June 2026 Cybersecurity Roundup: Supply Chain Breaches, Data Extortion, and Critical CVEs

June 2026 Cybersecurity Roundup

This June 2026 Cybersecurity Roundup lands in a month when the FIFA World Cup kickoff dominated the conversation, with most attention on cyber threats and fraud tied to the tournament. Away from the headlines, though, June’s most consequential incidents ran through SaaS supply chains, ransomware-driven data extortion, and identity compromise. Here’s a roundup of the…

Read More

OPNsense CVE-2026-57155: Root RCE via GeoIP Alias

OPNsense CVE-2026-57155

OPNsense CVE-2026-57155 (CVSS 9.9) is a path-traversal flaw in the firewall’s GeoIP alias importer that lets a low-privileged user escalate to full root remote code execution. It is the fifth critical or high-severity OPNsense vulnerability disclosed since May 2026, and it matters disproportionately for German Mittelstand IT teams and MSPs because OPNsense’s free, open-source model…

Read More

SharePoint RCE CVE-2026-45659: Active Exploits

SharePoint RCE CVE-2026-45659

SharePoint RCE CVE-2026-45659 is now under active exploitation, and the federal patch deadline set by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is July 4 — tomorrow. The CVSS 8.8 deserialization flaw lets any authenticated user with nothing more than baseline Site Member permissions run code remotely on the server. Shadowserver currently counts more…

Read More

Azure CLI Password Spray Bypasses MFA

Azure CLI Password Spray

An Azure CLI password spray campaign made more than 81 million login attempts against Microsoft accounts over two weeks and successfully compromised 78 accounts across 64 organizations — a meaningful share of which believed multi-factor authentication already protected them. The attackers did not break MFA. They found a legacy authentication path that most Conditional Access…

Read More

Top 5 Cybersecurity News Stories July 03, 2026

Cybersecurity News Stories July 03, 2026

The five stories in this week’s Cybersecurity News Stories July 03, 2026 share a common structural property: in each case, the compromised or weaponised system is one that organisations have quietly reassigned to a category other than “security risk.” Backup keys for encrypted messaging are a recovery mechanism, not an intelligence target — until Russian…

Read More