Risk
-
Exploitation attempts target Oracle Payments flaw patched in May
Exploitation attempts have surfaced against CVE-2026-46817 in Oracle Payments, part of Oracle E-Business Suite. The flaw was patched in May, but defenders are being told to check logs and restrict unpatched systems.
-
Google details Turla’s STOCKSTAY backdoor used against Ukraine and European targets
Google said Turla used a previously undocumented .NET backdoor called STOCKSTAY against government and military targets in Ukraine and other European entities, with activity dating to December 2022 and delivery through phishing and archive-based lures.
-
macOS flaw let standard users disable CrowdStrike and Kandji tools, researchers say
Researchers said a macOS flaw let standard user accounts disable major enterprise security tools, including CrowdStrike Falcon Sensor and Kandji, by abusing XPC communication. Vendors have patched the issue or are working on fixes.
-
Mirage2FA phishing kit uses HTML smuggling to target Microsoft 365 users
Fortra identified Mirage2FA, a phishing kit that uses HTML smuggling and obfuscated JavaScript to mimic Microsoft 365 sign-in pages and steal credentials during MFA prompts in an email campaign tied to cheacker[.]store.
-
Xsolis says phishing attack exposed data of 1.4 million people
Xsolis said a targeted phishing attack exposed files tied to 1,396,519 people, including names, addresses, Social Security numbers and medical treatment information. The company has notified law enforcement and is offering assistance to affected individuals.
-
DraftKings hacker ‘Snoopy’ gets 18 months in prison
A Minnesota man known as Snoopy was sentenced to 18 months in prison for his role in a 2022 DraftKings account hacking scheme that prosecutors said compromised 60,000 accounts and stole $600,000.
-
Fake GTA 6 early access sites push crypto scam and malware, reports say
Fake websites are using interest in Grand Theft Auto VI to sell nonexistent early access for cryptocurrency, security researchers say. The scam can also install malware on PC and Android devices.
-
Malwarebytes warns of parcel mule job scams posing as remote work
Malwarebytes says scammers are using fake remote job offers, including “Parcel Expert” roles, to recruit parcel mules who receive and forward stolen goods from home. The company warns of fraud, identity theft and possible law enforcement contact.
-
Mistic backdoor tied to ransomware access broker in attacks on multiple sectors
A new backdoor called Mistic has been used since April in attacks on insurance, education, IT and professional services firms, with researchers linking it to a ransomware access broker that sells network access.
-
U.S. seizes cloud account tied to HuiOne money laundering network
U.S. authorities seized a cloud account used by HuiOne Group subsidiaries and imposed new sanctions tied to Prince Group. Officials said the move targeted infrastructure that helped move billions of dollars from fraud and scam operations.








