DIGEST
Curated intelligence at the intersection of offensive security and AI — the latest items, newest first. See Top Picks for the highest-impact stories.
Sunday, June 21, 2026
Saturday, June 20, 2026
CRITICALMicrosoft Surface Devices Vulnerable to Local Privilege EscalationHIGHMicrosoft Attributes Mastra AI Supply Chain Attack to North Korean HackersHIGHHackers Exploiting Gravity SMTP WordPress Plugin Bug to Expose API Keys
Friday, June 19, 2026
HIGHJCPenney Breach Exposes 368,418 Employee AccountsHIGHKlue OAuth Breach Exposes Salesforce Customer Data, Icarus Group Claims AttackCRITICALUnpatchable 'usbliter8' Exploit Affects Apple A12 and A13 SecureROMHIGHThe Gentlemen RaaS Uses 'GentleKiller' EDR Framework to Disable SecurityHIGHTexas Government Data Breach Exposes Over 3 Million Driver’s LicensesHIGHAutoJack Attack Enables Remote Code Execution via AI Browsing AgentsCRITICALCISA Warns of Active Exploitation in FortiBleed Campaign Targeting Fortinet DevicesHIGHApple Patches Beats Studio Buds Flaw Allowing Eavesdropping
Thursday, June 18, 2026
HIGHPopa Android Botnet Linked to Publicly-Traded Israeli Firm NetNutCRITICALF5 Patches Critical NGINX Open Source RCE VulnerabilitiesHIGHMicrosoft Details CryptoBandits Clipper Campaign Using USB LNK Worm and Tor C2
Wednesday, June 17, 2026
HIGHMicrosoft Confirms RoguePlanet Defender Zero-Day, Patch in DevelopmentCRITICALCISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
Monday, June 15, 2026
HIGHDOJ Seizes Deepfake Nude Sites CFAKE and SOCFAKE Under TAKE IT DOWN ActHIGHSimpleHelp Vulnerability Allows Unauthenticated Creation of Rogue Remote Support AccountsHIGHChinese Hackers Abuse Google Workspace Rules to Steal Research and Defense EmailsHIGHNorth Korean Hackers Use Developer Tools as Malware Delivery ChannelsCRITICAL56 Million Accounts Exposed in June 2026 Stealer Log DumpCRITICALOptinMonster, TrustPulse, and PushEngage WordPress Plugins Hit by CDN Supply-Chain AttackCRITICALCisco Patches SD-WAN vManage Zero-Day Exploited for Root PrivilegesCRITICALLiteLLM Vulnerability Chain Allows Low-Privilege Users to Take Over AI Gateway ServersCRITICALOne-Click 'SearchLeak' Attack on Microsoft 365 Copilot Could Steal Sensitive DataHIGHInfinite Campus Data Breach Affects 137,000 School Staff AccountsCRITICALPalo Alto Networks Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
Sunday, June 14, 2026
HIGHFBI Disrupts Massive Chinese AI-Powered Phishing Service 'Outsider Enterprise'CRITICALUnauthenticated SQL Injection Found in Pi.Alert