Daily Pulse

Stay informed with today's critical security updates

Every organisation is different. The free "Daily Pulse" feed shows the broader threat landscape.

Want this specific and tailored to your organisation?

ThreatInsights – Click for more info

The Daily Pulse is refreshed automatically every day at 9:00 AM GMT

Want to learn more about Cyber Threat Intelligence?

Check out our free online self-paced training course.

Start Learning Now
Filter by type:(20 items)
CVE

Wednesday, June 10, 2026

WHAT

Ivanti: Max severity Sentry flaw allows code execution as root

WHY IT MATTERS

Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway solution, including a maximum-severity flaw that enables remote attackers to execute code with root privileges.

WHAT TO DO

Review affected systems, apply patches immediately, monitor for exploitation attempts, and verify patch deployment across all endpoints.

CVE

Wednesday, June 10, 2026

WHAT

Blame AI: Patch Tuesday Hits Record 206 CVEs

WHY IT MATTERS

Voluminous patch updates could soon be the norm, as artificial intelligence accelerates the speed and scale of vulnerability discovery.

WHAT TO DO

Review affected systems, apply patches immediately, monitor for exploitation attempts, and verify patch deployment across all endpoints.

CVE

Wednesday, June 10, 2026

WHAT

No Patch Planned for Exploited Arista EOS Vulnerability

WHY IT MATTERS

Organizations are advised to apply vendor-supplied mitigations or discontinue the vulnerable devices. The post No Patch Planned for Exploited Arista EOS Vulnerability appeared first on SecurityWeek.

WHAT TO DO

Review affected systems, apply patches immediately, monitor for exploitation attempts, and verify patch deployment across all endpoints.

Breach

Wednesday, June 10, 2026

WHAT

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

WHY IT MATTERS

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta's "AI support assistant" bot into resetting a...

WHAT TO DO

Check if your organization uses affected services, reset credentials, monitor for phishing attempts using leaked data, and review third-party risk.

Threat

Wednesday, June 10, 2026

WHAT

Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

WHY IT MATTERS

Six Proto6 Vulnerabilities in protobuf. js Apps to RCE and DoS.

WHAT TO DO

Assess potential impact to your environment, update security controls, inform relevant stakeholders, and monitor for related activity.

Threat

Wednesday, June 10, 2026

WHAT

Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address

WHY IT MATTERS

"Ghost-Sender" uses Exchange Online or on-premises in hybrid mode with a third-party mail server or spam filter to achieve this level of spoofing.

WHAT TO DO

Assess potential impact to your environment, update security controls, inform relevant stakeholders, and monitor for related activity.

Threat

Wednesday, June 10, 2026

WHAT

SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain

WHY IT MATTERS

SHub Reaper bypasses Apple's Terminal mitigation, steals credentials and documents, and plants a persistent backdoor for continued access after infection.

WHAT TO DO

Assess potential impact to your environment, update security controls, inform relevant stakeholders, and monitor for related activity.

Threat

Wednesday, June 10, 2026

WHAT

Liquid Glass for Linux? PearOS makes another Mac move - how it looks now

WHY IT MATTERS

PearOS has been promising to become the MacOS of Linux for some time now, and the latest release just might deliver.

WHAT TO DO

Assess potential impact to your environment, update security controls, inform relevant stakeholders, and monitor for related activity.

Threat

Wednesday, June 10, 2026

WHAT

Anthropic's new Claude Fable 5 is the same base model as Mythos but with guardrails attached

WHY IT MATTERS

Claude Fable 5 brings Mythos-class AI coding power to general users, but with cybersecurity guardrails, fallback models, and pricing that could make developers think twice.

WHAT TO DO

Assess potential impact to your environment, update security controls, inform relevant stakeholders, and monitor for related activity.

CVE

Wednesday, June 10, 2026

WHAT

Adobe Patches 123 Vulnerabilities

WHY IT MATTERS

Nearly half of the security holes, most allowing arbitrary code execution, have been fixed in Adobe’s Experience Manager product. The post Adobe Patches 123 Vulnerabilities appeared first on SecurityWeek.

WHAT TO DO

Review affected systems, apply patches immediately, monitor for exploitation attempts, and verify patch deployment across all endpoints.

AI

Tuesday, June 9, 2026

WHAT

Dreaming: Better memory for a more helpful ChatGPT — ChatGPT introduces a new memory system to better remember preferences, keeping context fresh and relevant across conversations.

WHY IT MATTERS

ChatGPT introduces a new memory system to better remember preferences, keeping context fresh and relevant across conversations.

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Tuesday, June 9, 2026

WHAT

174,000 Impacted by Lansing Community College Data Breach — Hackers accessed personal information stored on certain Lansing Community College systems in February 2025. The post 174,000 Impacted by Lansing Community College Data Breach appeared first on Secu...

WHY IT MATTERS

Hackers accessed personal information stored on certain Lansing Community College systems in February 2025. The post 174,000 Impacted by Lansing Community College Data Breach appeared first on SecurityWeek. ]]>

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Tuesday, June 9, 2026

WHAT

Rust-Written IronWorm Hits NPM Supply Chain — Like Shai-Hulud, the campaign targets developers to steal credentials and reuses them to propagate across the software supply channel.

WHY IT MATTERS

Like Shai-Hulud, the campaign targets developers to steal credentials and reuses them to propagate across the software supply channel.

WHAT TO DO

Audit ML dependencies, implement package pinning with hash verification, use isolated training environments, and scan for known malicious packages.

AI

Tuesday, June 9, 2026

WHAT

Out of the Crypt: The Evolving Cyber Extortion Economy — Unit 42 explores trends in data theft and extortion, outlining key strategies for organizations as frontier AI models advance. The post Out of the Crypt: The Evolving Cyber Extortion Economy appear...

WHY IT MATTERS

Unit 42 explores trends in data theft and extortion, outlining key strategies for organizations as frontier AI models advance. The post Out of the Crypt: The Evolving Cyber Extortion Economy appeared first on Unit 42. ]]>

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Tuesday, June 9, 2026

WHAT

AI brands as bait: How threat actors are using the AI hype in social engineering — As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure. The post AI brands as bait: How threat ac...

WHY IT MATTERS

As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure. The post AI brands as bait: How threat actors are using the AI hype in social engineering appeared first on Microsoft Security Blog. ]]>

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Tuesday, June 9, 2026

WHAT

SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain — SHub Reaper bypasses Apple's Terminal mitigation, steals credentials and documents, and plants a persistent backdoor for continued access after infection.

WHY IT MATTERS

SHub Reaper bypasses Apple's Terminal mitigation, steals credentials and documents, and plants a persistent backdoor for continued access after infection.

WHAT TO DO

Verify model provenance and checksums, scan for backdoor signatures, implement data validation pipelines, and use trusted model sources only.

AI

Tuesday, June 9, 2026

WHAT

UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

WHY IT MATTERS

UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Tuesday, June 9, 2026

WHAT

Trump AI Order Seeks Voluntary Frontier Model Testing — The White House's executive order establishes voluntary framework for early government access to frontier models while investing in federal security.

WHY IT MATTERS

The White House's executive order establishes voluntary framework for early government access to frontier models while investing in federal security.

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Tuesday, June 9, 2026

WHAT

'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud — The latest attacks, which hit 37 PyPI wheels and 19 code packages, show a continued evolution of the persistent software supply chain threat.

WHY IT MATTERS

The latest attacks, which hit 37 PyPI wheels and 19 code packages, show a continued evolution of the persistent software supply chain threat.

WHAT TO DO

Audit ML dependencies, implement package pinning with hash verification, use isolated training environments, and scan for known malicious packages.

AI

Tuesday, June 9, 2026

WHAT

ISO 42001:2023 and the New Reality of Cloud AI Data Risk

WHY IT MATTERS

ISO 42001:2023 and the New Reality of Cloud AI Data Risk

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.