Press "Enter" to skip to content

OSINT / CyberSec report 29.06.2026 00:08

1. Russian intelligence services are conducting a long-running campaign using fake support messages to steal credentials from government and military officials in Ukraine, the U.S., and Europe (The Hacker News).

2. The FBI and CISA warned that Russian hackers are now targeting Signal Backup Recovery Keys to gain access to historical message data (Bleeping Computer).

3. A critical remote code execution vulnerability in PTC Windchill has been added to the CISA Known Exploited Vulnerabilities catalog due to active exploitation (The Hacker News).

4. CISA issued an urgent directive for federal agencies to patch a vulnerability in Cisco Unified Communications Manager Server that is currently being exploited in the wild (Bleeping Computer).

5. A new Linux kernel vulnerability, CVE-2026-46331 or pedit COW, allows unprivileged users to gain root access and has a public exploit available (The Hacker News).

6. Researchers identified a new Linux kernel privilege escalation flaw, CVE-2026-43503 or DirtyClone, which enables local users to gain root access via cloned network packets (The Hacker News).

7. A high-severity flaw in Amazon Q Developer, tracked as CVE-2026-12957, allowed malicious repositories to execute commands and steal cloud credentials (The Hacker News).

8. Polymarket customers lost 3 million dollars following a supply-chain attack where hackers injected a malicious script into the platform frontend (Bleeping Computer).

9. A new malware family dubbed SharkLoader is being used in the StrikeShark campaign to deploy Cobalt Strike Beacons against diplomatic and government targets (The Hacker News).

10. A Chinese-speaking APT group identified as CL-STA-1062 is deploying a custom backdoor called TinyRCT against critical infrastructure in Southeast Asia (The Hacker News).

11. The Miasma malware family has expanded its supply-chain attacks to include malicious npm packages and abuse of GitHub Actions workflows (The Hacker News).

12. A database containing one million passports was leaked online after a low-value authentication system for cannabis dispensaries was compromised (Schneier).

13. Threat actors are impersonating OpenAI organizations to send fraudulent invites to cybersecurity firm employees as a ploy to steal sensitive information (Bleeping Computer).

14. A phishing campaign targeting hospitality organizations in Europe and Asia is using photo-themed ZIP files to deploy a Node.js implant (The Hacker News).

15. Security researchers discovered that malicious GitHub repositories can trick AI coding agents into executing hidden payloads that bypass standard security scanners (Bleeping Computer).

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *