(Credit: Microsoft) StealC infrastructure takedown assisted by AI analysis, C2 infiltrationLaura FrenchJune 25, 2026Microsoft, Proofpoint, IBM, Europol and other partners took aim the StealC and Amadey “assembly line.”
Closing the ‘risk window’: Why real-time remediation is the new security standardGreg PollockJune 24, 2026
Network SecurityFortiBleed campaign steals 110M credentials from FortiGate targetsLaura FrenchJune 24, 2026A tool called FortigateSniffer abuses a diagnostic utility to continuously monitor network traffic.
Vulnerability ManagementFFmpeg vulnerability ‘PixelSmash’ could enable RCE via video fileLaura FrenchJune 23, 2026An attacker can use a crafted file to trigger a heap buffer overflow and overwrite a function pointer.
PhishingMalware campaign uses VirusTotal manipulation, legitimate news sites to gain reputationLaura FrenchJune 18, 2026The clipboard hijacker campaign also uses “ghost networks” on social media to boost engagement.
IdentityIdentity is the foundation of trust. That makes it everyone’s problem.Heather FlanaganJune 18, 2026Identiverse 2026 highlighted identity’s expanding role in AI, trust and governance.
Network SecurityF5 releases out-of-band patches for two critical NGINX bugsSteve ZurierJune 18, 2026F5 issued urgent patches for two critical NGINX flaws that could enable DoS or code execution.
Vulnerability ManagementMax severity Joomla Content Editor extension flaw targeted in automated attacksLaura FrenchJune 17, 2026The flaw was added to CISA’s Known Exploited Vulnerabilities catalog with a three-day deadline.
RansomwareAttackers drop DragonForce ransomware leveraging MS Teams relay systemsSteve ZurierJune 17, 2026DragonForce ransomware abused Microsoft Teams relay infrastructure to hide C2 traffic.
Critical Infrastructure SecurityAUR suspends new registrations as 1,500-plus malicious packages flood repositoryLaura FrenchJune 17, 2026Malicious build scripts deploy a Rust-based infostealer and eBPF rootkit.