#cyberNEWS
DentaQuest data breach exposed info of 2.6 million accounts.
A data breach at the dental benefits administrator DentaQuest has reportedly exposed the sensitive data of 2.6 million accounts.
https://t.co/6PdMmGbq2C
#cyberNEWS
New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute.
A new denial-of-service (DoS) attack dubbed HTTP/2 Bomb can be launched from a single machine to take down web servers within seconds.
https://t.co/etHHoWIppU
#cyberNEWS
Microsoft Exchange Online outage causes email delays, failures.
Microsoft is working to address a widespread service issue affecting the mail flow pipeline for Exchange Online customers across North America, Asia-Pacific (APAC), and Europe.
https://t.co/619IB4RABk
#cyberNEWS
WordPress malware campaign hides payloads in Steam profiles.
Nearly 2,000 WordPress websites were infected with malware that relies on Steam Community profile comments to hide command-and-control (C2) data.
https://t.co/YynPEMeXgd
#cyberNEWS
Threat actors are abusing ChatGPT's content-sharing feature to display fake OpenAI outage pages that direct users to download malware disguised as the ChatGPT desktop application.
https://t.co/f95ejbaoEt
#cyberNEWS
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ.
https://t.co/bXC1G4c6jn
#cyberNEWS
The Glassworm botnet targeting developers in software supply-chain attacks has been disrupted after researchers took down its resilient command-and-control infrastructure relying on Solana blockchain transactions and the BitTorrent DHT network.
https://t.co/Nw0bC1gJYi
#cyberNEWS
How Varonis Atlas integrates Claude Compliance API for AI governance.
Varonis announced an integration with the Claude Compliance API, bringing Claude Enterprise and Claude Platform activity into Varonis' Atlas AI Security Platform.
https://t.co/rnND8QsX7E
#cyberNEWS
Anthropic appears to be preparing for the public rollout of "Mythos," which was announced in April as a restricted model that poses major security risks to private and public software.
https://t.co/i4PtbTuK1n
#cyberNEWS
A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows.
https://t.co/duoH0exqBi
#cyberNEWS
Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix, Disney+, and Spotify.
https://t.co/HiyqkSt1PV
#cyberNEWS
Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns.
https://t.co/RNTYHXdoHE
#cyberNEWS
Google has accidentally leaked details about an unfixed issue in Chromium that keeps JavaScript running in the background even when the browser is closed, allowing remote code execution on the device.
https://t.co/LAU89g4wz1
#cyberNEWS
Grafana breach caused by missed token rotation after TanStack attack.
The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the TanStack npm supply-chain attack last week.
https://t.co/8DtLWc9lD9
#cyberNEWS
Microsoft plans to raise the quality bar of Windows 11 drivers, as drivers "sit at the heart of every Windows experience" and connect the OS to the "silicon, components, and peripherals."
https://t.co/xMLoAyjNmu
#cyberNEWS
Leaked Shai-Hulud malware fuels new npm infostealer campaign.
The Shai-Hulud malware leaked last week is now used in new attacks on the Node Package Manager (npm) index, as infected packages emerged over the weekend.
https://t.co/qru0h2WxyM
#cyberNEWS
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing.
The Tycoon2FA phishing kit now supports device-code phishing attacks and abuses Trustifi click-tracking URLs to hijack Microsoft 365 accounts.
https://t.co/n7A30cqReJ
#cyberNEWS
The Russian hacker group Secret Blizzard has developed its long-running Kazuar backdoor into a modular peer-to-peer (P2P) botnet designed for long-term persistence, stealth, and data collection.
https://t.co/Um8pIR85WF
During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in cash awards after exploiting 15 unique zero-day vulnerabilities in multiple products, including Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux for Workstations.
https://t.co/iiHyyfit4F
#cyberNEWS
An 18-year-old flaw in the NGINX open-source web server, discovered using an autonomous scanning system, can be exploited for denial of service and, under certain conditions, remote code execution.
https://t.co/5NRSAEtCmr