June 2, 2026 A critical logic flaw in Meta’s AI-powered Instagram support chatbot allowed attackers to bypass two-factor authentication entirely, not by cracking codes, but by simply asking the bot …
IBM WebSphere Server Vulnerable to Remote Code Execution Attack Via Crafted Request
June 1, 2026 IBM has disclosed a critical security vulnerability in its WebSphere Application Server ecosystem that could allow attackers to execute arbitrary code through specially crafted HTTP requests. The …
Critical Magento Cache Plugin Vulnerability Enables Remote Code Execution Attacks
June 1, 2026 A critical security vulnerability has been discovered in a widely used Magento caching plugin that allows attackers to remotely execute malicious code with no login, configuration changes, …
Iranian Hackers Abuse AppDomainManager Hijacking to Evade EDR Detection
June 1, 2026 Iranian hackers have taken their cyberespionage playbook to a new level, deploying a sophisticated .NET hijacking technique to slip past endpoint defenses and target organizations across the …
SideCopy Hackers Deploy Persistent XenoRAT Malware to Target Afghanistan Finance Ministry
June 1, 2026 A Pakistan-linked threat group known as SideCopy has launched a focused cyberattack against Afghanistan’s Ministry of Finance, deploying a persistent remote access tool called XenoRAT. The campaign, …
Critical Plesk Vulnerability Let Users Execute Arbitrary Commands on the Server
June 1, 2026 A newly disclosed critical vulnerability in Plesk, tracked as CVE-2026-44962, is raising serious security concerns after researchers confirmed it can allow authenticated users to execute arbitrary operating …
Iran-Linked Hackers Destroy IT, Backups, and Recovery Systems in Cyberattack targeting Middle East
June 1, 2026 Iran-linked hackers have launched a sweeping campaign of digital destruction across the United States and the Middle East, wiping IT systems, erasing backups, and dismantling recovery infrastructure …
New DriveSurge Threat Actor Uses ClickFix and Fake Updates to Infect Website Visitors
June 1, 2026 A newly identified threat actor named DriveSurge has been quietly compromising thousands of legitimate websites to push malware onto unsuspecting visitors. Using a combination of fake browser …
Microsoft Investigates MFA Setup Failure and MySigns-In Portal Outage
Microsoft is currently investigating a service disruption affecting users attempting to set up multi-factor authentication (MFA) or access the self-service sign-in portal at mysignins.microsoft.com. The issue was officially acknowledged by …
Microsoft Tightens Entra ID Password Resets With New Authentication Change
June 1, 2026 Microsoft has announced a significant security update to its Entra ID Self-Service Password Reset (SSPR) feature, introducing stricter authentication requirements designed to reduce identity-based attacks. The update …
