Risk
-
Canada spy agency used court warrant to disrupt foreign botnets on home routers and IoT gear
Canada’s spy service used a 2024 court warrant to disrupt two foreign-run botnets on routers and IoT devices, in the first use of its threat-reduction powers this way, according to a public Federal Court ruling.
-
AryStinger malware turns legacy routers into reconnaissance network
AryStinger malware has infected at least 4,300 legacy routers and turned them into a reconnaissance and proxy network, according to a QiAnXin XLab technical analysis. The campaign also has a second strain aimed at QNAP NAS devices.
-
INTERPOL warns of surge in phishing, ransomware and scam centers across Asia and the South Pacific
INTERPOL says cybercrime has surged across Asia and the South Pacific, driven by phishing, ransomware and AI-enabled scams. The report cites more than 135,000 ransomware attacks in 2024 and rising losses from organized fraud networks.
-
Microsoft details AutoJack flaw that could let a web page trigger code on AI agent hosts
Microsoft said a flaw in AutoGen Studio could let a single web page trigger code execution on the host running an AI browsing agent. The issue affects two pre-release PyPI builds, while the stable release is not exposed.
-
Texas agency says license vendor breach exposed data on 3 million people
Texas Parks and Wildlife said a breach at its license system vendor exposed personal data tied to more than 3 million hunting and fishing license customers, including driver’s license details, passport numbers and contact information.
-
Salesforce disables Klue app after data theft incident
Salesforce disabled the Klue Battlecards app after a June 11 security incident at Klue that may have exposed customer data through connected accounts. Klue said legacy credentials were used to steal OAuth tokens.
-
F5 patches two critical NGINX flaws that could lead to code execution
F5 has patched two critical NGINX Open Source vulnerabilities that could permit remote code execution. The company released fixes, listed affected products and offered mitigations, while saying it has not seen in-the-wild exploitation.
-
USB worm spreads crypto-stealing malware through Windows shortcut files
A USB worm has been spreading clipboard-stealing malware that targets cryptocurrency wallets through Windows shortcut files, with activity tracked since at least February and communications hidden over Tor.
-
INC ransomware claims 830 victims since 2023, researchers say
INC ransomware has emerged as one of 2026’s most active cybercrime groups, with researchers linking it to 830 victims since 2023 and more than 120 incidents in the first quarter of this year.
-
DragonForce hackers used Microsoft Teams relay to hide command traffic, researchers say
DragonForce-linked attackers used a custom backdoor to hide command traffic inside Microsoft Teams relay infrastructure during a months-long intrusion at a major U.S. services firm, researchers said.










