Weekly Cyber Briefings
Every Monday, get a plain-English breakdown of the week's biggest threats, scams, and security tips — curated and written by our team using real intelligence, not hype.
No spam. Unsubscribe anytime. We never share your email.
Weekly Cyber Briefings Archive
Full briefings for subscribers. New issue every Monday.
ShinyHunters sextortion emails hitting inboxes nationwide · Steam forums weaponized with crypto miners · Chick-fil-A accounts breached · Paidwork: 23 million records including bank details leaked · TalentHook: 26 million résumés exposed · Bluetooth flaw in 2 million cars · Fake Odyssey streaming sites · OnTrac delivery breach
- ›ShinyHunters sextortion emails demanding $2,000 in Bitcoin are hitting inboxes — almost certainly fake mass-spam; do not pay, do not reply
- ›Steam community forums weaponized — fake help posts trick gamers into running PowerShell commands that install XMRig crypto miners
- ›Chick-fil-A One loyalty accounts breached via credential stuffing June 17–19 — names, email, QR codes, partial card numbers exposed
- ›Paidwork breach: 23 million gig worker records exposed including bank account numbers and transaction history
- ›TalentHook: 26 million résumés exposed — names, addresses, employment history usable for targeted job-offer scams
- ›Bluetooth flaw in ~2 million cars (Kia, Hyundai, Genesis) allows tracking and possible unlocking within 30 feet
- ›OnTrac parcel delivery breach: customer names, emails, phones, and delivery addresses accessed by attackers
- ›Good news: hacker who broke into 750 women's Snapchat accounts sentenced to 6 years; Google launches selfie video account recovery
The Week in 60 Seconds
This week's biggest story is one landing directly in people's inboxes: threatening emails claiming to be from the ShinyHunters hacking group, demanding $2,000 in Bitcoin and claiming to have compromising footage of you. These are almost certainly fake — someone downloaded old breach data and mass-mailed threats to millions. Do not pay. Beyond that, Steam gaming forums were turned into a trap for PC gamers. Chick-fil-A's loyalty app was breached using stolen passwords from other sites. A gig-work platform called Paidwork leaked 23 million records including bank account numbers. A Bluetooth flaw could let strangers track and unlock about 2 million cars.
Good news: a man who broke into 750 women's Snapchat accounts was sentenced to six years in prison. Google also launched a helpful new account recovery feature.
🚨 ShinyHunters Sextortion Emails — Scary, But Almost Certainly Fake
Who is affected: Anyone whose email appeared in a past data breach — which includes hundreds of millions of people.
What happened: Thousands of people received emails claiming to be from ShinyHunters, threatening to release embarrassing footage and demanding $2,000 in Bitcoin. They name a real company whose data was breached to appear credible. This is a scam. ShinyHunters denied involvement. The criminals simply downloaded past breach data and mass-mailed threats to millions of people. They almost certainly have nothing.
✅ What to do: Do not pay. Do not reply. Do not click any links. Mark it as spam and delete it. Change your password on the named company's site as routine practice. Report to the FBI at ic3.gov if you wish.
🎮 Steam Forum ClickFix — Crypto Miners on Gaming PCs
Who is affected: PC gamers who visit Steam community forums for troubleshooting help.
What happened: Attackers post fake fix instructions on Steam's forums. The posts look helpful but ask you to run a command in Windows PowerShell. That command installs the XMRig crypto miner, which silently uses your PC's power. Your computer slows down, runs hot, and your electricity bill rises.
✅ What to do: Never run a PowerShell command from a gaming forum, Reddit, or Discord. If your PC has slowed down unexpectedly: open Task Manager (Ctrl + Shift + Esc), click the CPU column, look for unfamiliar heavy usage. Run Malwarebytes (free) to scan for miners.
🔓 Breaches Affecting Real People
Chick-fil-A One: Attackers used stolen credentials from other breaches to log into Chick-fil-A accounts June 17–19. Exposed: names, email addresses, membership numbers, QR codes, account balances, partial card numbers, and for some accounts phone numbers, addresses, and birth dates. ✅ Change your Chick-fil-A One password immediately to a unique one. Check your balance for unauthorized redemptions.
Paidwork (23 million records): A March 2026 breach became a public 11 GB data dump this week. Exposed: names, emails, phone numbers, home addresses, birth dates, bank account numbers, and payout history. ✅ Check haveibeenpwned.com. Monitor your bank account. Consider a free credit freeze at all three bureaus.
TalentHook (26 million résumés): Names, home addresses, phone numbers, employment history, and education details exposed. Criminals can craft highly personalized job-offer scams using your specific work history. ✅ Check haveibeenpwned.com. Be alert for unusually personalized recruiting calls or emails.
OnTrac Parcel Delivery: Hackers breached OnTrac's network — names, emails, phone numbers, and delivery addresses may have been accessed. OnTrac handles deliveries for Amazon and major retailers. ✅ Watch for phishing texts referencing your delivery history or home address.
🚗 Bluetooth Flaw in 2 Million Cars
Who is affected: Owners of certain Kia, Hyundai, and Genesis vehicles with Bluetooth-connected systems.
What happened: Researchers found a Bluetooth vulnerability allowing someone within ~30 feet to track a vehicle's location and potentially unlock it. Roughly 2 million cars are estimated to be affected.
✅ What to do: Check your car manufacturer's website for security advisories or call your dealership. Accept any over-the-air software updates your car offers. Do not leave valuables visible in your car.
✅ Good News This Week
A man who systematically broke into 750 women's Snapchat accounts using credential stuffing to steal private photos was sentenced to six years in federal prison. Google launched a selfie video verification option for account recovery — set up your recovery options now at myaccount.google.com → Security before you need them.
✅ Your Action List This Week
- NOWGot a threatening ShinyHunters email demanding Bitcoin? Delete it. Do not pay. It is almost certainly mass-spam using your email from a past breach.
- NOWChick-fil-A One account? Change your password now to something unique. Check your balance for unauthorized redemptions.
- NOWCheck haveibeenpwned.com — Paidwork (23M records) and TalentHook (26M résumés) were added this week.
- WEEKIf you used Paidwork: monitor your bank account and consider a free credit freeze at all three bureaus.
- WEEKGamers: never run PowerShell commands from gaming forums. Run Malwarebytes if your PC has slowed down unexpectedly.
- WEEKUpdate the Adobe Acrobat Chrome extension: Chrome menu → Extensions → Manage Extensions → Update.
- WEEKSet up Google account recovery at myaccount.google.com → Security before you need it.
- MONTHStart using a password manager (Bitwarden is free) — unique passwords eliminate credential stuffing attacks entirely.
- MONTHCheck your car manufacturer's website or call your dealership about Bluetooth security updates.
Critical WordPress flaw puts 500M sites at risk · July Patch Tuesday: 570 fixes including 2 zero-days · QR code scams surging · Ransomware up 43% · AI voice scams now cloning real people in real time · AssuranceAmerica breach: 6.9M records · Windows LegacyHive flaw · Transport for London hackers sentenced
- ›Critical WordPress 'wp2shell' flaw (CVE-2026-60137) allows takeover of any site without a password — 500M sites at risk, update immediately
- ›July Patch Tuesday: 570 Windows fixes including 2 actively exploited zero-days (SharePoint + AD Federation Services)
- ›LegacyHive Windows flaw — works even on fully patched systems, no fix available yet
- ›QR code scams ('quishing') surging at restaurants, parking meters, and in emails — AI-generated fakes at scale
- ›AI voice cloning now clones real people from 3 seconds of audio — classic grandparent scam now hyper-convincing
- ›Ransomware up 43% in Q2 2026 — 2,279 victims, small businesses the primary target
- ›AssuranceAmerica breach confirmed: 6.9M records including driver's license numbers stolen
- ›Transport for London hackers sentenced to prison; FBI convicts elderly fraud tech support scammer
The Week in 60 Seconds
The biggest story this week affects anyone who has a website: a critical flaw nicknamed 'wp2shell' was found in WordPress that could allow attackers to take over any WordPress site without even needing a password. Over 500 million sites are potentially at risk. If you have a WordPress website, update it today. Microsoft also released its largest-ever Patch Tuesday, fixing 570 vulnerabilities including two being actively exploited right now. Ransomware attacks are up 43% compared to last year. A new wave of QR code scams is targeting shoppers, diners, and anyone who scans a code in public. And AI voice cloning has become so convincing that scammers can now clone a family member's voice from just three seconds of audio found on social media.
