Threat Intelligence Weekly

Неделя 22 · 03 June 2026 · malikai.org
158
Собрано историй
51
Критических
22
Высоких
13
CVE обнаружено
13
Источников
Executive Summary
На этой неделе доминировала эксплуатация zero-day уязвимостей в Palo Alto GlobalProtect (CVE-2026-0257) и Windows Netlogon (CVE-2026-41089) — обе активно атакуются в реальных кампаниях. AI-атаки достигли нового рубежа: первый zero-day, разработанный LLM, обходит 2FA. В supply chain — массовые компрометации npm, GitHub Actions и VS Code extension’ов. В финансовом секторе РФ — расширение пилота цифрового рубля и новые антифрод-требования к банкам.
#ZeroDay#AI Threats#SupplyChain#Финансы#Регуляторы
🛡️ Угрозы и уязвимости 10
#1 · 2 ист. WCS 3.3 Приоритет 1 CRITICAL Security Affairs The Hacker News
CVE-2025-48595
Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active
#2 · 2 ист. WCS 3.3 Приоритет 2 CRITICAL Security Affairs The Hacker News
CVE-2024-21182
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of a
#6 · 1 ист. WCS 1.4 Приоритет 6 HIGH BleepingComputer
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system. [...]
#8 · 1 ист. WCS 1.4 Приоритет 8 CRITICAL BleepingComputer
Acer is working to address two maximum-severity zero-day vulnerabilities affecting its Wave 7 mesh routers. [...]
#9 · 1 ист. WCS 1.4 Приоритет 9 CRITICAL BleepingComputer
European and international law enforcement agencies have dismantled nine organized crime groups and arrested 29 suspects in a major crackdown on illegal streaming operations. [...]
#11 · 1 ист. WCS 1.4 Приоритет 11 CRITICAL BleepingComputer
A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link. [...]
#12 · 1 ист. WCS 1.4 Приоритет 12 MEDIUM BleepingComputer
Microsoft announced today at its Build 2026 developer conference the release of Coreutils for Windows, bringing many commonly used Linux command-line utilities to Windows as native applications. [...]
#14 · 1 ист. WCS 1.4 Приоритет 14 CRITICAL BleepingComputer
CVE-2026-8206
Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators. [...]
#19 · 1 ист. WCS 1.4 Приоритет 19 CRITICAL BleepingComputer
CISA has ordered government agencies to secure their systems against a high-severity Oracle WebLogic Server vulnerability that was patched two years ago and is now actively exploited in attacks. [...]
#20 · 1 ист. WCS 1.4 Приоритет 20 MEDIUM The Hacker News
Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user's GitHub token. "Just by clicking a link, it's possible for an attacker to st
🤖 AI угрозы 10
#3 · 2 ист. WCS 3.1 Приоритет 3 MEDIUM BleepingComputer HelpNetSecurity
A Malware-as-a-Service (MaaS) operation named WeedHack is targeting Minecraft users and allows threat actors to gain remote access to victims’ screens, webcams, and files through a web-based dashboard, McAfee researchers
#10 · 1 ист. WCS 1.4 Приоритет 10 MEDIUM BleepingComputer
Google is introducing a new Android security feature that will detect and flag phone calls in which scammers use artificial intelligence to impersonate a user's personal contacts. [...]
#13 · 1 ист. WCS 1.4 Приоритет 13 MEDIUM BleepingComputer
OpenAI says it's rolling out a new update that improves the existing GPT-5.5 Instant model, and this move comes ahead of the scheduled retirement of multiple legacy models, including o3. [...]
#15 · 1 ист. WCS 1.4 Приоритет 15 HIGH BleepingComputer
A threat actor is using an AI-built ransomware attack toolkit that automates Active Directory discovery and helps evade endpoint detection and response (EDR) solutions. [...]
#16 · 1 ист. WCS 1.4 Приоритет 16 MEDIUM BleepingComputer
Microsoft is working to address a widespread service issue affecting the mail flow pipeline for Exchange Online customers across North America and Germany. [...]
#17 · 1 ист. WCS 1.4 Приоритет 17 MEDIUM BleepingComputer
Multiple Instagram users had their accounts hijacked after attackers convinced Meta's AI-powered support tools that they were the legitimate owners. [...]
#18 · 1 ист. WCS 1.4 Приоритет 18 CRITICAL BleepingComputer
AI-powered attacks and shadow AI adoption are creating new security risks inside the browser. Push Security explains why browser visibility is becoming critical for both threat detection and AI governance. [...]
#25 · 1 ист. WCS 1.4 Приоритет 25 MEDIUM The Hacker News
Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gaining control of victims' systems. The Minecraft-focused malware-as-a-service (MaaS) campaign
💳 Финмошенничество 1
#7 · 1 ист. WCS 1.4 Приоритет 7 HIGH BleepingComputer
A two-week penetration test can leave roughly 345 days of real-world exposure unvalidated. Sprocket Security explores why continuous testing is becoming critical as attack surfaces constantly change. [...]
⚖️ Регуляторы и политика 1
#36 · 1 ист. WCS 1.4 Приоритет 36 CRITICAL The Hacker News
Threat actors are attempting to actively exploit a critical security flaw impacting WP Maps Pro, a WordPress plugin that has had over 15,000 sales on the Envato Market, to create malicious administrator accounts on susce
— Джейсон Стетхэм
TI Weekly · auto-generated · 2026-06-03