News
-
Google Vertex AI SDK flaw let attackers hijack model uploads and run code
A flaw in Google’s Vertex AI SDK for Python let attackers hijack model uploads through a predictable bucket name and run code in Google’s serving environment. Google patched the issue, and researchers said they saw no exploitation in the wild.
-
New Rokarolla Android malware targets banking and crypto apps
A new Android banking trojan called Rokarolla targets 217 banking and cryptocurrency apps, uses 137 commands and can steal credentials, SMS codes and crypto payments, according to a technical analysis by Zimperium’s zLabs.
-
Researchers find Windows versions of SprySOCKS backdoor
Researchers found two Windows variants of the SprySOCKS backdoor and said they add stealth features, including kernel drivers and support for multiple network channels. The malware has been linked to China-associated espionage activity.
-
iRhythm says hackers stole patient data in breach of third-party business apps
iRhythm Holdings said hackers stole patient and personal information from third-party-hosted business applications. The company disclosed the breach in an SEC filing and said it found no evidence of impact to medical device systems or patient safety.
-
CISA flags LiteSpeed cPanel plugin flaw in Known Exploited Vulnerabilities catalog
CISA has added a LiteSpeed cPanel Plugin privilege escalation flaw to its Known Exploited Vulnerabilities catalog and set a June 18 deadline for federal agencies to patch. The issue can let a user with FTP or web shell access gain root on some shared hosting servers.
-
SimpleHelp bug lets attackers create rogue technician accounts
A critical SimpleHelp flaw lets unauthenticated attackers create privileged technician accounts on OIDC-enabled servers. The bug affects version 5.5.15 and older, along with 6.0 pre-release builds, and was fixed on June 9.
-
North Korean hackers shift phishing campaign to GitHub repositories, researchers say
North Korean linked hackers used recruitment-themed phishing emails and malicious GitHub repositories to target nearly 100 organizations, researchers said. The campaign aimed to steal developer credentials and cryptocurrency wallet data across Windows, macOS and Linux.
-
Malicious WordPress scripts in three popular plugins exposed more than 1.2 million sites
Malicious JavaScript in WordPress plugins PushEngage, OptinMonster and TrustPulse exposed more than 1.2 million sites to possible takeover when a logged-in administrator loaded the script, according to a Sansec technical analysis.
-
Palo Alto says PAN-OS flaw is under active exploitation
Palo Alto Networks said it has seen active exploitation of a PAN-OS authentication bypass flaw, CVE-2026-0257, in limited attacks against GlobalProtect portals. The company published indicators and urged customers to review logs for signs of abuse.
-
FBI, Google disrupt large AI-powered phishing service tied to millions of scam URLs
The FBI, Google and Black Lotus Labs have disrupted an AI-powered phishing service called Outsider Enterprise that used more than a million fraudulent URLs and is believed to have helped steal millions of credit card records.







