Supply Chain Attack via CDN Affects Popular WordPress Plugins Used by More Than 1.2 Million Websites

324/69 Tuesday, June 16, 2026 Security researchers have disclosed a supply chain attack affecting WordPress websites using Awesome Motive’s OptinMonster, TrustPulse, and PushEngage plugins. The attackers injected malicious code into JavaScript files served through the provider’s CDN. As a result, websites loading the affected scripts may have received modified code from the original source, without […]

chanapon

June 16, 2026

Extradited Ukrainian Man Pleads Guilty to Involvement in Conti Ransomware Attacks

323/69 Tuesday, June 16, 2026 Oleksii Oleksiyovych Lytvynenko, a 44-year-old Ukrainian national who was extradited from Ireland to the United States, has pleaded guilty in a U.S. court to conspiracy to commit wire fraud for his role in the Conti ransomware operation. Conti was one of the cybercrime groups that caused significant damage during the […]

chanapon

June 16, 2026

FBI Partners with Private Sector to Disrupt Large-Scale AI-Powered Phishing Platform

322/69 Tuesday, June 16, 2026 The U.S. Federal Bureau of Investigation (FBI), together with Google and Lumen’s Black Lotus Labs, has taken action to disrupt and dismantle a large-scale cybercrime network operating as a Phishing-as-a-Service platform under the name Outsider Enterprise. The platform reportedly used artificial intelligence (AI) technology to create phishing websites designed to […]

chanapon

June 16, 2026

Gogs Releases Patch for Zero-Day Vulnerability That Could Lead to Remote Code Execution

Gogs has released a patch to address a critical zero-day vulnerability that has not yet been assigned a CVE identifier. The flaw is an Argument Injection vulnerability that could allow attackers to execute code remotely on affected servers. The vulnerability affects all Gogs versions up to 0.14.2, including 0.15.0+dev, and has been fixed in version […]

chanapon

June 10, 2026

CISA Adds BerriAI LiteLLM and Check Point Security Gateway Vulnerabilities to KEV Catalog After Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming that they have been actively exploited in attacks. The vulnerabilities are CVE-2026-42271 in BerriAI LiteLLM, a Command Injection flaw with a CVSS score of 8.7, and CVE-2026-50751 in Check Point Security Gateway, a Critical […]

chanapon

June 10, 2026

WhatsApp Blocks New Pegasus Spyware Campaign and Files Motion in U.S. Court Against Developer

WhatsApp has blocked a new wave of cyberattack activity linked to Pegasus spyware, developed by the Israeli company NSO Group. The company has also filed a motion in a U.S. federal court seeking sanctions against NSO Group for allegedly violating a previous court order that barred it from targeting users of the platform in connection […]

chanapon

June 10, 2026

Instagram Users Urged to Enable 2FA After Vulnerability Found in Account Recovery System

309/69 Tuesday, June 9, 2026 Meta disclosed that 20,225 Instagram accounts were taken over after attackers exploited a vulnerability in its AI-assisted account recovery system, known as High Touch Support (HTS), to request password reset links. The system was designed to help users recover access to their Instagram accounts when they are unable to log […]

chanapon

June 9, 2026

New C0XMO Botnet Malware Targets DD-WRT Router Vulnerability

307/69 Tuesday, June 9, 2026 Cybersecurity researchers from Fortinet have discovered a new botnet malware named C0XMO, which is derived from the Gafgyt botnet. The malware targets router devices running DD-WRT firmware, as well as video recording devices, video management platforms, and devices running the Android operating system. It can operate across various processor architectures, […]

chanapon

June 9, 2026

ShinyHunters Publishes Data Allegedly Stolen from DentaQuest, Potentially Affecting 2.6 Million People

308/69 Tuesday, June 9, 2026 Reports indicate that the ShinyHunters cybercrime group has published 234 GB of data it claims to have stolen from DentaQuest, one of the largest dental benefits administrators in the United States, after ransom negotiations failed. The group had listed DentaQuest on its Tor-based data leak site in May before later […]

chanapon

June 9, 2026

CISA Adds Actively Exploited SolarWinds Serv-U Vulnerability to KEV Catalog

306/69 Monday, June 8, 2026 CISA has added a high-severity vulnerability in SolarWinds Serv-U to its Known Exploited Vulnerabilities (KEV) catalog after finding evidence that it has been actively exploited in attacks. The vulnerability, tracked as CVE-2026-28318, has a CVSS score of 7.5 and is a Denial-of-Service (DoS) flaw that could cause service disruption under […]

chanapon

June 8, 2026
1 5 6 7