HomeCybersecurity NewsCybersecurity News weekly roundup June 29, 2026
June 29, 2026

Cybersecurity News weekly roundup June 29, 2026

San Mateo, CA, June 29, 2026 — Developments, threats, and responses in the news last week.

STORIES LAST WEEK

Five Eyes agencies warn frontier AI could speed cyberattacks

Five Eyes agencies warned that frontier AI models could accelerate vulnerability discovery, exploit development and intrusion planning, raising pressure on defenders to shrink exposed services and patch faster. Reuters, June 22, 2026

AutoJack attack lets malicious webpages run code through AI browser agents

Microsoft’s AutoJack research showed a malicious page loaded by an AI browsing agent could cross the localhost boundary and run code on the host, exposing a weak default in agent tooling. The Hacker News, June 19, 2026

Amazon Q Developer patches workspace command execution flaws

AWS patched flaws in Language Servers for AWS that could let a trusted malicious workspace execute project commands through Amazon Q Developer plugins across major IDEs. Amazon Web Services, June 23, 2026

FortiBleed leak exposes credentials for 73,932 FortiGate systems

Insikt Group said a FortiBleed dataset exposed valid administrative and VPN credentials for 73,932 FortiGate systems, forcing edge-device credential rotation and exposure checks. Recorded Future, June 19, 2026

Cisco SD-WAN zero-day gave attackers root on service provider infrastructure

Mandiant said attackers used CVE-2026-20245 to turn compromised Cisco Catalyst SD-WAN administrator access into root on service provider infrastructure. Google Cloud, June 24, 2026

CISA orders Splunk Enterprise patching after exploited flaw

CISA ordered agencies to patch exploited Splunk Enterprise CVE-2026-20253 after proof-of-concept code showed unauthenticated file operations could be chained toward remote code execution. BleepingComputer, June 19, 2026

Attackers exploit PTC Windchill flaw to deploy web shells

Attackers exploited PTC Windchill CVE-2026-12569, an input validation flaw that can allow remote code execution through malicious network requests and web shell deployment. The Hacker News, June 26, 2026

Lantronix serial-to-IP flaw exploited after OT warning

A Lantronix EDS5000 command injection flaw was exploited after BRIDGE:BREAK disclosures, raising risk for serial-to-IP converters that bridge legacy industrial equipment into IP networks. SecurityWeek, June 25, 2026

Klue breach exposes Salesforce data through SaaS integration tokens

Klue’s Salesforce integration breach exposed customer data for multiple enterprise customers, showing how stolen OAuth tokens in SaaS connectors can bypass otherwise separate CRM environments. Cybersecurity Dive, June 23, 2026

FCC tightens security rules for undersea cable systems

The FCC voted to expand oversight of undersea cable systems and submarine line terminal equipment, adding supply chain restrictions to infrastructure that carries nearly all internet traffic. The Record, June 26, 2026

Tata Electronics confirms cyberattack after supplier documents appear online

Tata Electronics confirmed a cyber incident after alleged Apple supplier specifications and Tesla manufacturing documents appeared online, underscoring third-party exposure in high-tech manufacturing supply chains. The Record, June 23, 2026

NIST releases draft IoT cybersecurity rules for federal networks

NIST released draft SP 800-213 Rev. 1 to help federal agencies define cybersecurity requirements for IoT products before connecting them to government networks. NIST, June 24, 2026

Linux Foundation launches shared response program for critical open source flaws

The Linux Foundation launched Akrites as a shared security incident response and coordinated disclosure program for critical open source software, backed by major cloud, finance, and security companies. Linux Foundation, June 26, 2026

CI/CD flaws expose millions of repositories to supply chain takeover

Novee found exploitable GitHub Actions patterns that let unauthenticated attackers hijack workflows, push code, forge approvals, and steal credentials, turning generated CI/CD files into a supply chain control point. SecurityWeek, June 24, 2026

More cybersecurity news

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles