June 3, 2026 A threat actor used AI-assisted tools to automate Active Directory discovery and test endpoint detection and response (EDR) evasion techniques, highlighting the rise of AI-supported post-exploitation frameworks. …
Critical Apache ActiveMQ Vulnerability Allows Malicious Security Header Injections
June 3, 2026 A critical vulnerability in Apache ActiveMQ has been disclosed, allowing attackers to inject malicious HTTP security headers through improperly handled message properties, potentially leading to cross-site scripting …
Hackers Use YouTube and SEO Poisoning to Spread WeedHack Minecraft Malware
June 3, 2026 Hackers are hiding dangerous malware inside what look like popular Minecraft mods and game clients, using YouTube videos and search engine tricks to pull unsuspecting players into …
Microsoft 365 Android Apps Account Takeover Vulnerability Impacted Billions of Android Users
June 3, 2026 A single forgotten development flag left active in production code silently handed Microsoft account tokens to any app on an Android device, exposing billions of users across …
Windows Search URI Handler Flaw Leaks NTLMv2 Hashes to Attacker-Controlled Servers
June 3, 2026 A newly disclosed flaw in the Windows search URI handler can silently leak NTLMv2 hashes to attacker-controlled servers with nothing more than a single link click. This behavior is …
HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora
June 3, 2026 A newly disclosed remote denial-of-service exploit dubbed “HTTP/2 Bomb” targets the default HTTP/2 configurations of the world’s most widely deployed web servers, nginx, Apache httpd, Microsoft IIS, …
1-Click GitHub Token Vulnerability Lets Attackers Steal Users’ OAuth Tokens
June 3, 2026 A critical security vulnerability in Visual Studio Code’s webview implementation allows attackers to steal GitHub OAuth tokens, including read/write access to private repositories, simply by tricking a …
WordPress Malware Abuses Steam Community Profiles for C2 Operations
June 2, 2026 A newly discovered malware campaign targeting WordPress websites has raised serious concerns across the web security community. Attackers behind this campaign are using an unexpected method to …
Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign
June 2, 2026 A single threat actor has been running a fake political persona on Telegram for five years, quietly building an audience of over 17,000 subscribers while using stolen …
Attackers Abuse AWS, Google Cloud, Cloudflare, and Microsoft Services to Hide Malicious Traffic
June 2, 2026 Attackers Hide Malicious Traffic in Cloud Cybercriminals are increasingly weaponizing trusted cloud infrastructure, including Amazon Web Services, Google Cloud, Microsoft Azure, Cloudflare, and GitHub, to camouflage malicious …
