top of page
Frame 2.png
cybersecurity-concept-keylock-blue-colors-binary-code-lock-ai-generated 1.png
Trusted by 100.png

Weekly INK

Issue #203 - June 15, 2026

wi4.png

Stay informed on the threats, trends, and security developments that matter most to your business. Find practical insights to better understand risk and stay ahead of bad actors.

Talk to an expert
Frame 2.png
cybersecurity-concept-keylock-blue-colors-binary-code-lock-ai-generated 1.png
Trusted by 100.png

Issue #203 - June 15, 2026

Weekly INK

Free, practical resources to assess your status, understand risks, and enhance your security posture no sales pitch needed.

Talk to An Expert

Issue #203 - June 15, 2026

INC Ransomware Thrives by Mastering the Basics

Source: Dark Reading


INC ransomware has grown by focusing on practical, repeatable intrusion methods rather than novel tooling. Researchers said the group targets high-pressure sectors, uses familiar techniques such as stolen credentials, phishing, and unpatched remote services, and benefits from affiliate scalability as other ransomware groups decline or reorganize.


Link to article



Fileless Phantom Stealer Targets Browser Credentials

Source: Dark Reading


Researchers warned that Phantom Stealer is being delivered through a targeted phishing campaign against banks and other high-value organizations. The malware runs largely in memory, uses layered obfuscation, and steals browser credentials, session cookies, financial data, screenshots, and wallet information while exfiltrating through multiple channels.


Link to article



145 Mastra npm Packages Compromised via Hijacked Contributor Account

Source: The Hacker News


A compromised Mastra contributor account was used to publish malicious versions of 145 npm packages. The attack added an easy-day-js dependency that delivered a cryptocurrency-stealing remote access trojan through a postinstall loader. Researchers urged affected teams to roll back packages, rotate credentials, and inspect build systems.


Link to article



CISA orders feds to patch max severity Joomla plugin flaw by Friday

Source: BleepingComputer


CISA added a maximum-severity Joomla Content Editor plugin vulnerability to its exploited vulnerabilities catalog and ordered federal agencies to patch quickly. The flaw allows unauthenticated attackers to upload and execute PHP code by creating new editor profiles, creating serious risk for exposed Joomla deployments using the affected plugin.


Link to article



Critical Command Execution Vulnerability Patched in Cisco ISE

Source: SecurityWeek


Cisco patched a critical command execution flaw in Identity Services Engine and ISE Passive Identity Connector. The vulnerability allows authenticated remote attackers with administrative credentials to run commands on the underlying operating system and potentially elevate privileges. Cisco said fixed versions and a hotfix are available.


Link to article

frame 17b.png
Frame 1597880632.png

Talk to a Blue INK expert

From strengthening security and preparing for audits to navigating privacy and governing AI, we'll connect you directly with the right expert.

How can we best help?
Frame 1597880632.png

Have questions?

Let us know the best way to reach you and we will be in touch as soon as possible to answer your questions.

How can we best help?
frame 17c.png
Frame 1597880632.png

Stay ahead of new threats

Cut through the noise and stay ahead of emerging threats most relevant to your business. Our Weekly INK curates everything you need to know about cybersecurity threats targeting businesses. 

bottom of page