Cybersecurity News — 2026-07-01
Generated: 2026-07-01 | Sources: The Hacker News, SecurityWeek, Infosecurity Magazine, BleepingComputer, Check Point Research, CISA, TechCrunch, World Economic Forum
1. SimpleHelp Remote-Support Flaw (CVE-2026-48558, CVSS 10) Exploited to Push Malware
Attackers exploited a maximum-severity flaw in SimpleHelp, a remote-support (RMM) tool, to gain a trusted technician session on an internet-facing server and then use the platform's own tools to push malware — a loader called "TaskWeaver" and an infostealer, "Djinn Stealer". CISA added the flaw to its Known Exploited Vulnerabilities catalog on 29 June.
Why it matters for your business: Remote-support and remote-management tools are a favourite target because compromising one gives an attacker a legitimate-looking way into every machine it manages. If your IT provider or MSP uses an RMM tool, ask them to confirm it's patched and that its console isn't exposed to the open internet.
2. Microsoft Defender Zero-Day (CVE-2026-33825) Exploited Before a Fix
Microsoft's latest patch round addressed a large batch of flaws — around 15 rated critical and dozens more high severity — including a Microsoft Defender vulnerability (CVE-2026-33825) that was already being exploited in the wild as a zero-day before the patch shipped.
Why it matters for your business: "Zero-day" means attackers were using it before a fix existed, so the only defence is applying updates fast once they land. If your Windows machines and servers aren't set to install security updates automatically, turning that on is the single highest-return thing you can do today.
3. ServiceNow Discloses June Security Incident via an Exposed API
ServiceNow disclosed a June 2026 incident after attackers exploited an unauthenticated-access flaw in an API endpoint used by hosted customer instances. Malicious activity reportedly began in early June and was surfaced through bug-bounty reports days later.
Why it matters for your business: Even large, trusted SaaS platforms have flaws — and if you keep data in one, their incident becomes your incident. Keep an inventory of the cloud services that hold your data, watch for their security notices, and know who to contact if one reports a breach.
4. Klue Supply-Chain Breach Reaches Salesforce Data via Stolen OAuth Tokens
Klue confirmed a June supply-chain breach in which attackers used compromised legacy credentials to reach its integration environment and steal OAuth tokens connected to customer platforms — giving unauthorised access to Salesforce CRM data across multiple customers.
Why it matters for your business: The "connected apps" you authorise (an integration clicking Allow access to your CRM/email) hold long-lived tokens that are effectively keys to your data. Periodically review the third-party apps connected to your Google/Microsoft/Salesforce accounts and remove any you no longer use.
5. KDDI Email Breach — Up to 14.2 Million Addresses and Passwords Exposed
Japanese telecoms group KDDI disclosed a breach of an email platform it provides to several ISPs, detected in mid-June, in which attackers exploited a vulnerability in third-party software. Up to 14.22 million email addresses and passwords may have been exposed.
Why it matters for your business: Breached email/password pairs get reused by attackers against every other site — "credential stuffing". This is exactly why a unique password per site plus MFA matters: a password leaked from one provider shouldn't unlock anything else you own.
6. Ransomware Up 48% Year-on-Year — and Shifting to Pure Data Theft
Check Point reports ransomware attacks jumped 48% year over year even as overall cyberattack volume dipped. The bigger shift: many crews are abandoning file-encryption in favour of data theft and extortion — steal the data, threaten to leak it, demand payment.
Why it matters for your business: If the threat is "we'll publish your data" rather than "we've locked your files", backups alone won't save you — the data's already gone. That raises the value of the basics that stop the initial break-in (MFA, patching, phishing awareness) and of collecting less sensitive data in the first place.
7. AI-Related Weaknesses Named the Fastest-Growing Cyber Risk
The World Economic Forum's Global Cybersecurity Outlook found the overwhelming majority of organisations (~87%) now rate AI-related vulnerabilities as the fastest-growing cyber risk — from AI-supercharged phishing to insecure AI tools and integrations.
Why it matters for your business: You don't need to run AI models to be exposed — attackers use AI to make phishing more convincing, and the AI tools your team adopts add new places to leak data. Treat AI-tool logins and configs as sensitive, and keep reminding staff that a polished, personalised message can still be a scam.