π¦GitHub Disables Microsoft Repos Distributing Password-Stealing Malware
Microsoft abruptly removed 73 code repositories across its official Azure, Microsoft, and MicrosoftDocs organizations on GitHub after detecting a supply-chain campaign. Investigators confirmed that threat actors compromised the repositories during a “Miasma/Shai-Hulud” operation to push password-stealing malware, briefly disrupting continuous integration pipelines and causing automated deployment failures for external developers.
https://www.bleepingcomputer.com/news/security/github-disables-microsoft-repos-pushing-password-stealing-malware/
π€Over 20,000 Instagram Accounts Hijacked via Meta AI Support System
Meta disclosed that attackers successfully hijacked 20,225 Instagram accounts by exploiting a critical validation flaw in its AI-powered “High Touch Support” tool. The tool failed to verify if an email address matched the targeted profile when processing lockout assistance, allowing the malicious actors to route password reset links to themselves and compromise profiles lacking two-factor authentication.
https://www.bleepingcomputer.com/news/security/meta-ai-support-data-breach-affects-20-000-instagram-accounts/
πGoogle Patches Critical Chrome V8 Zero-Day Exploited in the Wild
Google rolled out an emergency security update fixing 74 flaws in the desktop Chrome browser, headlined by an actively exploited zero-day tracked as CVE-2026-11645. The high-severity bug is an out-of-bounds memory access flaw in the V8 JavaScript engine that can allow remote attackers to execute arbitrary code within the browser’s sandbox using specially crafted HTML pages.
https://www.infosecurity-magazine.com/news/google-patch-chrome-vulnerability/
ποΈWhite House Issues Executive Order on AI Cybersecurity Integration
A sweeping new Executive Order on “Promoting Advanced Artificial Intelligence Innovation and Security” sets strict 30-to-60-day deadlines for federal agencies to prioritize AI-driven cyber defenses. The directive establishes an “AI cybersecurity clearinghouse” involving CISA, the NSA, and private sector tech firms to discover software flaws, validate vulnerabilities, and fast-track critical defensive patch rollouts.
https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/
β‘Phishing Attacks Compromise Northeast Utility Vendor Eversource Energy
Eversource Energy confirmed a security incident exposing the highly sensitive personal and financial data of over 3,000 utility customers across Connecticut, Massachusetts, and New Hampshire. The data leak occurred after attackers utilized phishing and social engineering tactics to compromise two employee credentials, though the company noted that primary grid controls and critical operational infrastructure were unaffected.
https://www.govtech.com/security/cyber-attacks-impacted-3-000-northeast-utility-customers



