BlueHammer CVE: Ransomware Gangs Actively Exploit Microsoft Defender Privilege Escalation Flaw
June 30, 2026 CISA confirmed on Monday that ransomware gangs are now actively exploiting a high-severity Microsoft Defender privilege escalation vulnerability known as BlueHammer. The flaw, tracked as CVE-2026-33825, was originally leaked as a zero-day…
macOS ClickFix Attack Silently Deploys AMOS Infostealer via Fake CAPTCHA Terminal Commands
June 28, 2026 Security researchers at Palo Alto Networks Unit 42 have uncovered a new macOS ClickFix campaign that uses Terminal commands to silently download, mount, and execute infostealing malware. The campaign targets Mac users with fake CAPTCHA…
Polymarket Supply-Chain Attack Drains Million in Crypto via Frontend Compromise
June 28, 2026 Polymarket, a $9 billion cryptocurrency-based prediction market platform, disclosed on June 26, 2026, that attackers stole approximately $3 million from customers through a frontend supply-chain attack. Consequently, the breach exploited a…
Amazon Q Developer CVE Malicious MCP Configs Steal Cloud Credentials
June 26, 2026 A high-severity vulnerability in Amazon Q Developer could allow malicious repositories to run arbitrary commands and steal a developer’s cloud credentials. The flaw, tracked as CVE-2026-12957 with a CVSS score of 8.5, was disclosed by…
Cisco Unified CM CVE-2026-20230: Active Exploitation Confirmed
June 24, 2026 A critical server-side request forgery vulnerability in Cisco Unified Communications Manager is now under active exploitation in the wild. Threat intelligence firm Defused confirmed attacks against CVE-2026-20230 over the weekend, marking a…
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
June 24, 2026 Cybersecurity researchers at Novee Security have disclosed a critical new class of CI/CD workflow vulnerabilities called Cordyceps. This flaw allows unauthenticated attackers to hijack GitHub Actions workflows and seize full control of…
Xsolis Data Breach Exposes 1.4 Million Patient Records in Healthcare AI Firm
June 23, 2026 Healthcare technology firm Xsolis disclosed a data breach on June 23, 2026, that compromised the personal and protected health information of nearly 1.4 million individuals. Furthermore, the incident began with a targeted phishing attack on…
Squidbleed CVE-2026-47729: 29-Year Squid Proxy Bug Leaks HTTP Credentials
June 22, 2026 Researchers disclosed a critical heap over-read vulnerability in Squid Proxy that has existed since 1997. CVE-2026-47729, nicknamed Squidbleed, lets a trusted attacker on the same proxy leak another user’s cleartext HTTP requests.…
Unpatchable Exploit for Apple A12 and A13 SecureROM
June 21, 2026 Security researchers at Paradigm Shift have disclosed usbliter8. It is an unpatchable exploit that achieves arbitrary code execution inside Apple’s A12 and A13 SecureROM. This vulnerability was published on June 18, 2026, following…