June 2, 2026 A newly identified spearphishing campaign has been quietly targeting government officials, researchers, and technology workers in the Czech Republic and Taiwan. Threat researchers traced the operation to …
PHANTOMPULSE RAT Uses Process Injection and UAC Bypass to Compromise Windows Systems
June 2, 2026 A newly analyzed remote access trojan called PHANTOMPULSE has drawn serious attention for its advanced approach to compromising Windows systems. The malware is the final-stage payload in …
Nimbus Manticore APT Abuses Fake Recruitment Portal to Deliver Custom Malware
June 2, 2026 A state-linked hacking group has been caught running a carefully crafted fake recruitment operation to push custom malware onto unsuspecting victims. The group, known as Nimbus Manticore …
Android 0-Day Vulnerability Exploited in Attacks to Gain Complete Device Control
June 2, 2026 A critical Android zero-day vulnerability is being actively exploited in targeted attacks, allowing threat actors to gain near-complete control over affected devices without any user interaction. The …
Critical StrongDM Vulnerability Allows Attackers to Steal and Reuse Authentication
June 2, 2026 A critical authentication flaw in StrongDM’s desktop application has been identified that allows attackers to hijack user sessions by reusing locally stored authentication material, potentially exposing sensitive …
Hackers Use Meta’s AI Bot to Reset Passwords and Hijack Instagram Accounts
June 2, 2026 A critical logic flaw in Meta’s AI-powered Instagram support chatbot allowed attackers to bypass two-factor authentication entirely, not by cracking codes, but by simply asking the bot …
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after …
IBM WebSphere Server Vulnerable to Remote Code Execution Attack Via Crafted Request
June 1, 2026 IBM has disclosed a critical security vulnerability in its WebSphere Application Server ecosystem that could allow attackers to execute arbitrary code through specially crafted HTTP requests. The …
Critical Magento Cache Plugin Vulnerability Enables Remote Code Execution Attacks
June 1, 2026 A critical security vulnerability has been discovered in a widely used Magento caching plugin that allows attackers to remotely execute malicious code with no login, configuration changes, …
Iranian Hackers Abuse AppDomainManager Hijacking to Evade EDR Detection
June 1, 2026 Iranian hackers have taken their cyberespionage playbook to a new level, deploying a sophisticated .NET hijacking technique to slip past endpoint defenses and target organizations across the …