Good news: two of the hackers who attacked Transport for London in 2024 were sentenced to prison, and the FBI secured a conviction against a man who ran a fake tech support scam targeting elderly Americans.
🚨 Critical: WordPress 'wp2shell' Flaw — Update Your Site Now
CVE-2026-60137 — 500 Million Sites at Risk
Who is affected: Anyone who owns or manages a WordPress website — business owners, bloggers, online stores, portfolio sites, local service businesses.
Security researchers disclosed a critical vulnerability called 'wp2shell' affecting the WordPress REST API. The flaw allows an attacker to take complete control of any vulnerable WordPress site without needing a username or password — they can steal customer data, deface the site, redirect visitors to malicious pages, or use your hosting to attack others. Over 500 million WordPress websites are estimated to be affected. A fix exists, but only if you update.
✅ What to do: Log in to your WordPress dashboard right now. Apply the July 2026 update when prompted. Go to Plugins → Installed Plugins → Update All. Then go to Users → All Users and delete any administrator account you do not recognize. If someone manages your site for you, contact them today.
🛠️ Your Devices This Week
July Patch Tuesday — 570 Windows Fixes Including Two Actively Exploited
Who is affected: Everyone using a Windows computer at home or at work.
Microsoft released security updates for 570 vulnerabilities this week. Two are actively being exploited right now: one in SharePoint and one in Active Directory Federation Services. If you use Windows, your computer needs this update immediately.
✅ What to do: Start → Settings → Windows Update → Check for updates → Install all → Restart your computer.
LegacyHive — A Windows Flaw Even Fully-Patched Systems Can't Stop
Who is affected: Everyone using Windows, even after installing all available updates.
Researcher Nightmare-Eclipse released a new flaw called LegacyHive that lets a regular user on a Windows computer read the account settings of other users on the same machine — including saved credentials. No fix is available yet.
✅ What to do: Keep checking Windows Update. Avoid storing passwords or sensitive information in files on any shared computer. Apply the patch as soon as Microsoft releases it.
📱 Scams Targeting You This Week
QR Code Scams Surging — Restaurants, Parking, Shops, and Emails
Who is affected: Everyone who scans QR codes in public places or in emails.
Criminals place fake QR codes over legitimate ones at parking meters, restaurant tables, and retail stores, or embed them in emails. When you scan the fake code, it sends you to a lookalike website that steals your payment information or login credentials. AI-generated fake QR codes are now being produced at scale.
✅ What to do: Before scanning any QR code in public, check if it's a sticker placed over an existing code. After scanning, look at the URL before tapping "open." For parking: use your city's official parking app instead of scanning meter codes.
AI Voice Cloning Scams — Criminals Can Now Sound Exactly Like Someone You Know
Who is affected: Everyone — especially parents, grandparents, and anyone who might receive an emergency call from a family member.
AI voice cloning can now clone someone's voice from as little as three seconds of audio found on social media. The classic grandparent scam — a caller pretending to be a grandchild in trouble who needs money urgently — has become dramatically more convincing because the voice now sounds genuinely familiar. Variants targeting small business owners (a caller who sounds like your accountant requesting urgent payment) are also increasing.
✅ What to do: Establish a family safe word right now — a word only your immediate family knows. If you receive an unexpected call asking for urgent money: hang up and call them back on a number you already have. Never send money based on a single phone call, no matter how convincing the voice sounds.
Ransomware Up 43% — Small Businesses Are the Primary Target
Who is affected: All small business owners, solopreneurs, and freelancers.
GuidePoint Security reported 2,279 ransomware victims in Q2 2026 alone — a 43% increase. There are now more active ransomware groups than at any point in recorded history. Average ransom demands for small businesses range from $10,000 to $150,000.
✅ What to do: The three most effective protections: (1) Current, tested backups stored separately from your computers. (2) Up-to-date software on all computers. (3) Multi-factor authentication on email and remote access.
✍️ For Content Creators & Solopreneurs
Fake Invoice Emails Using AI to Impersonate Your Regular Contacts
AI-assisted phishing has made fake invoice emails far more convincing. Criminals research your business relationships online and send emails that appear to come from your real clients, referencing real project names, asking you to pay to a new bank account. Several freelancers reported receiving fake payment requests this week that looked identical to regular client communications.
✅ What to do: Establish one rule: any change to payment details must be verified by a phone call to a number you already have — not by replying to the email.
🏢 For Small Business Owners
AssuranceAmerica Breach — 6.9 Million Records Including Driver's Licenses
Who is affected: Anyone who has or has had an auto insurance policy with AssuranceAmerica.
AssuranceAmerica confirmed 6.9 million individuals affected. Stolen data includes names, contact information, driver's license numbers, insurance policy details, and vehicle information. Driver's license numbers can be used to create fake IDs and open financial accounts in your name.
✅ What to do: Place a free credit freeze at all three credit bureaus — Equifax (equifax.com), Experian (experian.com), and TransUnion (transunion.com). Free, fast, and prevents fraudulent account openings.
✅ Good News This Week
- Thalha Jubair and Owen Flowers sentenced to prison for the 2024 Transport for London cyberattack that disrupted train services and exposed customer bank details.
- FBI secured a conviction against a man who operated a fake tech support scam defrauding elderly Americans out of millions of dollars.
- npm version 12 now disables install scripts by default — closing a primary method supply chain attackers used to silently install malware on developers' computers.
✅ Your Action List This Week
Do These Now:
- Update WordPress immediately — apply the July 2026 update for wp2shell (CVE-2026-60137). Also update all plugins.
- Run Windows Update and restart your computer. July Patch Tuesday fixed 570 vulnerabilities including two actively exploited right now.
- Establish a family safe word for emergency calls. AI voice clones cannot know your private safe word.
Do These This Week:
- Stop before scanning your next QR code in public. Check if it's a sticker placed over an original. Look at the URL before proceeding.
- Brief everyone in your business who handles payments: any change to payment details must be verified by phone before acting.
- If you had an AssuranceAmerica insurance policy: freeze your credit at all three bureaus.
- Test your business backup. Ransomware is up 43% — knowing your backup works before you need it is everything.
Do These This Month:
- Set up multi-factor authentication on your email and any remote access your business uses.
- Review your business backup strategy — you need a cloud backup AND a physical backup not permanently connected to your computer.
- If you develop with JavaScript or Node.js: update npm to version 12 ("npm install -g npm@12").
💡 This Week's Spotlight: Scams Have Gotten Smarter. Your Habits Need to Match.
Three of this week's stories — QR code scams, AI voice cloning, and fake invoice emails — all work by making something fake look and sound exactly like something real. The old ways of spotting scams no longer work reliably. Bad spelling and awkward phrasing are gone — AI writes perfectly. Caller ID can be spoofed. QR codes are indistinguishable to the eye.
What does work is adding a small speed bump between receiving something and acting on it. Unexpected call asking for urgent action? Hang up. Call back on a number you already have. Unexpected email asking you to pay? Verify by phone first. QR code in public? Check the URL before proceeding. Voice sounds familiar but the situation feels off? Use your family safe word. These habits cost nothing and take seconds. They make you nearly immune to the most common scams targeting people right now.
