2026-06-05
Ars Technica Security
How a USB-connected speaker can infect a PC without ever being touched
Dark Reading
Exposed Fuel Tank Gauges Under Attack in the US
Amazon Security
Building secure B2C applications with fine-grained access control using Amazon Cognito and Amazon Verified Permissions
Microsoft Security
Securing CI/CD in an agentic world: Claude Code Github action case
Include Security
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy
Searchlight Cyber
Preemptive Threat Exposure Management in the Age of AI
Schneier on Security
AI Worm
Bishop Fox Security
Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis
MIT Technology Review
The Download: AI hacking beyond Mythos, and chatbots’ impact on our brains
MIT Technology Review
The Meta hack shows there’s more to AI security than Mythos
MIT Technology Review
Are AI chatbots making us lose control of our brains?
Malwarebytes
AI: Threat, tool, or both?
ISC SANS
ISC Stormcast For Friday, June 5th, 2026 https://isc.sans.edu/podcastdetail/9960, (Fri, Jun 5th)
2026-06-04
Dark Reading
Rust-Written IronWorm Hits NPM Supply Chain
Dark Reading
China's TA4922 Expands Cybercrime Attacks Globally
Ars Technica Security
Dashlane explains how attackers managed to download encrypted password vaults
Microsoft Security
Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us
Talos Intelligence
Reporting from Vegas: Networking, AI, and good boys
Black Lantern Security
CVE-2026-10880 - Osnexus Quantastor 9.8 Unauthenticated SQL Injection
Searchlight Cyber
Unknown assets explained with Asset Attribution Visualization
Searchlight Cyber
Introducing the AI Thread Assistant
Cloudflare
VoidZero is joining Cloudflare
MIT Technology Review
The Download: AI-generated lawsuits and virtual power plants for data centers
Talos Intelligence
Winning the cyber marathon with Tony Giandomenico
Talos Intelligence
Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting
Schneier on Security
Hacking Meta’s AI Chatbot
MIT Technology Review
How courts are coping with a flood of AI-generated lawsuits
Escape DAST
Introducing Cascade: the multi-agent penetration testing that becomes an expert in your business
clearbluejar's Blog
System Over Model, Tested: Reproducing Mythos's FreeBSD Find on Local Open-Weight Models
TrustedSec
The Privileged Roles Nobody Talks About
ISC SANS
ISC Stormcast For Thursday, June 4th, 2026 https://isc.sans.edu/podcastdetail/9958, (Thu, Jun 4th)
Teleport Blog
How to Make Trading Infrastructure Audit-Ready Across SSH, Kubernetes, Databases, and RDP
Greynoise
4 Ways GreyNoise Improves SOC Outcomes
Datadog HQ
Introducing Bits Agent Builder: Build agentic workflows for alert response and remediation
Sansec Threat Research
Magecart skimmer turns Stripe into a malware command server
2026-06-03
Dark Reading
Attackers Use AI to Automate EDR Evasion Testing
Ars Technica Security
Can't make sense of Dashlane's vault theft notification? You're not alone.
Cloudflare
Enforcing the First AS in BGP AS_PATHs
MIT Technology Review
How virtual power plants could provide energy for data centers
Artem Golubin
NULLs in ClickHouse can hurt performance
Bishop Fox Security
Otto Support - Testing MCP Servers
MIT Technology Review
The Download: Trump’s new AI order, and smart glasses for warfare
Black Hills Info Sec
Auditing GitLab: The CI/CD Kill Chain
Schneier on Security
AI Used to Decrypt Medieval Ciphers
Trail of Bits
The sorry state of skill distribution
Searchlight Cyber
June 3rd – This Week’s Top Cybersecurity and Dark Web Stories
Malwarebytes
Infostealers are becoming the go-to phishing payload
Microsoft Security
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign
ISC SANS
ISC Stormcast For Wednesday, June 3rd, 2026 https://isc.sans.edu/podcastdetail/9956, (Wed, Jun 3rd)
Conduition
Brink is Now Funding My Research
2026-06-02
Dark Reading
FBI-Flagged Phishing Kit Kali365 Expands Its Reach
Dark Reading
China Uses Dual-Method Cyberattack on Czech Orgs
Step Security
Nx Console VS Code Extension Compromised
Step Security
Multiple redhat-cloud-services npm Packages compromised
Step Security
Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets
Microsoft Security
Microsoft Build 2026: Securing code, agents, and models across the development lifecycle
Eye Security Research
Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild
MIT Technology Review
The Download: AI can run your admin department now
MIT Technology Review
Rehumanizing global health care with agentic AI
Schneier on Security
The Intersection of Encryption and AI
Schneier on Security
Microsoft Threatening Security Researcher
Reversemode
Did Israel Present a Video of Fast16 in Action?
Malwarebytes
Fake virus alerts are invading mobile games
MIT Technology Review
How small businesses can leverage AI
ISC SANS
ISC Stormcast For Tuesday, June 2nd, 2026 https://isc.sans.edu/podcastdetail/9954, (Tue, Jun 2nd)
Snyk
Protestware by open source maintainer to hinder agentic coding: The jqwik 1.10.0 Prompt Injection
Elastic Security Labs
From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligence
Sansec Threat Research
GorgonAgora: 4,800+ fake storefronts skim cards across hundreds of impersonated brands
2026-06-01
Dark Reading
Anthropic to Open Mythos AI to EU's ENISA
Ars Technica Security
Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts
Ars Technica Security
Dozens of Red Hat packages backdoored through its official NPM channel
The Citizen Lab
Chilling Effects of Trump’s War on Free Speech Extend Far Beyond Campus Walls – And That’s the Point
Dark Reading
Microsoft's Zero-Day Legal Threats Spark Backlash
Krebs on Security
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Schneier on Security
Vulnerability Disclosure in the Age of AI
Malwarebytes
Your phone called. It needs a cleanup.
Malwarebytes
A week in security (May 25 – May 31)
Troy Hunt
Weekly Update 506
ISC SANS
ISC Stormcast For Monday, June 1st, 2026 https://isc.sans.edu/podcastdetail/9952, (Mon, Jun 1st)
GMO Flatt Security Research
Poisoning Claude Code: One GitHub Issue to Break the Supply Chain
Flatt Security Research
Poisoning Claude Code: One GitHub Issue to Break the Supply Chain
Rosecurify
Seclog - #180
Sansec Threat Research
Sansec adds support for Sylius 1 & 2
2026-05-31
2026-05-30
Microsoft Security
Malicious npm packages abuse dependency confusion to profile developer environments