Breaking News – Cyber Threats (last 6h)
Generated: 2026-06-10 17:00 PDT
- Smashing Security podcast #471: This AI worm just rewrote its own rules
Graham Cluley • 2026-06-10 16:15 • grahamcluley.com
Researchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host its own AI brain. And then the researchers discovered their creation had quietly removed the list of machines it wasn’t supposed to attack.Meanwhile, Meta’s shiny new AI customer support agent has been cheerfully helping hackers help themselves to other people’s Instagram accounts. Just keep asking, politely but firmly, to have a password reset sent to a different email ad…
https://grahamcluley.com/smashing-security-podcast-471/ - Path traversal flaw in AI dev platform Langflow exploited in attacks
BleepingComputer • 2026-06-10 14:23 • www.bleepingcomputer.com
Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in the AI development platform Langflow, to write arbitrary files on exposed servers. […]
https://www.bleepingcomputer.com/news/security/path-traversal-flaw-in-ai-dev-platform-langflow-exploited-in-attacks/ - The ‘Miasma’ worm source code briefly leaked on GitHub
BleepingComputer • 2026-06-10 13:27 • www.bleepingcomputer.com
The Miasma credential-stealing attack framework, which has recently targeted open-source ecosystems through supply-chain attacks, was briefly open-sourced on GitHub. […]
https://www.bleepingcomputer.com/news/security/the-miasma-worm-source-code-briefly-leaked-on-github/ - GitHub announces npm security changes to tackle supply-chain attacks
BleepingComputer • 2026-06-10 12:41 • www.bleepingcomputer.com
GitHub has announced that npm v12, expected next month, will introduce several security-focused changes aimed at blocking supply-chain attacks abusing behaviors triggered by the ‘npm install’ command. […]
https://www.bleepingcomputer.com/news/security/github-announces-npm-security-changes-to-tackle-supply-chain-attacks/ - Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
BleepingComputer • 2026-06-10 11:31 • www.bleepingcomputer.com
Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations. […]
https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
