Press "Enter" to skip to content

OSINT / CyberSec report 25.06.2026 00:07

1. Threat actors are actively exploiting a critical vulnerability in Cisco Unified Communications Manager tracked as CVE-2026-20230 to achieve remote file writes (thehackernews.com).

2. The FortiBleed campaign has targeted over 430,000 FortiGate firewalls globally to harvest approximately 110 million credentials (thehackernews.com).

3. Two members of the Scattered Spider cybercrime group pleaded guilty to charges related to the 2024 cyberattack on Transport for London (bleepingcomputer.com).

4. Tata Electronics confirmed a cyberattack that resulted in the unauthorized exfiltration of internal data (bleepingcomputer.com).

5. Healthcare technology firm Xsolis suffered a data breach impacting 1.4 million individuals following a successful phishing attack (bleepingcomputer.com).

6. LastPass confirmed that customer data was accessed via its Salesforce environment after attackers stole OAuth tokens in a supply chain attack against Klue (bleepingcomputer.com).

7. A new macOS ClickFix campaign is using malicious disk images and Terminal commands to silently deploy information-stealing malware (bleepingcomputer.com).

8. An active phishing campaign targeting WhatsApp users across multiple countries is distributing VBScript files to install remote monitoring and management tools (thehackernews.com).

9. Researchers identified malicious npm packages posing as PostCSS tools that deliver a Windows-based remote access trojan (thehackernews.com).

10. The U.S. Department of Justice seized a cloud computing account used by subsidiaries of the HuiOne Group to facilitate cyber scam money laundering (thehackernews.com).

11. Unit 42 reported that malicious skills in the OpenClaw marketplace are bypassing automated scanners to deploy infostealers and execute financial fraud (unit42.paloaltonetworks.com).

12. A DPRK-linked backdoor named macOS.Gaslight uses prompt injection techniques to spoof LLM triage harnesses and hide credential stealing activities (sentinelone.com).

13. Four vulnerabilities in the Dify AI platform allow attackers to wiretap and exfiltrate sensitive AI chat histories (darkreading.com).

14. A hacker hijacked the national alert system in Brazil to broadcast messages to millions of mobile devices (bitdefender.com).

15. Anthropic confirmed that the guardrails for its Fable 5 AI model were bypassed by jailbreak attempts shortly after release (schneier.com).

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *