WordPress Malware Abuses Steam Community Profiles for C2 Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A newly discovered malware campaign targeting WordPress websites has raised serious concerns across the web security community. Attackers behind this campaign are using an unexpected method to communicate with infected sites, hiding command instructions inside Steam Community …

Threat Actor Uses Stolen Gemini API Keys to Automate Telegram Influence Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A single threat actor has been running a fake political persona on Telegram for five years, quietly building an audience of over 17,000 subscribers while using stolen AI credentials to power the entire operation. What looks like …

Attackers Abuse AWS, Google Cloud, Cloudflare, and Microsoft Services to Hide Malicious Traffic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 Attackers Hide Malicious Traffic in Cloud Cybercriminals are increasingly weaponizing trusted cloud infrastructure, including Amazon Web Services, Google Cloud, Microsoft Azure, Cloudflare, and GitHub, to camouflage malicious traffic, evade detection, and sustain long-lived Command and Control (C2) …

Red Hat Confirms Supply Chain Compromise of @redhat-cloud-services npm Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 Red Hat has officially confirmed a supply chain compromise affecting multiple packages published under the @redhat-cloud-services npm namespace, disclosed publicly on June 1, 2026. A compromised GitHub account was used to inject malicious code into frontend libraries …

Russia Says Foreign Spyware Found on High-Ranking Officials’ Mobile Phones

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 Russia’s Federal Security Service (FSB) has claimed it disrupted a large-scale cyber-espionage operation involving the deployment of advanced spyware on mobile devices used by high-ranking government officials. The agency stated that the campaign was orchestrated by unidentified …

Halo Security Honored with 2026 MSP Today Product of the Year Award

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 Miami Beach, FL, USA, June 2nd, 2026, CyberNewswire Attack Surface Management Platform Recognized for Exceptional Innovation and Successful Deployment Through The Channel Halo Security today announced that its attack surface management solution has been named a 2026 …

CISA Warns of Two-Year-Old Oracle WebLogic Server Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 CISA has issued a fresh warning highlighting active exploitation of a critical Oracle WebLogic Server vulnerability, tracked as CVE-2024-21182, adding it to its Known Exploited Vulnerabilities (KEV) catalog on June 1, 2026. The alert underscores the increasing …

Critical KMW CCTV Vulnerability Let Attackers Gain Unauthorized Access to Camera Feeds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A critical security flaw in KMW CCTV security cameras could allow attackers to gain full, unauthorized access to live camera feeds and device settings. The vulnerability, tracked as CVE-2026-5386, has been assigned a high CVSS v3 score …

CISA Flags Palo Alto Networks PAN-OS Vulnerability as Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Palo Alto Networks PAN-OS vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively leveraged in real-world attacks. The vulnerability …

Microsoft MSRC Allegedly Dismissed Dependency Confusion Vulnerability, Claims Researcher

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 2, 2026 A dependency confusion vulnerability affecting Microsoft’s Azure Portal after the Microsoft Security Response Center (MSRC) closed the case, claiming the confirmed remote code execution evidence did not constitute an exploitable security issue. The vulnerability was uncovered by …