Cybersecurity News | Daily Recap [24 Jun 2026]

Daily Recap, U.S. authorities seized Huione-related infrastructure tied to cyber scam laundering, while a Scattered Spider member pleaded guilty to hacking Transport for London and courts ordered takedowns of the Amadey and Stealc cybercrime ecosystems. The day also covered active exploitation of Cisco Unified CM (CVE-2026-20230), FortiGate credential harvesting linked to FortiBleed, and emerging AI/attack risks including a fake brand-landingpage agent skill reaching 26,000 agents.
#Huione #ScatteredSpider #TransportForLondon #Amadey #Stealc #CiscoUnifiedCM #CVE-2026-20230 #Ubiquiti #FortiGate #FortiBleed #Mistic #KongTuke #ClickFix #brand-landingpage #Anthropic #Mythos #U.S. #TataElectronics #Xolis #DraftKings

Read More
Cybersecurity News | Daily Recap [24 Jun 2026]

Daily Recap, LastPass confirmed its breach was tied to the Klue supply-chain compromise, while ShapedPlugin WordPress Pro plugins were backdoored in a separate supply-chain attack; London Hydro and Xsolis also disclosed large-scale data exposures. Across other headlines, the FortiBleed campaign used a custom FortiGate sniffer to steal firewall credentials, Squidbleed was shown to leak cleartext HTTP requests via Squid Proxy, and WhatsApp campaigns delivered ManageEngine RMM alongside OXLOADER and CastleStealer. #LastPass #Klue #ShapedPlugin #LondonHydro #Xsolis #FortiBleed #FortiGate #FortiGateSniffer #Russian #Squidbleed #SquidProxy #SamsungKNOX #Galaxy #WhatsApp #ManageEngineRMM #VBScript #OXLOADER #CastleStealer #JaredFromSubway #SearchYourTarget #DifyTap #Dify #AutoGenStudio #FFmpeg #PixelSmash #SAVE #postquantum #Windows1126H2 #DeepInstinct

Read More
Cybersecurity News | Daily Recap [24 Jun 2026]

Daily Recap, Five Eyes warns that advanced AI hacking models could reach the cyber scene within months, while INTERPOL reports rising phishing and AI-powered scams across Asia-Pacific. In addition, North Korean activity is linked to the Mastra NPM supply-chain attack, attackers are targeting the Gravity SMTP WordPress plugin, and the AryStinger botnet continues infecting D-Link routers.
#FiveEyes #INTERPOL #Mastra #NPM #NorthKorean #GravitySMTP #WordPress #AryStinger #DBlink #DLink #TexasParksAndWildlife #Ukraine #EU

Read More
Cybersecurity News | Daily Recap [24 Jun 2026]

Daily Recap, Police and international partners disrupted a malware network tied to Russia’s Evil Corp, while Operation Endgame took down SocGholish servers and cleaned 14,971 compromised WordPress sites. Security teams also warned that The Gentlemen ransomware uses the GentleKiller EDR-killer framework to target 400 security processes before encryption. #EvilCorp #OperationEndgame #SocGholish #WordPress #TheGentlemen #GentleKiller #Texas #FortiBleed #Fortinet #Klue #Icarus #GravitySMTP #usbliter8 #SecureROM #AppleA12 #AppleA13 #AutoJack #Beats #Continuum

Read More
Cybersecurity News | Daily Recap [24 Jun 2026]

Daily Recap, Security teams are being urged to treat every AI agent as a distinct identity and to keep pace with fast-moving threat patterns, including AI-generated deepfakes scrutiny and related harassment charges involving AI-made nude images. On the vulnerability and incident front, CISA warned of an actively exploited Splunk Enterprise flaw, enforcement disrupted the SocGholish botnet by cleaning nearly 15,000 WordPress sites tied to Evil Corp, and Fortinet users were advised to secure devices after the FortiBleed leak.
#AI #AI agent #No FAKES Act #Deepfakes #Splunk Enterprise #CISA #NGINX #REDCap #Recycle Bin #SocGholish #Evil Corp #WordPress #Gentlemen #CryptoBandits #NastyC2 #Claude #NIM #FortiBleed #Fortinet #WideField Security #Splunk #Nintendo #WebMD #Microsoft 365 #MFA #M365 Backup

Read More
Cybersecurity News | Daily Recap [24 Jun 2026]

Daily Recap, Klue linked an OAuth breach to Icarus-associated Salesforce data theft activity, while Kodak confirmed a breach after ShinyHunters claims, and FortiBleed reports exposed up to 75,000 Fortinet firewall/VPN devices with leaked credentials. Apple patched a Beats Studio Buds eavesdropping flaw, F5 delivered out-of-band fixes for critical NGINX issues, and Microsoft confirmed a RoguePlanet Defender zero-day is being patched as attackers rapidly exploit recently disclosed Fortinet flaws. #Klue #Icarus #Salesforce #Kodak #ShinyHunters #FortiBleed #Fortinet #BeatsStudioBuds #F5 #NGINX #RoguePlanetDefender #Microsoft #MFA #CISA #Telegram #EU #Ukraine

Read More
Cybersecurity News | Daily Recap [24 Jun 2026]

Daily Recap, patching and vulnerability updates dominated today as CISA ordered U.S. federal agencies to address an actively exploited critical Joomla plugin issue, while browser and enterprise-targeted fixes rolled out for Google Chrome, Firefox, Fortinet FortiSandbox, Rockwell Automation ICS, and LiteSpeed/Joomla. On the campaign side, new Rokarolla Android malware stole PINs, SMS codes, and crypto funds, ClickFix and GhostTree expanded evasion techniques, and ShinyHunters’ extortion claims were confirmed by Kodak. #CISA #Joomla #FortinetFortiSandbox #RockwellAutomation #LiteSpeed #Rokarolla #ClickFix #GhostTree #JetBrains #SteamWorkshop #WallPaperEngine #Kodak #ShinyHunters #iRhythm

Read More
Cybersecurity News | Daily Recap [24 Jun 2026]

Daily Recap, US regulators reported record $3.5 billion in 2025 losses from imposter scams as the FTC warned about rising victim costs, while the UK plans to ban social media access for children under 16 and other governments moved to strengthen fraud and reporting controls. CISA and vendors also warned about active exploitation of cPanel, Cisco SD-WAN/vManage, and Fortinet FortiSandbox flaws, alongside major intrusion and espionage updates including DragonForce using Microsoft Teams relays and NarwhalRAT delivery via fake Microsoft alerts. #ImposterScams #FTC #UK #cPanel #CiscoSDWAN #CiscoVmanage #FortinetFortiSandbox #DragonForce #BackdoorTurn #MicrosoftTeams #Astral #iRhythm #ShinyHunters #CalWater #Google #NarwhalRAT #LiteLLM #Copilot #SprySOCKS #OptinMonster #TrustCloud #NewCore

Read More
Cybersecurity News | Daily Recap [24 Jun 2026]

Daily Recap, Fraud and phishing activity included the FBI disrupting an AI-powered phishing service using 1 million URLs and reporting crypto scams that relied on couriers, while MENA users faced Sniper Dz lures through fake Facebook offers and browser alerts. Across cloud and breach headlines, attackers turned Microsoft 365 Copilot into a 1-click data-theft mechanism, exploited a PAN-OS GlobalProtect VPN flaw, and hit platforms including REDCap, Infinite Campus, and Novo Nordisk, with ransomware cases and supply-chain intrusions also continuing. #FBI #Microsoft365Copilot #GlobalProtect #REDCap #InfiniteCampus #NovoNordisk #Ozempic #Conti #SniperDz #Misere #ShaiHulud #MiniShaiHulud #Miasma #Hades #UNKDeadDrop #GoFlateLoader

Read More
Threat Research | Weekly Recap [14 Jun 2026]

Cybersecurity Threat Research ‘Weekly’ Recap. This week covered supply-chain and developer-focused intrusions (Shai-Hulud, Mini Shai-Hulud/Miasma/Hades, UNK_DeadDrop, GoFlateLoader) plus phishing and social-engineering campaigns that targeted Microsoft account tokens, social-media lure downloads, and FIFA/World Cup 2026 fraud kits. It also highlighted cloud/identity abuse and enterprise compromises (Entra Agent ID blueprint abuse, Azure DNS takeover, Duo Auth Proxy exposure, PulseRAT, MLTBackdoor) alongside ransomware/extortion/data theft cases (Tengu/Shisa, ShinyHunters) and defenses tied to flaws like ITScape (CVE-2026-46316).

