Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability

25/06/2026 0 Comments 0 tags

An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code. According to Island, the extension, named Adblock for YouTube

ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories

25/06/2026 0 Comments 0 tags

It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working,

New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

25/06/2026 0 Comments 0 tags

A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst’s artificial intelligence (AI) tools and trick

Surviving the Mythos Era: Richard Bejtlich on the Case for NDR

25/06/2026 0 Comments 0 tags

Despite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation: What happened? What evidence do we have? How

New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns

25/06/2026 0 Comments 0 tags

A new, stealthy backdoor named Mistic has been deployed as part of suspected financially motivated attacks aimed at multiple organizations spanning insurance, education, IT, and professional services sectors since April

Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access

25/06/2026 0 Comments 0 tags

An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new

CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited

24/06/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB)

Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered

24/06/2026 0 Comments 0 tags

A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. “The

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

24/06/2026 0 Comments 0 tags

Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains. The “critical exploitable pattern” has been codenamed Cordyceps

Dawn of the Apex Agentic Adversary

24/06/2026 0 Comments 0 tags

We are standing at the end of an era we never thought to mourn: the era of human-speed threats. For years, cybersecurity moved to a rhythm organizations could follow. A