๐จ Russian intelligence-linked phishers have a new Signal trick.
FBI and CISA say they are asking targets to share their Signal Backup Recovery Key.
If they get it, they can restore old backups, read message history, and take over the account.
Hereโs how the phishing works: https://thehackernews.com/2026/06/fbi-warns-russian-intelligence-hackers.html
FBI and CISA say they are asking targets to share their Signal Backup Recovery Key.
If they get it, they can restore old backups, read message history, and take over the account.
Hereโs how the phishing works: https://thehackernews.com/2026/06/fbi-warns-russian-intelligence-hackers.html
๐ฅ12๐5๐คฏ3๐ฑ1
๐ Gaslight doesnโt just steal from #macOS.
It tries to talk the analystโs AI tools out of analyzing it.
SentinelOne found a Rust-based implant with #Telegram C2 and 38 fake โsystemโ messages built to make LLM-assisted triage abort or refuse.
Read: https://thehackernews.com/2026/06/new-gaslight-macos-malware-uses-prompt.html
It tries to talk the analystโs AI tools out of analyzing it.
SentinelOne found a Rust-based implant with #Telegram C2 and 38 fake โsystemโ messages built to make LLM-assisted triage abort or refuse.
Read: https://thehackernews.com/2026/06/new-gaslight-macos-malware-uses-prompt.html
๐8
โก OpenAI is keeping GPT-5.6 behind a narrow gate.
Sol, Terra, and Luna are in limited preview for government-approved partners.
Sol adds stronger cyber safeguards for #vulnerability research, defensive testing, and dual-use requests.
Read: https://thehackernews.com/2026/06/openai-limits-gpt-56-rollout-as-sol.html
Sol, Terra, and Luna are in limited preview for government-approved partners.
Sol adds stronger cyber safeguards for #vulnerability research, defensive testing, and dual-use requests.
Read: https://thehackernews.com/2026/06/openai-limits-gpt-56-rollout-as-sol.html
๐16๐ค6๐คฏ6๐ฅ1
๐ A fake support SMS was the entry point.
Ukraineโs SSU and the FBI say Russian intelligence services targeted messaging accounts used by officials, military personnel, politicians, and activists.
The goal: steal credentials and sensitive information.
How the campaign worked: https://thehackernews.com/2026/06/ukraine-says-russian-intelligence-used.html
Ukraineโs SSU and the FBI say Russian intelligence services targeted messaging accounts used by officials, military personnel, politicians, and activists.
The goal: steal credentials and sensitive information.
How the campaign worked: https://thehackernews.com/2026/06/ukraine-says-russian-intelligence-used.html
๐9๐4โก3๐ฅ3๐ค2
โ ๏ธ A trusted VS Code workspace can trigger the attack.
Hijacked npm packages used hidden folder-open tasks instead of npm lifecycle scripts.
JavaScript was hidden as a font file, resolved through blockchain dead drops, and used to deploy a Python infostealer.
Learn more โ https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html
Hijacked npm packages used hidden folder-open tasks instead of npm lifecycle scripts.
JavaScript was hidden as a font file, resolved through blockchain dead drops, and used to deploy a Python infostealer.
Learn more โ https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html
๐1๐1
๐จ CVE-2026-55200 now has public PoC code.
The libssh2 flaw lets a malicious SSH server trigger memory corruption in a connecting client.
> No credentials
> No user interaction
> Affected through libssh2 1.11.1
The real cleanup problem is finding bundled and static copies in curl, Git, PHP, and appliances.
Learn more โ https://thehackernews.com/2026/06/public-poc-released-for-critical.html
The libssh2 flaw lets a malicious SSH server trigger memory corruption in a connecting client.
> No credentials
> No user interaction
> Affected through libssh2 1.11.1
The real cleanup problem is finding bundled and static copies in curl, Git, PHP, and appliances.
Learn more โ https://thehackernews.com/2026/06/public-poc-released-for-critical.html
๐ฅ6
๐ Microsoft removed 119 Edge extensions hiding malware in images and fonts.
Up to 2.6 MILLION installs. They posed as ad blockers, VPNs, translators, and video downloaders.
Some payloads stole credentials and ran ad fraud.
Read how StegoAd stayed hidden for years โ https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html
Up to 2.6 MILLION installs. They posed as ad blockers, VPNs, translators, and video downloaders.
Some payloads stole credentials and ran ad fraud.
Read how StegoAd stayed hidden for years โ https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html
๐20๐ฅ2
The SOC problem is no longer just detection.
It is the queue.
AI is now taking the first pass on alert triage, enrichment, and routine response so analysts can focus on calls that carry risk.
The 2026 Cybersecurity Stars Awards winners show where SOC automation is headed.
Read the story: https://awards.thehackernews.com/blog/ai-reads-the-alert-queue/
It is the queue.
AI is now taking the first pass on alert triage, enrichment, and routine response so analysts can focus on calls that carry risk.
The 2026 Cybersecurity Stars Awards winners show where SOC automation is headed.
Read the story: https://awards.thehackernews.com/blog/ai-reads-the-alert-queue/
๐ค5
โ ๏ธ Gamaredon ran 35 phishing campaigns against Ukraine in 2025.
ESET says it used new PowerShell tools, HTML smuggling, and CVE-2025-8088 to plant malware in Startup.
Simple malware. Harder infrastructure.
Read more โ https://thehackernews.com/2026/06/gamaredon-expands-ukraine-attacks-with.html
ESET says it used new PowerShell tools, HTML smuggling, and CVE-2025-8088 to plant malware in Startup.
Simple malware. Harder infrastructure.
Read more โ https://thehackernews.com/2026/06/gamaredon-expands-ukraine-attacks-with.html
๐5๐คฏ3๐ฅ2๐ค1
๐ 236,493 scam domains.
Experts say DCloud Uni-App templates are being used to run fake crypto exchanges, #WhatsApp phishing, gambling scams, and wallet drainers.
Read the full story โ https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html
Experts say DCloud Uni-App templates are being used to run fake crypto exchanges, #WhatsApp phishing, gambling scams, and wallet drainers.
Read the full story โ https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html
๐ฑ4๐ฅ2๐2
๐ EvilTokens hides account takeover risk from your SOC.
Static URL analysis misses it as the phishing page appears only after browser-side decryption. Avoid visibility gaps and accelerate response by uncovering the full attack flow in 1 min.
Read โ https://thn.news/ghost-analysis-2023
Static URL analysis misses it as the phishing page appears only after browser-side decryption. Avoid visibility gaps and accelerate response by uncovering the full attack flow in 1 min.
Read โ https://thn.news/ghost-analysis-2023
๐ฅ9๐4
Your encrypted credentials may not stay encrypted forever.
Attackers can harvest them now, store them, and decrypt them later when quantum hardware catches up.
That is why post-quantum migration should start with long-lived credentials and machine identities.
Read the full story: https://thehackernews.com/2026/06/why-post-quantum-cryptography-starts.html
Attackers can harvest them now, store them, and decrypt them later when quantum hardware catches up.
That is why post-quantum migration should start with long-lived credentials and machine identities.
Read the full story: https://thehackernews.com/2026/06/why-post-quantum-cryptography-starts.html
๐10๐ฑ2๐1๐ค1
โ ๏ธ Mustang Panda hid C2 in cloud traffic.
Acronis says the China-aligned group abused Zoho WorkDrive as a command channel in campaigns against Indian government and hydropower targets.
ZOHOMURK read commands from an inbox folder and wrote stolen output to an outbox.
Read ๐ https://thehackernews.com/2026/06/mustang-panda-uses-zoho-workdrive-as.html
Acronis says the China-aligned group abused Zoho WorkDrive as a command channel in campaigns against Indian government and hydropower targets.
ZOHOMURK read commands from an inbox folder and wrote stolen output to an outbox.
Read ๐ https://thehackernews.com/2026/06/mustang-panda-uses-zoho-workdrive-as.html
๐ค5๐2
โก DirtyClone leads the week, but the rest of the queue is ugly:
๐ง Linux root bug
๐จ PTC exploited
๐ Gaslight malware
๐ฏ Turla backdoor
๐งน StealC takedown
๐ค Agent prompt injection
๐ต๏ธ New infostealers
๐บ DVR proxy abuse
๐งฉ Urgent CVEs
Full recap: https://thehackernews.com/2026/06/weekly-recap-linux-kernel-flaws-ai.html
๐ง Linux root bug
๐จ PTC exploited
๐ Gaslight malware
๐ฏ Turla backdoor
๐งน StealC takedown
๐ค Agent prompt injection
๐ต๏ธ New infostealers
๐บ DVR proxy abuse
๐งฉ Urgent CVEs
Full recap: https://thehackernews.com/2026/06/weekly-recap-linux-kernel-flaws-ai.html
๐6๐ฅ2โก1
๐ฅ #WhatsApp is finally getting usernames.
The app has started global username reservations before a wider rollout later this year.
So people can message each other without handing over a phone number.
Details here: https://thehackernews.com/2026/06/whatsapp-is-finally-getting-usernames.html
The app has started global username reservations before a wider rollout later this year.
So people can message each other without handing over a phone number.
Details here: https://thehackernews.com/2026/06/whatsapp-is-finally-getting-usernames.html
๐ฅ26๐13๐9๐4
๐ The extension did not need to steal passwords to be dangerous.
Microsoft found a fake #Perplexity Chrome extension that logged searches and address bar input before redirecting users to real results.
How it worked, and what users should check: https://thehackernews.com/2026/06/malicious-perplexity-chrome-extension.html
Microsoft found a fake #Perplexity Chrome extension that logged searches and address bar input before redirecting users to real results.
How it worked, and what users should check: https://thehackernews.com/2026/06/malicious-perplexity-chrome-extension.html
๐คฏ5๐ฅ3๐2๐2
๐จ Oracle E-Business Suite has a new active exploitation problem.
CVE-2026-46817 is a CVSS 9.8 flaw in Oracle Payments that can allow unauthenticated HTTP takeover.
No public PoC. Attribution unknown.
Read the full report: https://thehackernews.com/2026/06/oracle-e-business-suite-flaw-cve-2026.html
CVE-2026-46817 is a CVSS 9.8 flaw in Oracle Payments that can allow unauthenticated HTTP takeover.
No public PoC. Attribution unknown.
Read the full report: https://thehackernews.com/2026/06/oracle-e-business-suite-flaw-cve-2026.html
๐ค5๐ฅ3๐2โก1๐คฏ1
โก Apple patched WebKit bugs found with AI tools.
The updates fix 30+ flaws across:
> iOS 26.5.2
> macOS Tahoe 26.5.2
> Safari 26.5.2
The fixes include WebKit CVEs, sandbox issues, and kernel-level bugs.
Details: https://thehackernews.com/2026/06/apple-patches-30-ios-macos-safari-flaws.html
The updates fix 30+ flaws across:
> iOS 26.5.2
> macOS Tahoe 26.5.2
> Safari 26.5.2
The fixes include WebKit CVEs, sandbox issues, and kernel-level bugs.
Details: https://thehackernews.com/2026/06/apple-patches-30-ios-macos-safari-flaws.html
โ ๏ธ Public PoC is out for CVE-2026-8037, a critical Progress Kemp LoadMaster API flaw.
It lets unauthenticated attackers run root commands when the API is enabled.
Patch now. Restrict API exposure.
Full story: https://thehackernews.com/2026/06/progress-kemp-loadmaster-flaw-could-let.html
It lets unauthenticated attackers run root commands when the API is enabled.
Patch now. Restrict API exposure.
Full story: https://thehackernews.com/2026/06/progress-kemp-loadmaster-flaw-could-let.html
๐คฏ1
๐ฎ Tell an AI browser itโs just playing a game.
Researchers say "BioShocking" tricked six AI agents, including #ChatGPT Atlas, Comet, and #Claude, into copying GitHub SSH credentials from a signed-in session.
Read how the attack chain worked: https://thehackernews.com/2026/06/new-bioshocking-attack-tricks-ai.html
Researchers say "BioShocking" tricked six AI agents, including #ChatGPT Atlas, Comet, and #Claude, into copying GitHub SSH credentials from a signed-in session.
Read how the attack chain worked: https://thehackernews.com/2026/06/new-bioshocking-attack-tricks-ai.html
๐ฅ4๐4๐1
๐จ Nearby file sharing has a local blind spot.
Researchers found six flaws in AirDrop and Quick Share that can crash sharing services, bypass Samsung session checks, and trigger a crash in Googleโs Windows app.
Apple and Google have started fixes.
Read: https://thehackernews.com/2026/06/airdrop-and-quick-share-flaws-let.html
Researchers found six flaws in AirDrop and Quick Share that can crash sharing services, bypass Samsung session checks, and trigger a crash in Googleโs Windows app.
Apple and Google have started fixes.
Read: https://thehackernews.com/2026/06/airdrop-and-quick-share-flaws-let.html
๐2