vulnerability Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws Microsoft released its June 2026 Patch Tuesday updates, addressing a significant number of vulnerabilities across its product suite. The updates include five publicly disclosed zero-day vulnerabilities, one of which is c… BleepingComputer · Jun 9, 2026 High zero-daypatchvulnerability
vulnerability Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws Microsoft released its June 2026 Patch Tuesday updates, addressing a significant number of vulnerabilities across its product suite. The updates included three previously unknown zero-day exploits and a total of 200 othe… BleepingComputer · Jun 9, 2026 High zero-daypatchmicrosoft
vulnerability Microsoft June 2026 Patch Tuesday, (Tue, Jun 9th) Microsoft today released patches for 204 vulnerabilities. 38 of these vulnerabilities are considered critical, and three have been disclosed before today. Six of the vulnerabilities affect Microsoft cloud solutions and d… SANS Internet Storm Center · Jun 9, 2026 High CVE-2026-49160CVE-2026-47291CVE-2026-45648
vulnerability OpenSSL Patches High-Severity Vulnerability Found With AI A total of 18 vulnerabilities have been patched in the latest OpenSSL releases, including many that were potentially discovered by AI. The post OpenSSL Patches High-Severity Vulnerability Found With AI appeared first on… SecurityWeek · Jun 9, 2026 High CVE-2026-45447
supply-chain Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues Microsoft is investigating a recent security incident involving the compromise of 73 open-source GitHub repositories as part of the ongoing "Miasma" supply chain attack. The attackers, utilizing a technique involving inf… The Hacker News · Jun 9, 2026 High supply chainopen sourceinformation stealer
supply-chain GitHub disables Microsoft repos pushing password-stealing malware Microsoft repositories on GitHub were temporarily disabled on June 5th due to concerns about distributing malware, specifically linked to the ongoing Miasma/Shai-Hulud supply-chain campaign. The incident involved the com… BleepingComputer · Jun 9, 2026 High USsupply-chain attackgithubmalware
threat-intel Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs Russian threat actors, including Shadow-Earth-066 (UAC-0226) and Earth Dahu (Primitive Bear, Shuckworm), are continuing to exploit a long-standing vulnerability (CVE-2025-8088) in WinRAR to conduct data theft and cyber e… Dark Reading · Jun 9, 2026 High CVE-2025-8088CVE-2023-38831RUUAwinrarvulnerabilitycyberespionage
threat-intel Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation Anthropic’s Claude Mythos AI model has demonstrated the ability to rapidly generate working exploits for known vulnerabilities in software like Firefox and Windows, significantly accelerating the attack process. The mode… SecurityWeek · Jun 9, 2026 High USaiexploitationn-day
vulnerability New Veeam vulnerability exposes backup servers to RCE attacks Veeam has released security updates to patch a critical Backup & Replication security flaw that can be exploited to gain remote code execution (RCE) on domain-joined backup servers. BleepingComputer · Jun 9, 2026 High CVE-2026-44963CVE-2024-40711
threat-intel Hackers pose as women seeking romance to spy on Russian soldiers A previously unknown cyber espionage group, SiribClone, has been targeting Russian military personnel by impersonating women seeking romantic relationships. The group’s primary goal is to gather battlefield intelligence… The Record · Jun 9, 2026 High RUespionagesocial-engineeringmobile-malware
threat-intel WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine A vulnerability in WinRAR, first identified in July 2025, is being exploited by Russia-aligned cyber groups to deploy malware targeting Ukrainian organizations. The attackers, including Earth Dahu and SHADOW-EARTH-066, a… The Hacker News · Jun 9, 2026 High CVE-2025-8088RUUAwinrarexploitukraine
vulnerability SAP Patches Critical NetWeaver, Commerce Vulnerabilities The flaws could lead to the disclosure of sensitive information, memory corruption, and disruption of normal system usage. The post SAP Patches Critical NetWeaver, Commerce Vulnerabilities appeared first on SecurityWeek… SecurityWeek · Jun 9, 2026 High CVE-2026-44748CVE-2026-27671CVE-2026-22732
vulnerability Siemens KACO Blueplanet Inverters This advisory from CISA details vulnerabilities within Siemens KACO Blueplanet Inverters, a series of industrial inverters used in energy systems. The vulnerabilities, specifically a CRC16-based algorithm for generating… CISA Advisories · Jun 9, 2026 High CVE-2025-40946CVE-2026-41125WOindustrial control systemsvulnerabilityauthentication
vulnerability Schneider Electric EcoStruxure Panel Server Schneider Electric has identified a vulnerability in its EcoStruxure Panel Server product line, specifically versions prior to 002.006.000. This vulnerability, classified as CWE-1188, allows for potential unauthorized au… CISA Advisories · Jun 9, 2026 High CVE-2026-6866FRcwe-1188firmwareauthentication
vulnerability Schneider Electric Modicon Network Managed Switches Schneider Electric has identified a vulnerability (CVE-2024-3596) in its Modicon Network Managed Switches due to a misconfigured RADIUS protocol. Specifically, disabling the RADIUS Server Message Authenticator option mak… CISA Advisories · Jun 9, 2026 High CVE-2024-3596WOradiuscvesecurity
supply-chain Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks A new wave of Shai-Hulud supply chain attacks has impacted over 471 NPM and PyPI packages, utilizing variants named Miasma and Hades. The attacks, originating from TeamPCP, involve credential harvesting and self-replicat… SecurityWeek · Jun 9, 2026 High supply chainnpmpypi
data-breach French govt messaging service breached in account hijacking attack The French government’s Tchap messaging service was breached after a compromised user account was used to gain access, leading to the theft of sensitive data including user information and over 13.5GB of files. The attac… BleepingComputer · Jun 9, 2026 High FRsocial engineeringdata theftmessaging
threat-intel New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing A new attack method, dubbed FROST, allows websites to track which sites and apps a user opens by analyzing the timing of SSD reads. Developed by researchers at Graz University of Technology, FROST leverages the Origin Pr… The Hacker News · Jun 9, 2026 High DEopfsssdtiming attack
supply-chain Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer A new supply chain attack, dubbed Hades, is leveraging the Miasma campaign to compromise 37 PyPI packages, including those used in bioinformatics and computational biology. The attack utilizes a malicious setup.pth file… The Hacker News · Jun 9, 2026 High RUsupply-chainpythoncredential-stealing
threat-intel Cybercriminals: the 'auditors' you never hired This article explores the psychological phenomenon of ‘normalcy bias’ – our tendency to underestimate risk and assume things will always go as they have in the past – and how it contributes to a persistent rise in cybera… WeLiveSecurity · Jun 9, 2026 High UKIRcognitive biasnormalcy biascybersecurity