UNC6508 Abuses Google Workspace Rules to Steal US Medical and Defense Research
June 16, 2026 Google’s Threat Intelligence Group has disrupted a China-nexus espionage campaign that hid inside North American medical and military research networks for more than a year. The threat actor, tracked as UNC6508, abused legitimate…
Cisco SD-WAN Zero-Day CVE-2026-20262: Active Root Exploit
June 15, 2026 Cisco has patched a critical zero-day vulnerability in its Catalyst SD-WAN Manager platform. The flaw, tracked as CVE-2026-20262, allows authenticated remote attackers to overwrite files and escalate to root privileges. CISA added the…
Novo Nordisk Clinical Trial Data Breach Exposes Patient and HCP Records
June 15, 2026 Danish pharmaceutical giant Novo Nordisk, the world’s largest insulin producer and maker of blockbuster GLP-1 drugs Wegovy and Ozempic, has disclosed a significant data breach. Attackers gained unauthorized access to internal IT…
FBI Dismantles Outsider Enterprise AI Phishing Ring: $1.9B in Losses
June 14, 2026 The FBI, working alongside Google and Black Lotus Labs, has dismantled a massive China-based phishing-as-a-service operation called Outsider Enterprise. This AI-powered cybercrime ring operated thousands of fake websites and sent millions…
US Government Orders Anthropic Fable 5 Suspension Over Jailbreak
June 13, 2026 The US government issued an export control directive ordering Anthropic to suspend access to Fable 5 and Mythos 5 for all users worldwide. The order, issued on June 12, 2026, cites national security concerns over a reported jailbreak of the…
Arch Linux AUR Supply Chain Attack: 400+ Packages Hijacked with Rootkit and Infostealer
June 12, 2026 Attackers hijacked more than 400 packages in the Arch Linux community repository this week. Furthermore, the malicious build scripts installed a Rust credential stealer and an optional eBPF rootkit on developer workstations. This Arch Linux…
French Government Tchap Messenger Breach Exposes 73,000 Public Sector Accounts
June 12, 2026 The French government disclosed a breach of its Tchap encrypted messaging platform that affects over 73,000 public sector employees. Attackers compromised a user account and scraped data from public chat rooms, exposing names, email…
Oracle PeopleSoft CVE-2026-35273: ShinyHunters Zero-Day RCE Under Active Exploit | June 2026
June 11, 2026 Oracle has issued an emergency security alert for CVE-2026-35273, a critical zero-day vulnerability in PeopleSoft Enterprise PeopleTools that enables unauthenticated remote code execution. The ShinyHunters extortion gang is actively…
Ivanti Sentry CVE Root RCE Under Active Exploit
June 11, 2026 Attackers are actively exploiting CVE-2026-10520, a maximum-severity vulnerability in Ivanti Sentry that allows unauthenticated root remote code execution on exposed secure mobile gateways. The flaw was patched on June 9, 2026, but threat…
Proto6: Six protobuf.js Vulnerabilities Expose Node.js Apps to RCE and DoS
June 10, 2026 Cybersecurity researchers at Cyera have disclosed six vulnerabilities — collectively codenamed Proto6 — in protobuf.js, a widely deployed JavaScript and TypeScript implementation of Google’s Protocol Buffers data serialization format.…