Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 16:34 09/06/2026 UTC
  • Case Case score 59 Check Point IKEv1 VPN Authentication Bypass Exploitation and Response Check Point disclosed that CVE-2026-50751 is being actively exploited as an authentication bypass in Remote Access VPN and Mobile Access deployments using deprecated IKEv1, reaching a few dozen organizations and including at least one case tied to Qilin ransomware activity.
  • Case Case score 60 Gamaredon and UAC-0226 WinRAR exploitation in Ukrainian organizations Trend Micro attributed ongoing WinRAR CVE-2025-8088 exploitation against Ukrainian organizations to Earth Dahu and SHADOW-EARTH-066, showing the attacks still run nearly a year after the patch and use RAR-ADS, startup LNK, PowerShell loaders, and credential-stealing follow-on tooling.
  • Case Case score 59 Gogs Rebase Injection Remote Code Execution and 0.14.3 Patch Response Gogs maintainers shipped 0.14.3 to fix a critical argument-injection zero-day in the rebase-before-merging workflow, closing an RCE path exploitable by authenticated non-admin users that could expose private repositories and secrets.
  • Security Patch Release H score 59 LiteLLM endpoint-hardening patch release (CVE-2026-42271) CISA added LiteLLM CVE-2026-42271 to the KEV catalog after evidence of active exploitation, raising immediate risk from command injection against proxy-host MCP test endpoints that was only hardened via the 1.83.7 release.
  • Security Patch Release H score 59 Check Point security patch release for CVE-2026-50751 Check Point issued patches for CVE-2026-50751 and disclosed related CVE-2026-50752 guidance, urging urgent migration away from deprecated IKEv1 and enforcement changes such as IKEv2-only and machine certificate authentication.
  • Campaign H score 57 Earth Dahu and SHADOW-EARTH-066 WinRAR exploitation campaign against Ukrainian organisations Trend Micro’s attribution of Earth Dahu and SHADOW-EARTH-066 to continued WinRAR CVE-2025-8088 exploitation advances the ongoing response by tying observed payload chains (GIFTEDCROOK, GammaPhish/GammaLoad/GammaSteel) to the same legacy RAR weaponization techniques.
Last updated: 18:50 08/06/2026 UTC

Latest updates

Browse →

Microsoft hit by cyberattack

Incident

Updated: 09.06.2026 18:42 · First: 09.06.2026 18:42 · 📰 2 src / 2 articles · H score: 14

A Microsoft GitHub repository removal incident in June 2026 disrupted continuous integration pipelines and briefly broke Azure/functions-action workflows used by developers. Microsoft later said it had temporarily removed some GitHub repositories while investigating potential malicious content, then restored some repos and kept others offline during the review. The incident was tied to a broader Miasma supply-chain campaign that compromised 73 open-source projects to inject an information stealer and prompted Microsoft to notify a small number of customers who may have pulled content from the affected repositories.

Miasma software supply chain campaign expands to new PyPI wave

Campaign

Updated: 09.06.2026 19:34 · First: 09.06.2026 19:34 · 📰 1 src / 1 articles · H score: 36

The Miasma supply-chain campaign has expanded into a new PyPI wave, increasing the risk that developers and downstream users will ingest information-stealing malware through trusted open-source packages. The latest cluster adds 23 packages and shows that the operators are changing delivery methods rather than relying on a single implant format.

Survey finds pressure to delay security reporting and widespread deployment of vulnerable code across 14 countries

Trend

Updated: 09.06.2026 18:30 · First: 09.06.2026 18:30 · 📰 1 src / 1 articles · H score: 16

A Checkmarx survey found that pressure to delay security reporting is pushing vulnerable code into production across 14 countries, increasing the chance that known flaws reach live systems. 95% of CISOs said they faced pressure to deprioritize or delay reporting of security issues, and 75% said their organizations knowingly deployed vulnerable code. Remediation is also lagging, with only 9% fixing over 90% of vulnerabilities within 90 days. The pattern shows that business deadlines and AI-generated code are widening the gap between discovery and fix.

AI coding assistant adoption becomes near-universal while governance lags in software development teams

Trend

Updated: 09.06.2026 18:00 · First: 09.06.2026 18:00 · 📰 1 src / 1 articles · H score: 16

AI coding assistants are now used by 97% of software engineers and DevOps professionals, but only 30% have fully governed oversight, leaving security and compliance controls behind adoption. The most common assistants are GitHub Copilot and Claude Code, and many teams run more than one tool. The gap is shifting work toward manual review, security testing, and vulnerability fixing, which slows delivery and raises code-risk exposure.

Veeam Backup & Replication domain-joined backup server RCE flaw (CVE-2026-44963)

Vulnerability

Updated: 09.06.2026 17:27 · First: 09.06.2026 17:27 · 📰 1 src / 1 articles · H score: 40

The CVE-2026-44963 flaw in Veeam Backup & Replication exposes domain-joined backup servers to remote code execution until admins move to 12.3.2.4854. The issue affects VBR 12.3.2.4465 and earlier version 12 builds, creating elevated risk for backup infrastructure that is joined to a Windows domain.

Veeam security patch release for CVE-2026-44963

Security Patch Release

Updated: 09.06.2026 17:27 · First: 09.06.2026 17:27 · 📰 1 src / 1 articles · H score: 48

Veeam released security updates for Veeam Backup & Replication to fix CVE-2026-44963, a critical flaw that could enable remote code execution on domain-joined backup servers. The issue affects VBR 12.3.2.4465 and earlier version 12 builds, while 12.3.2.4854 contains the fix. Version 13.x is not affected. Administrators running impacted builds need to deploy the patched release promptly to reduce exposure to code execution on backup infrastructure.

PhpBB authentication bypass flaw

Vulnerability

Updated: 09.06.2026 17:00 · First: 09.06.2026 17:00 · 📰 1 src / 1 articles · H score: 25

A critical phpBB authentication bypass now exposes versions up to 3.3.16 and the 4.0.0 alpha to account takeover, including administrators, through one unauthenticated request. The flaw affects standard installs in default database-authentication mode, so a normal deployment can be vulnerable out of the box. phpBB 3.3.17 is the complete fix and affected operators need to upgrade.

PhpBB 3.3.17 security update

Security Patch Release

Updated: 09.06.2026 17:00 · First: 09.06.2026 17:00 · 📰 1 src / 1 articles · H score: 23

phpBB released version 3.3.17 to fix PTT-2026-004 and PTT-2026-005, closing account-takeover flaws affecting forum deployments. The update is the only complete fix for PTT-2026-004 and requires administrators to upgrade.

Earth Dahu and SHADOW-EARTH-066 WinRAR exploitation campaign against Ukrainian organisations

Campaign

Updated: 09.06.2026 15:26 · First: 09.06.2026 15:26 · 📰 1 src / 1 articles · H score: 57

The Earth Dahu and SHADOW-EARTH-066 campaigns are still exploiting CVE-2025-8088 in WinRAR against Ukrainian organisations, extending exposure nearly a year after the patch and enabling stealer and espionage payloads. One chain uses crafted RAR archives with hidden ADS payloads, a Startup-folder LNK, and a PowerShell loader to launch GIFTEDCROOK and exfiltrate credentials and documents. The other chain uses an HTA-to-VBScript sequence to deliver GammaPhish, GammaLoad, and GammaSteel, showing sustained access and a shift to dedicated C2 infrastructure.

Gamaredon WinRAR malware chain using GammaPhish, GammaLoad, GammaWorm, and GammaSteel

Malware Activity

Updated: 02.06.2026 21:21 · First: 02.06.2026 21:21 · 📰 1 src / 2 articles · H score: 49

A Gamaredon-linked malware activity is using WinRAR CVE-2025-8088 to deliver staged payloads, including GammaPhish, GammaLoad, and GammaSteel, against Ukrainian organisations. The latest reporting also ties ongoing exploitation to Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226), with crafted RAR archives, hidden ADS payloads, and a Startup-folder LNK used to launch the infection chain. The activity shifted from Telegram exfiltration to dedicated C2 servers, and Earth Dahu's use of the flaw remained active through at least April 10, 2026.

