Microsoft has disclosed a critical remote code execution vulnerability in its Office ecosystem that can be exploited through a malicious Excel file. The vulnerability, tracked as CVE-2025-60727, affects multiple versions …
Critical Gemini CLI Vulnerability Lets Attackers Execute Arbitrary Code
June 29, 2026 A critical security vulnerability in Google’s Gemini CLI has been disclosed, allowing attackers to execute arbitrary code in certain CI/CD environments, particularly GitHub Actions workflows. The issue, …
Russia-Linked Turla Uses Compromised Infrastructure to Deploy STOCKSTAY in Ukraine Operations
June 29, 2026 Russia-linked threat group Turla has been quietly expanding its espionage arsenal with a new backdoor called STOCKSTAY, actively targeting government and military organizations in Ukraine since at …
ClawHub Skills Expose AI Agents to Remote Control Backdoors and Data Theft Attacks
June 29, 2026 AI-powered agents are no longer just answering questions. They now take actions, manage files, and run code on behalf of users. That shift has opened a dangerous …
LLM-Generated Mythic Agents Enable Disposable Red-Team Tooling From Prompt to Deployment
June 29, 2026 Red teamers and offensive security researchers have entered a new era where AI can write functional attack tools from a single sentence. A concept known as “disposable …
Millenium RAT Rewritten in C++ Infects 62,000+ Devices Across 160 Countries
June 29, 2026 A remote access trojan known as Millenium RAT has been quietly spreading across the globe, and the numbers are hard to ignore. Over 62,000 devices have been …
UNC1151 Ghostwriter Hackers Target Belarusian Politician in Gmail Phishing Campaign
A well-known hacker group called UNC1151, also widely known as Ghostwriter, has been caught running a targeted phishing campaign against a prominent Belarusian pro-democracy politician. The group, which has long …
China’s New Zhipu AI Reportedly Matches Claude Mythos in Vulnerability Detection
June 29, 2026 Zhipu AI’s open-weight GLM-5.2 model is reportedly performing on par with Anthropic’s restricted Claude Mythos in specific cybersecurity and software vulnerability detection tasks, a development that is …
RedAmon AI Tool that Chains Reconnaissance, Exploitation, and Post-exploitation
June 29, 2026 A new open-source offensive security platform called RedAmon is redefining automated penetration testing by chaining reconnaissance, exploitation, post-exploitation, AI-driven triage, and automated code remediation all into a …
OpenAI Released GPT-5.6 Sol With Limited Access and Strong Cyberattack Protections
OpenAI has officially begun a limited preview of the GPT‑5.6 model series Sol, Terra, and Luna, positioning its flagship Sol as the company’s most capable and security-hardened AI model to …
