New Prinz Eugen Ransomware Prioritizes Recent Files for Encryption
A new ransomware operation named Prinz Eugen targets recently modified files and leaves no ransom note, complicating recovery and ransom communications.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,764 stories synthesized.
A new ransomware operation named Prinz Eugen targets recently modified files and leaves no ransom note, complicating recovery and ransom communications.
Key findings • CVE-2026-56216 allows app-limited API keys to escalate to unrestricted org-wide keys • Four unauthenticated CVEs target Supabase PostgREST RPC endpoints for cross-tenant attack…
The ShinyHunters extortion gang claims to have stolen 8.8 terabytes of data from Amazon's One Medical unit and is threatening to publish it unless the company meets ransom demands by June 22.
The employee health plan of novelty retailer Spencer's Gifts has paid a $450,000 HIPAA penalty after a federal investigation into a 2021 Conti ransomware breach revealed systemic privacy and security rule failures.
Key findings • Two critical CVEs: arbitrary file read via BaseFileComponent nodes and IDOR in /api/v1/responses • Unauthenticated DoS via oversized multipart boundary on /api/v1/files/upload/…
Key findings • 13 CVEs disclosed together on 2026-06-19, one critical (CVE-2026-54782) and seven high-severity • Critical SAML authentication bypass allows full impersonation of any STS-issue…
Key findings • 13 CVEs disclosed June 18–19, 2026 across Copilot, Azure, Exchange, Dynamics 365, Edge, and developer libraries • Four Copilot-related flaws include an open redirect, command…
Key findings • 25 vulnerabilities disclosed in Joomla! components on June 19, 2026, within a single hour. • Majority of disclosed vulnerabilities are SQL injection flaws across numerous third…
Critical vulnerabilities in the SiderAI and MaxAI Chrome extensions, installed on over 10 million devices, allow attackers to silently extract Gmail, calendar, and AI conversation data without any user interaction.
A weekly roundup covers Apple's Beats eavesdropping patch, a supply chain attack on 1.2 million WordPress sites via OptinMonster, and a decade-long stealth operation by China-linked Velvet Ant.
Key findings • CVE-2026-52910: Use-after-free in BPF reuseport cBPF program handling, reported with a reproducer • CVE-2026-52909: Missing netns_immutable flag in ip6_vti fallback device allo…
Key findings • 12 CVEs disclosed together, all fixed in Apache APISIX 3.17.0 • Five authentication bypass/spoofing flaws across jwt-auth, hmac-auth, jwe-decrypt, opa, and authz-casdoor • …
Qualys researchers have uncovered HazyBeacon, a cyber-espionage campaign targeting Southeast Asian governments that weaponizes AWS Lambda Function URLs as stealthy command-and-control relays.
A breach at an unnamed license-sales vendor for the Texas Parks and Wildlife Department has exposed the personal data of over 3 million Texans, including driver's license and passport numbers.
Check Point researchers uncovered a campaign where attackers used fake GitHub stars, YouTube tutorials, and favorable VirusTotal comments to promote malicious cryptocurrency sniper bots and gambling predictors.
Threat actors injected malicious JavaScript into the Okendo Reviews widget, a platform used by over 18,000 e-commerce sites, to deliver remote access trojans and info-stealers via fake CAPTCHA prompts.
Key findings • CVE-2026-50242 allows authentication bypass via direct database access, leading to full admin control • CVE-2026-56141 enables account takeover through predictable restore code…
Microsoft has acknowledged a bug in all supported Windows releases where the Recycle Bin confirmation dialog displays internal filenames instead of the original file names after installing the June 2026 security updates.
International law enforcement has disrupted the SocGholish malware network, removing malicious code from 15,000 compromised websites and dismantling infrastructure linked to the Evil Corp ransomware group.
Mastodon 4.6 adds a Collections feature for grouping profiles and gives server administrators the ability to enforce two-factor authentication on all member accounts.
Google announced that Android developer verification enforcement will begin on September 30, 2026, in Brazil, Indonesia, Singapore, and Thailand, with global expansion planned for 2027.
A supply chain attack on competitive intelligence platform Klue has compromised Salesforce instances belonging to its customers, including cybersecurity firms Huntress and Recorded Future, with data exfiltration attributed to the emerging Icarus extortion group.
A stealthy China-linked malware framework called Showboat has been targeting Middle Eastern telecom companies since mid-2022, evading all 65 AV engines on VirusTotal until April 2026.
Key findings • All 16 packages were registered and disclosed on the same day (June 19, 2026), indicating a disposable-account attack pattern • The packages fall into three thematic clusters: …