June 17, 2026 AIRecon is an autonomous penetration testing agent that runs entirely offline, combining a self-hosted Ollama LLM with a Kali Linux Docker sandbox to automate end-to-end security assessments …
Critical LiteLLM Flaw Allows Authentication Bypass via Host Header Injection
June 17, 2026 A critical security vulnerability has been disclosed in LiteLLM, an increasingly popular proxy used for managing large language model (LLM) APIs. The flaw, tracked as CVE-2026-49468, allows …
Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code – Update Now!
June 17, 2026 Google has released a critical security update for its Chrome browser, addressing multiple high-severity vulnerabilities that could allow attackers to execute arbitrary code on affected systems. Users …
Hackers Abuse Steam Workshop Application Wallpapers to Hijack Active Steam Sessions
June 17, 2026 Threat actors have been abusing Valve’s Steam Workshop since late 2025, embedding malware inside Wallpaper Engine application wallpapers to hijack active Steam sessions and infect victims with …
Hackers Using Claude and OpenAI’s Codex for Exploitation, and Data Exfiltration Activities
June 17, 2026 Hackers are increasingly abusing Anthropic’s Claude and OpenAI’s Codex agents to automate reconnaissance, exploitation, and data exfiltration, often by disguising real intrusions as “authorized red team” work. …
Using Real-Time Network Monitoring to Spot Suspicious Application Behavior on macOS
June 17, 2026 In this guide, we will see how real-time network monitoring helps you spot suspicious application behavior on macOS, why traditional defenses leave a visibility gap, and how …
UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data
June 17, 2026 A sophisticated cybercriminal group has been quietly targeting law firms and professional services organizations across the United States since the beginning of 2026. The campaign is financially …
Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes
June 17, 2026 A state-linked hacker group known as Ghostwriter has launched a wave of targeted phishing attacks aimed at Gmail users, disguising malicious emails as official security alerts from …
The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful?
June 16, 2026 When Do IOCs Stop Being Useful? The concept of the IOC — the Indicator of Compromise — sits at the operational heart of modern threat detection. Block …
Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks
June 16, 2026 Threat actors are actively exploiting multiple critical vulnerabilities in Fortinet’s FortiSandbox platform, with live attack telemetry confirming exploitation attempts over the past 24 hours. Defused has flagged …

