vulnerability Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active… The Hacker News · Jun 2, 2026 Critical CVE-2025-48595
threat-intel White House unveils pared-back AI executive order The White House has released a revised executive order addressing artificial intelligence, significantly shortening the mandatory review period for AI model releases from 90 days to 30 days, responding to industry pressu… The Record · Jun 2, 2026 Medium USaicybersecurityregulation
threat-intel Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine The Gamaredon group is exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy a multi-stage malware campaign targeting Ukraine. This campaign utilizes GammaWorm and GammaSteel, designed for data theft and persistenc… The Hacker News · Jun 2, 2026 High CVE-2025-8088CVE-2026-21509RUUAwinrarmalwarevulnerability
vulnerability Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of a… The Hacker News · Jun 2, 2026 High CVE-2024-21182CVE-2026-21962
Microsoft Exchange Online outage causes email delays, failures Microsoft is working to address a widespread service issue affecting the mail flow pipeline for Exchange Online customers across North America and Germany. BleepingComputer · Jun 2, 2026
threat-intel Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis This SecurityWeek article examines the evolving cybersecurity crisis, highlighting a shift in focus from traditional vulnerability management to the challenges of rapid exploit development and runtime visibility. The rep… SecurityWeek · Jun 2, 2026 High airuntimepatching
threat-intel Russia claims foreign spy agencies hacked officials' phones Russia's FSB has accused foreign intelligence agencies of conducting a large-scale espionage operation targeting senior Russian officials through the use of malware installed on their mobile devices. The agency alleges t… The Record · Jun 2, 2026 High RUUNEUespionagesurveillanceforeign interference
phishing Instagram users locked out after Meta AI abused to steal accounts Instagram accounts were compromised due to attackers exploiting Meta’s AI-powered support tools to impersonate legitimate owners. Users were tricked into verifying their identities via AI-generated selfies, bypassing tra… BleepingComputer · Jun 2, 2026 High USaisocial mediaaccount takeover
vulnerability Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk A critical vulnerability was discovered in six Microsoft 365 Android apps – Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote – due to a debug flag left enabled in production code. This allowed… SecurityWeek · Jun 2, 2026 Critical CVE-2026-41100USdebugaccess tokensupply chain
vulnerability Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks. The post Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 2, 2026 Critical CVE-2025-48595CVE-2026-0059
threat-intel Why the browser is now the front line for AI security This BleepingComputer article highlights the escalating threat of AI-powered phishing attacks, primarily targeting the browser environment. Adversaries are leveraging AI to rapidly create and deploy phishing kits, automa… BleepingComputer · Jun 2, 2026 High USaiphishingbrowser
vulnerability Anthropic Expanding Mythos Access to 150 New Organizations Only approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products. The post Anthropic Expanding Mythos Access to 150 New Organizations appeared first o… SecurityWeek · Jun 2, 2026
supply-chain Red Hat removes tainted packages after software pipeline compromise Red Hat removed numerous software packages from its distribution pipeline after a compromised GitHub account was used to distribute credential-stealing malware. The attack, utilizing a variant of the Mini Shai-Hulud worm… The Record · Jun 2, 2026 High NOUKsupply chaingithubmalware
vulnerability CISA flags two-year-old Oracle flaw as actively exploited in attacks CISA has identified a two-year-old Oracle WebLogic Server vulnerability (CVE-2024-21182) as actively being exploited in attacks, prompting a directive for federal agencies to immediately patch their systems. The vulnerab… BleepingComputer · Jun 2, 2026 High CVE-2024-21182CVE-2025-61884CVE-2026-21992oracleweblogicvulnerability
threat-intel The Zero-Knowledge Threat Actor and the End of Responsible Disclosure This article discusses the rise of ‘zero-knowledge’ threat actors, empowered by AI, who pose a significant new challenge to cybersecurity. These actors, lacking deep technical expertise, can rapidly discover and exploit… SecurityWeek · Jun 2, 2026 High aivulnerabilityphishing
vulnerability Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches A critical vulnerability (CVE-2026-0826) has been identified in HP Poly Voice VoIP phone models, allowing for remote code execution with root privileges. The flaw, triggered by a stack-based buffer overflow when processi… SecurityWeek · Jun 2, 2026 Critical CVE-2026-0826USvoipbuffer overflowremote code execution
threat-intel Wardriving assessment across Mexico: Preparing for the 2026 World Cup Kaspersky GReAT conducted a wardriving assessment across Mexico City, Guadalajara, and Monterrey to analyze public Wi-Fi infrastructure ahead of the 2026 FIFA World Cup. The study, focused on passive observation and infr… Securelist · Jun 2, 2026 Medium MXpublic wifiwireless securityssid analysis
threat-intel Beyond Assume-Breach: How AI-Native Security Will Reshape Enterprise Defense This Dark Reading article discusses the evolving landscape of enterprise security, predicting a shift towards AI-native defenses driven by dynamic threats and increasing complexity. The article highlights the move away f… Dark Reading · Jun 2, 2026 High aimicrospheressecurity fabric
threat-intel CISA and Partners Urge Hardening Automatic Tank Gauge Systems CISA, alongside several US government agencies, has issued an alert regarding malicious cyber activity targeting Automatic Tank Gauge (ATG) systems used across sectors like energy, chemicals, and transportation. Cyber ac… CISA Advisories · Jun 2, 2026 High oticstank gauges