π¨ New Cisco SD-WAN vulnerability under active exploitation.
CVE-2026-20245 lets authenticated netadmin attackers run commands as root via crafted file uploads.
No patches or mitigations are available.
Check /var/log/scripts.log for IoCs.
Read: https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html
CVE-2026-20245 lets authenticated netadmin attackers run commands as root via crafted file uploads.
No patches or mitigations are available.
Check /var/log/scripts.log for IoCs.
Read: https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html
π₯8β‘5
π¨ 73 Microsoft GitHub repos just went dark.
They were hit by Miasma, a self-replicating supply chain attack spreading through trusted open-source channels.
Azure and MicrosoftDocs repos were among those impacted.
Read this: https://thehackernews.com/2026/06/miasma-worm-hits-73-microsoft-github.html
They were hit by Miasma, a self-replicating supply chain attack spreading through trusted open-source channels.
Azure and MicrosoftDocs repos were among those impacted.
Read this: https://thehackernews.com/2026/06/miasma-worm-hits-73-microsoft-github.html
π₯12π5π3β‘1π1
π₯ AI just found 21 zero-days in FFmpeg.
Thatβs the video library bundled inside many apps, tools, containers, and devices. Some bugs sat untouched for 15β20 years.
Google Chrome also dropped PATCHES for a record 429 vulnerabilities this week.
Read: https://thehackernews.com/2026/06/ai-agent-uncovers-21-zero-days-in.html
Thatβs the video library bundled inside many apps, tools, containers, and devices. Some bugs sat untouched for 15β20 years.
Google Chrome also dropped PATCHES for a record 429 vulnerabilities this week.
Read: https://thehackernews.com/2026/06/ai-agent-uncovers-21-zero-days-in.html
π14π€―10π₯3β‘2π1
π¨ A SolarWinds Serv-U bug is now on CISAβs exploited list.
CVE-2026-28318 can let unauthenticated requests crash the file server.
Patch: Serv-U 15.5.4 HF1.
Federal agencies have until June 19, 2026.
Read: https://thehackernews.com/2026/06/cisa-adds-actively-exploited-solarwinds.html
CVE-2026-28318 can let unauthenticated requests crash the file server.
Patch: Serv-U 15.5.4 HF1.
Federal agencies have until June 19, 2026.
Read: https://thehackernews.com/2026/06/cisa-adds-actively-exploited-solarwinds.html
β‘3π1π₯1π1
β‘ Your Smart TV might be scraping the web for π€ AI.
Not hacked. You tapped "accept" for fewer ads.
It said "occasionally." The fine print allows 200 GB a month.
Read β https://thehackernews.com/2026/06/free-apps-are-quietly-turning-smart-tvs.html
Your IP. Your bandwidth. Someone else's bot.
Not hacked. You tapped "accept" for fewer ads.
It said "occasionally." The fine print allows 200 GB a month.
Read β https://thehackernews.com/2026/06/free-apps-are-quietly-turning-smart-tvs.html
Your IP. Your bandwidth. Someone else's bot.
π€―21π4β‘3π₯1π1
OpenAI is adding βLOCKDOWN MODEβ to #ChatGPT.
It wonβt stop prompt injections.
Itβs built to reduce what attackers want next: a way to leak your data out.
The mode limits tools that connect to the web or external services, including browsing, images, deep research, agent mode, and file downloads.
Read β https://thehackernews.com/2026/06/new-chatgpt-lockdown-mode-limits-tools.html
It wonβt stop prompt injections.
Itβs built to reduce what attackers want next: a way to leak your data out.
The mode limits tools that connect to the web or external services, including browsing, images, deep research, agent mode, and file downloads.
Read β https://thehackernews.com/2026/06/new-chatgpt-lockdown-mode-limits-tools.html
π16π7π±4π₯2
β‘ #Microsoft is adding a 2-hour delay before VS Code extensions auto-update.
The wait gives maintainers more time to catch bad or compromised releases before they spread further.
β Microsoft, #GitHub, and #OpenAI extensions update instantly
β Manual updates still work anytime
β npm, pnpm, Bun, Yarn, and Bundler added similar delays
Read details: https://thehackernews.com/2026/06/vs-code-adds-2-hour-extension-auto.html
The wait gives maintainers more time to catch bad or compromised releases before they spread further.
β Microsoft, #GitHub, and #OpenAI extensions update instantly
β Manual updates still work anytime
β npm, pnpm, Bun, Yarn, and Bundler added similar delays
Read details: https://thehackernews.com/2026/06/vs-code-adds-2-hour-extension-auto.html
π15π₯8π5π€3
π¨ Dozens of U.S. firms were targeted with a simple playbook:
> Fake invoice email
> Fake IT support call
> Screen share
> Remote access tool
> Data theft
> Extortion demand within 30 mins
UNC3753 hit legal, finance, and professional services firms in JanβMay 2026.
