Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data

Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026.

To that end, organizations will be unable to connect … Continue reading Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data

Posted in Uncategorized

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users.

The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorr… Continue reading Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

Posted in Uncategorized

F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems.

The vulnerabilities are listed below –

CVE-2026-42530 (CVSS v4 score: 9.2) – A use-… Continue reading F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution

Posted in Uncategorized

ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories

The internet did not break this week. It got used exactly as designed, which is worse.

Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. … Continue reading ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories

Posted in Uncategorized

Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2

Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign that has targeted users since February 2026.

“The clipper in this campaign relies on Windows Script Host and ActiveX-driven logic to launch a bundled Tor proxy and poll… Continue reading Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2

Posted in Uncategorized

INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023

Cybersecurity researchers have charted the evolution of INC from an nascent ransomware-as-a-service (RaaS) operation to one of the most prolific cybercrime groups in 2026, claiming no less than 830 victims since August 2023.

“The disruption of LockBit… Continue reading INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023

Posted in Uncategorized

DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure.

According to f… Continue reading DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

Posted in Uncategorized

Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments

An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez, according to new findings from Check Point Research.

The threat actor also has at their disposal a dedicated WordP… Continue reading Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments

Posted in Uncategorized