F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

18/06/2026 0 Comments 0 tags

F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems. The vulnerabilities are listed

ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories

18/06/2026 0 Comments 0 tags

The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery

INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023

18/06/2026 0 Comments 0 tags

Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most prolific cybercrime groups in 2026, claiming no less than 830 victims

Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2

18/06/2026 0 Comments 0 tags

Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign that has targeted users since February 2026. “The clipper in this campaign relies on Windows Script Host and ActiveX-driven logic

DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

18/06/2026 0 Comments 0 tags

Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure.

Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network

18/06/2026 0 Comments 0 tags

If an autonomous AI agent interacts with your company’s core intellectual property today, can your security team instantly name the person who authorized it? For most enterprises, the answer is

The Scripts on Your Checkout Page Are Now a PCI DSS Problem

18/06/2026 0 Comments 0 tags

An independent PCI assessor tested Reflectiz against the new PCI DSS rules. Here is the verdict: See the full QSA assessment here → When a customer types their card number

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

17/06/2026 0 Comments 0 tags

Microsoft has formally disclosed that it’s working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability has now been assigned the CVE identifier CVE-2026-50656 (CVSS score:

Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments

17/06/2026 0 Comments 0 tags

An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez, according to new findings from Check Point

Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

17/06/2026 0 Comments 0 tags

A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials. Ordinary stuff, until one move near the end. Before his command-and-control