What we are reading

We are always asked what we are reading and paying attention to, whilst we want to keep you updated with this there is just too much stuff. Here is a sample of the daily reading lists.

'Boss Scam' Explained; How Cybercriminals Are Impersonating CEOs To Steal Millions
2026-06-23 18:10:02

... Your Car Run Better. Car Care Garage•371K views · 27:17. Go to channel Cybernews · World's Deadliest Computer Virus: WannaCry. Cybernews•4.1M views.

Go to External Site

 

Payouts King Ransomware Initial Access Broker Deploys New Edgecution Malware
2026-06-23 17:40:04

... malware delivery mechanism. The technique utilizes a malicious Microsoft Edge browser extension that exploits the Chrome native messaging protocol ...

Go to External Site

 

Signal Over Noise: Reachability Analysis Is the Reality Check SCA Has Been Missing
2026-06-23 17:00:10

A critical vulnerability in a package that is never invoked by your application may represent a different level of immediate risk than a lower ...

Go to External Site

 

The Four Critical Vulnerability Groups in Welsh Schools Amid Historic Heatwave | Streamline
2026-06-23 17:00:10

The Four Critical Vulnerability Groups in Welsh Schools Amid Historic Heatwave. A rare 40°C Met Office red alert has forced Welsh schools to ...

Go to External Site

 

Kaspersky's Sustainability report 2024–2025: building a safer cyberworld for people ...
2026-06-23 16:30:05

Kaspersky has released its Sustainability Report for 2024–2025, outlining how the company is working toward a safer and more resilient digital ...

Go to External Site

 

Abuse.ch MalwareBazaar (649 samples) | SOCRadar
2026-06-23 16:30:05

Threat intelligence report with 1298 extracted IOCs, MITRE ATT&CK mapping, and hunting context. Free by SOCRadar.

Go to External Site

 

Ankura CTIX FLASH Update – June 10, 2026 - Cybersecurity - United States - Mondaq
2026-06-23 16:30:04

Ankura presents a curated collection of expert insights spanning cybersecurity threats, regulatory compliance, dispute resolution, and enterprise ...

Go to External Site

 

WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
2026-06-23 16:30:04

Kaspersky says attackers are using fake WhatsApp document attachments to run VBScript malware and install ManageEngine RMM Central.

Go to External Site

 

Aikido Partners with Drydock to Bring Pre-Publish Malware Review to npm and PyPI
2026-06-23 16:30:04

We're partnering with Drydock so maintainers can see exactly what's inside a package before they approve it, catching malware before it ships instead ...

Go to External Site

 

Can AI beat AI? 3 challenges with VulnOps adoption | RL Blog - ReversingLabs
2026-06-23 16:30:04

SecOps leaders must tackle cost and risk to deliver autonomous vulnerability operations. But with frontier AI, it's critical.

Go to External Site

 

Incransom Targets Belpointe Asset Management in Latest Ransomware Attack - DeXpose
2026-06-23 16:30:04

Incransom hits Belpointe Asset Management in a significant ransomware incident, threatening to leak 400GB of data.

Go to External Site

 

FBI warns of cyber criminals' use of traffic distribution system in financial scams
2026-06-23 16:30:04

The FBI said in a public service announcement that cyber criminals are using traffic distribution systems to gain access to victim networks for ...

Go to External Site

 

Inside the dark web: Stolen identities for 95¢, malware, and scams-for-hire
2026-06-23 16:30:03

Beyond these forums, we encountered dedicated cybercrime marketplaces. These function like online stores where hackers and fraudsters can buy and sell ...

Go to External Site

 

Lehis Victory Highlights Estonian Fencing's Dual Challenge | shortl.ee
2026-06-23 16:10:11

... critical vulnerability. This dichotomy presents a strategic challenge for Estonian fencing, requiring a focused approach to mental resilience and ...

Go to External Site

 

DifyTap Flaws Expose AI Data Across Tenants on Platform Powering 1M+ Apps
2026-06-23 16:10:10

Another critical vulnerability, CVE-2026-41948, has a CVSS score of 9.4 and affects the Plugin Daemon service, which executes plugins. This flaw ...

Go to External Site

 

Cordyceps Supply Chain Flaw Impacting Code Repositories at thousands of Organizations
2026-06-23 16:10:10

Named Cordyceps after the parasitic fungus known for taking over its hosts, this critical vulnerability quietly burrows into software development ...

Go to External Site

 

What the Fortibleed campaign means for organizations running FortiGate firewalls - Help Net Security
2026-06-23 15:50:15

Throughout the operation, the attackers used CyberStrike, a legitimate open-source penetration testing AI agent, to automate reconnaissance ...

Go to External Site

 

WhatsApp Malware Alert: Hackers Hijacking Trusted Accounts To Spread Malicious Files - LatestLY
2026-06-23 15:50:14

This global campaign affects regions including Asia and South America, masquerading as Windows updates to bypass security. Users are urged to ...

Go to External Site

 

Windows Secure Boot certificates expire tomorrow. Don't ignore this deadline | PCWorld
2026-06-23 15:50:14

Users must install latest Windows updates to receive new certificates, as failure to update could cause serious boot failures. While the deadline ...

Go to External Site

 

OpenAI Daybreak Expands With GPT-5.5-Cyber, Codex Security and Patch the Planet
2026-06-23 14:50:16

GPT-5.5-Cyber is meant for narrower, higher-risk authorized workflows such as red teaming, exploit validation, penetration testing, reverse ...

Go to External Site

 

The Exploit Doesn't Exist. You Can Still Prove It Works Against You - Bleeping Computer
2026-06-23 14:50:15

Picus does it too, with Autonomous Penetration Testing. No argument there. But, while automating the launch makes you faster; it doesn't change ...

Go to External Site

 

Hacker employs Claude to breach booking firms, leaves millions of records publicly accessible
2026-06-23 14:50:15

Attacker bypassed AI guardrails by disguising malicious activity as legitimate penetration testing, compromising multiple accommodation companies.

Go to External Site

 

Five Eyes warn advanced AI could transform cyber capabilities within months - ForkLog
2026-06-23 14:50:07

It is important to distinguish several sources: the NCSC's March blog, the April assessment of Claude Mythos Preview and later AISI assessments. On ...

Go to External Site

 

INCENTIVE FOR CENTENARIANS | Photos - Philippine News Agency
2026-06-23 14:50:07

INCENTIVE FOR CENTENARIANS. Dr. Cesar A. Adegue, director of the National Commission of Senior Citizens (NCSC) in the Davao Region (right), ...

Go to External Site

 

Week 25: Fake voice messages spread malware and target login details
2026-06-23 14:50:07

23.06.2026 - Last week, the NCSC received a higher than usual number of reports about a scam involving fake voicemail messages sent via email.

Go to External Site

 

The hidden risks of unofficial streaming websites | The Daily Star
2026-06-23 14:30:06

One of the most talked about concerns is exposure to malware. Untrusted streaming sites often have hidden scripts or misleading download buttons that ...

Go to External Site

 

Hackers steal passport and driver's license data of 3 million Texans - Malwarebytes
2026-06-23 14:30:05

A breach at a Texas Parks and Wildlife Department vendor exposed personal information belonging to more than three million Texans.

Go to External Site

 

Microsoft links Mastra AI supply chain attack to North Korean hackers - Escudo Digital
2026-06-23 14:30:05

The operation that compromised dozens of Mastra AI framework packages has, according to Microsoft, a clear culprit: North Korea's Sapphire Sleet, ...

Go to External Site

 

SocGholish Takedown Highlights Malicious TDS Threats - Dark Reading
2026-06-23 14:30:04

SocGholish uses traffic distribution systems (TDSs) to provide initial access into victims' networks for cybercrime groups such as the notorious ...

Go to External Site

 

New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto - Hackread
2026-06-23 14:30:04

Microsoft warns of a new dual-action cryptocurrency clipper (CryptoBandits Malware) spreading through USB devices to alter wallet addresses and ...

Go to External Site

 

Meta pauses controversial employee-tracking program after security review | Malwarebytes
2026-06-23 14:30:04

Meta has paused its controversial employee-tracking program. Unfortunately, employee privacy wasn't what stopped it.

Go to External Site

 

Fake bosses, real losses: Govt alerts businesses to rising CEO impersonation scam
2026-06-23 14:30:04

I4C warns that cybercriminals are hijacking executive WhatsApp accounts and impersonating senior leaders to trick finance teams into transferring ...

Go to External Site

 

Critical FFmpeg Vulnerability Enables Weaponized Media File Attacks - Cyber Press
2026-06-23 13:10:13

JFrog Security Research has disclosed a critical vulnerability in FFmpeg, dubbed PixelSmash (CVE-2026-8461), carrying a CVSS score of 8.8 (High).

Go to External Site

 

USA Rare Earth vs MP Materials: The Trade Secrets Battle Explained - Discovery Alert
2026-06-23 13:10:13

However, standard sintered NdFeB magnets have a critical vulnerability: their magnetic performance degrades significantly at elevated temperatures.

Go to External Site

 

EU Bets on Digital Euro to Break Silicon Valley's Stranglehold on Payments | Streamline
2026-06-23 13:10:13

... critical vulnerability to the bloc's economic sovereignty. The digital euro aims to reclaim control over the continent's daily financial ...

Go to External Site

 

Tata Electronics Hit by Data Breach; Apple, Tesla Files Allegedly Exposed | Whalesbook
2026-06-23 13:10:13

Why This Matters for the Supply Chain. For investors and industry observers, this incident highlights a critical vulnerability in global supply chains ...

Go to External Site

 

iPhone XS, XR And Older Devices At Risk After This Apple Chip Flaw: What To Do
2026-06-23 13:10:12

Older iPhone users now have a reason to worry after a cybersecurity group has revealed a critical vulnerability in Apple's older chips that may help ...

Go to External Site

 

Researcher Earns $148,337 for Google Cloud Production RCE Vulnerability
2026-06-23 13:10:12

A critical vulnerability has been disclosed in FFmpeg's MagicYUV decoder that allows attackers to weaponize… 1 hour ago. Hackers Using ...

Go to External Site

 

New Phishing Attack Abuses Outlook and Microsoft 365 Groups Features to Attack Users
2026-06-23 13:10:12

A critical vulnerability has been disclosed in FFmpeg's MagicYUV decoder that allows attackers to weaponize… 45 minutes ago. Hackers Using ...

Go to External Site

 

Critical libssh2 Vulnerability Allows Attackers to Execute Remote Code Via Malicious SSH packets
2026-06-23 13:10:12

A critical vulnerability has been disclosed in FFmpeg's MagicYUV decoder that allows attackers to weaponize… 22 minutes ago. Hackers Using ...

Go to External Site

 

Critical FFmpeg Vulnerability Allows Attackers to Weaponize Media Files
2026-06-23 13:10:12

A critical vulnerability has been disclosed in FFmpeg's MagicYUV decoder that allows attackers to weaponize seemingly harmless media files and, in ...

Go to External Site

 

Death Toll Reaches 254 as Rapidly Spreading Ebola Outbreak Devastates DR Congo ...
2026-06-23 13:10:12

The highly porous borders between the DRC, Uganda, and Kenya represent a critical vulnerability for the entire region. The Kenyan Ministry of ...

Go to External Site

 

Mercedes reveals battery failures behind Russell and Antonelli's dramatic F1 race retirements
2026-06-23 13:10:11

The incidents, which occurred immediately after the drivers unleashed maximum power from their hybrid systems, have laid bare a critical vulnerability ...

Go to External Site

 

Five Eyes Spy Alliance Warns Anthropic's AI Bypasses Cybersecurity Defenses | Streamline
2026-06-23 13:10:11

Cybersecurity experts in Nairobi warn that the proliferation of AI tools capable of bypassing standard firewalls presents a critical vulnerability for ...

Go to External Site

 

The Anatomy of Industrial Volatility: Risk Cascades in LNG Infrastructure Restarts
2026-06-23 13:10:11

... critical vulnerability in the global industrial supply chain. This concentration of risk among foreign nationals is not accidental; it is a ...

Go to External Site

 

Pollution Levels In False Bay Threaten Marine Life And Public Health - 2OceansVibe
2026-06-23 13:10:11

This is the first research of this kind to be undertaken in Africa, and it highlights a critical vulnerability for one of South Africa's most ...

Go to External Site

 

OpenAI Daybreak Expands Patch Pipeline as Five Eyes Warns AI Attacks Are Months Away
2026-06-23 13:10:11

One specific result: OpenAI found CVE-2026-8390, a critical vulnerability in Firefox, during safety evaluations. Mozilla patched it two days ...

Go to External Site

 

Critical FFmpeg flaw discovered: just watching a video can fully compromise your system
2026-06-23 13:10:11

A critical vulnerability in the FFmpeg media processing framework allows attackers to execute arbitrary code via malicious video files.

Go to External Site

 

Scattered Spider Hackers Who Breached London Transport Network Plead Guilty
2026-06-23 13:10:11

A critical vulnerability has been disclosed in FFmpeg's MagicYUV decoder that allows attackers to weaponize… 2 hours ago. All Rights ReservedView ...

Go to External Site

 

Midair lifeline: Do B-52 bombers get refueled in the air? - WION
2026-06-23 13:10:10

Massive Fuel Transfer Rates. During a mid-air hookup, time is a critical vulnerability. The high-pressure boom system transfers fuel at an incredible ...

