IronWorm malware, similar to Shai-Hulud, hits 57 projects across 9 organizationsLaura FrenchJune 5, 2026The malware targets developer credentials and cryptocurrency and self-propagates on npm.
The Trump AI EO strikes a compromise to balance innovation with accountabilityJames Turgal June 4, 2026
China-linked actors using job sites to target government workers, Five Eyes warnsSC StaffJune 4, 2026
Network SecurityAnother Cisco Catalyst SD-WAN Manager bug actively exploitedSteve ZurierJune 5, 2026Cisco warns of an exploited SD-WAN flaw that can enable remote code execution and network compromise.
MalwareMalicious podcast, PDF apps spread FlutterShell macOS backdoor malwareLaura FrenchJune 5, 2026FlutterShell is linked to previous malvertising campaigns including TamperedChef.
Vulnerability Management9.8 Mirasvit bug actively exploited on Magento serversSteve ZurierJune 4, 2026CISA warns of an actively exploited Magento extension flaw that enables remote code execution.
Email securityStock exchange executive’s Outlook mailbox stolen over course of 5 monthsLaura FrenchJune 4, 2026The approximately 150-day espionage campaign incrementally exfiltrated emails to cloud services.
AI/MLTrump executive order on AI calls for voluntary 30-day review periodSteve ZurierJune 3, 2026Trump AI order proposes a 30-day voluntary review of frontier models before public release.
AI/MLAnthropic grants Mythos access to 150 more organizations, plans wider releaseLaura FrenchJune 3, 2026Project Glasswing partners discovered more than 10,000 vulnerabilities in its first month.
Vulnerability ManagementMost organizations that miss 24-hour patch window report breachesSteve ZurierJune 2, 2026Study points out that AI has shattered the model of patching on a two- to four-week schedule.
Vulnerability ManagementMicrosoft denies legal action against researchers after slamming BlueHammer publisherLaura FrenchJune 2, 2026The company was criticized after a blog posted that suggested law enforcement involvement.