Sunday, June 21, 2026
Cybersecurity News
Industry News
Expert Insights
Webinars
Learning Center
Topics
About
Sponsor
Cybersecurity News
Industry News
Expert Insights
Webinars
Learning Center
Topics
About
Sponsor
Combing the world for the cybersecurity stories you need to know.
Cybersecurity News
Handala’s Cal Water Breach Claim Exposes Hidden Risk in Utility Networks
June 20, 2026
Threat intelligence firm Dataminr reported that Handala, an Iran-linked threat actor, claimed it breached California Water Service and published stolen data from the utility. The evidence released so far, however, points to a narrower compromise…
Read More >
The Case for Runtime Security Is Now Undeniable
June 19, 2026
There has long been an industry consensus that moving threat detection earlier in the development lifecycle is an effective way to prevent incidents in production. Heavy investment in pre-production scanning, DevSecOps tooling, and “shift earlier”…
Read More >
Trump Executive Order Creates New Security Bargain Between Government and AI Industry
June 17, 2026
President Trump's June 2nd executive order on artificial intelligence marks a meaningful pivot. Previously, his administration maintained a hands-off posture toward the AI industry. While this order does not yet impose regulatory mandates, it constructs…
Read More >
Cybercriminals Targeted the 2026 FIFA World Cup Before Play Even Began
June 15, 2026
Cybercriminals began building infrastructure to target the 2026 FIFA World Cup well before the first match was played, according to a new report from Fortinet’s FortiGuard Labs. The company said it tracked FIFA-themed cyber activity…
Read More >
How a Fake Purchase Order Becomes a Full-Scale Enterprise Data Breach
June 09, 2026
Fortinet’s FortiGuard Labs recently discovered a phishing campaign with the goal of stealing sensitive data from target devices using a PureLogs variant. The lure hidden behind business document theming exploits the urgency and routine that…
Read More >
CVE-2026-9082 and the Hidden Risk in Drupal's Core
June 06, 2026
A recently discovered vulnerability in Drupal Core, tracked as CVE-2026-9082, has been exploited in the wild and added to the United States Cybersecurity and Infrastructure Security Agency’s (CISA) KEV catalog. The vulnerability is an SQL…
Read More >
Claw Chain Exposes the Blind Spot at the Center of Agentic AI Security
June 02, 2026
Open-source agentic AI platform OpenClaw has undergone rapid adoption since its late 2025 launch. First introduced as Clawdbot, OpenClaw has seen broad enterprise integration across IT automation, customer service, and messaging platforms. With the use…
Read More >
Twill Typhoon Modular Backdoor Rewrites Rules of Detection
June 01, 2026
Chinese-nexus threat actors have long demonstrated patience and operational sophistication. But newly-released research by Darktrace marks something more consequential than another well-executed intrusion. A Twill Typhoon attack documents an adversary that has engineered tooling to…
Read More >
How AI Is Collapsing the Federal Patching Window
May 29, 2026
The United States Cybersecurity and Infrastructure Security Agency (CISA) established the Known Exploited Vulnerabilities (KEV) catalog in November 2021 as a resource to aid federal agencies and the public in their efforts to defend against…
Read More >
Fake Claude Code Page Turns Trusted Developer Workflow Into Credential-Stealing Attack
May 26, 2026
A fake Claude Code installation page promoted through sponsored search results delivered an undocumented credential stealer by mimicking a familiar developer workflow, according to new research from Ontinue. Victims looking for Claude Code installation instructions…
Read More >
The AiTM Campaign That Made Your Policies Work Against You
May 22, 2026
A recent large-scale credential theft campaign discovered by Microsoft Defender Research serves as a prime demonstration of how institutional culture can become the attack surface for increasingly sophisticated phishing attacks. The design of the lure…
Read More >
How Open Source CI Workflows Became the New Supply Chain Vulnerability
May 21, 2026
On April 24th, 2026, the Elementary Open Source Python CLI was released containing malicious code, injected by an attacker posting a crafted pull request (PR) comment. The GitHub Actions workflow interpolated the comment into a…
Read More >
When Agents Decide to "Fix" It: The Governance Gap in Autonomous AI
May 19, 2026
All it took was the time to read this sentence, or about nine seconds. An AI coding agent wiped out months of customer data essential to the PocketOS SaaS platform and its car rental clients.…
Read More >
How Copy Fail Turned Linux's Memory Efficiency Against Itself
May 18, 2026
A newly discovered vulnerability, dubbed Copy Fail and tracked as CVE-2026-31431, defies the profile of a classic kernel exploit by requiring no race condition, no version-specific offsets, and no compiled payloads. The same 732-byte Python…
Read More >
SAP npm Compromise Exposes Credential Risk in Build Pipelines
May 15, 2026
Malicious versions of four SAP-related npm packages exposed developer machines and CI/CD systems to possible credential theft. Rather than targeting production SAP servers directly, the attack reached into the build pipeline used to create and…
Read More >
Why PhantomRPC Is a Flaw That Cannot Be Patched Away
May 14, 2026
The Remote Procedure Call (RPC) mechanism of the Interprocess Communication (IPC) ecosystem is the universal communication backbone of Windows systems, embedded so deeply in the OS that its failure modes become everyone's problem. A recent…
Read More >
Tax Phishing Is Moving From Personal Inboxes to the Workplace
May 12, 2026
Tax phishing has long been easy to dismiss as a seasonal consumer scam: fake IRS emails, refund bait, audit threats, and other lures aimed at people anxious about filing deadlines. New research from Hoxhunt suggests…
Read More >
What Zealot Reveals About AI's Cloud Offensive Capabilities
May 11, 2026
A disclosure from AI giant Anthropic in November 2025 confirmed that AI autonomously executed between 80% and 90% of a particular state-sponsored espionage campaign, effectively shifting the debate from hypothetical to a documented reality. Unit…
Read More >
Subscribe for the Latest News
Webinars
Thursday, Jun. 25
1pm ET / 10am PT
Leaked outside the scan path: the blind spots in secrets detection
Tuesday, Jun. 30
1pm ET / 10am PT
From Ticket to Threat: Preserving Context Across Security Teams
Tuesday, Jul. 7
1pm ET / 10am PT
The Unstructured Data Blindspot: Why Your Most Valuable Assets Are Your Least Protected