<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security Feed — BLACKMESA.CA</title>
    <link>https://news.blackmesa.ca</link>
    <description>Aggregated cybersecurity news, advisories, and threat intelligence.</description>
    <language>en-ca</language>
    <lastBuildDate>Thu, 04 Jun 2026 20:40:58 +0000</lastBuildDate>
    <ttl>240</ttl>
    <atom:link href="https://news.blackmesa.ca/feed.xml" rel="self" type="application/rss+xml"/>
    <image>
      <url>https://blackmesa.ca/favicon.svg</url>
      <title>BLACKMESA.CA Security Feed</title>
      <link>https://news.blackmesa.ca</link>
    </image>
  <item>
    <title><![CDATA[Name That Toon Contest]]></title>
    <link>https://www.darkreading.com/events/celebrate-20-years-of-dark-reading-name-that-toon-contest</link>
    <guid isPermaLink="true">https://www.darkreading.com/events/celebrate-20-years-of-dark-reading-name-that-toon-contest</guid>
    <pubDate>Fri, 26 Jun 2026 11:00:00 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[DentaQuest data breach exposed info of 2.6 million accounts]]></title>
    <link>https://www.bleepingcomputer.com/news/security/dentaquest-data-breach-exposed-info-of-26-million-accounts/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/dentaquest-data-breach-exposed-info-of-26-million-accounts/</guid>
    <pubDate>Thu, 04 Jun 2026 18:36:27 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <category>Breach</category>
    <description><![CDATA[A data breach at the dental benefits administrator DentaQuest has reportedly exposed the sensitive data of 2.6 million accounts.]]></description>
  </item>
  <item>
    <title><![CDATA[Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones]]></title>
    <link>https://www.wired.com/story/meta-smart-glasses-face-recognition-nametag-connections/</link>
    <guid isPermaLink="true">https://www.wired.com/story/meta-smart-glasses-face-recognition-nametag-connections/</guid>
    <pubDate>Thu, 04 Jun 2026 17:28:11 +0000</pubDate>
    <source>Wired Security</source>
    <category>Media</category>
    <category>Privacy</category>
    <description><![CDATA[Code reviewed by WIRED uncovered an unreleased face-recognition system embedded in Meta’s smart glasses platform. It’s designed to identify people via biometric data stored on users’ phones.]]></description>
  </item>
  <item>
    <title><![CDATA[Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public]]></title>
    <link>https://thehackernews.com/2026/06/cisco-patches-cve-2026-20230-in-unified.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/cisco-patches-cve-2026-20230-in-unified.html</guid>
    <pubDate>Thu, 04 Jun 2026 16:55:51 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>CVE</category>
    <category>Vuln</category>
    <category>Research</category>
    <description><![CDATA[Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root. It is tracked as CVE-2026-20230, and proof-of-concept…]]></description>
  </item>
  <item>
    <title><![CDATA[UN food agency discloses breach affecting 600,000 Gaza households]]></title>
    <link>https://www.bleepingcomputer.com/news/security/un-world-food-programme-breach-affects-600-000-gaza-households/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/un-world-food-programme-breach-affects-600-000-gaza-households/</guid>
    <pubDate>Thu, 04 Jun 2026 16:38:49 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <category>Breach</category>
    <description><![CDATA[The United Nations' World Food Programme (WFP), the world's largest humanitarian organization, revealed over the weekend that its self-registration application (SRA) for Palestine was breached.]]></description>
  </item>
  <item>
    <title><![CDATA[New IronWorm malware hits 36 packages in npm supply-chain attack]]></title>
    <link>https://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/</guid>
    <pubDate>Thu, 04 Jun 2026 15:25:37 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <category>Malware</category>
    <description><![CDATA[A new supply-chain attack has infected 36 packages on the Node Package Manager (npm) index with infostealer malware called IronWorm.]]></description>
  </item>
  <item>
    <title><![CDATA[Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories]]></title>
    <link>https://thehackernews.com/2026/06/claude-code-github-action-flaw-let-one.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/claude-code-github-action-flaw-let-one.html</guid>
    <pubDate>Thu, 04 Jun 2026 15:15:26 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Research</category>
    <description><![CDATA[A security researcher found a flaw in Anthropic's Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because…]]></description>
  </item>
  <item>
    <title><![CDATA[Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It]]></title>
    <link>https://thehackernews.com/2026/06/agentic-ai-is-transforming-defense-but.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/agentic-ai-is-transforming-defense-but.html</guid>
    <pubDate>Thu, 04 Jun 2026 15:10:00 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <description><![CDATA[Over the past several weeks, the cybersecurity community has been reminded how quickly frontier and agentic AI in defense networks can challenge our assumptions. When Anthropic's Claude Mythos model was made available…]]></description>
  </item>
  <item>
    <title><![CDATA[Proofpoint Warns TA4922 Deploys Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT]]></title>
    <link>https://cybersecuritynews.com/proofpoint-warns-ta4922-deploys-atlas-rat/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/proofpoint-warns-ta4922-deploys-atlas-rat/</guid>
    <pubDate>Thu, 04 Jun 2026 15:09:02 +0000</pubDate>
    <source>Cyber Security News</source>
    <category>News</category>
    <category>Malware</category>
    <description><![CDATA[A sophisticated cybercrime group known as TA4922 is raising alarms across the global security community. The group has been deploying a growing arsenal of malware, including Atlas RAT, RomulusLoader, SilentRunLoader…]]></description>
  </item>
  <item>
    <title><![CDATA[Bugcrowd Launches EU Data Residency Option For Evolving Data Sovereignty Needs]]></title>
    <link>https://www.darkreading.com/cyber-risk/bugcrowd-launches-eu-data-residency-option-for-evolving-data-sovereignty-needs</link>
    <guid isPermaLink="true">https://www.darkreading.com/cyber-risk/bugcrowd-launches-eu-data-residency-option-for-evolving-data-sovereignty-needs</guid>
    <pubDate>Thu, 04 Jun 2026 14:22:20 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <description><![CDATA[Organizations are growing serious about what nation’s rules apply to their data. Experts point to geopolitical tensions as a main contributing factor.]]></description>
  </item>
  <item>
    <title><![CDATA[Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook]]></title>
    <link>https://www.bleepingcomputer.com/news/security/hackers-are-after-the-gaps-in-your-vulnerability-program-heres-their-playbook/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/hackers-are-after-the-gaps-in-your-vulnerability-program-heres-their-playbook/</guid>
    <pubDate>Thu, 04 Jun 2026 14:01:11 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <category>Vuln</category>
    <description><![CDATA[Threat actors are actively teaching newcomers how to find, exploit, and profit from vulnerable systems. Flare explores what a popular underground hacking tutorial reveals about modern attacker workflows.]]></description>
  </item>
  <item>
    <title><![CDATA[ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories]]></title>
    <link>https://thehackernews.com/2026/06/threatsday-bulletin-ai-agents-gone.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/threatsday-bulletin-ai-agents-gone.html</guid>
    <pubDate>Thu, 04 Jun 2026 14:00:49 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <description><![CDATA[It got stupid again. The internet still feels held together with tape. Bad plugins, old bugs, fake tools, trusted apps doing shady things. Same mess, new wrapper. And now the weird stuff is normal. Forums go down and…]]></description>
  </item>
  <item>
    <title><![CDATA[How the “Swiss Cheese” model can help you choose the right MDR provider]]></title>
    <link>https://www.rapid7.com/blog/post/dr-swiss-cheese-model-helps-choose-mdr-providers</link>
    <guid isPermaLink="true">https://www.rapid7.com/blog/post/dr-swiss-cheese-model-helps-choose-mdr-providers</guid>
    <pubDate>Thu, 04 Jun 2026 13:53:41 +0000</pubDate>
    <source>Rapid7 Blog</source>
    <category>Research</category>
    <description><![CDATA[Not all managed detection and response (MDR) solutions are equal. Finding the differences between vendors can be quite hard, and then understanding how those differences impact your business can be even harder. For…]]></description>
  </item>
  <item>
    <title><![CDATA[Weaponized ChatGPT Download Site Delivers Malware Via Sponsored Search Results]]></title>
    <link>https://cybersecuritynews.com/weaponized-chatgpt-download-site-delivers-malware/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/weaponized-chatgpt-download-site-delivers-malware/</guid>
    <pubDate>Thu, 04 Jun 2026 13:46:12 +0000</pubDate>
    <source>Cyber Security News</source>
    <category>News</category>
    <category>Vuln</category>
    <category>Malware</category>
    <category>Research</category>
    <description><![CDATA[A new malvertising campaign is exploiting ChatGPT’s popularity by promoting a weaponized fake download site via sponsored search results, delivering malware to both Windows and macOS users. Security researchers from…]]></description>
  </item>
  <item>
    <title><![CDATA[Microsoft blames unexpected Windows driver updates on caching issue]]></title>
    <link>https://www.bleepingcomputer.com/news/microsoft/microsoft-blames-unexpected-windows-driver-updates-on-caching-issue/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/microsoft/microsoft-blames-unexpected-windows-driver-updates-on-caching-issue/</guid>
    <pubDate>Thu, 04 Jun 2026 13:41:42 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <description><![CDATA[On Wednesday, Microsoft fixed an issue that caused some Windows devices to install driver updates without notice despite policies configured to prevent auto-updates.]]></description>
  </item>
  <item>
    <title><![CDATA[Kali365 PhaaS Operation Expands Beyond Microsoft 365 to Target Okta and MAX Messenger]]></title>
    <link>https://cybersecuritynews.com/kali365-phaas-operation-expands-beyond-microsoft-365/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/kali365-phaas-operation-expands-beyond-microsoft-365/</guid>
    <pubDate>Thu, 04 Jun 2026 13:01:57 +0000</pubDate>
    <source>Cyber Security News</source>
    <category>News</category>
    <category>Phishing</category>
    <description><![CDATA[A new and fast-growing phishing operation is making waves in the cybersecurity world, and it is moving far beyond its original targets. Kali365, a phishing-as-a-service (PhaaS) platform first spotted in April 2026, was…]]></description>
  </item>
  <item>
    <title><![CDATA[Payouts King Ransomware Evades EDR With Obfuscation and Direct System Calls]]></title>
    <link>https://cybersecuritynews.com/payouts-king-ransomware-evades-edr/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/payouts-king-ransomware-evades-edr/</guid>
    <pubDate>Thu, 04 Jun 2026 12:51:47 +0000</pubDate>
    <source>Cyber Security News</source>
    <category>News</category>
    <category>Ransom</category>
    <description><![CDATA[A new ransomware group known as Payouts King has quietly been building a reputation since it first appeared in April 2025. While it spent most of last year flying under the radar, early 2026 brought a noticeable spike…]]></description>
  </item>
  <item>
    <title><![CDATA[Police dismantles fake ID marketplace used by migrant smugglers]]></title>
    <link>https://www.bleepingcomputer.com/news/security/police-dismantles-fake-id-marketplace-used-by-migrant-smugglers/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/police-dismantles-fake-id-marketplace-used-by-migrant-smugglers/</guid>
    <pubDate>Thu, 04 Jun 2026 12:29:12 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <description><![CDATA[French and Spanish authorities took down an online marketplace selling fake identity documents to migrant smuggling rings operating within the European Union.]]></description>
  </item>
  <item>
    <title><![CDATA[China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa]]></title>
    <link>https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html</guid>
    <pubDate>Thu, 04 Jun 2026 12:22:25 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Phishing</category>
    <description><![CDATA[A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa. These efforts have been complemented by a "rapid…]]></description>
  </item>
  <item>
    <title><![CDATA[Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code]]></title>
    <link>https://cybersecuritynews.com/wordpress-plugin-vulnerability-exploit/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/wordpress-plugin-vulnerability-exploit/</guid>
    <pubDate>Thu, 04 Jun 2026 12:01:36 +0000</pubDate>
    <source>Cyber Security News</source>
    <category>News</category>
    <category>Vuln</category>
    <description><![CDATA[Hackers are actively exploiting a critical remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin, allowing unauthenticated attackers to inject and execute arbitrary PHP code on vulnerable…]]></description>
  </item>
  <item>
    <title><![CDATA[NAVTOR NavBox]]></title>
    <link>https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-01</link>
    <guid isPermaLink="true">https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-01</guid>
    <pubDate>Thu, 04 Jun 2026 12:00:00 +0000</pubDate>
    <source>CISA Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <category>Vuln</category>
    <description><![CDATA[View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to gain unauthorized access to SOAP methods, resulting in a disruption of operations. The following versions of NAVTOR NavBox…]]></description>
  </item>
  <item>
    <title><![CDATA[Hitachi Energy MACH HiDraw]]></title>
    <link>https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-05</link>
    <guid isPermaLink="true">https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-05</guid>
    <pubDate>Thu, 04 Jun 2026 12:00:00 +0000</pubDate>
    <source>CISA Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <category>Vuln</category>
    <description><![CDATA[View CSAF Summary Hitachi Energy is aware of a buffer overflow vulnerability that affects MACH HiDraw product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer…]]></description>
  </item>
  <item>
    <title><![CDATA[Hitachi Energy ITT600 Explorer]]></title>
    <link>https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-02</link>
    <guid isPermaLink="true">https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-02</guid>
    <pubDate>Thu, 04 Jun 2026 12:00:00 +0000</pubDate>
    <source>CISA Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <category>Vuln</category>
    <category>DoS</category>
    <description><![CDATA[View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect ITT600 Explorer product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on…]]></description>
  </item>
  <item>
    <title><![CDATA[B&R PPT30 Operating System]]></title>
    <link>https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-03</link>
    <guid isPermaLink="true">https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-03</guid>
    <pubDate>Thu, 04 Jun 2026 12:00:00 +0000</pubDate>
    <source>CISA Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <category>Vuln</category>
    <description><![CDATA[View CSAF Summary B&R is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploits this vulnerability could make the OPC-UA server of the product…]]></description>
  </item>
  <item>
    <title><![CDATA[Hitachi Energy RTU500]]></title>
    <link>https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-04</link>
    <guid isPermaLink="true">https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-04</guid>
    <pubDate>Thu, 04 Jun 2026 12:00:00 +0000</pubDate>
    <source>CISA Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <category>Vuln</category>
    <description><![CDATA[View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect RTU500 product versions listed in this document. If exploited, these vulnerabilities primarily impact product availability, with potential…]]></description>
  </item>
  <item>
    <title><![CDATA[Teams and Google Drive Leveraged to Compromise Systems Within 20 Minutes]]></title>
    <link>https://cybersecuritynews.com/microsoft-teams-and-google-drive-abused/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/microsoft-teams-and-google-drive-abused/</guid>
    <pubDate>Thu, 04 Jun 2026 11:55:45 +0000</pubDate>
    <source>Cyber Security News</source>
    <category>News</category>
    <category>Malware</category>
    <description><![CDATA[Hackers are increasingly abusing trusted enterprise platforms such as Microsoft Teams and Google Drive to deploy stealthy remote access malware, with a newly observed campaign leveraging social engineering and…]]></description>
  </item>
  <item>
    <title><![CDATA[Travel scams are everywhere. Here&#8217;s how to avoid them]]></title>
    <link>https://www.malwarebytes.com/blog/scams/2026/06/travel-scams-are-everywhere-heres-how-to-avoid-them</link>
    <guid isPermaLink="true">https://www.malwarebytes.com/blog/scams/2026/06/travel-scams-are-everywhere-heres-how-to-avoid-them</guid>
    <pubDate>Thu, 04 Jun 2026 11:28:12 +0000</pubDate>
    <source>Malwarebytes Labs</source>
    <category>Threat Intel</category>
    <description><![CDATA[Planning a holiday should be exciting, fun, and not a cybersecurity risk. But booking flights, hotels, and rental properties often means sharing sensitive personal and financial information across multiple platforms…]]></description>
  </item>
  <item>
    <title><![CDATA[FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads]]></title>
    <link>https://thehackernews.com/2026/06/fluttershell-backdoor-spreads-to-macos.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/fluttershell-backdoor-spreads-to-macos.html</guid>
    <pubDate>Thu, 04 Jun 2026 11:19:53 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Malware</category>
    <category>Research</category>
    <description><![CDATA[Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called FlutterShell. According to Palo Alto Networks Unit 42, the campaign is said…]]></description>
  </item>
  <item>
    <title><![CDATA[Cisco warns of critical Unified CM flaw with PoC exploit code]]></title>
    <link>https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-unified-cm-flaw-with-poc-exploit-code/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-unified-cm-flaw-with-poc-exploit-code/</guid>
    <pubDate>Thu, 04 Jun 2026 11:09:50 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <category>Vuln</category>
    <category>Research</category>
    <description><![CDATA[Cisco has released security updates to patch a critical-severity Unified Communications Manager (Unified CM) flaw that allows attackers to gain root privileges.]]></description>
  </item>
  <item>
    <title><![CDATA[Hacking Meta’s AI Chatbot]]></title>
    <link>https://www.schneier.com/blog/archives/2026/06/hacking-metas-ai-chatbot.html</link>
    <guid isPermaLink="true">https://www.schneier.com/blog/archives/2026/06/hacking-metas-ai-chatbot.html</guid>
    <pubDate>Thu, 04 Jun 2026 11:04:09 +0000</pubDate>
    <source>Schneier on Security</source>
    <category>Media</category>
    <description><![CDATA[Hackers are convincing Meta’s AI support chatbot to let them take over other peoples’ accounts: A video posted on X showed the step-by-step process to hack someone’s Instagram account. The hacker allegedly used a VPN to…]]></description>
  </item>
  <item>
    <title><![CDATA[Comodo Internet Security 0-Day Vulnerability Lets Attacker Crash the User’s Windows System]]></title>
    <link>https://cybersecuritynews.com/comodo-internet-security-0-day-vulnerability/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/comodo-internet-security-0-day-vulnerability/</guid>
    <pubDate>Thu, 04 Jun 2026 10:30:21 +0000</pubDate>
    <source>Cyber Security News</source>
    <category>News</category>
    <category>Vuln</category>
    <description><![CDATA[An unpatched zero-day vulnerability in Comodo Internet Security’s firewall driver, Inspect.sys, after receiving no response from the vendor following multiple disclosure attempts. The vulnerability, dubbed ComoDoS…]]></description>
  </item>
  <item>
    <title><![CDATA[Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS]]></title>
    <link>https://thehackernews.com/2026/06/fake-sites-mimicking-open-source-tools.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/fake-sites-mimicking-open-source-tools.html</guid>
    <pubDate>Thu, 04 Jun 2026 09:51:28 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Malware</category>
    <category>Research</category>
    <description><![CDATA[Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families…]]></description>
  </item>
  <item>
    <title><![CDATA[Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months]]></title>
    <link>https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html</guid>
    <pubDate>Thu, 04 Jun 2026 09:33:57 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <description><![CDATA[Unknown attackers spent at least five months inside the Outlook mailbox of a senior executive at a major global stock exchange, copying the inbox out in small, repeated batches and routing it through Dropbox and…]]></description>
  </item>
  <item>
    <title><![CDATA[Cisco Unified Communications Manager Vulnerability Exposed Along With PoC Exploit Code]]></title>
    <link>https://cybersecuritynews.com/cisco-unified-communications-manager-vulnerability/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/cisco-unified-communications-manager-vulnerability/</guid>
    <pubDate>Thu, 04 Jun 2026 09:16:19 +0000</pubDate>
    <source>Cyber Security News</source>
    <category>News</category>
    <category>CVE</category>
    <category>Vuln</category>
    <category>Research</category>
    <description><![CDATA[Cisco has disclosed a critical server-side request forgery (SSRF) vulnerability in its Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME). Tracked as CVE-2026-20230, with…]]></description>
  </item>
  <item>
    <title><![CDATA[Meta&#8217;s AI support bot happily handed Instagram accounts to hackers]]></title>
    <link>https://www.malwarebytes.com/blog/ai/2026/06/metas-ai-support-bot-happily-handed-instagram-accounts-to-hackers</link>
    <guid isPermaLink="true">https://www.malwarebytes.com/blog/ai/2026/06/metas-ai-support-bot-happily-handed-instagram-accounts-to-hackers</guid>
    <pubDate>Thu, 04 Jun 2026 09:09:09 +0000</pubDate>
    <source>Malwarebytes Labs</source>
    <category>Threat Intel</category>
    <description><![CDATA[Customer service chatbots have one job: get the user what they’re asking for without bothering a human. Meta’s new AI support assistant took that brief a little too seriously. Over the past few months, attackers have…]]></description>
  </item>
  <item>
    <title><![CDATA[CISA Warns of Android Framework Integer Overflow Vulnerability Exploited in Attacks]]></title>
    <link>https://cybersecuritynews.com/android-framework-integer-overflow-vulnerability-exploited/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/android-framework-integer-overflow-vulnerability-exploited/</guid>
    <pubDate>Thu, 04 Jun 2026 09:07:01 +0000</pubDate>
    <source>Cyber Security News</source>
    <category>News</category>
    <category>CVE</category>
    <category>Vuln</category>
    <description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly identified Android Framework vulnerability, tracked as CVE-2025-48595 , to its Known Exploited Vulnerabilities (KEV) catalog, warning…]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-9149 Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-9149</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-9149</guid>
    <pubDate>Thu, 04 Jun 2026 08:45:36 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <category>Vuln</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-9150 Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-9150</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-9150</guid>
    <pubDate>Thu, 04 Jun 2026 08:45:29 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <category>Vuln</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-46598 Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-46598</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-46598</guid>
    <pubDate>Thu, 04 Jun 2026 08:45:22 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-27136 Invoking duplicate attributes can cause XSS in golang.org/x/net/html]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27136</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27136</guid>
    <pubDate>Thu, 04 Jun 2026 08:45:09 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-42506 Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42506</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42506</guid>
    <pubDate>Thu, 04 Jun 2026 08:45:02 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-25681 Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25681</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25681</guid>
