JFrog researchers discovered a malicious npm package masquerading as the legitimate postcss-selector-parser library, designed to deliver a multi-stage Windows remote access trojan to developers who install it. This supply chain attack demonstrates the ongoing threat of typosquatting and package impersonation in open-source ecosystems, where attackers exploit developer trust to distribute sophisticated malware.
OpenAI has expanded its Daybreak initiative with a full GPT-5.5-Cyber release designed to assist security defenders in identifying and patching software vulnerabilities. The enhanced tool aims to support defensive security teams in their remediation efforts against software flaws.
The Trump administration has issued an executive order mandating that all US federal agencies transition to post-quantum cryptography by 2031. This deadline establishes a concrete timeline for agencies to migrate away from current encryption standards vulnerable to future quantum computing threats.
Cybercriminals are exploiting the launch of GTA 6 pre-orders by creating fraudulent websites that promise early access to the game in exchange for cryptocurrency payments. These scams capitalize on high demand and consumer excitement around the title's release to deceive victims into financial loss.
Bitdefender Labs uncovered more than 55 fake-shop campaigns operating across 12 European countries between March and May 2026, impersonating major global brands including Samsung, Nike, Adidas, ZARA, H&M, Amazon, Lidl, and SHEIN. These counterfeit storefronts lured consumers with fraudulent deals on high-value products and World Cup-themed scams, exploiting brand recognition to steal payment information and distribute counterfeit goods. The investigation highlights a coordinated e-commerce fraud operation targeting European consumers at scale.
Two young British men have pleaded guilty to hacking Transport for London as part of a Scattered Spider operation, marking a significant enforcement action against the notorious threat group. The convictions demonstrate law enforcement's growing ability to identify and prosecute individual members of the distributed cybercriminal collective.
Trail of Bits and OpenAI launched "Patch the Planet," a landmark initiative pairing AI frontier models like GPT-5.5-Cyber with expert security engineers to systematically harden critical open-source projects, delivering 64 pull requests and 51 issues across 19 key projects in just the first week. Unlike typical AI-generated bug floods, the program goes beyond finding vulnerabilities—providing triage, patches, and long-term infrastructure improvements, with 37 patches already merged into projects like Python, RustCrypto, cURL, and PyPI. The initiative signals a fundamental shift in security work: as AI makes bug discovery trivial, the real value now lies in confirmation
ESET has identified GentleKiller, a framework distributed by the Gentlemen ransomware gang to its affiliates that specifically targets and disables endpoint detection and response (EDR) security software on victim systems. This tool represents a significant capability for ransomware operators, enabling them to neutralize defensive measures before deploying their encryption payloads.
A previously undisclosed BootROM vulnerability has been identified in Apple's A12 and A13 chips that cannot be patched due to its placement in the device's immutable firmware. The flaw is exploitable through USB, potentially allowing attackers to bypass security protections on affected devices. This unpatchable nature means the vulnerability will persist for the lifetime of devices using these chip generations.
Microsoft security researchers have attributed a supply chain attack against Mastra to North Korean threat actor Sapphire Sleet, marking another instance of state-sponsored targeting of AI-related infrastructure. The attack demonstrates continued efforts by adversaries to compromise software supply chains as a vector for broader compromise.
A breach of business intelligence platform Klue has compromised OAuth tokens that enabled threat actors to target at least four cybersecurity firms through Salesforce integration. The incident demonstrates how supply chain vulnerabilities in third-party platforms can expose security-focused organizations to unauthorized access and credential theft.
The NCSC has released guidance for Fortinet customers impacted by the FortiBleed threat campaign
Can Valorant brick YOUR PC? Is Vanguard safe?
PC Security Channel·45K views · 2 months ago
Can Valorant brick your PC? Vanguard sys Driver which is the anti-cheat software for Riot Games has come under scrutiny after bricking a lot of cheating devices, how much control does Valorant have?
HackTheBox - Nanocorp
IppSec·7.2K views · 2 months ago
00:00 - Introduction
01:00 - Start of nmap
05:00 - Looking at the contact form, it behaves oddly so disregarding it
07:00 - Playing with the PHP File Upload to see if we can upload PHP Files
10:00 - Using wget to download an image and see when it was uploaded to the webserver
12:30 - Looking into CVE-2025-24071, which we can create a .library-ms file that leaks NTLMv2 Hashes
17:30 - Cracking the web_svc NTLMv2 hash
19:50 - Using impacket's getTGT, then running RustHound and discovering we can take over another account via changepassword
25:00 - Using BloodyAD to add ourself to a group and then change the password
31:40 - Using WinRMexec to get a shell because Evil-WINRM doesn't support KRB+SSL Auth
36:30 - WinRM Shell returned, discovering we can write php scripts to the web directory but unfortunately this doesn't get us seimpersonate privileges
40:15 - Discovering CheckMK is running on the box, finding a privesc CVE
45:50 - Looking into the registry to discover which cached MSI is CheckMK
52:00 - Using RunasCS to switch to the web_svc user because we need an interactive login
01:04:30 - Changing the PID in the POC Script to be much lower which gets us the shell
AWS has introduced Continuum, an AI-powered platform designed to streamline the vulnerability management lifecycle by leveraging frontier AI models. The platform assists security teams across the key stages of vulnerability handling—discovery, prioritization, validation, and remediation—to improve efficiency in addressing code vulnerabilities.
Operation Endgame successfully disrupted a malware distribution network by removing SocGholish malware from approximately 15,000 compromised websites. The operation targeted infrastructure linked to Evil Corp, a notorious ransomware-affiliated group, significantly degrading their ability to deliver malware at scale.
Half of cybersecurity leaders report lacking confidence in their ability to detect threats across non-email communication platforms such as Slack and Teams, even as attackers increasingly target these channels. The finding highlights a significant gap between where modern threats are emerging and organizations' current detection and monitoring capabilities outside traditional email infrastructure. This confidence deficit suggests many security teams may be unprepared to identify compromises occurring through widely-adopted collaboration tools.
Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026
NetworkChuck·19K views · 2 months ago
Join us for our 90 minute Sumer of CCNA session, today at 5PM ET!