📡 Tech & Security Digest — 2026-06-30
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Critical SimpleHelp flaw exploited to deploy new stealer malware — Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented c…
- NAIC says public data stolen in ShinyHunters’ PeopleSoft breach — The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, an…
- CISA: Windows BlueHammer flaw now exploited by ransomware gangs — CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has…
- Nissan discloses employee data breach linked to Oracle zero-day attacks — Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerabili…
- Hackers now exploit critical Oracle E-Business flaw in attacks — Attackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to thr…
- CISA sets urgent deadline to fix Cisco flaw exploited in attacks — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Com…
- Clean GitHub repo tricks AI coding agents into running malware — An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisibl…
- FBI: Russian hackers now target Signal backup recovery keys — The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup …
Hacker News
- HackerRank open sourced its ATS. My resume scored 90/100. Oh wait 74. No – 88 (974 pts)
- .self: A new top-level domain designed to support self-hosting (498 pts)
Krebs on Security
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access — An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months b…
- Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse — A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against…
- Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild — A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber.
The vulnerabil…
- ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More — This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door…
- Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root — Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unifie…
- New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets — DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough&nb…
- Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks — Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source sup…
- Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs — Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities…
- Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack — Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware famil…
- GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns — GitHub is moving to strengthen software supply chain security by updating “actions/checkout” to block pwn request attacks that exploit the risky use o…