📡 Tech & Security Digest — 2026-06-24
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- The Exploit Doesn’t Exist. You Can Still Prove It Works Against You — Attackers can now weaponize newly disclosed vulnerabilities far faster than most organizations can patch them. Picus Security explains how security te…
- LastPass confirms data breach in Klue supply chain attack — LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company’s OAuth tokens in the Klue supply ch…
- WhatsApp phishing attack uses fake business docs to hack PCs — An ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote syst…
- Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks — A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks. […]…
- Webinar: Why email security teams are drowning in alerts — Phishing, BEC, and account takeover attacks continue to overwhelm security teams with alerts and investigations. This webinar explores how behavioral …
Hacker News
- Vulnerability reports are not special anymore (250 pts)
- Raspberry Pi Pico W as USB Wi-Fi Adapter (117 pts)
- Usbliter8: an A12/A13 SecureROM Exploit (138 pts)
Krebs on Security
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys — Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that’s installed on about 100,000 sites.
The…
- Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone — Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop…
- F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution — F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affe…
- Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week — Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber.
In a post …
- Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root — Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unifie…
- Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development — Microsoft has formally disclosed that it’s working to release a patch to address a Defender zero-day codenamed RoguePlanet.
The vulnerability has now…
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Con…
- China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth — Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS….
- GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns — GitHub is moving to strengthen software supply chain security by updating “actions/checkout” to block pwn request attacks that exploit the risky use o…
- OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws — OpenAI on Monday said it’s releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative the a…