TECHZONE™
Open in Telegram
TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news
Show more596
Subscribers
-124 hours
-37 days
-1130 days
Posts Archive
596
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
https://thehackernews.com/2026/06/openai-expands-daybreak-with-gpt-55.html
OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative the artificial intelligence (AI) company announced last month.
Calling GPT‑5.5‑Cyber its "strongest model yet for finding and helping patch software vulnerabilities," OpenAI said the model can "sustain deeper analysis across large codebases" to
596
Stop Your Legacy Infrastructure from Hijacking Your AI Agents
https://thehackernews.com/2026/06/stop-your-legacy-infrastructure-from.html
Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for - how attackers are circumventing AI security programs by using legacy infrastructure to hijack AI agents.
AI adoption is moving faster than security programs can account for. Roughly 71% of organizations are piloting AI agents across their
596
⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
https://thehackernews.com/2026/06/weekly-recap-browser-bugs-edr-killers.html
It’s Monday again.
This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control.
The annoying part is how little of this feels new. Weak credentials, sketchy downloads, browser extensions with too much access, and WordPress sites are used to push more
596
Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices
https://thehackernews.com/2026/06/canadas-spy-agency-used-first-of-its.html
Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets.
The Federal Court released a public version of the ruling on June 15. It is the first time the Canadian Security Intelligence Service has used its threat reduction warrant powers this way.
The warrant let CSIS alter,
596
AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
https://thehackernews.com/2026/06/arystinger-malware-infects-4300-legacy.html
A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin's XLab calls it AryStinger and counts at least 4,300 infected routers, a total it says is still rising.
The distinction matters. AryStinger exists for the stage of an attack that comes before the break-in. Infected
596
INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific
https://thehackernews.com/2026/06/interpol-warns-phishing-ransomware-and.html
A new report from INTERPOL has revealed a "dramatic increase" in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration, new technologies, organized criminal networks, and a disparity in cybersecurity maturity.
According to INTERPOL's 2025/2026 Asia and South Pacific Cyberthreat Assessment Report, phishing has emerged as the most widespread and
596
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
https://thehackernews.com/2026/06/hackers-exploit-gravity-smtp-wordpress.html
Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites.
The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens
596
Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html
Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips.
That code is burned into the silicon at manufacture. No software update can reach it. Affected devices will carry this flaw for as long as they stay in use.
This is not a remote attack. It requires
596
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
https://thehackernews.com/2026/06/the-gentlemen-raas-uses-gentlekiller.html
The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor.
This mature portfolio of EDR-terminating tools is centered around a framework that's known as GentleKiller.
"They also incorporate third-party or
596
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
https://thehackernews.com/2026/06/autojack-attack-lets-one-web-page.html
Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution.
Steer the agent to load an attacker's web page, and that page's JavaScript can reach a privileged local service on the same machine and spawn a process on the host.
No credentials, no sign-in screen, and no further user interaction once
596
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
https://thehackernews.com/2026/06/operation-endgame-disrupts-socgholish.html
Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites.
"With these actions we deprive cybercriminals of access to infected computer systems," Maikel Rollman of the Netherlands National High Tech Crime Unit said.
"This prevents
596
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
https://thehackernews.com/2026/06/cisa-warns-fortinet-customers-as.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps to secure against ongoing malicious activity aimed at thousands of internet-accessible devices.
The sweeping campaign, believed to be the work of Russian-speaking threat actors, has been codenamed FortiBleed. The number of compromised devices stands at
596
From Assistive to Agentic: The AI Shift That's Redefining Threat Management
https://thehackernews.com/2026/06/from-assistive-to-agentic-ai-shift.html
Introduction
The average enterprise security team has 40 or more security tools, giving a lot of visibility into internal telemetry and asset data. But often, these tools are working in siloes, generating (overlapping) alerts and data. And yet, breach dwell times remain stubbornly long (~43 days), response windows keep closing before teams can act, and analysts burn out triaging noise instead
596
Forget Data Leakage: Shadow AI's Real Threat Is Access Control
https://thehackernews.com/2026/06/forget-data-leakage-shadow-ais-real.html
The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools. Security teams responded with usage policies, domain blocks, and data loss prevention rules. That response made sense at the time.
It doesn't fit the problem anymore.
Shadow AI has shifted from a data leakage concern to an access control problem. The threat isn't
596
Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
https://thehackernews.com/2026/06/salesforce-disables-klue-app.html
Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026.
To that end, organizations will be unable to connect to Salesforce via the app until further notice, the American cloud-based software company noted in an alert published this week.
"Salesforce took
596
Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone
https://thehackernews.com/2026/06/apple-patches-beats-studio-buds-flaw.html
Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users.
The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorrect authorization impacting the Airoha Bluetooth audio SDK that makes it possible to pair a Bluetooth audio device without user consent.
596
Killing me gently: Inside Gentlemen’s EDR killer framework
https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/
ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen
596
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
https://thehackernews.com/2026/06/f5-patches-two-critical-nginx-open.html
F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems.
The vulnerabilities are listed below -
CVE-2026-42530 (CVSS v4 score: 9.2) - A use-after-free vulnerability in the ngx_http_v3_module that could be triggered by a remote unauthenticated attacker when NGINX Open Source is
596
Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network
https://thehackernews.com/2026/06/orphaned-ai-agents-how-to-find-hidden.html
If an autonomous AI agent interacts with your company's core intellectual property today, can your security team instantly name the person who authorized it?
For most enterprises, the answer is a simple no.
The rush to adopt internal AI tools has left a massive trail of administrative debt: orphaned agents (AI tools left running after their creator leaves the company) and standing privileges (
596
The Scripts on Your Checkout Page Are Now a PCI DSS Problem
https://thehackernews.com/2026/06/the-scripts-on-your-checkout-page-are.html
An independent PCI assessor tested Reflectiz against the new PCI DSS rules. Here is the verdict: See the full QSA assessment here →
When a customer types their card number into your checkout, their browser is running far more than your code. Analytics tags, a tag manager, a support widget, a payment iframe: a modern checkout loads dozens of third-party scripts, and any one of them can be turned
Available now! Telegram Research 2025 — the year's key insights 
