CISA Warns of Cisco Unified CM Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 CISA has added a critical server-side request forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager (Unified CM) to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies …

Microsoft Extends Windows 10 Security Updates for Users Up to October 2027

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 Microsoft has quietly expanded its Windows 10 Extended Security Updates (ESU) program, allowing consumers to receive critical security patches through October 12, 2027, an additional year beyond …

OpenAI Reportedly Delays ChatGPT 5.6 Release Following Trump Administration Request

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 OpenAI has agreed to stagger the public release of its latest AI model, GPT-5.6, after the Trump administration formally requested the company limit initial access to a …

Russia Used Cellebrite Tool to Hack Activist’s iPhone Despite Contract Cancellation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 Russian authorities deployed Cellebrite’s Universal Forensic Extraction Device (UFED) to breach the iPhone of opposition politician Andrey Pivovarov in June 2021, months after the Israeli surveillance firm …

Windows Secure Boot Certificate Expired — Billions of PCs Affected Including Linux Distros

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 The clock has run out. As of June 24, 2026, the first of Microsoft’s original Secure Boot certificates, the Microsoft Corporation KEK CA 2011, has officially expired, with the …

LokiBot Campaign Uses JScript Attachment, .NET Injector, and Process Injection to Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 LokiBot, one of the oldest credential-stealing malware families still active today, has resurfaced in a new multi-stage campaign designed to steal credentials from a wide range of …

ManageEngine AD360 Integration Flaw Exposes User Identity and Role Information to Attackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 ManageEngine has disclosed a high-severity vulnerability, tracked as CVE-2026-11374, affecting several of its identity and access management solutions when integrated with AD360. The flaw could allow unauthenticated …

Gemini 3.5 Flash Released With Computer Use Capabilities that Build Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 Google has officially released Gemini 3.5 Flash with native “computer use” capabilities, marking a significant shift toward autonomous AI agents that can interact directly with digital environments. …

Malicious Chrome Extension Uses Native Messaging Host to Execute PowerShell Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 A newly discovered malware campaign has turned Google Chrome into a remote backdoor without breaking any of the browser’s built-in rules. Spotted in June 2026, the attack …