June 26, 2026 Water utilities across the United States and Europe are under growing pressure as hackers continue to find easy ways in. Nation-state actors and affiliated groups have been …
New GIFTEDCROOK Chain Abuses WinRAR ADS and Reflective Loading to Steal Browser Data
June 26, 2026 A newly documented attack chain tied to threat actor group UAC-0226 is putting Windows users at serious risk. The campaign uses booby-trapped WinRAR archives, hidden file streams, …
Hackers Leveraged Shopify Oder-Tracking App Shop to Push Fake Invoices
June 26, 2026 Hackers are no longer waiting in your inbox. A newly identified scam technique places fake invoices directly inside shopping app order histories, making them feel more credible …
Critical python.org Vulnerability Allowed Attackers to Forge Admin-Level API Requests
A critical authentication bypass vulnerability in the python.org release management API could have allowed attackers to impersonate administrators, potentially redirecting millions of users to malicious download URLs. The flaw, responsibly …
KuinaExtractor Uses Telegram Exfiltration, UAC Bypass, and Sandbox Detection for Stealth
A newly uncovered infostealer called KuinaExtractor has been quietly evolving for over six months, posing a serious and growing threat to users across multiple platforms. Written in the Rust programming …
CL-STA-1062 Hackers Use TinyRCT Backdoor to Target Southeast Asian Governments
June 26, 2026 A Chinese-speaking threat group known as CL-STA-1062 has been running a quiet but aggressive campaign against government agencies and critical energy infrastructure across Southeast Asia. The attackers, …
Miasma Malware Uses binding.gyp and Bun to Execute Hidden Payloads in npm Packages
June 26, 2026 Supply chain attackers are getting more creative, and the latest threat is proof of that. A malware campaign known as Miasma has been caught hiding inside widely …
CISA Warns of Cisco Unified CM Vulnerability Exploited in Attacks
June 26, 2026 CISA has added a critical server-side request forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager (Unified CM) to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies …
Microsoft Extends Windows 10 Security Updates for Users Up to October 2027
June 26, 2026 Microsoft has quietly expanded its Windows 10 Extended Security Updates (ESU) program, allowing consumers to receive critical security patches through October 12, 2027, an additional year beyond …
OpenAI Reportedly Delays ChatGPT 5.6 Release Following Trump Administration Request
June 26, 2026 OpenAI has agreed to stagger the public release of its latest AI model, GPT-5.6, after the Trump administration formally requested the company limit initial access to a …
