π Android sideloading is getting a major new checkpoint.
Starting Sept. 30, 2026, certified #Android phones in Brazil, Indonesia, Singapore, and Thailand will block normal installs from unverified developers.
That applies beyond #Google Play, including third-party app stores and direct APK installs.
Details - https://thehackernews.com/2026/06/google-sets-sept-30-deadline-for.html
Starting Sept. 30, 2026, certified #Android phones in Brazil, Indonesia, Singapore, and Thailand will block normal installs from unverified developers.
That applies beyond #Google Play, including third-party app stores and direct APK installs.
Details - https://thehackernews.com/2026/06/google-sets-sept-30-deadline-for.html
π±9π4π3π€3π₯1π€―1
π¨ A fake Node.js download was the start of a real malware chain.
Elastic researchers found a new #malvertising campaign using Google Ads to deliver OXLOADER, a previously unreported loader that drops CastleStealer.
The payload was staged through Storj and built to avoid analysis.
Read: https://thehackernews.com/2026/06/new-oxloader-loader-uses-malicious.html
Elastic researchers found a new #malvertising campaign using Google Ads to deliver OXLOADER, a previously unreported loader that drops CastleStealer.
The payload was staged through Storj and built to avoid analysis.
Read: https://thehackernews.com/2026/06/new-oxloader-loader-uses-malicious.html
π€―6π₯3
β‘ AI-assisted social engineering has moved beyond the inbox.
Bobby Ford of Doppel says modern campaigns now span email, SMS, collaboration apps, social media, and paid ads β often as one attack chain.
The goal is no longer just blocking lures.
It is breaking the campaign earlier.
Read the full story: https://thehackernews.com/expert-insights/2026/06/beyond-blocking-disrupting-social.html
Bobby Ford of Doppel says modern campaigns now span email, SMS, collaboration apps, social media, and paid ads β often as one attack chain.
The goal is no longer just blocking lures.
It is breaking the campaign earlier.
Read the full story: https://thehackernews.com/expert-insights/2026/06/beyond-blocking-disrupting-social.html
π6π₯3
π€― A 1997 parser bug is still haunting Squid.
Squidbleed (CVE-2026-47729) can leak another userβs cleartext HTTP request through a shared Squid proxy, including credentials or session tokens.
Read π https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html
Squidbleed (CVE-2026-47729) can leak another userβs cleartext HTTP request through a shared Squid proxy, including credentials or session tokens.
Read π https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html
π9
π Private AI chats crossed tenant lines.
Researchers found four DifyTap flaws in #Dify, the 146K-star agentic workflow platform.
The bugs could expose AI conversations across tenants and leak uploaded document previews.
Read π https://thehackernews.com/2026/06/researchers-detail-difytap-flaws-in.html
Researchers found four DifyTap flaws in #Dify, the 146K-star agentic workflow platform.
The bugs could expose AI conversations across tenants and leak uploaded document previews.
Read π https://thehackernews.com/2026/06/researchers-detail-difytap-flaws-in.html
π14
β οΈ ALERT - ShapedPlugin Pro plugins were backdoored through official #WordPress update channels.
The malware can steal credentials, 2FA codes, wp-config.php data, and #WooCommerce order details.
Read π https://thehackernews.com/2026/06/shapedplugin-wordpress-pro-plugins.html
The malware can steal credentials, 2FA codes, wp-config.php data, and #WooCommerce order details.
Read π https://thehackernews.com/2026/06/shapedplugin-wordpress-pro-plugins.html
π5
π₯ OpenAI is putting GPT-5.5-Cyber in defendersβ hands.
The model is being released through Daybreak to help trusted defenders find, validate, and patch software flaws.
#OpenAI is also launching Patch the Planet with Trail of Bits to support open-source projects like cURL, Python, Sigstore, and aiohttp.
Read - https://thehackernews.com/2026/06/openai-expands-daybreak-with-gpt-55.html
The model is being released through Daybreak to help trusted defenders find, validate, and patch software flaws.
#OpenAI is also launching Patch the Planet with Trail of Bits to support open-source projects like cURL, Python, Sigstore, and aiohttp.
Read - https://thehackernews.com/2026/06/openai-expands-daybreak-with-gpt-55.html
π€11
π¨ That WhatsApp file from a trusted contact may not be safe.
A new VBS malware campaign is spreading through #WhatsApp Desktop/Web and installing ManageEngine Endpoint Central for remote access on Windows PCs.
