Daily Pulse

Stay informed with today's critical security updates

Every organisation is different. The free "Daily Pulse" feed shows the broader threat landscape.

Want this specific and tailored to your organisation?

ThreatInsights – Click for more info

The Daily Pulse is refreshed automatically every day at 9:00 AM GMT

Want to learn more about Cyber Threat Intelligence?

Check out our free online self-paced training course.

Start Learning Now
Filter by type:(20 items)
CVE

Monday, June 15, 2026

WHAT

CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats

WHY IT MATTERS

“Defenders cannot afford to take weeks to patch,” one Cybersecurity and Infrastructure Security Agency official warned on Wednesday.

WHAT TO DO

Review affected systems, apply patches immediately, monitor for exploitation attempts, and verify patch deployment across all endpoints.

Threat

Monday, June 15, 2026

WHAT

Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

WHY IT MATTERS

Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit.

WHAT TO DO

Assess potential impact to your environment, update security controls, inform relevant stakeholders, and monitor for related activity.

Breach

Monday, June 15, 2026

WHAT

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

WHY IT MATTERS

Lawmakers in both houses of Congress are demanding answers from the U. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub a...

WHAT TO DO

Check if your organization uses affected services, reset credentials, monitor for phishing attempts using leaked data, and review third-party risk.

Campaign

Monday, June 15, 2026

WHAT

Watering Hole Attacks Push ScanBox Keylogger

WHY IT MATTERS

Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.

WHAT TO DO

Update threat detection rules, brief security team on TTPs, enhance monitoring for IoCs, and review defensive posture against similar attacks.

Breach

Monday, June 15, 2026

WHAT

Phishing Attack Volume Down 20%, But Risk Still Rising

WHY IT MATTERS

Hackers are valuing quality over quantity, using AI to upgrade their phishing attacks rather than multiply them.

WHAT TO DO

Check if your organization uses affected services, reset credentials, monitor for phishing attempts using leaked data, and review third-party risk.

CVE

Monday, June 15, 2026

WHAT

A Record-Breaking Patch Tuesday for June 2026

WHY IT MATTERS

Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploit code for at least three of the weaknesses is now publicly available.

WHAT TO DO

Review affected systems, apply patches immediately, monitor for exploitation attempts, and verify patch deployment across all endpoints.

Campaign

Monday, June 15, 2026

WHAT

Turn specs into evals for any agent with ASSERT

WHY IT MATTERS

Adaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT) is an open-source framework for converting natural language behavior requirements into executable evaluations of AI models and agents. The post Turn specs into evals for any agent with ASSERT appeared first on Microsoft S...

WHAT TO DO

Update threat detection rules, brief security team on TTPs, enhance monitoring for IoCs, and review defensive posture against similar attacks.

Threat

Monday, June 15, 2026

WHAT

Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps

WHY IT MATTERS

The new open-source project could serve as the basis for a future of apps with features as complex as Slack, Discord, or Google Docs—but with added protection against surveillance.

WHAT TO DO

Assess potential impact to your environment, update security controls, inform relevant stakeholders, and monitor for related activity.

CVE

Monday, June 15, 2026

WHAT

CISA Adds One Known Exploited Vulnerability to Catalog

WHY IT MATTERS

gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. id=CVE-2026-35273" target="_blank">CVE-2026-35273</a> Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability</li> ...

WHAT TO DO

Review affected systems, apply patches immediately, monitor for exploitation attempts, and verify patch deployment across all endpoints.

Breach

Monday, June 15, 2026

WHAT

In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine

WHY IT MATTERS

Other noteworthy stories that might have slipped under the radar: ICS device exposure remains flat as attack surface widens, Microsoft issues incident response playbook for AI, IBM and AT&#038;T accused of hack cover-ups.

WHAT TO DO

Check if your organization uses affected services, reset credentials, monitor for phishing attempts using leaked data, and review third-party risk.

AI

Monday, June 15, 2026

WHAT

Chinese hackers hijack auth flow, spy on isolated network for a decade — Chinese hackers took control of a target organization's authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity. [...]

WHY IT MATTERS

Chinese hackers took control of a target organization's authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity. [...]

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing

WHY IT MATTERS

Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

BBVA puts AI at the core of banking with OpenAI — Learn how BBVA scaled ChatGPT Enterprise to 100,000 employees and partnered with OpenAI to accelerate AI-powered banking transformation worldwide.

WHY IT MATTERS

Learn how BBVA scaled ChatGPT Enterprise to 100,000 employees and partnered with OpenAI to accelerate AI-powered banking transformation worldwide.

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

WHY IT MATTERS

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

Why AI Projects Stall and How CIOs Can Respond

WHY IT MATTERS

Why AI Projects Stall and How CIOs Can Respond

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

FBI disrupts massive AI-powered phishing service using a million URLs — In a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing we...

WHY IT MATTERS

In a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing websites used to steal credit card data and passwords. [...]

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

Securing CI/CD in an agentic world: Claude Code Github action case — Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack...

WHY IT MATTERS

Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack chain, responsible disclosure process, Anthropic's mitigation, and guidance for securing AI-powered CI/CD workflows. The post Securing CI/CD in an agentic world: Claude Code Github action case appeared first on Microsoft Security Blog. ]]>

WHAT TO DO

Implement input validation, deploy prompt injection detection classifiers, limit AI agent permissions, and monitor for unusual API patterns.

AI

Monday, June 15, 2026

WHAT

AI Risk Worries Insurers & Businesses Alike — As companies adopt AI, many insurance firms are explicitly excluding AI risks, while others are forging ahead to create the right framework. What risks can firms reasonably manage?

WHY IT MATTERS

As companies adopt AI, many insurance firms are explicitly excluding AI risks, while others are forging ahead to create the right framework. What risks can firms reasonably manage?

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

Introducing the OpenAI Partner Network — OpenAI launches the Partner Network, investing $150M to help global partners accelerate enterprise AI adoption, deployment, and transformation.

WHY IT MATTERS

OpenAI launches the Partner Network, investing $150M to help global partners accelerate enterprise AI adoption, deployment, and transformation.

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

Turn Blind Trust into Verified Control with Prompt Security for Agentic AI — Prompt for Agentic AI Security empowers organizations with proactive governance, meaning security teams can deploy agents with confidence.

WHY IT MATTERS

Prompt for Agentic AI Security empowers organizations with proactive governance, meaning security teams can deploy agents with confidence.

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.