News
-
Ransomware groups use Citrix flaw, stolen VPN logins and supply chain credentials
Ransomware crews tied to Anubis, The Gentlemen, VECT and TeamPCP are using Citrix exploitation, valid VPN credentials, BYOVD techniques and supply chain access to break into targets and move through networks.
-
MeetingTV sues Palo Alto Networks over Koi Security report that linked startup to espionage campaign
MeetingTV has sued Palo Alto Networks and Koi Security over a threat-intelligence blog that linked the startup to Chinese espionage. The company says the report was AI-driven, inaccurate and led to blocks on its domains.
-
Hackers exploit Langflow flaw to push Monero miner in March-April campaign
Hackers exploited a critical Langflow remote code execution flaw over a 19-day period in March and April 2026 to deploy a Monero miner, disable security tools and spread to other hosts, according to a technical analysis from Trend Micro.
-
Malicious browser extension campaign steals crypto by swapping wallet addresses
McAfee Labs said a June campaign called Silent Swap uses malicious browser extensions to swap cryptocurrency wallet addresses in the clipboard, while a separate Socket disclosure found fake VPN extensions stealing sensitive data.
-
Japan military used infected USB drives linked to China-based hacking in nearly year-long breach
Japan’s Ground Self-Defense Force used counterfeit USB drives infected with malware on sensitive networks for nearly a year after they entered service during earthquake relief work, according to a Nikkei Asia investigation and leaked internal documents.
-
DHS revives critical infrastructure cyber information sharing with new ANCHOR-CI program
DHS is restoring a cyber information sharing forum for critical infrastructure with ANCHOR-CI, a CISA-run council that replaces CIPAC and will be exempt from federal advisory transparency rules.
-
Fake Perplexity Chrome extension tracked searches on Chrome Web Store
A malicious Chrome Web Store extension posing as Perplexity AI intercepted search traffic and collected browsing data, Microsoft said in a technical analysis. The company found no credential theft, but warned the permissions could enable broader abuse.
-
Exploitation attempts target Oracle Payments flaw patched in May
Exploitation attempts have surfaced against CVE-2026-46817 in Oracle Payments, part of Oracle E-Business Suite. The flaw was patched in May, but defenders are being told to check logs and restrict unpatched systems.
-
KDDI says breach may have exposed up to 14.2 million ISP email logins
KDDI said a breach in one of its email systems may have exposed up to 14.2 million customer email addresses and passwords across six Japanese internet service providers after attackers exploited third-party software.
-
Google details Turla’s STOCKSTAY backdoor used against Ukraine and European targets
Google said Turla used a previously undocumented .NET backdoor called STOCKSTAY against government and military targets in Ukraine and other European entities, with activity dating to December 2022 and delivery through phishing and archive-based lures.







