**
Ravie Lakshmanan **
Jun 11, 2026
Hacking News / Cybersecurity News
It’s been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. …
**
The Hacker News **
Jun 11, 2026
Cybersecurity Innovations and Excellence
Most good security work is invisible by design. Today is the exception.
The 2026 Cybersecurity Stars Awards winners are …
A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while …
**
Ravie Lakshmanan **
Jun 11, 2026
Endpoint Security / Vulnerability
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed …
Two security teams have shown, in separate research published this week, that OpenClaw , the popular self-hosted AI agent, can be driven to run attacker-controlled code or hand over sensitive data …
Back in 2023, I wrote a diary[ 1 ] discussing how commonly X-Frame-Options and CSP headers containing the frame-ancestors directive were used on 1 million most popular domains on the internet (based …
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment …
**
Ravie Lakshmanan **
Jun 10, 2026
Cyber Attack / Vulnerability
ServiceNow has warned about a security incident in which unknown threat actors exploited a flaw to obtain deeper unauthorized access to …
NSO Group Hacking WhatsApp Despite Court Order WhatsApp has caught the NSO Group phishing its users, in violation of a court order.
Tags: courts , hacking , phishing , spyware , WhatsApp
Posted on …
On June 9, Anthropic released Claude Fable 5 , the most capable model it has ever made, generally available. It also did something unusual: it shipped one model as two products, split not by …
**
The Hacker News **
Jun 10, 2026
Pentesting / Security Validation
Your pentest report looks clean. That might be the problem.
Run automated pentesting long enough, and the new findings start to dry …
Microsoft on Tuesday released fixes for a record 206 security vulnerabilities impacting its software portfolio, including three flaws that have been publicly disclosed at the time of release.
Of the …
**
Ravie Lakshmanan **
Jun 10, 2026
Vulnerability / Open Source
A high-severity unpatched security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) …
**
Ravie Lakshmanan **
Jun 10, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new vulnerabilities to its Known Exploited …
**
Ravie Lakshmanan **
Jun 10, 2026
Vulnerability / Patch Management
Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in …
Cybersecurity researchers have warned of a “resurgence and expansion” of JDY , a covert network associated with China-nexus state-sponsored threat actors.
“The JDY botnet comprises …
Microsoft June 2026 Patch Tuesday Published 2026-06-09. Last Updated 2026-06-09 17:34:29 UTC by Johannes Ullrich (Version: 1)
0 comment(s)
Microsoft today released patches for 204 vulnerabilities. 38 …
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch …
GPS As a Key Distribution Platform This is interesting:
> The U.S. military has likely been quietly broadcasting codes for its global encryption network using public GPS for nearly 20 years, …
Organizations have more visibility than ever. Growing tech stacks provide greater coverage, and network security teams are increasingly adopting AI and automation to help with routine tasks and reduce …
A malicious website can work out which sites you visit and which apps you open, using nothing but JavaScript and the timing of your SSD. The attack, called FROST , needs no native code, no extension, …
University of Toronto researchers have built and tested a proof-of-concept AI-driven computer worm that uses a locally hosted open-weight large language model to reason its way through a network, …
**
Ravie Lakshmanan **
Jun 09, 2026
Vulnerability / Browser Security
Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the …