• Open

    PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
    Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
    The Nansh0u Campaign – Hackers Arsenal Grows Stronger
    In the beginning of April, three attacks detected in the Guardicore Global Sensor Network (GGSN) caught our attention. All three had source IP addresses originating in South-Africa and hosted by VolumeDrive ISP (see IoCs).
    The Oracle of Delphi Will Steal Your Credentials
    Our deception technology is able to reroute attackers into honeypots, where they believe that they found their real target. The attacks brute forced passwords for RDP credentials to connect to the victim download and execute a previously undetected malware, which we named Trojan.sysscan.
    Keep Your Tech Flame Alive: Trailblazer Rachel Bayley
    In this Akamai FLAME Trailblazer blog post, Rachel Bayley encourages women to step into the unknown and to be their authentic selves.
    Threats Making WAVs - Incident Response to a Cryptomining Attack
    Guardicore security researchers describe and uncover a full analysis of a cryptomining attack, which hid a cryptominer inside WAV files. The report includes the full attack vectors, from detection, infection, network propagation and malware analysis and recommendations for optimizing incident response processes in data centers.
  • Open

    AutoJack: How a single page can RCE the host running your AI agent
    AutoJack is a novel exploit chain showing how a single malicious webpage can turn an AI browsing agent into a remote code execution vector on the host machine. By abusing trust in localhost, missing authentication, and unsafe parameter handling, attackers can trigger arbitrary process execution through AutoGen Studio’s MCP WebSocket. The research highlights a broader pattern - when agents can browse untrusted content and access local services, traditional boundaries like localhost are no longer secure. The post AutoJack: How a single page can RCE the host running your AI agent  appeared first on Microsoft Security Blog.

  • Open

    PEPR '26 - Training Developers' Privacy Awareness with Enforcement Cases
    No content preview
    PEPR '26 - Scaling Privacy Threat Modeling: From Architects to Developers
    No content preview
    PEPR '26 - Privacy Review for Non-Maniacs
    No content preview
    PEPR '26 - V.O.I.C.E.: A Data-Driven Risk Taxonomy for Synthetic Voice Generation
    No content preview
    PEPR '26 - Privacy in Theory, Bugs in Practice: Grey-Box Testing for Differential Privacy Libraries
    No content preview
    PEPR '26 - Mapping the Privacy Workforce in the AI Era
    No content preview
    PEPR '26 - The Emperor's New Embeddings: Obfuscating ML Inputs Doesn't Provide Privacy
    No content preview
    PEPR '26 - Shadow Data in Tool Calls: The Privacy Leak Hiding in Plain Sight
    No content preview
    PEPR '26 - Private AI: Building Trust Through Verifiable Computation
    No content preview
    PEPR '26 - Surfacing Hidden Privacy Risks in Code: Lessons from LLM and Retrieval Assisted Detection
    No content preview
    PEPR '26 - Production Multi-Party Computation via the Distributed Aggregation Protocol
    No content preview
    PEPR '26 - Adopting AI in Local Government with Privacy and Equity in Mind: A Case Study of the...
    No content preview
    PEPR '26 - The Disposable Identity: Eliminating Non-Human Identity Risk in Federal Healthcare...
    No content preview
    PEPR '26 - Designing for Civic Trust: An Infrastructure to Help Long Beach Residents Manage Their...
    No content preview
    PEPR '26 - Private Tuning of LLMs in Practice: From VaultGemma to Custom Fine-Tuning
    No content preview
  • Open

    Ralph Lauren - 139,903 breached accounts
    In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresses along with names, phone numbers, genders and age groups.
    Operation Endgame 4.0 - 153,527 breached accounts
    On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation, a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the operation remediated almost 15,000 compromised websites and disrupted more than 100 servers and domains used to distribute malware. Authorities also provided HIBP with 154k impacted email addresses and more than half a million previously unseen passwords.
    CFGI - 248,235 breached accounts
    In March 2026, the financial consulting and advisory firm CFGI was the target of a ShinyHunters "pay-or-leak" extortion campaign. The group subsequently publicised data allegedly obtained from CFGI comprising corporate contact information, including 243k unique email addresses, names, phone numbers and physical addresses.
  • Open

    New Forrester study shows customers who unified with Microsoft Security benefited from 124% ROI
    New Forrester Total Economic Impact™ study shows Microsoft Security consolidation delivers ROI, lowers risk, and prepares organizations to secure AI. The post New Forrester study shows customers who unified with Microsoft Security benefited from 124% ROI appeared first on Microsoft Security Blog.
    From package to postinstall payload: Inside the Mastra npm supply chain compromise
    A poisoned npm package infected 140+ projects with a hidden payload. This report highlights how to detect, hunt, and defend against supply chain attacks using Microsoft Defender and actionable threat intelligence. The post From package to postinstall payload: Inside the Mastra npm supply chain compromise appeared first on Microsoft Security Blog.
  • Open

    Accelerate security investigations with Kiro CLI
    When a security event occurs in your Amazon Web Services (AWS) environment, rapid response is critical. However security teams often struggle with time-consuming, manual processes that slow down investigations. Analysts must recall complex AWS Command Line Interface (AWS CLI) syntax for multiple services, manually correlate findings across Amazon GuardDuty, AWS CloudTrail, and other security tools, […]  ( 116 min )
    Spring 2026 SOC 1 and 2 reports are now available in OSCAL format
    Amazon Web Services (AWS) is excited to release the Spring 2026 System and Organization Controls (SOC) 1 and 2 reports in machine-readable OSCAL format alongside the PDF version of the reports. The reports cover 188 services over the 12-month period from April 1, 2025 to March 31, 2026, giving customers a full year of assurance. […]  ( 108 min )
  • Open

    Stop Treating Your LLMs Like Web Servers
    No content preview
    DNS Is Your Most Critical — and Most Misconfigured — Security Control
    No content preview
  • Open

    Black Hat Intercepted | Mike Spicer, Black Hat NOC Lead
    No content preview
    Black Hat Europe 2025 | Why We Can't Retrofit Old Security Principles Onto AI Agents
    No content preview
    Black Hat Europe 2025 | Understanding Trends & Patterns In Insider Threat: Analysis Of 1,000+ Cases
    No content preview
    Black Hat Europe 2025 | Token Injection: Crashing LLM Inference With Special Tokens
    No content preview
  • Open

    A New Fossil Discovery Just Rewrote 150 Years of Evolutionary Theory
    For 150 years, paleontologists assumed that the first vertebrates to leave the sea for land evolved a tadpole phase, similar to modern frogs. Immaculately-preserved fossils disprove that, scientists say.
    If AI Is Sentient Then So Is ‘Age of Empires II’
    “The point of the paper is to formally show that we anthropomorphise too readily."
    Salesforce’s Internal AI Leaderboard Has Teams Competing for Little Trophies
    The leaderboard, sorted by executive and the teams underneath them, has a feature that shows users which employees have not earned the badges. “click to see who 👀,” the leaderboard says.
  • Open

    Shynet | VERSION 0.13.1
    The following document describes identified vulnerabilities in the Shynet application version 0.13.1.
    The Smash-and-Grab Era
    We walk through three eras of cyber attacks and makes a troubling case that LLMs are removing the one constraint that kept attackers slow and detectable.
  • Open

    Microsoft working on a fix for RoguePlanet, a flaw that grants full PC control
    Microsoft says it's working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.
    Retro gaming fans are the new target for fake GitHub malware
    Retro gaming fans should be careful with GitHub projects that claim to be tools or plugins for their consoles. We looked at one example aimed at PlayStation Vita owners.
    Kodak confirms breach as ShinyHunters’ leak threat reaches deadline
    The photography giant confirmed a data breach after ShinyHunters claimed it stole 2.2 million records and threatened to leak them.
  • Open

    InfoSec News Nuggets – 06/18/2026
    Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development Microsoft formally acknowledged RoguePlanet, a Defender zero-day now tracked as CVE-2026-50656 with a CVSS score of 7.8, confirming it is working on a fix for the privilege escalation flaw in the Microsoft Malware Protection Engine nearly a week after a researcher going by Chaotic Eclipse […] The post InfoSec News Nuggets – 06/18/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Brazil’s Maturing Market Meets Maturing Threats: How Global Crypto Crime Trends Are Landing in Latin America’s Largest Market
    Brazil is Latin America’s largest crypto market, and one of the world’s most dynamic. Between July 2024 and June 2025,… The post Brazil’s Maturing Market Meets Maturing Threats: How Global Crypto Crime Trends Are Landing in Latin America’s Largest Market appeared first on Chainalysis.
    Mercado brasileiro amadurece e enfrenta ameaças cada vez mais sofisticadas: como as tendências globais do crime com cripto estão chegando ao maior mercado da América Latina
    O Brasil é o maior mercado de criptomoedas da América Latina e um dos mais dinâmicos do mundo. Entre julho… The post Mercado brasileiro amadurece e enfrenta ameaças cada vez mais sofisticadas: como as tendências globais do crime com cripto estão chegando ao maior mercado da América Latina appeared first on Chainalysis.
  • Open

    Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG…
    No content preview
    “Bug Bounty Bootcamp #47: Account Takeover 101 — How to Steal Everyone’s Account (Legally)”
    You don’t need to be a hacker in a hoodie. Just a missing IDOR, a leaky invite link, or a mass-assignable “role” field — and suddenly… Continue reading on InfoSec Write-ups »
    Build an IDOR Vulnerability Lab: Why WHERE Clauses Don’t Protect Your API.
    No content preview
    BEARCAT CTF 2026 WRITEUPS
    No content preview
    I almost ordered a product for free. (Business Logic Vulnerability)
    No content preview
    Building a Hackbot for Bug Bounties — Auth Testing Subagent Setup
    No content preview
    “Bug Bounty Bootcamp #46: Not Allowed From Your IP?”
    — How to Spoof, Brute-Force, and Mass-Assign Your Way Past Authentication Walls” Continue reading on InfoSec Write-ups »
    TryHackMe — Blog CTF | Full Write-Up
    No content preview
    VulnHub — Shenron: 1 | Full Walkthrough
    No content preview
    I Pentested a Real CRM System and Found 4 Critical Vulnerabilities — Here’s the Full Attack Chain
    No content preview

  • Open

    Crypto Clipper uses Tor and worm-like propagation for persistence and control
    Microsoft Threat Intelligence analyzed a cryptocurrency clipper campaign that combines clipboard theft, wallet replacement, Tor-based communications, and worm-like propagation. Beyond stealing cryptocurrency transactions, the malware establishes persistent access and enables follow-on activity through a lightweight backdoor capability. The post Crypto Clipper uses Tor and worm-like propagation for persistence and control appeared first on Microsoft Security Blog.
    Beyond the benchmark: Advancing security at AI speed
    Read how Microsoft Security has advanced its agentic vulnerability detection system, codename MDASH, integrating into real-world workflows across Windows, Azure, and identity systems. The post Beyond the benchmark: Advancing security at AI speed  appeared first on Microsoft Security Blog.
    ​​Forrester names Microsoft a Leader in the 2026 Extended Detection and Response Platforms Wave™ report
    Microsoft has been named a Leader in The Forrester Wave™: Extended Detection and Response Platforms, Q2 2026. The post ​​Forrester names Microsoft a Leader in the 2026 Extended Detection and Response Platforms Wave™ report appeared first on Microsoft Security Blog.
    AI is accelerating cyberattacks—here’s how to stay ahead
    See how Microsoft unifies identity and security signals to help teams prevent, detect, and respond to AI-accelerated attacks faster. The post AI is accelerating cyberattacks—here’s how to stay ahead appeared first on Microsoft Security Blog.
  • Open

    Black Box Probing: a Security Analysis of Xiaomi's MJA1 Secure Chip
    Xiaomi's MJA1 is a proprietary secure chip used in their recent cameras to protect sensitive data and device communications. With no public documentation available, we conducted a black-box security analysis covering hardware identification, I2C sniffing, flash dumping, and firmware reverse engineering. This post walks through how we mapped the chip's command protocol, brute-forced undocumented commands, and assessed its security properties.
  • Open

    Roblox developers are losing entire games to malware attacks
    Attackers are using fake job offers and malware to steal accounts, Robux, and Roblox games from the developers who build them.
    Rokarolla Android malware can take over your phone and steal banking logins
    Researchers have uncovered an Android banking Trojan that targets more than 200 banking and cryptocurrency apps and can take over infected devices.
    24 billion stolen records exposed online. Here’s what to do
    Researchers found an exposed collection of 24 billion stolen records, including usernames, passwords, and other sensitive account data.
    Malwarebytes earns AV-TEST Top Product award, aces other third-party tests
    Malwarebytes got top marks in independent tests against malware, phishing, and other online threats.
  • Open

    How Freedom Tech Is Pushing Back Against Digital Authoritarianism
    Senior legal advisor Siena Anstis and senior researcher John Scott-Railton spoke with Forbes about the lagging safeguards that let spyware proliferate.  The post How Freedom Tech Is Pushing Back Against Digital Authoritarianism appeared first on The Citizen Lab.
  • Open

    How Akamai Defended an Indian Bank Against Record-Breaking DDoS Attacks
    Learn how Akamai successfully neutralized one of the largest DDoS attacks ever recorded in the Indian banking sector before a single customer was impacted.
    Microsegmentation: Your Digital First Responder to LLM Threats
    No content preview
    Keep Your Tech FLAME Alive: Trailblazer Katrina Cole
    Meet Katrina Cole, an Information Security Consultant who entered tech at age 40. Read her advice for women in tech and her proactive approach to security.
  • Open

    Weekly Threat Bulletin – June 17th, 2026
    These are the top threats you should know about this week.
  • Open

    Seeing the Full Picture: Why Pre- and Post-Designation Exposure Changes Everything in Sanctions Screening
    Sanctions compliance in crypto isn’t just about knowing who’s on a list today. It’s about understanding the full arc of… The post Seeing the Full Picture: Why Pre- and Post-Designation Exposure Changes Everything in Sanctions Screening appeared first on Chainalysis.
    Approval Phishing: From Just One Case to Full-Scale Disruption
    Chain of Thought is our new expert-hosted webinar series, taking you behind the scenes of real investigations, emerging typologies and… The post Approval Phishing: From Just One Case to Full-Scale Disruption appeared first on Chainalysis.
  • Open

    ContinuumCon 2026 Redux!
    No content preview
  • Open

    Introducing AWS Continuum: Security at machine speed
    What we believe We’ve been thinking deeply about enterprise security. The operating model that served us for the past decade (collect telemetry, store it, query it, build dashboards to watch it) is no longer keeping pace. We need to shift to the new world: telemetry, context, reasoning, and actions. An approach that produces outcomes. The […]  ( 109 min )
  • Open

    ICE Appears to Be Buying Immigrants’ Tax Identifiers from a Data Broker
    A $10 million procurement reviewed by 404 Media indicates ICE is buying records related to immigrants’ tax identifiers. “It looks for all the world like Trump is trying to skirt the law and a court order to fuel his mass-deportation campaign,” Senator Ron Wyden said.
    Podcast: The Government Wants to End Anonymity on Phones
    The FCC's proposed changes to getting a phone plan; cops keep stalking with Flock; and a software update changes the AC in Amazon vans.
  • Open

    InfoSec News Nuggets – 06/17/2026
    144 Mastra npm Packages Compromised via Hijacked Contributor Account  A software supply chain attack codenamed easy-day-js compromised 144 npm packages associated with the Mastra namespace, a popular open-source framework for building AI applications, after attackers mass-published more than 140 malicious packages within an 88-minute automated window using a single hijacked npm account. The malicious code was introduced through a third-party dependency named […] The post InfoSec News Nuggets – 06/17/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Threat tactic spotlight: Subdomain takeover
    In this blog post you’ll learn how to detect and prevent subdomain takeover – a tactic where threat actors exploit dangling DNS records to redirect traffic to attacker-controlled resources. We’ll explain the issue, how the situation arises, and how you can use various AWS features and services to help mitigate the impact of this tactic. […]  ( 115 min )
  • Open

    Black Hat Europe 2025 | Insights From Phishing-Resistant Authentication
    No content preview
  • Open

    OFAC and Crypto Crime: Every OFAC Specially Designated National with Identified Cryptocurrency Addresses
    As far back as the early 1800s, the U.S. Department of the Treasury has issued economic sanctions to achieve foreign… The post OFAC and Crypto Crime: Every OFAC Specially Designated National with Identified Cryptocurrency Addresses appeared first on Chainalysis.
    How Ghana’s EOCO and the UK NCA are Using Blockchain Analysis to Return $15 Million to Fraud Victims
    When an e‑commerce “investment” platform promising high-yield returns began circulating in Ghana, thousands of people signed up to run online… The post How Ghana’s EOCO and the UK NCA are Using Blockchain Analysis to Return $15 Million to Fraud Victims appeared first on Chainalysis.
  • Open

    Hackers Publish Knicks and Madison Square Garden Data Online
    The data contains a list of "talent," including former Knicks players and coaches, and whether other celebrities are considered "Low Risk" or "High Risk." The data also contains emails between customers and MSG.
    Hackers Are Hijacking Entire Roblox Games Now
    Whereas Roblox hackers were previously focused on stealing players' high value items, some have taken over entire Roblox games, stealing their ownership and Robux in the process.
  • Open

    A Crash, Not a Shell: SolarWinds Serv-U CVE-2026-28318
    A single unauthenticated request can kill SolarWinds Serv-U, and the heap corruption underneath it looked like it could be more. Bishop Fox chased three separate roads to remote code execution and hit a wall on every one. Here is what we found, why it matters, and how to detect exposure safely.
  • Open

    “Free World Cup stream” sites are serving scams, not football
    We found dozens of fake World Cup streaming sites using football as bait to funnel visitors through a malicious advertising network.
    Cardiac patients’ medical data stolen and held to ransom
    Cardiac monitoring provider iRhythm has been hit by a data theft followed by an extortion attempt.
    Deepfake posting sites depicting famous women taken down by feds
    Thanks to Uncle Sam, anyone trying to find nonconsensual intimate deepfakes on CFake.com and SOCFake.com will be disappointed.
  • Open

    Infosec News Nuggets — June 16, 2026
    Cisco Fixes SD-WAN Manager Zero-Day Exploited in the Wild Cisco released patches for CVE-2026-20262, a zero-day in Catalyst SD-WAN Manager (formerly vManage) that has been actively exploited to escalate privileges to root, affecting all deployment types including on-prem, cloud-managed, and FedRAMP environments. The vulnerability stems from insufficient validation of user-supplied input during file uploads, allowing […] The post Infosec News Nuggets — June 16, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    CMMC & Higher Ed: What Tech Teams Need to Know Now | Dr. Dawn Dunkerley
    No content preview
  • Open

    Inside a malicious infrastructure delivering EtherRAT, phishing pages, and malicious software
    We found EtherRAT malware being distributed by a website with a strange homepage. Following the trail, we discovered a vast network of malicious infrastructures, distributing malware, malicious documents, remote desktop software, and phishing pages.
    Claude Fable 5 and Mythos 5 “abruptly disabled” after US gov. ban
    Anthropic has been ordered by the US government to cut off its newest Claude Fable 5 and Mythos 5 models for fear of abuse.
    Deepfake porn sites are going offline (re-air) (Lock and Code S07E12)
    This week on the Lock and Code podcast, we revisit an episode from 2024 with David Chiu that shows the progress made against deepfake porn.
    A week in security (June 8 – June 14)
    A list of topics we covered in the week of June 8 to June 14 of 2026
  • Open

    June 2026 Stealer Logs - 56,278,397 breached accounts
    In June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log records. The data also contained 124M unique passwords, which have been added to Pwned Passwords and are now searchable. Individuals can view any records captured against their email address in the stealer logs section of their dashboard. Organisations can see logs affecting their domain via the stealer logs API.
    Berkadia - 305,216 breached accounts
    In March 2026, the commercial real estate finance company Berkadia was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from Berkadia's Salesforce instance, including over 300k unique email addresses as well as names, physical addresses and phone numbers, among other data.
    Infinite Campus - 137,123 breached accounts
    In March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along with names, phone numbers, physical addresses and support tickets. Infinite Campus subsequently sent notifications, advising that the exposed data largely consisted of "names and contact information for school staff" and that "the majority is directory information commonly found on school websites".
  • Open

    Disclosure Day's Delusion Is That People Would Think Alien Videos Are Not AI
    The only plausible response to videos of aliens on television, at this point, would be cries of “that’s AI,” “fake,” and propaganda flowing in all directions.
    Judge Rules Blacked.com Can Sue Meta for Scraping Its Porn
    The judge found that Meta’s attempt to blame the pirating of thousands of Vixen.com and Tushy.com porn videos on rogue employees “strains credulity.”
    It Is Trivially Easy to Use Reddit to Manipulate AI Search, Research Suggests
    "We show that a tiny snippet—just 13 words—of retrieved text on a UGC website like Reddit, Wikipedia, Quora, or Facebook can change AI agents to output spam / scam content pretty consistently."
    The OPSEC Rave Wave (with Imani Thompson)
    We get into how platforms have tried to make surveillance cute, why that damn Duolingo owl emotionally manipulates you, and why learning about privacy best practices when surrounded by community works.
  • Open

    Spying Via Your Mobile Phone: Companies Can Locate Any Device at Any Time
    Citizen Lab doctoral fellow Swantje Lange spoke with Tagesspiegel about the Lab’s recent research on telecom surveillance campaigns. The post Spying Via Your Mobile Phone: Companies Can Locate Any Device at Any Time appeared first on The Citizen Lab.
  • Open

    Microsoft Defender email security benchmarking: Key insights from one year of data
    See how Microsoft Defender performed in one year of real-world email security benchmarking against SEG and ICES vendors. The post Microsoft Defender email security benchmarking: Key insights from one year of data appeared first on Microsoft Security Blog.
  • Open

    Infosec News Nuggets — June 15, 2026
    CISA Gives Feds 3 Days to Patch Ivanti Flaw Exploited in Attacks CISA issued Binding Operational Directive 26-04, mandating that federal agencies patch CVE-2026-10520 — a critical CVSS 10.0 authentication bypass in Ivanti Sentry — within three days after confirmed active exploitation in the wild. The vulnerability allows unauthenticated remote attackers to execute arbitrary commands […] The post Infosec News Nuggets — June 15, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    ContinuumCon 2026 - Day 3
    No content preview

  • Open

    📖 [The CloudSecList] Issue 342
    📖 [The CloudSecList] Issue 342 was originally published by Marco Lancini at CloudSecList on June 14, 2026.
  • Open

    ContinuumCon 2026 - Day 2
    No content preview
  • Open

    Scientists Discover Vast Ancient ‘Necropolis’ Teeming With Strange New Creatures
    A massive whale graveyard in the Indian Ocean contains the remains of hundreds of extinct whales dating back more than five million years, along with recent carcasses that support hotspots of seafloor life.

  • Open

    ContinuumCon 2026 - Day 1
    No content preview
    Payload Podcast 008 - Ryan Hausknecht
    No content preview
  • Open

    Attacking AI Video Processing | Patrick Double
    No content preview
  • Open

    Canada Finally Has a National AI Strategy. Experts Hate It.
    Senior fellow Cynthia Khoo writes that “pillars core to a functioning democracy are [being] reoriented around the false god of AI” in The Walrus.  The post Canada Finally Has a National AI Strategy. Experts Hate It. appeared first on The Citizen Lab.
    Who Watches the Watchers?
    Citizen Lab director Ron Deibert spoke to Politiken about the spyware industry, calling it “a symptom that something is fundamentally wrong.”  The post Who Watches the Watchers? appeared first on The Citizen Lab.
    Luis Fernando García On State Surveillance in Latin America
    Senior researcher Luis Fernando García participated in a Conversatorio Regional hosted by CELS, ODIA, Democracia en Red, and Vía Libre. The post Luis Fernando García On State Surveillance in Latin America appeared first on The Citizen Lab.
  • Open

    ‘You Will Not Speak on Flock Tonight’: County Commissioner Refuses to Let Residents Opposing Flock Speak at Meeting
    "I’ve spoken. I’m not debating this."
    Behind the Blog: World Cup Madness and Film Reviews
    This week, we discuss Trump fucking up the World Cup, some thoughts on ICE coverage, and movies.
  • Open

    Stolen iPhones could soon be worth a lot less to thieves
    Apple and the Met Police are working together to make stolen iPhones harder to reset, resell, and profit from.
    Fake verification pages are stealing Steam accounts from players
    A convincing fake FACEIT verification page is stealing Steam accounts by using a fake login window that looks completely legitimate.
  • Open

    Infosec News Nuggets — June 12, 2026
    Microsoft June 2026 Patch Tuesday Fixes 6 Zero-Days, 200 Flaws Microsoft’s June 2026 Patch Tuesday addressed a staggering 200 vulnerabilities, including five publicly disclosed zero-days and one being actively exploited in the wild. Among the most severe is CVE-2026-45657, a wormable Windows Kernel RCE rated CVSS 9.8 that allows remote, unauthenticated attackers to execute code […] The post Infosec News Nuggets — June 12, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Drupal Core CVE-2026-9082 Active Exploitation Confirmed Within Days of Disclosure
    Sensor Intel Series: June 2026 CVE Trends
  • Open

    Global Law Enforcement Dismantles ‘AudiA6’ Crypto Laundering Network Linked to Ransomware Gangs
    Summary An international coalition of law enforcement agencies, including the U.S. DOJ, Secret Service, Europol, CBZC, and others, dismantled “AudiA6,”… The post Global Law Enforcement Dismantles ‘AudiA6’ Crypto Laundering Network Linked to Ransomware Gangs appeared first on Chainalysis.
  • Open

    Software Update Automatically Turns off Amazon Delivery Drivers’ AC During Dangerous Summer Heat
    A new software update is turning off the AC in Amazon delivery vans after 10 minutes or 30 seconds under certain conditions.
  • Open

    Google can be liable for false AI Overviews, court rules
    "AI can make mistakes" isn't a good enough legal defense for defamatory or incorrect AI Overviews, a German court has ruled.
    VRChat says reported data breach never happened
    We explain what data was exposed, the potential risks, and the steps you should take now.
    Children’s phones must block nude images by September, UK says
    Apple and Google have three months to block nude images on children's phones. They're not allowed to collect any data while they do it.
  • Open

    Enabling Proper PCI Testing with Internal Penetration Tests
    PCI DSS v4.0.1 made internal penetration testing more complex, bringing cloud infrastructure, SaaS apps, and build pipelines explicitly into scope. Derek Rush breaks down how to scope a compliant IPT, what to test, and what a QSA-ready deliverable actually looks like in practice.
  • Open

