Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    ZDI-26-328: ASUS Business Manager Service Client-Side Authentication Local Privilege Escalation Vulnerability

    June 4, 2026

    Software supply chain attacks: check your dependencies

    June 4, 2026

    CVE-2026-41237 | THREATINT

    June 4, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Infosec News Nuggets — June 4, 2026 – AboutDFIR
    News

    Infosec News Nuggets — June 4, 2026 – AboutDFIR

    adminBy adminJune 4, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    The Worst Hacks and Breaches of 2026 (So Far)

    Halfway through what’s shaping up to be a brutal year for cybersecurity, a comprehensive roundup catalogs the most damaging digital incidents of 2026, including DOGE’s alleged upload of a live Social Security database to an unsecured server, Iranian state-backed hackers remotely wiping tens of thousands of Stryker employee devices in a destructive pivot from espionage, the ShinyHunters gang breaching education platform Instructure Canvas and disrupting finals for millions of students, the FBI declaring a “major cyber incident” after Chinese spies compromised a surveillance system exposing wiretap targets’ phone numbers, and a wave of supply chain attacks hitting security tools including Bitwarden and Checkmarx that cascaded into breaches at OpenAI and Vercel.

     

    Recent Palo Alto Networks Vulnerability Exploited for Weeks

    Threat actors began actively exploiting CVE-2026-0257, a high-severity authentication bypass in PAN-OS GlobalProtect, just four days after public disclosure, with Rapid7 observing exploitation campaigns starting May 17 from two successive hosting providers. The flaw allows attackers to forge cookies to bypass VPN authentication on vulnerable firewalls, and in eight out of ten observed cases the forged cookies were accepted by target systems. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by June 1; Palo Alto has released fixes for PAN-OS versions 10.2 through 12.1.

     

    2026 Data Breach Investigations Report

    This year’s annual DBIR marks a historic shift in the threat landscape: software vulnerability exploitation has surpassed stolen credentials as the leading initial access vector for the first time in the report’s 19-year history, now accounting for 31% of breaches. Ransomware is present in nearly half of all incidents, though ransom payouts are declining as more organizations refuse to pay. Generative AI is now boosting 15 different attack techniques, compressing exploitation timelines dramatically, while mobile devices have become a preferred target with phishing click rates 40% higher on phones than on traditional email.

     

    New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

    Researchers have disclosed a remote denial-of-service technique dubbed HTTP/2 Bomb that chains HTTP/2’s HPACK header compression with a zero-byte flow-control window to pin server memory indefinitely — a single client on a 100Mbps home connection can exhaust 32GB of Apache or Envoy server memory in roughly 20 seconds. The attack was discovered by OpenAI Codex and affects default configurations of NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. NGINX has patched the issue in version 1.29.8 and Apache has a fix in mod_http2 v2.0.41, but Microsoft IIS, Envoy, and Cloudflare Pingora have no patches available at time of writing.

     

    Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

    Pro-Iran hackers briefly defaced high-profile Instagram accounts — including the Obama White House account — by exploiting a flaw in Meta’s AI customer support chatbot that allowed attackers to add a new email address to any account during a password reset flow, effectively bypassing standard authentication. A Telegram-circulated video showed the attack required only a VPN connection near the target’s location and a brief conversation with the AI bot, after which the bot would send a one-time code to the attacker’s newly linked address. Meta has since patched the issue and stated that no back-end database was breached, though the accounts of multiple users were compromised before the emergency fix was deployed.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCVE-2026-50266 | THREATINT
    Next Article SSA-765405 V1.0: Multiple Vulnerabilities in SIMATIC RFID Readers
    admin
    • Website

    Related Posts

    News

    Software supply chain attacks: check your dependencies

    June 4, 2026
    News

    New IronWorm malware hits 36 packages in npm supply-chain attack

    June 4, 2026
    News

    Hackers Are After the Gaps in Your Vulnerability Program: Here’s Their Playbook

    June 4, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202630 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202630 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views
    Our Picks

    ZDI-26-328: ASUS Business Manager Service Client-Side Authentication Local Privilege Escalation Vulnerability

    June 4, 2026

    Software supply chain attacks: check your dependencies

    June 4, 2026

    CVE-2026-41237 | THREATINT

    June 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.