π»Microsoft June 2026 Patch Tuesday Addresses Nearly 200 Vulnerabilities Microsoft released June’s Patch Tuesday updates, addressing 198 vulnerabilities across Windows, Office, Azure, and other Microsoft products. The release includes multiple publicly disclosed zero-days affecting BitLocker, privilege escalation, and internet-facing services, reinforcing the importance of timely patch management. https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws/
π«ShinyHunters Targets Over 100 Higher Education Groups via Oracle Zero-Day Threat actor group ShinyHunters exploited a previously unknown Oracle PeopleSoft vulnerability to compromise more than 100 colleges and universities. Attackers leveraged the remote code execution flaw to steal student records and issue extortion demands across multiple institutions. https://www.highereddive.com/news/colleges-hit-in-cyberattack-by-group-behind-canvas-breach-google-says/822831/
π«Cardiac Monitor Maker iRhythm Confirms Extortion and Data Theft Hack Healthcare technology company iRhythm disclosed unauthorized access to third-party hosted business applications following a social engineering attack. Threat actors claim to have stolen proprietary information and patient health data associated with its wearable cardiac monitoring platform. https://www.securityweek.com/irhythm-confirms-data-stolen-in-hack/
π§Iranian Cyber Group Handala Claims Breach at California Water Service Iran-linked threat group Handala claims to have compromised California Water Service after exploiting an internet-facing platform. Researchers believe the attackers laterally moved through internal systems, highlighting the continued importance of protecting critical infrastructure. https://www.securityweek.com/iranian-cyber-group-handala-claims-cal-water-hack/
π‘Cisco Fixes Catalyst SD-WAN Flaw Under Active Zero-Day Exploitation Cisco released emergency updates for an actively exploited vulnerability affecting Catalyst SD-WAN Manager. The flaw could allow authenticated attackers to overwrite system files and escalate privileges, emphasizing the need for rapid remediation of internet-facing infrastructure. https://www.bleepingcomputer.com/news/security/cisco-fixes-sd-wan-vmanage-flaw-exploited-in-zero-day-attacks/
|