
Microsoft 365 hit by 81M password-spray attacks in two weeks
Over 81 million login attempts were recorded in a two-week password-spraying campaign against Microsoft 365 environments, security researchers reported.
Incidents, vulnerabilities, abuse and certificates.

Over 81 million login attempts were recorded in a two-week password-spraying campaign against Microsoft 365 environments, security researchers reported.

A campaign targeting Python developers has been distributing malicious PyPI packages that compromise Telegram bot servers, allowing attackers to read arbitrary files since November 2025.

AWS Certificate Manager (ACM) now supports the ACME protocol for automated public TLS certificate issuance, enabling centralized management, policy enforcement, and auditability across organizations.

The World Wide Web Consortium has released a draft policy outlining how security researchers can report suspected vulnerabilities in its standards and specifications, aiming to streamline triage and resolution through formal W3C processes.

A security researcher found that India’s .bank.in registry, operated by IDRBT, exposed bcrypt password hashes, contact details, and login metadata of 5,576 bank employees via unauthenticated API endpoints for over a year. The flaw was fixed after disclosure in early June 2026.

Attackers compromised an npm maintainer account to publish malicious updates to over 20 packages in the Leo Platform and RStreams ecosystems, stealing cloud credentials, GitHub tokens, and other secrets while evading two-factor authentication.

ASIO Director General Mike Burgess disclosed that state-sponsored hackers had compromised an Australian critical infrastructure provider, acquiring credentials and mapping networks to cripple systems at a strategic moment. The agency is expanding dedicated teams and AI tools to counter evolving threats, including espionage linked to the AUKUS defense pact.

CISA has added four critical vulnerabilities in Ubiquiti UniFi OS and Lantronix EDS5000 serial-to-Ethernet servers to its Known Exploited Vulnerabilities catalog, citing active exploitation. Federal agencies must apply patches or mitigations by 27 June 2026.

Security researchers have identified Mistic, a stealthy backdoor malware attributed to the KongTuke initial access broker, which sells network access to ransomware groups. The malware, active since April 2026, enables long-term persistence and in-memory payload execution, evading traditional detection methods.

A nationwide outage in Deutsche Bahn's GSM-R wireless network forced the German rail operator to cancel all train services for over two hours, stranding passengers and exposing vulnerabilities in legacy critical infrastructure.

A server-side request forgery vulnerability (CVE-2026-20230) in Cisco Unified CM and Unified CM SME is under active exploitation, allowing unauthenticated attackers to write files and escalate privileges to root. Cisco released patches on June 3, but reconnaissance activity has since been detected.

Xsolis, a U.S.-based healthtech company, disclosed a data breach affecting 1.39 million people after attackers gained network access through a targeted phishing attack on January 20, 2026. The exposed data includes names, addresses, Social Security numbers, and medical treatment details. The company has implemented additional security measures and is offering identity monitoring to affected individuals.

A June 2026 executive order establishes a 2030 deadline for U.S. government entities and contractors to migrate to post-quantum cryptographic standards, with Cloudflare releasing guidance for implementation.

Thalha Jubair and Owen Flowers pleaded guilty to breaching Transport for London's systems in August-September 2024, disrupting refund services and exposing customer data. The attack forced password resets for 28,000 employees and incurred £29m in losses.

Polymarket registered Poiymarket.com to help influencers produce videos of fake bets, according to a Wall Street Journal investigation. The scheme involved college student George Makihara, who appeared to win $410,000 across 145 staged wagers between January and May 2026.

Researchers at Qianxin's XLab identified the AryStinger botnet, which exploits known vulnerabilities in D-Link routers to enable distributed scanning, DNS tampering, and traffic monitoring. Nearly half of infections are in South Korea, with significant activity in China and Europe.

Attackers are exploiting an unauthenticated information disclosure flaw (CVE-2026-4020) in the Gravity SMTP WordPress plugin, allowing access to API keys, email credentials, and server details. Over 17 million exploit attempts have been blocked since early June 2026.

Security professionals will discuss emerging phishing tactics like Device Code phishing, which bypass traditional MFA by abusing legitimate Microsoft authentication processes, and how behavioral AI can detect such attacks earlier.

CISA has mandated federal agencies to patch a critical Splunk Enterprise vulnerability (CVE-2026-20253) by 21 June 2026, following evidence of in-the-wild attacks. The flaw allows unauthenticated file operations via a PostgreSQL sidecar endpoint.

A 21-year-old New York man faces cyberstalking charges after allegedly using AI-generated nude images and fake social media profiles to harass a former college classmate across multiple platforms between January and March 2025.