๐จ CVE-2026-55200 now has public PoC code.
The libssh2 flaw lets a malicious SSH server trigger memory corruption in a connecting client.
> No credentials
> No user interaction
> Affected through libssh2 1.11.1
The real cleanup problem is finding bundled and static copies in curl, Git, PHP, and appliances.
Learn more โ https://thehackernews.com/2026/06/public-poc-released-for-critical.html
The libssh2 flaw lets a malicious SSH server trigger memory corruption in a connecting client.
> No credentials
> No user interaction
> Affected through libssh2 1.11.1
The real cleanup problem is finding bundled and static copies in curl, Git, PHP, and appliances.
Learn more โ https://thehackernews.com/2026/06/public-poc-released-for-critical.html
๐ฅ6
๐ Microsoft removed 119 Edge extensions hiding malware in images and fonts.
Up to 2.6 MILLION installs. They posed as ad blockers, VPNs, translators, and video downloaders.
Some payloads stole credentials and ran ad fraud.
Read how StegoAd stayed hidden for years โ https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html
Up to 2.6 MILLION installs. They posed as ad blockers, VPNs, translators, and video downloaders.
Some payloads stole credentials and ran ad fraud.
Read how StegoAd stayed hidden for years โ https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html
๐20๐ฅ2
The SOC problem is no longer just detection.
It is the queue.
AI is now taking the first pass on alert triage, enrichment, and routine response so analysts can focus on calls that carry risk.
The 2026 Cybersecurity Stars Awards winners show where SOC automation is headed.
Read the story: https://awards.thehackernews.com/blog/ai-reads-the-alert-queue/
It is the queue.
AI is now taking the first pass on alert triage, enrichment, and routine response so analysts can focus on calls that carry risk.
The 2026 Cybersecurity Stars Awards winners show where SOC automation is headed.
Read the story: https://awards.thehackernews.com/blog/ai-reads-the-alert-queue/
๐ค5
โ ๏ธ Gamaredon ran 35 phishing campaigns against Ukraine in 2025.
ESET says it used new PowerShell tools, HTML smuggling, and CVE-2025-8088 to plant malware in Startup.
Simple malware. Harder infrastructure.
Read more โ https://thehackernews.com/2026/06/gamaredon-expands-ukraine-attacks-with.html
ESET says it used new PowerShell tools, HTML smuggling, and CVE-2025-8088 to plant malware in Startup.
Simple malware. Harder infrastructure.
Read more โ https://thehackernews.com/2026/06/gamaredon-expands-ukraine-attacks-with.html
๐5๐คฏ3๐ฅ2๐ค1
๐ 236,493 scam domains.
Experts say DCloud Uni-App templates are being used to run fake crypto exchanges, #WhatsApp phishing, gambling scams, and wallet drainers.
Read the full story โ https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html
Experts say DCloud Uni-App templates are being used to run fake crypto exchanges, #WhatsApp phishing, gambling scams, and wallet drainers.
Read the full story โ https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html
๐ฑ4๐ฅ2๐2
๐ EvilTokens hides account takeover risk from your SOC.
Static URL analysis misses it as the phishing page appears only after browser-side decryption. Avoid visibility gaps and accelerate response by uncovering the full attack flow in 1 min.
Read โ https://thn.news/ghost-analysis-2023
Static URL analysis misses it as the phishing page appears only after browser-side decryption. Avoid visibility gaps and accelerate response by uncovering the full attack flow in 1 min.
Read โ https://thn.news/ghost-analysis-2023
๐ฅ9๐4
Your encrypted credentials may not stay encrypted forever.
Attackers can harvest them now, store them, and decrypt them later when quantum hardware catches up.
That is why post-quantum migration should start with long-lived credentials and machine identities.
Read the full story: https://thehackernews.com/2026/06/why-post-quantum-cryptography-starts.html
Attackers can harvest them now, store them, and decrypt them later when quantum hardware catches up.
That is why post-quantum migration should start with long-lived credentials and machine identities.
Read the full story: https://thehackernews.com/2026/06/why-post-quantum-cryptography-starts.html
๐10๐ฑ2๐1๐ค1
โ ๏ธ Mustang Panda hid C2 in cloud traffic.
Acronis says the China-aligned group abused Zoho WorkDrive as a command channel in campaigns against Indian government and hydropower targets.
ZOHOMURK read commands from an inbox folder and wrote stolen output to an outbox.
Read ๐ https://thehackernews.com/2026/06/mustang-panda-uses-zoho-workdrive-as.html
Acronis says the China-aligned group abused Zoho WorkDrive as a command channel in campaigns against Indian government and hydropower targets.
ZOHOMURK read commands from an inbox folder and wrote stolen output to an outbox.