    <pubDate>Thu, 04 Jun 2026 08:44:55 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-39827 Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-39827</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-39827</guid>
    <pubDate>Thu, 04 Jun 2026 08:44:26 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-39835</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-39835</guid>
    <pubDate>Thu, 04 Jun 2026 08:44:06 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-25680 Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25680</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25680</guid>
    <pubDate>Thu, 04 Jun 2026 08:43:47 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <category>DoS</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-42502 Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42502</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42502</guid>
    <pubDate>Thu, 04 Jun 2026 08:43:19 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-39828 Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-39828</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-39828</guid>
    <pubDate>Thu, 04 Jun 2026 08:42:55 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-43964 Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43964</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43964</guid>
    <pubDate>Thu, 04 Jun 2026 08:42:06 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-41140 Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41140</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41140</guid>
    <pubDate>Thu, 04 Jun 2026 08:41:49 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-35414 OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35414</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35414</guid>
    <pubDate>Thu, 04 Jun 2026 08:40:55 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-1149 GNU Binutils ld xmalloc.c xstrdup memory leak]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1149</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1149</guid>
    <pubDate>Thu, 04 Jun 2026 08:39:23 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Hackers Use Fake Chrome Web Store Copyright Notices to Steal Google Credentials]]></title>
    <link>https://cybersecuritynews.com/hackers-use-fake-chrome-web-store-copyright-notices/</link>
    <guid isPermaLink="true">https://cybersecuritynews.com/hackers-use-fake-chrome-web-store-copyright-notices/</guid>
    <pubDate>Thu, 04 Jun 2026 07:49:48 +0000</pubDate>
    <source>Cyber Security News</source>
    <category>News</category>
    <category>Phishing</category>
    <description><![CDATA[A new phishing campaign is targeting Chrome extension developers using fake copyright removal notices that look like official messages from the Chrome Web Store. The scam tricks developers into entering their Google…]]></description>
  </item>
  <item>
    <title><![CDATA[Microsoft's Coreutils for Windows, (Thu, Jun 4th)]]></title>
    <link>https://isc.sans.edu/diary/rss/33048</link>
    <guid isPermaLink="true">https://isc.sans.edu/diary/rss/33048</guid>
    <pubDate>Thu, 04 Jun 2026 06:10:44 +0000</pubDate>
    <source>SANS Internet Storm Center</source>
    <category>Research</category>
    <description><![CDATA[I've been using the GnuWin32 CoreUtils for Windows for many years now (it gives you many *nix core commands on Windows).]]></description>
  </item>
  <item>
    <title><![CDATA[DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets]]></title>
    <link>https://thehackernews.com/2026/06/doj-disrupts-southeast-asia-crypto.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/doj-disrupts-southeast-asia-crypto.html</guid>
    <pubDate>Thu, 04 Jun 2026 06:06:25 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Crypto</category>
    <description><![CDATA[The U.S. Department of Justice (DoJ) on Wednesday announced the results of a sweeping action undertaken by government authorities and private sector companies to combat cyber-enabled and cryptocurrency fraud targeting…]]></description>
  </item>
  <item>
    <title><![CDATA[Pakistan Spies on Afghan Finance Ministry With Xeno RAT]]></title>
    <link>https://www.darkreading.com/cyberattacks-data-breaches/pakistan-spies-afghan-finance-ministry-xeno-rat</link>
    <guid isPermaLink="true">https://www.darkreading.com/cyberattacks-data-breaches/pakistan-spies-afghan-finance-ministry-xeno-rat</guid>
    <pubDate>Thu, 04 Jun 2026 04:01:00 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <category>Malware</category>
    <description><![CDATA[Despite broadly connected digital infrastructure, standard fare TTPs are enough to cause trouble for Afghanistan's porous cybersecurity.]]></description>
  </item>
  <item>
    <title><![CDATA[Chinese hackers use new Atlas RAT malware in European cyberattacks]]></title>
    <link>https://www.bleepingcomputer.com/news/security/chinese-hackers-use-new-atlas-rat-malware-in-european-cyberattacks/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/chinese-hackers-use-new-atlas-rat-malware-in-european-cyberattacks/</guid>
    <pubDate>Wed, 03 Jun 2026 21:45:27 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <category>Malware</category>
    <description><![CDATA[A Chinese-speaking cybercrime group has expanded its targeting to the European space, deploying previously undocumented malware and the Atlas backdoor.]]></description>
  </item>
  <item>
    <title><![CDATA[Attackers Use AI to Automate EDR Evasion Testing]]></title>
    <link>https://www.darkreading.com/endpoint-security/attackers-automate-edr-evasion-testing</link>
    <guid isPermaLink="true">https://www.darkreading.com/endpoint-security/attackers-automate-edr-evasion-testing</guid>
    <pubDate>Wed, 03 Jun 2026 21:34:07 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <category>Malware</category>
    <description><![CDATA[Python scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender.]]></description>
  </item>
  <item>
    <title><![CDATA[U.S. sanctions Nobitex crypto exchange used by Iranian ransomware actors]]></title>
    <link>https://www.bleepingcomputer.com/news/security/the-us-sanctions-nobitex-crypto-exchange-used-by-ransomware/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/the-us-sanctions-nobitex-crypto-exchange-used-by-ransomware/</guid>
    <pubDate>Wed, 03 Jun 2026 20:31:22 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <category>Ransom</category>
    <category>Crypto</category>
    <description><![CDATA[The U.S. Treasury's Office of Foreign Assets Control (OFAC) has announced sanctions against Nobitex, Iran's largest cryptocurrency exchange, for facilitating payments related to terrorist activities.]]></description>
  </item>
  <item>
    <title><![CDATA[CISA warns of cyberattacks targeting fuel tank monitoring systems]]></title>
    <link>https://www.bleepingcomputer.com/news/security/cisa-warns-of-cyberattacks-targeting-fuel-tank-monitoring-systems/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/cisa-warns-of-cyberattacks-targeting-fuel-tank-monitoring-systems/</guid>
    <pubDate>Wed, 03 Jun 2026 20:21:56 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <description><![CDATA[CISA, the FBI, the NSA, the Department of Energy, and other US government partners are warning that hackers are targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks…]]></description>
  </item>
  <item>
    <title><![CDATA[Tropical Blend: Cyber &amp; Politics Ramp Up Across Latin America]]></title>
    <link>https://www.darkreading.com/cyberattacks-data-breaches/nation-state-cyber-activity-latin-america</link>
    <guid isPermaLink="true">https://www.darkreading.com/cyberattacks-data-breaches/nation-state-cyber-activity-latin-america</guid>
    <pubDate>Wed, 03 Jun 2026 19:52:32 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <category>APT</category>
    <description><![CDATA[China-linked espionage groups have attacked at least a dozen nations in the region, gathering information on maritime shipping, oil production, and other geopolitical interests.]]></description>
  </item>
  <item>
    <title><![CDATA[Broadcom VMware security advisory (AV26-548)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-548</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-548</guid>
    <pubDate>Wed, 03 Jun 2026 19:49:24 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Cisco security advisory (AV26-547)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-547</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-547</guid>
    <pubDate>Wed, 03 Jun 2026 19:22:10 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[WhatsApp, Slack Notifications Could Hijack Google Gemini on Android]]></title>
    <link>https://thehackernews.com/2026/06/whatsapp-slack-notifications-could.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/whatsapp-slack-notifications-could.html</guid>
    <pubDate>Wed, 03 Jun 2026 19:11:15 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <description><![CDATA[A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini's voice assistant on Android and made it open a victim's connected windows, fake a message from…]]></description>
  </item>
  <item>
    <title><![CDATA[Cyber Insurance Rates Are Dropping, but Exclusions Widen]]></title>
    <link>https://www.darkreading.com/cyber-risk/cyber-insurance-rates-drop-exclusions-widen</link>
    <guid isPermaLink="true">https://www.darkreading.com/cyber-risk/cyber-insurance-rates-drop-exclusions-widen</guid>
    <pubDate>Wed, 03 Jun 2026 19:10:58 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <description><![CDATA[Cyber insurance coverage is slowly changing, and some policies may not provide coverage for social engineering attacks like ClickFix.]]></description>
  </item>
  <item>
    <title><![CDATA[New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute]]></title>
    <link>https://www.bleepingcomputer.com/news/security/new-http-2-bomb-dos-attack-crashes-web-servers-in-under-a-minute/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/new-http-2-bomb-dos-attack-crashes-web-servers-in-under-a-minute/</guid>
    <pubDate>Wed, 03 Jun 2026 19:08:19 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <category>DoS</category>
    <description><![CDATA[A new denial-of-service (DoS) attack dubbed HTTP/2 Bomb can be launched from a single machine to take down web servers within seconds.]]></description>
  </item>
  <item>
    <title><![CDATA[Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover]]></title>
    <link>https://www.darkreading.com/application-security/coding-gaffe-exposes-microsoft-365-accounts-takeover</link>
    <guid isPermaLink="true">https://www.darkreading.com/application-security/coding-gaffe-exposes-microsoft-365-accounts-takeover</guid>
    <pubDate>Wed, 03 Jun 2026 19:00:41 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <description><![CDATA[A disabled security setting meant to protect authentication across Android versions of key apps like Word, PowerPoint, and Excel paved the way for attackers to steal logins and data.]]></description>
  </item>
  <item>
    <title><![CDATA[xAI Asks Court to Strip Alleged Grok Deepfake Nudes Victims of Anonymity]]></title>
    <link>https://www.wired.com/story/xai-asks-court-to-strip-alleged-grok-deepfake-nudes-victims-of-anonymity/</link>
    <guid isPermaLink="true">https://www.wired.com/story/xai-asks-court-to-strip-alleged-grok-deepfake-nudes-victims-of-anonymity/</guid>
    <pubDate>Wed, 03 Jun 2026 18:49:32 +0000</pubDate>
    <source>Wired Security</source>
    <category>Media</category>
    <description><![CDATA[Four people suing Elon Musk's AI firm under pseudonyms due to the risks of being identified may face a difficult choice: Reveal your real names, or drop the lawsuit.]]></description>
  </item>
  <item>
    <title><![CDATA[We found this fake-invoice campaign while scammers were still building it]]></title>
    <link>https://www.malwarebytes.com/blog/threat-intel/2026/06/we-found-this-fake-invoice-campaign-while-scammers-were-still-building-it</link>
    <guid isPermaLink="true">https://www.malwarebytes.com/blog/threat-intel/2026/06/we-found-this-fake-invoice-campaign-while-scammers-were-still-building-it</guid>
    <pubDate>Wed, 03 Jun 2026 18:05:19 +0000</pubDate>
    <source>Malwarebytes Labs</source>
    <category>Threat Intel</category>
    <description><![CDATA[A new batch of fake payment invoices is being staged right now, and we caught the campaign while it was still being put together. The emails impersonate PayPal, Amazon, and Geek Squad, and others, and they all share one…]]></description>
  </item>
  <item>
    <title><![CDATA[One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens]]></title>
    <link>https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html</guid>
    <pubDate>Wed, 03 Jun 2026 17:58:00 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Research</category>
    <description><![CDATA[Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user's GitHub token. "Just by clicking a link, it's possible for an attacker to…]]></description>
  </item>
  <item>
    <title><![CDATA[Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)]]></title>
    <link>https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html</guid>
    <pubDate>Wed, 03 Jun 2026 16:40:00 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>CVE</category>
    <category>Vuln</category>
    <description><![CDATA[Redis has patched a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an autonomous AI tool built to hunt…]]></description>
  </item>
  <item>
    <title><![CDATA[CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog]]></title>
    <link>https://thehackernews.com/2026/06/cisa-adds-exploited-magento-rce-flaw.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/cisa-adds-exploited-magento-rce-flaw.html</guid>
    <pubDate>Wed, 03 Jun 2026 16:30:00 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>CVE</category>
    <category>Vuln</category>
    <description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to its Known Exploited Vulnerabilities…]]></description>
  </item>
  <item>
    <title><![CDATA[Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT]]></title>
    <link>https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html</guid>
    <pubDate>Wed, 03 Jun 2026 16:29:16 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Malware</category>
    <category>Research</category>
    <description><![CDATA[Cybersecurity researchers have flagged a new malspam campaign that makes use of Google's DoubleClick domain as a way to evade detection and ultimately deliver a remote access trojan (RAT) named DesckVB RAT. "Before the…]]></description>
  </item>
  <item>
    <title><![CDATA[A Day in the Life of an MDR Analyst: Inside the Modern SOC]]></title>
    <link>https://www.rapid7.com/blog/post/it-day-in-the-life-mdr-analyst-inside-the-modern-soc</link>
    <guid isPermaLink="true">https://www.rapid7.com/blog/post/it-day-in-the-life-mdr-analyst-inside-the-modern-soc</guid>
    <pubDate>Wed, 03 Jun 2026 16:27:08 +0000</pubDate>
    <source>Rapid7 Blog</source>
    <category>Research</category>
    <description><![CDATA[What actually happens inside a SOC when an incident unfolds? Most teams see the alerts and the outcomes, but the decision-making in between is often less visible. At the Rapid7 2026 Global Cybersecurity Summit, the…]]></description>
  </item>
  <item>
    <title><![CDATA[[Control Systems] Phoenix Contact Security Advisory (AV26-546)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/control-systems-phoenix-contact-security-advisory-av26-546</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/control-systems-phoenix-contact-security-advisory-av26-546</guid>
    <pubDate>Wed, 03 Jun 2026 15:39:58 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CISA warns of active attacks exploiting Android, Linux bugs]]></title>
    <link>https://www.bleepingcomputer.com/news/security/cisa-warns-of-active-attacks-exploiting-android-linux-bugs/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/cisa-warns-of-active-attacks-exploiting-android-linux-bugs/</guid>
    <pubDate>Wed, 03 Jun 2026 15:36:16 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <category>Vuln</category>
    <description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system.]]></description>
  </item>
  <item>
    <title><![CDATA[Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore]]></title>
    <link>https://thehackernews.com/2026/06/beyond-zero-day-see-your-network-like.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/beyond-zero-day-see-your-network-like.html</guid>
    <pubDate>Wed, 03 Jun 2026 14:56:46 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Vuln</category>
    <category>Breach</category>
    <description><![CDATA[Assume the breach. Zero-days keep shipping, AI is writing exploits faster than anyone patches, and "patch everything in time" stopped working years ago. Stop betting the org on winning that race. You don't control which…]]></description>
  </item>
  <item>
    <title><![CDATA[Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag]]></title>
    <link>https://thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html</guid>
    <pubDate>Wed, 03 Jun 2026 14:56:35 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <description><![CDATA[A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits account-token sharing to trusted Microsoft apps. Any other app on the same phone could ask…]]></description>
  </item>
  <item>
    <title><![CDATA[What 345 Days of Untested Exposure Looks Like at a Bank]]></title>
    <link>https://www.bleepingcomputer.com/news/security/what-345-days-of-untested-exposure-looks-like-at-a-bank/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/what-345-days-of-untested-exposure-looks-like-at-a-bank/</guid>
    <pubDate>Wed, 03 Jun 2026 14:02:12 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <description><![CDATA[A two-week penetration test can leave roughly 345 days of real-world exposure unvalidated. Sprocket Security explores why continuous testing is becoming critical as attack surfaces constantly change.]]></description>
  </item>
  <item>
    <title><![CDATA[Continuing Scans for swagger.json, (Wed, Jun 3rd)]]></title>
    <link>https://isc.sans.edu/diary/rss/33044</link>
    <guid isPermaLink="true">https://isc.sans.edu/diary/rss/33044</guid>
    <pubDate>Wed, 03 Jun 2026 13:40:00 +0000</pubDate>
    <source>SANS Internet Storm Center</source>
    <category>Research</category>
    <description><![CDATA[Enterprise applications often still use complex standards like SOAP for web services. The big advantage of SOAP is its tight and extensive standards, which enable interoperability across an enterprise governed by web…]]></description>
  </item>
  <item>
    <title><![CDATA[[Control systems] ABB security advisory (AV26-545)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/control-systems-abb-security-advisory-av26-545</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/control-systems-abb-security-advisory-av26-545</guid>
    <pubDate>Wed, 03 Jun 2026 13:01:01 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Google Chrome security advisory (AV26-544)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/google-chrome-security-advisory-av26-544</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/google-chrome-security-advisory-av26-544</guid>
    <pubDate>Wed, 03 Jun 2026 12:49:19 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Keep getting calls from questionable numbers? Meet Scam Number Check]]></title>
    <link>https://www.malwarebytes.com/blog/product/2026/06/keep-getting-calls-from-questionable-numbers-meet-scam-number-check</link>
    <guid isPermaLink="true">https://www.malwarebytes.com/blog/product/2026/06/keep-getting-calls-from-questionable-numbers-meet-scam-number-check</guid>
    <pubDate>Wed, 03 Jun 2026 12:16:04 +0000</pubDate>
    <source>Malwarebytes Labs</source>
    <category>Threat Intel</category>
    <description><![CDATA[Have you ever gotten a phone call and had a gut feeling that those random digits looked extra suspicious? It happens to millions of people every day. While many people have trained themselves to ignore such calls, they…]]></description>
  </item>
  <item>
    <title><![CDATA[Malicious Notifications Could Trick Google Gemini Users]]></title>
    <link>https://www.darkreading.com/application-security/malicious-notifications-could-trick-google-gemini-users</link>
    <guid isPermaLink="true">https://www.darkreading.com/application-security/malicious-notifications-could-trick-google-gemini-users</guid>
    <pubDate>Wed, 03 Jun 2026 12:01:00 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <description><![CDATA[A prompt injection flaw in Google Gemini's voice assistant let attackers hide malicious commands in notifications, enabling social engineering and more.]]></description>
  </item>
  <item>
    <title><![CDATA[CISA Adds One Known Exploited Vulnerability to Catalog]]></title>
    <link>https://www.cisa.gov/news-events/alerts/2026/06/03/cisa-adds-one-known-exploited-vulnerability-catalog</link>
    <guid isPermaLink="true">https://www.cisa.gov/news-events/alerts/2026/06/03/cisa-adds-one-known-exploited-vulnerability-catalog</guid>
    <pubDate>Wed, 03 Jun 2026 12:00:00 +0000</pubDate>
    <source>CISA Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <category>CVE</category>
    <category>Vuln</category>
    <description><![CDATA[CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-45247 Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data…]]></description>
  </item>
  <item>
    <title><![CDATA[Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)]]></title>
    <link>https://thehackernews.com/2026/06/shrinking-iam-attack-surface-through.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/shrinking-iam-attack-surface-through.html</guid>
    <pubDate>Wed, 03 Jun 2026 11:58:00 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <description><![CDATA[The Fragmented State of Modern Enterprise Identity Enterprise IAM is approaching a breaking point. As organizations scale, identity becomes increasingly fragmented across thousands of applications, decentralized teams…]]></description>
  </item>
  <item>
    <title><![CDATA[Acer working to patch max severity zero-days in Wave 7 routers]]></title>
    <link>https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/</guid>
    <pubDate>Wed, 03 Jun 2026 11:35:47 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <category>Vuln</category>
    <description><![CDATA[Acer is working to address two maximum-severity zero-day vulnerabilities affecting its Wave 7 mesh routers.]]></description>
  </item>
  <item>
    <title><![CDATA[The sorry state of skill distribution]]></title>
    <link>https://blog.trailofbits.com/2026/06/03/the-sorry-state-of-skill-distribution/</link>
    <guid isPermaLink="true">https://blog.trailofbits.com/2026/06/03/the-sorry-state-of-skill-distribution/</guid>
    <pubDate>Wed, 03 Jun 2026 11:00:00 +0000</pubDate>
    <source>Trail of Bits</source>
    <category>Research</category>
    <description><![CDATA[Public skill marketplaces are being flooded with malicious skills that steal credentials, exfiltrate data, and hijack agents. In response, a segment of the security industry released skill scanners, a new family of…]]></description>
  </item>
  <item>
    <title><![CDATA[Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes]]></title>
    <link>https://thehackernews.com/2026/06/unpatched-windows-search-uri.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/unpatched-windows-search-uri.html</guid>
    <pubDate>Wed, 03 Jun 2026 10:18:52 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>CVE</category>
    <category>Vuln</category>
    <category>Research</category>
    <description><![CDATA[Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the attacker. Like in the case of CVE-2026-33829, which impacted the Windows Snipping…]]></description>
  </item>
  <item>
    <title><![CDATA[ComoDoS - Exploiting a Remote Kernel Vulnerability in Comodo Internet Security]]></title>
    <link>https://malwaretech.com/2026/06/exploiting-a-remote-kernel-vulnerability-in-comodo-internet-security.html</link>
    <guid isPermaLink="true">https://malwaretech.com/2026/06/exploiting-a-remote-kernel-vulnerability-in-comodo-internet-security.html</guid>
    <pubDate>Wed, 03 Jun 2026 10:13:00 +0000</pubDate>
    <source>MalwareTech</source>
    <category>Threat Intel</category>
    <category>Vuln</category>
    <description><![CDATA[Sometimes firewall stops attackers, sometimes attackers stop firewall. analyzing a zero-day vulnerability in Comodo Internet Security's Firewall driver.]]></description>
  </item>
  <item>
    <title><![CDATA[Police dismantles 9 crime groups in illegal streaming crackdown]]></title>
    <link>https://www.bleepingcomputer.com/news/security/police-dismantles-9-crime-groups-in-illegal-streaming-crackdown/</link>
    <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/police-dismantles-9-crime-groups-in-illegal-streaming-crackdown/</guid>
    <pubDate>Wed, 03 Jun 2026 10:12:24 +0000</pubDate>
    <source>Bleeping Computer</source>
    <category>News</category>
    <description><![CDATA[European and international law enforcement agencies have dismantled nine organized crime groups and arrested 29 suspects in a major crackdown on illegal streaming operations.]]></description>
  </item>
  <item>
    <title><![CDATA[Global Stock Exchange Hit by Monthslong Email Campaign]]></title>
    <link>https://www.darkreading.com/cyberattacks-data-breaches/global-stock-exchange-hit-monthslong-email-campaign</link>
    <guid isPermaLink="true">https://www.darkreading.com/cyberattacks-data-breaches/global-stock-exchange-hit-monthslong-email-campaign</guid>
    <pubDate>Wed, 03 Jun 2026 10:01:00 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <category>APT</category>
    <description><![CDATA[A threat actor got a near-continuous view into an influential finance executive's email inbox, thanks to clever use of legitimate, native Windows tools.]]></description>
  </item>
  <item>
    <title><![CDATA[Infostealers are becoming the go-to phishing payload]]></title>
    <link>https://www.malwarebytes.com/blog/threat-intel/2026/06/infostealers-are-becoming-the-go-to-phishing-payload</link>
    <guid isPermaLink="true">https://www.malwarebytes.com/blog/threat-intel/2026/06/infostealers-are-becoming-the-go-to-phishing-payload</guid>
    <pubDate>Wed, 03 Jun 2026 08:59:47 +0000</pubDate>
    <source>Malwarebytes Labs</source>
    <category>Threat Intel</category>
    <category>Phishing</category>
    <description><![CDATA[Phishing has changed. Slowly but surely, cybercriminals are turning to infostealers instead. Traditional phishing hasn’t gone away. Far from it. But many attackers are no longer focused solely on tricking victims into…]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-40226 In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40226</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40226</guid>
    <pubDate>Wed, 03 Jun 2026 08:49:41 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-27144 Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27144</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27144</guid>
    <pubDate>Wed, 03 Jun 2026 08:49:33 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-32282 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32282</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32282</guid>
    <pubDate>Wed, 03 Jun 2026 08:48:03 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-29181 OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-29181</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-29181</guid>
    <pubDate>Wed, 03 Jun 2026 08:47:52 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-58160 Tracing logging user input may result in poisoning logs with ANSI escape sequences]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-58160</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-58160</guid>
    <pubDate>Wed, 03 Jun 2026 08:45:45 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-61727 Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-61727</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-61727</guid>
    <pubDate>Wed, 03 Jun 2026 08:45:23 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-61729 Excessive resource consumption when printing error string for host certificate validation in crypto/x509]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-61729</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-61729</guid>
    <pubDate>Wed, 03 Jun 2026 08:45:16 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-60876 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60876</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60876</guid>
    <pubDate>Wed, 03 Jun 2026 08:44:50 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-9403 jqlang jq JSON jq_test.c run_jq_tests assertion]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-9403</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-9403</guid>
    <pubDate>Wed, 03 Jun 2026 08:44:47 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-61725 Excessive CPU consumption in ParseAddress in net/mail]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-61725</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-61725</guid>
    <pubDate>Wed, 03 Jun 2026 08:44:18 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-58188 Panic when validating certificates with DSA public keys in crypto/x509]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-58188</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-58188</guid>
    <pubDate>Wed, 03 Jun 2026 08:44:06 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-61724 Excessive CPU consumption in Reader.ReadResponse in net/textproto]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-61724</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-61724</guid>
    <pubDate>Wed, 03 Jun 2026 08:43:59 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-58186 Lack of limit when parsing cookies can cause memory exhaustion in net/http]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-58186</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-58186</guid>
    <pubDate>Wed, 03 Jun 2026 08:43:51 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-58183 Unbounded allocation when parsing GNU sparse map in archive/tar]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-58183</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-58183</guid>
    <pubDate>Wed, 03 Jun 2026 08:43:44 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-25541 Bytes is vulnerable to integer overflow in BytesMut::reserve]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25541</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25541</guid>
    <pubDate>Wed, 03 Jun 2026 08:42:45 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2024-58266 The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-58266</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-58266</guid>
    <pubDate>Wed, 03 Jun 2026 08:42:44 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-5791 Users: `root` appended to group listings]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-5791</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-5791</guid>
    <pubDate>Wed, 03 Jun 2026 08:42:36 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-1176 GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflow]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1176</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1176</guid>
    <pubDate>Wed, 03 Jun 2026 08:42:29 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-6357 pip self-update functionality can import newly installed modules after wheel installation]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6357</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6357</guid>
    <pubDate>Wed, 03 Jun 2026 08:42:21 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-1178 GNU Binutils ld libbfd.c bfd_putl64 memory corruption]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1178</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1178</guid>
    <pubDate>Wed, 03 Jun 2026 08:42:20 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-3198 GNU Binutils objdump bucomm.c display_info memory leak]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-3198</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-3198</guid>
    <pubDate>Wed, 03 Jun 2026 08:42:12 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-46327 Go Snowflake Driver has race condition when checking access to Easy Logging configuration file]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-46327</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-46327</guid>
    <pubDate>Wed, 03 Jun 2026 08:42:07 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-46394 In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-46394</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-46394</guid>
    <pubDate>Wed, 03 Jun 2026 08:41:57 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2024-58251 In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-58251</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-58251</guid>
    <pubDate>Wed, 03 Jun 2026 08:41:47 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <category>DoS</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-29923 go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29923</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29923</guid>
    <pubDate>Wed, 03 Jun 2026 08:41:38 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2024-7598 Network restriction bypass via race condition during namespace termination]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-7598</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-7598</guid>
    <pubDate>Wed, 03 Jun 2026 08:41:20 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-1180 GNU Binutils ld elf-eh-frame.c _bfd_elf_write_section_eh_frame memory corruption]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1180</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1180</guid>
    <pubDate>Wed, 03 Jun 2026 08:41:06 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-1150 GNU Binutils ld libbfd.c bfd_malloc memory leak]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1150</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1150</guid>
    <pubDate>Wed, 03 Jun 2026 08:40:55 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-1151 GNU Binutils ld xmemdup.c xmemdup memory leak]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1151</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1151</guid>
    <pubDate>Wed, 03 Jun 2026 08:40:45 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2025-1152 GNU Binutils ld xstrdup.c xstrdup memory leak]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1152</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1152</guid>
    <pubDate>Wed, 03 Jun 2026 08:40:34 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-5928 Static buffer overflow in deprecated nis_local_principal]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5928</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5928</guid>
    <pubDate>Wed, 03 Jun 2026 08:40:02 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <category>Vuln</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2013-1633 easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-1633</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-1633</guid>
    <pubDate>Wed, 03 Jun 2026 08:39:48 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2023-27043 The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-27043</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-27043</guid>
    <pubDate>Wed, 03 Jun 2026 08:39:34 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare]]></title>
    <link>https://thehackernews.com/2026/06/new-http2-bomb-vulnerability-allows.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/new-http2-bomb-vulnerability-allows.html</guid>
    <pubDate>Wed, 03 Jun 2026 08:33:35 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Vuln</category>
    <category>DoS</category>
    <category>Research</category>
    <description><![CDATA[Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The vulnerability has been…]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2020-8561 Webhook redirect in kube-apiserver]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-8561</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-8561</guid>
    <pubDate>Wed, 03 Jun 2026 08:02:13 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2021-25740 Holes in EndpointSlice Validation Enable Host Network Hijack]]></title>
    <link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-25740</link>
    <guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-25740</guid>
    <pubDate>Wed, 03 Jun 2026 08:02:08 +0000</pubDate>
    <source>Microsoft Security</source>
    <category>Advisory</category>
    <category>CVE</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content]]></title>
    <link>https://thehackernews.com/2026/06/weedhack-attacks-minecraft-users.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/weedhack-attacks-minecraft-users.html</guid>
    <pubDate>Wed, 03 Jun 2026 06:16:54 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Malware</category>
    <category>Research</category>
    <description><![CDATA[Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gaining control of victims' systems. The Minecraft-focused malware-as-a-service (MaaS) campaign…]]></description>
  </item>
  <item>
    <title><![CDATA[Zoom CISO: AI as a Security Enabler, Not Role-Replacer]]></title>
    <link>https://www.darkreading.com/cybersecurity-operations/zoom-ciso-ai-security-enabler-role-replacer</link>
    <guid isPermaLink="true">https://www.darkreading.com/cybersecurity-operations/zoom-ciso-ai-security-enabler-role-replacer</guid>
    <pubDate>Tue, 02 Jun 2026 21:51:07 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <description><![CDATA[Zoom CISO Sandra McLeod discusses the challenges of securing a global communication platform, the promise of AI-driven security workflows, and her advice for aspiring cybersecurity leaders.]]></description>
  </item>
  <item>
    <title><![CDATA[FBI-Flagged Phishing Kit Kali365 Expands Its Reach]]></title>
    <link>https://www.darkreading.com/cyber-risk/fbi-flagged-phishing-kit-kali365-expands-its-reach</link>
    <guid isPermaLink="true">https://www.darkreading.com/cyber-risk/fbi-flagged-phishing-kit-kali365-expands-its-reach</guid>
    <pubDate>Tue, 02 Jun 2026 21:32:24 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <category>Phishing</category>
    <description><![CDATA[Once targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing.]]></description>
  </item>
  <item>
    <title><![CDATA[DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks]]></title>
    <link>https://www.darkreading.com/cyberattacks-data-breaches/drivesurge-hijacks-thousands-sites-clickfix-fakeupdate-attacks</link>
    <guid isPermaLink="true">https://www.darkreading.com/cyberattacks-data-breaches/drivesurge-hijacks-thousands-sites-clickfix-fakeupdate-attacks</guid>
    <pubDate>Tue, 02 Jun 2026 20:11:51 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <category>Malware</category>
    <description><![CDATA[A sneaky, wide-scale IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware.]]></description>
  </item>
  <item>
    <title><![CDATA[HPE security advisory (AV26-543)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-543</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-543</guid>
    <pubDate>Tue, 02 Jun 2026 20:02:25 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[China Uses Dual-Method Cyberattack on Czech Orgs]]></title>
    <link>https://www.darkreading.com/threat-intelligence/china-uses-dual-method-attack-czech-taiwan-orgs</link>
    <guid isPermaLink="true">https://www.darkreading.com/threat-intelligence/china-uses-dual-method-attack-czech-taiwan-orgs</guid>
    <pubDate>Tue, 02 Jun 2026 19:50:53 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <category>Phishing</category>
    <category>Malware</category>
    <description><![CDATA[China is stealing data from high-value targets via a sneaky, double-layer spear-phishing campaign that includes the Azureveil malware.]]></description>
  </item>
  <item>
    <title><![CDATA[Securing AI Agents Before They Go Rogue Is Next to Impossible]]></title>
    <link>https://www.darkreading.com/cyber-risk/securing-ai-agents-rogue</link>
    <guid isPermaLink="true">https://www.darkreading.com/cyber-risk/securing-ai-agents-rogue</guid>
    <pubDate>Tue, 02 Jun 2026 19:10:14 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <description><![CDATA[High-autonomy agents with broad permissions and unfettered access are a recipe for disaster, and enterprises need to act now before they become the next horror story.]]></description>
  </item>
  <item>
    <title><![CDATA[Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited]]></title>
    <link>https://thehackernews.com/2026/06/google-june-2026-android-update-patches.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/google-june-2026-android-update-patches.html</guid>
    <pubDate>Tue, 02 Jun 2026 18:46:00 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Vuln</category>
    <description><![CDATA[Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under…]]></description>
  </item>
  <item>
    <title><![CDATA[Mozilla security advisory (AV26-542)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/mozilla-security-advisory-av26-542</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/mozilla-security-advisory-av26-542</guid>
    <pubDate>Tue, 02 Jun 2026 18:35:44 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[These convincing copyright notices are designed to steal Google logins]]></title>
    <link>https://www.malwarebytes.com/blog/threat-intel/2026/06/these-convincing-copyright-notices-are-designed-to-steal-google-logins</link>
    <guid isPermaLink="true">https://www.malwarebytes.com/blog/threat-intel/2026/06/these-convincing-copyright-notices-are-designed-to-steal-google-logins</guid>
    <pubDate>Tue, 02 Jun 2026 18:24:07 +0000</pubDate>
    <source>Malwarebytes Labs</source>
    <category>Threat Intel</category>
    <description><![CDATA[A new scam is targeting people who publish Chrome extensions. The scam arrives as an official-looking “copyright removal request” claiming your extension is about to be removed from the Chrome Web Store and that you…]]></description>
  </item>
  <item>
    <title><![CDATA[JetBrains security advisory (AV26-541)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/jetbrains-security-advisory-av26-541</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/jetbrains-security-advisory-av26-541</guid>
    <pubDate>Tue, 02 Jun 2026 18:22:12 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine]]></title>
    <link>https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html</guid>
    <pubDate>Tue, 02 Jun 2026 18:21:49 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Vuln</category>
    <category>Malware</category>
    <category>Breach</category>
    <description><![CDATA[The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation. Per Sekoia, the activity…]]></description>
  </item>
  <item>
    <title><![CDATA[Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation]]></title>
    <link>https://thehackernews.com/2026/06/oracle-weblogic-cve-2024-21182-added-to.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/oracle-weblogic-cve-2024-21182-added-to.html</guid>
    <pubDate>Tue, 02 Jun 2026 18:14:42 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>CVE</category>
    <category>Vuln</category>
    <description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of…]]></description>
  </item>
  <item>
    <title><![CDATA[[Control systems] Siemens security advisory (AV26-540)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-540</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-540</guid>
    <pubDate>Tue, 02 Jun 2026 18:07:51 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Android security advisory – June 2026 monthly rollup (AV26-538) – Update 1]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/android-security-advisory-june-2026-monthly-rollup-av26-538</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/android-security-advisory-june-2026-monthly-rollup-av26-538</guid>
    <pubDate>Tue, 02 Jun 2026 17:58:26 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2)]]></title>
    <link>https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/</link>
    <guid isPermaLink="true">https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/</guid>
    <pubDate>Tue, 02 Jun 2026 17:30:33 +0000</pubDate>
    <source>Palo Alto Unit 42</source>
    <category>Threat Intel</category>
    <category>Malware</category>
    <description><![CDATA[Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more.]]></description>
  </item>
  <item>
    <title><![CDATA[HP security advisory (AV26-539)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/hp-security-advisory-av26-539</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/hp-security-advisory-av26-539</guid>
    <pubDate>Tue, 02 Jun 2026 15:24:01 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Samsung mobile security advisory (AV26-537)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/samsung-mobile-security-advisory-av26-537</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/samsung-mobile-security-advisory-av26-537</guid>
    <pubDate>Tue, 02 Jun 2026 15:09:15 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Beyond Assume-Breach: How AI-Native Security Will Reshape Enterprise Defense]]></title>
    <link>https://www.darkreading.com/cyber-risk/assume-breach-ai-native-security-reshape-enterprise-defense</link>
    <guid isPermaLink="true">https://www.darkreading.com/cyber-risk/assume-breach-ai-native-security-reshape-enterprise-defense</guid>
    <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <category>Breach</category>
    <description><![CDATA[Twenty years after Dark Reading launched, we're looking ahead at what's next for enterprise security. Spoiler: It's hyper-segmented, AI-orchestrated, and way more sophisticated than your dad's firewall.]]></description>
  </item>
  <item>
    <title><![CDATA[CISA and Partners Urge Hardening Automatic Tank Gauge Systems]]></title>
    <link>https://www.cisa.gov/resources-tools/resources/cisa-and-partners-urge-hardening-automatic-tank-gauge-systems</link>
    <guid isPermaLink="true">https://www.cisa.gov/resources-tools/resources/cisa-and-partners-urge-hardening-automatic-tank-gauge-systems</guid>
    <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
    <source>CISA Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[CISA and Partners Urge Hardening Automatic Tank Gauge Systems Overview The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), the…]]></description>
  </item>
  <item>
    <title><![CDATA[CISA Adds Two Known Exploited Vulnerabilities to Catalog]]></title>
    <link>https://www.cisa.gov/news-events/alerts/2026/06/02/cisa-adds-two-known-exploited-vulnerabilities-catalog</link>
    <guid isPermaLink="true">https://www.cisa.gov/news-events/alerts/2026/06/02/cisa-adds-two-known-exploited-vulnerabilities-catalog</guid>
    <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
    <source>CISA Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <category>CVE</category>
    <category>Vuln</category>
    <description><![CDATA[CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2022-0492 Linux Kernel Improper Authentication Vulnerability CVE-2025-48595…]]></description>
  </item>
  <item>
    <title><![CDATA[AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It]]></title>
    <link>https://thehackernews.com/2026/06/ai-driven-exploitation-is-destroying.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/ai-driven-exploitation-is-destroying.html</guid>
    <pubDate>Tue, 02 Jun 2026 11:58:00 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Vuln</category>
    <description><![CDATA[AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in the history of enterprise security…]]></description>
  </item>
  <item>
    <title><![CDATA[The Intersection of Encryption and AI]]></title>
    <link>https://www.schneier.com/blog/archives/2026/06/the-intersection-of-encryption-and-ai.html</link>
    <guid isPermaLink="true">https://www.schneier.com/blog/archives/2026/06/the-intersection-of-encryption-and-ai.html</guid>
    <pubDate>Tue, 02 Jun 2026 11:06:25 +0000</pubDate>
    <source>Schneier on Security</source>
    <category>Media</category>
    <description><![CDATA[As part of their 20th Anniversary celebration, Dark Reading asked five cybersecurity industry leaders who wrote blogs or columns for them over the years to select their favorite piece and share their reflections on the…]]></description>
  </item>
  <item>
    <title><![CDATA[Microsoft Threatening Security Researcher]]></title>
    <link>https://www.schneier.com/blog/archives/2026/06/microsoft-threatening-security-researcher.html</link>
    <guid isPermaLink="true">https://www.schneier.com/blog/archives/2026/06/microsoft-threatening-security-researcher.html</guid>
    <pubDate>Tue, 02 Jun 2026 11:00:42 +0000</pubDate>
    <source>Schneier on Security</source>
    <category>Media</category>
    <category>Vuln</category>
    <category>Research</category>
    <description><![CDATA[An anonymous security researcher called “Nightmare Eclipse” has been publishing a series of significant security exploits against Microsoft Windows—including one that breaks BitLocker. Microsoft has threatened legal…]]></description>
  </item>
  <item>
    <title><![CDATA[From Fake Purchase Orders to Remote Access: Analyzing the JS.MonoGlyphRAT Threat to US Enterprises]]></title>
    <link>https://any.run/cybersecurity-blog/monoglyphrat-attacks-us-enterprise/</link>
    <guid isPermaLink="true">https://any.run/cybersecurity-blog/monoglyphrat-attacks-us-enterprise/</guid>
    <pubDate>Tue, 02 Jun 2026 10:34:41 +0000</pubDate>
    <source>Any.Run Malware Analysis</source>
    <category>Threat Intel</category>
    <category>Malware</category>
    <category>Research</category>
    <description><![CDATA[A previously unidentified cyberattack is quietly spreading through US businesses — and most security tools are not catching it. Researchers at ANY.RUN have identified a new backdoor called JS.MonoGlyphRAT, an advanced…]]></description>
  </item>
  <item>
    <title><![CDATA[How Leading Organizations Are Turning EDR Into Operational Resilience]]></title>
    <link>https://thehackernews.com/2026/06/how-leading-organizations-are-turning.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/how-leading-organizations-are-turning.html</guid>
    <pubDate>Tue, 02 Jun 2026 10:30:00 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <description><![CDATA[Most organizations now recognize that endpoint protection alone is no longer sufficient. That's why adoption of endpoint detection and response (EDR) has accelerated rapidly in recent years. Organizations understand…]]></description>
  </item>
  <item>
