Cybersecurity and other IT news aggregator

LATEST FEEDS

  • What the Numbers Say About FIFA 2026 Cyber Risk

    What the Numbers Say About FIFA 2026 Cyber Risk 2026-06-30 at 17:48 By The FIFA World Cup 2026 opened on June 11. By that date, according to Check Point Research, the fraud infrastructure targeting it had already been built, staged, and partially deployed. Threat actor activity was pre-planned, months out, across three sectors and at…


  • GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks

    GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks 2026-06-30 at 17:26 By The safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has been public for decades. New research from Adversa AI, which is named the…


  • An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails

    An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails 2026-06-30 at 17:04 By Hajime Takai Key points LevelBlue has identified two distinct attack vectors associated with ValleyRAT: campaigns leveraging fake installers and campaigns initiated through malicious emails. The malicious email-based attack campaign analyzed in this report appears to target both Chinese and…


  • Aikido Security acquires Root to expand backported fixes for open source vulnerabilities

    Aikido Security acquires Root to expand backported fixes for open source vulnerabilities 2026-06-30 at 17:00 By Industry News Aikido Security has acquired Root, uniting behind a shared mission to make it easy for developers and agents to build with secure open source and tackle the growing threat of supply chain attacks. Open source is the…


  • Why Traditional Incident Response Retainers Leave CISOs Exposed (and Money on the Table)

    Why Traditional Incident Response Retainers Leave CISOs Exposed (and Money on the Table) 2026-06-30 at 17:00 By Carly Battaile I have lost count of the post-incident reviews where the most painful conversation was not about the breach itself. It was about the retainer. This article is an excerpt from LevelBlue Blog View Original Source


  • MetaMask launches stablecoin yield account with card spending

    MetaMask launches stablecoin yield account with card spending 2026-06-30 at 17:00 By Cointelegraph by Helen Partz MetaMask launches Money Account it says offers up to 4% variable APY on mUSD stablecoin balances and card spending, with DeFi-powered yield via vaults, excluding the UK and EU. This article is an excerpt from Cointelegraph.com News View Original…


  • Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)

    Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817) 2026-06-30 at 16:58 By Zeljka Zorz Exploitation attempts targeting a critical vulnerability (CVE-2026-46817) in Oracle Payments, the payment-processing module within Oracle’s E-Business Suite (EBS), have been spotted over the weekend, threat intelligence company Defused warned on Monday. The detected exploitation attempts (Source: Defused) “On 27 June 2026…


  • Cequence Platform 9.0 uses AI to simplify API security and compliance

    Cequence Platform 9.0 uses AI to simplify API security and compliance 2026-06-30 at 16:58 By Industry News Cequence Security has announced general availability of Cequence Platform 9.0, an AI-native release that changes how users interact with API security tools. Platform 9.0 ships with a built-in AI Assistant, an open Model Context Protocol (MCP) server that…


  • BlueHammer Vulnerability Exploited in Ransomware Attacks

    BlueHammer Vulnerability Exploited in Ransomware Attacks 2026-06-30 at 16:56 By Eduard Kovacs The Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released. The post BlueHammer Vulnerability Exploited in Ransomware Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • 282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study

    282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study 2026-06-30 at 16:49 By Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic. In many cases, the path in was visible just by watching…


  • Jamf enables AI Governance and shadow AI detection on Mac

    Jamf enables AI Governance and shadow AI detection on Mac 2026-06-30 at 16:48 By Industry News Jamf has announced general availability of AI Governance, a new capability within Jamf for Mac that enables IT and security teams to discover actively-used AI tools, enforce policy controls, and generate audit-ready reporting. Many organizations struggle to confidently audit…


  • OKX launches AI marketplace for autonomous agent economy

    OKX launches AI marketplace for autonomous agent economy 2026-06-30 at 16:39 By Cointelegraph by Zoltan Vardai OKX launched a beta marketplace for the agentic economy, enabling AI agents to autonomously find work and collaborate with other agents. This article is an excerpt from Cointelegraph.com News View Original Source


