Threat Intelligence

2026-06-22 00:00

FortiBleed campaign used custom FortiGate sniffer to steal credentials

FortiBleed campaign used custom FortiGate sniffer to steal credentials

Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal...

Read Article

2026-06-22 00:00

Microsoft says Windows 11 26H2 is coming soon, details upgrade process

Microsoft says Windows 11 26H2 is coming soon, details upgrade process

Microsoft has confirmed that Windows 11 version 26H2 will be the next feature update and that devices running Windows 11 24H2 and 25H2 will be able to upgrade using a small enablement package. The...

Read Article

2026-06-22 00:00

Microsoft fixes AutoGen Studio flaw that enabled code execution

Microsoft fixes AutoGen Studio flaw that enabled code execution

A vulnerability chain dubbed AutoJack in Microsoft’s AutoGen Studio interface for prototyping AI agents could let attackers manipulate an agent into executing arbitrary commands on its host system...

Read Article

2026-06-22 00:00

A Glimpse into the “Search Your Target” Market for Stolen Credentials

A Glimpse into the “Search Your Target” Market for Stolen Credentials

Threat actors are increasingly turning massive infostealer-derived credential collections into searchable underground services, allowing buyers to request credentials for a specific company,...

Read Article

2026-06-22 00:00

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

Multiple WordPress plugins fromShapedPluginwere compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code....

Read Article

2026-06-22 00:00

Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

Cybersecurity researchers have disclosed details of four vulnerabilities inDify, an open-source agentic workflow platform with more than146,000 GitHub stars, that could allow attackers to stealthily...

Read Article