Episode 78
Security Brief Daily | 09 Jun 2026
In This Episode
Google patches new Chrome zero-day flaw exploited in the wild — Bleeping Computer
Google has released emergency updates to patch another Chrome zero-day vulnerability that has been exploited in the wild, the fifth such flaw patched since the start of the year. "Google is aware that an exploit for CVE-2026-11645 exists in the wild," the company said in a...CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day — Bleeping Computer
CISA has ordered U.S. government agencies to secure their Check Point Remote Access VPN and Mobile Access deployments against a critical vulnerability exploited in zero-day attacks by Qilin ransomware affiliates. Unauthenticated remote attackers can exploit this security flaw...Critical UniFi OS bug lets hackers gain root without authentication — Bleeping Computer
Attackers can chain three already fixed vulnerabilities in the Ubiquiti UniFi OS server to execute remote code with root privileges and without authentication. The security issues are tracked as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. They have been addressed in...LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE — The Hacker News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-42271 (CVSS...WhatsApp says it disrupted new NSO spyware phishing attacks — Bleeping Computer
WhatsApp has detected and stopped spear-phishing campaigns allegedly conducted by the NSO Group after investigating user reports of social engineering attacks. The NSO Group is an Israeli commercial spyware vendor known for its advanced “Pegasus” tool that has been deployed...One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public — The Hacker News
Security researchers have published a detailed, working exploit for a Linux kernel use-after-free that lets an unprivileged local user escalate to root and break out of a container. The flaw, CVE-2026-23111, sits in the kernel's nf_tables packet-filtering code and was patched...VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances — The Hacker News
A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET (aka GRIMBOLT) and AGENTPSD to target Linux systems. The activity has been attributed by Volexity to a...UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign — The Hacker News
Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial services in the U.S. between January and May 2026. The activity has been attributed by...Security Brief Daily is an AI-generated cybersecurity news podcast. Always verify critical information with primary sources.