Critical python.org Vulnerability Allowed Attackers to Forge Admin-Level API Requests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical authentication bypass vulnerability in the python.org release management API could have allowed attackers to impersonate administrators, potentially redirecting millions of users to malicious download URLs. The flaw, responsibly …

KuinaExtractor Uses Telegram Exfiltration, UAC Bypass, and Sandbox Detection for Stealth

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly uncovered infostealer called KuinaExtractor has been quietly evolving for over six months, posing a serious and growing threat to users across multiple platforms. Written in the Rust programming …

CL-STA-1062 Hackers Use TinyRCT Backdoor to Target Southeast Asian Governments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 A Chinese-speaking threat group known as CL-STA-1062 has been running a quiet but aggressive campaign against government agencies and critical energy infrastructure across Southeast Asia. The attackers, …

CISA Warns of Cisco Unified CM Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 CISA has added a critical server-side request forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager (Unified CM) to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies …

Microsoft Extends Windows 10 Security Updates for Users Up to October 2027

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 Microsoft has quietly expanded its Windows 10 Extended Security Updates (ESU) program, allowing consumers to receive critical security patches through October 12, 2027, an additional year beyond …

OpenAI Reportedly Delays ChatGPT 5.6 Release Following Trump Administration Request

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 26, 2026 OpenAI has agreed to stagger the public release of its latest AI model, GPT-5.6, after the Trump administration formally requested the company limit initial access to a …

Russia Used Cellebrite Tool to Hack Activist’s iPhone Despite Contract Cancellation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 Russian authorities deployed Cellebrite’s Universal Forensic Extraction Device (UFED) to breach the iPhone of opposition politician Andrey Pivovarov in June 2021, months after the Israeli surveillance firm …

Windows Secure Boot Certificate Expired — Billions of PCs Affected Including Linux Distros

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 25, 2026 The clock has run out. As of June 24, 2026, the first of Microsoft’s original Secure Boot certificates, the Microsoft Corporation KEK CA 2011, has officially expired, with the …