Ivanti Sentry Zero-Day Hits CVSS 10.0 — Exploited Within 24 Hours of PoC Release, CISA Orders Emergency Patch
Summary CISA has added CVE-2026-10520 — a maximum-severity (CVSS 10.0) OS command injection vulnerability in Ivanti Sentry — to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch by…
Europol Dismantles AudiA6 — Crypto Laundering Service That Washed €336 Million for Ransomware Gangs
Summary Europol has announced the takedown of “AudiA6,” a professional cryptocurrency laundering operation that processed over €336 million in illicit profits for ransomware gangs and cybercriminal networks between 2022 and…
INTERPOL and Algerian Authorities Dismantle SniperDz — Nine-Year Phishing-as-a-Service Empire That Targeted 30+ Global Organizations
A joint operation led by Group-IB, INTERPOL, and Algerian authorities has dismantled “SniperDz,” a Phishing-as-a-Service (PhaaS) platform that operated for nine years while providing sophisticated phishing kits targeting over 30…
Anthropic CEO Dario Amodei Calls for FAA-Style Regulation of Powerful AI Models — Releases Dual Policy Roadmaps
Anthropic CEO Dario Amodei published a detailed essay on June 10 titled “Policy on the AI Exponential,” arguing that the most powerful AI models need government oversight modeled after the…
“GreatXML” Zero-Day Drops — BitLocker Bypass Grants SYSTEM Privileges on Any Windows Machine With Offline Scan History
Security researcher “Nightmare Eclipse” has released a zero-day exploit dubbed “GreatXML” that bypasses Microsoft’s BitLocker full-disk encryption and spawns a command prompt with SYSTEM privileges in Recovery Mode. The exploit…
ServiceNow Confirms API Flaw Exploited in the Wild — Unauthenticated Access Exposed Customer IT Data
ServiceNow has disclosed a security incident in which a misconfigured API endpoint was exploited, granting unauthenticated access to customer instance data. The anomalous activity began around June 2 and went…
ShinyHunters Exploit Oracle PeopleSoft Zero-Days in Mass Data Theft Campaign — 300+ Instances Across 100+ Organizations Compromised
The prolific ShinyHunters cybercrime group has launched a sweeping data theft and extortion campaign against Oracle PeopleSoft servers, claiming to have compromised more than 300 instances across over 100 organizations.…
Krebs Unmasks “The Gentlemen” Ransomware Boss — Russian National Alexander Yapaev Identified as Admin
Investigative journalist Brian Krebs, along with researchers from Check Point Software and Intel 471, has identified the administrator behind “The Gentlemen” ransomware-as-a-service (RaaS) operation as Alexander Andreevich Yapaev, a 36-year-old…
South Korea Fines Coupang $409 Million in Record-Breaking Data Breach Penalty — 33 Million Customer Records Exposed
South Korea’s Personal Information Protection Commission (PIPC) has dropped the hammer on e-commerce giant Coupang with a staggering 624.7 billion won (\$409 million) fine — the largest data breach penalty…
FIFA World Cup 2026 Fraud Campaigns Explode — FBI Warns of 19,000+ Fake Domains, Credential Harvesting, and Banking Malware
With the 2026 FIFA World Cup approaching, the FBI and cybersecurity researchers are warning of a massive surge in World Cup-themed fraud campaigns. Researchers have identified approximately 19,000 FIFA-themed domains…
