News
-
MeetingTV sues Palo Alto Networks over Koi Security report that linked startup to espionage campaign
MeetingTV has sued Palo Alto Networks and Koi Security over a threat-intelligence blog that linked the startup to Chinese espionage. The company says the report was AI-driven, inaccurate and led to blocks on its domains.
-
Hackers exploit Langflow flaw to push Monero miner in March-April campaign
Hackers exploited a critical Langflow remote code execution flaw over a 19-day period in March and April 2026 to deploy a Monero miner, disable security tools and spread to other hosts, according to a technical analysis from Trend Micro.
-
Malicious browser extension campaign steals crypto by swapping wallet addresses
McAfee Labs said a June campaign called Silent Swap uses malicious browser extensions to swap cryptocurrency wallet addresses in the clipboard, while a separate Socket disclosure found fake VPN extensions stealing sensitive data.
-
Japan military used infected USB drives linked to China-based hacking in nearly year-long breach
Japan’s Ground Self-Defense Force used counterfeit USB drives infected with malware on sensitive networks for nearly a year after they entered service during earthquake relief work, according to a Nikkei Asia investigation and leaked internal documents.
-
DHS revives critical infrastructure cyber information sharing with new ANCHOR-CI program
DHS is restoring a cyber information sharing forum for critical infrastructure with ANCHOR-CI, a CISA-run council that replaces CIPAC and will be exempt from federal advisory transparency rules.
-
Fake Perplexity Chrome extension tracked searches on Chrome Web Store
A malicious Chrome Web Store extension posing as Perplexity AI intercepted search traffic and collected browsing data, Microsoft said in a technical analysis. The company found no credential theft, but warned the permissions could enable broader abuse.
-
Exploitation attempts target Oracle Payments flaw patched in May
Exploitation attempts have surfaced against CVE-2026-46817 in Oracle Payments, part of Oracle E-Business Suite. The flaw was patched in May, but defenders are being told to check logs and restrict unpatched systems.
-
KDDI says breach may have exposed up to 14.2 million ISP email logins
KDDI said a breach in one of its email systems may have exposed up to 14.2 million customer email addresses and passwords across six Japanese internet service providers after attackers exploited third-party software.
-
Google details Turla’s STOCKSTAY backdoor used against Ukraine and European targets
Google said Turla used a previously undocumented .NET backdoor called STOCKSTAY against government and military targets in Ukraine and other European entities, with activity dating to December 2022 and delivery through phishing and archive-based lures.
-
Amazon Q Developer flaw let malicious repos run code and expose cloud credentials
Amazon Q Developer had a flaw that let a malicious repository run code and expose cloud credentials, according to Wiz Research. AWS says the issue is fixed, and customers are being urged to update affected plugins and language servers.