Read: https://thehackernews.com/2026/06/unc3753-used-vishing-and-physical.html
> Fake invoice email
> Fake IT support call
> Screen share
> Remote access tool
> Data theft
> Extortion demand within 30 mins
UNC3753 hit legal, finance, and professional services firms in JanβMay 2026.
Read: https://thehackernews.com/2026/06/unc3753-used-vishing-and-physical.html
π6π±4π3π₯2π€2π€―1
β οΈ China-linked spies hid where security tools often donβt look.
They used BRICKSTORM, PLENET, and AGENTPSD on #Linux appliances, including Egnyte Storage Sync, pfSense, and Synology NAS.
The access lasted at least 18 months.
Full story: https://thehackernews.com/2026/06/verdantbamboo-deploys-bsd-variant-of.html
They used BRICKSTORM, PLENET, and AGENTPSD on #Linux appliances, including Egnyte Storage Sync, pfSense, and Synology NAS.
The access lasted at least 18 months.
Full story: https://thehackernews.com/2026/06/verdantbamboo-deploys-bsd-variant-of.html
π8π₯8
AI isnβt just finding open-source bugs.
It may turn thousands of ignored scanner alerts into real attack chains β faster than maintainers can patch them.
That could force a new model for open-source security.
Why this matters now: https://thehackernews.com/2026/06/the-hardest-fork.html
It may turn thousands of ignored scanner alerts into real attack chains β faster than maintainers can patch them.
That could force a new model for open-source security.
Why this matters now: https://thehackernews.com/2026/06/the-hardest-fork.html
π11π₯3
π Hackers can get into some Check Point VPNs without knowing the password.
And itβs already being exploited.
The bug is CVE-2026-50751 and affects IKEv1 Remote Access/Mobile Access setups.
Check if your gateways are exposed.
Read: https://thehackernews.com/2026/06/critical-check-point-vpn-flaw-exploited.html
And itβs already being exploited.
The bug is CVE-2026-50751 and affects IKEv1 Remote Access/Mobile Access setups.
Check if your gateways are exposed.
Read: https://thehackernews.com/2026/06/critical-check-point-vpn-flaw-exploited.html
π₯9
AI is finding zero-days faster than security teams can respond.
NIST can't keep pace with CVEs.
Exploitation windows are now measured in hours.
Most vulnerability management programs weren't built for this environment.
In the latest Resilient Cyber episode, Chris Hughes sits down with Ivan Dwyer of Axonius to discuss what comes next β asset visibility, board conversations, AI vs. AI, and the metrics that actually matter when the volume explodes.
The Vulnpocalypse Playbook >> https://thn.news/vulnpocalypse-guide
NIST can't keep pace with CVEs.
Exploitation windows are now measured in hours.
Most vulnerability management programs weren't built for this environment.
In the latest Resilient Cyber episode, Chris Hughes sits down with Ivan Dwyer of Axonius to discuss what comes next β asset visibility, board conversations, AI vs. AI, and the metrics that actually matter when the volume explodes.
The Vulnpocalypse Playbook >> https://thn.news/vulnpocalypse-guide
π±8π€3π2
π¨ Meta caught NSO Group trying again.
This time, the spyware vendor was linked to phishing links aimed at #WhatsApp users β even after a court order barred it from targeting them.
Now Meta wants NSO held in contempt.
Details: https://thehackernews.com/2026/06/meta-blocks-nso-groups-new-whatsapp.html
This time, the spyware vendor was linked to phishing links aimed at #WhatsApp users β even after a court order barred it from targeting them.
Now Meta wants NSO held in contempt.
Details: https://thehackernews.com/2026/06/meta-blocks-nso-groups-new-whatsapp.html
π₯11π3π2π€―1
β οΈ AI didn't just make phishing better. It made it endless.
Attackers now spin up fake login pages and tailored lures in minutes. Every polished email piles onto your Tier 1 queue, and a real credential theft can sit buried while your team clears the noise.
Here's how SOCs are cutting through it π https://thehackernews.com/2026/06/ai-phishing-is-crushing-socs-with-alert.html
Attackers now spin up fake login pages and tailored lures in minutes. Every polished email piles onto your Tier 1 queue, and a real credential theft can sit buried while your team clears the noise.
Here's how SOCs are cutting through it π https://thehackernews.com/2026/06/ai-phishing-is-crushing-socs-with-alert.html
π10π₯1
> A worm loose in #Microsoft's own repos.
> A phone flaw is already being used to break in.
> Accounts stolen just by chatting with a support bot.
> A browser update that quietly mined crypto.
> Fake job ads hunting people with security clearances.
> A spy sitting in one inbox for five months.
That was just last week.
Here's everything you missed π https://thehackernews.com/2026/06/weekly-recap-instagram-account-hacks.html
> A phone flaw is already being used to break in.
> Accounts stolen just by chatting with a support bot.
> A browser update that quietly mined crypto.
> Fake job ads hunting people with security clearances.
> A spy sitting in one inbox for five months.
That was just last week.
Here's everything you missed π https://thehackernews.com/2026/06/weekly-recap-instagram-account-hacks.html
π₯8π2π1π1
π¨ A single stray "!" in the #Linux kernel's firewall code (nftables).
That one character let any normal logged-in user become root, and step out of the container.
The fix? One line.
And the exploit (CVE-2026-23111) to abuse it just went public.
Read: https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html
That one character let any normal logged-in user become root, and step out of the container.
The fix? One line.
And the exploit (CVE-2026-23111) to abuse it just went public.
Read: https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html
π€―13β‘5π±3π₯2
π¨ Hackers are already exploiting a flaw in LiteLLM, a widely used open-source AI gateway.
One bug (CVE-2026-42271) lets any logged-in user run commands on the server. Chain it with a second bug, and attackers get in with no login at all.
At risk: API keys, stored secrets, and everything connected to it.
π Details: https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html
One bug (CVE-2026-42271) lets any logged-in user run commands on the server. Chain it with a second bug, and attackers get in with no login at all.
At risk: API keys, stored secrets, and everything connected to it.
π Details: https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html
π17π₯2π±2
The "IT helpdesk" messaging you on Microsoft Teams could be a complete stranger.
Then your manager calls to confirm it's urgent. Same voice, except it's an AI clone built from a clip online.
Brian Long, founder of Adaptive Security, takes apart the rest: no malware, no exploit, all built-in Microsoft tools. The only thing they have to break is you.
The 10-minute window where nobody notices π https://thehackernews.com/expert-insights/2026/06/how-attackers-are-adding-ai-voice.html
Then your manager calls to confirm it's urgent. Same voice, except it's an AI clone built from a clip online.
Brian Long, founder of Adaptive Security, takes apart the rest: no malware, no exploit, all built-in Microsoft tools. The only thing they have to break is you.
The 10-minute window where nobody notices π https://thehackernews.com/expert-insights/2026/06/how-attackers-are-adding-ai-voice.html
π7π₯2π±2β‘1
π 37 poisoned wheels. 19 PyPI packages.
The malware can run when Python starts, before you import the poisoned PyPI package.
"Hades" installs Bun, starts a hidden stealer, and grabs GitHub, cloud, CI/CD, SSH, Docker, and developer secrets.
Read more on the Hades PyPI attack: https://thehackernews.com/2026/06/hades-pypi-attack-19-packages-poisoned.html
The malware can run when Python starts, before you import the poisoned PyPI package.
"Hades" installs Bun, starts a hidden stealer, and grabs GitHub, cloud, CI/CD, SSH, Docker, and developer secrets.
Read more on the Hades PyPI attack: https://thehackernews.com/2026/06/hades-pypi-attack-19-packages-poisoned.html
π€5π₯2β‘1
π¨ A website can figure out what you're doing on your computer.
No download. No permission. No popup.
> It's called FROST.
> Up to 95% accurate.
> And there's no fix yet.
You just leave the tab open, and JavaScript times your SSD to tell which sites you visit and which apps you open.
π Learn how this works: https://thehackernews.com/2026/06/new-frost-attack-lets-websites-track.html
No download. No permission. No popup.
> It's called FROST.
> Up to 95% accurate.
> And there's no fix yet.
You just leave the tab open, and JavaScript times your SSD to tell which sites you visit and which apps you open.
π Learn how this works: https://thehackernews.com/2026/06/new-frost-attack-lets-websites-track.html
π€―22π₯4β‘1
π¨ WARNING: Google just fixed a Chrome zero-day already used in real attacks.
The bug (CVE-2026-11645) hits V8, Chromeβs JavaScript engine, and can let attackers run code through a crafted HTML page.
Update your browser now.
Read the full story: https://thehackernews.com/2026/06/chrome-v8-zero-day-cve-2026-11645.html
The bug (CVE-2026-11645) hits V8, Chromeβs JavaScript engine, and can let attackers run code through a crafted HTML page.
Update your browser now.
Read the full story: https://thehackernews.com/2026/06/chrome-v8-zero-day-cve-2026-11645.html
π₯9π6π1