βΌοΈπ¨ A critical Joomla Content Editor vulnerability is under active attack and rated CVSS 10.0. Joomla is used by 1.2% of all websites on the internet.
The vulnerability, CVE-2026-48907: an unauthenticated attacker can create an editor profile, upload PHP, and take full control of the site.
CISA and Italy's CSIRT have both issued alerts.
The vulnerability, CVE-2026-48907: an unauthenticated attacker can create an editor profile, upload PHP, and take full control of the site.
CISA and Italy's CSIRT have both issued alerts.
π¨ An AI-enabled Dutch man was sentenced to 2.5 years in prison for using deepfakes to open 47 bank accounts. The man used ChatGPT to plan his criminal activity, which included using residential proxies.
He sourced victim photos from social media, older data breaches, and by posing as a landlord on an online marketplace to request ID documents. He then built deepfakes from those photos to beat the bank's facial verification during mobile onboarding.
Border police flagged him carrying multiple bank cards. His phone held dozens of IDs, victim photos, and ChatGPT chats on how to bypass identity verification.
He sourced victim photos from social media, older data breaches, and by posing as a landlord on an online marketplace to request ID documents. He then built deepfakes from those photos to beat the bank's facial verification during mobile onboarding.
Border police flagged him carrying multiple bank cards. His phone held dozens of IDs, victim photos, and ChatGPT chats on how to bypass identity verification.
π€£16π4π2π2β€1π₯1
βΌοΈπ¨ Grok AI was used by the US to help fire more than 2,000 munitions at 2,000 separate targets inside Iran within 96 hours. The disclosure comes from a sworn declaration by Cameron Stanley, the Pentagon's chief digital and AI officer, filed June 15 in the NAACP's lawsuit against xAI in the Northern District of Mississippi. Stanley said the Grok Gov Model, running inside Palantir's Maven Smart System, drove the strikes during Operation Epic Fury, the codename for the war launched on Iran in late February.
The filing was meant to protect xAI's Colossus 2 data center in Memphis, which the NAACP says is illegally polluting Black neighborhoods. The Pentagon argued the site is a matter of national security and named xAI one of only three vendors cleared to run mission-critical operations on classified networks.
The filing was meant to protect xAI's Colossus 2 data center in Memphis, which the NAACP says is illegally polluting Black neighborhoods. The Pentagon argued the site is a matter of national security and named xAI one of only three vendors cleared to run mission-critical operations on classified networks.
π€¬16π5π¨4β€3π₯2π©2π1
π¨ Apple is raising prices across its product line, blaming chip shortages. CEO Tim Cook says the hikes are unavoidable as AI buyers drain memory and storage supply.
π€£14π€¬10π3π€1
βΌοΈ A fully AI-enabled hacker was caught, revealing his full system prompts, which included his resume and his IP address. He had Claude and Codex agents locally and was using them remotely to carry out reconnaissance, exploitation, and data exfiltration activities.
In his sessions, the attacker Injects a "senior red team penetration tester⦠fully authorized" persona.
He might be dumber than you think: The attacker's first jobs for Claude were polishing his resume, then building an automated job application tool. That resume lists his full name, location, schooling, and LinkedIn profile, exposing him as a young man in Addis Ababa, Ethiopia.
Posing as a redteam, the attacker got Claude to suggest and rank ways to profit from the breaches. Claude and Codex blocked most of these, flagging it as illegitimate. He still pulled a list: extortion, data sale, BEC, fund theft, plus attempts to crack a Bitcoin wallet and sell stolen credentials.
Full disclosure: https://research.openanalysis.net/claude/codex/hacking/ai%20hacking/llm/redteam/policy%20violation/2026/06/16/compromised-claude-hacking.html
In his sessions, the attacker Injects a "senior red team penetration tester⦠fully authorized" persona.
He might be dumber than you think: The attacker's first jobs for Claude were polishing his resume, then building an automated job application tool. That resume lists his full name, location, schooling, and LinkedIn profile, exposing him as a young man in Addis Ababa, Ethiopia.
Posing as a redteam, the attacker got Claude to suggest and rank ways to profit from the breaches. Claude and Codex blocked most of these, flagging it as illegitimate. He still pulled a list: extortion, data sale, BEC, fund theft, plus attempts to crack a Bitcoin wallet and sell stolen credentials.
Full disclosure: https://research.openanalysis.net/claude/codex/hacking/ai%20hacking/llm/redteam/policy%20violation/2026/06/16/compromised-claude-hacking.html
π€£21π3β€1π€ͺ1
βΌοΈ BREAKING: Volkswagen has banned GrapheneOS users from using their app. Users are reporting they can't log in or control their car anymore. Users are confused, saying Volkswagen allows their app to be used on End-of-Life Android versions, but not on fully patched GrapheneOS.
https://discuss.grapheneos.org/d/35949-volkswagen-app/50
https://discuss.grapheneos.org/d/35949-volkswagen-app/50
π19π€¬9π€£6π©3
π¨βΌοΈ BREAKING: The threat actor who breached Novo Nordisk, the company behind Ozempic, has leaked 264 GB of data. They are also mocking Novo Nordisk, claiming the company was using passwords like "novo123" for critical systems and that its security team sucks.
The breach includes source code, proprietary information on both marketed and pipeline drugs, clinical trial records, data on employees, doctors, and patients, and manufacturing details. The threat actor also claims it obtained private internal AI models from Novo's systems.
They allegedly breached Novo in March via a GitHub access token that let it clone the company's repositories and find additional credentials. The intrusion ran for over two months and yielded roughly 1.3 terabytes across more than 700,000 files.
The breach includes source code, proprietary information on both marketed and pipeline drugs, clinical trial records, data on employees, doctors, and patients, and manufacturing details. The threat actor also claims it obtained private internal AI models from Novo's systems.
They allegedly breached Novo in March via a GitHub access token that let it clone the company's repositories and find additional credentials. The intrusion ran for over two months and yielded roughly 1.3 terabytes across more than 700,000 files.
π11π₯7
βΌοΈ Over two months ago, Tesla USA remotely force-pushed code to cars in Europe and Asia with the line: "APE Updated from Mothership." (see evidence below)
The so-called Tesla 'Mothership', without user consent or interaction, woke the cars up remotely and disabled Full Self-Driving (FSD) and Enhanced Autopilot functionality. Some people had paid almost $9,000 for these features.
We then received reports from users in Europe who nearly got into accidents after the remote update, because they didn't know what it had done: it had shut off traffic light recognition and automated stops. They ran red lights while on Autopilot β something that never happened before the update.
Tesla says it pushed the update because it detected CAN bus manipulation devices used to alter the car's functions. Functions of a car you own β or at least thought you did. A car you thought was safe to drive β but suddenly safety features you'd paid for and relied on for years were gone.
To this date, Tesla still hasn't given an official statement or offered a solution for the affected customers.
The so-called Tesla 'Mothership', without user consent or interaction, woke the cars up remotely and disabled Full Self-Driving (FSD) and Enhanced Autopilot functionality. Some people had paid almost $9,000 for these features.
We then received reports from users in Europe who nearly got into accidents after the remote update, because they didn't know what it had done: it had shut off traffic light recognition and automated stops. They ran red lights while on Autopilot β something that never happened before the update.
Tesla says it pushed the update because it detected CAN bus manipulation devices used to alter the car's functions. Functions of a car you own β or at least thought you did. A car you thought was safe to drive β but suddenly safety features you'd paid for and relied on for years were gone.
To this date, Tesla still hasn't given an official statement or offered a solution for the affected customers.
π±13π€£7π2π€¬2
βΌοΈ Trump mocked Zuckerberg and Bezos behind their backs, flashing their "kissing my ass" texts to guests. In a conversation with Elon Musk, Trump said of the pair, "They hated me... look at them now," and Musk replied, "First-class groveling."
Bezos allegedly trashed his own Washington Post to Trump too, calling it one of his worst investments and the staff "terrible."
From the forthcoming Haberman and Swan book Regime Change, obtained by WIRED ahead of its June 23 release.
Bezos allegedly trashed his own Washington Post to Trump too, calling it one of his worst investments and the staff "terrible."
From the forthcoming Haberman and Swan book Regime Change, obtained by WIRED ahead of its June 23 release.
π€£16π©3