📡 Tech & Security Digest — 2026-06-16
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks — Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attack…
- CISA warns of another cPanel plugin flaw exploited in attacks — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an acti…
- Chinese hackers breach REDCap servers, steal medical research — A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institutio…
- Ransomware gang abuses Microsoft Teams relays to hide malicious traffic — DragonForce ransomware used a custom malware named ‘Backdoor.Turn’ to hide command-and-control traffic inside Microsoft Teams relay infrastructure. [….
Hacker News
- How memory safety CVEs differ between Rust and C/C++ (134 pts)
- A backdoor in a LinkedIn job offer (1223 pts)
- I hacked into the worst e-bike and fixed it [video] (100 pts)
- Ask HN: Has anyone replaced Claude/GPT with a local model for daily coding? (1028 pts)
The Hacker News
- Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now — Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild.
The high-sever…
- Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware — The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft …
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities — The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to k…
- Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week — Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber.
In a post …
- Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE — A high-severity security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active …
- Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code — Veeam has released security patches to address a critical flaw in its Backup & Replication software that could result in remote code execution.
T…
- WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine — Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after p…
- Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw — Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild…
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication — Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file …
- LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution — Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain tha…