• New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

    New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

    Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The vulnerability has been codenamed HTTP/2 Bomb by Calif. “The vulnerable behavior exists in each server’s default HTTP/2 configuration,” the company said, adding it was discovered by OpenAI Codex by chaining

    Read More

  • Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content

    Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content

    Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gaining control of victims’ systems. The Minecraft-focused malware-as-a-service (MaaS) campaign has been codenamed Weedhack by McAfee Labs, stating the activity has been active since January 2026 and impersonates Minecraft clients and mods to infect users. In all, 3820

    Read More

  • Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited

    Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited

    Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active exploitation. Tracked as CVE-2025-48595 (CVSS score: 8.4), the security flaw has been described as a case of privilege escalation without requiring any…

    Read More

  • Merkley, Senate Colleagues Call to Halt Implementation of Trump’s Illegal Executive Order to Eliminate Vote-by-Mail

    Merkley, Senate Colleagues Call to Halt Implementation of Trump’s Illegal Executive Order to Eliminate Vote-by-Mail

    Senators Direct Commerce Secretary to Explain Department’s Involvement with USPS and Elections, and Preserve Documents for Congressional Oversight

    Read More

  • Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

    The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation. Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR, to launch an HTML Application payload dubbed GammaPhish, which is then…

    Read More

  • AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.

    AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.

    AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in the history of enterprise security. As a result, the window between a vulnerability being disclosed and indiscriminate exploitation observed across the internet is now measured in hours, not days. The…

    Read More

  • How Leading Organizations Are Turning EDR Into Operational Resilience

    How Leading Organizations Are Turning EDR Into Operational Resilience

    Most organizations now recognize that endpoint protection alone is no longer sufficient. That’s why adoption of endpoint detection and response (EDR) has accelerated rapidly in recent years. Organizations understand that modern attacks move faster, evade traditional prevention controls, and require continuous visibility into suspicious activity across the environment. But owning EDR

    Read More

  • Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT

    Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT

    Cybersecurity researchers have disclosed details of a spear-phishing campaign likely undertaken by the Pakistan-aligned SideCopy group targeting Afghanistan’s Ministry of Finance with an open-source remote access trojan called Xeno RAT. “The campaign opens with a spear phishing delivery – a ZIP archive containing a malicious LNK file bearing a carefully crafted Pashto-language filename,”

    Read More

  • Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

    Password manager Dashlane has disclosed that “fewer than” 20 users on the personal subscription plan had their encrypted vaults downloaded following a brute-force attack launched by an unknown party. On May 31, 2026, the company said an “external” threat actor launched a brute-force attack against certain Dashlane user accounts with the aim of breaking two-factor…

    Read More

  • Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

    Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

    A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. “This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and potential

    Read More