malware NFCShare Android malware spreads via fake banking app updates on GitHub A new variant of the NFCShare Android malware is spreading through fake updates for banking apps hosted on GitHub, targeting financial institutions across Europe. The malware leverages NFC technology to steal payment car… BleepingComputer · Jun 8, 2026 High ITSPGEnfcandroidbanking
threat-intel AI Slop Will Kill Cybersecurity Storytelling If We Let It This Dark Reading article discusses the growing concern that AI-generated content is eroding the quality and credibility of cybersecurity storytelling. Elizabeth Safran argues that relying solely on AI for content creati… Dark Reading · Jun 8, 2026 Medium aicontentnarrative
data-breach SoFi confirms third-party data breach at Hong Kong subsidiary SoFi Hong Kong is warning that it suffered a data breach after hackers gained access to a database at a third-party vendor containing customer information. BleepingComputer · Jun 8, 2026 High
New Apple feature automatically changes your compromised passwords At WWDC 26, Apple announced an Apple Intelligence-powered feature that can automatically fix weak and compromised passwords. This works in Safari, and it's rolling out with iOS 27. BleepingComputer · Jun 8, 2026
threat-intel Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks The Silent Ransom group is conducting a targeted extortion campaign against US law firms, utilizing a sophisticated multi-stage attack chain involving vishing, IT impersonation, and physical intrusions. Google’s Mandiant… Dark Reading · Jun 8, 2026 High USvishingsocial engineeringremote access
supply-chain New Shai-Hulud attack trojanizes 19 science-focused PyPI packages A new supply-chain attack, dubbed Shai-Hulud, has compromised 19 popular Python packages hosted on the PyPI, distributing a trojan designed to steal developer secrets. The malware leverages a chain of execution to downlo… BleepingComputer · Jun 8, 2026 High supply-chainpythonsecrets
vulnerability Check Point VPN Flaw Exploited Since Early May A critical zero-day vulnerability (CVE-2026-50751) in Check Point's Security Gateways and Spark Firewalls has been exploited since early May by a Qilin ransomware affiliate. The flaw, involving a logic flaw in certificat… Dark Reading · Jun 8, 2026 Critical CVE-2026-50751CVE-2026-50752zero-dayikev1vpn
threat-intel UK gives big tech 3 months to create device controls to block nude images of kids The UK government is mandating that major tech companies, including Apple and Google, implement device controls within three months to block nude images of children from smartphones and tablets. This initiative aims to c… The Record · Jun 8, 2026 High UKchild sexual abuseonline safetydevice security
vulnerability One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public A critical vulnerability, CVE-2026-23111, has been discovered in the Linux kernel’s nf_tables packet-filtering code, allowing unprivileged users to escalate to root access and break out of containers. The flaw, initially… The Hacker News · Jun 8, 2026 Critical CVE-2026-23111linuxkerneluse-after-free
threat-intel Iran Signed a Ceasefire — Its Hackers Didn't This Dark Reading article discusses the ongoing cyber warfare between Iran and the United States, highlighting a significant loophole in international conflict rules. Following a ceasefire extension, U.S. agencies warned… Dark Reading · Jun 8, 2026 High IRUSIScyberwarfarecritical infrastructureiran
phishing WhatsApp says it disrupted new NSO spyware phishing attacks WhatsApp has detected and stopped spear-phishing campaigns allegedly conducted by the NSO Group after investigating user reports of social engineering attacks. BleepingComputer · Jun 8, 2026 Medium
A Security Raises $37 Million for Autonomous Offensive Security Platform The company founded by Yossi Torati, Omer Gull, and Yuval Itzchakov has emerged from stealth mode. The post A Security Raises $37 Million for Autonomous Offensive Security Platform appeared first on SecurityWeek . SecurityWeek · Jun 8, 2026
threat-intel Armenia’s pro-Europe party wins election despite Russia-linked disinformation Armenia’s parliamentary election saw the pro-Europe Civil Contract party secure a significant victory, despite a large-scale disinformation campaign orchestrated by Russia-linked actors. This campaign utilized tactics su… The Record · Jun 8, 2026 Medium RUAMUSdisinformationinfluence_operationcyberattack
phishing Meta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order Meta on Monday said it detected and blocked spear-phishing attempts linked to Israeli spyware vendor NSO Group. In addition, the tech giant said it's filing a federal court contempt order against the company for violatin… The Hacker News · Jun 8, 2026 Medium
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th) This report details the ongoing TeamPCP supply chain campaign, which has recently seen increased activity and expanded impact. CISA has formally acknowledged and addressed the campaign, adding vulnerabilities to its Know… SANS Internet Storm Center · Jun 8, 2026 High CVE-2026-45321CVE-2026-48027CVE-2026-8398USsupply chainnpmgithub
vulnerability Critical Zcash Vulnerability Found and Fixed If you’re a user—owner?—of this cryptocurrency, this is important: On May 29, the security researcher Taylor Hornby found a critical vulnerability in Zcash Orchard privacy pool using Claude Opus 4.8. The Zcash team hired… Schneier on Security · Jun 8, 2026 Critical
threat-intel WhatsApp says NSO targeted users with spearfishing attacks in violation of court order WhatsApp has accused NSO Group of violating a court order by conducting spearfishing attacks against its users, utilizing social engineering techniques to lure individuals into clicking malicious links. This follows a pr… The Record · Jun 8, 2026 High USspear-phishingsocial-engineeringspyware
vulnerability Gogs patches critical zero-day enabling remote code execution A critical zero-day vulnerability in Gogs, a remote collaboration platform, has been identified, allowing authenticated attackers to execute remote code and access private repositories. The flaw, present in versions up t… BleepingComputer · Jun 8, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPremote-code-executionzero-dayauthentication
supply-chain 'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud A new wave of attacks, dubbed the 'Hades' campaign, has targeted the Python Package Index (PyPI) with a variant of the Shai-Hulud worm. This campaign involved compromising 37 PyPI wheels and 19 code packages, utilizing a… Dark Reading · Jun 8, 2026 High USsupply-chainpythonopen-source
vulnerability Critical UniFi OS bug lets hackers gain root without authentication A critical vulnerability in UniFi OS Server versions 5.0.6 and earlier allows attackers to gain root access without authentication by chaining three previously identified flaws. This vulnerability, detailed by Bishop Fox… BleepingComputer · Jun 8, 2026 Critical CVE-2026-34908CVE-2026-34909CVE-2026-34910remote code executionroot accessauthentication bypass