## Critical Cybersecurity Developments: 2026-06-20 ### Executive Summary This report synthesizes verified breaking developments from trusted industry sources and real-time threat intelligence feeds. The following analysis integrates live search results with established security frameworks. — ### Live Search Results Analysis Based on current intelligence, the following threat vectors are active: #### 1. Emerging Threat Vectors…
Global Security News
Inside GentleKiller: The EDR-Killer Powering The Gentlemen
The Gentlemen equips affiliates with a centralized EDR-killer suite, rapidly weaponizing BYOVD exploits to disable security tools before ransomware attacks. ESET published a detailed breakdown of The Gentlemen‘s technical infrastructure on June 18, the result of months of incident-level investigation corroborated by the group’s own internal data leak from May 2026. Since emerging in late…
Global Security News
New Prinz Eugen ransomware prioritizes recent files for encryption
Global Security News
Microsoft links Mastra AI supply chain attack to North Korean hackers
Global Security News
MDR Provider Comparison: Time to Discover and Respond to Threats
A detailed MDR provider comparison covering tiers, response speed, coverage, threat intelligence, pricing, and breach warranties to help you choose.
Global Security News
Cielo vs Nansen vs Arkham: Which Wallet Tracker Pairs Best With a Telegram Trading Bot?
In this post, we will compare Cielo vs Nansen vs Arkham and I will tell you which wallet tracker pairs best with a Telegram trading bot? Most tracker comparisons stop at “which one has the prettiest dashboard.” That misses the actual workflow. The tracker is one stage of a two-stage pipeline. Stage one surfaces a…
Global Security News
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that’s installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens
Global Security News
The Market’s AI Fanfare Is Running Into a Harsh Political Reality
Global Security News
Why Apple Enjoys Peerless iPhone Pricing Power
Global Security News
FortiBleed Exposes Global Credential-Spraying Operation

FortiBleed exposed a massive campaign that made billions of login attempts against Fortinet VPNs, compromising organizations worldwide. FortiBleed wasn’t a targeted hack. It was a factory. A multi-operator crew ran an industrial-scale attack against Fortinet FortiGate SSL VPN devices worldwide, and security researcher Volodymyr “Bob” Diachenko of SecurityDiscovery.com caught them only because they left their…
Global Security News
CISA Warns of Active Exploitation Following FortiBleed Leak

FortiBleed exposed credentials for 74,000 Fortinet devices, with attackers actively exploiting the leak to target systems worldwide. On June 18, CISA issued an emergency alert after reports surfaced that credentials for approximately 74,000 Fortinet firewalls and VPN gateways had been leaked in what researchers are calling FortiBleed. The agency confirmed that threat actors were actively…
Global Security News
The hidden costs of electric vehicle ownership Australians should budget for
Global Security News
Solidarity
For decades, by many means, fair or foul, personal information as per the Australian Privacy Act 1988 has been extracted from the individual for commercial and state actor…
Global Security News
Secretive Wall Street Powerhouse Jane Street Seizes the AI Spotlight
The firm has surged from a handful of staffers to 3,500 with plans to recruit more than 500 employees this year.
Global Security News
Why the Memory Crunch Is Almost Impossible to Solve
Global Security News
Klue OAuth breach victim list grows as Icarus hackers claim attack
Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers’ Salesforce environments, as the new “Icarus” extortion group publicly claims the attack. […]
Top Tech Tools
Top 10 Mini PCs & LLM Capability (2026)

The barrier to entry for local AI has officially collapsed. In 2026, running a highly capable Large Language Model (LLM) no longer requires a massive tower with multiple discrete GPUs pulling 1000 watts. If you are building agentic frameworks, running local log analysis for Identity Threat Detection and Response (ITDR), or just want an uncensored…
Global Security News
LLMS, Identity, EDR, JiGong, QiLin, Warlock, with Rob Allen from Threatlocker… – Rob Allen – SWN #591
Top Tech Tools, Uncategorized
Top 10 Amazon Best-Reviewed AI PC Minis (2026)
The era of pure cloud-dependency for AI is closing. For cybersecurity professionals, developers, and privacy-conscious users, 2026 is the year the “AI Mini PC” moved from a novelty to a necessity. Thanks to processors packing dedicated Neural Processing Units (NPUs) exceeding 40 TOPS (Tera Operations Per Second) and high-bandwidth unified memory, you no longer need…
Global Security News
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Global Security News
Threat actor adds advanced ‘EDR killer’ tools to ransomware-as-a-service platform
One of the world’s top ransomware groups has given its criminal affiliates access to advanced tools capable of successfully disabling many of today’s enterprise endpoint detection and response (EDR) products, new research by security company ESET has found. The group in question is The Gentlemen, which, since its appearance last year using this moniker, has…
Competitive Reports
Agent-less Endpoint Defense: Positives, Negatives, Scenarios

