A federal court has ruled that an executive order issued by former President Trump, which aimed to create federal voter lists for each state and limit mail-in ballots through the USPS, is unconstitutional. The court's decision effectively nullifies the provisions of the order, impacting how states manage voter registration and mail-in voting processes. This ruling is significant as it addresses the ongoing debate over election integrity and access, particularly in light of concerns raised about voter suppression. The decision may influence future legislation and executive actions related to elections, as it sets a precedent for the limits of federal authority in state election matters.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
BleepingComputer
Law enforcement agencies have taken significant action against the PirloTV sports piracy network, seizing 44 domains associated with the illegal streaming platform. This crackdown aims to disrupt the distribution of unauthorized sports content, which affects both the rights holders of the broadcasts and legitimate viewers. PirloTV has been known for providing free access to premium sports events without proper licensing, leading to financial losses for broadcasters and sports leagues. The seizure of these domains is a part of ongoing efforts to combat online piracy and protect intellectual property rights. This incident serves as a reminder of the legal risks associated with using unlicensed streaming services, as users may also face repercussions.
Mistic is a new backdoor being used by a group linked to KongTuke, aimed at maintaining long-term access to networks targeted by ransomware attacks. Security researchers from Symantec have identified Mistic in attacks primarily directed at sectors like insurance, education, IT, and professional services. This backdoor allows attackers to operate quietly over an extended period, making it a serious concern for organizations in these industries. The stealthy nature of Mistic means that it can evade detection while enabling further exploitation of compromised systems. Companies should be vigilant and enhance their security measures to prevent such intrusions.
A significant security vulnerability in Cisco's Catalyst SD-WAN Manager has been exploited by attackers months before its public disclosure. The flaw, which was revealed in early June, was reportedly being used in attacks as early as March. This situation raises serious concerns for organizations using Cisco's SD-WAN technology, as they may have been at risk for an extended period without knowledge of the threat. Companies are urged to review their systems and apply any available patches to mitigate potential risks. The exploitation of this vulnerability highlights the importance of timely disclosures and the need for vigilance in monitoring systems for suspicious activity.
Australia's Security and Intelligence Organisation (ASIO) has created specialized teams to address cyber sabotage threats from nation-states targeting the country's critical infrastructure. This move, announced by ASIO Director-General Mike Burgess, reflects increasing concerns about foreign interference and cyber attacks aimed at essential services and systems. By focusing resources on these dedicated units, ASIO aims to enhance its capabilities in detecting and mitigating potential cyber incidents that could disrupt public safety and national security. This development is particularly important as nations globally face rising cyber threats, making it crucial for Australia to strengthen its defenses against such risks.
SCM feed for Latest
A new website, whynopasskeys.com, has been launched to call attention to the fact that many major apps and services have not yet adopted passkey authentication, a more secure method for logging in. Research shows that around 25% of popular platforms, including Instagram, Netflix, and Spotify, are still relying on traditional password systems. This is concerning because passwords can be vulnerable to theft and hacking. By shaming these companies, the site aims to encourage them to upgrade their security measures. The lack of passkey implementation puts users at risk of account breaches, emphasizing the need for better security practices in the tech industry.
Account takeover attacks remain a significant challenge for organizations as attackers often exploit legitimate accounts and trusted services to gain unauthorized access. This issue complicates detection and response efforts for security teams. A recent webinar discussed how behavioral AI can enhance the identification of compromised accounts, enabling quicker responses to these incidents. The focus is on using advanced technology to automate workflows that can mitigate the risks associated with account takeovers. As these attacks can lead to severe data breaches and financial losses, understanding and addressing them is crucial for businesses and their customers.
Cal Water, a utility in California, recently investigated a cyberattack attributed to the Iranian hacker group Handala. Despite the hackers claiming they could disrupt the water supply, Mandiant, the cybersecurity firm assisting in the investigation, found no evidence of any operational technology (OT) activity being compromised. This incident raises concerns about the security of critical infrastructure, especially given the attackers' bold claims. While the immediate threat appears to be contained, it serves as a reminder for utilities and other essential services to remain vigilant against potential cyber threats. Ensuring the integrity of water supplies is crucial for public safety and trust.
On June 22, 2026, the NSA, along with its Five Eyes partners, issued a critical warning about the rapidly evolving nature of cyber threats. They noted that the timeline for potential cyberattacks has significantly shortened, going from years to just months. This shift poses a serious risk to national security and the integrity of critical infrastructure. The agencies emphasized the need for organizations to enhance their cybersecurity measures and preparedness to counter these fast-evolving threats. As cybercriminals become more sophisticated, timely detection and response will be essential for all sectors, especially government and private industries.
Hackread – Cybersecurity News, Data Breaches, AI and More
A suspected cyberattack in Brazil has led to a fake emergency alert being sent to mobile phones across the country. In response to this incident, officials have taken the national alert system offline while they investigate the breach. The alert, which falsely warned of an emergency, has raised concerns about the security of communication systems and the potential for panic among the public. This incident highlights vulnerabilities in emergency notification systems and the importance of robust cybersecurity measures to protect against such attacks. Authorities are currently examining how the breach occurred and what can be done to prevent future incidents.
Schneier on Security
Recent research has explored how large language models (LLMs) are vulnerable to prompt injection attacks. The study reveals that LLMs don't just respond to role tags but also learn to recognize the style of text in different instruction blocks. This means that attackers could manipulate LLMs by using innocuous-seeming text to subtly influence their responses. The researchers argue that without a true understanding of roles, defenses against prompt injection will be an ongoing challenge. This is significant because it exposes a fundamental weakness in LLMs that could lead to misuse in various applications, affecting users and developers alike.
Richard Bejtlich discusses the challenges that security operations teams face when investigating incidents, despite having access to a wealth of telemetry data. Many teams struggle to answer fundamental questions about what happened, what evidence they have, and whether they're seeing the complete picture. Bejtlich emphasizes the need for teams to move beyond just relying on alerts for initial triage and to adopt a more thorough investigative approach. This shift is crucial for improving incident response and ensuring that security teams can effectively protect their organizations from potential threats.
A recently discovered flaw in macOS allows standard users to disable Endpoint Detection and Response (EDR) and Mobile Device Management (MDM) features, which are critical for maintaining device security and management. This vulnerability could be exploited by malicious actors to weaken security controls, making it easier for them to execute attacks or gain unauthorized access to sensitive data. All macOS versions that support EDR and MDM functionalities are affected. Organizations using these features should be particularly vigilant, as the ability for unauthorized users to disable such protections can lead to significant security risks. As of now, there is no indication that this vulnerability is being actively exploited in the wild, but the potential for misuse remains a concern for IT departments.
Infosecurity Magazine
A new report from Black Kite reveals a significant spike in ransomware attacks across Europe, with incidents rising by more than 50% over the past year. The analysis also highlights a troubling increase in supply chain attacks, which can compromise multiple organizations through a single vulnerability. This surge in ransomware poses a serious risk to businesses, governments, and critical infrastructure, leading to potential data loss and financial damage. Companies need to be vigilant and strengthen their cybersecurity measures to protect against these escalating threats. The findings serve as a stark reminder of the ongoing challenges in cybersecurity and the need for proactive defenses.
Kaspersky researchers have examined the growing cybersecurity threats facing small and medium-sized businesses (SMBs) in 2026. They found that attacks using fake artificial intelligence tools are on the rise, alongside traditional phishing schemes. These tactics are particularly concerning as they can lead to data breaches and the sale of sensitive information on the dark web. SMBs, which often lack the resources of larger corporations, are especially vulnerable to these types of attacks. Companies need to enhance their security measures and educate employees about recognizing scams to protect themselves against these evolving threats.