grc-scanSecurity & governance
News digest29 June 2026Archived edition

Cybersecurity News

This edition was published on 29 June 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest digest for the current picture.

The takeaway

Step back from the individual stories and the same few themes run through almost all of them. Unpatched internet-facing kit — VPNs, firewalls, enterprise apps — is still the number-one way attackers get in, and ransomware crews like "The Gentlemen" follow exactly that path. The unglamorous controls keep doing the heavy lifting: patch promptly (especially anything exposed to the internet), turn on MFA for remote access and email, change default passwords on every connected device, and keep tested offline backups. And for your team, the recurring human risk is the unexpected attachment or link — a few seconds of caution defuses most of it.

Cybersecurity News — 2026-06-29

Generated: 2026-06-29 | Sources: The Hacker News, eSecurity Planet, CYFIRMA, SecurityWeek, Dark Reading, CISA, Krebs on Security, CrowdStrike, BleepingComputer


1. ShinyHunters Hit 100+ Organisations via Oracle PeopleSoft Zero-Day

The ShinyHunters group exploited a zero-day remote-code-execution flaw (CVE-2026-35273, CVSS 9.x) in Oracle PeopleSoft to compromise more than 100 organisations — mostly colleges and universities — stealing hundreds of thousands of student records including names, addresses, dates of birth, GPAs, and student IDs. Oracle patched the vulnerability in its June Critical Security Patch Update alongside 243 other CVEs.

Why it matters for your business: If you or your suppliers use Oracle enterprise software, verify that the June patch bundle has been applied. Universities storing student data show that any sector running legacy enterprise platforms is in scope — not just tech companies.


2. Check Point VPN Authentication Bypass — Patch Now (CVE-2026-50751)

Check Point issued an urgent hotfix for a critical flaw in its IKEv1 VPN protocol that lets an unauthenticated attacker bypass authentication entirely. The vulnerability is under active exploitation in the wild, meaning attackers are already using it — not just testing it.

Why it matters for your business: If your office or remote workers connect via a Check Point VPN, apply the hotfix today. A VPN that can be bypassed without credentials gives attackers a direct route into your internal network.


3. FortiBleed Campaign — 86,644 FortiGate Firewalls Compromised

CISA and security researchers are warning about the "FortiBleed" campaign, which has compromised nearly 87,000 FortiGate firewall/VPN appliances by exploiting unpatched vulnerabilities. Many of the affected devices belong to small and medium businesses that rely on Fortinet for perimeter security.

Why it matters for your business: Firewalls and VPN gateways are high-value targets because compromising them gives attackers a front-row seat to your entire network. If you run FortiGate hardware, check your firmware version against Fortinet's current advisory and update immediately.


4. "The Gentlemen" Ransomware — 332 Victims, Targeting VPNs and Firewalls

The Gentlemen is now the second most active ransomware group globally, with over 332 published victims since mid-2025. The group's entry point is consistently internet-facing devices — VPNs, firewalls, and remote-access services — and once inside they can encrypt an entire network within hours.

Why it matters for your business: The pattern is clear: an unpatched firewall or VPN appliance is step one for ransomware. The trio of patching, MFA on remote access, and tested offline backups stops the majority of these attacks before they become catastrophic.


5. Amazon Q AI Coding Assistant Flaw — CVE-2026-12957 (CVSS 8.5)

A vulnerability in how Amazon's Q AI coding assistant handled Model Context Protocol (MCP) configurations meant a malicious project file downloaded via git clone could escalate to full cloud-account compromise. The flaw has been patched.

Why it matters for your business: AI dev tools are becoming a real attack surface. If your team uses AI coding assistants or AI-connected tools, treat their configuration files and extensions as untrusted — a poisoned project file should not be able to reach your cloud credentials.


6. Linux Kernel "pedit COW" — Exploit Public Within 24 Hours (CVE-2026-46331)

An out-of-bounds write in the Linux kernel's traffic-control packet-editing subsystem lets a local unprivileged user gain full root access. A working public exploit appeared within a day of the CVE being published, dramatically shrinking the window for patching.

Why it matters for your business: Any Linux server, container host, or shared-hosting environment where an attacker already has limited access can be fully taken over. "Patch soon" means now — with a public exploit available, automated attack tools will follow quickly.


7. WordPress "Gravity SMTP" Plugin Exploited — 100,000 Sites at Risk (CVE-2026-4020)

Attackers are actively exploiting a recently disclosed flaw in Gravity SMTP, a WordPress plugin installed on approximately 100,000 websites, to take control of affected sites.

Why it matters for your business: WordPress plugins remain one of the most common ways small-business websites get compromised. If you run WordPress, enable automatic updates for plugins, remove any you don't actively use, and check for this specific plugin immediately.


8. Kimwolf DDoS Botnet Operator Arrested

Canadian authorities arrested a 23-year-old Ottawa man (alias "Dort") for allegedly building and operating Kimwolf — an IoT botnet that enslaved millions of smart devices for large-scale distributed denial-of-service attacks. The botnet spread by exploiting default credentials on routers, cameras, and other connected devices.

Why it matters for your business: IoT devices (smart TVs, cameras, network printers, routers) left on factory-default passwords are routinely hijacked and weaponised. Change default passwords on every connected device and keep firmware updated — this arrest shows authorities are catching up, but prevention is faster than prosecution.


9. Amadey & StealC Malware Infrastructure Dismantled

A coordinated law-enforcement operation backed by Bitdefender, Bitsight, ESET, and Microsoft took down the criminal infrastructure behind the Amadey loader and StealC infostealer — two of the most widely-used tools for credential theft and ransomware staging.

Why it matters for your business: Infostealers like StealC harvest saved passwords from browsers, which then get sold and used in follow-on attacks. This takedown is a genuine win, but reset credentials on any machine that may have been exposed, and ensure endpoint protection is current on all staff devices.


10. Hotel Phishing Campaign — Hospitality Sector Targeted Across Europe and Asia

An active phishing campaign has been targeting hotels and hospitality businesses across Europe and Asia since April 2026. Attackers send photo-themed ZIP files; opening them installs a Node.js implant that gives attackers access to front-desk machines — which hold booking systems, payment data, and guest personal information.

Why it matters for your business: If you work in hospitality or any customer-facing service, treat unexpected email attachments — especially from "guests" — as suspicious. Staff awareness training and a clear rule of "don't open unexpected attachments" are cheap controls that directly address this threat.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Summaries are compiled from public threat-intelligence feeds and security news sources. This digest is for awareness purposes only and does not constitute professional security advice.