One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

15/06/2026 0 Comments 0 tags

A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search. Researchers at Varonis

⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More

15/06/2026 0 Comments 0 tags

Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This week is

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

15/06/2026 0 Comments 0 tags

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site

152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic

15/06/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a network of 152 Google Chrome extensions that act as new tab live wallpaper add-ons to distribute a potentially unwanted program (PUP) family. The cluster spans

The Onboarding Password Mistake That Creates Unnecessary Risk

15/06/2026 0 Comments 0 tags

Employee onboarding is a busy time for IT teams. New starters need devices, accounts, access permissions, and passwords, all delivered within a tight timeframe. That usually means sharing a temporary

Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

15/06/2026 0 Comments 0 tags

Palo Alto Networks has revealed that it has observed “active exploitation” of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The

Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts

15/06/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of fraudulent activity targeting users across the Middle East and North Africa by employing various fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations.

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

13/06/2026 0 Comments 0 tags

Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability,

U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals

13/06/2026 0 Comments 0 tags

Anthropic said on Friday it will “abruptly disable” its most advanced artificial intelligence (AI) models, Claude Fable 5 and Mythos 5, for all users after the U.S. government ordered it

Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

12/06/2026 0 Comments 0 tags

Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built