Instagram users locked out after Meta AI abused to steal accounts

Attackers have successfully hijacked Instagram accounts by exploiting Meta's AI-powered support systems. The attackers tricked the AI into believing they were the legitimate account owners, leading to users being locked out of their accounts.

Why the browser is now the front line for AI security

The browser has become a critical front line for AI security due to the rise of AI-powered attacks and the adoption of shadow AI. Push Security emphasizes the need for enhanced browser visibility to effectively detect threats and govern AI usage.

CISA flags two-year-old Oracle flaw as actively exploited in attacks

CISA has issued a directive to US government agencies, ordering them to patch a two-year-old, high-severity Oracle WebLogic Server vulnerability. This flaw, which was previously patched, is now being actively exploited in real-world attacks.

Infected Red Hat npm packages expose developer credentials

A new supply chain attack, dubbed Miasma, has compromised over 30 Red Hat Cloud Services-related npm packages, inserting a worm designed to steal developer credentials and authentication tokens. The malware, an evolution of the Shai-Hulud family, also expands its scope to collect cloud identities from Google Cloud and Azure. While most of the infected packages have been removed, the attack highlights ongoing risks in the software supply chain.

AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.

AI is accelerating the timeline for vulnerability exploitation, shrinking the window between disclosure and weaponization to mere hours. This rapid exploitation demands a fundamental shift in how organizations approach vulnerability management, moving beyond traditional reactive patching to more proactive and AI-aware strategies.

Oracle WebLogic Vulnerability Exploited in the Wild

A critical vulnerability, identified as CVE-2024-21182, in Oracle WebLogic Server is actively being exploited in the wild. This vulnerability can be exploited without requiring any authentication, posing a significant risk to affected servers.

Attackers exploit Palo Alto GlobalProtect flaw days after disclosure

Attackers are actively exploiting a Palo Alto Networks GlobalProtect vulnerability, tracked as CVE-2026-0257, to gain unauthorized VPN access into corporate networks. The flaw, which allows for credential-less authentication bypass, was initially disclosed as medium severity but was quickly escalated to high urgency by Palo Alto Networks due to observed exploitation.

The Intersection of Encryption and AI

Bruce Schneier reflects on his 2010 article warning about the limitations of cryptography in securing modern networks against various threats. He reiterates his long-standing argument that cryptography is ill-equipped to solve prevalent network security issues such as denial-of-service attacks, data theft, and network penetration.

Microsoft Threatening Security Researcher

A security researcher known as 'Nightmare Eclipse' has published details of significant Windows exploits, including one that bypasses BitLocker encryption. Microsoft has responded by threatening legal action against the researcher, leading to a public exchange of recriminations.

Meta AI Hands Over High-Profile Instagram Accounts to Hackers

Hackers exploited a confused deputy vulnerability in Meta's AI chatbot to gain control of high-profile Instagram accounts. By requesting the AI to link an account to a new email address, the attackers were able to gain unauthorized access.

Northern Ireland cops issue PSA after official phone number spoofed by scammers

Police in Northern Ireland have issued a public service announcement (PSA) after their official phone number was spoofed by scammers. The fraudsters were reportedly asking victims to purchase gift cards as part of their fraudulent scheme. Authorities are urging the public to be vigilant against such tactics.

Attack targeting OpenAI Codex users exposes AI software supply chain risks

A malicious npm package named codexui-android, disguised as a remote UI for OpenAI Codex, has been found to exfiltrate developer authentication tokens. Attackers allegedly injected malicious code into the published package that was not present in its public GitHub repository, highlighting risks in the AI software supply chain.

Supply Chain Attack Hits 32 Red Hat NPM Packages

A supply chain attack has compromised 32 Red Hat npm packages, with attackers publishing 96 malicious package versions. These versions contained a credential-stealing worm, reportedly similar to Mini Shai-Hulud.

Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT

A spear-phishing campaign, attributed to the Pakistan-aligned SideCopy group, has targeted Afghanistan's Ministry of Finance. The attackers used a ZIP archive containing a malicious LNK file with a Pashto-language filename to deliver the Xeno RAT, an open-source remote access trojan.

Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

Dashlane experienced a brute-force attack where attackers attempted to access user accounts. The company's security systems automatically locked accounts to prevent further unauthorized access and limited the number of encrypted vault downloads that could be initiated.

New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)

A new wave of phishing emails is using SVG files as attachments to deliver malicious content. Threat actors are leveraging the SVG format to embed harmful code, bypassing traditional email filters by presenting the content as an image without any URLs in the email body.

Pointing a Cursor at evading detection

AI is accelerating the development and testing of tools, but human oversight remains critical in driving the workflow. This advancement impacts areas like Endpoint Detection and Response (EDR) systems.

Red Hat npm packages compromised to steal developer credentials

A supply-chain attack compromised over 30 npm packages within Red Hat's '@redhat-cloud-services' namespace. The attackers distributed a new variant of the Shai-Hulud malware, named "Miasma," designed to steal developer credentials.

Spain arrests doxer leaking sensitive data of govt employees

Spanish police have arrested an individual accused of leaking sensitive data belonging to government employees from several important state organizations. Among the affected entities was the National Cybersecurity Institute (INCIBE). The investigation is ongoing to determine the full extent of the data leak and identify any accomplices.

Election interlopers register 5K+ domains, hope to catch some voting phish

Malicious actors have registered over 5,000 new domains in an effort to impersonate election-related entities and conduct phishing attacks. These domains are designed to mimic legitimate election websites and organizations, aiming to trick voters into revealing personal information. This tactic highlights the shift from direct election system attacks to social engineering methods.

Microsoft's Zero-Day Legal Threats Spark Backlash

Microsoft has threatened legal action against a security researcher who published several zero-day exploits, sparking backlash from the cybersecurity community. Critics argue that Microsoft's stance discourages responsible disclosure and could hinder vulnerability research.

Dashlane password manager users locked out by brute force attacks

Dashlane password manager is investigating reports of users being locked out of their accounts due to brute-force attacks. These attacks appear to originate from unknown locations and devices, with attackers attempting multiple login attempts. Dashlane is working to address the issue and has stated that no user data has been compromised.

Oracle’s first monthly patch release fixes 35 flaws, including 11 rated ‘critical’

Oracle has released its first monthly Critical Security Patch Update (CSPU) for May 2026, addressing 35 vulnerabilities, including 11 rated as critical. Among these are several flaws with publicly available exploit code, some of which have been known for a considerable time, highlighting ongoing challenges with patching embedded open-source components.

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

Hackers exploited Meta's AI support bot to gain unauthorized access to Instagram accounts, including those of the Obama White House and the U.S. Space Force Chief Master Sergeant. Instructions circulating on Telegram guided users on how to trick the AI into resetting account passwords, leading to the brief defacement of these accounts with pro-Iranian content.

WordPress malware campaign hides payloads in Steam profiles

A sophisticated WordPress malware campaign has been discovered that uses Steam Community profile comments to hide its command-and-control (C2) infrastructure. Attackers are exploiting WordPress sites to inject malicious code, which then communicates with C2 servers disguised within user comments on Steam profiles, making detection more challenging.

Vulnerability Disclosure in the Age of AI

A new article by Melissa Hathaway argues that AI is dramatically accelerating vulnerability discovery, exposing decades of software development prioritizing speed over security. It calls for a coordinated national and international effort involving governments, vendors, and operators to accelerate remediation and invest in automated repair before adversaries exploit this opportunity.

Microsoft investigates Office Apps, Teams file access issues

Microsoft is investigating an ongoing incident that is preventing users of Microsoft Teams and Office for the web from accessing and opening files. The issue appears to be related to issues with accessing files from SharePoint and OneDrive, impacting users across various platforms and devices.

Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit

Palo Alto Networks is urging users to patch a critical authentication bypass vulnerability in its PAN-OS GlobalProtect VPN, which is being actively exploited in the wild. Adversaries have already launched two waves of attacks leveraging this flaw, highlighting the urgency for defenders to apply the necessary security updates.

Race Against Time: Why Faster Vulnerability Alerts Matter

Attackers are increasingly exploiting vulnerabilities before organizations can identify and patch them. Faster vulnerability alerts are crucial for reducing exposure and improving security response times.

Critical Windows Netlogon RCE flaw now exploited in attacks

The Centre for Cybersecurity Belgium has issued a warning that threat actors are actively exploiting a critical Windows Netlogon Remote Code Execution (RCE) vulnerability in ongoing attacks. This vulnerability was recently patched, highlighting the ongoing threat posed by unaddressed security flaws.

Palo Alto VPN bug graduates from advisory to active exploitation

Attackers are actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks' PAN-OS software. This flaw allows unauthorized access to VPNs, necessitating urgent patching for affected users and organizations.