Risk
-
Researchers say macOS malvertising campaign is spreading FlutterShell backdoor
Researchers say a macOS malvertising campaign has been spreading a new backdoor called FlutterShell through trojanized desktop apps and ads, with activity seen as recently as March 2026.
-
Redis patches two-year-old use-after-free flaw that enabled remote command execution
Redis patched CVE-2026-23479, a use-after-free flaw in blocking-client code that could lead to remote command execution. The bug affected versions 7.2.0 through 8.6.2 and had gone unnoticed for more than two years.
-
Fake open-source tool sites used to push malware through gated redirects
Researchers say fake sites impersonating open-source tools such as Ghidra and dnSpy are using gated redirects to push malware, including Remus Stealer, AnimateClipper and SessionGate, after users click download buttons.
-
Hackers spent months inside stock exchange executive’s Outlook inbox
Unknown attackers spent at least five months inside a senior stock exchange executive’s Outlook mailbox, copying messages in small batches and routing them through Dropbox and OneDrive in what researchers described as espionage.
-
CISA adds exploited Magento extension flaw to known vulnerabilities list
CISA added a critical Magento extension flaw to its exploited vulnerabilities catalog after reports of active abuse. The bug, CVE-2026-45247, can allow remote code execution and affects versions of Mirasvit Cache Warmer before 1.11.12.
-
Google patches Gemini flaw that could let poisoned notifications trigger Android actions
Google patched a Gemini on Android flaw that let a poisoned notification influence the assistant, potentially triggering actions from fake messages to smart home controls. SafeBreach said the bug was fixed server-side and no in-the-wild abuse was found.
-
Malspam campaign uses Google DoubleClick redirect chain to deliver DesckVB RAT
A malspam campaign is using Google DoubleClick redirects and personalized phishing pages to deliver DesckVB RAT, a .NET trojan. The attack chain uses HTML attachments, PowerShell, process hollowing, and anti-analysis checks.
-
CISA warns of cyberattacks targeting fuel tank monitoring systems
CISA warned on June 3 that cyberattacks are targeting fuel tank monitoring systems used in critical infrastructure. The report did not identify the attackers or say whether the activity caused outages or damage.
-
Unpatched Windows Search URI flaw could leak NTLMv2 hashes
Researchers said an unpatched Windows search: URI flaw could leak NTLMv2 hashes through a crafted link. Microsoft did not fix the issue after disclosure in April 2026, and the report advised SMB and NTLM mitigations.








