News
-
Amazon Q Developer flaw let malicious repos run code and expose cloud credentials
Amazon Q Developer had a flaw that let a malicious repository run code and expose cloud credentials, according to Wiz Research. AWS says the issue is fixed, and customers are being urged to update affected plugins and language servers.
-
Microsoft flags photo ZIP phishing campaign targeting hotels in Europe and Asia
Microsoft said a phishing campaign has targeted hotels and other hospitality organizations in Europe and Asia since April 2026, using photo-themed ZIP files to install a Node.js implant and gain access to front-desk machines.
-
Xsolis says phishing attack exposed data of 1.4 million people
Xsolis said a targeted phishing attack exposed files tied to 1,396,519 people, including names, addresses, Social Security numbers and medical treatment information. The company has notified law enforcement and is offering assistance to affected individuals.
-
DraftKings hacker ‘Snoopy’ gets 18 months in prison
A Minnesota man known as Snoopy was sentenced to 18 months in prison for his role in a 2022 DraftKings account hacking scheme that prosecutors said compromised 60,000 accounts and stole $600,000.
-
China’s 360 says it has built tools to match Anthropic’s Mythos
Chinese cybersecurity firm 360 Security Technology said on Wednesday in Beijing that it has developed two AI security tools meant to answer Anthropic’s Mythos, including one that it said can automatically discover software vulnerabilities and had found 3,432 flaws. KEY FACTS Conference 360 founder Zhou Hongyi unveiled the tools at the ISC.AI 2026 cybersecurity conference…
-
Mistic backdoor tied to ransomware access broker in attacks on multiple sectors
A new backdoor called Mistic has been used since April in attacks on insurance, education, IT and professional services firms, with researchers linking it to a ransomware access broker that sells network access.
-
U.S. seizes cloud account tied to HuiOne money laundering network
U.S. authorities seized a cloud account used by HuiOne Group subsidiaries and imposed new sanctions tied to Prince Group. Officials said the move targeted infrastructure that helped move billions of dollars from fraud and scam operations.
-
Cisco Unified CM flaw under active exploitation after public disclosure
Threat actors are exploiting CVE-2026-20230 in Cisco Unified CM and Unified CM SME, a critical flaw that can enable server-side request forgery and file writes. Cisco has patched affected versions, and WebDialer must be enabled for abuse.
-
Trump order sets 2030 deadline for federal post-quantum cryptography migration
President Donald Trump signed an executive order on June 22 setting 2030 and 2031 deadlines for federal post-quantum cryptography migration. The move advances the U.S. timeline and adds new planning and procurement pressure.
-
Xsolis says phishing attack exposed data of 1.4 million people
Xsolis said a January phishing attack exposed sensitive data tied to nearly 1.4 million people, including Social Security numbers and medical treatment information. The company is notifying affected individuals and offering identity monitoring.