  • Digi International’s DANI automates network diagnostics and device management

    Digi International’s DANI automates network diagnostics and device management 2026-06-30 at 16:34 By Industry News Digi International has announced the launch of DANI, the Digi Artificial Network Intelligence agent, a purpose-built AI network operations agent natively embedded in a networking device management platform, Digi Remote Manager (DRM). Embedded directly within DRM as a value-added service,…


  • Security Organizations Reveal Threat Management Fails to Match Visibility

    Security Organizations Reveal Threat Management Fails to Match Visibility 2026-06-30 at 16:31 By A recent report by Filigran analyzes the gap between threat visibility and threat management.  This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • Strategy’s new plan divides industry observers even as MSTR, STRC climb

    Strategy’s new plan divides industry observers even as MSTR, STRC climb 2026-06-30 at 16:14 By Cointelegraph by Helen Partz Strategy’s new Bitcoin capital framework draws Wall Street backing from Benchmark with a $570 per share target even as traders question long-term demand risk. This article is an excerpt from Cointelegraph.com News View Original Source


  • Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks

    Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks 2026-06-30 at 16:00 By Kevin Townsend Decades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, potentially turning malicious repositories into supply chain attack vectors. The post Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks appeared first…


  • Aflac Japan Data Breach Impacts 4.38 Million

    Aflac Japan Data Breach Impacts 4.38 Million 2026-06-30 at 15:52 By Ionut Arghire Hackers accessed the insurance giant’s policyholder portal multiple times between June 15 and June 25. The post Aflac Japan Data Breach Impacts 4.38 Million appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks

    AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks 2026-06-30 at 15:39 By Two researchers have found six security flaws in AirDrop and Quick Share, the wireless features that beam files between nearby devices with no cables or shared network. An attacker within wireless range, with just a laptop and no…


  • StarkWare unveils Starknet quantum roadmap, says industry has no excuse

    StarkWare unveils Starknet quantum roadmap, says industry has no excuse 2026-06-30 at 15:30 By Cointelegraph by Martin Young “The crypto industry shouldn’t need wake-up calls from the White House or anyone else,” said StarkWare CEO Eli Ben-Sasson. This article is an excerpt from Cointelegraph.com News View Original Source


  • Spiko links EU regulated T-bill funds to Coinbase stablecoin rails

    Spiko links EU regulated T-bill funds to Coinbase stablecoin rails 2026-06-30 at 15:21 By Cointelegraph by Ezra Reguerra Spiko integrated Coinbase Payments into two EU regulated UCITS Treasury funds, enabling USDC and EURC subscriptions and redemption payments through Base. This article is an excerpt from Cointelegraph.com News View Original Source


  • Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat

    Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat 2026-06-30 at 15:00 By Kevin Townsend Chris Thompson’s journey took him from hacking game controls as a teenager to founding IBM’s X-Force Red team. The post Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat appeared first on…


  • Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History

    Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History 2026-06-30 at 14:48 By Associated Press The ruling was made in the case of a bank robber whose identity was discovered through a geofence warrant. The post Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History appeared first on SecurityWeek.…


  • Exploitation of Recent Oracle E-Business Suite Vulnerability Begins

    Exploitation of Recent Oracle E-Business Suite Vulnerability Begins 2026-06-30 at 14:29 By Ionut Arghire The critical-severity defect allows unauthenticated attackers to take over the E-Business Suite’s Payments product. The post Exploitation of Recent Oracle E-Business Suite Vulnerability Begins appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

    Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer 2026-06-30 at 14:18 By An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer. The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0), a critical authentication bypass…


  • Solana Company to back Kazakhstan’s $6B crypto megacity ambition

    Solana Company to back Kazakhstan’s $6B crypto megacity ambition 2026-06-30 at 14:00 By Cointelegraph by Felix Ng Nasdaq-listed Solana Company has signed a memorandum of understanding with Kazakhstan’s Alatau City, which seeks to become a key crypto hub in Central Asia. This article is an excerpt from Cointelegraph.com News View Original Source


  • SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)

    SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) 2026-06-30 at 13:25 By Zeljka Zorz Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials associated with cloud…


  • The BYOVD Epidemic: How Attackers Are Weaponizing Trusted Windows Drivers to Kill Security

    The BYOVD Epidemic: How Attackers Are Weaponizing Trusted Windows Drivers to Kill Security 2026-06-30 at 13:00 By Threat Hunter Team Bring Your Own Vulnerable Driver (BYOVD) has gone from a niche tactic to a standard part of the ransomware playbook and Windows’ own kernel hardening does little to stop it. This article is an excerpt…


  • The AI Token Costs That Can Break Cybersecurity

    The AI Token Costs That Can Break Cybersecurity 2026-06-30 at 13:00 By Danelle Au As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. The post The AI Token Costs That Can Break Cybersecurity appeared first on SecurityWeek. This article is an…


  • Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App

    Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App 2026-06-30 at 12:58 By rohansinhacyblecom Executive Summary Cyble Research and Intelligence Labs identified an emerging Android malware family tracked as Glitch SPY, distributed through a fraudulent Polish apartment and house rental platform designed to lure users into downloading an Android APK. Based…


  • Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth

    Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth 2026-06-30 at 12:45 By A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI.…


  • Nissan Employee Data Breached in Oracle PeopleSoft Hack

    Nissan Employee Data Breached in Oracle PeopleSoft Hack 2026-06-30 at 12:25 By Eduard Kovacs Only a handful of the 100 organizations targeted in the PeopleSoft campaign have been confirmed. The post Nissan Employee Data Breached in Oracle PeopleSoft Hack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Michigan judge blocks Kalshi from allowing residents to place sports bets

    Michigan judge blocks Kalshi from allowing residents to place sports bets 2026-06-30 at 12:08 By Cointelegraph by Zoltan Vardai A Michigan Judge has temporarily blocked Kalshi from offering sports betting contracts to residents, escalating the state-federal fight over prediction markets and gambling laws. This article is an excerpt from Cointelegraph.com News View Original Source


  • Critical SimpleHelp Vulnerability Exploited for Malware Delivery

    Critical SimpleHelp Vulnerability Exploited for Malware Delivery 2026-06-30 at 11:43 By Ionut Arghire The threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling. The post Critical SimpleHelp Vulnerability Exploited for Malware Delivery appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials

    New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials 2026-06-30 at 11:37 By Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants into copying a user’s credentials…


  • Celsius-linked Bitcoin miner Ionic Digital seeks Nasdaq direct listing amid AI pivot

    Celsius-linked Bitcoin miner Ionic Digital seeks Nasdaq direct listing amid AI pivot 2026-06-30 at 11:16 By Cointelegraph by Ezra Reguerra The Celsius-linked Bitcoin miner is seeking a Nasdaq direct listing as it repurposes mining infrastructure for AI and high-performance computing workloads. This article is an excerpt from Cointelegraph.com News View Original Source


  • Kali Linux 2026.2 trims VM boot times, refreshes its desktops

    Kali Linux 2026.2 trims VM boot times, refreshes its desktops 2026-06-30 at 11:16 By Sinisa Markovic Penetration testers who run Kali Linux inside virtual machines boot their systems faster after the 2026.2 release. The change comes from a decision about graphics firmware, the code that drives NVIDIA, AMD, and Intel GPUs. That firmware has grown…


  • Ransomware Is About Leverage: Return on Risk Takes It Away

    Ransomware Is About Leverage: Return on Risk Takes It Away 2026-06-30 at 11:00 By Return on Risk offers an alternative way to think about resilience.  This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • OpenClaw for iOS: The viral open-source AI agent comes to iPhone and iPad