The Scenario: What is Agentless Endpoint Defense? Definition:Agentless Endpoint Defense is a security architecture that protects endpoints (laptops, desktops, servers, mobile devices) without installing any software agents, daemons, or processes on the target machine. Instead, it uses external infrastructure, network-based scanning, cloud APIs, hardware security modules, or passive data collection, to monitor, detect, and respond…
Global Security News
Unpatchable ‘usbliter8’ Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple’s A12 and A13 chips. That code is burned into the silicon at manufacture. No software update can reach it. Affected devices will carry this flaw for as long as they stay in use. This is not…
Global Security News
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor. This mature portfolio of EDR-terminating tools is centered around a framework that’s known as GentleKiller. “They also incorporate third-party or
Uncategorized
Critical Cybersecurity Updates: 2026-06-19
## Critical Cybersecurity Developments: 2026-06-19 ### Executive Summary This report synthesizes verified breaking developments from trusted industry sources and real-time threat intelligence feeds. The following analysis integrates live search results with established security frameworks. — ### Live Search Results Analysis Based on current intelligence, the following threat vectors are active: #### 1. Emerging Threat Vectors…
Global Security News
Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime
Global Security News
Solving an ARD problem in AI: Agentic Resource Discovery
Enterprises implementing agentic AI face a challenge: Which tools should they allow their agents to use, where can they be found, and how can they be used safely? A new protocol, Agentic Resource Discovery, or ARD, aims to let agents answer those questions for themselves. Behind it are Google, Microsoft, Cisco, Nvidia, Salesforce and others.…
Global Security News
US should take 50% stake in major AI firms, says Bernie Sanders

With the market capitalization of AI companies soaring, US Senator Bernie Sanders is looking to give the American people a piece of the action. The veteran senator for Vermont has introduced the American AI Sovereign Wealth Fund Bill, aiming to give the public a 50 percent ownership in the largest AI companies in the US.…
Global Security News
OpenAI gets the attention it needs from AI researcher Noam Shazeer

An IT executive changing jobs usually attracts little attention outside a narrow group of people, but Noam Shazeer’s move from Google to OpenAI is as momentous as any high-value soccer transfer. He announced the news in a post on X: “I’m excited to share that I’ll be joining OpenAI and look forward to working with…
Global Security News
Texas govt data breach exposes over 3 million driver’s licenses
Global Security News
Nearly 15,000 infected websites cleaned in SocGholish crackdown

We’re always happy to end the week with some positive news. A law enforcement action called Operation Endgame just delivered a major win against the long‑running SocGholish (aka FakeUpdates) operation. SocGholish is a malware framework that has been active since at least 2017 and is best known for abusing hacked, legitimate WordPress sites to push…
Global Security News
Apple’s Hide My Email tweak leaves privacy fans fuming
Global Security News
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent to load an attacker’s web page, and that page’s JavaScript can reach a privileged local service on the same machine and spawn a process on the host. No credentials, no…
Global Security News
Best AI Alert Triage Tools for Modern SOC Teams

In this post, I will talk about the best AI Alert Triage tools for modern SOC teams. This guide covers the leading AI alert triage tools available to modern SOC teams, what each one actually does, and how to evaluate the category against your operational needs. What AI Alert Triage Actually Means The SANS 2025…
Global Security News
The Ninja Creami just dropped to an all time low price for Prime Day – and I recommend one
Make your own ice cream, gelato, sorbet, and smoothie bowls with the Ninja Creami, now 22% off for Amazon Prime Day.
Global Security News
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites. “With these actions we deprive cybercriminals of access to infected computer systems,” Maikel Rollman of the Netherlands National High Tech Crime Unit said. “This prevents
Global Security News
Google, Microsoft offer specs to help you prove your AI is behaving nicely