    Infosec News Nuggets — June 11, 2026
    ServiceNow tells customers a bug left some of their data exposed to the internet Cloud platform giant ServiceNow has notified enterprise customers that a software bug was allowing unauthenticated users to access data stored in customer instances without requiring credentials. The flaw, patched on June 5, was caused by an API endpoint configured with authentication […] The post Infosec News Nuggets — June 11, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    University of Nottingham - 454,635 breached accounts
    In June 2026, the University of Nottingham was the target of a cyber attack, later linked to a ShinyHunters "pay or leak" extortion campaign. Tens of gigabytes of data were subsequently published online and included 455k unique email addresses along with extensive personal information including names, addresses, phone numbers, ethnicities, disabilities, passport numbers and information relating to academic enrolments and fee payments. In a post about the incident, the university advised that the breach affected both "current students, and alumni".
  • Open

    Ron Deibert Speaks About “Greek Watergate”
    Citizen Lab director Ron Deibert gave a keynote speech about the Greek spyware scandal at an event hosted by Eteron think tank in Athens in May. The post Ron Deibert Speaks About “Greek Watergate” appeared first on The Citizen Lab.
  • Open

    Weekly Threat Bulletin – June 10th, 2026
    These are the top threats you should know about this week.
  • Open

    Free Spotify Premium hacks on social media are spreading infostealers
    Cybercriminals are turning TikTok and Instagram Reels into malware delivery platforms, using free software tutorials to spread infostealers.
  • Open

    Turn specs into evals for any agent with ASSERT
    Adaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT) is an open-source framework for converting natural language behavior requirements into executable evaluations of AI models and agents. The post Turn specs into evals for any agent with ASSERT appeared first on Microsoft Security Blog.
  • Open

    AI Security at Machine Speed: A Roadmap for Modern AppSec
    With AI API calls set to grow 1,000x by 2027, you need a roadmap to secure your enterprise against agentic threats.
  • Open

    Infosec News Nuggets — June 10, 2026
    Self-replicating Miasma worm hits 73 Microsoft GitHub repositories in supply chain attack The Miasma worm has reached Microsoft’s own GitHub repositories, forcing GitHub to disable 73 repos across Azure, Azure-Samples, Microsoft, and MicrosoftDocs after the worm planted malicious code designed to harvest developer credentials. The attack exploited previously compromised contributor credentials — the same account […] The post Infosec News Nuggets — June 10, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Chainalysis and the Korean National Police Agency (KNPA) Sign MoU to Strengthen Virtual Asset Investigation Capabilities
    In April 2026, Chainalysis signed a Memorandum of Understanding (MoU) with the Korean National Police Agency (KNPA) to deepen cooperation… The post Chainalysis and the Korean National Police Agency (KNPA) Sign MoU to Strengthen Virtual Asset Investigation Capabilities appeared first on Chainalysis.
    체이널리시스와 대한민국 경찰청(KNPA), 디지털 자산 수사 역량 강화를 위한 양해각서(MoU) 체결
    오늘 체이널리시스는 대한민국 경찰청(KNPA)과 디지털 자산 범죄 수사 협력을 강화하기 위한 양해각서(MoU)를 체결했습니다. 이번 협약은 교육, 인증, 실무형 수사 프로그램… The post 체이널리시스와 대한민국 경찰청(KNPA), 디지털 자산 수사 역량 강화를 위한 양해각서(MoU) 체결 appeared first on Chainalysis.
    The Hidden Code Problem: How Unverified Smart Contracts Are Becoming a Preferred Target for Attackers
    Summary In the last six months, at least $36.7 million has been stolen from protocols whose source code was never… The post The Hidden Code Problem: How Unverified Smart Contracts Are Becoming a Preferred Target for Attackers appeared first on Chainalysis.
  • Open

    Submission to the Standing Senate Committee on National Security, Defence and Veterans Affairs of Bill C-8
    On May 25, senior research associate Kate Robertson appeared before SECD to testify on Bill C-8. The post Submission to the Standing Senate Committee on National Security, Defence and Veterans Affairs of Bill C-8 appeared first on The Citizen Lab.
  • Open

    Black Hat Stories | Jessica Oppenheimer, Director, SOC Integrations, Splunk Security
    No content preview
  • Open

    Reconstructing AI activity in investigations
    Learn how to investigate AI activity in Microsoft 365 Copilot and Azure AI services using a structured, telemetry-driven approach. This playbook helps security teams reconstruct events, assess data exposure, and detect potential threats faster. The post Reconstructing AI activity in investigations  appeared first on Microsoft Security Blog.
  • Open

    No Way Out? C2 Through AWS Data Perimeter via Bedrock-AgentCore - Dan Gansel
    No content preview
  • Open

    Mythos Doesn't Deploy Itself
    AI is raising the ceiling for skilled researchers and flooding bug bounty programs with polished but inaccurate submissions at the same time. Both things are true, and the reconciling variable is the harness built around the model and the expertise of the person driving it.
  • Open

    Infosec News Nuggets — June 9, 2026
    Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups — Check Point disclosed active exploitation of CVE-2026-50751 (CVSS 9.3), a logic flaw in certificate validation affecting Remote Access VPN and Mobile Access deployments using the deprecated IKEv1 protocol. The bug lets an unauthenticated remote attacker establish a VPN session without a valid […] The post Infosec News Nuggets — June 9, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Extending LLVM's BOLT-based Binary Analyser to Validate Stack Variable Initialisation
    The Open Source Technology Improvement Fund (OSTIF) commissioned Quarkslab to extend the BOLT-based static binary analyser in LLVM to support additional compiler flags for security hardening. This work resulted in the first iteration of a scanner for validating the implementation of -ftrivial-auto-var-init.
  • Open

    You Used to Call Me On My Shell Phone | Jacob Swinsinski
    No content preview
  • Open

    ICYMI: May 2026 @AWS Security
    Read all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered AI security, network protection, identity management, compliance frameworks, and supply chain security. Read […]  ( 112 min )
    Operationalizing AWS security: A maturity roadmap
    Enabling security tooling is the starting point. Making it operational—where findings drive decisions, response times are measurable, and your security posture improves week over week—is where most organizations struggle. This blog post provides a phased maturity roadmap for organizations that have already enabled AWS Security Hub and Amazon GuardDuty. These two services form the foundation […]  ( 118 min )
  • Open

    Infosec News Nuggets — June 8, 2026
    New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare — Security researchers at Calif have disclosed a novel denial-of-service technique, dubbed the HTTP/2 Bomb, that weaponizes two well-known mechanisms — HPACK header compression and Slowloris-style connection holding — in a previously unseen combination. Rather than stuffing large values into the […] The post Infosec News Nuggets — June 8, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Your Origin Server Might Be Your Most Expensive Decision
    No content preview

  • Open

    Get One Step Ahead at Black Hat 🚀
    No content preview
  • Open

    Baker Distributing - 102,935 breached accounts
    In May 2026, the HVAC/R wholesale distributor Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" site. In early June, the group publicly published data they claimed had been obtained from Baker's SharePoint and Salesforce infrastructure including 103k unique email addresses along with names, physical addresses, phone numbers and tickets relating to the company's HVAC contractor customer base. The exposed data was largely corporate contact and support information with limited sensitivity.

