CISA Urges Hardening Fortinet Devices Following FortiBleed Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 CISA has issued an urgent advisory warning organizations to secure their Fortinet devices following reports of a large-scale credential exposure campaign known as “FortiBleed.” The alert comes after threat actors were found exploiting compromised credentials linked to …

China-Linked Showboat Malware Uses Linux Persistence to Target Telecom Companies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 A sophisticated China-linked malware framework has been quietly targeting telecom companies across the Middle East for nearly four years. Showboat is a Linux-based tool that stayed completely hidden from antivirus systems until April 2026, raising serious concerns …

CISA Warns of Splunk Enterprise Critical Function Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 CISA has issued a high-priority alert warning organizations about a critical vulnerability in Splunk Enterprise that is actively being exploited in the wild. The flaw, tracked as CVE-2026-20253, has been added to CISA’s Known Exploited Vulnerabilities (KEV) …

Node.js Fixes 12 Vulnerabilities, Including 2 High-Severity Authentication Bypasses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 Node.js has released a new round of security updates addressing 12 vulnerabilities across its supported release lines, including two high-severity flaws that could lead to authentication bypass and denial-of-service (DoS) attacks. The updates impact Node.js versions 22.x, …

Hackers Use Weaponized Windows Shortcuts to Spread Crypto Clipper Across USB Drives

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 A newly discovered cryptocurrency clipper malware has been quietly stealing digital assets from victims since February 2026, spreading through a trick that most users would never suspect: weaponized Windows shortcut files on USB drives. The malware is …

AI-Powered Public Surveillance and Biometric Data Collection Expand Government Monitoring

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 19, 2026 Governments are expanding their digital reach in ways unimaginable just a decade ago. A growing wave of AI-powered surveillance, biometric data collection, and commercial spyware is reshaping how states monitor citizens and visitors. The scale of this …

Authorities Dismantle SocGholish Malware Network — 106 Servers and 101 Domains Seized

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 Authorities have dismantled the criminal infrastructure behind SocGholish, one of the most persistent malware frameworks active since 2017, seizing 106 servers and 101 domains while remediating nearly 15,000 infected websites worldwide. The coordinated takedown was executed as …

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded …

New iPhone BootROM Vulnerability Exposes Apple SoCs to Full Chain-of-Trust Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 A novel BootROM vulnerability, dubbed usbliter8, affects Apple devices powered by A12, S4/S5, and A13 SoCs. The exploit chains a hardware-level bug in the Synopsys DWC2 USB controller with a firmware configuration flaw, enabling full application processor …

Hackers Breached Klue Integration to Steal Salesforce CRM Data via OAuth Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 18, 2026 Threat actors exploited a trusted third-party SaaS integration to silently harvest enterprise CRM data, marking the latest chapter in an escalating wave of OAuth-abuse attacks targeting Salesforce ecosystems. Researchers at ReliaQuest observed attackers leveraging a compromised Klue …