# Today's Top Stories
June 16, 2026
-
1The Hacker News general Jun 15Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
Palo Alto Networks confirmed active exploitation of CVE-2026-0257 (CVSS 7.8), an authentication bypass flaw in PAN-OS GlobalProtect portal and gateway components. An unknown threat actor is leveraging the vulnerability to gain unauthorized access to GlobalProtect portals. Security teams running PAN-OS with GlobalProtect enabled should prioritize patching immediately given confirmed in-the-wild exploitation.
-
2BleepingComputer general Jun 15Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
Cisco released patches for CVE-2026-20262, a privilege escalation vulnerability in Catalyst SD-WAN Manager that was actively exploited as a zero-day to gain root privileges. The flaw affects a widely deployed enterprise WAN management platform, making this a high-priority patch for network security teams managing SD-WAN infrastructure.
-
3BleepingComputer general Jun 15Chinese hackers breach REDCap servers, steal medical research
Google's Threat Intelligence Group exposed UNC6508, a China-nexus espionage actor that breached exposed REDCap research servers at North American medical, academic, and military institutions, deploying the InfiniteRed backdoor to steal credentials. The group operated undetected from at least 2023 into 2025, then abused victims' own Google Workspace email forwarding rules to silently exfiltrate sensitive research and defense communications.
-
4BleepingComputer general Jun 15New attack turned Microsoft 365 Copilot into 1-click data theft tool
Varonis Threat Labs disclosed 'SearchLeak,' a three-bug chain in Microsoft 365 Copilot Enterprise that allowed a single click on a legitimate microsoft.com URL to exfiltrate emails, OneDrive files, SharePoint content, and MFA codes. The attack exploited trusted domain infrastructure, bypassing standard URL filtering and anti-phishing controls; the vulnerability has since been patched by Microsoft.
-
5SecurityWeek general Jun 15FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service
The FBI and Google jointly dismantled 'Outsider Enterprise,' a phishing-as-a-service platform that operated more than 9,000 phishing sites, harvested nearly 4 million stolen credit cards, and caused approximately $1.9 billion in financial losses. The takedown represents a significant disruption to the cybercriminal ecosystem supplying phishing infrastructure at scale.
-
ADSponsoredProtect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected → -
6The Hacker News general Jun 15Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
Attackers compromised JavaScript files distributed via the CDN of Awesome Motive, affecting WordPress plugins OptinMonster, TrustPulse, and PushEngage in a supply-chain attack. The malicious code triggered only when a logged-in administrator loaded the page, silently creating a rogue admin account and installing a persistent backdoor plugin — a stealthy, privilege-aware infection vector affecting potentially hundreds of thousands of WordPress sites.
-
7SecurityWeek general Jun 15French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker
A threat actor identified as 'Misere' breached Tchap, the French government's sovereign encrypted messaging platform, compromising approximately 73,000 government accounts and allegedly stealing user messages and account data. The breach of a platform explicitly designed for secure official communications is a significant intelligence and operational security failure for French authorities.
-
8SecurityWeek general Jun 15Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges
Oleksii Oleksiyovych Lytvynenko, a Ukrainian national, pleaded guilty in the US to charges related to his role developing a malware loader for the Conti ransomware operation. The conviction advances ongoing US law enforcement efforts to prosecute members of the Conti group, which was responsible for hundreds of millions of dollars in ransomware damages globally.
-
9BleepingComputer general Jun 15Infinite Campus data breach affects 137,000 school staff accounts
ShinyHunters stole personal data from over 137,000 school staff accounts by exploiting Salesforce infrastructure belonging to Infinite Campus, a K-12 student information system used widely across the US, with the breach occurring in March 2026. The same group also claims to have stolen 297 GB of data from the Council of Europe, threatening to leak employee personal information.
-
10SecurityWeek general Jun 15Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer
A ransomware group called 'The Gentlemen' attacked Mackay Sugar, Australia's second-largest sugar producer, shutting down mill operations in a disruptive OT/IT incident. The attack demonstrates continued ransomware pressure on critical agricultural and food supply infrastructure, with physical operational consequences extending beyond data theft.