β οΈ Malicious Sicoob NuGet steals Brazilian bank credentials while npm packages target AWS and CI/CD secrets.
The fake "Sicoob.Sdk" versions 2.0.0β2.0.4 exfiltrate client IDs, PFX certificates, and passwords. It was downloaded nearly 500 times.
Multiple npm packages from one actor also steal cloud and pipeline secrets.
Full report: https://thehackernews.com/2026/05/malicious-sicoob-nuget-steals-banking.html
The fake "Sicoob.Sdk" versions 2.0.0β2.0.4 exfiltrate client IDs, PFX certificates, and passwords. It was downloaded nearly 500 times.
Multiple npm packages from one actor also steal cloud and pipeline secrets.
Full report: https://thehackernews.com/2026/05/malicious-sicoob-nuget-steals-banking.html
π5π2π₯1π€1
β οΈ A previously unknown threat actor has been quietly targeting #Ukraine since at least August 2025.
GREYVIBE uses spear-phishing, fake CAPTCHA pages, and fraudulent websites to deliver custom #malware to military, government, civilian, and business targets.
Researchers also found evidence of AI-assisted malware development and links to the cybercrime ecosystem.
Full report: https://thehackernews.com/2026/05/new-russian-linked-greyvibe-targets.html
GREYVIBE uses spear-phishing, fake CAPTCHA pages, and fraudulent websites to deliver custom #malware to military, government, civilian, and business targets.
Researchers also found evidence of AI-assisted malware development and links to the cybercrime ecosystem.
Full report: https://thehackernews.com/2026/05/new-russian-linked-greyvibe-targets.html
π8π5π₯4
β‘ AI is making DDoS attacks faster, smarter, and far more dangerous.
Attackers are now using AI to discover weak spots, create new attack vectors, and scale assaults with terrifying efficiency.
Join our next expert webinar: "A New Perspective on #DDoS Attacks in the Age of AI"
Learn real-world examples of AI-powered attacks and practical ways to defend against them β before they hit you.
π Register Now (Free): https://thehacker.news/ai-ddos-attacks
Attackers are now using AI to discover weak spots, create new attack vectors, and scale assaults with terrifying efficiency.
Join our next expert webinar: "A New Perspective on #DDoS Attacks in the Age of AI"
Learn real-world examples of AI-powered attacks and practical ways to defend against them β before they hit you.
π Register Now (Free): https://thehacker.news/ai-ddos-attacks
π12β‘2π1
β οΈ Attackers used an LLM agent for post-exploitation after breaching a public Marimo notebook via CVE-2026-39987, a pre-auth RCE flaw affecting versions β€0.20.4.
The intrusion stole cloud credentials, retrieved an SSH key from AWS Secrets Manager, and exfiltrated a PostgreSQL database via eight SSH sessions in under two minutes.
Full report: https://thehackernews.com/2026/05/attackers-use-llm-agent-for-post.html
The intrusion stole cloud credentials, retrieved an SSH key from AWS Secrets Manager, and exfiltrated a PostgreSQL database via eight SSH sessions in under two minutes.
Full report: https://thehackernews.com/2026/05/attackers-use-llm-agent-for-post.html
π±8π₯6π€―4π3
β οΈ A new technique called "ChatGPhish" turns OpenAIβs ChatGPT into a #phishing tool.
No special prompt required... simply summarizing a malicious web page can cause #ChatGPT to display phishing links, fake security alerts, QR codes, and attacker-hosted images in its trusted interface.
Full story: https://thehackernews.com/2026/05/chatgphish-vulnerability-turns-chatgpt.html
No special prompt required... simply summarizing a malicious web page can cause #ChatGPT to display phishing links, fake security alerts, QR codes, and attacker-hosted images in its trusted interface.
Full story: https://thehackernews.com/2026/05/chatgphish-vulnerability-turns-chatgpt.html
π€―29π9π8π5π₯3
π¨ CVE-2026-0257, a PAN-OS and Prisma Access authentication bypass flaw, is under active exploitation.
The CVSS 7.8 bug can enable unauthorized VPN access and, in some observed cases, access to internal networks.
Patch immediately or apply mitigations.
Details: https://thehackernews.com/2026/05/pan-os-globalprotect-authentication.html
The CVSS 7.8 bug can enable unauthorized VPN access and, in some observed cases, access to internal networks.
Patch immediately or apply mitigations.
Details: https://thehackernews.com/2026/05/pan-os-globalprotect-authentication.html
π₯11π6π4π€―2
Dutch authorities have dismantled a botnet comprising at least 17 million infected devices, including computers, smartphones, tablets, and IoT devices.
More than 200 servers in the Netherlands supported the operation. Police seized a subset of the infrastructure, and the hosting provider subsequently took the network offline.
