June 2, 2026 A dependency confusion vulnerability affecting Microsoft’s Azure Portal after the Microsoft Security Response Center (MSRC) closed the case, claiming the confirmed remote code execution evidence did not …
Mustang Panda Deploys PlugX RAT Through Multi-Stage LNK and PowerShell Attack Chain
June 2, 2026 A well-known Chinese state-sponsored threat group called Mustang Panda has been caught running a sophisticated cyberattack campaign using its signature remote access tool, PlugX. The group used …
TP-Link Router Vulnerability Allows Attackers to Execute Arbitrary System Commands
A newly disclosed high-severity vulnerability in TP-Link routers could allow attackers to execute arbitrary system commands and fully compromise affected devices. Tracked as CVE-2026-5509, the flaw affects Archer BE450 v1 …
Claude Code’s GitHub Actions Vulnerability Lets Attackers Compromise Any Repository
June 2, 2026 A critical supply chain vulnerability in Claude Code’s GitHub Actions that could allow attackers to compromise any repository using Anthropic’s official CI/CD workflow, including Anthropic’s own infrastructure. …
Hackers Deploy AZUREVEIL Adaptix C2 Agent via Spearphishing Campaign
June 2, 2026 A newly identified spearphishing campaign has been quietly targeting government officials, researchers, and technology workers in the Czech Republic and Taiwan. Threat researchers traced the operation to …
PHANTOMPULSE RAT Uses Process Injection and UAC Bypass to Compromise Windows Systems
June 2, 2026 A newly analyzed remote access trojan called PHANTOMPULSE has drawn serious attention for its advanced approach to compromising Windows systems. The malware is the final-stage payload in …
Nimbus Manticore APT Abuses Fake Recruitment Portal to Deliver Custom Malware
June 2, 2026 A state-linked hacking group has been caught running a carefully crafted fake recruitment operation to push custom malware onto unsuspecting victims. The group, known as Nimbus Manticore …
Android 0-Day Vulnerability Exploited in Attacks to Gain Complete Device Control
June 2, 2026 A critical Android zero-day vulnerability is being actively exploited in targeted attacks, allowing threat actors to gain near-complete control over affected devices without any user interaction. The …
Critical StrongDM Vulnerability Allows Attackers to Steal and Reuse Authentication
June 2, 2026 A critical authentication flaw in StrongDM’s desktop application has been identified that allows attackers to hijack user sessions by reusing locally stored authentication material, potentially exposing sensitive …
Hackers Use Meta’s AI Bot to Reset Passwords and Hijack Instagram Accounts
June 2, 2026 A critical logic flaw in Meta’s AI-powered Instagram support chatbot allowed attackers to bypass two-factor authentication entirely, not by cracking codes, but by simply asking the bot …
