A supply chain attack on market intelligence platform Klue has hit cybersecurity firms Huntress and Recorded Future, among what The Register reports are hundreds of affected Klue customers. Starting June 11, hackers reached Klue's backend servers and pushed a code update that harvested OAuth tokens for customers' integrations. Klue notified customers on June 12.
They then abused the Salesforce REST API to pull large volumes of CRM data — nearly 1,000 queries in 15 minutes, with extraction windows running over six hours. Salesforce wasn't the only exposure: the stolen tokens also covered Klue integrations with HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive and Slack.
Huntress lost business contacts, price quotes and other sales data. Recorded Future lost client contact names and email addresses, and possibly business contract information. Neither lost threat intelligence, passwords or payment data.
Huntress has linked the attack to Icarus, an extortion group that emerged in April 2026, after receiving direct extortion messages from a threat actor identifying as "mr bean." Klue customers should revoke and re-authorise their integration tokens.
Source: SecurityWeek
A supply chain attack on market intelligence platform Klue has hit cybersecurity firms Huntress and Recorded Future, among what The Register reports are hundreds of affected Klue customers. Starting June 11, hackers reached Klue's backend servers and pushed a code update that harvested OAuth tokens for customers' integrations. Klue notified customers on June 12.
They then abused the Salesforce REST API to pull large volumes of CRM data — nearly 1,000 queries in 15 minutes, with extraction windows running over six hours. Salesforce wasn't the only exposure: the stolen tokens also covered Klue integrations with HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive and Slack.
Huntress lost business contacts, price quotes and other sales data. Recorded Future lost client contact names and email addresses, and possibly business contract information. Neither lost threat intelligence, passwords or payment data.
Huntress has linked the attack to Icarus, an extortion group that emerged in April 2026, after receiving direct extortion messages from a threat actor identifying as "mr bean." Klue customers should revoke and re-authorise their integration tokens.
Source: SecurityWeek
Security researchers at HawkTrace have disclosed a high-severity SSRF vulnerability in Microsoft Exchange, tracked as CVE-2026-45504 with a CVSS score of 8.8. The flaw lets authenticated low-privileged users read arbitrary files from on-premises Exchange servers — think credentials, config files, and internal service data. Exchange Online is not affected.
The attack exploits how Exchange handles attachment previews via its OneDriveProUtilities component, passing user-controlled URLs into HTTP requests without proper validation. A simple file:// URI with a fragment character (#) bypasses protections entirely.
A working PoC is now live on GitHub, making patching urgent. Check Microsoft's advisory for the affected builds and the update that fixes them, and block Exchange from reaching untrusted external endpoints in the meantime.
Source: Cybersecurity News
Security researchers at HawkTrace have disclosed a high-severity SSRF vulnerability in Microsoft Exchange, tracked as CVE-2026-45504 with a CVSS score of 8.8. The flaw lets authenticated low-privileged users read arbitrary files from on-premises Exchange servers — think credentials, config files, and internal service data. Exchange Online is not affected.
The attack exploits how Exchange handles attachment previews via its OneDriveProUtilities component, passing user-controlled URLs into HTTP requests without proper validation. A simple file:// URI with a fragment character (#) bypasses protections entirely.
A working PoC is now live on GitHub, making patching urgent. Check Microsoft's advisory for the affected builds and the update that fixes them, and block Exchange from reaching untrusted external endpoints in the meantime.
Source: Cybersecurity News
Texas Parks and Wildlife Department is offering free credit monitoring to over 3 million Texans after a cybersecurity breach exposed personal data from the state's hunting and fishing license system. Texas Cyber Command detected the incident at a third-party licensing vendor, which officials have not named, and the department disclosed it in late June.
Compromised data includes driver's license information, passport numbers, email addresses, phone numbers and home addresses. No Social Security numbers, dates of birth, financial data or minors' records were affected. License sales remain unaffected, and will proceed as scheduled for August and the next license year.
Impacted residents can enroll in one year of free Kroll credit monitoring until September 14, 2026. Support is available at (844) 959-7123, weekdays 8 a.m.–5:30 p.m. Officials also advise freezing your credit, placing fraud alerts, and staying alert to scam calls or emails impersonating the department.
Source: CBS News Texas
Texas Parks and Wildlife Department is offering free credit monitoring to over 3 million Texans after a cybersecurity breach exposed personal data from the state's hunting and fishing license system. Texas Cyber Command detected the incident at a third-party licensing vendor, which officials have not named, and the department disclosed it in late June.
