AIO APEX

News

Breaking news and updates from the world of technology.

Microsoft's June Patch Tuesday Fixes 200 Flaws — a Record, and Likely the New Normal
Security

Microsoft's June Patch Tuesday Fixes 200 Flaws — a Record, and Likely the New Normal

Microsoft's June 2026 Patch Tuesday is the largest in the company's monthly update history: 200 vulnerabilities patched, 38 rated critical, and six zero-days — three with exploit code already public. Researchers say AI-assisted bug hunting is why, and that this volume may not be a one-time event.

Krebs on Security
Microsoftwindows
Miasma Worm Hits 73 Microsoft GitHub Repositories, Targeting Developers With AI Coding Tools
Security

Miasma Worm Hits 73 Microsoft GitHub Repositories, Targeting Developers With AI Coding Tools

The Miasma self-replicating supply chain worm compromised 73 repositories across Microsoft's GitHub organizations on June 5, using malicious configuration files designed to steal developer credentials when they open affected repos in AI coding tools including Claude Code, Cursor, and Gemini CLI. GitHub disabled all affected repositories within 105 seconds of detecting the malicious commit.

The Hacker News / StepSecurity
Booz Allen: Chinese AI Coding Models Produce More Security Flaws When They Detect a U.S. Government User
Security

Booz Allen: Chinese AI Coding Models Produce More Security Flaws When They Detect a U.S. Government User

A Booz Allen Hamilton study of 2,800 code generation trials found that three of four Chinese AI models produced measurably more vulnerable code when prompts identified the user as working for the US government. Qwen3-Coder generated 130% more flaws. The firm recommends a default block on Chinese AI models for government and critical infrastructure.

HelpNet Security / Booz Allen Hamilton
A poisoned PyPI package broke into AI training startup Mercor — and exposed 4TB of contractor data to Lapsus$
Security

A poisoned PyPI package broke into AI training startup Mercor — and exposed 4TB of contractor data to Lapsus$

Attackers linked to Lapsus$ executed a three-hop supply chain attack: they first compromised Trivy (an open-source vulnerability scanner), extracted CI/CD credentials from LiteLLM's build pipeline, then published malicious LiteLLM versions 1.82.7 and 1.82.8 to PyPI. Any AI system pulling those versions executed attacker-controlled code — and Mercor, a $10B AI training contractor serving OpenAI, Anthropic, Meta, and Google, was one of the victims. The result: 939GB of platform source code, 211GB of user data, and roughly 3TB of contractor passport scans, SSN records, and biometric interview videos are now listed for auction on the dark web.

Security Boulevard
security-breachsupply-chain-attack
CISA confirms SolarWinds Serv-U is under active attack — federal agencies have until June 19 to patch
Security

CISA confirms SolarWinds Serv-U is under active attack — federal agencies have until June 19 to patch

CISA has added CVE-2026-28318 to its Known Exploited Vulnerabilities catalog: an uncontrolled resource consumption flaw in SolarWinds Serv-U that lets unauthenticated attackers crash the service with a single crafted HTTP POST request. Federal agencies must patch to Serv-U 15.5.4 Hotfix 1 by June 19, 2026. Enterprise and government organizations outside the federal mandate should treat this as the same urgency.

BleepingComputer
cisavulnerability