📰 DAILY THREAT BRIEFING
Wednesday, June 24, 2026
12 News Items
THN · BleepingComputer · Krebs · Dark Reading · SANS

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of June 24, 2026.

  1. Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
    — Bleeping Computer

    A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in atta…
  2. Tata Electronics confirms cyberattack as hackers leak data
    — Bleeping Computer

    Tata Electronics has confirmed in a statement to BleepingComputer that it was the target of a cyberattack that impacted parts of its IT infr…
  3. Scope of Salesforce Attacks Expands as Icarus Leaks Data
    — Dark Reading

    More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers' Salesforce data.
  4. Windows 11 KB5095093 update rolls out new Point-in-Time restore feature
    — Bleeping Computer

    ​​Microsoft has released the KB5095093 preview cumulative update for Windows 11 24H2 and 25H2, which fixes numerous bugs and begins roll…
  5. Healthtech firm Xolis suffers data breach impacting 1.4 million people
    — Bleeping Computer

    Healthcare technology company Xsolis says that sensitive data belonging to nearly 1.4 million individuals was compromised in a phishing atta…
  6. 'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
    — Dark Reading

    The CI/CD workflow weakness affects Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris analytics database, Cloudf…
  7. FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
    — The Hacker News

    A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operati…
  8. Scattered Spider Hackers Plead Guilty on Day 1 of Trial
    — Krebs on Security

    Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport …
  9. Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
    — The Hacker News

    Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roug…
  10. Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration
    — The Hacker News

    President Trump signed an executive order on June 22 setting hard deadlines for federal agencies to move high-value assets and high-impact…
  11. GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns
    — The Hacker News

    GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the r…
  12. SocGholish Takedown Highlights Malicious TDS Threats
    — Dark Reading

    SocGholish uses traffic distribution systems (TDSs) to provide initial access into victims' networks for cybercrime groups such as the notor…

Generated by HiveNet.ai Threat Intelligence Platform · June 24, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC