Feeds last updated @: UTC - 22:45 - 13/06/2026
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
https://www.theregister.com/security
https://hackread.com/extradited-ukrainian-admits-conti-ransomware-attacks/
https://hackread.com/atomic-arch-hijacks-linux-aur-packages-malware/
https://hackread.com/shinyhunters-universities-oracle-peoplesoft-zero-day-attack/
https://hackread.com/spacex-pre-ipo-market-crypto-synthetic-access/
https://hackread.com/feds-seize-audia6-dark2web-crypto-laundering-case/
https://www.debian.org/security/
https://msrc.microsoft.com/update-guide/vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-10846
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11822
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11824
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40034
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5222
https://www.ncsc.nl/alerts/microsoft-verhelpt-6-ernstige-kwetsbaarheden-in-windows
https://www.ncsc.nl/alerts/ernstige-kwetsbaarheden-in-check-point-remote-and-mobile-access-vpn
https://www.ncsc.nl/nieuws/ncsc-sluit-zich-aan-bij-sectorpact-weerbaar-energiesysteem
https://www.ncsc.nl/expertblogs/misconfiguraties-bieden-open-deur-tot-gevoelige-gegevens
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1909
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1811
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1908
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1907
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1906
https://thehackernews.com/2026/06/critical-splunk-enterprise-flaw-lets.html
https://thehackernews.com/2026/06/us-orders-anthropic-to-suspend-fable-5.html
https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html
https://thehackernews.com/2026/06/google-sues-chinese-smishing-network.html
https://thehackernews.com/2026/06/china-linked-hackers-backdoored-linux.html
https://techrepublic.com/topic/security
A new Windows zero-day reportedly bypasses BitLocker, adding pressure on Microsoft as researchers debate the exploit’s real-world impact.
The post New Windows Zero-Day Claims BitLocker Bypass Amid Microsoft Disclosure Fight appeared first on TechRepublic.
https://www.techrepublic.com/article/news-windows-bitlocker-zero-day-june-2026/
South Korea fined Coupang $409 million after regulators said weak security controls led to a massive breach affecting 37.5 million accounts.
The post South Korea Drops a $409M Fine on Coupang in Historic Data Breach Ruling appeared first on TechRepublic.
https://www.techrepublic.com/article/news-coupang-record-fine-409m-apac-south-korea/
Microsoft reportedly limited internal use of Claude Fable 5 while legal teams review Anthropic’s 30-day data-retention policy.
The post Microsoft Restricts Claude Fable 5 Access Amid AI Safety Review appeared first on TechRepublic.
https://www.techrepublic.com/article/news-microsoft-claude-fable-5-data-retention/
CISA’s LiteLLM warning shows why AI gateways and agents need service account governance, scoped access, credential rotation, and audit trails.
The post CISA Warning: LiteLLM Flaw Could Expose Enterprise AI Gateways appeared first on TechRepublic.
https://www.techrepublic.com/article/news-litellm-cisa-ai-gateway-service-account-governance/
Meta description: French officials are investigating a Tchap breach after an attacker claimed that 650,000 messages and 73,000 accounts were exposed via a hijacked account.
The post France’s Tchap Breach: 650,000 Messages, 73,000 Accounts Exposed appeared first on TechRepublic.
https://www.techrepublic.com/article/news-tchap-breach-emea-france/
https://www.bleepingcomputer.com/
https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/
https://krebsonsecurity.com/2026/06/a-record-breaking-patch-tuesday-for-june-2026/
https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/
https://krebsonsecurity.com/2026/05/lawmakers-demand-answers-as-cisa-tries-to-contain-data-leak/
1,000 breaches is one hell of a milestone. It's not just the process of getting data, verifying it, loading it, sending notifications etc, it's all the other stuff that goes into keeping the whole thing afloat. Legal docs. Trademarks. Accounting. Agreements. The most mind-numbingly
Today, we welcome the 46th government onboarded to Have I Been Pwned’s free gov service: the Philippines.
The Philippines’ National CERT, working with the Department of Information and Communications Technology, now has access to monitor official government domains against the data in HIBP. This gives their Cyber
https://www.troyhunt.com/welcoming-the-philippine-government-to-have-i-been-pwned/
Today, I loaded the 1,000th data breach into Have I Been Pwned. Reflecting on that milestone number, I pondered how to mark the occasion in writing, and what immediately came to mind was a very simple question: why is it still needed? Especially considering the emergence of privacy regulations
https://www.troyhunt.com/1000-data-breaches-later-the-disclosure-lag-is-worse-than-ever/
I'm finding it quite fascinating to watch the current spate of ShinyHunters breaches and dumps. There's the obvious criminality of it all, but then there's also the response from organisations (or lack thereof, as it relates to disclosure to victims), the appearance and disappearance
Today, we welcome the 45th government onboarded to Have I Been Pwned’s free gov service: Bhutan. The Bhutan Computer Incident Response Team, BtCIRT, now has access to monitor Bhutanese government domains against the data in HIBP. As Bhutan’s national CIRT, BtCIRT is responsible for consuming threat
https://www.troyhunt.com/welcoming-the-bhutanese-government-to-have-i-been-pwned/
This fluid pump was inspired by the way squids propel themselves through the water.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
https://www.schneier.com/blog/archives/2026/06/friday-squid-blogging-squid-inspired-fluid-pump.html
Let no one accuse Bernie Sanders of ducking the big questions. Writing in the New York Times last week, the senator asked: “Will the future of humanity be determined by a handful of billionaires who have promoted and developed AI, with virtually no democratic input, who stand to become even richer and more powerful than they are today?”
We agree entirely that this is one of the most potent questions facing global democracy today. Our book, Rewiring Democracy, surveys the emerging uses for and impacts of AI in democracy around the world and reaches the same conclusion: that the most urgent risk posed by AI is the ...
https://www.schneier.com/blog/archives/2026/06/bernie-sanders-ai-sovereign-wealth-fund-plan.html
The surveillance company Leonardo wants more data:
A surveillance company plans to add sensors to automatic license plate readers (ALPRs) that would mean the devices, as well as capture the license plate of passing vehicles, would also sweep up unique identifiers of mobile phones, wearables, and other Bluetooth-enabled devices in those cars, potentially letting law enforcement identify specific drivers or passengers.
The technology, called SignalTrace, would turn ALPR cameras from devices focused on tracking cars to ones that can more readily track the location of particular people. ALPR cameras have become a commonly deployed technology all across the U.S.; SignalTrace would make some of those cameras capable of collecting much more data...
https://www.schneier.com/blog/archives/2026/06/enhanced-license-plate-tracking.html
WhatsApp has caught the NSO Group phishing its users, in violation of a court order.
https://www.schneier.com/blog/archives/2026/06/nso-group-hacking-whatsapp-despite-court-order.html
This is interesting:
The U.S. military has likely been quietly broadcasting codes for its global encryption network using public GPS for nearly 20 years, turning each satellite into a hidden “numbers station,” according to Steven Murdoch...
That means every device that uses GPS has been receiving hidden government information for years, and nobody outside the military knew it until now.
[...]
Murdoch discovered that this particular sentinel was transmitted by all 31 operational satellites within a window of a few hours on May 26, 2011, potentially heralding the activation of a new operational system. He confirmed that this timeline coincided with the rollout of the military’s Over-the-Air Distribution (OTAD) and the Over-the-Air Rekeying (OTAR) by cross-referencing declassified documents, including a 2015 presentation about the dates of the operation...
https://www.schneier.com/blog/archives/2026/06/gps-as-a-key-distribution-platform.html
Independent testing confirms what our customers already know: Sophos Endpoint delivers consistent, real-world protection at every tier of the market, from the largest enterprises to small businesses.
https://www.sophos.com/en-us/blog/sophos-se-labs-awards-2026
How AI is rewriting vulnerability research, and how our program has adapted
https://www.sophos.com/en-us/blog/bug-bounties-in-the-mythos-era
Learn more and share your feedback with the team on the Sophos Workspace Protection Community.
https://www.sophos.com/en-us/blog/sophos-workspace-protection-update
Following a certification test, Sophos X-Ops found an unexpected guest had hitched a ride
https://www.sophos.com/en-us/blog/you-do-surprise-me-exe-an-unexpected-executable-in-hola-browser
AI accelerated tool development and testing, but humans drove the workflow
https://www.sophos.com/en-us/blog/pointing-a-cursor-at-evading-detection