Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit
Ukrainian National Pleads Guilty to Wire Fraud Conspiracy in Connection with Conti Ransomware
Malware
IronWorm: Shai-Hulud’s rustier cousin
Using AI Agents to Analyze Malware on REMnux
The Miasma worm’s path of destruction
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Inside-Onyxc2-The-New-Stealer-Targeting-210-Apps
Hacking
Attackers Actively Exploiting Critical Vulnerability in Everest Forms Pro Plugin
How a USB-connected speaker can infect a PC without ever being touched
Reproducing CVE-2026-23111: How one character can change everything
Off By !: Exploiting a Use-after-Free in the Linux Kernel
The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds
Google patches new Chrome zero-day flaw exploited in the wild
Will AI Kill the Bug Bounty Industry?
Nightmare Eclipse – RoguePlanet
GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan
Max severity Ivanti Sentry vulnerability now exploited in attacks
Intelligence and Information Warfare
VerdantBamboo: Just Another BRICKSTORM in the Firewall
Hackers pose as women seeking romance to spy on Russian soldiers
Russia upgrades rules for its digital spy system to better track citizens online
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open
Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation
Hackers pose as women seeking romance to spy on Russian soldiers
OceanLotus: From external espionage to domestic targeting
Cyber Intel Brief: Handala Claims Breach of California Water Service
Cybersecurity
ESET APT Activity Report Q4 2025–Q1 2026
AI tools becoming hot commodities on ransomware marketplaces
Meta Deletes Face-Recognition System From Its Smart Glasses App After WIRED Report
Fighting Spyware: An Update From WhatsApp
The June 2026 Security Update Review
Nearly 22,000 Live Cameras With No Login Required: A Mysterium VPN Research
He Blew the Whistle on DOGE. Then His Brakes Were Cut
Anthropic to disable its most advanced AI models after US order limiting foreign access
Statement on the US government directive to suspend access to Fable 5 and Mythos 5
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)