π¨ ACTIVE EXPLOITS & INCIDENTS
- Insurance Body Confirms Hackers Posted Oracle PeopleSoft Breach Data β Cybersecurity Dive The National Association of Insurance Commissioners (NAIC) confirmed data from an Oracle PeopleSoft breach was posted by threat actors. Some ratings agencies have suspended data feeds as a precaution, indicating active exploitation and potential downstream impact on insurance sector data integrity.
- Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks β The Hacker News China-aligned Mustang Panda APT is actively targeting Indian government and hydropower sectors, leveraging Zoho WorkDrive as a covert C2 channel. New malware variants and compromised high-level administrative machines highlight a sophisticated supply chain abuse and espionage campaign.
- Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input β The Hacker News / Microsoft Security Blog A malicious Chromium extension impersonating the AI search engine Perplexity silently logged all user search queries and address bar inputs, routing them through attacker-controlled servers before redirecting to legitimate results. Google removed the extension after Microsoftβs responsible disclosure, but affected users should audit browser extensions immediately.
π VULNERABILITIES & CVEs
- Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More β The Hacker News New DirtyClone Linux kernel vulnerability enables local privilege escalation, increasing risk of full system compromise if exploited. Combined with emerging AI-powered malware and infostealers, this highlights the need for urgent patching and enhanced endpoint monitoring.
π VENDOR BULLETINS & ADVISORIES
- Microsoft Extends Windows Server 2022 Hotpatching Until October 2027 β BleepingComputer Microsoft has extended hotpatching support for Windows Server 2022 by one year beyond mainstream support, until October 2027. Organizations relying on hotpatching for critical uptime should adjust maintenance plans accordingly to leverage this extended security update window.
π΅οΈ THREAT RESEARCH & DEEP DIVES
- Researchers Demo New Claude Code Attack Using Harmless-Looking Repositories to Hijack Developer Machines β SecurityWeek Researchers demonstrated a novel attack abusing Claude Code AI to execute reverse shells via indirect prompts hidden in seemingly benign code repositories. This technique enables stealthy remote code execution on developer machines, raising concerns about AI-assisted supply chain and developer environment compromises.
- What the June 2026 Threat Technique Catalog Update Means for Your AWS Environment β AWS Security Blog AWS CIRT released an updated threat technique catalog reflecting recent attack patterns observed in cloud environments. The update includes new TTPs for detecting and mitigating emerging threats in AWS workloads, emphasizing the importance of continuous threat hunting and incident response tuning in cloud-native contexts.
πΌ INDUSTRY NEWS, M&A & DEALS
- Straiker Raises $64 Million for AI Security Platform β SecurityWeek Straiker secured $64M in funding to advance its AI security platform that identifies AI agents and monitors their access, behavior, and risk profiles. This investment signals growing market demand for AI governance and defense tools amid rising AI-driven attack surfaces.
π PRODUCT LAUNCHES & UPDATES
- WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy β SecurityWeek / BleepingComputer / The Hacker News WhatsApp has begun global rollout of an optional username system allowing users to mask phone numbers behind usernames for messaging. This privacy enhancement aims to reduce phone number exposure and associated risks such as SIM swapping and targeted phishing.
π° LESSER-KNOWN / UNDER-REPORTED
- U.S. Offers $10 Million for Hackers Targeting WhatsApp, Signal Users β BleepingComputer The U.S. Department of State announced rewards up to $10M for information on UNC5792 and UNC4221 hacker groups linked to Russian intelligence, who target encrypted messaging users. This highlights ongoing geopolitical cyber espionage efforts against secure communication platforms.