← Latest brief

Security news.

·Afternoon Brief

Today's cybersecurity news highlights significant data breaches, critical vulnerabilities, and ongoing efforts against sophisticated threat actors. Several reports detail new attack techniques targeting macOS, AI platforms, and supply chains, while law enforcement continues to pursue cybercriminals globally.

BLEEPINGBREACH
Jun 23READ

Healthtech Firm Xolis Suffers Data Breach Impacting 1.4 Million People

Healthcare technology company Xsolis disclosed a phishing attack that compromised sensitive data for nearly 1.4 million individuals.

CISAKEV
Jun 23READ

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added CVE-2025-67038 (Lantronix EDS5000), CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 (Ubiquiti UniFi OS) to its KEV Catalog due to active exploitation.

BLEEPINGMALWARE
Jun 23READ

New macOS ClickFix Attack Silently Mounts DMGs to Push Infostealer

A new macOS campaign, dubbed "ClickFix," uses Terminal commands to silently download, mount, and launch info-stealing malware from malicious disk image (DMG) files.

SECURITYWEEKAI
Jun 23READ

Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Four vulnerabilities, collectively named DifyTap, in the Dify AI platform could allow attackers to read private chats and access internal APIs across tenants.

BLEEPINGSUPPLY CHAIN
Jun 23READ

LastPass Confirms Data Breach in Klue Supply Chain Attack

LastPass announced that hackers accessed customer data from its Salesforce environment by stealing the company's OAuth tokens in the Klue supply chain attack.

DARK READINGMALWARE
Jun 23READ

FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist

Threat actors are using a Golang-based sniffer to target 430,000 FortiGate firewalls, identifying 110 million credentials in an ongoing global campaign.

SECURITYWEEKRCE
Jun 23READ

FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances

A newly disclosed FFmpeg flaw, 'PixelSmash,' could enable remote code execution in applications using the libavcodec library by sending crafted media files.

KREBS
Jun 23READ

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Two members of the Scattered Spider cybercrime group pleaded guilty in the UK to charges related to the August 2024 cyberattack that crippled Transport for London.

Generated twice daily from public security RSS feeds. Informational only.