June 5, 2026 A trusted browser application has landed at the center of a supply chain security incident after researchers discovered that its official delivery pipeline had been quietly compromised. …
New Gafgyt Variant Targets Multiple Linux Architectures With Modular Propagation
June 5, 2026 A newly discovered variant of the Gafgyt botnet malware, named C0XMO, has been quietly spreading across Linux-based devices by targeting a known vulnerability in DD-WRT router firmware. …
Microsoft 365 Service Degradation Bypassed Windows Driver Auto-Update Controls
June 5, 2026 Microsoft has resolved a Microsoft 365 service degradation issue that temporarily bypassed Windows driver auto-update controls, leading to unintended driver installations on managed devices. The issue affected …
New SHub Stealer Variant Malware Targets Chrome, Firefox, Brave, Edge, Opera, and Crypto Wallets
June 5, 2026 A dangerous new variant of the SHub Stealer malware has emerged, targeting Mac users in ways that are smarter and harder to detect than before. The updated …
VECT 2.0 Ransomware Can Damage Files Its Own Decryptor Cannot Reliably Restore
June 5, 2026 A new ransomware strain called VECT 2.0 is raising serious concerns among security professionals, and for a troubling reason — even if a victim pays the ransom, …
Cisco SD-WAN Vulnerability Exploited in the Wild to Execute Arbitrary Commands as Root User
Cisco has disclosed a high-severity vulnerability in its Catalyst SD-WAN Manager that is actively being exploited in the wild, allowing attackers to execute arbitrary commands with root privileges. The issue, …
Let’s Encrypt Unveils Merkle Tree Certificates to Secure the Web Against Quantum Threats
June 5, 2026 Let’s Encrypt has announced its roadmap for post-quantum Web PKI, centering on a novel approach called Merkle Tree Certificates (MTCs), a design that delivers quantum-resistant authentication without …
Microsoft Edge Vulnerability Allows Remote Attackers to Execute Arbitrary Code
June 5, 2026 Microsoft has released a security update addressing a critical vulnerability in Microsoft Edge that could allow remote attackers to execute arbitrary code on vulnerable systems. Tracked as …
ClawHub, Cisco, Vercel’s Malicious Skill Detector Bypassed to upload Malicious Skills
AI skill scanners from ClawHub, Cisco, and Vercel’s skills. The platform can be bypassed with minimal effort, allowing malicious skills to be uploaded and distributed through public marketplaces. The findings …
HexStrike AI RED-TEAM With 127 Security Tools and BOAZ Red Team Integration
June 5, 2026 A fork of the original HexStrike AI project has been released as HexStrike AI v6.0, an advanced Model Context Protocol (MCP)-based cybersecurity automation framework that merges 127 professional …