Read: https://thehackernews.com/2026/05/dutch-authorities-dismantle-botnet.html
More than 200 servers in the Netherlands supported the operation. Police seized a subset of the infrastructure, and the hosting provider subsequently took the network offline.
Read: https://thehackernews.com/2026/05/dutch-authorities-dismantle-botnet.html
π15π12π₯5π€5π4
β οΈ Threat actors are actively exploiting a critical vulnerability in WP Maps Pro.
CVE-2026-8732 (CVSS 9.8) lets unauthenticated attackers create admin accounts and take over sites. It affects all versions up to 6.1.0.
Update to 6.1.1 now.
Read: https://thehackernews.com/2026/06/critical-wp-maps-pro-flaw-actively.html
CVE-2026-8732 (CVSS 9.8) lets unauthenticated attackers create admin accounts and take over sites. It affects all versions up to 6.1.0.
Update to 6.1.1 now.
Read: https://thehackernews.com/2026/06/critical-wp-maps-pro-flaw-actively.html
π10π8π₯3
π¨ A legitimate-looking npm package for OpenAI Codex has been stealing developer auth tokens for over a month.
codexui-android, marketed as a remote web UI, has seen 29,000+ weekly downloads. Since version 0.1.82 it quietly sends ~/.codex/auth.json β including non-expiring refresh tokens β to an attacker server.
Read: https://thehackernews.com/2026/06/openai-codex-authentication-tokens.html
codexui-android, marketed as a remote web UI, has seen 29,000+ weekly downloads. Since version 0.1.82 it quietly sends ~/.codex/auth.json β including non-expiring refresh tokens β to an attacker server.
Read: https://thehackernews.com/2026/06/openai-codex-authentication-tokens.html
π₯11π2π±2
π China-aligned hackers are intensifying espionage campaigns.
Operation Dragon Weave is hitting Czech Republic and Taiwan with spear-phishing ZIPs to deploy AdaptixC2 via Azure Blob Storage.
It gives attackers full remote control with 36 commands.
Learn More: https://thehackernews.com/2026/06/china-aligned-groups-ramp-up-attacks.html
Stay alert with unexpected email attachments.
Operation Dragon Weave is hitting Czech Republic and Taiwan with spear-phishing ZIPs to deploy AdaptixC2 via Azure Blob Storage.
It gives attackers full remote control with 36 commands.
Learn More: https://thehackernews.com/2026/06/china-aligned-groups-ramp-up-attacks.html
Stay alert with unexpected email attachments.
π8π5π₯4
The βvCISO platformβ label is outdated for todayβs MSPs.
Service providers need portfolio-wide security programs, CISO-grade intelligence, and revenue insights.
Thatβs why the Security Growth Platform category has emerged β and Cynomi currently defines it with its unified frameworks and 100% partner-only model.
Read: https://thehackernews.com/2026/06/the-security-growth-platform-why-msps.html
Service providers need portfolio-wide security programs, CISO-grade intelligence, and revenue insights.
Thatβs why the Security Growth Platform category has emerged β and Cynomi currently defines it with its unified frameworks and 100% partner-only model.
Read: https://thehackernews.com/2026/06/the-security-growth-platform-why-msps.html
π4π₯3
β‘ PAN-OS exploited. Gogs 0-day. GlassWorm takedown. AI malware lures. Smishing wave. OAuth phish kits. SonicWall scans.
Monday #cybersecurity recap is stacked.
Read it - https://thehackernews.com/2026/06/weekly-recap-new-linux-flaw-pan-os.html
Monday #cybersecurity recap is stacked.
Read it - https://thehackernews.com/2026/06/weekly-recap-new-linux-flaw-pan-os.html
π₯10π2
π₯ A new supply chain attack has hit official Red Hat Cloud Services npm packages.
The Miasma campaign, a fresh Mini Shai-Hulud variant, plants a malicious preinstall hook that steals GitHub secrets, cloud credentials, SSH keys, and more from developer and CI/CD environments.
It also adds persistence and downstream poisoning.
Read: https://thehackernews.com/2026/06/miasma-supply-chain-attack-compromises.html
The Miasma campaign, a fresh Mini Shai-Hulud variant, plants a malicious preinstall hook that steals GitHub secrets, cloud credentials, SSH keys, and more from developer and CI/CD environments.
It also adds persistence and downstream poisoning.
Read: https://thehackernews.com/2026/06/miasma-supply-chain-attack-compromises.html
π₯13π±7π4
π¨ A brute-force attack against certain Dashlane accounts bypassed 2FA protections in a handful of cases, allowing attackers to register new devices and download encrypted vault copies.
Fewer than 20 personal plan users were affected.
Full details: https://thehackernews.com/2026/06/dashlane-discloses-brute-force-attack.html
Fewer than 20 personal plan users were affected.
Full details: https://thehackernews.com/2026/06/dashlane-discloses-brute-force-attack.html
π3