-
ShinyHunters Exploit Salesforce Guest Access Misconfigurations
Observed in the wild In early March, Salesforce warned that customers running public Experience Cloud sites were being targeted due to over‑permissive guest user configurations. Shortly afterwards, the ShinyHunters extortion group claimed responsibility, stating they had stolen data from around 100 high‑profile…
-
Axios npm Supply Chain Compromise Delivers Cross-Platform RAT
Observed in the wild In late March, malicious versions of the popular JavaScript HTTP library Axios, axios@1.14.1 and axios@0.30.4, were published to npm outside the project’s normal release workflow. Any organisation or developer automatically pulling these versions via version ranges was potentially exposed, affecting…
-
SearchLeak Chains Legacy Web Bugs into One-Click Copilot Data Exfiltration
For awareness In June, Varonis disclosed “SearchLeak”, a critical vulnerability chain in Microsoft 365 Copilot Enterprise, remediated by Microsoft under CVE-2026-42824. The issue allowed one-click exfiltration of sensitive organisational data, including emails, meeting content, SharePoint/OneDrive files, and MFA/OTP codes,…
-
Mass FortiGate Credential Leak Enables Widespread Remote Network Access
In June, researchers identified a dataset containing valid administrative credentials for ~75,000 internet-facing Fortinet FortiGate firewalls. The data appears recent and largely distinct from earlier leaks, with most affected devices still online. Impact spans global organisations, representing roughly half of exposed…
-
DragonForce Abuse Microsoft Teams Infrastructure for Covert C2
Observed in the wild On 16 June, Symantec reported that DragonForce ransomware actors compromised a major U.S. services organisation, maintaining access for 1–2 months following initial intrusion in December 2025. The attackers deployed ransomware and a persistent backdoor, enabling data theft and continued access. The…
-
UnDefend Proof-of-Concept Targets Windows Defender Update Availability
Observed in the wild A publicly available GitHub repository, UnDefend, demonstrates a proof‑of‑concept denial‑of‑service condition against Microsoft Defender by intentionally disrupting its ability to update and function correctly. While published as research rather than a campaign, Huntress has reported observing UnDefend…
-
Shai-Hulud 3.0: New Malware Signals Evolving Supply Chain Threats
Observed in the wild On 29 December, a security researcher discovered a new variant of the Shai-Hulud malware, dubbed “The Golden Path” (v3.0), embedded in the @vietmoney /react-big-calendar npm package (v0.26.2). This appears to be a technical evolution rather than a copycat, with reports limited to a single package,…
-
Codex Discovers High-Amplification HTTP/2 Denial-of-Service Technique
Observed in the wild On 2 June, researchers disclosed a new HTTP/2 denial-of-service technique affecting major web servers including nginx, Apache httpd, Microsoft IIS and Envoy. The vulnerability exists in default configurations and can allow a single client to exhaust tens of gigabytes of memory within seconds, rendering…
-
FIFA World Cup 2026 Lures Drive Phishing, Malware and Credential Theft Campaigns
Observed in the wild On 4 June, FortiGuard Labs reported a large-scale cybercrime ecosystem forming ahead of the FIFA World Cup 2026, active since at least January 2026. The campaign targets fans, businesses, and employees across sectors including travel, hospitality, media, and retail. Over 13,000 World Cup-themed domains…
-
One‑Click Attack Chain Targets GitHub Tokens Through VSCode in Browser
Observed in the wild On 2 June, a researcher disclosed a VSCode/web‑based github.dev flaw allowing attackers to steal GitHub OAuth tokens by tricking users into clicking a link. Affected users are those who access repositories via github.dev (browser‑based VSCode), including private repo users, as tokens grant broad repo…