AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

19/06/2026 0 Comments 0 tags

Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent to load an attacker’s web

Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

19/06/2026 0 Comments 0 tags

Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites. “With

CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices

19/06/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps to secure against ongoing malicious activity aimed at thousands of internet-accessible

From Assistive to Agentic: The AI Shift That’s Redefining Threat Management

19/06/2026 0 Comments 0 tags

Introduction The average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset data. But often, these tools are working in

Forget Data Leakage: Shadow AI’s Real Threat Is Access Control

19/06/2026 0 Comments 0 tags

The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security teams responded with usage policies, domain blocks, and data

Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data

19/06/2026 0 Comments 0 tags

Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026. To

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

19/06/2026 0 Comments 0 tags

Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users. The vulnerability, tracked as CVE-2025-20701

F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

18/06/2026 0 Comments 0 tags

F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems. The vulnerabilities are listed

ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories

18/06/2026 0 Comments 0 tags

The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery

INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023

18/06/2026 0 Comments 0 tags

Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most prolific cybercrime groups in 2026, claiming no less than 830 victims