SecurityTicks

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign 2026-06-26 at 19:21 By A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia. The activity, particularly aimed at state-owned enterprises in the […]

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign Read More »

US senators push to end CFTC ‘assault’ on state oversight of prediction markets

US senators push to end CFTC ‘assault’ on state oversight of prediction markets 2026-06-26 at 19:10 By Cointelegraph by Turner Wright A group of 17 Democratic senators went after the CFTC’s funding for lawsuits over prediction markets, calling it an “assault” on state authorities. This article is an excerpt from Cointelegraph.com News View Original Source

US senators push to end CFTC ‘assault’ on state oversight of prediction markets Read More »

Bitcoin makes first sub-$60K close since Q3 2024 as tech stocks enter ‘deep bear market’

Bitcoin makes first sub-$60K close since Q3 2024 as tech stocks enter ‘deep bear market’ 2026-06-26 at 18:55 By Cointelegraph by William Suberg Bitcoin risked turning $60,000 into resistance as BTC price weakness persisted following another tech-driven sell-off in Asian stock markets. This article is an excerpt from Cointelegraph.com News View Original Source

Bitcoin makes first sub-$60K close since Q3 2024 as tech stocks enter ‘deep bear market’ Read More »

Security Leaders Discuss Texas Hunting, Fishing License Data Breach

Security Leaders Discuss Texas Hunting, Fishing License Data Breach 2026-06-26 at 18:30 By The Texas Parks and Wildlife Department reported that the personal information of more than three million Texas hunting and fishing license customers may have been affected by a recent data breech. This article is an excerpt from Subscribe to Security Magazine’s RSS […]

Security Leaders Discuss Texas Hunting, Fishing License Data Breach Read More »

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories 2026-06-26 at 18:23 By Eduard Kovacs AWS has patched the vulnerability and published its own advisory to inform customers about the potential impact.  The post Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories appeared first on SecurityWeek. This article is an excerpt from […]

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories Read More »

More Klue Breach Victims Identified as Hackers Get Hacked

More Klue Breach Victims Identified as Hackers Get Hacked 2026-06-26 at 18:01 By Ionut Arghire Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact. The post More Klue Breach Victims Identified as Hackers Get Hacked appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

More Klue Breach Victims Identified as Hackers Get Hacked Read More »

In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs

In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs 2026-06-26 at 17:30 By SecurityWeek News Other noteworthy stories that might have slipped under the radar: Russia used Cellebrite to hack activist’s phone, Five Eyes issue urgent AI threat warning, macOS Gaslight backdoor, Scattered Spider guilty pleas. The post In Other News: Chinese Mythos-Like […]

In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs Read More »

🎙️SECURITY.COM The Podcast: The Parasite in the Machine: Unmasking the Speagle Infostealer

🎙️SECURITY.COM The Podcast: The Parasite in the Machine: Unmasking the Speagle Infostealer 2026-06-26 at 17:30 By Enterprise Security Group Innocuous error reports, hypersonic targets, and a mystery with no fingerprints This article is an excerpt from SECURITY.COM View Original Source

🎙️SECURITY.COM The Podcast: The Parasite in the Machine: Unmasking the Speagle Infostealer Read More »

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries 2026-06-26 at 16:57 By A flaw in the Linux kernel’s traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed “pedit COW,” is an out-of-bounds write in the packet-editing action (act_pedit) that corrupts shared page-cache memory. A public, working […]

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries Read More »

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs 2026-06-26 at 16:53 By A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer’s cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and Amazon Q does the rest. Amazon […]

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs Read More »

Nebulock Raises $25 Million for AI-Native Contextual Security

Nebulock Raises $25 Million for AI-Native Contextual Security 2026-06-26 at 15:37 By Ionut Arghire The cybersecurity startup provides threat hunting, proactive detection, and behavioral security analytics. The post Nebulock Raises $25 Million for AI-Native Contextual Security appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Nebulock Raises $25 Million for AI-Native Contextual Security Read More »

CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue 2026-06-26 at 15:31 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its […]

CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue Read More »

Proof’s x401 establishes an open protocol for AI agent identity and authorization

Proof’s x401 establishes an open protocol for AI agent identity and authorization 2026-06-26 at 15:08 By Industry News Proof has launched x401, an open, issuer-neutral protocol that lets any website or API ask for and verify the identity behind agents. With x401, a service can ask for the proof it requires: verified identity, age, membership, […]

Proof’s x401 establishes an open protocol for AI agent identity and authorization Read More »

New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets

New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets 2026-06-26 at 14:51 By DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration for this variant. Tracked as CVE-2026-43503 (CVSS 8.8), it lets a local […]

New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets Read More »

Critical open-source projects get a new security framework

Critical open-source projects get a new security framework 2026-06-26 at 14:41 By Anamarija Pogorelec Open source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation. The Linux Foundation has launched Akrites, an industry initiative that brings together technology companies, financial institutions, security vendors, […]

Critical open-source projects get a new security framework Read More »

Guardian Agents: The Next Layer of Identity Governance

Guardian Agents: The Next Layer of Identity Governance 2026-06-26 at 14:30 By AI agents are moving through enterprise environments, inheriting permissions, traversing systems, and executing decisions at machine speed with minimal oversight. The identity infrastructure built to govern human access wasn’t designed for autonomous actors, and the gap between what enterprises are deploying and what […]

Guardian Agents: The Next Layer of Identity Governance Read More »

Linux Foundation Unveils New Open Source Security Project Akrites

Linux Foundation Unveils New Open Source Security Project Akrites 2026-06-26 at 14:28 By Ionut Arghire It will provide the tools and channels to report, patch, and disclose open source software vulnerabilities. The post Linux Foundation Unveils New Open Source Security Project Akrites appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Linux Foundation Unveils New Open Source Security Project Akrites Read More »

Synology issues critical fix for MailPlus Server vulnerabilities

Synology issues critical fix for MailPlus Server vulnerabilities 2026-06-26 at 13:57 By Zeljka Zorz Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update fixes three flaws: CVE-2026-13136, stemming from faulty authorization checks, may allow remote attackers to read or […]

Synology issues critical fix for MailPlus Server vulnerabilities Read More »

Google Details Turla’s New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

Google Details Turla’s New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks 2026-06-26 at 13:42 By The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizations in Ukraine, and entities that have an interest in Italian foreign policy. […]

Google Details Turla’s New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks Read More »

Scroll to Top