    OpenClaw for iOS: The viral open-source AI agent comes to iPhone and iPad 2026-06-30 at 10:45 By Anamarija Pogorelec OpenClaw, a self-hosted personal AI assistant that connects to existing chat apps, is now available on iPhone, iPad and Apple Watch. The release brings chat, real-time voice conversations, approvals, device capabilities, and private automations to iOS.…


  • Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs

    Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs 2026-06-30 at 10:15 By Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security.…


  • Quantifind Raises $200 Million for AI-Native Risk Intelligence

    Quantifind Raises $200 Million for AI-Native Risk Intelligence 2026-06-30 at 09:40 By Ionut Arghire Quantifind will accelerate international expansion and extend its platform’s localized risk intelligence capabilities. The post Quantifind Raises $200 Million for AI-Native Risk Intelligence appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Australia’s crypto travel rule is coming into effect: Here’s what’s changing

    Australia’s crypto travel rule is coming into effect: Here’s what’s changing 2026-06-30 at 09:29 By Cointelegraph by Jesse Coghlan From July, crypto exchanges operating in Australia will prompt for additional information on all outgoing and incoming transfers. This article is an excerpt from Cointelegraph.com News View Original Source


  • AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin

    AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin 2026-06-30 at 09:15 By Mirko Zorz Phones and laptops ship with a feature that sends files to nearby devices over the air, with no cables, accounts, or prior pairing. Apple calls its version AirDrop. Google and Samsung call theirs Quick Share.…


  • Product showcase: Scam calls, phishing, and data breaches? Meet AVG Mobile Security

    Product showcase: Scam calls, phishing, and data breaches? Meet AVG Mobile Security 2026-06-30 at 08:45 By Anamarija Pogorelec AVG Mobile Security for iOS helps protect users against online threats with features including Web Guard, VPN, Scam Guardian Pro, Hack Alerts, and Photo Vault. It also identifies suspicious calls and scam text messages and helps keep…


  • Vulnerability reports are arriving faster than GitHub can review them

    Vulnerability reports are arriving faster than GitHub can review them 2026-06-30 at 08:25 By Anamarija Pogorelec Across the open source world, people are reporting software flaws in record numbers, and the systems built to verify those reports are straining under the weight. The GitHub Advisory Database, which feeds automated security alerts to millions of projects,…


  • New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking

    New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking 2026-06-30 at 08:04 By Eduard Kovacs CISA has published an advisory to inform organizations about three vulnerabilities found by a researcher in Daktronics controllers. The post New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking appeared first on SecurityWeek. This article is…


  • Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild

    Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild 2026-06-30 at 08:04 By A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Payments that…


  • Hottest cybersecurity open-source tools of the month: June 2026

    Hottest cybersecurity open-source tools of the month: June 2026 2026-06-30 at 08:00 By Anamarija Pogorelec Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory AI…


  • Ford rehires experienced engineers after AI misses the mark

    Ford rehires experienced engineers after AI misses the mark 2026-06-30 at 05:03 By Fox Business Ford has rehired experienced human engineers to help address the shortcomings of artificial intelligence (AI) tools meant to tackle quality issues in the automaker’s production processes. This article is an excerpt from Latest Technology News | New York Post View Original Source


  • Singapore’s Hyperliquid warning, Indonesia’s FinFluencer licence: Asia Express

    Singapore’s Hyperliquid warning, Indonesia’s FinFluencer licence: Asia Express 2026-06-30 at 04:23 By Cointelegraph by Andrew Fenton Hyperliquid follows Bybit onto Singapore’s “naughty” list, Indonesia’s new scheme to certify social media influencers promoting crypto: Asia Express. This article is an excerpt from Cointelegraph.com News View Original Source


  • UK sets final crypto rules as firms face 2027 FCA authorization deadline

    UK sets final crypto rules as firms face 2027 FCA authorization deadline 2026-06-30 at 02:01 By Cointelegraph by Zoltan Vardai The UK’s financial regulator has published its crypto regulatory framework, setting the authorization deadline for cryptocurrency firms for February 2027. This article is an excerpt from Cointelegraph.com News View Original Source


Browse older archives

Scroll to Top