Read More
Cybersecurity News | Daily Recap [24 Jun 2026]

Daily Recap, U.S. export controls compelled Anthropic to take Fable 5 and Mythos 5 offline for foreign nationals, underscoring tighter access to advanced AI models. Elsewhere, Chinese-linked actors showed long-running stealth in an authentication hijack and Linux backdoor campaigns, while Arch Linux AUR package hijacking pushed an infostealer and eBPF rootkit. #Anthropic #Fable5 #Mythos5 #Fable5 #Mythos5 #AuthHijack #LinuxBackdoor #ArchLinuxAUR #eBPF #Conti #ShinyHunters #OraclePeopleSoft #Coupang #23andMe #phpBB #FISA #DeepfakePornSite

Read More
Cybersecurity News | Daily Recap [24 Jun 2026]

Daily Recap, urgent patching focus returned as CISA directed federal agencies to address actively exploited Ivanti issues, while Oracle mitigated a PeopleSoft zero-day tied to data theft and Microsoft resolved Windows update failures linked to the WUSA installer. Across breaches and espionage, Novo Nordisk disclosed clinical trials exposure, tchap accounts were reported as affected in France, and threat activity included Iran’s Handala claiming access to Cal Water and Russia’s Void Blizzard facing charges, with ShinyHunters also linked to PeopleSoft exploitation. #Ivanti #CISA #Oracle #PeopleSoft #WUSA #NovoNordisk #tchap #Maine #Handala #CalWater #VoidBlizzard #ShinyHunters #Europol #AudiA6 #ClaudeFable5 #Anthropic #CyberCorps

Read More
Cybersecurity News | Daily Recap [24 Jun 2026]

Daily Recap, AI-driven attacks are straining MSP security stacks as tools like OnyxC2 Stealer promise “enterprise-grade” theft, while the Miasma worm source code was briefly leaked on GitHub. Separately, the China-linked JDY botnet expanded beyond 1,500 devices to conduct reconnaissance and target U.S. military networks, while OpenAI said a likely Chinese influence operation tried to use ChatGPT to stir debate on data centers. #OnyxC2 #OnyxC2Stealer #Miasma #GitHub #JDY #ChatGPT #OpenAI #U.S. military

Read More
Cybersecurity News | Daily Recap [24 Jun 2026]

Daily Recap, Microsoft issued its June 2026 Patch Tuesday updates with a record 206 fixes and addressed multiple zero-days including YellowKey, GreenPlasma, MiniPlasma, and RoguePlanet, while also flagging potential issues installing some monthly updates on upgraded PCs. ServiceNow patched an already-exploited vulnerability and disclosed a customer data security incident, while Ivanti Sentry and Cisco SD-WAN faced high-risk flaws amid broader enterprise RCE and library vulnerability updates, including OpenSSL and Veeam Backup & Replication. #YellowKey #GreenPlasma #MiniPlasma #RoguePlanet #ServiceNow #Veeam #IvantiSentry #CiscoSDWAN #OpenSSL #Windows10 #Windows11

Read More
Cybersecurity News | Daily Recap [24 Jun 2026]

Daily Recap, Google and SAP released urgent fixes for a fifth Chrome zero-day exploited in the wild, plus critical NetWeaver/Commerce vulnerabilities and a LiteLLM issue that could be chained to unauthenticated remote code execution. CISA also ordered U.S. federal agencies to patch an exploited Check Point VPN flaw within 3 days, while Shai-Hulud supply-chain attacks targeted NPM and PyPI and WhatsApp/Meta disrupted additional NSO Group phishing campaigns.
#Chrome #NetWeaver #Commerce #LiteLLM #CheckPoint #Qilin #IKEv1 #Shai-Hulud #NPM #PyPI #NFCShare #WhatsApp #Meta #NSOGroup #SoFi #HongKong #UniFiOS

Read More