Isometric network nodes illustrating widespread data breaches and AI security flaws.

Daily Cybersecurity News - June 30, 2026

CISA Windows BlueHammer Flaw Now Exploited by Ransomware Gangs

Ransomware crews are now abusing a Windows privilege escalation bug in Microsoft Defender that CISA warned about weeks ago.

The flaw lets low-privileged users trigger elevation through Defender's scanning process. CISA added it to the KEV catalog after seeing it in zero-day attacks and now confirms ransomware use.

Affects unpatched Windows systems missing Microsoft’s April 2026 security update. Common risk areas include corporate laptops, developer workstations, and endpoints where local compromise can be chained into ransomware activity.

Ransomware use was confirmed months after the April public leak and patch cycle.

Vulnerabilities Expose Private Data in Indian Government Systems

A researcher found critical flaws in Indian government portals that let outsiders grab private citizen records without credentials.

One vulnerability in the national government portal allowed unauthenticated takeover. Multiple systems exposed personal data fields through simple web requests.

Affected portals handle national services and store citizen information across several government departments.

Researcher notified authorities before public disclosure and no active exploitation was reported.

Source: Dark Reading

Nissan Hit By ShinyHunters Via Oracle Zeroday

Nissan disclosed a breach hitting current and former employee records after attackers exploited an Oracle PeopleSoft flaw.

ShinyHunters used the zero-day in the same campaign that hit other organizations. Nissan confirmed the incident and began notifying affected staff.

The group previously used similar access to steal data from multiple targets. Nissan only mentions employee information and does not detail volume.

The same flaw appeared in earlier ShinyHunters operations against other victims.

Fake Perplexity Extension Tracked Searches

A fake Perplexity extension on the Chrome Web Store intercepted user searches and logged browsing data for weeks.

It posed as the real AI tool, captured queries through content scripts, and sent results to attacker-controlled servers. The campaign targeted researchers and tech users who installed the extension for productivity.

The trick is old, but the choice of a popular AI brand shows how attackers now ride trusted names instead of generic lures.

It stayed live on the store from early May until removal in late June 2026.

Djinn Stealer Targets Cloud AI Credentials

A new infostealer called Djinn Stealer is hitting developer machines through a critical flaw in SimpleHelp remote management software.

Attackers exploit CVE-2026-48558 to gain authenticated access, then drop a Node.js loader that delivers the cross-platform stealer. It grabs cloud keys, SSH credentials, Git tokens, and local config files for AI tools including Claude, Gemini, and Codex.

The collection rules stand out for their breadth across CI/CD, infrastructure-as-code, and AI agent setups on Windows, macOS, and Linux in one sweep. No named actor or prior cluster links appear in reporting.

Blackpoint discovered the samples during an incident involving an internet-facing SimpleHelp server used by managed service providers.

Source: Dark Reading

282 iOS AI Apps Leak API Keys and Open AI Proxy Access

Researchers found 282 iOS AI apps leaking paid API keys and backend tokens in plaintext network traffic.

They tested 444 apps and saw nearly two thirds expose reusable keys or open proxies that accept direct requests.

The study examined real app traffic rather than code review, using traffic interception to extract and validate leaked credentials.

Researchers used a custom network monitor to capture the requests during normal app use.

Can Clothes Make You Invisible to Facial Recognition

A researcher released graphic tees designed to break facial recognition models in surveillance cameras.

The shirts use printed patterns that trigger misclassifications in the neural networks. They work against common open models by exploiting how the vision systems parse human features.

The approach builds on existing adversarial patch research rather than introducing new techniques. It targets consumer-grade camera pipelines instead of hardened enterprise systems.

Open patterns shared on GitHub.

Source: Dark Reading