Pangram's Probable Cause
Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way
AI agents can access data, trigger workflows, deploy code, and interact with critical business systems, often with little oversight. Token Security breaks down why AI agents are becoming a new identity and governance challenge.
Police raid malware network tied to Russia's Evil Corp hacker group
Campagne di phishing a tema criptovalute abusano del nome dell’Agenzia delle Entrate
CVE-2026-48907 and LiteSpeed cPanel Plugin Flaws Come Under Active Attack
Attackers are exploiting CVE-2026-48907 in Joomla JCE and a LiteSpeed cPanel plugin flaw, enabling PHP code execution and privilege escalation.
Webinar: How attackers bypass MFA and how defenders can respond
Modern phishing attacks, including Device Code phishing, can undermine MFA protections and grant attackers access to corporate accounts without stealing passwords. This webinar explores how behavioral AI can help security teams detect compromised accounts faster and automate response workflows.
Claude Fable 5 sospeso per un jailbreak non universale: perché conta anche per le aziende europee
Il governo statunitense, sulla base di una reazione sproporzionata rispetto alla gravità tecnica del problema, ha ritenuto necessaria la sospensione totale e immediata dell'accesso a Claude Fable 5. Ecco cosa significa e perché si applica, per definizione, anche a utenti e aziende europee
Microsoft: June 2026 Windows updates break Recycle Bin prompts
Microsoft has confirmed a confusing Windows bug that causes different filenames to appear in the confirmation dialog when deleting a file from the Recycle Bin.
UK's information commissioner resigns over ‘inappropriate humour’
CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
CISA has urged U.S. federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks.
The Hacker News Recognizes ANY.RUN as the Best Security Investigation Platform 2026
Explore ANY.RUN's innovative approaches that made The Hacker News recognize the company at the Cybersecurity Stars Awards 2026.
NIS 2, la scadenza del 30 giugno e lo stato reale della compliance nelle aziende italiane
NIS 2 compliance: entro il 30 giugno le aziende devono classificare attività e servizi critici secondo il modello ACN. Scopri obblighi, difficoltà e rischi
Norton 360 Deluxe, l’antivirus fino a 5 dispositivi in sconto del 68%
Norton 360 Deluxe è in offerta con uno sconto del 68%: ecco come avere il famoso antivirus e come proteggere i propri dispositivi.
NY man charged after harassing college student with AI-generated nudes
A New York man faces cyberstalking charges after allegedly sharing AI-generated nude images and fabricated racist messages using fake social media profiles to harass a Georgia college student.
Nintendo Confirms Employee Data Exposed in TinyPulse Cyberattack
Nintendo confirms employee survey data exposure in the TinyPulse cyberattack as Shadowbyt3$ claims broader theft and demands $2M ransom.
Operation Endgame Hits SocGholish Malware Network, 14,971 Websites Cleaned
Operation Endgame Hits SocGholish Malware Network as international law enforcement remediates nearly 15,000 infected websites.
New iPhone BootROM Flaw Enables Hardware-Level Compromise
iPhone BootROM vulnerability affects A12, A13 and Apple Watch S4/S5 devices, enabling SecureROM code compromise via USB flaw in usbliter8 exploit.
Nintendo Confirms Employee Data Exposed in TinyPulse Cyberattack
Nintendo confirms employee survey data exposure in the TinyPulse cyberattack as Shadowbyt3$ claims broader theft and demands $2M ransom.
Governance by design: il prezzo delle scorciatoie
Ridurre le analisi, comprimere le verifiche e rinviare le valutazioni può apparire come la scelta più conveniente, per accelerare i processi decisionali. Ma l'esperienza sul campo svela l'importanza della Governance by design. Ecco perché le scorciatoie si trasformano in costi dilatati, asimmetrici e imprevedibili
CISA warns Fortinet users to secure devices after FortiBleed leak
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged Fortinet customers to secure their devices after nearly 74,000 firewall and VPN credentials were exposed in a data leak dubbed "FortiBleed."
FBI Warns of a Hidden Web Tactic Fueling Phishing and Ransomware
FBI Warns of malicious traffic distribution systems being used to redirect users to phishing sites, malware downloads, and online financial scams.
Ralph Lauren - 139,903 breached accounts
In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresses along with names, phone numbers, genders and age groups.
Gentlemen ransomware uses multiple EDR killers to disable defenses
The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks.
Nova Claims Access to NSW Systems: Between 400 GB Exfiltrated and Data Disputed by Authorities
Operation Endgame 4.0 - 153,527 breached accounts
On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation, a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the operation remediated almost 15,000 compromised websites and disrupted more than 100 servers and domains used to distribute malware. Authorities also provided HIBP with 154k impacted email addresses and more than half a million previously unseen passwords.
Bulgaria allowed surveillance tech firm to sell products to repressive regimes, report says
FlipCTL — our GUI framework for embedded Linux systems
Do you know why Flipper Zero is so popular? Not because of the little cute dolphin, but because you can use it right out of the box. If we made Flipper Zero in a Proxmark3-like form factor without a screen (no offense, Iceman), it would only be used by a small group of hardcore professionals. We all love simple, clear things: press a button and get results.
Before Flipper Zero, no one really cared about intuitive interfaces of niche devices for geeks. Everyone was building separate hardware and
Nintendo confirms data stolen in WebMD subsidiary cyberattack
Nintendo of America has confirmed to BleepingComputer that threat actors stole survey data from the third-party TinyPulse service used internally, but its systems were not compromised.
Close Encounters of the Human Kind
In the latest Threat Source, Hazel channels her inner Spielberg to explore why humans are delightfully irrational, reminding us that while security best practices are simple in theory, they’re a lot harder to pull off when you’re busy dealing with real life.
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded…