Cybersecurity News
Understand the Threats. Protect What Matters.
- The FCC Wants to Kill Burner Phonesby Andy Greenberg, Lily Hay Newman on June 13, 2026 at 10:30 am
Plus: AI bug hunting fuels Microsoft’s biggest-ever Patch Tuesday, ShinyHunters ransomware gang exploits an Oracle zero-day, and more.
- Grok Is Still Hosting Sexualized Deepfakes of Famous Womenby Matt Burgess on June 11, 2026 at 7:41 pm
A WIRED investigation found dozens of “nudified” deepfake images and videos on Grok’s website, including nonconsensual depictions of celebrities and at least one prominent US politician.
- Drug Sites Hijacked Spotify’s Search Ranking Through Fake Podcastsby Dell Cameron on June 11, 2026 at 4:07 pm
A joint congressional report describes a spam operation that turned tens of thousands of fake podcasts into search-engine bait for illegal pharmacy and scam sites.
- Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Appsby Andy Greenberg on June 11, 2026 at 12:00 pm
The new open-source project could serve as the basis for a future of apps with features as complex as Slack, Discord, or Google Docs—but with added protection against surveillance.
- CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threatsby Lily Hay Newman on June 10, 2026 at 8:55 pm
“Defenders cannot afford to take weeks to patch,” one Cybersecurity and Infrastructure Security Agency official warned on Wednesday.
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to [email protected]
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authenticationby [email protected] (The Hacker News) on June 13, 2026 at 1:23 pm
Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system. “In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or truncate arbitrary
- U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationalsby [email protected] (The Hacker News) on June 13, 2026 at 5:42 am
Anthropic said on Friday it will “abruptly disable” its most advanced artificial intelligence (AI) models, Claude Fable 5 and Mythos 5, for all users after the U.S. government ordered it to suspend access to the models for foreign nationals, whether inside or outside the U.S., citing national security concerns. The AI company said it received an order at 5:21 p.m. ET, instructing it to suspend
- Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkitby [email protected] (The Hacker News) on June 12, 2026 at 7:33 pm
Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBPF rootkit to hide itself. The AUR is Arch Linux’s community package collection, and it is separate
- Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishingby [email protected] (The Hacker News) on June 12, 2026 at 6:59 pm
Google on Friday said it’s pursuing legal action against a Chinese cybercrime network, accusing it of using its Gemini artificial intelligence (AI) agent to send phishing text messages targeting Americans. The network is said to be behind the development and management of a phishing-as-a-service (PhaaS) software kit called Outsider, per the tech giant. “The operation weaponized Gemini to help
- China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decadeby [email protected] (The Hacker News) on June 12, 2026 at 6:17 pm
Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system itself. Sygnia, which tracks the group as Velvet Ant, says it backdoored the PAM and OpenSSH components that decide who is allowed to sign in, planting its access where ordinary cleanup could not reach it. The network it targeted had no










