Skip to content
The Coolest Info

The Coolest Info

Subscribe
The Coolest Info

The Coolest Info

Security

Cybersecurity, vulnerabilities, threats, and defense

  • Security

NFCShare Malware Is Stealing Credit Cards Through Fake Banking Apps on GitHub — And It’s Spreading Fast

June 9, 2026June 9, 20260

NFCShare Android malware has expanded from targeting a single German bank to hitting financial institutions across Italy and Spain, using fake banking app updates hosted on GitHub to steal credit card data via NFC.

  • Security

New House AI Bill Could Reshape How Frontier Models Are Regulated — And It’s Already Sparking Fights

June 9, 20260

A bipartisan House bill would force frontier AI developers to submit to independent audits, fund open-source security grants, and create AI security testbeds — but its preemption of state AI laws has sparked fierce opposition from both sides of the aisle.

  • Security

2.5 Million Student Loan Borrowers Had Their Data Exposed — And Scammers Are Probably Already Planning to Use It

June 9, 2026June 9, 20260

A breach at Nelnet Servicing exposed names, addresses, and Social Security numbers for 2.5 million student loan borrowers — and the timing couldn’t be worse with loan forgiveness scams already circulating.

  • Security

Shai-Hulud Strikes Again: 19 Science PyPI Packages Trojanized to Steal Developer Secrets

June 9, 2026June 9, 20260

The Shai-Hulud supply-chain campaign compromised 19 scientific PyPI packages (Dynamo, Spateo, CoolBox, U-FISH, and more) with malware that steals developer secrets — cloud keys, publishing tokens, SSH keys, and AI tool configs. The payload triggers on any Python invocation.

  • Security

A One-Character Typo in the Linux Kernel Let Attackers Grab Root — And Full Exploits Are Now Public

June 9, 20260

A single-character typo in the Linux kernel’s nf_tables code (CVE-2026-23111) turns any unprivileged local account into root — and working exploits are now public. Full technical write-ups from Exodus Intelligence and FuzzingLabs detail Debian, Ubuntu, and RHEL exploitation paths.

  • Security

Your Marketing Team Is Vibe Coding Apps Connected to Production Data — and Security Has No Idea

June 8, 2026June 8, 20260

Vibe-coded apps built by non-developers are exposing medical records, financial data, and corporate secrets on the open internet — and most security teams have zero visibility into what’s been deployed.

  • Security

Meta Catches NSO Group Running Fresh WhatsApp Phishing Campaign — Then Files Contempt Order

June 8, 20260

Meta detected a new NSO Group spear-phishing campaign targeting WhatsApp users, took down the infrastructure, and filed a contempt order — the spyware vendor was already under a permanent injunction.

  • Security

Three Ubiquiti UniFi OS Flaws Chain Together to Give Attackers Root — No Password Needed

June 8, 2026June 8, 20260

Bishop Fox researchers have confirmed that three patched Ubiquiti UniFi OS Server vulnerabilities (CVE-2026-34908/34909/34910) chain into an unauthenticated root RCE. No credentials or user interaction required — and there’s no authentication log trail to detect it.

  • Security

Attackers Are Bypassing Check Point VPN Passwords Using a Deprecated Protocol Nobody Should Still Be Using

June 8, 2026June 8, 20260

A critical Check Point VPN flaw (CVE-2026-50751) lets attackers bypass passwords entirely by exploiting the deprecated IKEv1 protocol. Active exploitation is underway against dozens of organizations, with at least one Qilin ransomware affiliate already leveraging the access.

  • Security

Check Point VPN Zero-Day Exploited by Qilin Ransomware Gang — Patch Now

June 8, 20260

Check Point’s VPN zero-day CVE-2026-50751 is being actively exploited by the Qilin ransomware gang. Only affects deprecated IKEv1 setups, but patching can’t wait.

  • 1
  • 2
  • 3
  • 4
  • 5

Recent Posts

  • OnePlus Is Chasing 240Hz Phone Screens — Here’s Why That’s Complicated
  • He Lost €5,900 to a Bank Spoofing Scam — Then Watched His Bank Blame Him and Lose in Court
  • Attackers Abuse Google DoubleClick to Stealthily Deliver .NET Malware
  • Microsoft Investigative Playbook for Copilot and Azure AI: A Practical Guide
  • AethexAI Raises $3M to Build Voice AI That Actually Works in Africa and the Middle East

Recent Comments

No comments to show.

Archives

  • June 2026

Categories

  • crypto
  • Security
  • Tech
    Online Newspaper - News / Magazine WordPress Theme 2026.
    Back To Top