400+ Arch Linux AUR Packages Hijacked to Deploy Credential Stealer
Attackers hijacked over 400 AUR packages to install a Rust-based credential stealer. Systems built from affected packages since June 11 should be treated as com
VPN & PrivacyAttackers hijacked over 400 AUR packages to install a Rust-based credential stealer. Systems built from affected packages since June 11 should be treated as com
VPN & PrivacyINTERPOL's Operation Ramz disrupted Sniper Dz, a decade-old PhaaS platform, resulting in 201 arrests across 13 MENA countries and the takedown of its infrastruc
GuidesServiceNow patched a flaw on June 5, 2026 after threat actors exploited it to query instance tables across a subset of customers.
VPN & PrivacyChinese APT group UNC5221 used Brickstorm, Plenet, and AgentPSD to maintain access across a victim network and its MSP for over 18 months.
ThreatsFree apps embed Bright Data's SDK to route web-scraping traffic through home IPs, including always-on smart TVs, with consent screens that don't match actual da
ThreatsCISA added CVE-2026-28318, a DoS flaw in SolarWinds Serv-U, to its KEV catalog with a federal patch deadline of June 19, 2026.
Threats
An AI agent found 21 FFmpeg zero-days for ~$1,000. That same week, Chrome 149 patched a record 429 bugs.
Over 900 ATG systems in the US sit exposed on the open internet, vulnerable to command execution attacks that could disable fuel leak detection.
PCPJack compromised 230 AWS, Azure, and Google Cloud servers to build a covert SMTP relay network, leaving tools exposed on an open C2 directory.
A Cisco UCM flaw with a CVSS 8.6 score, FSB spyware claims, and $7.7B in sanctioned Iranian crypto volume define this week's threat landscape.
The 2026 Verizon DBIR confirms what browser telemetry has shown for months: the browser is the primary attack surface most enterprises aren't watching.
CVE-2026-3300 in Everest Forms Pro lets unauthenticated attackers run arbitrary PHP and create rogue admin accounts.
A dark web tutorial by "Hercules" breaks vulnerability exploitation into steps any beginner can follow - and it's spreading fast.
A new skimming campaign routes stolen payment data through api.stripe.com, bypassing CSP filters by abusing trusted infrastructure.
A flaw in Claude Code's GitHub Action let any attacker with a bot account hijack public repos and steal write credentials via prompt injection.