📡 Tech & Security Digest — 2026-06-18
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Microsoft working on Defender patch for RoguePlanet zero-day — Microsoft confirmed that it’s working on a security patch for a Defender zero-day vulnerability named “RoguePlanet,” disclosed one week ago. […]…
- Kodak confirms data breach claimed by ShinyHunters extortion gang — Kodak has confirmed that it’s working with external cybersecurity experts to investigate a security breach after hackers gained access to some of the …
- CISA orders feds to patch max severity Joomla plugin flaw by Friday — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity flaw in the Widget Factory J…
Hacker News
- The hacker sent by Anthropic to calm the government’s nerves about AI safety (78 pts)
- US holds off blacklisting DeepSeek, more than 100 firms deemed security risks (459 pts)
Krebs on Security
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware — The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft …
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities — The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to k…
- Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week — Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber.
In a post …
- Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE — A high-severity security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active …
- Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development — Microsoft has formally disclosed that it’s working to release a patch to address a Defender zero-day codenamed RoguePlanet.
The vulnerability has now…
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Con…
- Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw — Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild…
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication — Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file …
- LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution — Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain tha…
- China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth — Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS….