Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 14:53 16/06/2026 UTC
  • Incident H score 93 PushEngage hit by cyberattack Awesome Motive remediated its marketing site and rotated all credentials, including a stolen CDN API key, after CDN-delivered malware targeting PushEngage/OptinMonster/TrustPulse created rogue WordPress admin access and backdoor persistence.
  • Exploitation Wave H score 49 Fortinet FortiSandbox multi-CVE exploitation wave Defused reported an active FortiSandbox exploitation wave in the past 24 hours across multiple critical CVEs, advancing the likelihood of near-term unauthenticated RCE/privilege escalation against unpatched appliances.
  • Data Leak H score 34 IRhythm patient data exfiltration from third-party business applications iRhythm Holdings disclosed a material data breach after exfiltrators stole patients’ personal and health information from third-party hosted business applications, moving the incident into confirmed breach/SEC reporting status.
  • Data Leak H score 82 Council of Europe ShinyHunters data leak claim ShinyHunters added the Council of Europe to its Tor leak site claiming 297GB+ of stolen data with a June 16 release deadline, escalating potential exposure of sensitive public- and employee-related records.
  • Incident H score 54 Adriatic Port Authority (Autorità di Sistema Portuale del hit by ransomware attack linked to Anubis The Adriatic Port Authority reported a ransomware breach tied to Anubis that disrupted Ancona port operations and exposed port records, increasing operational and safety-related risk from leaked contracts and safety plans.
  • Incident H score 51 Infinite Campus hit by data theft breach linked to ShinyHunters Infinite Campus disclosed a Salesforce data theft exposing 137,100+ school staff accounts linked to ShinyHunters, advancing breach confirmation with large-scale personally identifiable information.
Last updated: 11:36 16/06/2026 UTC
  • Incident H score 93 PushEngage hit by cyberattack Awesome Motive remediated its marketing site, migrated servers, and rotated the stolen CDN API key after a UpdraftPlus-driven CDN supply-chain compromise to tampered JavaScript, advancing incident containment for OptinMonster/TrustPulse/PushEngage-delivered attacks.
  • Case Case score 93 Awesome Motive WordPress Plugin Supply-Chain Compromise The Awesome Motive WordPress plugin supply-chain case was updated with the latest credential-rotation and CDN remediation steps following attackers’ CDN API key theft via a compromised UpdraftPlus environment, tightening response but leaving the initial access path unresolved.
  • Law Enforcement H score 63 FBI takedown of Outsider Enterprise phishing service The FBI takedown dismantled Outsider Enterprise’s Telegram-run phishing-as-a-service operation by seizing infrastructure and accounts, materially reducing ongoing SMS smishing and credential/card theft enabled by the network.
  • Campaign H score 89 PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign Awesome Motive reported mitigation action for the CDN script-tampering campaign—rotating the CDN API key and moving to a new marketing server—lowering risk that affected pages continue triggering rogue admin creation and backdoors.
  • Data Leak H score 82 Council of Europe ShinyHunters data leak claim ShinyHunters added the Council of Europe to its Tor leak site claiming 297GB+ of stolen data and a June 16 release deadline, escalating extortion pressure and potential downstream exposure for large-scale sensitive records.
  • Security Patch Release H score 79 Veeam security patch release for CVE-2026-44963 Veeam released security updates for CVE-2026-44963 to address remote code execution on domain-joined backup servers, advancing remediation for high-impact backup-infrastructure compromise risk.

Latest updates

Browse →

UK under-16 social media age-check ban

Public Sector Action

Updated: 16.06.2026 17:38 · First: 16.06.2026 17:38 · 📰 1 src / 1 articles · H score: 25

The UK government announced a ban on under-16s using social media, requiring age checks for new accounts and tightening access to major platforms. The rollout is set for spring 2027, with regulations due before Christmas and Ofcom asked to study verification methods. New users will likely need to upload an ID or pass a facial age scan, while long-standing accounts are mostly grandfathered. The move pushes UK social media toward verified access and away from anonymous account creation.

FishMonger multi-country government espionage campaign

Campaign

Updated: 16.06.2026 17:30 · First: 16.06.2026 17:30 · 📰 1 src / 1 articles · H score: 33

FishMonger ran a multi-country espionage campaign against government bodies in Honduras, Taiwan, Thailand and Pakistan across 2023 and 2024. The activity points to a sustained public-sector collection effort rather than an isolated intrusion. The campaign matters because it shows repeated targeting across several jurisdictions using the same operator identity and backdoor-based access pattern.

GhostTree and GhostBranch NTFS junction loops that evade recursive folder scanning

Technical Analysis

Updated: 16.06.2026 17:17 · First: 16.06.2026 17:17 · 📰 1 src / 1 articles · H score: 23

GhostTree and GhostBranch use recursive NTFS junction loops to generate effectively unlimited paths, allowing files in the same folder to evade EDR and Windows Defender recursive scans.

FTC imposter-scam warning and Impersonation Rule enforcement

Public Sector Action

Updated: 16.06.2026 16:42 · First: 16.06.2026 16:42 · 📰 1 src / 1 articles · H score: 33

The FTC warned that Americans lost $3.5 billion to imposter scams in 2025, elevating a major public anti-fraud response around impersonation-driven theft. The agency tied the warning to its Impersonation Rule enforcement posture and said the fraud problem has continued to scale. The losses underscore how impersonation schemes are draining consumers through phone, text, email, social media, and search-based lures.

Rokarolla Android banking trojan activity

Malware Activity

Updated: 16.06.2026 16:15 · First: 16.06.2026 16:15 · 📰 2 src / 2 articles · H score: 27

The Rokarolla Android banking trojan is expanding phone-level control on infected devices, letting attackers steal credentials, intercept authentication codes, and hide fraud from banks. It targets 217 banking and cryptocurrency apps and uses 137 commands to manage calls, texts, overlays, and screenshots. The malware spreads through malicious sites posing as TikTok or Google Chrome, then abuses Accessibility Services and default SMS/call handling to isolate victims and suppress alerts.

CISA KEV order for FCEB agencies on LiteSpeed cPanel flaw

Public Sector Action

Updated: 16.06.2026 13:47 · First: 16.06.2026 13:47 · 📰 1 src / 1 articles · H score: 36

CISA added the LiteSpeed cPanel user-end plugin flaw to KEV and ordered Federal Civilian Executive Branch agencies to secure systems within three days under BOD 26-04. The action raises compliance urgency across the federal civilian footprint because the vulnerability is actively exploited and can lead to root escalation on affected shared hosting servers. Agencies are being pushed to treat the flaw as an immediate remediation item rather than a routine patch.

CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)

Advisory/Mitigation

Updated: 16.06.2026 08:41 · First: 16.06.2026 08:41 · 📰 2 src / 2 articles · H score: 38

CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privilege-escalation issue that can turn FTP or web shell access into root on shared hosting servers running CloudLinux/CageFS. LiteSpeed says affected builds include LiteSpeed cPanel Plugin before 2.4.8 and LiteSpeed WHM PlugIn before 5.3.2.0, with a fix in LiteSpeed WHM Plugin v5.3.2.1 bundled with cPanel plugin v2.4.8 or higher.

Fortinet FortiSandbox multi-CVE exploitation wave

Exploitation Wave

Updated: 16.06.2026 12:19 · First: 16.06.2026 12:19 · 📰 2 src / 2 articles · H score: 49

Fortinet FortiSandbox is facing an active exploitation wave that puts affected deployments at risk of unauthenticated remote code execution and privilege escalation. Defused said attackers are exploiting multiple critical vulnerabilities, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The activity was observed during the past 24 hours, and Fortinet had already released fixes on April 14. Administrators need to move to the latest released versions to block incoming attacks.

FortiSandbox unauthenticated command injection (CVE-2026-25089)

Vulnerability

Updated: 16.06.2026 13:30 · First: 16.06.2026 13:30 · 📰 1 src / 1 articles · H score: 47

CVE-2026-25089 is an unauthenticated operating system command injection in FortiSandbox-related products that was seen in active exploitation over the past 24 hours. The flaw can let an attacker send crafted HTTP requests to execute unauthorized commands on exposed systems.

Fortinet security patch release for CVE-2026-39813

Security Patch Release

Updated: 16.06.2026 12:19 · First: 16.06.2026 12:19 · 📰 2 src / 2 articles · H score: 41

Fortinet released April 14 security updates for FortiSandbox, covering CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The patch release fixes three critical vulnerabilities that can enable unauthenticated privilege escalation and remote code execution. Administrators must upgrade affected deployments to the latest released versions to block incoming attacks.

Backdoor.Turn Microsoft Teams TURN relay malware activity

Malware Activity

Updated: 16.06.2026 13:18 · First: 16.06.2026 13:18 · 📰 2 src / 2 articles · H score: 29

Backdoor.Turn is a Go-based RAT now tied to covert command-and-control traffic hidden through Microsoft Teams TURN relay servers, creating a trusted-looking channel for remote access. Symantec says it is the first known in-the-wild malware to abuse this relay path. The activity was observed in December 2025 during an intrusion against a major U.S. services company. The malware's stealthy transport and post-exploitation features raise the risk of undetected compromise.

Major U.S. services company hit by ransomware attack linked to DragonForce

Incident

Updated: 16.06.2026 13:18 · First: 16.06.2026 13:18 · 📰 2 src / 2 articles · H score: 38

A DragonForce ransomware incident hit a major U.S. services company in December 2025, with attackers maintaining access for up to two months and hiding command-and-control traffic in Microsoft Teams. Researchers said the intrusion used a Go-based RAT dubbed Backdoor.Turn to blend traffic into Teams relay infrastructure and a QUIC session, then added persistence by changing settings, creating accounts, and modifying firewall rules. The activity ended with data exfiltration and systems encryption, and the initial foothold was likely through an SQL or MSSQL server flaw.

Earth Lusca Operation FishMedley espionage campaign

Campaign

Updated: 16.06.2026 12:44 · First: 16.06.2026 12:44 · 📰 1 src / 1 articles · H score: 38

A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organizations across Taiwan, Hungary, Turkey, Thailand, France, and the U.S. The campaign matters because it shows coordinated targeting across multiple countries rather than a single isolated intrusion. The operation also reinforces the group's repeatable access and follow-on activity against government and organizational targets.

ESET analysis of SprySOCKS Windows variants adds IOC-backed detection guidance

Technical Analysis

Updated: 16.06.2026 12:00 · First: 16.06.2026 12:00 · 📰 3 src / 3 articles · H score: 34

ESET identified previously undocumented Windows variants of SprySOCKS, a backdoor attributed to FishMonger and linked to I-Soon. The WIN_DRV and WIN_PLUS variants add kernel-level stealth and retain TCP, UDP, and WebSocket command-and-control, plus 30+ espionage commands. ESET traced activity to 2023-2024 against government bodies in Honduras, Taiwan, Thailand, and Pakistan, and found signs the activity may extend into a UEFI bootkit chain.

SprySOCKS Windows backdoor activity against government organizations

Malware Activity

Updated: 16.06.2026 12:00 · First: 16.06.2026 12:00 · 📰 3 src / 3 articles · H score: 23

SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to government organizations in Taiwan, Thailand, Pakistan, and Honduras and uses TCP, UDP, and WebSocket communications with more than 30 commands for system data collection, process and service management, and file operations. WIN_DRV adds kernel drivers for stealth, hiding processes, files, network connections, and registry keys while also supporting TCP traffic diversion. ESET links the activity to Earth Lusca / FishMonger and notes limited indications of a UEFI bootkit path involving CVE-2023-24932.

FBI courier-assisted crypto scam warning

Advisory/Mitigation

Updated: 16.06.2026 11:15 · First: 16.06.2026 11:15 · 📰 1 src / 1 articles · H score: 32

The FBI has renewed warnings about cryptocurrency investment scams that use couriers and cash pickups to bypass bank checks and keep victims sending money. The advisory says scammers tell targets that in-person cash is needed to continue investing or to pay fake withdrawal fines. It also warns that fraudsters may claim an account has been flagged and direct the victim to a courier as an alternative payment path.

ScarCruft NarwhalRAT spear-phishing malware activity

Malware Activity

Updated: 16.06.2026 11:14 · First: 16.06.2026 11:14 · 📰 1 src / 1 articles · H score: 23

ScarCruft (APT37) is using spear-phishing emails that impersonate Microsoft Account security alerts to deliver NarwhalRAT, creating a multi-stage malware threat that can steal data and maintain remote control on compromised hosts. The infection chain uses a ZIP archive with a malicious LNK file to start the payload dropper flow. NarwhalRAT supports keylogging, screenshot capture, ambient audio recording, and C2 execution, giving operators broad visibility into victim systems.

IRhythm patient data exfiltration from third-party business applications

Data Leak

Updated: 16.06.2026 09:31 · First: 16.06.2026 09:31 · 📰 2 src / 2 articles · H score: 34

iRhythm Holdings disclosed a data breach involving third-party-hosted business applications after a threat actor used social engineering to access data and demanded payment on June 9, 2026. The company said it detected unauthorized activity on June 8, confirmed that some data was stolen, and is still determining the full scope. The exposed material includes proprietary data and patients’ protected health information, while products, clinical or medical device systems, and financial reporting systems were not impacted.

IRhythm Holdings hit by cyberattack

Incident

Updated: 16.06.2026 09:31 · First: 16.06.2026 09:31 · 📰 2 src / 2 articles · H score: 31

iRhythm Holdings disclosed a data breach after attackers used social engineering against third-party-hosted business applications and stole patients' personal and health information. The company said it detected unauthorized activity on June 8, 2026, was contacted on June 9 with claims of stolen proprietary data and patient protected health information, and later confirmed that some data has been stolen. iRhythm said the incident did not affect its products, clinical or medical device systems, manufacturing and distribution operations, or financial reporting systems, and it is still determining the full scope of the breach.

CISA adds CVE-2026-20262 to KEV and orders federal fixes

Public Sector Action

Updated: 16.06.2026 09:05 · First: 16.06.2026 09:05 · 📰 1 src / 1 articles · H score: 32

CISA added CVE-2026-20262 to its Known Exploited Vulnerabilities (KEV) catalog and required Federal Civilian Executive Branch (FCEB) agencies to apply Cisco's fixes by June 29, 2026, forcing federal remediation of an actively exploited Cisco SD-WAN flaw. The action targets Cisco Catalyst SD-WAN Manager after evidence showed abuse in the wild. Cisco said the flaw could let an authenticated remote attacker create or overwrite files and potentially reach root. The deadline gives federal agencies a clear remediation window for a live exploitation risk.

DOJ seizure of CFAKE.com and SOCFAKE.com deepfake domains

Law Enforcement

Updated: 16.06.2026 00:56 · First: 16.06.2026 00:56 · 📰 1 src / 1 articles · H score: 26

The U.S. Department of Justice and Homeland Security Investigations seized CFAKE.com and SOCFAKE.com, disrupting a deepfake pornography operation and taking the domains offline under a federal warrant. The action is the first publicly announced domain seizure under the TAKE IT DOWN Act. The domains allegedly hosted nonconsensual AI-generated nude images and videos of women, including public figures.

SimpleHelp remote management software privileged technician account creation security flaw (CVE-2026-48558)

Vulnerability

Updated: 15.06.2026 23:06 · First: 15.06.2026 23:06 · 📰 1 src / 1 articles · H score: 46

A critical CVE-2026-48558 in SimpleHelp remote management software lets unauthenticated attackers create privileged Technician accounts when OIDC is enabled, putting remote administration access at risk. The flaw affects 5.5.15 and older and 6.0 pre-release versions. SimpleHelp released 5.5.16 and 6.0RC2 on June 9 to fix the issue. No evidence of active exploitation was reported.

SimpleHelp security update for CVE-2026-48558

Security Patch Release

Updated: 15.06.2026 23:06 · First: 15.06.2026 23:06 · 📰 1 src / 1 articles · H score: 65

SimpleHelp released 5.5.16 and 6.0RC2 on June 9 to fix CVE-2026-48558, a critical OIDC authentication flaw that could let unauthenticated attackers create privileged Technician accounts. The update matters for deployments that rely on OIDC because the bug could bypass MFA and grant remote-management access. The patch narrows exposure for affected SimpleHelp 5.5.15 and older installations and 6.0 pre-release builds.

INFINITERED REDCap backdoor and credential harvester

Malware Activity

Updated: 15.06.2026 22:44 · First: 15.06.2026 22:44 · 📰 1 src / 1 articles · H score: 26

The INFINITERED malware was deployed on REDCap servers to preserve access, steal credentials, and operate as a backdoor inside compromised research environments. It trojanized REDCap system files, hijacked the upgrade process so reinfected code would survive updates, and harvested usernames and passwords from the login page. The malware also accepted commands through HTTP cookies and ran on every page load, extending persistence through November 2025.

Contagious Interview UNK_DeadDrop GitHub phishing campaign

Campaign

Updated: 15.06.2026 22:32 · First: 15.06.2026 22:32 · 📰 1 src / 1 articles · H score: 37

The Contagious Interview cluster is running the UNK_DeadDrop phishing campaign to lure developers with recruitment and code review themes, reaching nearly 100 organizations. The operation routes targets to actor-controlled GitHub repositories and VS Code projects that can trigger malicious code with little interaction. The campaign spans finance, cryptocurrency, education, technology, and other sectors, raising the risk of malware execution and credential theft.

North Korea-aligned developer-targeting operations shift from fake interviews to recruitment phishing at scale

Threat Actor Meta

Updated: 15.06.2026 22:32 · First: 15.06.2026 22:32 · 📰 1 src / 1 articles · H score: 31

North Korea-aligned developer-targeting operations are shifting from fake interviews to recruitment-themed phishing at scale, increasing the risk of industrialized credential and wallet theft across developer communities. The change indicates a more automated and scalable adversary operating model built around malicious GitHub repositories and code-review lures.

PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign

Campaign

Updated: 15.06.2026 12:59 · First: 15.06.2026 12:59 · 📰 3 src / 3 articles · H score: 89

A multi-plugin supply-chain campaign targeted Awesome Motive WordPress plugins OptinMonster, TrustPulse, and PushEngage, with malicious JavaScript delivered through the vendor’s CDN and triggered only when a WordPress administrator loaded an infected page. The code created rogue administrator accounts, installed a self-hiding backdoor plugin, and established follow-on access, putting up to 1.2 million websites at risk through the affected install base. Awesome Motive says attackers first reached a marketing server by exploiting a known UpdraftPlus flaw, stole the CDN API key, and then modified distributed JavaScript; the company has since rotated credentials and said its production systems were not breached.

PushEngage hit by cyberattack

Incident

Updated: 15.06.2026 12:59 · First: 15.06.2026 12:59 · 📰 3 src / 3 articles · H score: 93

Awesome Motive's WordPress plugin delivery paths for OptinMonster, TrustPulse, and PushEngage were hit in a CDN supply-chain incident after attackers stole a CDN API key from a server compromised through UpdraftPlus. The tampered JavaScript could activate when a WordPress administrator loaded an affected page, creating a rogue admin account, installing a hidden backdoor, and sending captured data to tidio[.]cc. OptinMonster is used on at least 1.2 million websites, and the incident exposed sites that loaded the poisoned files to site takeover risk.

Awesome Motive WordPress Plugin Supply-Chain Compromise

Case

Updated: 15.06.2026 20:37 · First: 15.06.2026 12:59 · 📰 0 src / 2 articles

PushEngage, OptinMonster, and TrustPulse were used to serve tampered JavaScript that only activated for logged-in WordPress administrators, then created attacker-controlled administrator access and installed hidden persistence. The exposure began on June 12, with PushEngage still serving malicious code on June 13 and into June 14 from some CDN servers. Any site that loaded the poisoned files needs compromise review even if the visible script has been replaced. Response has centered on file replacement, CDN cache clearing, credential rotation, and server-side hunting, while the initial access path into the delivery environment remains unresolved.

Cisco security patch release for CVE-2026-20262

Security Patch Release

Updated: 15.06.2026 20:12 · First: 15.06.2026 20:12 · 📰 2 src / 2 articles · H score: 47

Cisco released security updates for CVE-2026-20262 in Catalyst SD-WAN Manager, covering multiple release trains after the zero-day was exploited to reach root privileges. The fixed-build map spans 20.9, 20.12, 20.15, 20.18, and 26.1 trains, and the issue affects on-prem and cloud-managed deployments. Administrators were told to upgrade and review logs for index.jsp and .war upload attempts.