grc-scanSecurity & governance
News digest30 June 2026Archived edition

Cybersecurity News

This edition was published on 30 June 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest digest for the current picture.

The takeaway

This month's thread is people, not just machines. The fastest-growing attacks — device-code phishing, fake AI-tool sign-ins, reused passwords from breaches like Temu — work by tricking someone into approving or typing a credential, so the highest-value habits are human: question any unexpected "approve this sign-in" prompt, use a unique password per site, and turn on MFA everywhere. Underneath that, the basics still decide outcomes: turn on automatic updates (Microsoft's record 198-CVE Patch Tuesday includes no-click critical flaws), keep tested offline backups, and ask whoever manages your software about its patching and dependency hygiene. And if you supply public-sector or regulated clients, tighter UK rules on incident reporting and ransom payments are coming — start documenting your incident response now.

Cybersecurity News — 2026-06-30

Generated: 2026-06-30 | Sources: The Hacker News, TechCrunch, BleepingComputer, Microsoft Security Blog, CrowdStrike, Tenable, eSecurity Planet, SecurityWeek, Check Point Research, CISA


1. Temu Allegedly Exposed 310 Million Customer Records

A threat actor is selling what they claim to be 310 million Temu user records on a dark-web forum, including names, email addresses, and account details. Researchers caution the true scale is unverified, but the listing has attracted significant attention in criminal marketplaces.

Why it matters for your business: If your customers or staff shop online, their email addresses and passwords from previous breaches may now be in circulation. Encourage everyone to use unique passwords per site and enable multi-factor authentication — a leaked Temu password that matches their work email account is a direct business risk.


2. Device Code Phishing Attacks Up 37× — 18+ Attack Kits Active

Security researchers report a 37-fold increase year-on-year in "device code" phishing attacks, with more than 18 distinct attack kits now in the wild. The technique tricks users into approving a login request on a legitimate Microsoft 365 or Google sign-in page — no malicious link, no fake site — bypassing traditional phishing filters entirely.

Why it matters for your business: Your staff can be caught by this even if they're careful. If someone receives an unexpected "approve this sign-in" prompt on their phone or browser, they should always deny it and report it. Training people to question unexpected authentication requests is the single most effective defence.


3. AI Brand Impersonation: Attackers Using ChatGPT, Copilot and Claude as Lures

Microsoft Threat Intelligence published research showing a surge in phishing campaigns impersonating popular AI tools — ChatGPT, Microsoft Copilot, DeepSeek, and Anthropic's Claude. The emails and pages look like genuine AI product sign-ins but harvest credentials or install malware. The campaigns exploit the "AI hype" to increase click-through rates.

Why it matters for your business: The AI tools your team uses daily are now being weaponised as bait. A realistic-looking "your Copilot subscription needs re-authorising" email is easy to fall for. Bookmark the real URLs for the tools you use, and never enter credentials from an email link.


4. npm and Go Package Supply Chain Attack — Python Infostealer Delivered

Researchers uncovered two hijacked npm packages and a cluster of malicious Go packages that silently install a Python-based information stealer on Windows, Linux, and macOS. The packages appear legitimate and would be installed automatically by developers as part of routine dependency updates.

Why it matters for your business: If you have a developer, freelancer, or agency managing your website or software, ask them about their dependency scanning process. Supply chain attacks now reach through trusted tools — a single poisoned package can harvest AWS keys, database passwords, and API tokens from a developer's machine.


5. Nintendo Hit by ShadowByt3$ Ransomware — 859 MB of Employee Data Claimed

The ShadowByt3$ ransomware group claims to have attacked Nintendo and stolen 859 MB of employee data including personal information. Nintendo has not confirmed the breach. The incident follows a broader pattern of ransomware groups targeting well-known brands to maximise leverage and publicity.

Why it matters for your business: High-profile targets make the news; the same tactics hit smaller businesses every day, without the publicity. Ransomware groups use stolen employee data both to demand ransoms and to sell credentials that enable follow-on attacks. Offline, tested backups and MFA on every account remain the core defences.


6. DirtyClone Linux Kernel Flaw Gives Local Attackers Root — CVE-2026-43503

A new Linux kernel vulnerability (CVE-2026-43503), a variant of the earlier "Dirty Frag" class of flaws, allows a local user — such as someone with a compromised web application or shared-hosting account — to escalate to full root privileges. The flaw was disclosed with a proof-of-concept.

Why it matters for your business: Any Linux web server, VPS, or container host needs to apply the kernel patch promptly. If your website runs on shared Linux hosting, your provider should handle this — but it is worth checking their security update notices. An attacker who gets limited access via a web vulnerability can turn it into complete server control.


7. Microsoft June Patch Tuesday — Largest Ever: 198 CVEs Including Two CVSS 9.8 Flaws

Microsoft's June 2026 Patch Tuesday is the largest in the history of the programme, addressing 198 CVEs — 32 rated Critical. Two remote, unauthenticated code-execution flaws scored CVSS 9.8: CVE-2026-45657 (Windows Kernel) and CVE-2026-47291 (HTTP.sys), both exploitable without any user interaction.

Why it matters for your business: A CVSS 9.8 "no-click, no-login" flaw means attackers can compromise an unpatched Windows machine over the network without anyone opening a file or clicking anything. If your Windows computers and servers are not set to install updates automatically, enabling that now is the single highest-return action you can take today.


8. UK Proposes Ban on Ransomware Payments by Public Bodies and Critical Infrastructure

The UK government published a consultation proposing to ban ransomware payments by public sector bodies and critical national infrastructure (CNI) operators, while requiring all other businesses to notify the government before paying a ransom. The policy aims to remove the financial incentive driving ransomware growth.

Why it matters for your business: A payment ban does not yet apply to private SMBs under the current proposal, but the notification requirement would. More importantly, this signals the direction of UK regulation. If your business would need to pay a ransom to recover, that's a gap that tested backups close — check yours now, before the policy lands.


9. UK Cyber Security and Resilience Bill Progresses — Tighter Incident Reporting Coming

The Cyber Security and Resilience (Network and Information Systems) Bill completed its final parliamentary stages this month. Once enacted, it will expand incident-reporting obligations to a wider range of IT and digital-service providers, tighten enforcement powers for the Information Commissioner's Office, and update the UK's CNI security framework.

Why it matters for your business: If you are an IT provider, managed-service provider, or digital-services supplier to public-sector or regulated clients, new mandatory breach-notification timelines will apply to you. Start mapping your incident-response procedures now — regulators will expect documented processes, not improvised responses.


10. Quantum Computing Threat Prompts "Harvest Now, Decrypt Later" Warning

Security agencies and researchers renewed warnings about "harvest now, decrypt later" attacks, where nation-state actors are storing encrypted data today to decrypt it once quantum computers become capable enough to break current public-key cryptography. NIST's post-quantum standards are available now; migration timelines are measured in years.

Why it matters for your business: If you hold sensitive data — health records, legal documents, financial data — that must remain confidential for 10+ years, the encryption protecting it today may not hold in a decade. Begin asking your software and cloud providers about their post-quantum migration roadmap; this is no longer a theoretical concern.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Summaries are compiled from public threat-intelligence feeds and security news sources. This digest is for awareness purposes only and does not constitute professional security advice.