data-breach Nissan Employee Data Breached in Oracle PeopleSoft Hack Only a handful of the 100 organizations targeted in the PeopleSoft campaign have been confirmed. The post Nissan Employee Data Breached in Oracle PeopleSoft Hack appeared first on SecurityWeek . SecurityWeek · Jun 30, 2026 High CVE-2026-35273
vulnerability Critical SimpleHelp Vulnerability Exploited for Malware Delivery A critical vulnerability (CVE-2026-48558) in SimpleHelp RMM software allowed unauthorized access and subsequent malware deployment. The flaw, related to OpenID Connect authentication, enabled attackers to gain full techn… SecurityWeek · Jun 30, 2026 Critical CVE-2026-48558USoidcauthenticationmalware
threat-intel New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials A LayerX security firm discovered a new attack technique, dubbed BioShocking, that exploits AI browsers to trick users into revealing their login credentials. The method involves manipulating the AI browser into believin… The Hacker News · Jun 30, 2026 High N/aiprompt injectioncredential theft
vulnerability Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth A critical vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster allows unauthenticated attackers to execute arbitrary commands as root by manipulating API requests. The flaw stems from a lack of proper sanitization… The Hacker News · Jun 30, 2026 Critical CVE-2026-8037CVE-2026-33691CVE-2024-1212CAcommand-injectionrootapi
threat-intel Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs Apple released a significant security update addressing over 30 vulnerabilities across its iOS, macOS, and Safari platforms. Notably, several WebKit vulnerabilities were identified using AI tools, highlighting a new tren… The Hacker News · Jun 30, 2026 Medium CVE-2026-43707CVE-2026-43716CVE-2026-43745webkitaivulnerability
Quantifind Raises $200 Million for AI-Native Risk Intelligence Quantifind will accelerate international expansion and extend its platform’s localized risk intelligence capabilities. The post Quantifind Raises $200 Million for AI-Native Risk Intelligence appeared first on SecurityWee… SecurityWeek · Jun 30, 2026
vulnerability New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking CISA has published an advisory to inform organizations about three vulnerabilities found by a researcher in Daktronics controllers. The post New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking appe… SecurityWeek · Jun 30, 2026
vulnerability Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper… The Hacker News · Jun 30, 2026 Critical CVE-2026-46817CVE-2025-61882CVE-2026-35273
ISC Stormcast For Tuesday, June 30th, 2026 https://isc.sans.edu/podcastdetail/9988, (Tue, Jun 30th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. SANS Internet Storm Center · Jun 30, 2026
threat-intel NIST Enrichment Reductions Impact CVE Coverage, Accuracy This article reports on a reduction in in-depth analysis of vulnerabilities by the National Institute of Standards and Technology (NIST), impacting the National Vulnerability Database (NVD). Research by Volerion revealed… Dark Reading · Jun 29, 2026 Medium CVE-2026-8856vulnerabilitynistcvss
threat-intel 'Djinn' Stealer Targets Cloud, AI Credentials The ‘Djinn’ stealer, delivered via a SimpleHelp vulnerability (CVE-2026-48558), is targeting cloud and AI credentials, specifically focusing on developer and administrator environments. Blackpoint Cyber’s APG tracked an… Dark Reading · Jun 29, 2026 High CVE-2026-48558DKaicredentialsstealer
threat-intel Vulnerabilities Expose Private Data in Indian Government Systems A security researcher discovered 14 vulnerabilities across multiple Indian government IT systems, including portals for education, civil service, and scholarships. These vulnerabilities exposed sensitive personal data, s… Dark Reading · Jun 29, 2026 High INvulnerabilitydata-breachidentity-access-management
threat-intel Can Clothes Make You Invisible to Facial Recognition? This Dark Reading article details a research project spearheaded by Bill Swearingen aimed at developing clothing designs to evade facial recognition technology. Swearingen’s approach focuses on exploiting weaknesses in f… Dark Reading · Jun 29, 2026 Medium USfacial recognitionsurveillanceai
threat-intel Iran, Russia, China Target Water Systems for Sabotage A DomainTools report details ongoing nation-state targeting of water systems by Iran, Russia, and China, primarily through exploiting weak passwords, exposed PLCs, and HMI vulnerabilities. The motivations behind these at… Dark Reading · Jun 29, 2026 High IRRUCHcritical infrastructurenation-statewater systems
threat-intel Justices rule that cellphone location histories are protected by the Fourth Amendment The Supreme Court ruled that police use of cellphone location history data obtained from tech companies constitutes a Fourth Amendment search and requires a warrant. This decision effectively rejects the "third-party doc… The Record · Jun 29, 2026 High USfourth amendmentlocation trackingprivacy
malware Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input A malicious Chrome extension disguised as the Perplexity AI search engine was discovered by Microsoft, intercepting user searches and address bar input. The extension secretly logged this data by routing it through an at… The Hacker News · Jun 29, 2026 High chromeextensiondata collection
US racks up about 400 wins over illegal World Cup streaming sites The World Cup’s organizing body, FIFA, helped identify hundreds of domains taken down in an action organized by the U.S. Department of Justice, along with the help of U.S. broadcaster NBC Universal and other entities. The Record · Jun 29, 2026
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private WhatsApp on Monday officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three billion users on the messaging platform. The optional feature is designed to hel… The Hacker News · Jun 29, 2026
vulnerability Factoring RSA Keys with Many Zeros Interesting research on a new class of weak RSA keys: keys with lots of zeros. It turns out that these keys are out in the wild. The badkeys project is an open-source service that checks public keys for known vulnerabili… Schneier on Security · Jun 29, 2026 High
WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy An optional ‘username key’ adds another layer by requiring a secondary credential before someone can message users. The post WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy appeared first on Securit… SecurityWeek · Jun 29, 2026