  • Open

    📖 [The CloudSecList] Issue 341
    📖 [The CloudSecList] Issue 341 was originally published by Marco Lancini at CloudSecList on June 07, 2026.
  • Open

    JHT Course Launch! Windows Maldev 6
    No content preview

  • Open

    AI Beyond Triage and Hunting | Chris Botelho
    No content preview
  • Open

    Building secure B2C applications with fine-grained access control using Amazon Cognito and Amazon Verified Permissions
    Modern web applications require robust security controls to protect user data and application resources. Authentication and authorization are two fundamental pillars of application security that answer critical questions: Who are you? and What are you allowed to do? Implementing these controls correctly can be challenging for developers, especially when building data-intensive applications with frameworks like […]  ( 114 min )
  • Open

    Inside the Black Hat community 💻
    No content preview
  • Open

    Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis
    A three-part vulnerability chain in UniFi OS Server lets an unauthenticated attacker bypass the auth gateway, hit a command injection sink, and escalate to root in a single request. Bishop Fox confirmed the chain end to end and breaks down the attack, the impact, and how to detect it safely.
  • Open

    Infosec News Nuggets — June 5, 2026
    Hackers Spied on a Stock Exchange Executive’s Outlook Mailbox for Five Months Unknown attackers spent at least five months quietly inside the Outlook mailbox of a senior executive at a major global stock exchange, exfiltrating the inbox in small, repeated batches and routing the stolen data through Dropbox and OneDrive so the traffic blended in […] The post Infosec News Nuggets — June 5, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    BCD Travel - 396,313 breached accounts
    In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other exposed data included names, addresses, phone numbers, job titles and employer names, spanning a variety of different data sets including leads, internal staff and support tickets.

  • Open

    From prompt to pwned: chaining LLM and web bugs to Admin
    During a Red Team exercise we were able to chain multiple LLM and web-based vulnerabilities to achieve admin account takeover from a low-privileged account. Trusting the LLM turned out to be the first falling domino of a long chain of events that lead to complete compromise. In this article we describe how it went down.
  • Open

    Amazon Cognito unlocks advanced capabilities with next-generation infrastructure
    Amazon Cognito recently introduced high-throughput performance for demanding workloads, customer-managed keys for full control over data encryption at rest, and multi- Region replication for business continuity improvement. These capabilities were made possible through a next-generation storage infrastructure designed for extensibility and scale. To deliver this, we migrated hundreds of millions of user profiles, and you […]  ( 110 min )
    Gain visibility into DDoS attacks with flow logs in AWS Shield Advanced
    Reconstructing distributed denial of service (DDoS) attack traffic used to mean combining data from multiple sources after the fact. AWS Shield Advanced attack flow logs change that—they capture traffic metadata during attacks so you can pinpoint sources, verify mitigations, and feed your existing analysis pipelines. Shield publishes logs to Amazon Simple Storage Service (Amazon S3), […]  ( 111 min )
    Customize federated sign-in with new Amazon Cognito Lambda trigger
    You can use Amazon Cognito user pools to add sign-up and sign-in functionality to your web and mobile applications. You can authenticate users directly with Amazon Cognito managed accounts using passwords, passwordless flows, or custom authentication flows, or let users federate in through external identity providers (IdP) using SAML, OpenID Connect, or social providers such […]  ( 119 min )
  • Open

    Black Hat Europe 2025 | From Live Exploitation to Zero-Day Discovery: Investigating Attacks on Gogs
    No content preview
    Black Hat Europe 2025 | Network Operations Center (NOC) Report
    No content preview
    Black Hat Europe 2025 | Weaponizing Image Scaling Against Production AI Systems
    No content preview
  • Open

    BIG SHOW TODAY & AI vibes
    No content preview
  • Open

    Putting CLIMATE into Practice: Building an Inventory Management Plan
    No content preview

  • Open

    Black Hat Europe 2025 | The Post-NVD Era: A Call for Global CVE Decentralization
    No content preview
    Why leaders in cybersecurity keep coming back to Black Hat
    No content preview
  • Open

    DentaQuest - 2,553,599 breached accounts
    In May 2026, the dental benefits administrator DentaQuest was the target of a ShinyHunters "pay or leak" extortion campaign that resulted in the group publicly publishing hundreds of gigabytes of data allegedly obtained from the company. The data included 2.6M unique email addresses along with names, addresses and phone numbers. Much of the data appeared in healthcare enrollment files (ASC X12 transaction sets) with some containing Medicaid IDs, while additional data appeared in member records and related files. DentaQuest acknowledged "a cybersecurity incident involving unauthorized access to a limited portion of our network", and advised they had contained the attack and mitigated the threat.
  • Open

    Topic Bridge
    CASI leaderboard shifts, and two incidents where AI was handed the keys.
    Weekly Threat Bulletin – June 3rd, 2026
    These are the top threats you should know about this week.
  • Open

    "Practical Android Software Protection in the Wild" - An Appetizer
    This article describes the main software protection techniques used in Android applications, organized around a taxonomy covering environment checks, obfuscation, and program loading abuse. It presents the results of a large-scale analysis of nearly 2.5 million Android apps, studying how widely these protections are adopted across different markets, app categories, and malware samples.
  • Open

    Are ANY hacking scenes actually good?
    No content preview
  • Open

    Otto Support - Testing MCP Servers
    MCP servers introduce a new attack surface, but the security fundamentals are familiar. In this final otto-support post, we use nmap, a Nuclei template, and MCP Inspector to discover, enumerate, and exploit an authorization gap without ever touching an LLM.
  • Open

    Optimize AI Inference: Real-Time NodeBalancers Metrics for AI Workloads
    No content preview
  • Open

    When One Vulnerability Cascades Across Cloud Infrastructure - Albin Vattakattu & Ryan Nolette
    No content preview
    Barbarians at the Gate: Visualizing and Blocking SDLC Infrastructure Threats with SITF - S Berkovich
    No content preview
    Transforming Security Incident Metadata to Security Outcomes - Cydney Stude & Steve de Vera
    No content preview
    A Hero’s Guide to Building a Cloud Security Program Without a 20-Person Guild - Steve Turner
    No content preview
    Schrödinger’s Detection: Finding the "Zombie" Rules in Your SIEM - Gowthamaraj
    No content preview
    Beyond the Checkbox: What Breaks When You Actually Stress-Test Cloud Incident Response - M Harvey
    No content preview
    Do Apps Have Imposter Syndrome? Unmasking Token Theft Campaigns - Shahar Dorfman & Sapir Federovsky
    No content preview
    One Architectural Sin, Two Clouds, and a Universal Attack Technique for Data Hijacking - Yahav
    No content preview
    Artificial Intelligence 🤝 Natural Stupidity - Brandon Sherman
    No content preview
    Beyond the Perimeter: Retrofitting VPC-SC at Enterprise Scale - Priya Puranik & Akshay Mahajan
    No content preview
    Data Perimeters: Beyond the Marketing - Matt Luttrell
    No content preview
    Paying More for Worse Security: An AWS Marketplace Horror Story - Corey Quinn
    No content preview

  • Open

    Black Hat Europe 2025 | You Win Some, You CheckSum: A Kerberos Delegation Vulnerability
    No content preview
  • Open

    Identify unused AWS KMS keys and prevent accidental key deletions
    As you scale your use of Amazon Web Services (AWS), managing KMS keys becomes increasingly important. Whether you manage a handful of keys or thousands across multiple AWS accounts and AWS Regions, there’s often a need to audit key usage to help you meet compliance requirements, evaluate your risk posture, and optimize key management costs. […]  ( 112 min )
    Secure multi-tenant AI agents with Amazon Bedrock AgentCore resource-based policies
    Software as a service (SaaS) providers building AI-powered applications on Amazon Bedrock AgentCore often need to serve multiple tenants with distinct security requirements from a shared infrastructure. Some tenants require cross-account access from their own Amazon Web Services (AWS) accounts, while others mandate that traffic stay within a private virtual private cloud (VPC) for regulatory […]  ( 114 min )
  • Open

    I made AI agents apply for my Security Team. Then I gave the agents access to AWS. - Cole Horsman
    No content preview
    Observing Escalation Paths in Kubernetes - William Taylor
    No content preview
  • Open

    Highlights from the Akamai India Partner Summit 2026
    No content preview
  • Open

    A Hacker's Way of Thinking (with Ted Harrington)
    No content preview

  • Open

    Chilling Effects of Trump’s War on Free Speech Extend Far Beyond Campus Walls – And That’s the Point
    Citizen Lab senior research fellow Jon Penney and co-author Bruce Schneier wrote an op-ed in The Conversation about chilling effects. The post Chilling Effects of Trump’s War on Free Speech Extend Far Beyond Campus Walls – And That’s the Point appeared first on The Citizen Lab.
  • Open

    Spring 2026 SOC 1, 2, and 3 reports are now available with 188 services in scope
    Amazon Web Services (AWS) is pleased to announce that the Spring 2026 System and Organization Controls (SOC) 1, 2, and 3 reports are now available. The reports cover 188 services over the 12-month period from April 1, 2025–March 31, 2026, giving customers a full year of assurance. These reports demonstrate our continuous commitment to adhering […]  ( 109 min )
  • Open

    A Linux Backdoor is For Sale on the Dark Web
    No content preview
  • Open

    Edmunds - 177,860 breached accounts
    In January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as having been breached. Data purportedly obtained in the incident was later published publicly and included 178k unique email addresses, usernames, passwords, IP addresses, phone numbers and vehicle-related records.

  • Open

    Scala Security Audit
    The Scala team has partnered with the Open Source Technology Improvement Fund (OSTIF) to conduct its first security audit. This initiative aims to identify potential vulnerabilities through static and dynamic analysis and provide greater confidence in Scala. The security audit conducted by Quarkslab is particularly focused on Scala 3.

  • Open

    Atlas Menu - 63,926 breached accounts
    In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresses along with usernames, IP addresses, support tickets and passwords stored as bcrypt hashes.
  • Open

    📖 [The CloudSecList] Issue 340
    📖 [The CloudSecList] Issue 340 was originally published by Marco Lancini at CloudSecList on May 31, 2026.
  • Open

    ContinuumCon Teaser: solst/ice, Zack Korman, & Spencer Alessi!!
    No content preview

  • Open

    Unmasking Romance Scams with OSINT | Mishaal Khan
    No content preview
  • Open

    Black Hat Europe 2025 | Flaw And Order: Finding The Needle In The Haystack Of CodeQL Using LLMs
    No content preview
  • Open

    Researchers Uncover Espionage in Mobile Networks
    Swantje Lange spoke with the Hasso Plattner Institut about sophisticated surveillance campaigns being used to exploit mobile networks. The post Researchers Uncover Espionage in Mobile Networks appeared first on The Citizen Lab.
  • Open

    Looting UniFi Controllers: Detecting and Weaponizing CVE-2026-22557
    A CVSS 10.0 path traversal in UniFi Network Application lets unauthenticated attackers read controller backups, extract credentials, and take over every managed device on the network. Bishop Fox breaks down the attack paths, the preconditions, and a safe detection tool to check your exposure.
  • Open

    Payload Podcast 007 with Andy Piazza (klrgrz)
    No content preview

  • Open

    Why and how to migrate to a Transit Gateway-attached AWS Network Firewall
    AWS Network Firewall now supports native attachment to AWS Transit Gateway. Customers commonly use Transit Gateway to route traffic from Amazon Virtual Private Cloud (Amazon VPC) networks to a centralized inspection VPC (a VPC dedicated to hosting firewall endpoints for traffic inspection) where their network firewall endpoints are deployed. This centralized deployment model reduces the […]  ( 115 min )
    Simplifying policy management with URL and Domain Category filtering on AWS Network Firewall
    Network administrators face a persistent challenge: maintaining domain blocklists and allowlists that keep pace with the internet. New websites and services emerge daily, and keeping these lists current requires constant manual updates that leave gaps in coverage. This challenge intensifies when managing access to rapidly evolving categories like AI services, where new tools launch on […]  ( 117 min )
  • Open

    Charter - 4,851,517 breached accounts
    In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group later published the data, which exposed 4.9M unique email addresses along with names, phone numbers and physical addresses. A subset of approximately 85k records originating from an internal employee directory also included job titles. Charter confirmed the incident, but stated that no sensitive personal information or customer proprietary network information (CPNI) was exfiltrated.
    Kemper - 269,299 breached accounts
    In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign. The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign targeting hundreds of organisations using the same method. The group later published tens of gigabytes of data they claimed included internal directory data, Salesforce records and Stripe payment logs. Among the 269k unique email addresses were names, phone numbers, physical addresses and partial payment card data including the last 4 digits, expiry dates and card brands. Kemper confirmed the incident and stated they had engaged third-party cybersecurity experts and notified law enforcement.
  • Open

    Consistent Protections Without Compromise: Akamai’s WAF Is Now on AWS Marketplace
    No content preview

  • Open

    The Small Model Cliff
    CASI Leaderboard, Bias Jailbreak, and Three Coordinated Supply Chain Incidents
    Weekly Threat Bulletin – May 27th, 2026
    These are the top threats you should know about this week.
  • Open

    Google served me Malware
    No content preview
  • Open

    Distributed AI Inference: Why Placement Is the New Bottleneck
    In real AI systems, bottlenecks don't disappear, they move. Learn about why inference placement, not raw compute, is the decisive infrastructure question.
  • Open

    Mytheresa - 84,108 breached accounts
    In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group. After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The exposed data also included names, phone numbers, physical addresses, purchases and partial credit card data including card type, last 4 digits and expiry date.

  • Open

    Ameriprise - 502,597 breached accounts
    In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePoint infrastructure, and subsequently published the data after negotiations allegedly failed. The published data contained 500k unique email addresses as well as names, phone numbers, physical addresses and employer information. In their disclosure to state attorneys general, Ameriprise reported 47,876 affected people; the larger email address population represents contacts from Ameriprise's broader operational systems, including internal staff. Ameriprise further advised that they have "implemented heightened monitoring of your account(s) to include enhanced identity verification procedures".
  • Open

    Payload Podcast 007 with Andy Piazza (klrgrz)
    No content preview
  • Open

    Welcoming the AWS Customer Incident Response Team
    May 26, 2026: This post was originally published in July 2022. It has been updated to reflect current engagement options, new threat intelligence resources such as the Threat Technique Catalog for AWS (TTC), additional open-source tools, and the distinction between AWS CIRT support and the AWS Security Incident Response managed service. Welcome back, or welcome […]  ( 110 min )
    Well-architected best practices for software supply chain security
    There have been multiple notable supply chain attacks using the npm Registry since September: Shai-Hulud, Chalk/Debug, one abusing tea.xyz tokens, and recently axios. Thanks to community efforts involving the Amazon Inspector team, the Open Source Security Foundation, and others, the affected packages were quickly flagged, which reduced the impact of these incidents. Supply chain attacks […]  ( 115 min )
  • Open

    Introducing Password-Less Provisioning and Atomic Customization for VMs
    Akamai Cloud introduces password-less provisioning and atomic customization. Align with Zero Trust by eliminating root passwords and hardening VMs at creation.
  • Open

    Sparkplug B Protocol Fuzzing with AI Assistance
    Sparkplug B is the dominant protocol in ICS and SCADA environments, but no public security fuzzer existed for it until now. Bishop Fox used AI-assisted development to build one from scratch, covering all 9 message types, 19 data types, and 87+ field paths from the full specification.

  • Open

    Trump Wants to Tap Your Phone. Ottawa Might Let Him.
    Senior research associate Kate Robertson discusses the risks Bill C-22 poses for future data-sharing agreements with foreign law enforcement agencies. The post Trump Wants to Tap Your Phone. Ottawa Might Let Him. appeared first on The Citizen Lab.
  • Open

    Hack the Notes: Exploring Pen-Test Documentation | Christian Duncan
    No content preview

  • Open

    7-Eleven - 185,256 breached accounts
    In April 2026, 7-Eleven was the victim of a "pay or leak" extortion campaign by ShinyHunters, with the data later published that month. The incident exposed 185k unique email addresses, along with names, physical addresses, dates of birth and phone numbers. A small number of records also contained additional exposed data fields. The company later advised the breach was limited to "certain 7-Eleven systems used to store franchisee documents", a statement consistent with the exposed data.

  • Open

    📖 [The CloudSecList] Issue 339
    📖 [The CloudSecList] Issue 339 was originally published by Marco Lancini at CloudSecList on May 24, 2026.

  • Open

    Detecting CVE-2026-0265 at Scale: PAN-OS CAS Authentication Bypass
    CVE-2026-0265 lets unauthenticated attackers forge a JWT and log in as any trusted user on CAS-enabled PAN-OS deployments. Bishop Fox built a detection tool that returns a definitive verdict from a single anonymous request, and breaks down exactly how the bug works and what to do about it.
    CVE-2026-27886: Unauthenticated Boolean-Oracle Exfiltration of Administrator Secrets in Strapi
    A sanitization bypass in Strapi 4.0.0 through 5.36.1 lets unauthenticated attackers extract an admin's password reset token character by character and take over the account. With over 20,000 internet-facing hosts exposed, Bishop Fox breaks down how the exploit works and how to remediate it.
  • Open

    Deserialization payloads for exploits w/ GO-based .NET & Java gadget generation | Jonathan Peterson
    No content preview

  • Open

    Decentralized Threat: Stealthy P2P Cryptominer Targeting Ollama Endpoints
    The Akamai SIRT uncovered a custom P2P Trojan masquerading as system activity. Learn how to detect and mitigate this stealthy Go-based cryptominer.
    Secure Identity at the Edge: Akamai Partners with Auth0
    The Akamai and Auth0 partnership secures identity at the edge by combining edge intelligence and adaptive authentication to stop fraud and enhance user trust.
    CVE-2026-9082: Mitigating a Critical SQL Injection Vulnerability in Drupal
    Learn how the complex Drupal SQLi vulnerability (CVE-2026-9082) exploits PostgreSQL environments and its data theft risks — and how to ensure you’re protected.
  • Open

    AWS KY3P report now available for third-party supplier due diligence
    We’re excited to announce that Amazon Web Services (AWS) has completed the S&P Global Know Your Third Party (KY3P) assessment of its security posture. This assessment demonstrates our continued commitment to meet the heightened expectations of cloud service providers. Customers can now use the AWS KY3P assessment to reduce their supplier due diligence burden. KY3P, […]  ( 107 min )
    Automating identity lifecycle and security with AWS Directory Service APIs
    Managing identities and access across complex environments has become more critical than ever. AWS Directory Service for Managed Microsoft Active Directory, also known as AWS Managed Microsoft AD, has added new capabilities to manage users and groups. Now, you can perform create, read, update, and delete (CRUD) operations on users and groups directly through AWS […]  ( 112 min )
  • Open

    Dragonica Lunaris - 126,293 breached accounts
    In December 2025, the European Dragonica private server Dragonica Lunaris suffered a data breach. The incident exposed 126k email addresses, usernames, dates of birth and bcrypt password hashes. The service operator confirmed the breach and advised it has since been fixed.
    Windows93 / Myspace93 - 46,105 breached accounts
    In January 2021, the parody site Windows93 suffered a data breach of the Myspace93 sub-site after a beta application was exploited to download server files. The compromised data was later leaked in June and included 46k Myspace93 accounts containing email and IP addresses, usernames and passwords stored in plain text.

  • Open

    Why Policy in Amazon Bedrock AgentCore chose Cedar for securing agentic workflows
    Agents have agency: they adapt and find multiple ways to solve problems. This autonomy creates a fundamental security challenge: the large language model (LLM) at the heart of the agent is non-deterministic, and its decisions can’t be predicted or guaranteed in advance. It can hallucinate harmful actions with complete confidence. It’s vulnerable to prompt injection […]  ( 115 min )
  • Open

    Weekly Threat Bulletin – May 20th, 2026
    These are the top threats you should know about this week.
2026-06-19T04:21:20.649Z osmosfeed 1.15.1