Clear Infosec weekly Threat Intelligence Bulletin for June 24, 2026. Curated cyber security news, threats, and guidance with links to the original sources.
Cyber Security News
- Maine forced to take down data breach portal after fake notices filed with authorities The US state of Maine has taken its public data breach notification portal offline after someone submitted fraudulent breach disclosures impersonating two well-…
- Copilot SearchLeak Attack Allows 1-Click Data Theft The critical, three-stage attack is now patched, but it’s part of a new group of AI prompt-injection issues that use hidden URLs and other variables…
- INC Ransomware Thrives by Mastering the Basics And one of those basics is focusing on sectors where a ransomware disruption creates immediate pressure to pay up, like with healthcare…
- Scope of Salesforce Attacks Expands as Icarus Leaks Data More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers’ Salesforce data…
- Hacker hijacks Brazil’s national alert system sending “misanthropy” to millions of phones Emergency alert systems work because people believe them. Every time one of these systems issues a false alert – whether through negligence or a deliberate atta…
Best Practices
- What are the cyber threats to the 2026 Fifa World Cup? Dig deeper on some of the security issues facing the 2026 World Cup as the tournament faces unprecedented threat levels and challenges…
- Attackers abuse Google Ads GitLab and Claude to deliver malware Threat actors are abusing trusted platforms, including Google Ads, GitLab pages, and Claude’s shared chat feature, to trick users into ex…
- FortiBleed campaign exposes 75000 Fortinet firewalls worldwide A massive credential-compromise campaign dubbed “Fortibleed” has been found to expose tens of thousands of Fortinet devices worldwide, wi…
- UK government and Cisco unveil AI digital skills initiative Networking giant and UK Department for Science, Innovation and Technology announce strategic collaboration to help increase AI adoption and widen access to digi…
- AI is exposing the biggest weakness in cybersecurity: We never built a health model Until now! For 30 years, cybersecurity has operated like an emergency room. Reactive. Crisis-driven. Always triaging. We are extraordinarily good…
New Threats and Vulnerabilities
- China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. “The Win…
- LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian…
- One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails Files and MFA Codes A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise S…
- Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider Summary The Cybersecurity and Infrastructure Security Agency (CISA) is releasing this advisory in response to ransomware actors leveraging unpatched instances o…
- Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations Summary The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint advisory to dissemina…
Patch Management
- AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. S…
- Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account se…
- Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild. The vul…
- Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive rese…
- CISA Adds Cisco Chrome and Arista Flaws to KEV Catalog Amid Active Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog…
AI and Security
- Anthropic recruits army to sell Claude to nonprofits AI may or may not be pushing lots of people out of the workforce, but Anthropic has good news as the Claude creator is creating temporary positions to promote…
- Inside the clouds new agentic AI-ready Arm-powered foundation When Spotify evaluated its cloud compute options, it needed more than incremental improvements. Its recommendation engine delivers real-time suggestions to mil…