Kali Linux 2026.2 released with 9 new tools, NetHunter updates
Kali Linux 2026.2 adds 9 new security tools and revamps NetHunter for Android pentesting. Boot times improve 70%, with GNOME 50 and Linux kernel 6.19.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
The full HackWire archive — 3,892 stories, newest first.
Kali Linux 2026.2 adds 9 new security tools and revamps NetHunter for Android pentesting. Boot times improve 70%, with GNOME 50 and Linux kernel 6.19.
Microsoft adds bot security to Teams requiring organizer approval. The default-deny policy blocks unauthorized bots from impersonating staff and stealing credentials.
Aflac Japan disclosed its second major data breach in 12 months, with unauthorized actors accessing customer personal information, bank account details, and policy data during an 11-day window in mid-June 2026. The company contained the breach upon discovery and confirmed U.S. operations were unaffe
SimpleHelp's OIDC bypass (CVE-2026-48558) allows unauthenticated access via forged tokens. Exploited to deploy Djinn Stealer malware targeting developer credentials across managed systems.
Nissan was breached via a zero-day in Oracle PeopleSoft (CVE-2026-35273) affecting 100+ organizations. ShinyHunters stole employee SSNs, banking data, and tax records across the Americas.
Kemp LoadMaster contains a critical pre-auth RCE flaw (CVSS 9.8) enabling unauthenticated root access via a broken input sanitization function. With a public PoC available, thousands of organizations must patch urgently.
A "BioShocking" attack uses indirect prompt injection to trick AI browser agents into stealing credentials by disguising malicious commands as game rules. Six major AI browsers including ChatGPT proved vulnerable, exposing critical risks in autonomous agent mode.
Ransomware operators exploit BlueHammer (CVE-2026-33825), a Windows Defender flaw enabling escalation to SYSTEM access. CISA confirmed active exploitation in campaigns, requiring immediate patching.
Quantifind closed a $200M funding round to expand its AI-native financial crime prevention platform globally. The funding reflects growing demand for advanced solutions to combat money laundering and sanctions evasion.
Apple released emergency patches for 30+ vulnerabilities, including four critical WebKit flaws discovered via AI tools. The memory corruption bugs enable remote code execution through malicious websites on iOS and macOS.
Critical vulnerabilities in Daktronics display controllers allow remote hijacking of highway signs and billboards. Attackers could gain root-level access to systems affecting millions worldwide.
Oracle Payments faces critical exploitation: CVE-2026-46817 allows unauthenticated remote control via HTTP. Actively exploited just 30 days post-patch, threatening thousands of enterprise deployments.
A SimpleHelp RMM vulnerability enables Djinn Stealer deployment targeting developer credentials and cloud infrastructure. The attack chain demonstrates modern supply chain exploitation methods.
Critical flaw in Horner Automation Cscape (CVE-2026-12897) allows code execution when opening malicious CSP files, risking manufacturing control systems. Requires local access but poses significant threat to environments with external consultants or remote workers. Patch available in version 10.2 SP
Yokogawa exposed CVE-2026-11833, allowing unauthenticated attackers to steal configurations from industrial control systems via cleartext transmission, potentially enabling attacks on critical manufacturing and energy infrastructure.
Researcher Sushant Bhardwaj uncovered 14 vulnerabilities in Indian government portals exposing millions of citizens' sensitive data, including bank accounts and addresses. The critical flaws stemmed from inadequate server-side access controls, allowing unauthorized access to records across education
NAIC contradicts ShinyHunters' theft claims following a PeopleSoft zero-day breach. The hackers exploited the vulnerability across 100+ organizations and leaked NAIC data after failed ransom demands.
Nissan suffered a breach via Oracle PeopleSoft zero-day, exposing employee SSNs and banking data. ShinyHunters compromised 300+ instances, expanding attacks to enterprise HR systems from education.
Amazon Q's VS Code extension has a critical flaw enabling credential theft through malicious repositories. MCP integration allows arbitrary code execution with low attack complexity.
Iran, Russia, and China-linked nation-state attackers are breaching water utilities by exploiting basic security lapses—weak passwords, misconfigured networks, exposed controllers—rather than sophisticated exploits. Water systems have historically lacked cybersecurity investment and been underestima
Adversarial patterns on clothing fool facial recognition AI with 60-90% accuracy in lab tests. Experts warn that real-world effectiveness is limited by deployment challenges and advancing defenses.
A malicious Perplexity Chrome extension logged searches and keystrokes, routing data to attackers. It appeared normal to users. Microsoft detected it; Google removed it from the Web Store.
Microsoft extended Windows Server 2022 hotpatching support to October 2027, giving enterprises two additional years to deploy critical security patches without reboots. This addresses the operational complexity of managing large-scale server deployments and aligns with industry trends toward zero-do
WhatsApp launches usernames to hide phone numbers from new contacts, addressing privacy concerns. The optional-credential feature won't appear in public directories—usernames must be directly shared to enable messaging.