Google, Microsoft, OpenAI, and others want to help enterprises demonstrate that their AI applications are behaving themselves through the creation of a new foundation. The Appia Foundation will, it explained rather impenetrably, “establish modular specifications that provide a connecting layer to bridge foundational global standards with practical, trusted assessments across the global AI value chain.”…
Global Security News
Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections
Luxembourg, Luxembourg, 19th June 2026, CyberNewswire
Global Security News
Microsoft broke some OLE automations with latest Windows update

Microsoft Office users may find that some of their applications are failing to open when called on by third-party applications. It’s an issue that has emerged after the latest round of Microsoft updates. The problem affects Word, Excel, and other Office applications opened from third-party offerings including CCH Engagement, Workpaper Manager, Zotero, or dental office…
Global Security News
Microsoft broke some OLE automations with latest Windows update

Microsoft Office users may find that some of their applications are failing to open when called on by third-party applications. It’s an issue that has emerged after the latest round of Microsoft updates. The problem affects Word, Excel, and other Office applications opened from third-party offerings including CCH Engagement, Workpaper Manager, Zotero, or dental office…
Global Security News
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps to secure against ongoing malicious activity aimed at thousands of internet-accessible devices. The sweeping campaign, believed to be the work of Russian-speaking threat actors, has been codenamed FortiBleed. The number of compromised devices stands at
Global Security News
OpenAI adds spend controls and usage analytics to ChatGPT Enterprise

OpenAI has introduced spend controls and enhanced usage analytics for ChatGPT Enterprise to enable organizations to monitor AI adoption, track consumption across teams, and set budgets for AI usage. But, analysts cautioned, it still can’t show how those costs lead to business benefits. The new features provide administrators with centralized dashboards showing how ChatGPT is…
Global Security News
Imposter scams cost Americans $3.5 billion in 2025 – and it’s getting worse
Global Security News
Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse
Global Security News
14,971 WordPress Sites Cleaned in Global SocGholish Takedown

Operation EndGame disrupted SocGholish, taking down 106 servers and cleaning 14,971 WordPress sites used to spread fake-update malware. On June 18, 2026, law enforcement agencies from the Netherlands, Canada, the United States, and Germany, coordinated through Europol, executed a joint action week against SocGholish, one of the most persistent and widely deployed malware distribution networks…
Global Security News
eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks
Global Security News
Every AI Agent Is an Identity. Most Organizations Don’t Treat Them That Way
Global Security News
Stressors, AI Forcing Changes to Cybersecurity Teams
Global Security News
Klue breach lead to Salesforce data theft, Huntress affected

Cybersecurity vendor Huntress was among multiple companies hit by a breach originating at Klue, a market intelligence platform used to integrate CRM and sales data across various business tools. Huntress published a detailed account of the incident on June 18, framing it as a “security domino effect” that began with one compromised integration credential and…
Top Tech Tools
Top 10 Geeky and Technical Bathroom Items on Amazon – Review Data Report

Executive Summary This report analyzes the top 10 bathroom gadgets with the highest review counts on Amazon, focusing on tech-focused, geeky items with proven customer satisfaction (4.5+ stars). Product List (Ranked by Review Count) 1. Emlimny Toilet Night Light Gadget 2. Bitvae X122 Toothbrush Cleaner & Sanitizer 3. Keenray Bucket Towel Warmer 4. SereneLife Towel…
Global Security News
CVE-2026-42530: Critical NGINX HTTP/3 Flaw Can Trigger DoS and Possible RCE
F5 has released out-of-band security updates to address multiple NGINX Vulnerabilities, including CVE-2026-42530, a critical issue in the ngx_http_v3_module that can be exploited by a remote, unauthenticated attacker. The flaw is a use-after-free condition in NGINX’s HTTP/3 implementation that can cause worker-process restarts and denial of service, and in environments where ASLR is disabled or…
Global Security News
Webinar: How attackers bypass MFA and how defenders can respond
Modern phishing attacks, including Device Code phishing, can undermine MFA protections and grant attackers access to corporate accounts without stealing passwords. This webinar explores how behavioral AI can help security teams detect compromised accounts faster and automate response workflows. […]
Global Security News
Cybercriminals abused GitHub, YouTube and VirusTotal to push crypto-stealing malware

A cryptocurrency-stealing malware campaign used inflated GitHub activity, software reviews, YouTube tutorials and favorable VirusTotal comments to make malicious trading and gambling tools appear trustworthy, Check Point researchers found. According to the researchers, the attackers packaged the malware as tools designed to help users make money. The offerings included cryptocurrency sniper bots and gambling “predictors”…
Global Security News
I flew 2,700 miles with Apple, Sony, and Sennheiser headphones – this pair had the best audio
Air travel is the true test for ANC headphones and earbuds. My multiple journeys revealed key strengths and weaknesses of the latest models.
Global Security News
The Secret Revolution in Battery Technology: 3-D Printing
Startups are attempting to put energy storage anywhere and everywhere.
Global Security News
From Assistive to Agentic: The AI Shift That’s Redefining Threat Management
Introduction The average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset data. But often, these tools are working in siloes, generating (overlapping) alerts and data. And yet, breach dwell times remain stubbornly long (~43 days), response windows keep closing before teams can act, and…
Global Security News
Apple patches Beats Studio Buds flaw that could turn earbuds into a wiretap

Apple has patched a Bluetooth flaw in Beats Studio Buds that could potentially turn your earbuds into a nearby wiretap. When you buy a pair of Bluetooth earbuds, you expect them to play your music and your calls—not someone else’s. But a vulnerability in Apple’s Beats Studio Buds shows how that trust can be abused,…
Global Security News
Microsoft: June 2026 Windows updates break Recycle Bin prompts
Microsoft has confirmed a confusing Windows bug that causes different filenames to appear in the confirmation dialog when deleting a file from the Recycle Bin. […]
Global Security News
Penetration Testing Services in South Africa
Global Security News
How to use Excel formulas and functions

One of the most commonly used Microsoft programs, Excel is highly useful for data collecting, processing, and analysis. To fully harness Excel’s powers, though, you need to make use of formulas. Excel formulas allow you to perform calculations, analyze data, and return results quickly and accurately. The usefulness of formulas is even greater once you…
Global Security News
AWS Unveils ‘Continuum,’ an AI-Powered Vulnerability Management Platform
Global Security News
Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)
CISA has added CVE-2026-20253, a critical, remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog, and ordered US federal civilian agencies to apply mitigations by June 21, 2026. In-the-wild exploitation has also been confirmed by the vendor and Resecurity, who said that its potential for full system compromise should push organizations to…
Global Security News
Forget traffic lights, Google’s reCAPTCHA may ask for hand gestures

Google has introduced hand gesture verification for reCAPTCHA, a new method for verifying that a user is human. Google’s reCAPTCHA is part of Google Cloud Fraud Defense, a fraud and abuse prevention platform for bot, account, and transaction protection. It uses risk analysis and challenge-based verification to help organizations identify automated activity and suspicious behavior.…
Global Security News
CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
CISA has urged U.S. federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks. […]
Global Security News
U.S. CISA adds Splunk Enterprise flaw to its Known Exploited Vulnerabilities catalog and urges agencies to fix it by Sunday
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Splunk Enterprise flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Splunk Enterprise flaw, tracked as CVE-2026-20253 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw CVE-2026-20253 is an improper authentication vulnerability in the PostgreSQL sidecar service of…
Global Security News
Forget Data Leakage: Shadow AI’s Real Threat Is Access Control
The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security teams responded with usage policies, domain blocks, and data loss prevention rules. That response made sense at the time. It doesn’t fit the problem anymore. Shadow AI has shifted from a data leakage concern…
Global Security News
8 Top AI SOC Platforms to Watch Out for in 2026

In this post, I will highlight the top AI SOC platforms to watch in 2026. In the age of ever-rising alert volumes, tighter budgets, and sophisticated adversaries, the question is no longer “Should we use AI in the SOC?” It’s “How do we use AI so it augments human analysts rather than replaces them?”. Here…
Global Security News
Operation Endgame Disrupts Malware Network Linked to Major Ransomware Gang
Global Security News
You can get Amazon Prime totally free for 6 months if you’re age 18-24 – what to know
Amazon’s Prime for Young Adults plan gets college students and young people a big break on the membership. Here’s how to get it.
Global Security News
Q&A: Temporal aims to be the reliability backbone for an agentic AI economy

As AI shifts from output-generating large language models (LLMs) to armies of agents taking actions on their own, there is a growing threat that failures could affect system reliability. Temporal, a Bellevue, WA firm founded in 2019, hopes to solve that problem by stabilizing AI and long-running computing processes through “durable execution,” a technology that…
Global Security News
Breaking the SOC triangle: How AI reshapes security operations trade-offs
A simple framework has always governed security operations that I call the SOC Triangle. It is a balance between quality, consistency and cost efficiency. Every SOC operates within it. Push for higher-quality investigations, deeper analysis, richer context, fewer missed signals and you pay for it in time and expertise. Standardize workflows to ensure consistency across…
Global Security News
FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites
Cybersecurity experts warn that active hacking networks are using fake hotel bookings, cloned websites, and live chat features to scam FIFA World Cup 2026 fans.
Global Security News
Mastodon 4.6 adds profile Collections and two-factor controls

People who run accounts on the open source social network Mastodon can now group profiles together and share those groups across the web. The 4.6 release centers on a feature called Collections, along with reworked profiles, email newsletters, server administration controls, and a set of accessibility changes. Server controls The release gives server administrators a…
Global Security News
How to bring the best Android 17 features to any Android phone today

Google’s latest and greatest Android version is officially now out in the world and available — but if you’re using any phone other than a Pixel, that doesn’t mean much for you just yet. The reason why is simple: Despite Google officially launching Android 17 and starting to send it out to Android phone-owners this…
Global Security News
The Hacker News Recognizes ANY.RUN as the Best Security Investigation Platform 2026

ANY.RUN has been recognized as the Best Security Investigation Platform 2026 at the Cybersecurity Stars Awards by The Hacker News. This award reflects our dedication to building solutions that make a real impact on daily security operations. At ANY.RUN, we help SOC and MSSP teams worldwide streamline threat investigation workflows through confident decision-making, full malware and phishing visibility, and actionable insights thataccelerate incident investigations and response. We thank our global community of security professionals for continuously trusting our solutions and supporting our growth! Reinforcing Our Position as a Market…
Global Security News
Google sets timeline for Android developer verification enforcement

Android’s developer verification protections will take effect on September 30, 2026, starting with users in Brazil, Indonesia, Singapore, and Thailand. Developers distributing apps through participating stores in those markets must complete the verification process by the deadline. Google Play, HONOR App Market, OPPO App Market, Galaxy Store, Palm Store, V-Appstore, and GetApps will begin verifying…
Global Security News
Trump-Loving Crypto Super PAC Finally Backs a Democrat: Ritchie Torres
A crypto super PAC that has praised President Donald Trump and previously endorsed an all-Republican slate of candidates has finally found a Democrat it can get behind: New York Rep. Ritchie Torres. The Fellowship PAC dropped $300,000 on Monday to boost Torres in the final days of his reelection primary campaign, funneling its ad spend…
Global Security News
Accenture to buy Dragos, runZero, and NetRise in $4.2 billion cybersecurity deal

Accenture is expanding its position with the acquisition of a majority stake in Dragos and all of runZero and NetRise to deliver end-to-end operational technology (OT) security for the critical infrastructure and industrial operations underpinning power grids, pipelines, manufacturing, distribution facilities and data centers. The Dragos Platform will expand to cover the extended environment that…
Global Security News
Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data

Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026. To that end, organizations will be unable to connect to Salesforce via the app until further notice, the American cloud-based software company noted in an alert…
Global Security News
Security considerations for adopting Claude Code and Cowork for SMBs

You are a security leader at a small or medium-sized business (SMB), and your organization has decided to adopt Claude. If you are like me, after the initial “surprise” wears off, you probably want to quickly get your arms around what adopting Claude means for the business, and for security specifically. Below are some lessons…
Global Security News
Confidence Lacks in Threat Detection Across Non-Email Channels like Slack and Teams
Half of cybersecurity leaders lack confidence in detecting threats on Slack, Teams and other non-email platforms, despite growing attacker focus
Global Security News
NY man charged after harassing college student with AI-generated nudes
A New York man faces cyberstalking charges after allegedly sharing AI-generated nude images and fabricated racist messages using fake social media profiles to harass a Georgia college student. […]
Global Security News
Microsoft says web-enabled AI agents can trigger host-level RCE
Microsoft is warning of a novel remote code execution (RCE) path possible through web-enabled AI agents, demonstrating the technique against AutoGen Studio, its open-source interface for building and testing multi-agent applications. The demonstration showed that a malicious webpage rendered by an AutoGen-powered browsing agent could reach a local Model Context Protocol (MCP) service and run…
Global Security News
Report: AI is Reshaping Trust, Scams, and Identity Theft
A new report launched this week by Malwarebytes, “Face value: How AI is reshaping trust, identity and scams,” reveals the hidden cost of AI to the public: increased fraud that is dismantling trust in reality and in one another. The report surveyed 1,500 adults across the U.S., U.K., and DACH region, exploring the help, harm,…
Global Security News
Peter Thiel ‘s Secret Society Leak Creates a Perfect Target List for Espionage, Influence Operations, and Blackmail
A simple website flaw exposed members, political profiles, login tokens, and dating data from Peter Thiel ‘s secretive Dialog network. Dialog, a private invitation-only organization cofounded in 2006 by billionaire tech investor Peter Thiel, has spent two decades refusing to disclose its membership. That position became harder to maintain last week when Swiss hacktivist maia…
Global Security News
BlackFog brings shadow AI visibility to macOS endpoints with ADX Vision

BlackFog has announced the general availability of ADX Vision for macOS, extending its shadow AI detection, governance, and prevention platform to Apple endpoints. With this release, enterprises can now apply a single, consistent AI data-loss policy across Windows and macOS devices to stop sensitive data from leaving the organization through unsanctioned LLMs. The release addresses…
Global Security News
eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)
I detected an interesting phishing email this morning. It targets a major Belgian bank: The phishing in itself is a classic one, not relevant but the malicious link is interesting: hxxp://[::ffff:5511:74be]/kWC5PHA1 The technique used by the attacker is to bypass simple security controls trying to extract domain names and IP addresses via simple regular expressions.…
Global Security News
M365 Copilot SearchLeak: Your prompt injection attack surface just got bigger
A recent proof-of-concept attack against Microsoft’s M365 Copilot Enterprise highlights what could be a much broader prompt injection threat based on a common way many AI-enhanced web services operate. Dubbed SearchLeak, the attack hinged on a typical malicious objective: to leak sensitive corporate data by tricking employees to click on specially crafted links. To carry…
Global Security News
CISA warns Fortinet users to secure devices after FortiBleed leak
Global Security News
Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users. The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorrect authorization impacting the Airoha Bluetooth audio SDK that makes it possible to pair a Bluetooth audio…
Global Security News
Vodafone Warns Millions Could Miss Critical Text Messages from 1 July
Global Security News
Holding Redlich partners with Legora to deploy AI across transactional practices
Global Security News
Your browser tab could become encrypted storage for someone else’s files

Decentralized storage networks already hand pieces of people’s data to strangers’ machines. The lasting question across these networks is whether the machine holding the data can read it. A research paper by Gregory Magarshak, a professor at IENYC, describes a system called Safecloud built on one design rule: the nodes that store data see only…
Global Security News
IAS Launches Quality Connect, Giving Publishers Greater Visibility into Advertiser Campaign Preferences
New IAS Pulse solution closes the transparency gap between buyers and sellers, enabling publishers to better meet advertiser quality standards, reduce wasted media, and build…
Global Security News
24 Billion Stolen Credentials Exposed in Massive Data Leak

24 Billion Records Left Open Online: Passwords, Emails, and Everything Else Exposed database with 24 Billion records revealed stolen credentials from infostealers, Telegram channels, and breach collections, risking account takeovers. Cybernews researchers found an exposed Elasticsearch cluster on June 12th containing 24 billion records and more than 8.3 terabytes of data. They triple-checked the numbers.…
Global Security News
Companies are discarding the logs they need to catch a breach

Many large enterprises discard most of the log data their systems generate, and they do it on purpose to keep costs down. A Dynatrace survey of 450 senior IT leaders at large enterprises found that half of organizations drop or never collect an average of 86 percent of their logs, even after filtering and aggregation.…
Global Security News
Asia-Pacific scam networks generate nearly $40 billion a year

Cybercrime is taking a larger share of criminal activity in Asia and the Pacific. More than half of surveyed jurisdictions reported that cybercrime accounts for over 30% of all crimes recorded nationally, according to INTERPOL’s 2025/2026 Asia and South Pacific Cyberthreat Assessment Report. Distribution of malware types detected within the Asia and South Pacific region…
Global Security News
New infosec products of the week: June 19, 2026
Here’s a look at the most interesting products from the past week, featuring releases from ArmorCode, Barracuda Networks, Blue Planet, Flip, Fortinet, Legit Security, Tigera, and WitnessAI. Fortinet FortiSOC unifies SIEM, SOAR, threat intelligence, and AI in one platform Fortinet has announced the availability of FortiSOC, a unified, cloud-delivered security operations center (SOC) platform. FortiSOC…























