Microsoft has urged IT Admins to Prepare for Windows 11, Version 26H2 Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 Microsoft has urged IT administrators to begin preparing for the upcoming Windows 11 version 26H2 update, which is now available for testing through the Windows Insider Program. The release continues Microsoft’s shift toward a predictable, low-disruption servicing …

New Malware Attack Via WhatsApp Attacking Windows System to Enable Remote Access For Attackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 A new and active malware campaign is spreading through WhatsApp, targeting everyday Windows users across more than a dozen countries. The threat uses malicious script files disguised as routine financial documents, tricking people into running harmful code …

GitHub Actions Checkout Update Blocks Workflows Triggered by Malicious pull_request_target

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 GitHub has rolled out a significant security enhancement to GitHub Actions by updating actions/checkout to block unsafe workflows that abuse the pull_request_target event. The pull_request_target trigger is widely known as one of the most misused events because it runs with the base repository’s GITHUB_TOKEN, …

Chinese Cyber Contractors Use Malware, Botnets, and Stolen Data to Enable State Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 China’s cyber operations have evolved far beyond what most people imagine when they picture a state-sponsored hacker. Instead of lone government agents breaking into servers, the country now runs an intricate web of private companies, contractors, and …

North Korean Hackers Abuse Mastra npm Supply Chain to Target Developers and CI/CD Pipelines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 North Korean hackers have turned a widely used developer tool into a weapon, quietly poisoning more than 140 software packages that developers across the world rely on every day. The campaign is sophisticated, stealthy, and far-reaching, raising …

13-Word Reddit Comment Can Poison ChatGPT and Gemini AI Search Results

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 A newly published academic paper has revealed a critical vulnerability in AI-powered deep-research systems, including those underpinning commercial tools like OpenAI’s Deep Research and Google’s Gemini Deep Research, that allows a single short Reddit comment to manipulate …

Hackers Impersonate Node.js Installer in Google Ads to Deploy Infostealer Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 Hackers are using fake Google Ads to push a brand-new malware loader that disguises itself as the popular Node.js installer. The campaign has been actively targeting Windows users in the United States, silently dropping a dangerous infostealer …

Hackers Compromised 10,000+ GitHub Repositories to Inject Malicious Script

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 A large-scale malware campaign has been uncovered on GitHub after a researcher identified more than 10,000 repositories distributing Trojan-laced archives, raising concerns about abuse of the platform’s trust model and limitations in automated detection. The investigation began …

Malicious JetBrains and VS Code Extensions Steal OpenAI, Anthropic, and DeepSeek API Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 Developers who rely on AI coding tools are now facing a serious new threat. A coordinated malware campaign has been uncovered on the JetBrains Marketplace, where at least 15 fake IDE plugins were quietly stealing AI provider …

Anthropic’s Mythos AI Model Reportedly Breached NSA Classified Systems in Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 22, 2026 Anthropic’s flagship Mythos AI model reportedly infiltrated nearly all of the National Security Agency (NSA) ‘s classified systems within a few hours during an authorized red-team evaluation on June 11. This incident now seems to be the …