KuinaExtractor Uses Telegram Exfiltration, UAC Bypass, and Sandbox Detection for Stealth

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly uncovered infostealer called KuinaExtractor has been quietly evolving for over six months, posing a serious and growing threat to users across multiple platforms. Written in the Rust programming language, the malware targets browser data, cryptocurrency wallets, and credentials …

CL-STA-1062 Hackers Use TinyRCT Backdoor to Target Southeast Asian Governments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 A Chinese-speaking threat group known as CL-STA-1062 has been running a quiet but aggressive campaign against government agencies and critical energy infrastructure across Southeast Asia. The attackers, active since at least March 2022, spent much of 2025 …

Miasma Malware Uses binding.gyp and Bun to Execute Hidden Payloads in npm Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 Supply chain attackers are getting more creative, and the latest threat is proof of that. A malware campaign known as Miasma has been caught hiding inside widely used npm packages, using a clever mix of tools and …

CISA Warns of Cisco Unified CM Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 CISA has added a critical server-side request forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager (Unified CM) to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies and organizations to apply patches immediately amid active exploitation in …

Microsoft Extends Windows 10 Security Updates for Users Up to October 2027

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 Microsoft has quietly expanded its Windows 10 Extended Security Updates (ESU) program, allowing consumers to receive critical security patches through October 12, 2027, an additional year beyond the program’s originally planned expiration date of October 12, 2026. …

OpenAI Reportedly Delays ChatGPT 5.6 Release Following Trump Administration Request

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 OpenAI has agreed to stagger the public release of its latest AI model, GPT-5.6, after the Trump administration formally requested the company limit initial access to a select group of government-approved partners, citing the model’s advanced capabilities …

Russia Used Cellebrite Tool to Hack Activist’s iPhone Despite Contract Cancellation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 Russian authorities deployed Cellebrite’s Universal Forensic Extraction Device (UFED) to breach the iPhone of opposition politician Andrey Pivovarov in June 2021, months after the Israeli surveillance firm publicly announced it had terminated all contracts with Russian customers, …

Windows Secure Boot Certificate Expired — Billions of PCs Affected Including Linux Distros

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 The clock has run out. As of June 24, 2026, the first of Microsoft’s original Secure Boot certificates, the Microsoft Corporation KEK CA 2011, has officially expired, with the Microsoft UEFI CA 2011 following on June 27, 2026. A …

25-Year-Old Vulnerability in cURL Used by 30 Billion Devices Finally Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 A critical security flaw lurking in curl for over 25 years has been patched, as part of a record-breaking security release that fixed 18 CVEs, the most ever issued in a single curl version. The vulnerability, CVE-2026-8932, …

LokiBot Campaign Uses JScript Attachment, .NET Injector, and Process Injection to Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 LokiBot, one of the oldest credential-stealing malware families still active today, has resurfaced in a new multi-stage campaign designed to steal credentials from a wide range of applications. The campaign uses a JScript email attachment as its …