Cyber Security Week in Review: June 19, 2026
In brief: Fortinet, Cisco and other vendors fix multiple exploited bugs, Arch Linux users targeted in a large-scale malware campaign, and more.
In brief: Fortinet, Cisco and other vendors fix multiple exploited bugs, Arch Linux users targeted in a large-scale malware campaign, and more.
The campaign promotes fake Solana and Pump.fun sniper bots and crash-game predictors via phishing websites, GitHub repositories, SourceForge projects, YouTube videos, and posts on legitimate news websites.
Attackers hijacked a legitimate npm account belonging to a former Mastra contributor and published 144 malicious package versions within 88 minutes.
The plugins, published under seven different vendor accounts, were masked as AI coding assistants, code-review tools, and Git utilities.
Backdoor.Turn is believed to be the first known malware observed in real-world attacks abusing Microsoft Teams TURN relay servers for stealthy communications.
Lytvynenko also admitted to helping develop a loader used to deploy malware.
ESET confirmed real-world activity between 2023 and 2024, targeting government organizations in Honduras, Taiwan, Thailand, and Pakistan.
Cisco has released patches for CVE-2026-20262, a zero-day vulnerability affecting Catalyst SD-WAN Manager.
GhostWriter has increasingly focused on Gmail users since March of this year.
GTIG believes the attackers first compromised the organization in September 2023 after probing outdated REDCap installations.
Showing elements 161 - 170