Weedhack attacks Minecraft users, CountLoader reaches 86K, miners spread via pirated content

Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube in an attempt to spread malware that can take control of victims’ systems. A Minecraft-focused malware-as-a-service (MaaS) campaign, codenamed Weedhack by McAfee Labs, says the operation has been active since January 2026 and infects users by impersonating Minecraft clients and mods. In total, […]
Google’s June 2026 Android update fixes 124 flaws, 1 of which is actively being exploited

Ravi LakshmananJune 2, 2026Vulnerabilities / Mobile Security Google on Monday released patches for 124 security vulnerabilities affecting its Android operating system through June 2026. This includes one high-severity flaw in a framework component that is being actively exploited. This security flaw is tracked as CVE-2025-48595 (CVSS score: 8.4) and is described as a case of […]
Gamaredon exploits WinRAR to attack GammaWorm and GammaSteel against Ukraine

Ravi LakshmananJune 2, 2026Threat Intelligence/Malware A Russian hacker group known as Gamaredon is believed to have continuously exploited vulnerabilities in WinRAR and distributed multiple families of malware aimed at data theft and propagation. According to Sekoia, this activity involves weaponizing CVE-2025-8088, a path traversal flaw in WinRAR, to launch an HTML application payload called GammaPhish, […]
Oracle WebLogic CVE-2024-21182 added to KEV catalog after active exploitation

Ravi LakshmananJune 2, 2026Vulnerability/Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw affecting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. Vulnerability CVE-2024-21182 (CVSS score: 7.5) allows an unauthenticated attacker with network access to take control of a susceptible […]
AI-powered exploits are disrupting vulnerability management. Here’s what to do:

AI exploitation schedules are rapidly shrinking and will continue to shrink. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever before in the history of enterprise security. As a result, the time between a vulnerability being disclosed and indiscriminate exploitation observed on the Internet is now hours instead of days. The industry’s main answer […]
How leading organizations are turning EDR into operational resilience

Most organizations now realize that endpoint protection alone is no longer enough. As a result, the adoption of endpoint detection and response (EDR) has accelerated rapidly in recent years. Organizations understand that modern attacks move faster, evade traditional defense controls, and require continuous visibility of suspicious activity across the environment. However, possessing EDR capabilities does […]
Pakistan-linked sidecopy targets Afghan Treasury with Xeno RAT

Ravi LakshmananJune 2, 2026Cyber espionage/threat intelligence Cybersecurity researchers have revealed details of a spear-phishing campaign believed to be conducted by the Pakistan-aligned SideCopy group that targeted the Afghan Ministry of Finance using an open-source remote access Trojan called Xeno RAT. “The campaign begins with a spear phishing delivery, a ZIP archive containing a malicious LNK […]
Dashlane exposes brute force attack, encrypted vault downloaded by less than 20 users

Ravi LakshmananJune 2, 2026Identity security/data protection Password manager Dashlane has revealed that fewer than 20 users of its personal subscription plans had their encrypted vaults downloaded following a brute force attack by an unknown party. On May 31, 2026, the company announced that an “external” attacker launched a brute force attack against certain Dashlane user […]
Miasma supply chain attack compromises Red Hat npm packages with credential-stealing worm

A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, compromised the @redhat-cloud-services package to steal credentials and sensitive information from developer machines and distribute a self-propagating worm. “This is effectively a Mini Shai-Hulud campaign, using the same core tactics of execution at install, credential collection, CI/CD targeting, encrypted exfiltration, and potential downstream propagation,” Socket […]
New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

Ravie LakshmananJun 01, 2026Cybersecurity / Hacking Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some “patched-ish” thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering […]