📡 Tech & Security Digest — 2026-06-27
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- CISA sets urgent deadline to fix Cisco flaw exploited in attacks — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Com…
- FBI: Russian hackers now target Signal backup recovery keys — The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup …
- Polymarket customers lose $3 million in supply-chain attack — Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform’s front…
Hacker News
- Show HN: Hacker News on a train station-style flip board (65 pts)
- What happened after 2k people tried to hack my AI assistant (361 pts)
- Incident CVE-2026-LGTM (542 pts)
- U.S. allows Anthropic to release Mythos AI to ‘trusted’ US organizations (408 pts)
- OpenAI leans toward waiting until next year for IPO (164 pts)
Krebs on Security
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys — Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that’s installed on about 100,000 sites.
The…
- Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access — An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months b…
- Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root — Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unifie…
- New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets — DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough&nb…
- Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks — Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source sup…
- Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack — Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware famil…
- GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns — GitHub is moving to strengthen software supply chain security by updating “actions/checkout” to block pwn request attacks that exploit the risky use o…
- OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws — OpenAI on Monday said it’s releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative the a…
- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More — It’s Monday again.
This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to s…
- INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific — A new report from INTERPOL has revealed a “dramatic increase” in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet pe…