    <title><![CDATA[Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor]]></title>
    <link>https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoor/</link>
    <guid isPermaLink="true">https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoor/</guid>
    <pubDate>Tue, 02 Jun 2026 10:00:31 +0000</pubDate>
    <source>Palo Alto Unit 42</source>
    <category>Threat Intel</category>
    <category>Malware</category>
    <description><![CDATA[Operation FlutterBridge is a malvertising campaign targeting macOS users. It distributed the new backdoor FlutterShell, built using the Flutter framework.]]></description>
  </item>
  <item>
    <title><![CDATA[23andMe exposed genetic information of millions, lawsuit says]]></title>
    <link>https://www.malwarebytes.com/blog/data-breaches/2026/06/23andme-exposed-genetic-information-of-millions-lawsuit-says</link>
    <guid isPermaLink="true">https://www.malwarebytes.com/blog/data-breaches/2026/06/23andme-exposed-genetic-information-of-millions-lawsuit-says</guid>
    <pubDate>Tue, 02 Jun 2026 09:53:19 +0000</pubDate>
    <source>Malwarebytes Labs</source>
    <category>Threat Intel</category>
    <category>Breach</category>
    <description><![CDATA[California has sued the former shell of DNA testing company 23andMe over alleged security failures and misleading statements surrounding its 2023 data breach. On May 27, 2026, Attorney General Rob Bonta filed suit in…]]></description>
  </item>
  <item>
    <title><![CDATA[Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT]]></title>
    <link>https://thehackernews.com/2026/06/pakistan-linked-sidecopy-targets.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/pakistan-linked-sidecopy-targets.html</guid>
    <pubDate>Tue, 02 Jun 2026 09:05:40 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Phishing</category>
    <category>Malware</category>
    <category>Research</category>
    <description><![CDATA[Cybersecurity researchers have disclosed details of a spear-phishing campaign likely undertaken by the Pakistan-aligned SideCopy group targeting Afghanistan's Ministry of Finance with an open-source remote access trojan…]]></description>
  </item>
  <item>
    <title><![CDATA[Fake virus alerts are invading mobile games]]></title>
    <link>https://www.malwarebytes.com/blog/mobile/2026/06/fake-virus-alerts-are-invading-mobile-games</link>
    <guid isPermaLink="true">https://www.malwarebytes.com/blog/mobile/2026/06/fake-virus-alerts-are-invading-mobile-games</guid>
    <pubDate>Tue, 02 Jun 2026 09:03:55 +0000</pubDate>
    <source>Malwarebytes Labs</source>
    <category>Threat Intel</category>
    <description><![CDATA[Sometimes it happens. You’re happily playing a game on your phone or laptop when suddenly alarms pop up out of nowhere: “Your device is infected!” “Your iCloud is full!” “Your account is restricted for watching porn!”…]]></description>
  </item>
  <item>
    <title><![CDATA[New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)]]></title>
    <link>https://isc.sans.edu/diary/rss/33040</link>
    <guid isPermaLink="true">https://isc.sans.edu/diary/rss/33040</guid>
    <pubDate>Tue, 02 Jun 2026 07:29:25 +0000</pubDate>
    <source>SANS Internet Storm Center</source>
    <category>Research</category>
    <category>Phishing</category>
    <description><![CDATA[For a few days, my SANS ISC mailbox is flooded with emails that delivers SVG files. An SVG ("Scalable Vector Graphic") is a web-friendly vector file format used for graphics and icons. No URL in the body, just “an…]]></description>
  </item>
  <item>
    <title><![CDATA[175: Bayrob]]></title>
    <link>https://darknetdiaries.com/episode/175/</link>
    <guid isPermaLink="true">https://darknetdiaries.com/episode/175/</guid>
    <pubDate>Tue, 02 Jun 2026 07:00:00 +0000</pubDate>
    <source>Darknet Diaries</source>
    <category>Podcast</category>
    <category>Malware</category>
    <description><![CDATA[It started with a fake car listing on eBay. What looked like a simple online scam quietly grew, over more than a decade, into one of the most sophisticated cybercrime operations the FBI had ever traced. Custom malware…]]></description>
  </item>
  <item>
    <title><![CDATA[Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded]]></title>
    <link>https://thehackernews.com/2026/06/dashlane-discloses-brute-force-attack.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/dashlane-discloses-brute-force-attack.html</guid>
    <pubDate>Tue, 02 Jun 2026 03:55:25 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <description><![CDATA[Password manager Dashlane has disclosed that "fewer than" 20 users on the personal subscription plan had their encrypted vaults downloaded following a brute-force attack launched by an unknown party. On May 31, 2026…]]></description>
  </item>
  <item>
    <title><![CDATA[Anthropic to Open Mythos AI to EU's ENISA]]></title>
    <link>https://www.darkreading.com/cyber-risk/anthropic-mythos-ai-eu-enisa</link>
    <guid isPermaLink="true">https://www.darkreading.com/cyber-risk/anthropic-mythos-ai-eu-enisa</guid>
    <pubDate>Mon, 01 Jun 2026 21:07:48 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <description><![CDATA[The European security agency's entry to Project Glasswing is the result of "strong bilateral cooperation" between the European Commission and Anthropic.]]></description>
  </item>
  <item>
    <title><![CDATA[Microsoft's Zero-Day Legal Threats Spark Backlash]]></title>
    <link>https://www.darkreading.com/application-security/microsoft-zero-day-legal-threats-backlash</link>
    <guid isPermaLink="true">https://www.darkreading.com/application-security/microsoft-zero-day-legal-threats-backlash</guid>
    <pubDate>Mon, 01 Jun 2026 18:52:26 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <category>Vuln</category>
    <category>Research</category>
    <description><![CDATA[After a disgruntled security researcher published several zero-day exploits in recent weeks, Microsoft seemingly indicated criminal charges were in order.]]></description>
  </item>
  <item>
    <title><![CDATA[Broadcom VMware security advisory (AV26-536)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-536</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-536</guid>
    <pubDate>Mon, 01 Jun 2026 18:31:58 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Qualcomm security advisory – June 2026 monthly rollup (AV26-535)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/qualcomm-security-advisory-june-2026-monthly-rollup-av26-535</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/qualcomm-security-advisory-june-2026-monthly-rollup-av26-535</guid>
    <pubDate>Mon, 01 Jun 2026 18:27:07 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm]]></title>
    <link>https://thehackernews.com/2026/06/miasma-supply-chain-attack-compromises.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/miasma-supply-chain-attack-compromises.html</guid>
    <pubDate>Mon, 01 Jun 2026 17:40:28 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Malware</category>
    <category>Breach</category>
    <description><![CDATA[A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. "This…]]></description>
  </item>
  <item>
    <title><![CDATA[Oracle security advisory – July 2024 quarterly rollup (AV24-401) - Update 1]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/oracle-security-advisory-july-2024-quarterly-rollup-av24-401</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/oracle-security-advisory-july-2024-quarterly-rollup-av24-401</guid>
    <pubDate>Mon, 01 Jun 2026 17:39:35 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts]]></title>
    <link>https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/</link>
    <guid isPermaLink="true">https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/</guid>
    <pubDate>Mon, 01 Jun 2026 17:32:50 +0000</pubDate>
    <source>Krebs On Security</source>
    <category>News</category>
    <description><![CDATA[The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on…]]></description>
  </item>
  <item>
    <title><![CDATA[Vulnerability Disclosure in the Age of AI]]></title>
    <link>https://www.schneier.com/blog/archives/2026/06/vulnerability-disclosure-in-the-age-of-ai.html</link>
    <guid isPermaLink="true">https://www.schneier.com/blog/archives/2026/06/vulnerability-disclosure-in-the-age-of-ai.html</guid>
    <pubDate>Mon, 01 Jun 2026 16:49:39 +0000</pubDate>
    <source>Schneier on Security</source>
    <category>Media</category>
    <category>Vuln</category>
    <description><![CDATA[New article: “ Responsible Disclosure in the Age of AI: A Call for Urgent Action ,” by Melissa Hathaway. Abstract: Artificial intelligence is fundamentally reshaping the balance between vulnerability discovery and…]]></description>
  </item>
  <item>
    <title><![CDATA[Plesk security advisory (AV26-534)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/plesk-security-advisory-av26-534</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/plesk-security-advisory-av26-534</guid>
    <pubDate>Mon, 01 Jun 2026 14:56:27 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Ivanti security advisory (AV26-533)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/ivanti-security-advisory-av26-533</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/ivanti-security-advisory-av26-533</guid>
    <pubDate>Mon, 01 Jun 2026 14:50:50 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Fake BlueWallet steals passwords, accounts, and crypto from Macs]]></title>
    <link>https://www.malwarebytes.com/blog/threat-intel/2026/06/fake-bluewallet-steals-passwords-accounts-and-crypto-from-macs</link>
    <guid isPermaLink="true">https://www.malwarebytes.com/blog/threat-intel/2026/06/fake-bluewallet-steals-passwords-accounts-and-crypto-from-macs</guid>
    <pubDate>Mon, 01 Jun 2026 14:40:25 +0000</pubDate>
    <source>Malwarebytes Labs</source>
    <category>Threat Intel</category>
    <category>Breach</category>
    <category>Crypto</category>
    <description><![CDATA[A fake website impersonating BlueWallet (a real Bitcoin wallet) is targeting Mac users with a simple but effective attack. BlueWallet itself has not been compromised. Instead, cybercriminals have stolen the name and…]]></description>
  </item>
  <item>
    <title><![CDATA[Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit]]></title>
    <link>https://www.darkreading.com/threat-intelligence/patch-palo-alto-auth-bypass-bug-exploit</link>
    <guid isPermaLink="true">https://www.darkreading.com/threat-intelligence/patch-palo-alto-auth-bypass-bug-exploit</guid>
    <pubDate>Mon, 01 Jun 2026 14:35:51 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <category>Vuln</category>
    <description><![CDATA[Exploiting the PAN-OS GlobalProtect VPN vulnerability requires certain conditions, but adversaries have done so in two attack waves that started in mid-May.]]></description>
  </item>
  <item>
    <title><![CDATA[⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More]]></title>
    <link>https://thehackernews.com/2026/06/weekly-recap-new-linux-flaw-pan-os.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/weekly-recap-new-linux-flaw-pan-os.html</guid>
    <pubDate>Mon, 01 Jun 2026 13:59:54 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Vuln</category>
    <category>Phishing</category>
    <description><![CDATA[Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools…]]></description>
  </item>
  <item>
    <title><![CDATA[Mozilla security advisory (AV26-532)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/mozilla-security-advisory-av26-532</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/mozilla-security-advisory-av26-532</guid>
    <pubDate>Mon, 01 Jun 2026 13:25:32 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Red Hat security advisory (AV26-531)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/red-hat-security-advisory-av26-531</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/red-hat-security-advisory-av26-531</guid>
    <pubDate>Mon, 01 Jun 2026 13:19:43 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[[Control systems] CISA ICS security advisories (AV26–530)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-530</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-530</guid>
    <pubDate>Mon, 01 Jun 2026 13:15:12 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <category>ICS/OT</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Ubuntu security advisory (AV26-529)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/ubuntu-security-advisory-av26-529</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/ubuntu-security-advisory-av26-529</guid>
    <pubDate>Mon, 01 Jun 2026 13:07:31 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Dell security advisory (AV26-528)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/dell-security-advisory-av26-528</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/dell-security-advisory-av26-528</guid>
