ICYMI: 2026-06-29
Latest Headlines
Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
Meta Contractors Posed as Teens to Prompt Rival Chatbots About Suicide, Sex, and Drugs
Top Google Security Staff Warn Search Data Could Be Hacked if EU Rules Change
WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy
Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack
‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access
OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review
US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve
OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI
WhatsApp Launches New Username Feature to Communicate Without Exposing Phone Numbers
EvilTokens Phishing Breaches Finance Firms Using “Ghost” Code Across U.S. and European Businesses
New Claude Code Attack Allows Attackers to Take Full Control of Developers’ Systems
U.S. Seizes Hundreds Domains Used to Stream World Cup Matches Illegally
Public PoC Released for Deserialization RCE Vulnerability in Splunk Secure Gateway
Hackers Exploiting Critical Oracle E-Business Suite Vulnerability Actively in Attacks
Critical Dell Wyse Vulnerabilities Enable Remote Code Execution Attacks
Microsoft 365 Apps RCE Vulnerability Exploited Using a Malicious Excel File
Critical Gemini CLI Vulnerability Lets Attackers Execute Arbitrary Code
Russia-Linked Turla Uses Compromised Infrastructure to Deploy STOCKSTAY in Ukraine Operations
Nissan discloses employee data breach linked to Oracle zero-day attacks
NAIC says public data stolen in ShinyHunters’ PeopleSoft breach
WhatsApp rolls out usernames to help users hide their phone number
Microsoft extends Windows Server 2022 hotpatching until October 2027
U.S. offers $10 million for hackers targeting WhatsApp, Signal users
Critical SimpleHelp flaw exploited to deploy new stealer malware
Hackers now exploit critical Oracle E-Business flaw in attacks
Webinar: Why business email compromise attacks keep succeeding
US seizes hundreds of FIFA World Cup illegal streaming domains
– MTZ