Risk
-
U.S. county linked to $1 million payment in data theft extortion case
A case study linked a $1 million payment to a U.S. government entity after stolen files were threatened with release. The report pointed to Union County, Ohio, and described a data theft extortion scheme with no evidence of encryption.
-
Sysdig says AI agent ran ransomware attack through patched Langflow flaw
Sysdig says an AI agent carried out a ransomware attack from start to finish after exploiting a patched Langflow flaw, stealing credentials and encrypting a production database. The report says the case shows how exposed software and weak defaults can be chained automatically.
-
MeetingTV sues Palo Alto Networks over Koi Security report that linked startup to espionage campaign
MeetingTV has sued Palo Alto Networks and Koi Security over a threat-intelligence blog that linked the startup to Chinese espionage. The company says the report was AI-driven, inaccurate and led to blocks on its domains.
-
Malicious browser extension campaign steals crypto by swapping wallet addresses
McAfee Labs said a June campaign called Silent Swap uses malicious browser extensions to swap cryptocurrency wallet addresses in the clipboard, while a separate Socket disclosure found fake VPN extensions stealing sensitive data.
-
Japan military used infected USB drives linked to China-based hacking in nearly year-long breach
Japan’s Ground Self-Defense Force used counterfeit USB drives infected with malware on sensitive networks for nearly a year after they entered service during earthquake relief work, according to a Nikkei Asia investigation and leaked internal documents.
-
DHS revives critical infrastructure cyber information sharing with new ANCHOR-CI program
DHS is restoring a cyber information sharing forum for critical infrastructure with ANCHOR-CI, a CISA-run council that replaces CIPAC and will be exempt from federal advisory transparency rules.
-
Fake Perplexity Chrome extension tracked searches on Chrome Web Store
A malicious Chrome Web Store extension posing as Perplexity AI intercepted search traffic and collected browsing data, Microsoft said in a technical analysis. The company found no credential theft, but warned the permissions could enable broader abuse.
-
Exploitation attempts target Oracle Payments flaw patched in May
Exploitation attempts have surfaced against CVE-2026-46817 in Oracle Payments, part of Oracle E-Business Suite. The flaw was patched in May, but defenders are being told to check logs and restrict unpatched systems.
-
Google details Turla’s STOCKSTAY backdoor used against Ukraine and European targets
Google said Turla used a previously undocumented .NET backdoor called STOCKSTAY against government and military targets in Ukraine and other European entities, with activity dating to December 2022 and delivery through phishing and archive-based lures.
-
macOS flaw let standard users disable CrowdStrike and Kandji tools, researchers say
Researchers said a macOS flaw let standard user accounts disable major enterprise security tools, including CrowdStrike Falcon Sensor and Kandji, by abusing XPC communication. Vendors have patched the issue or are working on fixes.