Compromised data includes driver's license information, passport numbers, email addresses, phone numbers and home addresses. No Social Security numbers, dates of birth, financial data or minors' records were affected. License sales remain unaffected, and will proceed as scheduled for August and the next license year.
Impacted residents can enroll in one year of free Kroll credit monitoring until September 14, 2026. Support is available at (844) 959-7123, weekdays 8 a.m.–5:30 p.m. Officials also advise freezing your credit, placing fraud alerts, and staying alert to scam calls or emails impersonating the department.
Source: CBS News Texas
Cybersecurity firm Sophos is warning of a dangerous new partnership between ransomware group Vect and TeamPCP, a credential-theft gang whose members it says were previously affiliated with the English-speaking Com collective. Announced by the groups in late March and detailed in a July 2 blog post, the arrangement pairs TeamPCP's large-scale supply chain attacks with Vect's ransomware-as-a-service operation.
Sophos has confirmed at least one Vect deployment using TeamPCP-stolen credentials. It also found a flaw worth knowing about before anyone considers negotiating: Vect's encryption destroys files larger than 128KB rather than encrypting them, so paying up won't bring them back.
TeamPCP's side of the operation is substantial. Between March and May 2026 it compromised the Trivy, Checkmarx, LiteLLM and Telnyx developer tools, reaching more than 1,000 enterprise environments and taking around 300GB of compressed data — including over 500,000 credentials and 10,000 CI/CD workflows from Trivy alone.
The FBI issued a simultaneous FLASH warning, naming TeamPCP malware including CanisterWorm, Sandclock, Miasma, and the self-replicating worm Mini Shai-Hulud.
Source: Infosecurity Magazine
Cybersecurity firm Sophos is warning of a dangerous new partnership between ransomware group Vect and TeamPCP, a credential-theft gang whose members it says were previously affiliated with the English-speaking Com collective. Announced by the groups in late March and detailed in a July 2 blog post, the arrangement pairs TeamPCP's large-scale supply chain attacks with Vect's ransomware-as-a-service operation.
Sophos has confirmed at least one Vect deployment using TeamPCP-stolen credentials. It also found a flaw worth knowing about before anyone considers negotiating: Vect's encryption destroys files larger than 128KB rather than encrypting them, so paying up won't bring them back.
TeamPCP's side of the operation is substantial. Between March and May 2026 it compromised the Trivy, Checkmarx, LiteLLM and Telnyx developer tools, reaching more than 1,000 enterprise environments and taking around 300GB of compressed data — including over 500,000 credentials and 10,000 CI/CD workflows from Trivy alone.
The FBI issued a simultaneous FLASH warning, naming TeamPCP malware including CanisterWorm, Sandclock, Miasma, and the self-replicating worm Mini Shai-Hulud.
Source: Infosecurity Magazine
The threat actors behind FortiBleed — a massive credential-harvesting campaign targeting Fortinet FortiGate firewalls — are feeding stolen access to the Inc Ransom and Lynx ransomware gangs. SOCRadar researchers caught a single operator logged into both groups' ransom negotiation panels while using infrastructure tied directly to FortiBleed, though they assess FortiBleed runs as a separate outfit selling access rather than as a partner in either operation.
Of 430,000 FortiGate devices targeted globally, roughly 12,000 currently carry FortiBleed's Golang sniffer, which quietly turns the firewall itself into a credential harvester. Credentials have been stolen from over 30,000. Of 409 targets where attackers gained admin access, 354 saw the full chain executed — VPN breach, domain controller access, domain admin.
At least 12 ransomware deployments have been confirmed, encrypting hundreds of endpoints. SOCRadar also flagged an unpatched Nextcloud zero-day being actively exploited during FortiBleed's access-brokering stage; Nextcloud says it has had no formal report and has promised a fast fix.
Source: Dark Reading
The threat actors behind FortiBleed — a massive credential-harvesting campaign targeting Fortinet FortiGate firewalls — are feeding stolen access to the Inc Ransom and Lynx ransomware gangs. SOCRadar researchers caught a single operator logged into both groups' ransom negotiation panels while using infrastructure tied directly to FortiBleed, though they assess FortiBleed runs as a separate outfit selling access rather than as a partner in either operation.
Of 430,000 FortiGate devices targeted globally, roughly 12,000 currently carry FortiBleed's Golang sniffer, which quietly turns the firewall itself into a credential harvester. Credentials have been stolen from over 30,000. Of 409 targets where attackers gained admin access, 354 saw the full chain executed — VPN breach, domain controller access, domain admin.
At least 12 ransomware deployments have been confirmed, encrypting hundreds of endpoints. SOCRadar also flagged an unpatched Nextcloud zero-day being actively exploited during FortiBleed's access-brokering stage; Nextcloud says it has had no formal report and has promised a fast fix.
Source: Dark Reading
Aflac has disclosed a significant data breach at its Japanese subsidiary, affecting nearly 4.4 million customers. Hackers were inside Aflac Japan's systems from June 15 until discovery on June 25, stealing policy details, personal information, and bank account data — including premium payment records for around 230,000 customers.
The company filed with the SEC on June 30, confirming US operations were unaffected. Some customer portal services remain offline, including medical check-up reservations and the AI support concierge, though claims and payments continue via call centers. Aflac Japan has notified authorities and says no misuse has been confirmed yet.
No attribution has been made, though researchers have raised the possibility of Scattered Spider involvement — the group blamed for a 2025 intrusion at Aflac. It's the third breach Aflac has disclosed since 2023. Anyone with premium payments set up should keep an eye on their bank account regardless.
Source: Infosecurity Magazine
Aflac has disclosed a significant data breach at its Japanese subsidiary, affecting nearly 4.4 million customers. Hackers were inside Aflac Japan's systems from June 15 until discovery on June 25, stealing policy details, personal information, and bank account data — including premium payment records for around 230,000 customers.
The company filed with the SEC on June 30, confirming US operations were unaffected. Some customer portal services remain offline, including medical check-up reservations and the AI support concierge, though claims and payments continue via call centers. Aflac Japan has notified authorities and says no misuse has been confirmed yet.
No attribution has been made, though researchers have raised the possibility of Scattered Spider involvement — the group blamed for a 2025 intrusion at Aflac. It's the third breach Aflac has disclosed since 2023. Anyone with premium payments set up should keep an eye on their bank account regardless.
Source: Infosecurity Magazine
Two critical vulnerabilities in Cursor IDE — the AI coding tool used by over half of Fortune 500 companies — could give attackers full remote code execution without any user interaction. Discovered by Cato AI Labs and dubbed "DuneSlide," both flaws carry a 9.8 CVSS score (CVE-2026-50548 and CVE-2026-50549).
The attack works through prompt injection: a victim simply types a normal prompt that accidentally pulls in attacker-controlled content — from a poisoned web search or rogue MCP server. From there, attackers can overwrite core sandbox binaries and compromise both the local machine and connected SaaS workspaces.
Cursor 3.0, out since April 2, fixes both. Every earlier version is affected, and there's no sign of exploitation in the wild. Getting there took some pushing: Cursor rejected Cato's initial report in February, saying its threat model didn't account for MCP server misuse, and only reopened the cases after the researchers escalated.
Cato says more disclosures are coming across other AI coding agents.
Source: Cybersecurity News
Two critical vulnerabilities in Cursor IDE — the AI coding tool used by over half of Fortune 500 companies — could give attackers full remote code execution without any user interaction. Discovered by Cato AI Labs and dubbed "DuneSlide," both flaws carry a 9.8 CVSS score (CVE-2026-50548 and CVE-2026-50549).
The attack works through prompt injection: a victim simply types a normal prompt that accidentally pulls in attacker-controlled content — from a poisoned web search or rogue MCP server. From there, attackers can overwrite core sandbox binaries and compromise both the local machine and connected SaaS workspaces.
Cursor 3.0, out since April 2, fixes both. Every earlier version is affected, and there's no sign of exploitation in the wild. Getting there took some pushing: Cursor rejected Cato's initial report in February, saying its threat model didn't account for MCP server misuse, and only reopened the cases after the researchers escalated.
Cato says more disclosures are coming across other AI coding agents.
Source: Cybersecurity News
Security firm Adversa AI has found a structural flaw — dubbed GuardFall — affecting 10 of 11 popular open source AI coding agents, including Hermes, OpenCode and Roo-code. Lead researcher Omer Ben Simon showed that attackers can embed old-school Bash tricks like quote removal and $IFS spacing into content agents ingest, such as a poisoned README or Makefile.
Once inside, those commands can silently steal AWS credentials or wipe dev environments, running with the developer's full account authority. The worst case is a CI pipeline with auto-execute switched on, where nobody is watching the terminal at all.
Only one agent, Continue, successfully blocked all test bypasses. Adversa recommends maintainers adopt a tokenize-and-canonicalize evaluator guard — the approach Continue uses — rather than relying on pattern-based text matching that Bash simply rewrites around. No fixes have been announced yet, so if your agents run unattended in CI, turning off auto-execute is the short-term answer.
Source: SecurityWeek
Security firm Adversa AI has found a structural flaw — dubbed GuardFall — affecting 10 of 11 popular open source AI coding agents, including Hermes, OpenCode and Roo-code. Lead researcher Omer Ben Simon showed that attackers can embed old-school Bash tricks like quote removal and $IFS spacing into content agents ingest, such as a poisoned README or Makefile.
Once inside, those commands can silently steal AWS credentials or wipe dev environments, running with the developer's full account authority. The worst case is a CI pipeline with auto-execute switched on, where nobody is watching the terminal at all.
Only one agent, Continue, successfully blocked all test bypasses. Adversa recommends maintainers adopt a tokenize-and-canonicalize evaluator guard — the approach Continue uses — rather than relying on pattern-based text matching that Bash simply rewrites around. No fixes have been announced yet, so if your agents run unattended in CI, turning off auto-execute is the short-term answer.
Source: SecurityWeek
AWS has patched a high-severity bug in the Amazon Q Developer extension that could let attackers steal cloud credentials just by getting a developer to open a malicious repository. Tracked as CVE-2026-12957 and discovered by Wiz Research, the flaw allowed Amazon Q to automatically load and execute MCP server configurations without user approval — silently, before any code review happened.
Because spawned processes inherited the developer's full environment, attackers could grab AWS credentials, API keys, SSH secrets and other sensitive environment variables. Wiz built a working proof of concept; no widespread attacks have been reported.
The fix landed in AWS Language Server version 1.65.0, which covers Amazon Q in VS Code and the other IDEs it supports. Update, then check your existing MCP configurations — patching stops new configs from auto-executing, but won't remove one a poisoned repo already dropped. Similar MCP-related vulnerabilities have also been found in Claude Code, Cursor and Windsurf.
Source: Dark Reading
AWS has patched a high-severity bug in the Amazon Q Developer extension that could let attackers steal cloud credentials just by getting a developer to open a malicious repository. Tracked as CVE-2026-12957 and discovered by Wiz Research, the flaw allowed Amazon Q to automatically load and execute MCP server configurations without user approval — silently, before any code review happened.
Because spawned processes inherited the developer's full environment, attackers could grab AWS credentials, API keys, SSH secrets and other sensitive environment variables. Wiz built a working proof of concept; no widespread attacks have been reported.
The fix landed in AWS Language Server version 1.65.0, which covers Amazon Q in VS Code and the other IDEs it supports. Update, then check your existing MCP configurations — patching stops new configs from auto-executing, but won't remove one a poisoned repo already dropped. Similar MCP-related vulnerabilities have also been found in Claude Code, Cursor and Windsurf.
Source: Dark Reading
The hacking group ShinyHunters has claimed responsibility for a major cyber-attack on the University of Nottingham, confirmed on June 10. Around 455,000 unique email addresses were compromised — the number of people affected is lower, since many had both a university and a personal address — and one expert put the haul at roughly 40 gigabytes taken from the university's student record system.
Stolen data includes passport numbers, national insurance numbers, dates of birth, financial details, ethnicity and disability information, affecting both current students and alumni. Early speculation pointed to voice phishing or a supply chain breach; reporting since has identified the entry point as an Oracle PeopleSoft zero-day, CVE-2026-35273, which Mandiant links to attacks on more than 100 organisations, most of them universities.
Security researcher Troy Hunt believes the university was held to ransom and refused to pay, which is why the data was published — the university itself won't comment while the criminal investigation runs. EMSOU's Regional Cyber Crime Unit is investigating, and the university has notified the ICO, NCSC, Office for Students and Action Fraud.
Affected individuals should enable multi-factor authentication and stay alert to unexpected phone calls.
Source: BBC News
The hacking group ShinyHunters has claimed responsibility for a major cyber-attack on the University of Nottingham, confirmed on June 10. Around 455,000 unique email addresses were compromised — the number of people affected is lower, since many had both a university and a personal address — and one expert put the haul at roughly 40 gigabytes taken from the university's student record system.
Stolen data includes passport numbers, national insurance numbers, dates of birth, financial details, ethnicity and disability information, affecting both current students and alumni. Early speculation pointed to voice phishing or a supply chain breach; reporting since has identified the entry point as an Oracle PeopleSoft zero-day, CVE-2026-35273, which Mandiant links to attacks on more than 100 organisations, most of them universities.
Security researcher Troy Hunt believes the university was held to ransom and refused to pay, which is why the data was published — the university itself won't comment while the criminal investigation runs. EMSOU's Regional Cyber Crime Unit is investigating, and the university has notified the ICO, NCSC, Office for Students and Action Fraud.
Affected individuals should enable multi-factor authentication and stay alert to unexpected phone calls.
Source: BBC News