North Korea Compromises Mastra AI Framework in Massive npm Supply Chain Attack
Summary Microsoft has attributed a sweeping supply chain attack on the Mastra AI npm ecosystem to North Korea’s Sapphire Sleet group (also tracked as BlueNoroff/UNC1069). Over 140 packages within the…
Censys Expands Into Security Operations — Bringing Internet Intelligence Directly Into SOC Workflows
Summary Censys announced on June 18 a major expansion into security operations, embedding its internet intelligence platform directly into SOC workflows through new integrations with leading SIEM, SOAR, and threat…
FBI Warns Cybercriminals Are Weaponizing Traffic Distribution Systems to Deliver Ransomware and Phishing
Summary The FBI has issued a Public Service Announcement (I-061826-PSA) on June 18 warning that cybercriminals are increasingly exploiting Traffic Distribution Systems (TDS) to funnel victims toward ransomware, phishing pages,…
GreatXML Zero-Day Bypasses Windows BitLocker Encryption Without Recovery Key — No Patch Available
Summary Prolific exploit researcher Nightmare Eclipse (also known as Chaotic Eclipse) has publicly released “GreatXML,” a zero-day exploit that bypasses Windows BitLocker encryption by abusing the trust boundary between the…
SANS 2026 Detection Engineering Report: 80% of Practitioners Falling Behind the Threat Landscape
Summary The 2026 SANS State of Detection Engineering Report, developed in partnership with Anvilogic, paints a sobering picture of the defensive security profession. Based on a survey of over 300…
Low-Skilled Attacker Uses Claude Code and OpenAI Codex to Breach 14 Companies — Recovered AI Logs Reveal the Full Kill Chain
Summary Researchers at OALABS (Open Analysis) have published a damning report detailing how a low-skilled attacker successfully breached at least 14 companies using Anthropic’s Claude Code and OpenAI’s Codex as…
Critical Splunk Enterprise Flaw Actively Exploited Days After Disclosure — CISA Orders Emergency Patch by Sunday
Summary A critical vulnerability in Splunk Enterprise (CVE-2026-20253) with a perfect CVSS score of 9.8 is now being actively exploited in the wild, just days after its disclosure on June…
HTTP/2 Bomb — AI-Discovered DoS Vulnerabilities Can Knock Web Servers Offline in Seconds
Summary A pair of newly disclosed HTTP/2 denial-of-service vulnerabilities dubbed the “HTTP/2 Bomb” are sending shockwaves through the web infrastructure community. CVE-2026-49975 affects the default HTTP/2 configurations of Apache HTTP…
ShinyHunters Breaches Madison Square Garden — 26 Million Customer Records and 45 GB of Corporate Data Stolen
Summary The ShinyHunters extortion group has claimed responsibility for breaching Madison Square Garden (MSG), exfiltrating 45 GB of corporate and customer data including 26 million customer records, customer support email…
SpaceX Acquires AI Coding Giant Cursor for $60 Billion in Largest Startup M&A Deal of 2026
Summary SpaceX has announced the acquisition of Cursor (Anysphere, Inc.) in a $60 billion all-stock deal — the largest startup M&A transaction of 2026. Cursor, the AI coding assistant founded…
