Cyber Brief · Jun 29 · 12 stories
Monday, June 29, 2026 · sent to 1 subscribers
News
· The Hacker News · Jun 29
A public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory corruption on a connecting client, with possible code execution. No credentials, no user interaction. The bug affects every release up to and including …
News
· The Hacker News · Jun 29
Microsoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary image and font files, then woke up days after install to steal credentials and run ad fraud.
The company calls it StegoAd, a mash-up of steganography and adware…
News
· BleepingComputer · Jun 28
Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. [...]
News
· InfoSecurity Magazine · Jun 29
An attacker has exploited a zero day in Oracle Peoplesoft to gain access to the IT systems of the NAIC, the standard-setting association for the US federal insurance system
News
· BleepingComputer · Jun 26
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. [...]
News
· InfoSecurity Magazine · Jun 29
Experts warn the Jaguar Land Rover breach bears hallmarks of Kremlin-backed hackers, citing novel ransomware, strategic timing and efforts to obscure attribution
News
· CSO Online · Jun 26
Hackers are exploiting a critical vulnerability recently patched in PTC Windchill and FlexPLM, two product lifecycle management solutions used by organizations across a range of industries, including defense, aerospace, automotive, medical, electronics, industrial machinery, and consumer goods.
…
News
· Help Net Security · Jun 29
A malicious GitHub repository can silently compromise a developer’s machine without containing a single line of malicious code, security researchers at Mozilla’s Zero Day Investigative Network (0DIN) warned. The attack The proof-of-concept attack targets AI-powered coding agents such as…
News
· Help Net Security · Jun 28
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Encrypted DNS still tells an eavesdropper where to look Encrypted DNS runs across much of the Internet. DNS over TLS, HTTPS, and QUIC keep the contents of a query away from anyone watching a network li…
News
· CyberScoop · Jun 29
ith federal PQC deadlines set for 2030 and 2031, CISOs face a multi-year transformation program that most organizations have not yet started. The window for orderly execution is narrowing fast.
The post What the post-quantum executive order really demands of CISOs appeared first on CyberScoop.
Advisories
· CISA · Jun 25
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code.
The following versions of Delta Electronics DTM Soft are affected:
DTMSoft vers:all/*
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.8
Delta Electronics
Delta Electronics D…
Advisories
· CISA · Jun 25
View CSAF
Summary
Successful exploitation of this vulnerability could allow a local attacker to disclose information and execute arbitrary code.
The following versions of Horner Automation Cscape are affected:
Cscape <10.2_SP3
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.8
Horner A…