Attackers can move in 29 minutes. High and critical application flaws take 55 days on average to fix.
The real problem is not how many vulnerabilities AI finds. It is how long those vulnerabilities stay exposed.
Read why mobilization now matters most: https://t.co/FjTJqAPzjr
📧Vous recevez des e-mails sur les « pixels de suivi » ? C'est normal. Intégrés dans certains courriels, ils peuvent indiquer à l'expéditeur si un message a été ouvert. Leur utilisation est encadrée et vous devez être mieux informés et garder le contrôle 👉https://t.co/grsBuXgyyx
🚗🛴🚲Véhicules connectés : la CNIL publie sa recommandation sur l’utilisation des données de localisation 👉 https://t.co/M0bevwokGb
Particuliers : dans quelles conditions vos données de localisation peuvent être utilisées et quels sont vos droits ? 👉 https://t.co/3xDAGWXgwc
🆕The EDPB has published an update of the the One-Stop-Shop (OSS) case digest on right to object and right to erasure, developed in the framework of the Support Pool of Experts (SPE) programme.
Find out more ➡️ https://t.co/BTuqZ1yrco
> Your TV is not just a TV.
> Your browser is not just a browser.
> Your old creds are not dead.
This #ThreatsDay is packed smart TV proxyware, a curl bug from 2001, Hoppscotch takeover, macOS ClickFix, fake Teams IT, M365 phishing, AI crime forums, and more.
Read the full bulletin: https://t.co/KxWjmtZqNN
Today Greet Gysen will be at the DPO Day 2026 to talk about the role of DPOs and DPAs in a constantly evolving regulatory landscape.
#DPODay2026#GDPR#DataProtection
📢 Les inscriptions pour le webinaire « Fournisseurs et prestataires de l’écosystème « pixels » : comment implémenter la recommandation CNIL ? » sont ouvertes ! 👉 https://t.co/LA5plpL1Zp
📅 Le jeudi 4 juin 2026 à 11h
🚨 Iranian hackers deployed a new AI-assisted backdoor called MiniFast.
https://t.co/9G4jgruPAK
IRGC-linked group Nimbus Manticore targeted aviation, software, telecom, and energy sectors across the U.S., Europe, and the Middle East.
The campaigns used:
• Phishing lures
• SEO poisoning
• Trojanized Zoom and SQL Developer installers
• Fake meeting invites
• AppDomain hijacking
Activity was tracked between February and April 2026.
Agentic AI is already operating inside companies — often unseen.
Nearly 70% of firms now use AI agents that can plan and act independently, creating “identity dark matter”: hidden AI accounts with broad access that evade normal controls.
Risks + defenses: https://t.co/oi6Lt6Fc8H
🚨 Threat actors used AI to create the first known zero-day 2FA bypass on a popular open-source admin tool.
Google spotted it in a planned mass exploitation campaign and helped fix it before widespread use.
Full report: https://t.co/lIVuCTZ4WJ
⚠️ UPDATE: #cPanel flaw now tracked as CVE-2026-41940 (CVSS 9.8)—an auth bypass granting unauthenticated admin access.
Reportedly exploited as a 0-day, with activity observed for at least 30 days before disclosure. Root cause: CRLF injection enabling session forgery.
🔗 Exploit mechanics and real-world impact → https://t.co/8mHLoqywHY
🔥 A U.S. federal agency was hacked via Cisco firewall.
Attackers used ASA flaws to install FIRESTARTER, a backdoor that stays even after patches and normal reboots.
Fix requires full reimage or hard power cycle, not just updating software.
🔗 Read → https://t.co/sbjyK90Fuy
A 24-year-old linked to #ScatteredSpider pleaded guilty after stealing $8 million in digital assets from multiple companies.
The campaign used SMS phishing to capture employee credentials, then SIM swapping to take over accounts across telecom, tech, and crypto firms.
🔗 Read → https://t.co/uGFlpHwtss
🚨 Researchers found 22 vulnerabilities in serial-to-IP converters, with ~20,000 devices exposed online.
Exploitation can enable device takeover and tampering with data between legacy systems and IP networks, impacting industrial operations.
🔗 Read → https://t.co/dv4h2sNk6W
🔥 NIST will now prioritize CVE analysis.
263% rise in vulnerabilities forced it to enrich only high-risk cases (KEV, federal, critical software). Others stay listed but without full analysis, marked “Not Scheduled.”
🔗 Read about it here → https://t.co/1Y7KbAgeFt
MFA protects login. Not the session.
As Alicia Townsend explains, session cookies become the real credential after authentication. If stolen, attackers get access with no password, no MFA, no alerts.
🔗 How session hijacking bypasses MFA → https://t.co/u84GFQLmPY
The EDPB adopted a template for Data Protection Impact Assessments (DPIA) to help organisations structure, harmonise and evidence their DPIA reporting processes. Read more: https://t.co/dG2ELqR9zf
The template is open for public consultation until 9 June: https://t.co/Zr94147W4B
⚡ U.K. moves to jail tech execs over failure to remove non-consensual intimate images.
New bill amendments also criminalize incest porn and adults roleplaying as children, expanding platform liability.
🔗 What the law changes for platforms and execs → https://t.co/Jl6vMDdBxG
Android trojan Mirax is spreading via Meta ads, hitting 220K+ accounts with fake streaming apps.
It gives attackers full device control and turns phones into proxy nodes to mask fraud using real IPs.
🔗 How RAT + proxy is reshaping mobile attacks → https://t.co/aeHjCf4xHe