Suspected North Korean actors use fake ‘coding assignments’ to steal cryptoLaura FrenchJune 9, 2026Targets are encouraged to clone Git repositories to their VS Code or Cursor code editors.
The Trump AI EO strikes a compromise to balance innovation with accountabilityJames Turgal June 4, 2026
FTC orders Illuminate Education to improve data security after student data breachSC StaffJune 8, 2026
IdentitySilent Ransom Group moves to in-person method if vishing attempt failsSteve ZurierJune 8, 2026Mandiant warns Silent Ransom Group uses vishing and even in-person visits to steal data.
Supply chainIronWorm malware, similar to Shai-Hulud, hits 57 projects across 9 organizationsLaura FrenchJune 5, 2026The malware targets developer credentials and cryptocurrency and self-propagates on npm.
Network SecurityAnother Cisco Catalyst SD-WAN Manager bug actively exploitedSteve ZurierJune 5, 2026Cisco warns of an exploited SD-WAN flaw that can enable remote code execution and network compromise.
MalwareMalicious podcast, PDF apps spread FlutterShell macOS backdoor malwareLaura FrenchJune 5, 2026FlutterShell is linked to previous malvertising campaigns including TamperedChef.
Vulnerability Management9.8 Mirasvit bug actively exploited on Magento serversSteve ZurierJune 4, 2026CISA warns of an actively exploited Magento extension flaw that enables remote code execution.
Email securityStock exchange executive’s Outlook mailbox stolen over course of 5 monthsLaura FrenchJune 4, 2026The approximately 150-day espionage campaign incrementally exfiltrated emails to cloud services.
AI/MLTrump executive order on AI calls for voluntary 30-day review periodSteve ZurierJune 3, 2026Trump AI order proposes a 30-day voluntary review of frontier models before public release.
AI/MLAnthropic grants Mythos access to 150 more organizations, plans wider releaseLaura FrenchJune 3, 2026Project Glasswing partners discovered more than 10,000 vulnerabilities in its first month.