Dev.to
6/19/2026

Security news weekly round-up - 19th June 2026
Short summary
This security roundup covers five critical threats: EvilTokens OAuth phishing targeting Microsoft 365, a SearchLeak Copilot vulnerability, attackers using Claude and Codex to breach 14 companies, a massive credential database leak, and mobile/USB malware campaigns. Organizations should patch vulnerabilities, verify credentials against breaches, defend against phishing, and secure endpoints. The barrier to cyberattack entry continues lowering as attackers leverage AI tools.
- •Five active threats: EvilTokens phishing, Copilot SearchLeak, AI-assisted breaches, credential leaks, malware campaigns
- •Required actions: patch Copilot, verify credentials, train against phishing, secure mobile and USB devices
- •Trend: low-skilled attackers using Claude and Codex dramatically reduces barrier to entry for cyber threats
Generated with AI, which can make mistakes.
Is this a good recommendation for you?


