Risk
-
Salesforce disables Klue app after data theft incident
Salesforce disabled the Klue Battlecards app after a June 11 security incident at Klue that may have exposed customer data through connected accounts. Klue said legacy credentials were used to steal OAuth tokens.
-
F5 patches two critical NGINX flaws that could lead to code execution
F5 has patched two critical NGINX Open Source vulnerabilities that could permit remote code execution. The company released fixes, listed affected products and offered mitigations, while saying it has not seen in-the-wild exploitation.
-
USB worm spreads crypto-stealing malware through Windows shortcut files
A USB worm has been spreading clipboard-stealing malware that targets cryptocurrency wallets through Windows shortcut files, with activity tracked since at least February and communications hidden over Tor.
-
INC ransomware claims 830 victims since 2023, researchers say
INC ransomware has emerged as one of 2026’s most active cybercrime groups, with researchers linking it to 830 victims since 2023 and more than 120 incidents in the first quarter of this year.
-
DragonForce hackers used Microsoft Teams relay to hide command traffic, researchers say
DragonForce-linked attackers used a custom backdoor to hide command traffic inside Microsoft Teams relay infrastructure during a months-long intrusion at a major U.S. services firm, researchers said.
-
Law enforcement disrupts SocGholish malware tied to Evil Corp
Law enforcement cleaned nearly 15,000 infected WordPress sites and took down 106 servers in an Operation Endgame action targeting SocGholish malware linked to Evil Corp. Authorities also urged site owners to change credentials and enable multi-factor authentication.
-
Fake reputation campaign pushes crypto clipper through GitHub, YouTube and news sites
A campaign used fake reputation signals across GitHub, SourceForge, YouTube and news sites to promote a crypto clipboard hijacker, according to a technical analysis from Check Point Research. The malware replaced copied wallet addresses with attacker-controlled ones.
-
144 Mastra npm packages hit by supply chain attack
A supply chain attack compromised 144 npm packages in the Mastra namespace in June 2026, with a malicious dependency used to drop payloads that could steal wallet data, browser information and credentials.
-
Malicious JetBrains plugins stole AI provider keys, researchers say
Researchers say 15 JetBrains Marketplace plugins posed as AI assistants while stealing user API keys for services such as OpenAI and DeepSeek. The campaign has run since October 2025 and included two plugins with more than 25,000 downloads each.
-
CISA warns of actively exploited Joomla editor flaw rated maximum severity
CISA added a maximum-severity Joomla content editor flaw to its known exploited vulnerabilities list, citing active abuse. The bug affects JCE versions up to 2.9.99.4 and was fixed in June 2026.








