ICYMI: 2026-06-30
Latest Headlines
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses
GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials
Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks
Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat
Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History
Exploitation of Recent Oracle E-Business Suite Vulnerability Begins
Critical SimpleHelp Vulnerability Exploited for Malware Delivery
Quantifind Raises $200 Million for AI-Native Risk Intelligence
Anthropic’s Claude Code Reportedly Uses Hidden Code to Detect Chinese Users
Microsoft Teams’ New Feature Blocks Bots from Joining Meetings
NDSS Symposium Heads to Seoul in 2027 to Expand Global Cybersecurity Collaboration
Reflectiz to Host Webinar, Joined by Taboola, on Securing Third-Party Marketing in the AI Era
False Positive or First Sign of a Breach? How Tier 1 SOC Analysts Can Tell the Difference Faster
New BioShocking Attack Allows Attackers to Trick AI Browser and Leak Credentials
Multiple AirDrop and Quick Share Vulnerabilities Allow Attackers to Crash Devices
AppViewX Launches Global Partner Program Amid Rising Demand for Machine and Agent Identity Security
Critical Progress Kemp LoadMaster Vulnerability Enables Pre-Auth Remote Code Execution
Bing Search for ‘ManageEngine OpManager’ Delivers Akira Ransomware
Anthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower price
New BioShocking attack manipulates AI browser into data theft
Malicious PyPI packages give hackers control of Telegram bot servers
Fake Perplexity extension on Chrome Web Store tracked searches
Lessons from the Underground: How to Combat Business Email Compromise
Insurance giant Aflac discloses data breach after subsidiary hack
Kali Linux 2026.2 released with 9 new tools, NetHunter updates
Blackfield ransomware asks Nidec Corporation for $2 million ransom
CISA: Windows BlueHammer flaw now exploited by ransomware gangs
– MTZ