Hackers started exploiting a critical vulnerability in SAP Commerce Cloud just three days after its public disclosure, according to threat intelligence organizations. The vulnerability is tracked as CVE-2026-58231 and is described as an issue involving insufficient authorization checks and input… Read More "Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure"
New CISO appointments 2026 | CSO Online
Lexitas appoints Joe Giannetti as CIO and CISO Lexitas named Joe Giannetti its new CIO and CISO. Giannetti brings more than 25 years of experience in technology and security leadership from high-growth organizations, including Employ, Applied Systems, and previous roles… Read More "New CISO appointments 2026 | CSO Online"
Microsoft Attributes Mastra AI Supply Chain Attack to North Korea
A supply chain attack which targeted Mastra, an open-source typescript for building AI-powered applications and agents, was the work of North Korean hackers, cybersecurity researchers have said. The attribution was made on June 19 by Microsoft Defender Security Research Team… Read More "Microsoft Attributes Mastra AI Supply Chain Attack to North Korea"
Fortune 500 Companies Hit in Azure Data Theft Campaign
A threat actor is selling data allegedly stolen directly from the Azure tenants of several Fortune 500 organizations. Using the moniker ‘TheHatman’, the threat actor has been offering millions of records apparently stolen from well-known brands such as McDonald’s Corporation,… Read More "Fortune 500 Companies Hit in Azure Data Theft Campaign"
Unpatchable BootROM Flaw Impacts Apple A12, A13 Chips
A novel iPhone BootROM vulnerability has been discovered by researchers that gives attackers with physical access a route to compromise the boot chain on Apple A12, S4/S5 and Apple A13 systems-on-chips (SoCs). Paradigm Shift’s new analysis shared how the bug, which… Read More "Unpatchable BootROM Flaw Impacts Apple A12, A13 Chips"
GentleKiller Framework Disables Victims’ Security Software
One of the most active ransomware gangs of 2026 has been handing its affiliates a ready-made toolkit for switching off victims’ security software before the encryption begins. New analysis from ESET detailed the endpoint detection and response (EDR) killer suite… Read More "GentleKiller Framework Disables Victims’ Security Software"
Five Eyes Group Issues Urgent Call to Tackle Frontier AI Threats
The leaders of the Five Eyes cybersecurity agencies have warned that frontier AI will “fundamentally” transform offensive and defensive capabilities within months. In a public statement issued on June 22, the UK, US, Canada, New Zealand and Australia called on… Read More "Five Eyes Group Issues Urgent Call to Tackle Frontier AI Threats"
Scattered Spider Teens Convicted of TfL Cyber-Attack
Two British youngsters who hacked Transport for London (TfL) in 2024 have pleaded guilty to their crimes, according to the National Crime Agency (NCA). Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, were teenagers… Read More "Scattered Spider Teens Convicted of TfL Cyber-Attack"
GTA 6 Scams Emerge as Pre-Orders Open
As Rockstar Games announced pre-orders for Grand Theft Auto VI (GTA 6) will be available from June 25, scammers have already whipped up fake websites offering early access. These websites are offering access to GTA 6 and VIP early access… Read More "GTA 6 Scams Emerge as Pre-Orders Open"
Trump Issues Executive Order to Fast-Track Post-Quantum Migration
US federal agencies will have to complete their post-quantum cryptography (PQC) migration by 2030, or 2031 at the latest depending on use cases. In a new executive order (EO) signed on June 22 (EO 14412), US president Donald Trump issued… Read More "Trump Issues Executive Order to Fast-Track Post-Quantum Migration"