Go to External Site

 

Kaspersky warns of malware campaign targeting WhatsApp Desktop and Web - NewsBytes
2026-06-23 12:40:12

The files use names in different languages and even pretend to be Windows updates to dodge security checks. Kaspersky's advice? Don't open ...

Go to External Site

 

In 2011, Microsoft signed the Secure Boot certificates that still sit inside millions of Windows ...
2026-06-23 12:40:12

... Windows updates, but will lose access to new early-boot protections ... Microsoft says devices that no longer receive Windows updates will ...

Go to External Site

 

Abuse.ch MalwareBazaar (746 samples) | SOCRadar
2026-06-23 12:40:05

Threat intelligence report with 1492 extracted IOCs, MITRE ATT&CK mapping, and hunting context. Free by SOCRadar.

Go to External Site

 

Week 25: Fake voice messages spread malware and target login details
2026-06-23 12:40:04

23.06.2026 - Last week, the NCSC received a higher than usual number of reports about a scam involving fake voicemail messages sent via email.

Go to External Site

 

Uplevelling Black Hat Threat Hunters - Cisco Blogs
2026-06-23 12:40:03

Recently, Splunk Attack Analyzer (SAA) superseded Secure Malware Analytics (SMA) as the official malware threat analysis platform at Black Hat. With ...

Go to External Site

 

New terminal protection: How Apple wants to fend off ClickFix attacks - Heise
2026-06-23 12:40:03

macOS Terminal (Illustration): Danger from problematic commands. (Image: Dragon Claws / Shutterstock). at 1:05 pm CEST.

Go to External Site

 

Boss Scam Explained: How One WhatsApp Message Can Cost Millions |Fake CEO, Real Money
2026-06-23 12:40:03

India's cybercrime agency has warned organisations about a growing fraud known as the "Boss Scam" or CEO impersonation scam.

Go to External Site

 

GTA 6 early access is nothing but a scam - Malwarebytes
2026-06-23 12:40:03

A new wave of scam websites is offering something millions of people want: a way to play Grand Theft Auto VI before it comes out.

Go to External Site

 

OpenAI's Cybersecurity AI Surpasses Anthropic's Mythos 5
2026-06-23 12:30:14

It can perform penetration testing, vulnerability analysis, and malicious code analysis. OpenAI explained, “Our goal is to provide AI to as many ...

Go to External Site

 

Compliance Says You're Covered. Your Attack Surface Differs - BankInfoSecurity
2026-06-23 12:30:14

He has more than 20 years of experience scaling cybersecurity companies, with expertise in penetration testing, security program transformation, risk ...

Go to External Site

 

DJI Power 1000 Mini Earns TÜV SÜD Certification, Raising the Bar for Portable ... - Mynewsdesk
2026-06-23 12:30:14

Reliability is built into the product at every level: from LFP cells that have passed nail penetration testing, to flame-retardant materials that ...

Go to External Site

 

Alliance for Fort Gordon hosts Cyber Patriot Summer Camp this week - WJBF
2026-06-23 12:30:14

“One day, I hope to work for some type of government agency, doing penetration testing like one of our instructors actually does,” he said.

Go to External Site

 

Canada's spy service got a court order to remotely clean #malware-infected devices. CSIS used ...
2026-06-23 11:00:04

The Hacker News (@TheHackersNews). 68 likes. ⚡ Canada's spy service got a court order to remotely clean #malware-infected devices.

Go to External Site

 

Bill Pulte begins firing staff at US intelligence office: Report - Türkiye Today
2026-06-23 10:50:08

... (NCSC) were expected to face major cuts. "The deep state firings have begun," a source told CNN, which first reported the news of the terminations ...

Go to External Site

 

Five Eyes warns frontier AI could upend cyber security within months - MSN
2026-06-23 10:50:08

ncsc.gov.uk + 3. Recent AI restrictions highlight security concerns. The Trump administration's export-control directive on Anthropic's Fable 5 and ...

Go to External Site

 

Russia, China, Iran Behind 75% of UK Critical Infrastructure Attacks, NCSC Warns – SOFX
2026-06-23 10:50:07

Horne said the NCSC managed more than 200 incidents affecting CNI and its supporting systems in the year to May 2026, a volume mirroring the agency's ...

Go to External Site

 

a-9999.a-dc-msedge.net — Malware & Phishing Check | SOCRadar
2026-06-23 07:10:03

Is a-9999.a-dc-msedge.net safe? Check risk score, DNS history, and phishing & malware campaigns linked to this domain.

Go to External Site

 

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
2026-06-23 07:10:03

Attackers backdoored ShapedPlugin Pro updates, stealing credentials, 2FA codes, wp-config.php data, and WooCommerce order details.

Go to External Site

 

Avast One Premium - Review 2026 - PCMag UK
2026-06-23 07:10:03

Avast One Premium brings together enhanced antivirus and a collection of other security, privacy, and performance features for all your devices, ...

Go to External Site

 

UK warns businesses: AI coding spikes vulnerabilities | DigitalShield - Escudo Digital
2026-06-23 06:50:07

The UK's National Cyber Security Centre (NCSC) has published an analysis directed at organizations about the latent risks of vibe coding, a rising ...

Go to External Site

 

Five Eyes issues urgent cyber AI preparedness guidance | Let's Data Science
2026-06-23 06:50:06

... NCSC New Zealand). The agencies urge leaders to treat cyber risk as a ... NCSC said they are accessing frontier models and working with ...

Go to External Site

 

Five Eyes warns new AI models pose urgent cyber risk within months - Crypto Briefing
2026-06-23 06:50:06

... NCSC, the UK's NCSC, the US NSA, and CISA. The core message: frontier AI models are anticipated to exceed current industry expectations. The ...

Go to External Site

 

OpenAI Releases GPT‑5.5‑Cyber With Full Automation for Vulnerability Detection and Patching
2026-06-23 06:10:10

... critical vulnerability remediation gap in open-source software. More than 30 open-source projects have committed to participate, including: cURL ...

Go to External Site

 

The Anatomy of Stadium Security Failures: A Brutal Breakdown - Weddings
2026-06-23 06:10:10

In a sellout venue operating at a capacity of 52,497 fans, the presence of an incendiary device represents a critical vulnerability in the event's ...

Go to External Site

 

OpenAI Launches the 'Patch the Planet' Initiative: Vaccinate Open Source Code with AI
2026-06-23 06:10:10

The Log4j vulnerability incident a few years ago was a typical example—a widely used open-source tool was found to have a critical vulnerability, ...

Go to External Site

 

Rootkit Removal: A Step-by-Step Guide - Panda Security Mediacenter
2026-06-23 05:20:05

Rootkits are sneaky malware that hide deep in your system. Learn how to detect and remove them, and find out how Panda Security keeps you ...

Go to External Site

 

Regulatory and Executive Impersonation for WhatsApp Account Takeover using Malicious ... - PIB
2026-06-23 05:20:05

The Indian Cyber Crime Coordination Centre (I4C) has observed an emerging trend in cybercrime referred to as the "Boss Scam" or CEO impersonation ...

Go to External Site

 

Beyond the Login Field: The Evolved Phishing Tradecraft Your Users Aren't Ready For
2026-06-23 05:20:04

Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users ...

Go to External Site

 

b6e41b35fd514049f7384bc05a5...
2026-06-23 05:20:04

b6e41b35fd514049f7384bc05a560210 — MD5 hash analysis: malware family, threat-actor attribution, MITRE ATT&CK mapping, and first/last-seen data.

Go to External Site

 

OceanLotus (APT32) Explained: Tactics, Malware, and TTPs - SOC Prime
2026-06-23 05:20:04

OceanLotus APT32 targets Southeast Asia with spearphishing, supply chain attacks, custom malware, and DLL sideloading.

Go to External Site

 

38.47.123.84.nip.io — Malware & Phishing Check | SOCRadar
2026-06-23 05:20:04

Is 38.47.123.84.nip.io safe? Check risk score, DNS history, and phishing & malware campaigns linked to this domain. Free threat intel — no signup.

Go to External Site

 

Gain resilience and confidence: Cybersecurity awareness training is now the norm - ESET
2026-06-23 03:10:11

... critical vulnerability. AI-driven tools enable highly convincing scams, including deepfakes and personalized spear phishing messages, increasing ...

Go to External Site

 

mathfocus.gr — Malware & Phishing Check | SOCRadar
2026-06-23 00:20:05

Is mathfocus.gr safe? Check risk score, DNS history, and phishing & malware campaigns linked to this domain. Free threat intel — no signup.

Go to External Site

 

Thousands of D-Link and QNAP NAS routers compromised by fast-moving AryStinger ... - TechRadar
2026-06-23 00:20:03

QiAnXin XLab uncovered “AryStinger,” malware exploiting old D-Link/Linksys router flaws (CVE‑2013‑3307, CVE‑2016‑5681) to build a ...

Go to External Site