Security Feed

240 Followers
1 Following
10.2K Posts
Monitors security RSS feeds
Maintained byPhil Massyn

๐Ÿ”น BleepingComputer

Microsoft's Coreutils project brings Linux commands to Windows

Microsoft announced today at its Build 2026 developer conference the release of Coreutils for Windows, bringing many commonly used Linux command-line utilities to Windows as native applications. [...]

๐Ÿ”— https://www.bleepingcomputer.com/news/microsoft/microsofts-coreutils-project-brings-linux-commands-to-windows/

Microsoft's Coreutils project brings Linux commands to Windows

Microsoft announced today at its Build 2026 developer conference the release of Coreutils for Windows, bringing many commonly used Linux command-line utilities to Windows as native applications.

BleepingComputer

๐Ÿ”น Security News | TechCrunch

Cyera eyes $12B valuation at 80x ARR multiple despite operating losses

The cybersecurity company is nearing a $300 million round led by Evolution Equity Partners.

๐Ÿ”— https://techcrunch.com/2026/06/02/cyera-eyes-12b-valuation-at-80x-arr-multiple-despite-operating-losses/

Cyera eyes $12B valuation at 80x ARR multiple despite operating losses | TechCrunch

The cybersecurity company is nearing a $300 million round led by Evolution Equity Partners.

TechCrunch

๐Ÿ”น BleepingComputer

OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models

OpenAI says it's rolling out a new update that improves the existing GPT-5.5 Instant model, and this move comes ahead of the scheduled retirement of multiple legacy models, including o3. [...]

๐Ÿ”— https://www.bleepingcomputer.com/news/artificial-intelligence/openai-upgrades-gpt-55-as-it-plans-to-retire-legacy-chatgpt-models/

OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models

OpenAI says it's rolling out a new update that improves the existing GPT-5.5 Instant model, and this move comes ahead of the scheduled retirement of multiple legacy models, including o3.

BleepingComputer

๐Ÿ”’ Security News Digest - 2026-06-02

๐Ÿ“Š 19 updates from 9 sources:

๐Ÿ”น SecurityWeek: Two New Reports Offer Competing Explanations for Cybersecurityโ€™s Growing Crisis
https://www.securityweek.com/two-new-reports-offer-competing-explanations-for-cybersecuritys-growing-crisis/

๐Ÿ”น BleepingComputer: Microsoft Exchange Online outage causes email delays, failures
https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-causes-email-delays-failures/

๐Ÿ”น Unit 42: The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2)
https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/

๐Ÿ”น The Hacker News: Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
https://thehackernews.com/2026/06/oracle-weblogic-cve-2024-21182-added-to.html

๐Ÿ”น The Hacker News: Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html

๐Ÿฆ  Malwarebytes: These convincing copyright notices are designed to steal Google logins
https://www.malwarebytes.com/blog/threat-intel/2026/06/these-convincing-copyright-notices-are-designed-to-steal-google-logins

๐Ÿ”น The Record from Recorded Future News: White House unveils pared-back AI executive order
https://therecord.media/white-house-unveils-ai-executive-order

๐Ÿ”น The Hacker News: Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
https://thehackernews.com/2026/06/google-june-2026-android-update-patches.html

๐Ÿ”น darkreading: Securing AI Agents Before They Go Rogue Is Next to Impossible
https://www.darkreading.com/cyber-risk/securing-ai-agents-rogue

๐Ÿ”น Latest Bulletins: CVE-2026-10584 - HTTPS Fallback to HTTP in Graph Explorer
https://aws.amazon.com/security/security-bulletins/rss/2026-038-aws/

๐Ÿ”น darkreading: China Uses Dual-Method Cyberattack on Czech Orgs
https://www.darkreading.com/threat-intelligence/china-uses-dual-method-attack-czech-taiwan-orgs

๐Ÿ”น BleepingComputer: AI-built ransomware toolkit automates EDR evasion, AD discovery
https://www.bleepingcomputer.com/news/security/ai-built-ransomware-toolkit-automates-edr-evasion-ad-discovery/

๐Ÿ”น SecurityWeek: Trump Signs Executive Order That Invites Vetting of Top AI Models for National Security Risks
https://www.securityweek.com/trump-signs-executive-order-that-invites-vetting-of-top-ai-models-for-national-security-risks/

๐Ÿ”น darkreading: DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks
https://www.darkreading.com/cyberattacks-data-breaches/drivesurge-hijacks-thousands-sites-clickfix-fakeupdate-attacks

๐Ÿ”น iTnews - Security: Trump administration to ask US AI firms to voluntarily submit models for cyber security tests
https://www.itnews.com.au/news/trump-administration-to-ask-us-ai-firms-to-voluntarily-submit-models-for-cyber-security-tests-626371?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+Security+feed

๐Ÿ”น darkreading: FBI-Flagged Phishing Kit Kali365 Expands Its Reach
https://www.darkreading.com/cyber-risk/fbi-flagged-phishing-kit-kali365-expands-its-reach

๐Ÿ”น darkreading: Zoom CISO: AI as Security Enabler, Not Role-Replacer
https://www.darkreading.com/cybersecurity-operations/zoom-ciso-ai-security-enabler-role-replacer

๐Ÿ”น BleepingComputer: Over 116,000 Mincraft systems infected in WeedHack malware campaign
https://www.bleepingcomputer.com/news/security/over-116-000-mincraft-systems-infected-in-weedhack-malware-campaign/

๐Ÿ”น BleepingComputer: Critical Kirki flaw exploited to hijack WordPress admin accounts
https://www.bleepingcomputer.com/news/security/critical-kirki-flaw-exploited-to-hijack-wordpress-admin-accounts/

#InfoSec #SecurityNews

Two New Reports Offer Competing Explanations for Cybersecurity's Growing Crisis

As AI accelerates cyberattacks, two reports debate the root cause of security failures: inadequate visibility into exploitable vulnerabilities or poor operational control of existing defenses.

SecurityWeek

๐Ÿ”’ Security News Digest - 2026-06-02

๐Ÿ“Š 24 updates from 9 sources:

๐Ÿฆ  Malwarebytes: Fake virus alerts are invading mobile games
https://www.malwarebytes.com/blog/mobile/2026/06/fake-virus-alerts-are-invading-mobile-games

๐Ÿ”น The Hacker News: Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT
https://thehackernews.com/2026/06/pakistan-linked-sidecopy-targets.html

๐Ÿ”น SecurityWeek: Supply Chain Attack Hits 32 Red Hat NPM Packages
https://www.securityweek.com/supply-chain-attack-hits-32-red-hat-npm-packages/

๐Ÿฆ  Malwarebytes: 23andMe exposed genetic information of millions, lawsuit says
https://www.malwarebytes.com/blog/data-breaches/2026/06/23andme-exposed-genetic-information-of-millions-lawsuit-says

๐Ÿ”น Unit 42: Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor
https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoor/

๐Ÿ”น The Hacker News: How Leading Organizations Are Turning EDR Into Operational Resilience
https://thehackernews.com/2026/06/how-leading-organizations-are-turning.html

๐Ÿ”น SecurityWeek: Meta AI Hands Over High-Profile Instagram Accounts to Hackers
https://www.securityweek.com/meta-ai-hands-over-high-profile-instagram-accounts-to-hackers/

๐Ÿ”น BleepingComputer: Google fixes one actively exploited Android zero-day, 124 flaws
https://www.bleepingcomputer.com/news/security/google-fixes-one-actively-exploited-android-zero-day-124-flaws/

๐Ÿ”น SecurityWeek: Oracle WebLogic Vulnerability Exploited in the Wild
https://www.securityweek.com/oracle-weblogic-vulnerability-exploited-in-the-wild/

๐Ÿ”น The Hacker News: AI-Driven Exploitation is Destroying Vulnerability Management. Hereโ€™s How to Handle It.
https://thehackernews.com/2026/06/ai-driven-exploitation-is-destroying.html

๐Ÿ”น darkreading: Beyond Assume-Breach: How AI-Native Security Will Reshape Enterprise Defense
https://www.darkreading.com/cyber-risk/assume-breach-ai-native-security-reshape-enterprise-defense

๐Ÿ”น SecurityWeek: Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches
https://www.securityweek.com/critical-vulnerability-in-hp-voip-phones-enables-enterprise-network-breaches/

๐Ÿ”น SecurityWeek: The Zero-Knowledge Threat Actor and the End of Responsible Disclosure
https://www.securityweek.com/the-zero-knowledge-threat-actor-and-the-end-of-responsible-disclosure/

๐Ÿ”น BleepingComputer: CISA flags two-year-old Oracle flaw as actively exploited in attacks
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-weblogic-flaw/

๐Ÿ”น The Record from Recorded Future News: Red Hat removes tainted packages after software pipeline compromise
https://therecord.media/red-hat-removes-tainted-packages-after-software-pipeline-compromise

๐Ÿ”น SecurityWeek: Anthropic Expanding Mythos Access to 150 New Organizations
https://www.securityweek.com/anthropic-expanding-mythos-access-to-150-new-organizations/

๐Ÿ”น BleepingComputer: Why the browser is now the front line for AI security
https://www.bleepingcomputer.com/news/security/why-the-browser-is-now-the-front-line-for-ai-security/

๐Ÿ”น SecurityWeek: Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities
https://www.securityweek.com/android-update-patches-exploited-zero-day-123-other-vulnerabilities/

๐Ÿ”น Security News | TechCrunch: Anthropic scales Claude Mythos to critical infrastructure in 15+ countries
https://techcrunch.com/2026/06/02/anthropic-scales-claude-mythos-to-critical-infrastructure-in-15-countries/

๐Ÿ”น SecurityWeek: Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk
https://www.securityweek.com/exclusive-how-one-line-of-code-put-billions-of-microsoft-android-app-downloads-at-risk/

๐Ÿ”น Latest Bulletins: CVE-2026-10591 - Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths
https://aws.amazon.com/security/security-bulletins/rss/2026-037-aws/

๐Ÿ”น Security News | TechCrunch: Password manager Dashlane says hackers stole some customersโ€™ password vaults
https://techcrunch.com/2026/06/02/password-manager-dashlane-says-hackers-stole-some-customers-password-vaults/

๐Ÿ”น BleepingComputer: Instagram users locked out after Meta AI abused to steal accounts
https://www.bleepingcomputer.com/news/security/instagram-users-locked-out-after-meta-ai-abused-to-steal-accounts/

๐Ÿ”น The Record from Recorded Future News: Russia claims foreign spy agencies hacked officials' phones
https://therecord.media/russia-claims-foreign-spy-agencies-hacked-gov-officials

#InfoSec #SecurityNews

Fake virus alerts are invading mobile games

"Your device is infected!" Fake account warnings and virus alerts are turning some in-game ads into malware traps.

Malwarebytes

๐Ÿ”น SecurityWeek

Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

Dashlaneโ€™s security systems automatically locked accounts to protect them against the hacking attempts. The post Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads appeared first on SecurityWeek.

๐Ÿ”— https://www.securityweek.com/dashlane-brute-force-attack-leads-to-limited-encrypted-vault-downloads/

Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

Dashlane has been targeted in a brute-force attack campaign that resulted in a limited number of encrypted vaults being downloaded.

SecurityWeek

๐Ÿ”น SecurityWeek

Oracleโ€™s First Monthly Patches Resolve 77 Vulnerabilities

Oracleโ€™s monthly Critical Security Patch Update (CSPU) rollouts are meant to deliver critical fixes faster. The post Oracle’s First Monthly Patches Resolve 77 Vulnerabilities appeared first on SecurityWeek.