24 billion passwords leaked online · Free VPN apps failing to protect you · Instagram AI using your public photos · Windows Defender flaw finally patched · Crypto wallet SDK stealing seed phrases · WordPress sites hacked through old plugins · AI tools can be tricked into leaking your files
- ›24 billion usernames and passwords compiled from thousands of past breaches — now freely available to criminals
- ›Most free VPN apps on Android failing basic privacy tests — 2.4 billion downloads affected
- ›Instagram quietly enabled Meta AI Muse Image using your public photos without asking — opt-out required
- ›Windows Defender RoguePlanet flaw (CVE-2026-50656) finally patched July 9
- ›Crypto SDK @injectivelabs/sdk-ts v1.20.21 published July 8 stealing wallet seed phrases
- ›WP-SHELLSTORM targeting 1.4 million WordPress sites via Breeze caching plugin and JCE editor
- ›GhostApproval: Cursor, Claude Code, Amazon Q, Copilot can be tricked into leaking sensitive files
The Week in 60 Seconds
A lot happened this week that directly affects regular people. The biggest story: a colossal database of 24 billion leaked usernames and passwords was found online — larger than any previous leak. If you reuse passwords across accounts, one of yours is almost certainly in it. The good news: there's a free tool to check. Also this week: most free VPN apps on Android phones were found to be failing at the one thing they're supposed to do. Instagram quietly enabled a feature that lets people use your public photos to generate AI images. A patch finally arrived for the Windows Defender flaw we've been tracking for weeks. And WordPress site owners have a new wave of attacks to watch out for.
The good news column is solid this week: a ransomware negotiator was sentenced to prison, Google disrupted a massive botnet, and a Vietnamese piracy network was taken down.
🚨 The Big Story: 24 Billion Passwords Leaked Online
24 Billion Records — The Largest Credential Leak Ever Recorded
Who is affected: Everyone with an online account — email, social media, banking, streaming, shopping.
Security researchers discovered a database containing approximately 24 billion usernames and passwords compiled from thousands of past data breaches. Criminals use databases like this in credential stuffing attacks: they try your email and password combination on every service until one works. If you've ever reused a password on more than one site, the risk is real.
✅ What to do: Check if your email appears in known breaches at haveibeenpwned.com (free, trusted). If it does, change your password on every account that uses the same password. Set up two-factor authentication on email, banking, and social media. A password manager like Bitwarden (free) makes this manageable.
🛠️ Your Devices This Week
Windows Defender 'RoguePlanet' Flaw — Finally Patched
Who is affected: Everyone using Windows 10 or Windows 11.
The RoguePlanet flaw in Windows Defender (CVE-2026-50656) has finally been patched by Microsoft. This flaw allowed someone with access to your computer to take complete SYSTEM-level control. The patch arrived on July 9.
✅ What to do: Start → Settings → Windows Update → Check for updates → install → restart. Do this today.
Most Free VPN Apps on Android Are NOT Actually Protecting You
Who is affected: Android users who use a free VPN app.
Researchers tested 281 popular free VPN apps and found most fail at the basics. 29 apps allow browsing traffic to leak outside the encrypted tunnel. 61 apps send some data in plain text. Apps with at least one problem have been downloaded more than 2.4 billion times.
✅ What to do: Look up your app on vpnpro.com. Best free options with verified no-leak records: ProtonVPN Free and Windscribe Free.
Fake 7-Zip Installer Turns Your Computer Into a Criminal's Relay
Who is affected: Anyone who recently downloaded 7-Zip from a website other than 7-zip.org.
A campaign called Lurking Lizard set up more than 230 fake download sites. When someone installs the fake version, their computer is quietly enrolled into a residential proxy network — criminals route their attacks through your home internet connection.
✅ What to do: Only download 7-Zip from 7-zip.org. If you downloaded it elsewhere recently: uninstall, run Malwarebytes, reinstall from 7-zip.org.
📸 For Content Creators & Social Media Users
Instagram's New AI Tool Can Use Your Public Photos to Generate Images — Without Asking
Who is affected: Anyone with a public Instagram account.
Meta quietly enabled Muse Image — an AI tool that allows other users to use your public Instagram photos to generate AI content. People can even @-mention your account in a Meta AI prompt to pull your images into AI-generated scenes. This feature was turned on by default for all public accounts.
✅ What to do: Instagram Settings → Account → Meta AI → Training and Usage → turn off "Allow Meta AI to use my content."
AI Coding Tools Can Be Tricked Into Leaking Your Files — GhostApproval Attack
Who is affected: Developers and creators who use Cursor, Claude Code, or GitHub Copilot.
Security researchers at Wiz found a flaw affecting six popular AI coding assistants. A booby-trapped code project can trick the AI into asking permission to edit one harmless file, but the actual change lands on a sensitive file — potentially exposing private keys or passwords.
✅ What to do: Review exactly what files the AI is asking to edit before approving. Keep your AI coding assistant updated — patches are being released.
🏢 For Small Business Owners & Entrepreneurs
WordPress Sites Hacked Through Old Plugins — Breeze Caching and JCE Editor
Who is affected: Business owners with WordPress websites with outdated plugins.
WP-SHELLSTORM has been systematically breaking into WordPress websites through outdated Breeze caching plugin and JCE editor plugin. Attackers install hidden backdoors and sell that access to other criminals. Target list: more than 1.4 million websites.
✅ What to do: WordPress dashboard → Plugins → update every plugin, especially Breeze. Then Users → All Users and delete any administrator account you don't recognize.
Crypto Wallet SDK Supply Chain Attack — Seed Phrases Being Stolen
Who is affected: Anyone who accepts or holds cryptocurrency using @injectivelabs/sdk-ts.
Attackers compromised Injective Labs and published malicious version 1.20.21 of @injectivelabs/sdk-ts on July 8. Anyone who installed it had malware run that stole cryptocurrency wallet private keys and seed phrases.
✅ What to do: If you installed version 1.20.21 on July 8: treat your wallet credentials as compromised. Move funds to a new wallet and generate new seed phrases. Seed phrases should always be stored on paper, never digitally.
✅ Good News This Week
- Ransomware negotiator Angelo Martino — who secretly worked for BlackCat/ALPHV while pretending to help victims — sentenced to 70 months in federal prison.
- Google disrupted the NetNut botnet by disabling its command infrastructure and pushing protections to ~2 million affected Android devices via Play Protect.
- Vietnamese authorities arrested seven people behind HiAnime, an illegal streaming network that generated $12.85 million in ad revenue.
✅ Your Action List This Week
Do These Now:
- Check haveibeenpwned.com with your email address and change any reused passwords immediately.
- Run Windows Update and restart your computer — the RoguePlanet Defender flaw is patched as of July 9.
- If you have a WordPress website: update all plugins and check Users for unknown accounts.
- Turn off Meta's AI image training on Instagram: Settings → Account → Meta AI → Training and Usage → off.
Do These This Week:
- Check your free VPN app on vpnpro.com. Safest free options: ProtonVPN Free and Windscribe Free.
- Only download 7-Zip from 7-zip.org.
- Enable multi-factor authentication on email, banking, and social media accounts.
- Update your AI coding assistant (Cursor, Claude Code, Copilot).
- Ensure cryptocurrency seed phrases are written on paper and stored physically — not digitally.
Avalon ransomware via fake legal emails · SharePoint exploit active · Bad Epoll Linux root flaw · Mac malware steals passwords · AI agent automates attacks · Scattered Spider teen charged · Claude Fable 5 launches
- ›Avalon ransomware framework arrives via fake legal documents (password-protected attachments)
- ›Microsoft SharePoint CVE-2026-45659 actively exploited by ransomware groups — CISA deadline was July 4
- ›Bad Epoll (CVE-2026-46242) lets any Linux user take full root control
- ›PamStealer Mac malware disguised as popular clipboard app Maccy
- ›JadePuffer AI agent ran hundreds of attacks overnight with no human involvement
- ›Scattered Spider member Peter Stokes, 19, federally charged
- ›Anthropic launches Claude Fable 5 — now widely available
The Week in 60 Seconds
This week brought a ransomware framework sophisticated enough to earn its own name: Avalon. It arrives via fake legal documents, hides inside files that look safe, and quietly takes over a computer before deploying ransomware. Microsoft SharePoint — the file-sharing system used by millions of businesses — has an actively exploited flaw that ransomware groups are using right now. A new Linux root vulnerability called Bad Epoll was fixed but needs to be applied immediately. Mac users face a new password-stealing app disguised as a popular clipboard tool. And in an industry first, a cybercrime group used an AI agent to automate attacks with almost no human involvement — running hundreds of attacks while the criminals slept. On the positive side: Anthropic launched Claude Fable 5, and a 19-year-old Scattered Spider member has been charged by federal prosecutors.
🛠️ Urgent Updates Your Devices Need Now
Microsoft SharePoint — Ransomware Groups Are Actively Exploiting This Right Now
Who is affected: Businesses that use Microsoft SharePoint for internal file sharing, team collaboration, or document management.
CISA confirmed ransomware attackers are actively exploiting CVE-2026-45659 in SharePoint. An attacker who has any kind of login to your SharePoint system (even a basic account) can use this to run their own code on your server. Microsoft patched this in May. The CISA federal deadline was July 4.
✅ What to do: Ask your IT provider or Microsoft 365 administrator: "Has the May 2026 SharePoint patch been applied?" If you manage SharePoint yourself: apply all pending updates immediately. This cannot wait.
Linux Computers — "Bad Epoll" Flaw Lets Anyone Take Full Control
Who is affected: Anyone running Linux on a computer, server, or Android device.
Bad Epoll (CVE-2026-46242) lets any ordinary user with access to a Linux machine take complete root control. It affects Linux desktops, servers, and Android devices. A fix is available.
✅ What to do: Update Linux systems immediately. On Ubuntu or Debian: run sudo apt update && sudo apt upgrade. On Red Hat/CentOS/Fedora: run sudo dnf update. For Android: install the latest security update.
Mac Users — "PamStealer" Malware Disguised as a Popular Clipboard App
Who is affected: Mac users who downloaded a clipboard manager called "Maccy" from any site other than maccy.app.
Security researchers found malware called PamStealer distributed through a fake website designed to look like the legitimate Maccy clipboard manager. When installed, it steals your Mac login password and sends it to attackers — along with passwords stored in your browser.
✅ What to do: Only download Maccy from the official site: maccy.app. If you downloaded it from any other website recently, delete the app immediately and change your Mac login password. Run a scan with Malwarebytes for Mac.
🚨 The Biggest Threats This Week
Avalon — A New Ransomware System Arriving as a Fake Legal Document
Who is affected: Business owners, office managers, and anyone who receives contracts, invoices, or legal documents by email.
Security researchers documented Avalon — a new ransomware framework delivered through emails that appear to contain legal documents (court notices, contracts, compliance paperwork). The attachment is password-protected (the password is in the email to bypass security filters), and when opened, it quietly installs itself and begins taking over the computer. The ransomware it deploys is called CrownX.
✅ What to do: Do not open password-protected attachments from senders you do not know personally — even if the email looks official. Legitimate courts and legal firms do not send unsolicited password-protected archives. Verify by calling the sender directly using a phone number you find yourself.
AI Agent Automates Hundreds of Cyberattacks While Criminals Sleep
A criminal group called JadePuffer used an AI agent to automate cyberattacks almost entirely without human involvement. The AI independently sent phishing emails, harvested credentials, logged into victim accounts, and exfiltrated data — running continuously through the night. Separately, another group called Kairos used AI to write personalized ransom notes and successfully extorted $1 million from a US government-linked entity.
✅ What to do: Enable multi-factor authentication (MFA) on every account — this week. If an AI agent steals your password but cannot get past MFA, the attack stops there.
NetNut Rented Out Millions of Hacked Devices — Your Router May Have Been One
A proxy service called NetNut was found renting access to millions of compromised devices — including home and office routers — to cybercriminals and nation-state hackers. The devices were compromised without their owners' knowledge.
✅ What to do: Restart your router (unplug for 30 seconds). Log into your router's admin page and check for firmware updates. Change the default admin password. If your router is more than 5–6 years old, consider replacing it.
PolinRider — 108 Malicious Packages and Browser Extensions
A new supply chain campaign published 108 malicious packages across npm and the Chrome and Firefox extension stores. The packages appeared legitimate but were designed to steal credentials and API keys, specifically targeting developers who use AI coding tools.
✅ What to do: Review your browser extensions and remove anything you do not actively use or do not recognize. Audit recent npm package installs and check your AI service billing dashboards for unexpected usage.
North Korea Targets Developers with Fake Job Interview Assignments
North Korean hackers continued their "ContagiousInterview" campaign, sending fake job interview coding assignments to developers. When the developer runs the code, malware called BeaverTail and OtterCookie is installed — stealing cryptocurrency wallets, browser passwords, and developer credentials.
✅ What to do: Never run code from someone you don't know on your main work computer. Use an isolated environment for any unsolicited coding assignments.
🤖 AI This Week
Anthropic Launches Claude Fable 5 — Now Widely Available
Anthropic released Claude Fable 5, making it widely available after a period of limited access. It is already being used by security researchers to find software vulnerabilities. Available at claude.ai. As with any AI tool: do not type passwords, client confidential information, or financial account details into any AI chat.
Agentic Browsers Can Be Tricked Into Abandoning Safety Rules
Security researchers demonstrated that agentic browsers — AI tools that browse the web for you — can be manipulated by malicious websites into abandoning their safety guidelines and exfiltrating your credentials (called context manipulation). Be cautious about which websites you allow AI browser agents to access, especially for tasks involving sensitive accounts.
Microsoft Moving to Quantum-Safe Encryption Sooner Than Expected
Microsoft announced it is accelerating its transition to post-quantum cryptography (PQC) — encryption designed to resist attacks from future quantum computers. No immediate action required, but worth knowing for long-term IT planning.
✅ Your Action List This Week
Do These Now:
- Update Linux computers and servers immediately. Android users: install the latest security update.
- Ask your IT provider: "Has the May 2026 SharePoint patch been applied?" Ransomware groups are actively using this flaw.
- Do not open password-protected email attachments from unknown senders this week — Avalon ransomware spreads through fake legal documents.
- If you downloaded Maccy from any site other than maccy.app: delete it, change your Mac login password, and run Malwarebytes for Mac.
Do These This Week:
- Enable multi-factor authentication on every business account not already secured. AI agents are running credential-theft attacks overnight automatically.
- Restart your router. Update its firmware. Change the default admin password.
- Review browser extensions in Chrome and Firefox. Remove anything you don't actively use.
- Tell your team: do not open unsolicited coding assignments from "job opportunities" on your main work computer.
Do These This Month:
- Set up or update your AI usage policy. Three rules: no confidential data in AI chats, verify all AI tool invitations, treat AI output as a draft.
- Schedule a security awareness session for your team on AI-powered phishing.
- Test your business backups. Ask your IT provider to do a test restore.
💡 This Week's Spotlight: The Attack That Runs Itself
JadePuffer's AI agent attack deserves its own moment of attention. Until now, every cyberattack required a human to be doing something — sending the phishing email, logging into the stolen account, making decisions. Criminals had to be awake and paying attention. That friction limited scale. JadePuffer removed that friction. Their AI agent sent phishing emails, received replies, harvested credentials, logged into accounts, and exfiltrated data — all without a human in the loop. Hundreds of attack attempts while the criminals slept.
The good news: the defenses work the same way. Multi-factor authentication, tested backups, and a team trained to pause before acting on urgent requests are still the right answers. The businesses that weather this era well will be the ones that made the basic things permanent and tested — not the ones with the most sophisticated security tools.
OpenAI releases GPT-5.6 · Fake OpenAI invites stealing business secrets · MSG data published after Knicks title · Linux root flaw exploited within 24 hours · New macOS malware fools AI security tools · Five Eyes issue urgent AI warning
- ›Fake OpenAI workspaces tricking employees into sharing company secrets
- ›OpenAI releases GPT-5.6 in three versions: Sol, Terra, and Luna
- ›Five Eyes intelligence agencies issue urgent joint warning: AI weaponized against businesses
- ›macOS 'Gaslight' malware engineered to fool AI-powered security tools
- ›Madison Square Garden fan data (45 GB) published after Knicks NBA title — ShinyHunters
- ›Linux 'pedit COW' flaw exploited within 24 hours of disclosure
- ›Polymarket refunds $3M after third-party vendor hack
The Week in 60 Seconds
A big week. OpenAI launched its most powerful AI yet — GPT-5.6, in three versions — on the same day the Five Eyes intelligence alliance issued an urgent joint warning about AI being used as a weapon against businesses. Attackers are creating fake official-looking OpenAI workspaces to trick employees into sharing sensitive company information. The Madison Square Garden data dump landed publicly after the Knicks won the NBA Finals and reportedly declined to pay a ransom. A new Linux flaw was exploited within 24 hours of being made public. And a new Mac virus is specifically designed to trick the AI-powered security tools that defenders use. Good news: law enforcement disrupted a major illegal sports streaming operation, and Polymarket reimbursed $3 million to customers after a hack.
🤖 AI This Week — Powerful New Tools and New Scams
Fake OpenAI Workspaces Tricking Employees Into Sharing Company Secrets
Who is affected: Everyone who uses ChatGPT at work, especially business owners and their teams.
Attackers are creating fake OpenAI "tenants" (workspaces) that look identical to legitimate company ChatGPT setups. They then invite employees to join, making it look like an official company tool. When employees use the fake workspace, everything they type — business plans, customer information, legal documents, financial data — is captured by the attackers.
✅ What to do: Before joining any ChatGPT workspace or accepting any AI tool invitation at work: confirm with your manager or IT contact that it is a legitimate, company-approved setup. If you received an unexpected invitation, do not join it until you have verified it with a human colleague.
OpenAI Releases GPT-5.6 — Three Versions for Different Needs
OpenAI released GPT-5.6 in three versions: Sol (most powerful, best for complex tasks), Terra (balanced for everyday work), and Luna (fast and affordable). These are the most capable AI models OpenAI has released, initially to a limited set of companies working with the US government. Broader availability is rolling out over time.
Security reminder: Never type sensitive passwords, credit card numbers, or confidential client information into any AI chat.
Five Eyes Intelligence Agencies Issue Urgent Warning: AI Is Being Weaponized
The intelligence agencies of the United States, United Kingdom, Canada, Australia, and New Zealand issued a joint urgent warning: criminal groups and state-sponsored hackers are now using AI to dramatically improve the quality and scale of their attacks. AI is being used to write more convincing phishing emails, create fake voices and videos, accelerate hacking, and find weaknesses in business software faster than ever before.
✅ Three practical responses: (1) Slow down on unexpected requests — AI can now write a perfect email that sounds exactly like your CEO or your bank. Verify any unexpected financial request by phone before acting. (2) Enable multi-factor authentication everywhere. (3) Train your team — AI-powered scams now sound indistinguishable from real communications.
macOS 'Gaslight' Malware — Built to Fool the Security Tools That Protect Macs
Who is affected: Mac users, especially those in businesses that use AI-powered security software.
Researchers discovered "Gaslight" — Mac malware specifically engineered to confuse AI-assisted security tools. It hides fake debugging clues and misleading information inside itself to trick automated security scanners into thinking it's harmless.
✅ What to do: Keep your Mac fully updated via System Settings → Software Update. Do not download software from outside the Mac App Store or directly trusted software company websites.
🚨 Major Stories This Week
Madison Square Garden Fan Data Published Online After Knicks Win NBA Finals
Who is affected: Fans of the New York Knicks, New York Rangers, and anyone with an MSG account.
The ShinyHunters criminal group published a 45 GB archive of data stolen from Madison Square Garden Sports this week, reportedly after the company declined to pay a ransom. The timing was deliberate — released days after the Knicks won the NBA championship. The data includes customer emails, ticketing records, and internal files classifying high-profile individuals. At least one lawsuit has already been filed.
✅ What to do: If you have an MSG, Knicks, or Rangers account: change your password immediately and enable two-factor authentication. Be alert for targeted phishing emails that use your name, ticket history, or event details to appear credible.
Linux Computers — New Root Flaw Exploited Within 24 Hours
A new flaw called "pedit COW" in the Linux operating system was publicly disclosed and had a working exploit published within 24 hours. The flaw lets someone with basic access to a Linux machine take complete root (administrator) control. Unlike previous Linux flaws, this one is especially tricky because file-integrity security checks come back clean even after the exploit has run.
✅ What to do: Update your Linux systems immediately. On Ubuntu/Debian: run sudo apt update && sudo apt upgrade. On RHEL/CentOS/Fedora: run sudo dnf update.
Polymarket Refunds $3 Million to Customers After Third-Party Vendor Hack
Polymarket announced it will fully reimburse approximately $3 million to customers who lost money after attackers injected a malicious script into the platform's website via a breach at a third-party vendor. This is another example of why third-party vendor security matters: a hack of a service provider can impact the platform you trust even when the platform itself is not hacked.
PirloTV Sports Piracy Ring Dismantled — 44 Illegal Streaming Domains Seized
Law enforcement disrupted a major illegal sports streaming operation by seizing 44 domains linked to PirloTV. Beyond the legal issues, these platforms frequently deliver malware and steal payment credentials from users.
🏢 For Business Owners & Solopreneurs
The Fake OpenAI Workspace Attack Is Targeting Your Team Right Now. Tell your team right now that any AI tool invitation needs to be verified with you or your IT contact before they join. Five minutes of communication prevents a potentially devastating data leak.
The Five Eyes Warning Should Change How You Think About Phishing. Your team can no longer rely on bad spelling or awkward phrasing to identify fake emails. AI writes perfect emails. The only reliable defense is a process: any unexpected financial request or sensitive information request gets verified by phone before acting on it.
If Your Business Uses ChatGPT, You Need an AI Usage Policy. Three rules cover most of the risk: (1) Never type client names, passwords, or confidential information into any AI tool. (2) Verify any AI workspace invitation with your manager before joining. (3) Treat AI-generated output as a first draft that needs review.
✅ Your Action List This Week
Do These Now:
- Tell your team TODAY: any invitation to a ChatGPT workspace or AI tool must be verified with you before they join.
- Update Linux computers and servers immediately. The pedit COW flaw was exploited within 24 hours of disclosure.
- If you have an MSG or Knicks/Rangers account: change your password and enable two-factor authentication.
Do These This Week:
- Create or update your AI usage policy. Share it with your team in writing.
- Brief your team on AI-powered phishing. Any unexpected financial request needs phone verification before action.
- Update your Mac via System Settings → Software Update. Gaslight malware targets Macs and is designed to evade security tools.
- Audit which AI tools your team is using and which ones are company-approved.
Do These This Month:
- Test your business backups. Ransomware groups grew 40% in Q1 2026.
- Set up passkeys on your most important accounts. Search "set up passkey" on your Google, Apple, or Microsoft account to start.
💡 This Week's Spotlight: When AI Becomes the Weapon
This week brought two AI stories that sit on opposite sides of the same line: OpenAI's GPT-5.6 launch and the Five Eyes warning that AI is being used to attack businesses at unprecedented scale. The same tools that help you write emails faster also help criminals craft perfect phishing messages, create convincing fake voices, and find weaknesses in your software automatically.
For small business owners, one thing has changed permanently: you can no longer teach employees to spot scams by looking for bad writing. AI writes perfectly. The new rule is process, not detection. Any unexpected financial request, account change, or sensitive information request gets verified by a second method — a phone call, a walk down the hall — before anyone acts on it.
30,000 Fortinet logins stolen · Amazon One Medical hit by extortion gang · Apple iPhone chip flaw cannot be patched · AI coding plugins stealing your API keys · 15,000 WordPress sites cleaned up · Microsoft 365 Copilot one-click data theft flaw · UK warns AI code could cause security disasters
- ›Hackers built a database of 30,000 verified working passwords for Fortinet devices in 194 countries
- ›Amazon One Medical extortion threat — claimed 8.8 TB of healthcare data stolen
- ›Usbliter8: hardware flaw in iPhone A12/A13 chips that can never be patched
- ›15 malicious AI coding plugins found on JetBrains Marketplace stealing API keys
- ›Microsoft 365 Copilot SearchLeak flaw allowed one-click email/file theft (now patched)
- ›15,000 infected WordPress sites cleaned up in international law enforcement operation
- ›UK NCSC warns AI-written code is creating hidden security disasters in production software
The Week in 60 Seconds
This was a heavy week. Hackers built a secret database of 30,000 confirmed working passwords for Fortinet networking equipment used by businesses in 194 countries. A major healthcare company was hit by extortion threats claiming 8.8 TB of data was stolen. Researchers revealed a flaw in some iPhones and iPads that cannot ever be fixed because it's in the hardware itself. Malicious fake AI tools on developer marketplaces were caught stealing credentials. A massive law enforcement operation cleaned up 15,000 infected websites. And the UK's top cybersecurity agency warned that AI-written code is creating security time bombs in software being shipped right now.
🛠️ Urgent Updates Your Devices Need
Chrome — Update It Again (Fifth Zero-Day of 2026)
Google released another emergency Chrome security update, fixing CVE-2026-11645 — a serious flaw that attackers were already actively exploiting. This is the fifth time in 2026 that attackers found a Chrome flaw before Google could patch it.
✅ What to do: Open Chrome → three dots → Help → About Google Chrome → let it update → restart. Do this now.
Apple iPhones & iPads — A Flaw That Can Never Be Fixed
Who is affected: Anyone with an iPhone or iPad using an A12 or A13 chip (iPhone XS, XR, 11, 11 Pro, SE 2nd gen, iPad Air 3rd gen, iPad mini 5th gen).
Researchers published a working exploit called "Usbliter8" that can permanently compromise an iPhone by exploiting a flaw burned into the chip at the factory. No software update can ever fix it. However, the attack requires the attacker to physically hold your device and connect it to special hardware within two seconds in a specific mode.
✅ What to do: Keep your device physically secure. Enable a strong PIN or password so that even if someone picks it up, they cannot put it into the vulnerable mode (DFU mode). This flaw cannot be exploited remotely.
🚨 Major Breaches & Threats This Week
30,000 Fortinet Business Logins Stolen — Companies in 194 Countries
Who is affected: Small and medium businesses that use Fortinet VPN or firewall equipment.
Cybersecurity researchers discovered that hackers have built a database of over 30,000 verified, working login credentials for Fortinet network devices stolen from companies across 194 countries. These are real, active passwords that work right now. Companies including Fortune 500 firms and government agencies are confirmed in the stolen database.
✅ What to do: Contact your IT provider TODAY and ask: "Have our Fortinet devices been affected by the FortiBleed credential theft campaign?" Ask them to reset all Fortinet admin passwords immediately and apply outstanding firmware updates.
Amazon One Medical — 8.8 Terabytes of Healthcare Data Under Extortion Threat
Who is affected: Anyone who uses Amazon's One Medical healthcare service.
An extortion group claimed to have stolen 8.8 terabytes of data from One Medical, Amazon's healthcare subsidiary. If real, the data could include medical records, appointment histories, insurance information, and personal contact details.
✅ What to do: If you are a One Medical patient: change your account password and enable two-factor authentication at onemedical.com. Be alert for phishing emails that use your medical history or appointment details to appear legitimate.
Salesforce — Customer Data Accessed Through a Third-Party App
An extortion group called Icarus gained access to customer data stored in Salesforce by compromising a third-party app called Klue that was connected to the platform. Salesforce itself was not hacked — the entry point was a trusted connected app.
✅ What to do: If your business uses Salesforce: review which third-party apps are connected to your Salesforce account (Setup → Connected Apps). Remove any apps you no longer actively use. Every connected app is a potential entry point.
WordPress SocGholish Malware — 15,000 Sites Cleaned by Law Enforcement
Dutch law enforcement, working with agencies from Canada, Germany, and the United States, cleaned up nearly 15,000 infected WordPress websites that had been secretly redirecting visitors to malware. The operation took down 106 criminal servers.
✅ What to do: For website owners: log in to your WordPress dashboard and run all available updates. For everyone: if you visit a website and your browser suddenly opens a pop-up asking you to update Chrome or install a PDF viewer, close it immediately without clicking anything.
🤖 AI Tools — New Risks This Week
Fake AI Coding Plugins Stealing Developer Credentials — 15 Malicious Plugins Found
Who is affected: Freelancers, developers, and anyone who uses JetBrains tools (IntelliJ, PyCharm, WebStorm) with plugins.
Security researchers found 15 malicious plugins on the official JetBrains Marketplace. Each pretended to be an AI coding assistant. When installed, they silently stole AI API keys — credentials connected to your billing account. A stolen API key can rack up thousands of dollars in unauthorized charges before you notice.
✅ What to do: Review every plugin installed in your JetBrains IDE and remove any AI assistant plugin you didn't specifically install yourself or that has very few reviews. Check your AI service billing dashboards for unexpected usage spikes.
Microsoft 365 Copilot — "SearchLeak" One-Click Data Theft Flaw (Now Patched)
Security researchers discovered a flaw called SearchLeak in Microsoft 365 Copilot that allowed attackers to steal a victim's emails, calendar appointments, and files with a single click on a seemingly legitimate Microsoft link. Microsoft has patched this flaw.
No action needed — Microsoft fixed this. But this is a good reminder: even links that appear to go to official company websites can be crafted to cause harm.
UK's Top Cybersecurity Agency Warns: AI-Written Code Is Creating Security Disasters
The UK National Cyber Security Centre (NCSC) warned that AI coding tools are producing code with serious security flaws — and developers are shipping it without proper review. The NCSC specifically warned this could create "security disasters" if left unchecked.
✅ What to do: If your business uses AI-generated code: ask your developer "Has any AI-generated code on our website or app been reviewed by a human for security issues?" Treat AI-generated code as a first draft that needs security review before going live.
✅ Your Action List This Week
Do These Now:
- Update Chrome. Three dots → Help → About Google Chrome → update → restart.
- If your business uses Fortinet VPN or firewall: call your IT provider right now to change all passwords and apply firmware updates.
- If you use JetBrains coding tools with plugins: review all installed plugins and remove any AI assistant plugins you didn't intentionally install.
- If you are a One Medical patient: change your password and enable two-factor authentication.
Do These This Week:
- Review connected apps in Salesforce, your email platform, and your website. Remove any apps you no longer actively use.
- Update your WordPress site — core, theme, and all plugins.
- Set up billing alerts on any AI service you pay for. A sudden spike in usage is an early warning of a stolen API key.
- Keep your iPhone or iPad physically secure. The Usbliter8 hardware flaw requires someone to physically hold your device.
Do These This Month:
- Ask your developer: "Has any AI-generated code on our website been reviewed for security?"
- Set up passkeys on your most important accounts. More secure than passwords and cannot be phished.
- Test your business backups. Ask your IT provider to do a test restore.
💡 This Week's Spotlight: Why "Trusted" Doesn't Mean "Safe"
Three separate incidents this week had the same root cause: attackers got in through something the victim already trusted. Salesforce wasn't hacked — a trusted app connected to it was. WordPress sites weren't hacked directly — trusted plugins were backdoored. Microsoft 365 Copilot wasn't hacked — a trusted microsoft.com link was weaponized. JetBrains Marketplace wasn't hacked — trusted-looking plugins on it were malicious.
Modern attackers are not trying to smash down the front door. They are finding side doors — trusted connections, established relationships, legitimate-looking tools — and slipping through quietly. The practical rule: regularly audit what has access to your accounts and devices, and remove anything you no longer actively need. A connected app you forgot about six months ago is exactly the kind of side door attackers are looking for.
Biggest Windows update in history · Unpatched Defender flaw · World Cup scams at full force · ShinyHunters hits NY Knicks & Rangers · Ransomware revenue up 40% · 152 Chrome extensions caught spying · Agentjacking attacks on AI tools
- ›Microsoft released 200 security fixes in one day — the largest Patch Tuesday in history
- ›New Windows Defender flaw 'RoguePlanet' — no fix yet — all Windows 10 and 11 affected
- ›FIFA World Cup: 4,300+ fake FIFA websites live, banking malware in streaming apps
- ›ShinyHunters claims breach of Madison Square Garden — Knicks & Rangers fan data
- ›Ransomware criminal revenue up 40% in Q1 2026
- ›152 Chrome extensions caught secretly recording browser activity
- ›'Agentjacking' attack hijacks AI coding tools via monitoring service compromise
The Week in 60 Seconds
This was one of the busiest weeks of the year for security. Microsoft released the largest single security update in its history — 200 fixes in one day. Hours later a researcher dropped a new Windows flaw with no fix. The FIFA World Cup opened and scammers are running at full capacity. ShinyHunters claimed to have stolen data from Madison Square Garden, home of the New York Knicks and Rangers. A new attack called "Agentjacking" hijacks AI coding tools on developer computers. 152 Chrome extensions were caught secretly recording what you do online. And ransomware criminal groups grew their income by 40% in just three months.
🛠️ Windows — Update Now, Then Watch for One More
Microsoft Released 200 Security Fixes in a Single Day — The Biggest Ever
Who is affected: Everyone using a Windows computer — at work or at home.
On June 9, Microsoft patched approximately 200 security vulnerabilities in one update — the largest Patch Tuesday in the company's history. This included 33 critical flaws. If your computer has not restarted since early this week, it may be missing these protections.
✅ What to do: Click the Windows Start button → Settings → Windows Update → Check for updates → Install all → Restart your computer.
New Windows Defender Flaw "RoguePlanet" — No Fix Yet
Who is affected: All Windows 10 and Windows 11 users — including fully updated systems.
Hours after the 200-fix update, a security researcher published a new flaw in Windows Defender that lets someone with access to your computer take complete control. There is no patch yet. Microsoft is expected to release one soon.
✅ What to do: Keep Windows Update turned on and check it daily this week. Lock your screen whenever you step away (Windows key + L).
🚨 Scams & Fraud to Know About This Week
FIFA World Cup Scams — Running at Full Force All Month
Who is affected: Everyone — especially people following or traveling to World Cup matches.
The tournament is open and scam activity is at its peak. 4,300+ fake FIFA websites are live. One criminal operation runs 300 cloned FIFA login pages. Unofficial streaming apps are installing banking malware on phones. Fake FIFA emails are circulating in many languages.
✅ Three rules: (1) Tickets and streaming — FIFA.com only. (2) Do not download any unofficial streaming apps. (3) Treat all FIFA-themed emails as suspicious unless you initiated contact.
ShinyHunters Claims Breach of Madison Square Garden — Knicks & Rangers Fan Data
Who is affected: Fans of the New York Knicks, New York Rangers, and anyone who bought tickets or merchandise through MSG.
The ShinyHunters cybercrime group claimed it stole data from Madison Square Garden Sports. MSG has not confirmed the breach.
✅ What to do: If you have an account with MSG, the Knicks, or the Rangers: change your password now and enable two-factor authentication. Watch for targeted phishing emails using your name and ticket purchase history.
Ransomware Criminal Revenue Up 40% — Businesses Are the Primary Target
Rapid7 research confirmed that ransomware groups increased their revenue by nearly 40% in Q1 2026 compared to the same period last year. Small businesses are attractive targets precisely because they often have less security protection than large companies.
✅ What to do: Make sure you have working, tested backups of your business data stored somewhere separate from your main computers.
152 Chrome Extensions Caught Secretly Recording Your Browser Activity
Who is affected: Anyone who uses Google Chrome with browser extensions installed.
Security researchers found 152 Chrome extensions on the official Chrome Web Store — many disguised as "live wallpaper" tools — that were secretly logging user data and faking Google search traffic.
✅ What to do: Open Chrome and go to Extensions (three dots → Extensions → Manage Extensions). Review every extension installed. Remove any you do not recognize, any live wallpaper extension, and anything you haven't used recently.
New "Agentjacking" Attack Hijacks AI Coding Tools
Who is affected: Freelancers, developers, and solopreneurs who use AI coding assistants like Cursor, Copilot, or Claude Code.
Researchers discovered a new attack technique called Agentjacking that hijacks AI coding assistants by injecting a malicious instruction through a monitoring tool called Sentry. When an AI coding tool connects to a compromised Sentry setup, the attacker can silently run their own code on the developer's computer.
✅ What to do: Only allow AI tools to connect to services you explicitly approved and configured yourself. If you use Sentry for error tracking, ensure you're connected to the official sentry.io service.
✅ Your Action List This Week
Do These Now:
- Run Windows Update on every computer. The biggest Windows security update in history dropped this week.
- Audit your Chrome browser extensions. Remove anything you don't recognize, any live wallpaper tool, and anything you haven't used in months.
- If you use Dashlane: change your master password today.
- If you are a Knicks or Rangers fan with an MSG account: change your password and enable two-factor authentication.
Do These This Week:
- Keep Windows Update turned on and check daily. A new Defender flaw with no fix yet (RoguePlanet) is expected to be patched soon.
- Contact your IT provider and ask: "Have we applied the June 2026 Check Point VPN patch?"
- Test your business backups. Ask your IT provider to do a test file restore from your most recent backup.
- Share the FIFA warning with employees and family: FIFA.com only for tickets and streaming.
💡 This Week's Spotlight: Passwords Are Not Enough Anymore
The Dashlane breach this week was not a complicated hack. Attackers used a brute-force technique to repeatedly guess two-factor authentication codes until they got in. This matters because two-factor authentication — the extra code you get by text message — is something most people now use as their main security layer beyond a password. And for most everyday accounts, it's still a good protection. But it's not unbreakable.
The stronger version of two-factor authentication is a physical security key (like a YubiKey) or a passkey — a method built into modern iPhones, Android phones, and Windows computers. Unlike text message codes, these cannot be guessed, intercepted, or brute-forced. For most small businesses and home users, switching to passkeys for your most important accounts — email, banking, password manager — is the single most effective security upgrade available in 2026.
Seven Cisco SD-WAN zero-days in 2026 · IronWorm npm hits 36 packages · FIFA phishing peaks June 11 · Oxford careers platform breached · WFP cyberattack · Belgian banks must reimburse phishing victims · Smart TV botnet: 150M home IPs · OpenAI largest-ever ChatGPT overhaul
- ›CVE-2026-20245 in Cisco SD-WAN — seventh actively exploited zero-day with no patch available
- ›IronWorm: tenth supply chain attack campaign in 40 days — 36 npm packages infected
- ›FIFA World Cup opens June 11 — 4,300+ fraudulent domains, banking malware in streaming apps
- ›Oxford University CareerConnect breached via third-party provider Group GTI
- ›UN World Food Programme cyberattack — scope under investigation
- ›Belgian court rules banks must reimburse phishing victims immediately upon loss report
- ›Smart TV botnet enrolling 150 million home IP addresses — enterprise WFH risk
Executive Summary
The week of June 8, 2026 opens with three converging pressures: a seventh actively exploited Cisco SD-WAN zero-day with no patch available, the FIFA World Cup 2026 opening Thursday with over 4,300 fraudulent domains operational and banking malware embedded in streaming apps, and a tenth npm supply chain campaign (IronWorm) demonstrating that the record-breaking May supply chain surge has carried without interruption into June. This week also surfaces a landmark Belgian court ruling requiring banks to reimburse phishing victims immediately upon loss report, Oxford University's CareerConnect platform breached via third-party provider Group GTI, OpenAI's announcement of its largest-ever ChatGPT overhaul, and a smart TV botnet now spanning 150 million home IP addresses.
Headline Story: Seven Cisco SD-WAN Zero-Days — An Architecture Crisis
CVE-2026-20245 in Cisco Catalyst SD-WAN Manager — the seventh actively exploited SD-WAN vulnerability of 2026 — entered this week still without a patch. The vulnerability allows arbitrary command execution as root by an attacker on the network. This is the most concentrated pattern of exploitation against a single enterprise product line in 2026.
The Seven — A 2026 Timeline:
- CVE-2026-20127 — Authentication bypass exploited by UAT-8616 in early 2026
- CVE-2026-20130 — Privilege escalation in SD-WAN Manager
- CVE-2026-20155 — Configuration injection enabling persistent unauthorized access
- CVE-2026-20163 — Information disclosure used to map SD-WAN topology
- CVE-2026-20182 (CVSS 10.0) — Authentication bypass, maximum severity; CISA federal deadline was May 17
- CVE-2026-20198 — Command injection in SD-WAN overlay management
- CVE-2026-20245 (Active, No Patch) — Arbitrary command execution as root in Catalyst SD-WAN Manager
Architecture-Level Response: Assess blast radius — map what is accessible from a compromised SD-WAN Manager. Restrict management plane exposure — SD-WAN Manager interfaces should never be internet-facing. Evaluate architecture alternatives. Brief your board — seven exploited CVEs in one product is a board-level risk item.
Supply Chain Attacks — Week Ten
IronWorm — Tenth Supply Chain Campaign Since May 1
IronWorm represents the tenth confirmed supply chain attack campaign in 40 days, infecting 36 npm packages in coordinated waves. The fact that ten campaigns have landed in 40 days without a slowdown confirms that supply chain attack execution has been commoditized. The barrier to launching a new npm supply chain campaign is now measured in hours and dollars, not days and skills.
Recommended posture: Enable real-time npm behavioral monitoring. Freeze non-critical npm dependency updates this week. Audit all npm installs from June 5 onward against the IronWorm IoC list.
Smart TV Botnet — Enterprise WFH Risk Assessment
The smart TV botnet disclosed by Include Security — an SDK embedded in free apps on Samsung, LG, and Roku platforms that enrolls home TVs into a 150 million-plus IP pool — carries specific enterprise risk for organizations with work-from-home populations. Employees whose smart TVs are enrolled in this infrastructure are using corporate systems from networks where their IP is actively being used for third-party scraping operations.
✅ What to do: Advise work-from-home employees to segment work devices onto a dedicated home network VLAN or guest network, separate from smart TVs and IoT devices.
FIFA World Cup 2026 — Threat Brief
Documented fraud infrastructure: 4,300+ fraudulent FIFA domains registered since August 2025 — a ten-month infrastructure buildout. One operator running 300 cloned FIFA sites. Banking malware in streaming apps. 150 million ticket requests (30x oversubscribed) creating optimal conditions for ticket marketplace fraud.
Recommended employee advisory: Purchase tickets only at FIFA.com. Stream only through official broadcasters listed at FIFA.com. Do not download apps from unofficial sources. Treat all FIFA-themed email as high risk.
Threat Actor Activity & Incidents
Oxford University CareerConnect — Third-Party Breach via Group GTI
Oxford University disclosed that its CareerConnect careers platform, managed by third-party provider Group GTI, was compromised on June 8, 2026. The breach exposed student and graduate career data including contact information, employment history, and career application details.
Belgian Court — Banks Must Reimburse Phishing Victims Upon Loss Report
A Belgian court ruled that banks must reimburse phishing victims as soon as they report a loss, regardless of whether the victim is deemed to have acted negligently. The ruling reverses the burden of proof for phishing-related bank losses in Belgium and establishes a financial accountability precedent likely to influence EU-wide banking regulation.
OpenAI — Largest-Ever ChatGPT Overhaul Announced
OpenAI announced its largest-ever ChatGPT overhaul ahead of the company's anticipated public listing. Enterprise ChatGPT deployments should be re-validated against organizational AI usage policies following major platform updates — major updates can reset security configurations to defaults.
✅ Your Action List This Week
P1 — Immediate (Cannot Wait):
- Apply SD-WAN Manager network access controls for CVE-2026-20245. Restrict management interface to authorized administrator subnets. Remove internet-facing exposure.
- Apply Cisco UCM patch for CVE-2026-20230 if not done last week. Public PoC exploit is actively circulating.
- Issue FIFA World Cup phishing advisory to all employees before the opening match.
- Freeze non-critical npm dependency updates this week. Audit all npm installs from June 5 onward for IronWorm campaign packages.
P2 — This Week:
- Apply SolarWinds Serv-U patches for CVE-2026-28318. CISA KEV-listed with confirmed active exploitation.
- Verify Linux kernel CVE-2022-0492 is patched across all Linux systems. CISA KEV re-addition confirms 2026 active exploitation.
- Re-validate enterprise ChatGPT usage policy configurations following OpenAI's announced major overhaul.
- Commission Cisco SD-WAN architecture review. Seven exploited CVEs in six months is a board-level architecture risk.
P3 — This Month:
- Implement continuous third-party vendor monitoring for your highest-risk vendors.
- Add a third-party breach scenario to your next incident response exercise.
- Review contractual vendor notification requirements — ensure breach notification timelines of hours, not 72 hours.
💡 Weekly Spotlight: The Third-Party Vendor Is Your Largest Attack Surface
A pattern has emerged across the breach disclosures of May and June 2026 that is too consistent to be coincidental: the initial access vector is not a zero-day in the victim's own systems. It is a phishing email to a vendor employee, a compromised third-party platform, or a malicious package in a trusted supply chain. Oxford via Group GTI. Conagra via a vendor phishing attack. Canvas via Instructure. The Oncology Institute via TriZetto.
The perimeter your security program is designed to defend is not where the attacks are landing. Organizations apply rigorous security controls to systems they own and operate, then extend trust — often implicitly — to the vendors and service providers who connect to those systems. Annual security questionnaires and one-time certifications create compliance documentation without creating security assurance.
What continuous third-party risk management looks like: Move from annual to continuous vendor monitoring. Apply least-privilege to all third-party access. Maintain a live third-party access inventory. Include third-party breach scenarios in incident response exercises. Require vendors to notify you within hours, not days.
Written by BV Cyber Guardian · Powered by AI-assisted threat research · No spam · Unsubscribe anytime