Gamaredon and UAC-0226 WinRAR exploitation in Ukrainian organizations

Case

Updated: 09.06.2026 15:26 · First: 01.06.2026 14:00 · 📰 0 src / 2 articles

Gamaredon activity in Ukrainian networks has broadened into a wider WinRAR CVE-2025-8088 exploitation story that also includes SHADOW-EARTH-066 (UAC-0226) operations against Ukrainian organizations. The intrusion paths abuse malicious RAR content to gain startup persistence, then branch into fileless VBScript, NTFS Alternate Data Streams, PowerShell-driven loading, and dedicated follow-on tooling. Available evidence ties the activity to long-term espionage access, document theft, and, in the UAC-0226 chain, browser credential and cookie theft through GIFTEDCROOK. The exploitation remained active well after the July 2025 patch release, keeping WinRAR remediation and host hunting high-priority for Ukrainian defenders.

CISA announces 2026 President’s Cup winners

Public Sector Action

Updated: 09.06.2026 15:00 · First: 09.06.2026 15:00 · 📰 1 src / 1 articles · H score: 16

CISA announced the winners of the seventh annual President’s Cup cybersecurity competition on June 9, 2026. The federal contest ran from January through the last week of May and drew more than 800 individuals and 200 teams into defensive, offensive, and team-based cyber challenges. The program recognizes and rewards federal cyber talent across the U.S. government workforce, with winners from the U.S. Navy, U.S. Army, and U.S. Marine Corps.

AI-driven worm reasons at runtime and self-replicates across a 33-host test network

Technical Analysis

Updated: 09.06.2026 14:59 · First: 09.06.2026 14:59 · 📰 1 src / 1 articles · H score: 40

Researchers demonstrated a proof-of-concept AI-driven worm that reasons at runtime and self-replicates, showing adaptive host-to-host spread across a 33-host vulnerable test network. The prototype raises the risk of runtime exploit generation, fresh-advisory weaponization, and GPU-assisted propagation without a fixed exploit chain.

Tchap hit by cyberattack

Incident

Updated: 09.06.2026 13:53 · First: 09.06.2026 13:53 · 📰 1 src / 1 articles · H score: 19

A compromised user account enabled an unauthorized breach of Tchap, putting the French government's encrypted messaging platform at risk of exposing conversations and personal data. The incident was detected by ANSSI and disclosed by DINUM on Monday, with investigation still underway.

FROST browser SSD timing side channel via OPFS

Technical Analysis

Updated: 09.06.2026 12:50 · First: 09.06.2026 12:50 · 📰 1 src / 1 articles · H score: 16

FROST turns browser storage timing into a remote SSD side channel that can identify which sites a user visits and which apps they open. The technique runs inside the browser sandbox with JavaScript only, raising privacy risk across macOS and Linux desktop systems.

Check Point Remote Access VPN and Mobile Access authentication bypass (CVE-2026-50751)

Vulnerability

Updated: 08.06.2026 16:05 · First: 08.06.2026 16:05 · 📰 3 src / 4 articles · H score: 56

Check Point warned that CVE-2026-50751 is a critical authentication bypass in Remote Access VPN and Mobile Access deployments using deprecated IKEv1, letting an attacker bypass user authentication and establish a VPN connection without a valid password. Check Point said the flaw has been actively exploited since May 7, 2026, with activity affecting a few dozen targeted organizations worldwide and one post-compromise case linked to a Qilin ransomware affiliate. The company also disclosed CVE-2026-50752, a related certificate-validation flaw in the same IKEv1 path, and said it has not been observed exploited.

Check Point VPN CVE-2026-50751 targeted exploitation wave

Exploitation Wave

Updated: 08.06.2026 17:17 · First: 08.06.2026 17:17 · 📰 3 src / 3 articles · H score: 56

CVE-2026-50751 is an active exploitation wave against Check Point Remote Access VPN and Mobile Access deployments that use deprecated IKEv1. The flaw is an authentication bypass that can let a remote attacker establish a VPN connection without a valid password, and Check Point said abuse has reached a few dozen targeted organizations globally. Exploitation has been observed since May 7, 2026, increased in early June, and in one case was tied to a Qilin ransomware affiliate in post-compromise activity. Check Point also identified CVE-2026-50752 in the same IKEv1 certificate-validation path and said it has not been observed exploited.

Check Point IKEv1 VPN Authentication Bypass Exploitation and Response

Case

Updated: 09.06.2026 12:30 · First: 08.06.2026 16:05 · 📰 0 src / 3 articles

Check Point gateways using deprecated IKEv1 are facing active exploitation of CVE-2026-50751 in Remote Access VPN and Mobile Access deployments. The bug lets unauthenticated attackers bypass authentication and open VPN sessions on exposed systems under specific legacy configuration conditions, and confirmed impact has reached a few dozen organizations globally since at least May 7, 2026. Defensive pressure rose as patches and mitigation guidance were released for affected Security Gateways and Spark Firewalls, one post-exploitation case was associated with a Qilin ransomware affiliate, and CVE-2026-50751 entered the Known Exploited Vulnerabilities catalog. CVE-2026-50752 was disclosed alongside the response for site-to-site VPN connections, but available evidence does not show it being exploited in the wild.

Hades Bun-powered JavaScript stealer on PyPI

Malware Activity

Updated: 09.06.2026 12:13 · First: 09.06.2026 12:13 · 📰 1 src / 1 articles · H score: 34

A new Hades PyPI malware wave uses a Python startup hook to launch a Bun-powered JavaScript stealer, putting developer and CI/CD credentials at risk. The payload can harvest secrets, keys, and local configuration data from package-install environments. It extends a known supply-chain playbook with automatic execution before normal package use.

Miasma GitHub and npm supply-chain campaign

Campaign

Updated: 02.06.2026 00:38 · First: 02.06.2026 00:38 · 📰 2 src / 3 articles · H score: 48

The Miasma supply-chain campaign has expanded into a new PyPI branch called Hades, with 37 malicious wheel artifacts across 19 packages. The compromised releases use a -setup.pth startup hook to execute during Python startup, download the Bun JavaScript runtime, and launch an obfuscated _index.js stealer. The activity targets developer systems for credential theft, CI/CD secret harvesting, and GitHub-centric exfiltration, and it adds LLM prompt injection plus repository-based payload staging. The campaign remains part of the broader Mini Shai-Hulud / Miasma lineage rather than a standalone Python incident.

CISA KEV order for FCEB remediation of CVE-2026-50751

Public Sector Action

Updated: 09.06.2026 11:18 · First: 09.06.2026 11:18 · 📰 1 src / 1 articles · H score: 49

CISA ordered Federal Civilian Executive Branch agencies to secure CVE-2026-50751, forcing a rapid federal response to a flaw that can let attackers bypass authentication on affected Check Point VPN systems. The directive matters because the vulnerability has already been used in zero-day attacks and is now on the Known Exploited Vulnerabilities (KEV) Catalog. Agencies must meet the June 11 deadline under Binding Operational Directive 22-01.

Check Point security patch release for CVE-2026-50751

Security Patch Release

Updated: 08.06.2026 16:05 · First: 08.06.2026 16:05 · 📰 1 src / 2 articles · H score: 59

Check Point released security updates to patch CVE-2026-50751 in Remote Access VPN and Mobile Access deployments. The update addressed a critical authentication bypass on systems using deprecated IKEv1, after the flaw was exploited in zero-day attacks. Check Point also disclosed CVE-2026-50752 and urged customers to apply the fixes immediately or use mitigation steps such as IKEv2 only and mandatory Machine Certificate Authentication.

WhatsApp contempt motion against NSO Group

Regulatory/Legal Action

Updated: 09.06.2026 11:15 · First: 09.06.2026 11:15 · 📰 1 src / 1 articles · H score: 32

WhatsApp moved the US court to hold NSO Group in contempt over a permanent injunction tied to spyware targeting of users. The company says NSO violated the order by using social engineering and malicious links aimed at WhatsApp users and by creating test accounts and groups that were taken down. The request seeks to keep the court's restrictions on NSO in force after years of litigation over Pegasus.

