📡 Tech & Security Digest — 2026-06-13
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Oracle mitigates PeopleSoft zero-day exploited in data theft attacks — Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution…
- CISA orders feds to patch actively exploited Ivanti flaw by Sunday — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch an actively exploited Ivanti Sentry flaw within …
Hacker News
- Twenty One Zero-Days in FFmpeg (191 pts)
- Malware developers added nuclear and biological weapons text to to their spyware (378 pts)
- Adaptive PDFs (146 pts)
- There Is Life Before Main in Rust (78 pts)
- Shepherd’s Dog: A Game by the Most Dangerous AI Model (66 pts)
- Open source AI must win (842 pts)
- Show HN: Putt.day a daily mini golf game (157 pts)
Krebs on Security
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now — Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild.
The high-sever…
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities — The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to k…
- LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited…
- One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public — Security researchers have published a detailed, working exploit for a Linux kernel use-after-free that lets an unprivileged local user escalate to roo…
- Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE — A high-severity security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active …
- Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code — Veeam has released security patches to address a critical flaw in its Backup & Replication software that could result in remote code execution.
T…
- WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine — Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after p…
- LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution — Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain tha…
- CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol f…
- ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories — It’s been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there’s a supply…