Read ๐ https://thehackernews.com/2026/06/mustang-panda-uses-zoho-workdrive-as.html
๐ค5๐2
โก DirtyClone leads the week, but the rest of the queue is ugly:
๐ง Linux root bug
๐จ PTC exploited
๐ Gaslight malware
๐ฏ Turla backdoor
๐งน StealC takedown
๐ค Agent prompt injection
๐ต๏ธ New infostealers
๐บ DVR proxy abuse
๐งฉ Urgent CVEs
Full recap: https://thehackernews.com/2026/06/weekly-recap-linux-kernel-flaws-ai.html
๐ง Linux root bug
๐จ PTC exploited
๐ Gaslight malware
๐ฏ Turla backdoor
๐งน StealC takedown
๐ค Agent prompt injection
๐ต๏ธ New infostealers
๐บ DVR proxy abuse
๐งฉ Urgent CVEs
Full recap: https://thehackernews.com/2026/06/weekly-recap-linux-kernel-flaws-ai.html
๐6๐ฅ2โก1
๐ฅ #WhatsApp is finally getting usernames.
The app has started global username reservations before a wider rollout later this year.
So people can message each other without handing over a phone number.
Details here: https://thehackernews.com/2026/06/whatsapp-is-finally-getting-usernames.html
The app has started global username reservations before a wider rollout later this year.
So people can message each other without handing over a phone number.
Details here: https://thehackernews.com/2026/06/whatsapp-is-finally-getting-usernames.html
๐ฅ26๐13๐9๐4
๐ The extension did not need to steal passwords to be dangerous.
Microsoft found a fake #Perplexity Chrome extension that logged searches and address bar input before redirecting users to real results.
How it worked, and what users should check: https://thehackernews.com/2026/06/malicious-perplexity-chrome-extension.html
Microsoft found a fake #Perplexity Chrome extension that logged searches and address bar input before redirecting users to real results.
How it worked, and what users should check: https://thehackernews.com/2026/06/malicious-perplexity-chrome-extension.html
๐คฏ4๐ฅ3๐2๐2
๐จ Oracle E-Business Suite has a new active exploitation problem.
CVE-2026-46817 is a CVSS 9.8 flaw in Oracle Payments that can allow unauthenticated HTTP takeover.
No public PoC. Attribution unknown.
Read the full report: https://thehackernews.com/2026/06/oracle-e-business-suite-flaw-cve-2026.html
CVE-2026-46817 is a CVSS 9.8 flaw in Oracle Payments that can allow unauthenticated HTTP takeover.
No public PoC. Attribution unknown.
Read the full report: https://thehackernews.com/2026/06/oracle-e-business-suite-flaw-cve-2026.html
๐ค4๐ฅ3๐2โก1๐คฏ1
โก Apple patched WebKit bugs found with AI tools.
The updates fix 30+ flaws across:
> iOS 26.5.2
> macOS Tahoe 26.5.2
> Safari 26.5.2
The fixes include WebKit CVEs, sandbox issues, and kernel-level bugs.
Details: https://thehackernews.com/2026/06/apple-patches-30-ios-macos-safari-flaws.html
The updates fix 30+ flaws across:
> iOS 26.5.2
> macOS Tahoe 26.5.2
> Safari 26.5.2
The fixes include WebKit CVEs, sandbox issues, and kernel-level bugs.
Details: https://thehackernews.com/2026/06/apple-patches-30-ios-macos-safari-flaws.html
โ ๏ธ Public PoC is out for CVE-2026-8037, a critical Progress Kemp LoadMaster API flaw.
It lets unauthenticated attackers run root commands when the API is enabled.
Patch now. Restrict API exposure.
Full story: https://thehackernews.com/2026/06/progress-kemp-loadmaster-flaw-could-let.html
It lets unauthenticated attackers run root commands when the API is enabled.
Patch now. Restrict API exposure.
Full story: https://thehackernews.com/2026/06/progress-kemp-loadmaster-flaw-could-let.html
๐คฏ1
๐ฎ Tell an AI browser itโs just playing a game.
Researchers say "BioShocking" tricked six AI agents, including #ChatGPT Atlas, Comet, and #Claude, into copying GitHub SSH credentials from a signed-in session.
Read how the attack chain worked: https://thehackernews.com/2026/06/new-bioshocking-attack-tricks-ai.html
Researchers say "BioShocking" tricked six AI agents, including #ChatGPT Atlas, Comet, and #Claude, into copying GitHub SSH credentials from a signed-in session.
Read how the attack chain worked: https://thehackernews.com/2026/06/new-bioshocking-attack-tricks-ai.html
๐ฅ3๐3๐1
๐จ Nearby file sharing has a local blind spot.
Researchers found six flaws in AirDrop and Quick Share that can crash sharing services, bypass Samsung session checks, and trigger a crash in Googleโs Windows app.
Apple and Google have started fixes.
Read: https://thehackernews.com/2026/06/airdrop-and-quick-share-flaws-let.html
Researchers found six flaws in AirDrop and Quick Share that can crash sharing services, bypass Samsung session checks, and trigger a crash in Googleโs Windows app.
Apple and Google have started fixes.
Read: https://thehackernews.com/2026/06/airdrop-and-quick-share-flaws-let.html