Daily Pulse

Stay informed with today's critical security updates

Every organisation is different. The free "Daily Pulse" feed shows the broader threat landscape.

Want this specific and tailored to your organisation?

ThreatInsights – Click for more info

The Daily Pulse is refreshed automatically every day at 9:00 AM GMT

Want to learn more about Cyber Threat Intelligence?

Check out our free online self-paced training course.

Start Learning Now
Filter by type:(20 items)
Breach

Thursday, June 18, 2026

WHAT

‘Dangerous’ AI Models Are Coming No Matter What

WHY IT MATTERS

The US government crackdown on Anthropic’s Claude Fable 5 and Mythos 5 hides a glaring truth: AI models with advanced hacking capabilities will soon be the norm.

WHAT TO DO

Check if your organization uses affected services, reset credentials, monitor for phishing attempts using leaked data, and review third-party risk.

Threat

Thursday, June 18, 2026

WHAT

Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack

WHY IT MATTERS

The attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control. The post Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack appeared first on SecurityWeek.

WHAT TO DO

Assess potential impact to your environment, update security controls, inform relevant stakeholders, and monitor for related activity.

Campaign

Thursday, June 18, 2026

WHAT

Watering Hole Attacks Push ScanBox Keylogger

WHY IT MATTERS

Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.

WHAT TO DO

Update threat detection rules, brief security team on TTPs, enhance monitoring for IoCs, and review defensive posture against similar attacks.

Threat

Thursday, June 18, 2026

WHAT

Lawmakers leery about Trump administration’s Anthropic order

WHY IT MATTERS

Some panned it, some said they needed more information, but caution figured into all of the responses. The post Lawmakers leery about Trump administration’s Anthropic order appeared first on CyberScoop.

WHAT TO DO

Assess potential impact to your environment, update security controls, inform relevant stakeholders, and monitor for related activity.

CVE

Thursday, June 18, 2026

WHAT

AI’s constant patching treadmill can be a security problem

WHY IT MATTERS

The breakneck speed of model releases may be creating short, silent security gaps as developers must choose between performance and security, according to a new report. The post AI’s constant patching treadmill can be a security problem appeared first on CyberScoop.

WHAT TO DO

Review affected systems, apply patches immediately, monitor for exploitation attempts, and verify patch deployment across all endpoints.

Threat

Thursday, June 18, 2026

WHAT

Google exposes China espionage group that’s been lurking in networks undetected since 2023

WHY IT MATTERS

The revelation mirrors an alarming pattern of Chinese espionage groups dropping backdoors into critical infrastructure to intercept research and steal data with national security implications. The post Google exposes China espionage group that’s been lurking in networks undetected since 2023 appe...

WHAT TO DO

Assess potential impact to your environment, update security controls, inform relevant stakeholders, and monitor for related activity.

Breach

Thursday, June 18, 2026

WHAT

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

WHY IT MATTERS

Lawmakers in both houses of Congress are demanding answers from the U. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub a...

WHAT TO DO

Check if your organization uses affected services, reset credentials, monitor for phishing attempts using leaked data, and review third-party risk.

Breach

Thursday, June 18, 2026

WHAT

FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.

WHY IT MATTERS

A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide.

WHAT TO DO

Check if your organization uses affected services, reset credentials, monitor for phishing attempts using leaked data, and review third-party risk.

Breach

Thursday, June 18, 2026

WHAT

Student Loan Breach Exposes 2.5M Records

WHY IT MATTERS

5 million people were affected, in a breach that could spell more trouble down the line.

WHAT TO DO

Check if your organization uses affected services, reset credentials, monitor for phishing attempts using leaked data, and review third-party risk.

Threat

Thursday, June 18, 2026

WHAT

Why Account Takeovers Are Rising and How to Stop Them

WHY IT MATTERS

Account takeovers are rising as attackers bypass traditional defenses through phishing, session hijacking, and MFA fatigue. Specops Software explores how device trust and continuous verification help reduce account takeover risk.

WHAT TO DO

Assess potential impact to your environment, update security controls, inform relevant stakeholders, and monitor for related activity.

AI

Monday, June 15, 2026

WHAT

Chinese hackers hijack auth flow, spy on isolated network for a decade — Chinese hackers took control of a target organization's authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity. [...]

WHY IT MATTERS

Chinese hackers took control of a target organization's authentication stack and maintained persistence for 10 years, with full visibility into the administrative activity. [...]

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing

WHY IT MATTERS

Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

BBVA puts AI at the core of banking with OpenAI — Learn how BBVA scaled ChatGPT Enterprise to 100,000 employees and partnered with OpenAI to accelerate AI-powered banking transformation worldwide.

WHY IT MATTERS

Learn how BBVA scaled ChatGPT Enterprise to 100,000 employees and partnered with OpenAI to accelerate AI-powered banking transformation worldwide.

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

WHY IT MATTERS

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

Why AI Projects Stall and How CIOs Can Respond

WHY IT MATTERS

Why AI Projects Stall and How CIOs Can Respond

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

FBI disrupts massive AI-powered phishing service using a million URLs — In a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing we...

WHY IT MATTERS

In a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing websites used to steal credit card data and passwords. [...]

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

Securing CI/CD in an agentic world: Claude Code Github action case — Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack...

WHY IT MATTERS

Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack chain, responsible disclosure process, Anthropic's mitigation, and guidance for securing AI-powered CI/CD workflows. The post Securing CI/CD in an agentic world: Claude Code Github action case appeared first on Microsoft Security Blog. ]]>

WHAT TO DO

Implement input validation, deploy prompt injection detection classifiers, limit AI agent permissions, and monitor for unusual API patterns.

AI

Monday, June 15, 2026

WHAT

AI Risk Worries Insurers & Businesses Alike — As companies adopt AI, many insurance firms are explicitly excluding AI risks, while others are forging ahead to create the right framework. What risks can firms reasonably manage?

WHY IT MATTERS

As companies adopt AI, many insurance firms are explicitly excluding AI risks, while others are forging ahead to create the right framework. What risks can firms reasonably manage?

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

Introducing the OpenAI Partner Network — OpenAI launches the Partner Network, investing $150M to help global partners accelerate enterprise AI adoption, deployment, and transformation.

WHY IT MATTERS

OpenAI launches the Partner Network, investing $150M to help global partners accelerate enterprise AI adoption, deployment, and transformation.

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.

AI

Monday, June 15, 2026

WHAT

Turn Blind Trust into Verified Control with Prompt Security for Agentic AI — Prompt for Agentic AI Security empowers organizations with proactive governance, meaning security teams can deploy agents with confidence.

WHY IT MATTERS

Prompt for Agentic AI Security empowers organizations with proactive governance, meaning security teams can deploy agents with confidence.

WHAT TO DO

Deploy adversarial robustness testing, implement input anomaly detection, use ensemble models for critical decisions, and add confidence thresholds.