ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

22/06/2026 0 Comments 0 tags

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. “Attackers compromised

Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

22/06/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily read artificial intelligence

29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests

22/06/2026 0 Comments 0 tags

A heap over-read in the Squid web proxy can leak another user’s cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic

Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries

22/06/2026 0 Comments 0 tags

Google has set September 30, 2026, as the day it begins enforcing Android developer verification in the first four countries, and the major device-maker app stores are in from the start. On

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

22/06/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER. According to Elastic Security Labs, the campaign leverages

⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More

22/06/2026 0 Comments 0 tags

It’s Monday again. This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way

Stop Your Legacy Infrastructure from Hijacking Your AI Agents

22/06/2026 0 Comments 0 tags

Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for – how attackers are circumventing

Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices

22/06/2026 0 Comments 0 tags

Canada’s spy service got a judge’s permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets. The Federal Court released a

AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network

22/06/2026 0 Comments 0 tags

A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin’s XLab calls it AryStinger and

INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific

22/06/2026 0 Comments 0 tags

A new report from INTERPOL has revealed a “dramatic increase” in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration, new technologies, organized criminal networks, and