    <pubDate>Mon, 01 Jun 2026 13:01:54 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)]]></title>
    <link>https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed</link>
    <guid isPermaLink="true">https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed</guid>
    <pubDate>Mon, 01 Jun 2026 13:00:00 +0000</pubDate>
    <source>Rapid7 Blog</source>
    <category>Research</category>
    <category>CVE</category>
    <category>Vuln</category>
    <category>Research</category>
    <description><![CDATA[Overview Rapid7 Labs conducted a zero-day research project against an HP Poly VVX 450 Voice over Internet Protocol (VoIP) phone. This research resulted in the discovery of a critical unauthenticated stack-based buffer…]]></description>
  </item>
  <item>
    <title><![CDATA[CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation]]></title>
    <link>https://www.rapid7.com/blog/post/ve-cve-2026-0826-how-an-old-bug-can-feed-ai-powered-impersonation</link>
    <guid isPermaLink="true">https://www.rapid7.com/blog/post/ve-cve-2026-0826-how-an-old-bug-can-feed-ai-powered-impersonation</guid>
    <pubDate>Mon, 01 Jun 2026 13:00:00 +0000</pubDate>
    <source>Rapid7 Blog</source>
    <category>Research</category>
    <category>CVE</category>
    <description><![CDATA[One of the more persistent myths in security is that old bug classes become old problems. They don’t. They just show up in different places, under different conditions, and usually at the exact moment we’ve convinced…]]></description>
  </item>
  <item>
    <title><![CDATA[IBM security advisory (AV26-527)]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-527</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-527</guid>
    <pubDate>Mon, 01 Jun 2026 12:52:02 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[Microsoft security advisory – May 2026 monthly rollup (AV26-456) – Update 2]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-may-2026-monthly-rollup-av26-456</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-may-2026-monthly-rollup-av26-456</guid>
    <pubDate>Mon, 01 Jun 2026 12:34:39 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  <item>
    <title><![CDATA[CISA Adds One Known Exploited Vulnerability to Catalog]]></title>
    <link>https://www.cisa.gov/news-events/alerts/2026/06/01/cisa-adds-one-known-exploited-vulnerability-catalog</link>
    <guid isPermaLink="true">https://www.cisa.gov/news-events/alerts/2026/06/01/cisa-adds-one-known-exploited-vulnerability-catalog</guid>
    <pubDate>Mon, 01 Jun 2026 12:00:00 +0000</pubDate>
    <source>CISA Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <category>CVE</category>
    <category>Vuln</category>
    <description><![CDATA[CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2024-21182 Oracle WebLogic Server Unspecified Vulnerability This type of…]]></description>
  </item>
  <item>
    <title><![CDATA[China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan]]></title>
    <link>https://thehackernews.com/2026/06/china-aligned-groups-ramp-up-attacks.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/china-aligned-groups-ramp-up-attacks.html</guid>
    <pubDate>Mon, 01 Jun 2026 11:54:24 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>APT</category>
    <description><![CDATA[A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent. According to Seqrite Labs, targets of…]]></description>
  </item>
  <item>
    <title><![CDATA[The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools]]></title>
    <link>https://thehackernews.com/2026/06/the-security-growth-platform-why-msps.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/the-security-growth-platform-why-msps.html</guid>
    <pubDate>Mon, 01 Jun 2026 11:30:00 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <description><![CDATA[Three years ago, the practical question for an MSP building a cybersecurity practice was which "vCISO platform" to buy. The term was good shorthand for the work at the time: assessments, advisory, reporting, maybe a…]]></description>
  </item>
  <item>
    <title><![CDATA[OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack]]></title>
    <link>https://thehackernews.com/2026/06/openai-codex-authentication-tokens.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/openai-codex-authentication-tokens.html</guid>
    <pubDate>Mon, 01 Jun 2026 09:31:15 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Research</category>
    <description><![CDATA[Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui-android, is…]]></description>
  </item>
  <item>
    <title><![CDATA[Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts]]></title>
    <link>https://thehackernews.com/2026/06/critical-wp-maps-pro-flaw-actively.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/06/critical-wp-maps-pro-flaw-actively.html</guid>
    <pubDate>Mon, 01 Jun 2026 08:45:29 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Vuln</category>
    <description><![CDATA[Threat actors are attempting to actively exploit a critical security flaw impacting WP Maps Pro, a WordPress plugin that has had over 15,000 sales on the Envato Market, to create malicious administrator accounts on…]]></description>
  </item>
  <item>
    <title><![CDATA[Your phone called. It needs a cleanup]]></title>
    <link>https://www.malwarebytes.com/blog/mobile/2026/06/your-phone-called-it-needs-a-cleanup</link>
    <guid isPermaLink="true">https://www.malwarebytes.com/blog/mobile/2026/06/your-phone-called-it-needs-a-cleanup</guid>
    <pubDate>Mon, 01 Jun 2026 08:31:44 +0000</pubDate>
    <source>Malwarebytes Labs</source>
    <category>Threat Intel</category>
    <description><![CDATA[Does it sometimes take your phone a few minutes to accomplish one simple task? That can be wildly frustrating. But you’re in luck, because we’ve got a free tool that scans your phone for leftover files, temporary data…]]></description>
  </item>
  <item>
    <title><![CDATA[Rapid7 and Exclusive Networks Expand Partnership Across the Nordics]]></title>
    <link>https://www.rapid7.com/blog/post/c-rapid7-exclusive-networks-expand-nordics-partnership-stronger-cybersecurity-outcomes-together</link>
    <guid isPermaLink="true">https://www.rapid7.com/blog/post/c-rapid7-exclusive-networks-expand-nordics-partnership-stronger-cybersecurity-outcomes-together</guid>
    <pubDate>Mon, 01 Jun 2026 08:00:00 +0000</pubDate>
    <source>Rapid7 Blog</source>
    <category>Research</category>
    <description><![CDATA[Building stronger cybersecurity outcomes together The cybersecurity landscape across the Nordics is evolving rapidly. Organizations are facing increasing pressure to modernize security operations, reduce complexity, and…]]></description>
  </item>
  <item>
    <title><![CDATA[A week in security (May 25 &#8211; May 31)]]></title>
    <link>https://www.malwarebytes.com/blog/news/2026/06/a-week-in-security-may-25-may-31</link>
    <guid isPermaLink="true">https://www.malwarebytes.com/blog/news/2026/06/a-week-in-security-may-25-may-31</guid>
    <pubDate>Mon, 01 Jun 2026 07:01:00 +0000</pubDate>
    <source>Malwarebytes Labs</source>
    <category>Threat Intel</category>
    <description><![CDATA[Last week on Malwarebytes Labs: Payment apps are watching what you say (Lock and Code S07E11) Scammers pretending to be Microsoft had help from US executives 700+ education and tech websites hijacked in huge ClickFix…]]></description>
  </item>
  <item>
    <title><![CDATA[Payment apps are watching what you say (Lock and Code S07E11)]]></title>
    <link>https://www.malwarebytes.com/blog/podcast/2026/05/payment-apps-are-watching-what-you-say-lock-and-code-s07e11</link>
    <guid isPermaLink="true">https://www.malwarebytes.com/blog/podcast/2026/05/payment-apps-are-watching-what-you-say-lock-and-code-s07e11</guid>
    <pubDate>Mon, 01 Jun 2026 01:52:57 +0000</pubDate>
    <source>Malwarebytes Labs</source>
    <category>Threat Intel</category>
    <description><![CDATA[This week on the Lock and Code podcast… In the United States today, you can have your bank account closed, your credit cards cancelled, and your online payments revoked for any number of crimes, like funding terrorism…]]></description>
  </item>
  <item>
    <title><![CDATA[Unidentified RAT pushes NetSupport RAT, (Mon, Jun 1st)]]></title>
    <link>https://isc.sans.edu/diary/rss/33034</link>
    <guid isPermaLink="true">https://isc.sans.edu/diary/rss/33034</guid>
    <pubDate>Mon, 01 Jun 2026 00:02:30 +0000</pubDate>
    <source>SANS Internet Storm Center</source>
    <category>Research</category>
    <category>Malware</category>
    <description><![CDATA[Introduction]]></description>
  </item>
  <item>
    <title><![CDATA[YARA-X 1.17.0 Release, (Sun, May 31st)]]></title>
    <link>https://isc.sans.edu/diary/rss/33032</link>
    <guid isPermaLink="true">https://isc.sans.edu/diary/rss/33032</guid>
    <pubDate>Sun, 31 May 2026 16:01:29 +0000</pubDate>
    <source>SANS Internet Storm Center</source>
    <category>Research</category>
    <description><![CDATA[YARA-X's 1.17.0 release brings 5 improvements (several performance improvements) and 1 bugfix.]]></description>
  </item>
  <item>
    <title><![CDATA[Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices]]></title>
    <link>https://thehackernews.com/2026/05/dutch-authorities-dismantle-botnet.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/05/dutch-authorities-dismantle-botnet.html</guid>
    <pubDate>Sun, 31 May 2026 12:22:12 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>Malware</category>
    <description><![CDATA[Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks. The bot network, per the…]]></description>
  </item>
  <item>
    <title><![CDATA[Cybercrime Crew Claims It Hacked Mike Lindell’s MyPillow]]></title>
    <link>https://www.wired.com/story/security-news-this-week-cybercrime-crew-claims-it-hacked-mike-lindells-mypillow/</link>
    <guid isPermaLink="true">https://www.wired.com/story/security-news-this-week-cybercrime-crew-claims-it-hacked-mike-lindells-mypillow/</guid>
    <pubDate>Sat, 30 May 2026 10:30:00 +0000</pubDate>
    <source>Wired Security</source>
    <category>Media</category>
    <category>Ransom</category>
    <category>Privacy</category>
    <description><![CDATA[Plus: A ransomware group is now stealing data in person, BusPatrol wants to hand its license plate surveillance data to the cops, and more.]]></description>
  </item>
  <item>
    <title><![CDATA[PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation]]></title>
    <link>https://thehackernews.com/2026/05/pan-os-globalprotect-authentication.html</link>
    <guid isPermaLink="true">https://thehackernews.com/2026/05/pan-os-globalprotect-authentication.html</guid>
    <pubDate>Sat, 30 May 2026 06:41:26 +0000</pubDate>
    <source>The Hacker News</source>
    <category>News</category>
    <category>CVE</category>
    <category>Vuln</category>
    <description><![CDATA[Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS…]]></description>
  </item>
  <item>
    <title><![CDATA[Friday Squid Blogging: Another Squid]]></title>
    <link>https://www.schneier.com/blog/archives/2026/05/friday-squid-blogging-another-squid.html</link>
    <guid isPermaLink="true">https://www.schneier.com/blog/archives/2026/05/friday-squid-blogging-another-squid.html</guid>
    <pubDate>Fri, 29 May 2026 21:05:33 +0000</pubDate>
    <source>Schneier on Security</source>
    <category>Media</category>
    <description><![CDATA[Someone named “Squid” seems to be a “ West Country legend .” As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.]]></description>
  </item>
  <item>
    <title><![CDATA[Name That Toon: Mark of (Cybersecurity) Progress]]></title>
    <link>https://www.darkreading.com/cloud-security/name-that-toon-mark-of-cybersecurity-progress</link>
    <guid isPermaLink="true">https://www.darkreading.com/cloud-security/name-that-toon-mark-of-cybersecurity-progress</guid>
    <pubDate>Fri, 29 May 2026 20:22:04 +0000</pubDate>
    <source>Dark Reading</source>
    <category>News</category>
    <description><![CDATA[As part of Dark Reading's 20th anniversary package, we asked readers for a cybersecurity-related caption that captures their thoughts about the industry's last two decades.]]></description>
  </item>
  <item>
    <title><![CDATA[Palo Alto Networks security advisory (AV26-462) – Update 1]]></title>
    <link>https://cyber.gc.ca/en/alerts-advisories/palo-alto-networks-security-advisory-av26-462</link>
    <guid isPermaLink="true">https://cyber.gc.ca/en/alerts-advisories/palo-alto-networks-security-advisory-av26-462</guid>
    <pubDate>Fri, 29 May 2026 20:10:00 +0000</pubDate>
    <source>CCCS Alerts &amp; Advisories</source>
    <category>Advisory</category>
    <description><![CDATA[]]></description>
  </item>
  </channel>
</rss>
