📡 Tech & Security Digest — 2026-06-25
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access — New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create …
- Malicious Edge extension abuses Native Messaging as bridge to malware — A malicious Microsoft Edge extension dubbed ‘Edgecution’ has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based …
- CISA warns of max severity Ubiquiti flaws exploited in attacks — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers actively exploiting flaws in Ubiquity UniFi OS and Lantronix se…
- The Exploit Doesn’t Exist. You Can Still Prove It Works Against You — Attackers can now weaponize newly disclosed vulnerabilities far faster than most organizations can patch them. Picus Security explains how security te…
- Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks — A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks. […]…
Hacker News
- Zero-Downtime Deployments with Docker Compose – No Kubernetes Required (50 pts)
- Exploiting vulnerabilities in Johnson and Johnson web apps (82 pts)
- Anthropic says Alibaba illicitly extracted Claude AI model capabilities (389 pts)
- OpenAI unveils its first custom chip, built by Broadcom (690 pts)
- RubyLLM: A Ruby framework for all major AI providers (384 pts)
Krebs on Security
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys — Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that’s installed on about 100,000 sites.
The…
- Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access — An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months b…
- Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone — Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop…
- F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution — F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affe…
- Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root — Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unifie…
- Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development — Microsoft has formally disclosed that it’s working to release a patch to address a Defender zero-day codenamed RoguePlanet.
The vulnerability has now…
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Con…
- Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks — Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source sup…
- GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns — GitHub is moving to strengthen software supply chain security by updating “actions/checkout” to block pwn request attacks that exploit the risky use o…
- OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws — OpenAI on Monday said it’s releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative the a…