๐Ÿ”— https://www.securityweek.com/oracles-first-monthly-patches-resolve-77-vulnerabilities/

Oracle's First Monthly Patches Resolve 77 Vulnerabilities

Oracle has released its first monthly Critical Security Patch Update (CSPU) to resolve 77 vulnerabilities across its products.

SecurityWeek

๐Ÿ”น The Hacker News

Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

Password manager Dashlane has disclosed that "fewer than" 20 users on the personal subscription plan had their encrypted vaults downloaded following a brute-force attack launched by an unknown party. On May 31, 2026, the company said an "external" threat actor launched a brute-force attack against certain Dashlane user accounts with the aim of breaking two-factor authentication (2FA)

๐Ÿ”— https://thehackernews.com/2026/06/dashlane-discloses-brute-force-attack.html

Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

Brute-force attacks bypassed 2FA on some Dashlane accounts on May 31, 2026, enabling fewer than 20 encrypted vault downloads.

The Hacker News

๐Ÿ”น iTnews - Security

'Miasma' worm infests Red Hat npm packages

Trusted publishing defence mechanism side-stepped with compromised token.

๐Ÿ”— https://www.itnews.com.au/news/miasma-worm-infests-red-hat-npm-packages-626327?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+Security+feed

'Miasma' worm infests Red Hat npm packages

Trusted publishing defence mechanism side-stepped with compromised token.

iTnews

๐Ÿ”’ Security News Digest - 2026-06-01

๐Ÿ“Š 12 updates from 7 sources:

๐Ÿ”น The Hacker News: Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
https://thehackernews.com/2026/06/miasma-supply-chain-attack-compromises.html

๐Ÿ”น SecurityWeek: Dutch Police Dismantle Massive 17-Million-Device Botnet
https://www.securityweek.com/dutch-police-dismantle-massive-17-million-device-botnet/

๐Ÿ”น BleepingComputer: Dashlane password manager users locked out by brute force attacks
https://www.bleepingcomputer.com/news/security/dashlane-password-manager-users-locked-out-by-brute-force-attacks/

๐Ÿ”น SecurityWeek: WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites
https://www.securityweek.com/wp-maps-pro-vulnerability-exploited-to-take-over-wordpress-sites/

๐Ÿ”น The Record from Recorded Future News: NSA selects new leads for key cybersecurity posts
https://therecord.media/nsa-selects-new-leads-for-cyber-posts

๐Ÿ”น Security News | TechCrunch: Hackers hijacked Instagram accounts by tricking Meta AI support chatbot into granting access
https://techcrunch.com/2026/06/01/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/

๐Ÿ”น Red Canary: Red Canary CFP tracker: May 2026
https://redcanary.com/blog/news-events/red-canary-cfp-tracker-june-2026/

๐Ÿ”น The Record from Recorded Future News: Inspector general finds NIST mistakes have made vulnerability database ineffective
https://therecord.media/nist-mistakes-vulnerability-database-inspector-general

๐Ÿ”น iTnews - Security: Microsoft backs down on legal threats against 0day disclosing researchers
https://www.itnews.com.au/news/microsoft-backs-down-on-legal-threats-against-0day-disclosing-researchers-626325?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+Security+feed

๐Ÿ”น BleepingComputer: Spain arrests doxer leaking sensitive data of govt employees
https://www.bleepingcomputer.com/news/security/spain-arrests-doxer-leaking-sensitive-data-of-govt-employees/

๐Ÿ”น BleepingComputer: Red Hat npm packages compromised to steal developer credentials
https://www.bleepingcomputer.com/news/security/red-hat-npm-packages-compromised-to-steal-developer-credentials/

๐Ÿ”น BleepingComputer: Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
https://www.bleepingcomputer.com/news/security/hackers-hijack-thousands-of-sites-for-clickfix-and-fakeupdate-attacks/

#InfoSec #SecurityNews

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

Compromised npm packages targeted Red Hat cloud services, enabling credential theft and expanding supply chain risks.

The Hacker News