NSO Group WhatsApp spear-phishing campaign

Campaign

Updated: 08.06.2026 20:08 · First: 08.06.2026 20:08 · 📰 3 src / 3 articles · H score: 40

NSO Group remains tied to a WhatsApp spear-phishing campaign that used malicious links to push targets to external websites outside the app. On June 8, WhatsApp said it successfully disrupted the activity, removed test accounts and groups, and published related domains including fr24cast[.]com, ghazacast[.]com, and ikhwancast[.]com. WhatsApp also asked a US court to hold the blacklisted spyware firm in contempt for violating a permanent injunction, keeping the pressure on a campaign already associated with Pegasus abuse and prior targeting of WhatsApp users.

Chrome V8 JavaScript engine out-of-bounds read/write zero-day exploited in the wild (CVE-2026-11645)

Vulnerability

Updated: 09.06.2026 09:56 · First: 09.06.2026 09:56 · 📰 3 src / 3 articles · H score: 45

Google has patched CVE-2026-11645, a Chrome V8 JavaScript engine zero-day that was exploited in the wild and could let remote attackers run code inside the browser sandbox. The flaw was triggered with crafted HTML pages, putting Chrome users on Windows, Mac, and Linux at risk until the emergency update reached their devices. Google said the fix was rolling out through Stable Desktop builds worldwide.

Google security patch release for CVE-2026-11645

Security Patch Release

Updated: 09.06.2026 09:56 · First: 09.06.2026 09:56 · 📰 3 src / 3 articles · H score: 56

Google released emergency Chrome updates to fix CVE-2026-11645, a zero-day that had already been exploited in the wild. The patched release covers Chrome Stable Desktop users on Windows, Mac, and Linux as the fix rolls out worldwide. The update is high priority because the flaw enables code execution inside the browser sandbox.

BerriAI LiteLLM actively exploited command injection (CVE-2026-42271)

Vulnerability

Updated: 09.06.2026 09:26 · First: 09.06.2026 09:26 · 📰 1 src / 1 articles · H score: 51

CVE-2026-42271 in BerriAI LiteLLM was added to CISA's KEV catalog after evidence of active exploitation, creating remote command-execution risk for affected proxy deployments. The command injection flaw impacts LiteLLM Python package versions >= 1.74.2 < 1.83.7 and can let an authenticated user run arbitrary commands on the host. Version 1.83.7 patches the issue by restricting the vulnerable endpoints to the PROXY_ADMIN role.

LiteLLM endpoint-hardening patch release (CVE-2026-42271)

Security Patch Release

Updated: 09.06.2026 09:26 · First: 09.06.2026 09:26 · 📰 1 src / 1 articles · H score: 59

BerriAI released LiteLLM 1.83.7, hardening access to the vulnerable MCP test endpoints that accepted full server configurations. The update now requires the PROXY_ADMIN role for both endpoints, aligning them with the save endpoint and closing the weaker access-control path. The release addresses CVE-2026-42271 in LiteLLM versions >= 1.74.2 < 1.83.7, a command-injection flaw that could let authenticated users run arbitrary commands on the proxy host.

NFCShare fake banking-app update phishing campaign

Campaign

Updated: 09.06.2026 01:11 · First: 09.06.2026 01:11 · 📰 1 src / 1 articles · H score: 40

The NFCShare phishing campaign is using fake banking-app updates on GitHub to steal payment card data from customers of multiple banks across Europe, expanding the theft risk across a broad financial-services target set. The operation combines impersonated bank login pages, deceptive update prompts, and malicious Android packages to capture card details and a 4-digit PIN. It matters because the theft path is built for reusable fraud against bank customers rather than a single isolated lure.

NFCShare Android malware spreads via fake banking-app updates

Malware Activity

Updated: 09.06.2026 01:11 · First: 09.06.2026 01:11 · 📰 1 src / 1 articles · H score: 21

The NFCShare Android malware is being spread as fake banking-app updates on GitHub, broadening attacks against customers of multiple banks and financial institutions across Europe. The malware uses a phishing site and a fake verification screen to trick victims into placing their cards near the phone’s NFC chip, then reads the card data with Android’s IsoDep interface and EMV commands. It steals the card number, card type, expiry date, and a 4-digit PIN, then sends the data to attacker C2 infrastructure over WebSocket for payment-relay abuse.