Cybersecurity Daily: News & Threats
(00:00:00) CISA's June 11 Deadline, Chrome's 5th Zero-Day & 698 Ransomware Attacks in May (00:01:18) Chrome V8 Fifth Zero-Day 2026 (00:02:04) Microsoft's Record Patch Tuesday (00:03:04) Ransomware Surge May 2026 (00:03:34) GenAI Leakage and Azure Supply Chain (00:04:25) What to Watch Next CISA has issued one of its tightest-ever emergency directives: every US federal civilian agency must patch CVE-2026-50751, an authentication bypass in Check Point Remote Access VPN, by end of day June 11 — or disconnect. Qilin ransomware affiliates have had a working exploit since at least May 7, with confirmed attacks across dozens of organizations globally. Mitigation paths exist — disable IKEv1 or enforce machine certificate authentication — but the three-day clock leaves no room for low-priority treatment of legacy VPN debt. Elsewhere on the threat landscape, Google has patched CVE-2026-11645, a V8 out-of-bounds read/write flaw in Chrome that enables remote code execution via a crafted HTML page. This is Chrome's fifth confirmed zero-day in 2026, with a $55,000 bounty paid on discovery. Microsoft's June Patch Tuesday broke records: more than 200 critical CVEs addressed, including 360 Chromium-related fixes. Three had public exploits at release time. A researcher known as Nightmare Eclipse — claiming former Microsoft employee status — has publicly pledged a mass exploit drop on July 14, a date now worth monitoring. May 2026 ransomware data paints a stark picture: 698 reported attacks globally, up 48% year-over-year. Business Services saw a 359% spike. Three groups account for 39% of all attacks; 58 additional groups share the rest — a resilient, industrialized ecosystem. Finally: enterprise GenAI tools are leaking credentials and IP at scale, with 1 in 25 prompts carrying high-risk content, and Microsoft's Azure Durable Task SDK has suffered a second Shai-Hulud worm infection across 72 public repositories — raising questions about whether remediation of the May attack was ever complete. This episode includes AI-generated content.
40 episodes
Comments
0Be the first to comment
Sign up now and become a member of the Cybersecurity Daily: News & Threats community!