Adobe Patches 123 Vulnerabilities
Adobe patched 123 vulnerabilities across 11 products; ColdFusion and Campaign Classic flaws are priority 1 (expected exploitation). Most are XSS issues in Experience Manager.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
The full HackWire archive — 3,892 stories, newest first.
Adobe patched 123 vulnerabilities across 11 products; ColdFusion and Campaign Classic flaws are priority 1 (expected exploitation). Most are XSS issues in Experience Manager.
**Summary:** Microsoft patched 200 vulnerabilities in June, including three pre-disclosed threats: a Windows DoS, BitLocker bypass, and privilege escalation. All rated "exploitation more likely" requiring urgent action.
Two Russian threat groups exploit patched WinRAR flaw (CVE-2025-8088) against Ukrainian military targets. Despite a July 2025 patch, they continue generating new attack samples as of April 2026.
Microsoft Exchange's 'Ghost-Sender' vulnerability allows unauthenticated email spoofing in hybrid environments, bypassing SPF/DKIM/DMARC security controls. Attackers can impersonate any user for CEO fraud or invoice scams. Active exploitation confirmed.
OpenClaw AI agents fall for phishing, exposing AWS credentials and enterprise data. Social engineering tactics defeat their security protections, even with explicit anti-phishing instructions.
Miasma campaign compromised 73 Microsoft GitHub repositories via a previously breached developer account, creating supply chain risks for downstream applications. The attack reuses stolen credentials from a separate Miasma breach, indicating persistent attacker access to critical development infrast
Microsoft took 73 GitHub repos offline due to Miasma, a supply chain attack injecting malware to steal developer credentials and API tokens. The incident highlights vulnerabilities in open-source software supply chains.
Veeam RCE (CVE-2026-44963, CVSS 9.4) allows authenticated users to execute code with backup privileges. Low entry barrier, catastrophic impact: backup takeover, ransomware deployment, data loss.
KB5094127 patches June Windows 10 vulnerabilities while managing Secure Boot certificate expiration—preventing boot failures that could affect millions of enterprise systems.
SAP released critical patches (June 11) for 15 vulnerabilities affecting NetWeaver and Commerce Cloud. A critical unauthenticated remote code execution flaw in NetWeaver poses immediate risk to unpatched deployments; enterprises should patch urgently.
Meta is expanding its use of off-site business data from targeted ads to Feed personalization and AI responses. This broadens privacy concerns as regulators scrutinize the company.
Microsoft removed 73 GitHub repositories after a malware supply-chain attack targeted AI development tools. The Miasma/Shai-Hulud campaign was contained in 105 seconds but disrupted CI/CD pipelines.
Mythos Preview significantly improves vulnerability detection in source code analysis, but independent testing by security firm XBOW shows it still requires human expertise and live validation to identify real exploits.
Microsoft's June 9, 2026 Windows 11 Patch Tuesday updates deliver security fixes and new features like Bluetooth LE audio sharing across versions 25H2, 24H2, and 23H2. Install immediately via Settings > Windows Update; updates are mandatory and require a restart.
Microsoft patched 200 vulnerabilities in June 2026, including 33 Critical-severity flaws and three publicly disclosed zero-days. While currently unexloited, the public disclosure accelerates attack timelines, making urgent patching essential to prevent widespread exploitation.
Claude Mythos creates working exploits for known vulnerabilities in hours, outpacing typical patch timelines. This AI-accelerated exploit development collapses the traditional security response window, leaving defenders exposed.
Critical Veeam Backup RCE (CVE-2026-44963) affects v12.x; authenticated users can execute code on backup servers. Urgent patching needed; v13.x unaffected. Backup infrastructure is a key ransomware target.
France's government messaging platform was breached via account hijacking attacks targeting authentication mechanisms. Attackers accessed sensitive communications and could impersonate officials, threatening policy discussions and diplomatic exchanges.
AI automation is collapsing vulnerability discovery scarcity, upending bug bounty economics. Anthropic's Mythos shows AI can accelerate security research to machine speed, forcing industry transformation.
Atsign's AI Architect uses cryptographic invisibility to protect AI agents from identity-based attacks by making application credentials undiscoverable and unexploitable.
Google patched CVE-2026-11645, a critical V8 vulnerability (CVSS 8.8) under active exploitation in the wild. The out-of-bounds memory flaw enables attackers to escape Chrome's sandbox and execute arbitrary code with user privileges.
Researchers built an autonomous AI worm using local language models—no cloud needed. It self-replicates across networks, generates custom attacks per target, and requires zero human intervention.
Russian-aligned hackers exploit a patched WinRAR flaw (CVE-2025-8088) to deliver stealing malware to Ukrainian targets through malicious RAR files—nearly a year after patches became available.
100+ NPM/PyPI packages hit by Shai-Hulud attacks with 471+ malicious artifacts since June 1. Leaked source code accelerated the worm's spread across JavaScript and Python ecosystems.