Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 16:02 20/06/2026 UTC
Last updated: 08:03 20/06/2026 UTC
  • Incident H score 93 PushEngage hit by cyberattack Awesome Motive remediated a CDN supply-chain compromise by migrating its marketing site and rotating the stolen CDN API key after an UpdraftPlus server exploit, advancing the investigation while reducing continued poisoned-JavaScript exposure risk.
  • Vulnerability H score 89 Widget Factory Joomla Content Editor JCE actively exploited improper access control security flaw (CVE-2026-48907) CISA added Widget Factory Joomla Content Editor flaw CVE-2026-48907 to KEV based on active exploitation, accelerating patch urgency because the improper access control can enable unauthenticated PHP code execution.
  • Public Sector Action H score 89 CISA KEV remediation order for CVE-2026-48907 CISA ordered FCEB agencies to fix CVE-2026-48907 by June 19, tightening compliance deadlines for a maximum-severity, actively exploited Joomla access-control weakness.
  • Campaign H score 89 FortiBleed Fortinet credential-theft campaign CISA warned FortiBleed impacted 86,644 compromised FortiGate/VPN devices as of June 19, highlighting ongoing opportunistic credential abuse and prompting session termination, reset, and phishing-resistant MFA.
  • Public Sector Action H score 89 CISA warning on FortiBleed for FortiGate customers Researchers surfaced working Fortinet credentials on an exposed server tied to FortiBleed, materially increasing the likelihood of successful logins and follow-on compromises.
  • Data Leak H score 80 FortiBleed Fortinet/FortiGate VPN credential leak FortiBleed updates now include a verified worldwide set of 86,644 working VPN credentials, shifting the threat from suspected exposure to actionable account compromise risk.

Latest updates

Browse →

Prinz Eugen hands-on-keyboard ransomware activity

Malware Activity

Updated: 20.06.2026 18:23 · First: 20.06.2026 18:23 · 📰 1 src / 1 articles · H score: 4

The Prinz Eugen ransomware operation is actively using hands-on-keyboard tradecraft and legitimate RMM tools, which makes intrusions harder to spot and contain. Researchers say the operators likely start with stolen RDP credentials, then manually deploy servertool.exe and maintain access with RemotePC. The encryptor focuses on recently modified files, skips a ransom note, and pushes victims toward out-of-band extortion. The activity has already been tied to multiple victims, including a Standard Bank breach demand of 1 BTC.

Prinz Eugen hackers campaign expands across multiple victims

Campaign

Updated: 20.06.2026 18:23 · First: 20.06.2026 18:23 · 📰 1 src / 1 articles · H score: 4

The Prinz Eugen ransomware campaign is using stolen RDP credentials, RemotePC, and hands-on operator control to break into multiple victims. It matters because the operation combines manual intrusion tradecraft with data encryption and exfiltration, increasing extortion pressure and reducing detection. Researchers say the group has reached at least five victims, while the leak site currently lists three. In one Standard Bank breach, the attacker demanded 1 BTC and was refused.

Sapphire Sleet Mastra npm supply-chain campaign

Campaign

Updated: 20.06.2026 17:09 · First: 20.06.2026 17:09 · 📰 1 src / 1 articles · H score: 39

The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff, putting more than 140 npm packages and developer endpoints at risk of credential and crypto-wallet theft. Attackers compromised the npm maintainer account "ehindero" and used its publishing privileges to push malicious updates into the @mastra scope. Those updates injected easy-day-js, which ran a postinstall hook, contacted attacker-controlled C2 infrastructure, and downloaded a second-stage payload. The resulting stealer targeted Windows, Linux, and macOS systems and checked for 166 cryptocurrency wallet extensions.

Mastra @mastra/* npm packages hit by network compromise

Incident

Updated: 17.06.2026 10:38 · First: 17.06.2026 10:38 · 📰 2 src / 2 articles · H score: 42

Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the activity to Sapphire Sleet (BlueNoroff), saying the attackers hijacked the npm maintainer account "ehindero" and published malicious updates to more than 140 npm packages in the @mastra scope. The poisoned packages injected easy-day-js, which ran a postinstall hook, fetched a second-stage payload, and deployed a cross-platform stealer on Windows, Linux, and macOS. The activity put credentials, API keys, authentication tokens, and cryptocurrency wallets at risk across developer systems, CI runners, and build environments.

Gravity SMTP security patch release for CVE-2026-4020

Security Patch Release

Updated: 20.06.2026 12:56 · First: 20.06.2026 12:56 · 📰 1 src / 1 articles · H score: 16

Gravity SMTP released version 2.1.5 to fix CVE-2026-4020, closing a medium-severity information disclosure flaw in the WordPress plugin. The patch addresses a bug that let unauthenticated visitors pull API keys, secrets, and OAuth tokens from plugin data. The update is urgent because the plugin is installed on about 100,000 sites and exploit traffic is already active.

Klue hit by network compromise

Incident

Updated: 18.06.2026 17:19 · First: 18.06.2026 17:19 · 📰 2 src / 3 articles · H score: 39

Klue confirmed a June 12, 2026 security incident in which an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastructure and access data in connected Salesforce environments. The activity is now publicly claimed by Icarus, which said Klue.com was impacted and that partner Salesforce instances were exfiltrated. Reports from Huntress and ReliaQuest tie the theft to automated Python scripts and Salesforce API querying, with affected organizations including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. Klue says the incident was limited to third-party integrations and that there is no evidence customer content stored directly in the Klue platform was impacted.

Klue Battlecards app Salesforce customer data leak

Data Leak

Updated: 19.06.2026 12:03 · First: 19.06.2026 12:03 · 📰 2 src / 2 articles · H score: 41

A Klue-related Salesforce data leak on June 12 exposed customer records after an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastructure and access connected environments. Huntress and ReliaQuest tied the activity to stolen integration access, Python scripting, and bulk Salesforce REST API querying, and Icarus has now publicly claimed responsibility on its leak site. Additional affected organizations have disclosed impacts, while most say the exposure was limited to Salesforce instances rather than their core platforms or infrastructure.

Gravity SMTP actively exploited information disclosure flaw (CVE-2026-4020)

Vulnerability

Updated: 19.06.2026 23:25 · First: 19.06.2026 23:25 · 📰 2 src / 2 articles · H score: 16

An actively exploited unauthenticated information disclosure flaw in Gravity SMTP exposes API keys, secrets, OAuth tokens, and email-service credentials on sites using the plugin, with the affected footprint reaching 100,000 WordPress sites. The vulnerability is tracked as CVE-2026-4020, affects version 2.1.4 and older, and was fixed in 2.1.5. Wordfence says it has blocked more than 17 million attempts, including a spike on June 7.

Apple A12/A13 SecureROM USB DMA underflow with public usbliter8 exploit security flaw

Vulnerability

Updated: 19.06.2026 21:37 · First: 19.06.2026 21:37 · 📰 1 src / 1 articles · H score: 0

A public usbliter8 exploit now reaches arbitrary code execution in Apple's SecureROM, exposing an unpatchable USB DMA underflow flaw across A12, A13, S4, and S5 hardware. The attack needs physical possession, DFU mode, and a RP2350-based microcontroller board, but it completes in under two seconds before the signed boot chain loads. Because the vulnerable code is burned into silicon, no software update can remove the flaw. The result is a durable device-custody risk for environments that must protect high-value Apple hardware from direct access.

CERT/CC UEFI DBX mitigation for vendor-signed applications

Advisory/Mitigation

Updated: 19.06.2026 21:33 · First: 19.06.2026 21:33 · 📰 1 src / 1 articles · H score: 28

CERT/CC issued mitigation guidance to apply UEFI Forbidden Signature Database (DBX) updates, reducing Secure Boot bypass risk for affected vendor-signed UEFI applications. The advisory covers binaries from Acer, AMD, ASUS, ECS, Getac, GIGABYTE, Toshiba, and Uniwill. Administrators are being told to revoke trust in the affected binaries before they can execute during boot.

Texas Parks and Wildlife Department license system vendor hit by network compromise

Incident

Updated: 19.06.2026 19:12 · First: 19.06.2026 19:12 · 📰 1 src / 1 articles · H score: 59

The Texas Parks and Wildlife Department license system vendor suffered an intrusion that led to unauthorized access and exposed customer records for millions of license holders. The breach prompted a state investigation and raised follow-on risks of phishing and social engineering against affected people.

Texas Parks and Wildlife Department customer data exposed after Texas Parks and Wildlife Department breach

Data Leak

Updated: 19.06.2026 19:12 · First: 19.06.2026 19:12 · 📰 1 src / 1 articles · H score: 63

The Texas Parks and Wildlife Department disclosed a data breach at its license system vendor that exposed personal information for 3,087,721 Texas hunting and fishing license customers. The exposed dataset included driver’s license information, passport numbers, email addresses, phone numbers, and residential addresses, creating elevated risk of phishing and social engineering abuse. Officials said SSNs, dates of birth, and financial information were not impacted.

AutoGen Studio MCP WebSocket localhost trust bypass RCE flaw

Vulnerability

Updated: 19.06.2026 18:30 · First: 19.06.2026 18:30 · 📰 1 src / 1 articles · H score: 29

A remote code execution flaw in AutoGen Studio affects the MCP WebSocket surface in pre-release builds 0.4.3.dev1 and 0.4.3.dev2. The exploit chain uses a localhost trust bypass, missing authentication, and command execution from a request parameter. The hardening fix is in GitHub main at commit b047730, but no patched PyPI build has landed yet.

Operation Endgame international cybercrime disruption initiative

Public Sector Action

Updated: 19.06.2026 18:07 · First: 19.06.2026 18:07 · 📰 1 src / 1 articles · H score: 57

Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets and criminal infrastructure used for malware delivery. The operation has already removed 106 servers and cleaned 14,971 WordPress sites, reducing abuse paths used to spread follow-on payloads. Launched in 2024, the initiative keeps pressure on the infrastructure that supports large-scale cybercrime.

CISA warning on FortiBleed for FortiGate customers

Public Sector Action

Updated: 19.06.2026 17:00 · First: 19.06.2026 17:00 · 📰 1 src / 1 articles · H score: 89

CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached 86,644 compromised devices by June 19, 2026 and was targeting internet-accessible gateways and administrators. CISA directed operators to terminate active sessions, reset passwords, enforce strong password policies, and enable phishing-resistant MFA.

AWS Continuum launches AI-powered vulnerability management lifecycle platform

Security Tool/Service

Updated: 19.06.2026 14:00 · First: 19.06.2026 14:00 · 📰 1 src / 1 articles · H score: 14

AWS Continuum launched in gated preview as a new AI-powered vulnerability management platform for AWS environments, expanding security teams’ ability to manage code flaws from discovery through remediation. The platform combines prioritization, validation, and remediation with access to structured and unstructured organization data, including documents and communications. AWS also bundled AWS Security Agent capabilities for penetration testing, code scanning, and threat modelling, broadening the platform’s defensive reach.

FortiBleed Fortinet credential-theft campaign

Campaign

Updated: 19.06.2026 13:48 · First: 19.06.2026 13:48 · 📰 2 src / 2 articles · H score: 89

The FortiBleed campaign is an ongoing Fortinet credential-theft activity tied to internet-accessible FortiGate appliances and other Fortinet firewalls and VPN gateways. CISA warned customers to harden devices after researchers linked the campaign to 86,644 compromised devices as of June 19, 2026. The activity used mass-scanning, a bespoke credential-spraying tool, and passive traffic monitoring to collect more logins, with Russian-speaking threat actors believed to be involved. CISA advised terminating active sessions, resetting credentials, enabling phishing-resistant MFA, and reviewing logs to limit further access.

FortiBleed Fortinet/FortiGate VPN credential leak

Data Leak

Updated: 17.06.2026 18:12 · First: 17.06.2026 18:12 · 📰 2 src / 3 articles · H score: 80

FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from internet-facing Fortinet infrastructure across 194 countries. CISA urged customers to harden FortiGate devices by terminating sessions, resetting credentials, enabling phishing-resistant MFA, reviewing logs, and restricting management access. Reporting links the exposure to a Russian-speaking threat actor using SSL VPN authentication interception, hash cracking, and Active Directory pivoting, with at least four organizations fully compromised and broad impact across government and critical infrastructure.

Splunk Enterprise unauthenticated file operations flaw (CVE-2026-20253)

Vulnerability

Updated: 13.06.2026 16:23 · First: 13.06.2026 16:23 · 📰 2 src / 2 articles · H score: 46

Splunk Enterprise now has a critical CVE-2026-20253 flaw that lets an unauthenticated attacker perform arbitrary file operations and potentially reach remote code execution on affected servers. The issue affects versions below 10.2.4 and 10.0.7, while Splunk Cloud is not impacted. The weakness sits in a PostgreSQL sidecar service endpoint that lacks authentication controls, allowing network-reachable users to invoke file operations without credentials. Exploit details published for the flaw increase the risk of opportunistic abuse even though there is no evidence of in-the-wild exploitation.

Non-email threat-detection confidence gap across collaboration channels

Trend

Updated: 19.06.2026 12:00 · First: 19.06.2026 12:00 · 📰 1 src / 1 articles · H score: 25

A survey found a broad non-email threat-detection gap across Slack, Microsoft Teams, and social channels, increasing exposure as attackers move beyond email. At Infosecurity Europe 2026, 50% of 169 cybersecurity professionals said their organizations lack strong confidence in detecting threats on messaging and social platforms. The pattern is reinforced by low confidence in Slack (40%) and only partial training coverage for non-email threats.

Anthony Belford spoofed-account harassment campaign against a Georgia college student

Campaign

Updated: 19.06.2026 11:44 · First: 19.06.2026 11:44 · 📰 1 src / 1 articles · H score: 35

The alleged spoofed-account harassment campaign against a Georgia college student has been tied to repeated use of fake social profiles and email to spread AI-generated nude images and racist fabrications. The activity allegedly spanned January to March 2025 and kept following the victim after a transfer in August 2024. Multiple impersonation accounts were created on Instagram, LinkedIn, Reddit, X, Strava, and Yahoo. The operation widened the harm by contacting the victim's mother and amplifying the abuse across several platforms.

Anthony Belford federal cyberstalking arraignment

Law Enforcement

Updated: 19.06.2026 11:44 · First: 19.06.2026 11:44 · 📰 1 src / 1 articles · H score: 22

Anthony Belford was arraigned after a federal grand jury indictment on cyberstalking charges, advancing a case tied to AI-generated nude image harassment of a college student. Prosecutors say he used fake Instagram, LinkedIn, Reddit, X, Strava, and Yahoo accounts between January and March 2025 to impersonate the victim and spread racist and anti-Muslim messages. The conduct allegedly continued after the victim transferred to a Georgia college in August 2024, and one spoofed Yahoo account was used to send an AI-generated nude image to the victim's mother.

CISA FortiBleed mitigation guidance

Advisory/Mitigation

Updated: 19.06.2026 09:47 · First: 19.06.2026 09:47 · 📰 3 src / 3 articles · H score: 67

CISA issued mitigation guidance for FortiBleed, urging operators of internet-accessible Fortinet devices to harden exposed FortiGate and VPN environments after a large-scale credential theft campaign. Reported figures now place the verified credential set at 86,644 confirmed working credentials across 194 countries, with researchers also citing at least four organizations fully compromised. CISA’s actions center on ending active sessions, resetting credentials, enabling phishing-resistant MFA, reviewing logs, and restricting management access to reduce account abuse.

CISA KEV order for SolarWinds Serv-U CVE-2026-28318

Public Sector Action

Updated: 06.06.2026 11:14 · First: 06.06.2026 11:14 · 📰 2 src / 2 articles · H score: 50

CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the KEV catalog and ordered FCEB agencies to remediate it by June 19, 2026. The directive expands operational urgency for federal civilian environments because the flaw is tied to active exploitation. SolarWinds says the issue is fixed in Serv-U 15.5.4 HF1.

Gentlemen ransomware EDR-killer tooling

Malware Activity

Updated: 19.06.2026 01:31 · First: 19.06.2026 01:31 · 📰 2 src / 2 articles · H score: 34

Gentlemen ransomware-as-a-service (RaaS) is actively maintaining a suite of EDR killers led by GentleKiller to disable endpoint defenses before encryption. ESET says the framework has at least eight variants, impersonates legitimate security products such as Kaspersky, Valorant, Javelin, and WatchDog, and uses BYOVD with vulnerable drivers to obtain kernel-level privileges and target more than 400 processes across roughly 48 security vendors and products. The broader tooling set also includes HexKiller, ThrottleBlood, HavocKiller, and OxideHarvest. ESET also reported that Gentlemen can operationalize newly disclosed BYOVD PoC exploits within days and appears to favor victims with FortiGate endpoint configurations.

Nintendo of America employees customer data exposed after Nintendo of America breach

Data Leak

Updated: 18.06.2026 21:31 · First: 18.06.2026 21:31 · 📰 1 src / 1 articles · H score: 26

Nintendo of America confirmed that internal employee survey data from TinyPulse was stolen, exposing information tied to a small subset of employees while leaving Nintendo systems and customer data untouched. The breach was paired with Shadowbyt3$ ransom claims, including a demand for $2 million and warnings that the stolen material could be leaked publicly. The confirmed exposure is limited to survey content, but the event adds pressure because the threat actor says more employee-related data may exist.

Vo1d botnet campaign targeting unofficial Android-based TV boxes

Campaign

Updated: 18.06.2026 20:37 · First: 18.06.2026 20:37 · 📰 1 src / 1 articles · H score: 88

The Vo1d campaign continues to target unofficial Android-based TV boxes, keeping a large-scale proxy botnet alive across consumer devices. The operation turns those boxes into relay nodes that can forward traffic for advertising fraud, account takeovers, and mass data-scraping. Researchers say the activity has persisted for four years and spans millions of devices. The scale and persistence make the campaign a broad abuse platform rather than a one-off botnet flare-up.

Popa botnet forcing consumer TV boxes to relay traffic

Malware Activity

Updated: 18.06.2026 20:37 · First: 18.06.2026 20:37 · 📰 1 src / 1 articles · H score: 76

The Popa botnet has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. The activity has persisted for four years, making it a long-lived proxy layer rather than a short burst of abuse. The scale increases the risk of traffic laundering, downstream misuse, and attribution confusion for affected sites and network defenders.

F5 security patch release for CVE-2026-42530

Security Patch Release

Updated: 18.06.2026 20:32 · First: 18.06.2026 20:32 · 📰 1 src / 1 articles · H score: 39

F5 released security updates for NGINX Open Source after finding two critical vulnerabilities that could lead to remote code execution on affected systems. The patch set covers CVE-2026-42530 and CVE-2026-42055, with fixed builds spanning NGINX Open Source and related NGINX products. Administrators using the affected HTTP/3, HTTP/2, proxy, WAF, and ingress components need to move to the fixed versions to remove the code-execution risk.

USB-spreading clipboard-stealing malware targeting cryptocurrency wallets

Malware Activity

Updated: 18.06.2026 19:20 · First: 18.06.2026 19:20 · 📰 1 src / 1 articles · H score: 27

A USB-spreading clipboard-stealing malware family is actively stealing seed phrases, private keys, and wallet addresses from Windows victims, putting cryptocurrency funds at direct risk. The malware also captures screenshots and sends stolen data over Tor, making detection and takedown harder. Its use of LNK shortcut files on removable drives gives it a worm-like propagation path across connected systems.