Security Brief Daily

Jun 17, 2026 · #83


Listen Later

Episode 83

Security Brief Daily | 17 Jun 2026

In This Episode
  • Microsoft working on Defender patch for RoguePlanet zero-dayBleeping Computer
    Microsoft confirmed that it's working on a security patch for a Defender zero-day vulnerability named "RoguePlanet," disclosed one week ago. The security researcher who published a RoguePlanet exploit during the June 2026 Patch Tuesday (known as Nightmare Eclipse) said it...
  • Kodak confirms data breach claimed by ShinyHunters extortion gangBleeping Computer
    Kodak has confirmed that it's working with external cybersecurity experts to investigate a security breach after hackers gained access to some of the company's data. Founded in 1880 as the Eastman Kodak Company and headquartered in Rochester, New York, Kodak has 79,000...
  • 144 Mastra npm Packages Compromised via Hijacked Contributor AccountThe Hacker News
    As many as 144 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed...
  • Critical Fortinet FortiSandbox flaws now exploited in attacksBleeping Computer
    Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused. Fortinet released security updates for these three critical-severity security flaws (tracked as...
  • Ransomware gang abuses Microsoft Teams relays to hide malicious trafficBleeping Computer
    DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure. The backdoor abuses the Traversal Using Relays around NAT (TURN) protocol used by Microsoft Teams to distribute messages when a...
  • CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code ExecutionThe Hacker News
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The...
  • ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update LuresThe Hacker News
    Cybersecurity researchers have flagged multiple ClickFix campaigns that deliver three malware loaders called BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, per independent reports from Morphisec, BlueVoyant, and Huntress, respectively. Attacks involving BabaDeda Loader,...
  • China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based StealthThe Hacker News
    Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. "The Windows variants discovered are internally marked as WIN_DRV and WIN_PLUS," ESET said in a report shared with The Hacker...
  • Security Brief Daily is an AI-generated cybersecurity news podcast. Always verify critical information with primary sources.

    ...more
    View all episodesView all episodes
    Download on the App Store

    Security Brief DailyBy Security Brief Daily