Glowing lock icons representing urgent patches for widespread cybersecurity vulnerabilities.

Daily Cybersecurity News - June 9, 2026

Chrome Update Patches Active Exploit and 73 Others

Google just shipped a Chrome update that kills an actively exploited zero-day plus 73 other bugs.

The fix targets a high-severity flaw in the V8 JavaScript engine, CVE-2026-11645. Attackers already weaponized it in the wild. CVSS 8.8 for the main issue. No other details leaked on the active one yet..

Desktop users on Windows, Mac, and Linux need the update. Enterprise fleets and personal browsers alike.

This is Google's fifth actively exploited Chrome zero-day of 2026.

Source: Malwarebytes

Veeam Flaw Lets Attackers Run Code on Backup Servers

Veeam patched a flaw that gives remote attackers code execution on domain-joined backup servers.

The issue sits in Backup & Replication, CVE-2026-44963, CVSS 9.4. Any authenticated domain user reaches RCE on the backup server - low privilege, wide blast radius. Veeam shipped fixes in the latest builds.

Only domain-joined Veeam Backup & Replication servers are affected. Workgroup (non-domain-joined) setups stay clear. Version 13.x is not affected.

Affects v12 through 12.3.2.4465; fixed in 12.3.2.4854.

CISA gives feds 3 days to patch Check Point VPN bug

CISA ordered federal agencies to patch a Check Point VPN flaw in three days. Ransomware groups already used it as a zero-day.

The bug is in Remote Access VPN and Mobile Access products. It lets attackers bypass authentication for admin access without credentials. Zero-day exploitation confirmed by Qilin affiliates.

Affects Check Point gateways running versions before the fixed release. Hits government and enterprise deployments with exposed VPN portals.

CISA added it to the KEV catalog on the same day as the directive.

Microsofts Open Source Tools Hacked To Steal AI Passwords

Attackers hit Microsoft open source repos for Azure and AI coding tools on GitHub.

a compromised contributor account let them push malicious commits (the Miasma worm). The goal was stealing passwords from AI developers who pulled the tainted tools.

Microsoft yanked dozens of repos fast. The move shows supply chain attacks still target developer workflows directly.

Attackers focused on repos tied to Azure AI and coding assistants.

Source: TechCrunch

New Shai Hulud Trojanizes Science PyPI Packages

A new Shai Hulud campaign trojanized 19 science-focused packages on PyPI.

Attackers published malicious versions that steal developer secrets. The packages had hundreds of thousands of downloads combined.

The shift is the target: a registry worm by nature, now pushing into the scientific Python ecosystem on PyPI.

The operation hit packages tied to scientific computing and data tools.

WhatsApp Disrupted NSO Spyware Phishing

NSO Group ran fresh spear-phishing campaigns that WhatsApp caught and blocked.

Attackers posed as trusted contacts to trick users into clicking malicious links. The campaigns targeted individuals already under surveillance interest.

WhatsApp's quick response shows the same social-engineering playbook NSO has used for years, just repackaged for current messaging flows.

WhatsApp acted after user reports surfaced, stopping the campaigns before wider spread.

GPS As a Key Distribution Platform

The U.S. military has used public GPS signals to broadcast encryption keys for nearly 20 years.

Each satellite acts as a hidden numbers station sending codes for a global encryption network. Every GPS receiver has quietly picked them up since the program started.

The detail comes from Steven Murdoch via Bruce Schneier. No independent confirmation or technical breakdown has surfaced yet.

The scheme has run quietly since the mid-2000s.