vulnerability CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day The Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive (BOD) 22-01, requiring U.S. federal agencies to patch a critical zero-day vulnerability in Check Point’s Remote Acces… BleepingComputer · Jun 9, 2026 High CVE-2026-50751CVE-2024-24919zero-dayvpnikev1
vulnerability Google patches new Chrome zero-day flaw exploited in the wild Google has released a security update to address a newly discovered and actively exploited zero-day vulnerability (CVE-2026-11645) within the Chrome browser. This flaw, originating in the V8 JavaScript engine, allows att… BleepingComputer · Jun 9, 2026 High CVE-2026-11645CVE-2024-0519CVE-2026-2441zero-daychromev8
threat-intel When “Hi, This Is IT” Comes Through Microsoft Teams This report details a tactic employed by threat actors, primarily Cloaked Ursa (APT29), to compromise organizations by impersonating IT departments within Microsoft Teams. The attackers leverage trusted communication cha… Palo Alto Unit 42 · Jun 8, 2026 High microsoft teamssocial engineeringmfa
malware NFCShare Android malware spreads via fake banking app updates on GitHub A new variant of the NFCShare Android malware is spreading through fake updates for banking apps hosted on GitHub, targeting financial institutions across Europe. The malware leverages NFC technology to steal payment car… BleepingComputer · Jun 8, 2026 High ITSPGEnfcandroidbanking
data-breach SoFi confirms third-party data breach at Hong Kong subsidiary SoFi Hong Kong is warning that it suffered a data breach after hackers gained access to a database at a third-party vendor containing customer information. BleepingComputer · Jun 8, 2026 High
threat-intel Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks The Silent Ransom group is conducting a targeted extortion campaign against US law firms, utilizing a sophisticated multi-stage attack chain involving vishing, IT impersonation, and physical intrusions. Google’s Mandiant… Dark Reading · Jun 8, 2026 High USvishingsocial engineeringremote access
supply-chain New Shai-Hulud attack trojanizes 19 science-focused PyPI packages A new supply-chain attack, dubbed Shai-Hulud, has compromised 19 popular Python packages hosted on the PyPI, distributing a trojan designed to steal developer secrets. The malware leverages a chain of execution to downlo… BleepingComputer · Jun 8, 2026 High supply-chainpythonsecrets
threat-intel UK gives big tech 3 months to create device controls to block nude images of kids The UK government is mandating that major tech companies, including Apple and Google, implement device controls within three months to block nude images of children from smartphones and tablets. This initiative aims to c… The Record · Jun 8, 2026 High UKchild sexual abuseonline safetydevice security
threat-intel Iran Signed a Ceasefire — Its Hackers Didn't This Dark Reading article discusses the ongoing cyber warfare between Iran and the United States, highlighting a significant loophole in international conflict rules. Following a ceasefire extension, U.S. agencies warned… Dark Reading · Jun 8, 2026 High IRUSIScyberwarfarecritical infrastructureiran
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th) This report details the ongoing TeamPCP supply chain campaign, which has recently seen increased activity and expanded impact. CISA has formally acknowledged and addressed the campaign, adding vulnerabilities to its Know… SANS Internet Storm Center · Jun 8, 2026 High CVE-2026-45321CVE-2026-48027CVE-2026-8398USsupply chainnpmgithub
threat-intel WhatsApp says NSO targeted users with spearfishing attacks in violation of court order WhatsApp has accused NSO Group of violating a court order by conducting spearfishing attacks against its users, utilizing social engineering techniques to lure individuals into clicking malicious links. This follows a pr… The Record · Jun 8, 2026 High USspear-phishingsocial-engineeringspyware
vulnerability Gogs patches critical zero-day enabling remote code execution A critical zero-day vulnerability in Gogs, a remote collaboration platform, has been identified, allowing authenticated attackers to execute remote code and access private repositories. The flaw, present in versions up t… BleepingComputer · Jun 8, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPremote-code-executionzero-dayauthentication
supply-chain 'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud A new wave of attacks, dubbed the 'Hades' campaign, has targeted the Python Package Index (PyPI) with a variant of the Shai-Hulud worm. This campaign involved compromising 37 PyPI wheels and 19 code packages, utilizing a… Dark Reading · Jun 8, 2026 High USsupply-chainpythonopen-source
threat-intel Everybody Is Vibe Coding But Nobody Told the Security Team This article discusses the emerging security challenges posed by "vibe coding," a new approach to software development heavily reliant on AI-assisted tools. Rapid, AI-driven application development, particularly using pl… SecurityWeek · Jun 8, 2026 High UKaivibe-codingshadow-ai
threat-intel Russia upgrades rules for its digital spy system to better track citizens online Russia has updated its SORM (System for Operative Investigative Activities) digital surveillance system to enhance its capabilities for tracking citizens online. The updated regulations expand the data accessible through… The Record · Jun 8, 2026 High RUsurveillancedigital privacyinternet monitoring
threat-intel ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More This week’s security news highlights a series of attacks and vulnerabilities, including a supply chain attack targeting Microsoft GitHub repositories via the Miasma Worm, a zero-day exploit in Android, and ongoing cyberc… The Hacker News · Jun 8, 2026 High CVE-2025-48595CVE-2026-28318CVE-2026-39210CHUSGEsupply-chainzero-daycybercrime
vulnerability Check Point links VPN zero-day attacks to Qilin ransomware gang Check Point identified a zero-day vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access deployments, exploited by the Qilin ransomware gang. The flaw allowed unauthenticated attackers to bypass authen… BleepingComputer · Jun 8, 2026 High CVE-2026-50751CVE-2026-50752ISJAAUzero-dayvpnauthentication
threat-intel AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload This article discusses the increasing challenge of AI-powered phishing attacks overwhelming Security Operations Centers (SOCs). Attackers are leveraging AI to create more convincing and varied phishing campaigns, leading… The Hacker News · Jun 8, 2026 High USphishingaisoc
threat-intel Cybersecurity M&A Roundup: 26 Deals Announced in May 2026 In May 2026, several cybersecurity firms announced a significant wave of mergers and acquisitions, primarily focused on expanding capabilities in areas like AI-powered security, zero trust architectures, and endpoint pro… SecurityWeek · Jun 8, 2026 High ISUKUSm&aai securityzero trust
threat-intel The Hardest Fork This article discusses a concerning trend in the open-source software ecosystem – the emergence of sophisticated, chained vulnerabilities, potentially driven by actors like Move 37. While the specific 'Mythos' model may… The Hacker News · Jun 8, 2026 High USCHopen sourcevulnerabilitysupply chain