Claude Opus 4.8 Finds Vulnerability in Zcash Privacy System That Could Be Used to Create Hard-to-Detect Counterfeit Coins

305/69 Monday, June 8, 2026 Reports indicate that security researcher Taylor Hornby used Claude Opus 4.8 to help discover a critical vulnerability in Zcash’s Orchard Privacy Pool, the newer shielded transaction system of Zcash that has been in use since May 2022. The system uses Zero-Knowledge Proof technology to verify the validity of transactions without […]

chanapon

June 8, 2026

Critical Everest Forms Pro Vulnerability Exploited to Take Over WordPress Websites

304/69 Monday, June 8, 2026 Reports indicate that threat actors are actively exploiting a critical vulnerability (CVE-2026-3300) affecting the Everest Forms Pro plugin for the WordPress content management system, versions 1.9.12 and earlier. The vulnerability allows attackers to execute malicious code on the server without authentication, enabling threat actors to fully take control of affected […]

chanapon

June 8, 2026

WordPress Administrators Urged to Update Kirki and Burst Statistics Plugins Following Website Takeover Risks

303/69 Friday, June 5, 2026 Researchers from Defiant (Wordfence) have warned that threat actors are actively exploiting vulnerabilities in the WordPress plugins Kirki and Burst Statistics to escalate privileges and take control of vulnerable websites. The first flaw, tracked as CVE-2026-8206 (CVSS 9.8), affects Kirki versions 6.0.0 through 6.0.6. It is a privilege escalation and […]

sittisak mintaboon

June 5, 2026

Cyber Espionage Campaign Targeted Stock Exchange Executive’s Outlook Account for Over Five Months

302/69 Friday, June 5, 2026 Researchers from the Threat Hunting teams at Broadcom Symantec and Carbon Black have uncovered a cyber espionage campaign targeting the Outlook account of a senior executive at a major global stock exchange. The attackers maintained access to the compromised mailbox for approximately 150 days, from October 2025 to March 2026. […]

sittisak mintaboon

June 5, 2026

Threat Actors Leverage AI to Develop Automated Malware Testing Platform for EDR Evasion

301/69 Friday, June 5, 2026 Cybersecurity researchers have revealed that threat actors are increasingly leveraging artificial intelligence (AI) to develop automated malware testing platforms designed to evade Endpoint Detection and Response (EDR) solutions. The activity was observed targeting leading security products, including Sophos, CrowdStrike, and Microsoft Defender. The campaign was uncovered after suspicious payloads triggered […]

sittisak mintaboon

June 5, 2026

Google Releases Android Security Updates Addressing 124 Vulnerabilities, Including Actively Exploited CVE-2025-48595

300/69 Thursday, June 4, 2026 Google has released the June 2026 Android Security Bulletin, addressing a total of 124 vulnerabilities. Among the most significant is CVE-2025-48595, a privilege escalation vulnerability with a CVSS score of 8.4 that has reportedly been exploited in the wild. Google stated that there are indications of “limited, targeted exploitation” of […]

sittisak mintaboon

June 4, 2026

GoDaddy Discovers Malware on Nearly 2,000 WordPress Sites Using Steam as a Command-and-Control Infrastructure

299/69 Thursday, June 4, 2026 Security researchers at GoDaddy have reported the discovery of malware infecting approximately 1,980 WordPress websites. The malware uses the Valve Corporation Steam Community platform as its Command-and-Control (C2) infrastructure. Instead of communicating with traditional malicious servers, the malware retrieves commands from comments posted on Steam user profiles. While these comments […]

sittisak mintaboon

June 4, 2026

OpenAI Announces GPT-5.5 System Updates and Plans to Retire Older AI Models

298/69 Thursday, June 4, 2026 OpenAI has announced a new round of system updates aimed at improving the performance of GPT-5.5 Instant while also preparing to retire several older AI models, including o3 and GPT-4.5. The changes will directly affect paid users currently relying on these models. According to the company, the transition is intended […]

sittisak mintaboon

June 4, 2026

Warning: Windows Netlogon Vulnerability Actively Exploited in the Wild; Administrators Urged to Patch Immediately

297/69 Tuesday, June 2, 2026 The Belgian Centre for Cyber Security (CCB) has warned that the Windows Netlogon vulnerability tracked as CVE-2026-41089 is being actively exploited in real-world attacks. The vulnerability is rated Critical and was addressed by Microsoft in its May 2026 security updates. The flaw affects the Netlogon service, a core component of […]

sittisak mintaboon

June 2, 2026

ShinyHunters Publishes Allegedly Stolen Charter Communications Data, Potentially Impacting More Than 5 Million Customers

296/69 Tuesday, June 2, 2026 Reports indicate that the cybercriminal group ShinyHunters has published data allegedly stolen from Charter Communications after the company reportedly refused to pay a ransom demand. Charter Communications is one of the largest telecommunications providers in the United States, offering internet, cable television, mobile, and landline phone services under the Spectrum […]

sittisak mintaboon

June 2, 2026
1 11 12 13 105