📡 Tech & Security Digest — 2026-06-14
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Oracle mitigates PeopleSoft zero-day exploited in data theft attacks — Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution…
- CISA orders feds to patch actively exploited Ivanti flaw by Sunday — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch an actively exploited Ivanti Sentry flaw within …
Hacker News
- Don’t trust large context windows (77 pts)
- Python 3.14 garbage collection rigamarole (52 pts)
- Pyodide 314.0: Python packages can now publish WebAssembly wheels to PyPI (123 pts)
- Police officer investigated for using AI to ‘create evidence’ in multiple cases (318 pts)
- AI coding at home without going broke (287 pts)
- The state of building user interfaces in Rust (186 pts)
- AI OSS tool repo goes archived over night after raising $7.3M Seed (259 pts)
Krebs on Security
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now — Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild.
The high-sever…
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities — The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to k…
- LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited…
- One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public — Security researchers have published a detailed, working exploit for a Linux kernel use-after-free that lets an unprivileged local user escalate to roo…
- Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE — A high-severity security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active …
- Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code — Veeam has released security patches to address a critical flaw in its Backup & Replication software that could result in remote code execution.
T…
- WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine — Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after p…
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication — Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file …
- LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution — Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain tha…
- ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories — It’s been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there’s a supply…