Read the details: https://thehackernews.com/2026/06/whatsapp-vbscript-campaign-uses-fake.html
A new VBS malware campaign is spreading through #WhatsApp Desktop/Web and installing ManageEngine Endpoint Central for remote access on Windows PCs.
Read the details: https://thehackernews.com/2026/06/whatsapp-vbscript-campaign-uses-fake.html
π12π±5π4β‘1π₯1
A breach should not spread across the whole company.
That is the point of containment.
Even if attackers get in, the goal is to stop them from moving further.
The article explains how security teams and leading vendors are approaching that problem.
Read: https://awards.thehackernews.com/blog/assume-breach-containment-strategy/
That is the point of containment.
Even if attackers get in, the goal is to stop them from moving further.
The article explains how security teams and leading vendors are approaching that problem.
Read: https://awards.thehackernews.com/blog/assume-breach-containment-strategy/
π8
β οΈ A tiny npm package can hide a full malware chain.
Researchers found malicious npm packages posing as PostCSS/build tools that deploy a Windows RAT.
The malware uses JavaScript, PowerShell, VBS, and Python to steal Chrome credentials, run commands, and move files.
Read - https://thehackernews.com/2026/06/malicious-npm-packages-pose-as-postcss.html
Researchers found malicious npm packages posing as PostCSS/build tools that deploy a Windows RAT.
The malware uses JavaScript, PowerShell, VBS, and Python to steal Chrome credentials, run commands, and move files.
Read - https://thehackernews.com/2026/06/malicious-npm-packages-pose-as-postcss.html
π9π3
Running IT for a fast-growing 700-person company with a lean team sounds like a recipe for SaaS chaos. Not for the Drata team.
Nudge Security sat down with Gordon Nhieu, Senior IT Manager at Drata recently to dive into how their team got visibility into shadow SaaS, scaled governance, and kept up with a fast-moving org in the AI era.
No slides. No sales pitch. Just a candid look at how one lean IT team is making it work.
https://thn.news/saas-sprawl-nudge
Nudge Security sat down with Gordon Nhieu, Senior IT Manager at Drata recently to dive into how their team got visibility into shadow SaaS, scaled governance, and kept up with a fast-moving org in the AI era.
No slides. No sales pitch. Just a candid look at how one lean IT team is making it work.
https://thn.news/saas-sprawl-nudge
π3
AI is moving from writing attacks to running parts of them.
Agentic AI can help automate recon, social engineering, exploit selection, and malware work with less human input.
The risk is not just speed. It is misplaced trust.
Read why it matters: https://thehackernews.com/2026/06/agentic-ai-weapon-that-no-longer-needs.html
Agentic AI can help automate recon, social engineering, exploit selection, and malware work with less human input.
The risk is not just speed. It is misplaced trust.
Read why it matters: https://thehackernews.com/2026/06/agentic-ai-weapon-that-no-longer-needs.html
π€―7π€3
β‘ A risky #GitHub Actions pattern is getting blocked by default.
Starting June 18, 2026, actions/checkout v7 will refuse common fork PR checkout patterns in privileged workflows.
See how the new checkout guardrail works: https://thehackernews.com/2026/06/github-updates-actionscheckout-to-block.html
The aim: reduce βpwn requestβ attacks that can expose secrets or a privileged GITHUB_TOKEN.
Starting June 18, 2026, actions/checkout v7 will refuse common fork PR checkout patterns in privileged workflows.
See how the new checkout guardrail works: https://thehackernews.com/2026/06/github-updates-actionscheckout-to-block.html
The aim: reduce βpwn requestβ attacks that can expose secrets or a privileged GITHUB_TOKEN.
π4
π Washington is preparing for the quantum threat before it arrives.
A new Trump order gives federal agencies until 2030 to move key systems to post-quantum crypto.
Digital signatures are due by 2031.
Read - https://thehackernews.com/2026/06/trump-order-sets-2030-deadline-for.html
A new Trump order gives federal agencies until 2030 to move key systems to post-quantum crypto.
Digital signatures are due by 2031.
Read - https://thehackernews.com/2026/06/trump-order-sets-2030-deadline-for.html
π8π€―5π€1
π₯ A fake AI Agent skill reportedly reached 26,000 agents after passing security scans.
The payload was loaded later from an external link that scanners did not check, and that link could be changed after review.
Read how the blind spot worked π https://thehackernews.com/2026/06/fake-ai-agent-skill-passed-security.html
The payload was loaded later from an external link that scanners did not check, and that link could be changed after review.
Read how the blind spot worked π https://thehackernews.com/2026/06/fake-ai-agent-skill-passed-security.html
π₯13π€1
π¨ FFortiBleed went beyond FortiGate firewalls.
Researchers say a Russian-speaking IAB targeted 430,000+ FortiGate firewalls, deployed credential sniffers, and identified over 110 million credentials.
Read: https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html
The campaign also hit other internet-facing systems.
Researchers say a Russian-speaking IAB targeted 430,000+ FortiGate firewalls, deployed credential sniffers, and identified over 110 million credentials.
Read: https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html
The campaign also hit other internet-facing systems.
π₯11π3β‘2π1π€1
π Cisco Unified CM admins should check WebDialer now.
CVE-2026-20230 is being exploited, and vulnerable WebDialer-enabled systems can be abused by unauthenticated attackers to write files.
Cisco patched it in 14SU6 and 15SU5.
Read: https://thehackernews.com/2026/06/cisco-unified-cm-flaw-exploited-after.html
CVE-2026-20230 is being exploited, and vulnerable WebDialer-enabled systems can be abused by unauthenticated attackers to write files.
Cisco patched it in 14SU6 and 15SU5.
Read: https://thehackernews.com/2026/06/cisco-unified-cm-flaw-exploited-after.html
π₯5π1
β‘ The crackdown on HuiOne is now widening.
The DoJ seized a cloud account tied to HuiOne subsidiaries, while Treasury sanctioned 9 people and 26 entities linked to Prince Group.
The focus: crypto scam proceeds, laundering, and the networks behind Southeast Asia scam operations.
Read π https://thehackernews.com/2026/06/doj-seizes-huione-cloud-account-tied-to.html
The DoJ seized a cloud account tied to HuiOne subsidiaries, while Treasury sanctioned 9 people and 26 entities linked to Prince Group.
The focus: crypto scam proceeds, laundering, and the networks behind Southeast Asia scam operations.
Read π https://thehackernews.com/2026/06/doj-seizes-huione-cloud-account-tied-to.html
π₯3π3β‘1π±1
Last Chance to Register for GRC Now | Get 8 Free CPEs
Join over 15K of your peers already registered for the July 8-9 GRC Now virtual event! Register and attend to explore the latest trends in GRC, cyber risk, practical strategies for AI governance, guidance for regulatory changes, and more.
β¨ Bonus: Youβll earn up to 8 free CPE credits for attending.
Register now: https://thn.news/grc-now-reshape-resilience
Join over 15K of your peers already registered for the July 8-9 GRC Now virtual event! Register and attend to explore the latest trends in GRC, cyber risk, practical strategies for AI governance, guidance for regulatory changes, and more.
β¨ Bonus: Youβll earn up to 8 free CPE credits for attending.
Register now: https://thn.news/grc-now-reshape-resilience
π2
Cybersecurity is losing the time buffer it used to depend on.
Agentic AI could compress the gap between finding a weakness and weaponizing it. That puts hidden IT, IoT, and OT assets directly in the blast path.
Know whatβs on your network before attacker automation does.
See why asset visibility matters now: https://thehackernews.com/2026/06/dawn-of-apex-agentic-adversary.html
Agentic AI could compress the gap between finding a weakness and weaponizing it. That puts hidden IT, IoT, and OT assets directly in the blast path.
Know whatβs on your network before attacker automation does.
See why asset visibility matters now: https://thehackernews.com/2026/06/dawn-of-apex-agentic-adversary.html
π2π1
π Cybercrime crews just lost part of their malware supply chain.
Operation Endgame disrupted infrastructure behind Amadey and StealC β malware used to steal data and deliver additional payloads.
Authorities say the operation led to:
- 326 servers dismantled
- 142 domains taken down
- 27M stolen credentials recovered
- $47 M+ in criminal crypto assets restricted
Read: https://thehackernews.com/2026/06/amadey-and-stealc-malware-network.html
Operation Endgame disrupted infrastructure behind Amadey and StealC β malware used to steal data and deliver additional payloads.
Authorities say the operation led to:
- 326 servers dismantled
- 142 domains taken down
- 27M stolen credentials recovered
- $47 M+ in criminal crypto assets restricted
Read: https://thehackernews.com/2026/06/amadey-and-stealc-malware-network.html
π₯10β‘3π3π3π€2