News
-
Texas agency says license vendor breach exposed data on 3 million people
Texas Parks and Wildlife said a breach at its license system vendor exposed personal data tied to more than 3 million hunting and fishing license customers, including driver’s license details, passport numbers and contact information.
-
Salesforce disables Klue app after data theft incident
Salesforce disabled the Klue Battlecards app after a June 11 security incident at Klue that may have exposed customer data through connected accounts. Klue said legacy credentials were used to steal OAuth tokens.
-
Apple patches Beats Studio Buds flaw that could let nearby attackers eavesdrop
Apple has patched a high-severity Beats Studio Buds Bluetooth flaw that could let nearby attackers eavesdrop through the microphone. The advisory says the fix is in Beats Firmware Update 1B211 and requires no user interaction.
-
DragonForce hackers used Microsoft Teams relay to hide command traffic, researchers say
DragonForce-linked attackers used a custom backdoor to hide command traffic inside Microsoft Teams relay infrastructure during a months-long intrusion at a major U.S. services firm, researchers said.
-
Law enforcement disrupts SocGholish malware tied to Evil Corp
Law enforcement cleaned nearly 15,000 infected WordPress sites and took down 106 servers in an Operation Endgame action targeting SocGholish malware linked to Evil Corp. Authorities also urged site owners to change credentials and enable multi-factor authentication.
-
Apple patches Beats Studio Buds flaw that could let attackers hear conversations
Apple has patched a high-severity Bluetooth flaw in Beats Studio Buds that could let an attacker in range listen through the microphone before pairing. The update is delivered as firmware 1B211.
-
Researchers say attacker used Tailscale and SSH to keep access after C2 outage
A technical analysis by Cato Networks says an attacker kept access to a French automotive business after a C2 outage by installing OpenSSH and Tailscale on a victim machine and using a separate access path.
-
144 Mastra npm packages hit by supply chain attack
A supply chain attack compromised 144 npm packages in the Mastra namespace in June 2026, with a malicious dependency used to drop payloads that could steal wallet data, browser information and credentials.
-
Malicious JetBrains plugins stole AI provider keys, researchers say
Researchers say 15 JetBrains Marketplace plugins posed as AI assistants while stealing user API keys for services such as OpenAI and DeepSeek. The campaign has run since October 2025 and included two plugins with more than 25,000 downloads each.
-
CISA warns of actively exploited Joomla editor flaw rated maximum severity
CISA added a maximum-severity Joomla content editor flaw to its known exploited vulnerabilities list, citing active abuse. The bug affects JCE versions up to 2.9.99.4 and was fixed in June 2026.










