Risk
-
New Rokarolla Android malware targets banking and crypto apps
A new Android banking trojan called Rokarolla targets 217 banking and cryptocurrency apps, uses 137 commands and can steal credentials, SMS codes and crypto payments, according to a technical analysis by Zimperium’s zLabs.
-
Researchers find Windows versions of SprySOCKS backdoor
Researchers found two Windows variants of the SprySOCKS backdoor and said they add stealth features, including kernel drivers and support for multiple network channels. The malware has been linked to China-associated espionage activity.
-
iRhythm says hackers stole patient data in breach of third-party business apps
iRhythm Holdings said hackers stole patient and personal information from third-party-hosted business applications. The company disclosed the breach in an SEC filing and said it found no evidence of impact to medical device systems or patient safety.
-
CISA flags LiteSpeed cPanel plugin flaw in Known Exploited Vulnerabilities catalog
CISA has added a LiteSpeed cPanel Plugin privilege escalation flaw to its Known Exploited Vulnerabilities catalog and set a June 18 deadline for federal agencies to patch. The issue can let a user with FTP or web shell access gain root on some shared hosting servers.
-
SimpleHelp bug lets attackers create rogue technician accounts
A critical SimpleHelp flaw lets unauthenticated attackers create privileged technician accounts on OIDC-enabled servers. The bug affects version 5.5.15 and older, along with 6.0 pre-release builds, and was fixed on June 9.
-
Microsoft 365 Copilot flaw could expose emails and files with one click
Researchers said a single click on a Microsoft link could expose emails, calendar data and indexed files from Microsoft 365 Copilot Enterprise Search through a three-bug chain called SearchLeak.
-
Malicious WordPress scripts in three popular plugins exposed more than 1.2 million sites
Malicious JavaScript in WordPress plugins PushEngage, OptinMonster and TrustPulse exposed more than 1.2 million sites to possible takeover when a logged-in administrator loaded the script, according to a Sansec technical analysis.
-
Sniper Dz campaign used fake Facebook offers to target MENA users
Researchers said a fraud campaign targeted users in the Middle East and North Africa with fake Facebook offers, redirecting them through layered websites and browser tricks to push phishing, premium SMS, call scams and investment fraud.
-
Palo Alto says PAN-OS flaw is under active exploitation
Palo Alto Networks said it has seen active exploitation of a PAN-OS authentication bypass flaw, CVE-2026-0257, in limited attacks against GlobalProtect portals. The company published indicators and urged customers to review logs for signs of abuse.
-
FBI, Google disrupt large AI-powered phishing service tied to millions of scam URLs
The FBI, Google and Black Lotus Labs have disrupted an AI-powered phishing service called Outsider Enterprise that used more than a million fraudulent URLs and is believed to have helped steal millions of credit card records.







