📡 Tech & Security Digest — 2026-06-19
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Apple fixes Beats Studio Buds flaw that let hackers spy on conversations — Apple has released security updates to patch a high-severity flaw affecting the Beats Studio Buds wireless earbuds that could allow attackers in Bluet…
- ShapedPlugin update flow hacked to infect WordPress sites — Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack that distributed infected releases to paying customers via the …
- F5 issues out-of-band patches for critical NGINX vulnerabilities — Cybersecurity company F5 has released out-of-band security updates to address multiple NGINX web server vulnerabilities, including two critical-severi…
Hacker News
- I found 10k GitHub repositories distributing Trojan malware (798 pts)
- Apple A12 and A13 Chips: New Unpatchable Exploit (24 pts)
- Noam Shazeer Joins OpenAI (329 pts)
Krebs on Security
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone — Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop…
- F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution — F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affe…
- Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware — The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft …
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities — The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to k…
- Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week — Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber.
In a post …
- Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development — Microsoft has formally disclosed that it’s working to release a patch to address a Defender zero-day codenamed RoguePlanet.
The vulnerability has now…
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Con…
- Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw — Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild…
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication — Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file …
- LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution — Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain tha…