ag00EYPCM3Nz1G0Hvzuf6wBV-HzDFoSiYDEEdjPU45Bk_rIlGk9dJ_MMVuue/s260-e100/ad-malware.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-8520237315398248235</id><published>2026-06-03T20:26:46.087+05:30</published><updated>2026-06-03T20:26:46.109+05:30</updated><title type="text">Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore</title><summary type="html">
Assume the breach. Zero-days keep shipping, AI is writing exploits faster than anyone patches, and "patch everything in time" stopped working years ago. Stop betting the org on winning that race. You don't control which bug lands. You control what it can reach once it does.

That is a question about the shape of your network, and most teams have the shape wrong. HD Moore, creator of Metasploit </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/8520237315398248235" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/8520237315398248235" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/beyond-zero-day-see-your-network-like.html" rel="alternate" title="Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore" type="text/html"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzZPASJ7ymlBpeDWq_d-byWp58FpBR6tdX6QfLJFFoGRHK9xB5mTbx0guIcMFKFYV87inRtJyM-cKJXI0Td5fVtpC1ITBFmp2myS2wBynVSF3rZP2jZWH6uR-_14ZEalErJASiKWVDJ_TD551AC0pN5A3Mu8y-Z1zW5mKvFMOmdLzrdWnhYCif0FR1lOE/s260-e100/hd.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-6927112998351451076</id><published>2026-06-03T20:26:35.982+05:30</published><updated>2026-06-03T20:26:35.982+05:30</updated><title type="text">Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag</title><summary type="html">
A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits account-token sharing to trusted Microsoft apps.

Any other app on the same phone could ask for the signed-in user's token and get it, then read email, open files, browse the calendar, and send messages as that user. No password, no login screen, no permission prompt.

</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6927112998351451076" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6927112998351451076" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html" rel="alternate" title="Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_pEYWDRVadGL0WYM3iSY6jqFgBez8snXgoyeyAzcXNmxiytv-FgiKoBJX3aPivuYhSJjXp4o_zO1dQSIPUfduaAlB-rvSti7pFhdDZSrAa-ennBdfdVpe1Xo0dMxKATB8te61pyJAf60x5CP6OJzjzmtpFIg_qHQqA7VP-rUnEpaT37Z0qBOmbZ52BfM/s260-e100/ms-android.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-9179062494750118971</id><published>2026-06-03T17:28:00.000+05:30</published><updated>2026-06-03T17:28:00.107+05:30</updated><title type="text">Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)</title><summary type="html">
The Fragmented State of Modern Enterprise Identity

Enterprise IAM is approaching a breaking point. As organizations scale, identity becomes increasingly fragmented across thousands of applications, decentralized teams, machine identities, and autonomous systems.

The result is Identity Dark Matter: identity activity that sits outside the visibility of centralized IAM and beyond the reach of </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/9179062494750118971" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/9179062494750118971" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/06/shrinking-iam-attack-surface-through.html" rel="alternate" title="Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)" type="text/html"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiuT21gubKVL2cAsQrEiju_yAE3Pxe1IPxsl9RlGfhMEeis2IuQglnZjwTme6xM1_IJNymXFY1kZsouMGecR2lQnzvMDXyjnY1Y7CT1Dz_xf0pRVkwJEJG9o1EfOlPMfgfZ0MO6eyKGKJDwRHrEsw2-Cai9QO3pfrryeSENy5kH4C_pdjDgsXVOO80TPy8/s260-e100/orchid.jpg" width="72"/></entry></feed>