📡 Tech & Security Digest — 2026-06-21
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Klue OAuth breach victim list grows as Icarus hackers claim attack — Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect t…
- CISA: Splunk Enterprise flaw actively exploited, patch by Sunday — CISA has urged U.S. federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in a…
- Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin — Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites. [….
- Microsoft links Mastra AI supply chain attack to North Korean hackers — Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire…
- Webinar: How attackers bypass MFA and how defenders can respond — Modern phishing attacks, including Device Code phishing, can undermine MFA protections and grant attackers access to corporate accounts without steali…
Hacker News
- Linux eliminates the strncpy API after six years of work, 360 patches (201 pts)
- Show HN: Ember, a native iOS Hacker News reader I built around accessibility (94 pts)
- Temporary Cloudflare accounts for AI agents (206 pts)
Krebs on Security
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys — Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that’s installed on about 100,000 sites.
The…
- Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone — Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop…
- F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution — F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affe…
- Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware — The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft …
- Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week — Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber.
In a post …
- Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development — Microsoft has formally disclosed that it’s working to release a patch to address a Defender zero-day codenamed RoguePlanet.
The vulnerability has now…
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Con…
- Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw — Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild…
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication — Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file …
- China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth — Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS….