ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

06/08/2026 0 Comments 0 tags

Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

06/08/2026 0 Comments 0 tags

Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3

AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory

06/08/2026 0 Comments 0 tags

A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

06/08/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed a security issue with Apple’s iCloud Private Relay tool that can expose a user’s real IP address. Introduced with iOS 15, iCloud Private Relay employs a

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

06/08/2026 0 Comments 0 tags

Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

06/08/2026 0 Comments 0 tags

Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent’s tools with no check that a model turn had

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

06/08/2026 0 Comments 0 tags

Attackers broke into an organization’s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

06/08/2026 0 Comments 0 tags

A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

06/08/2026 0 Comments 0 tags

A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

06/08/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a “factory-shipped backdoor” implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in