Vulnerabilities

Apple Patches Beats Eavesdropping Flaw

June 20, 2026 08:02 · 12 min read
Apple Patches Beats Eavesdropping Flaw

Recent Vulnerability Disclosures

This week, several significant vulnerability disclosures and patches were announced, affecting various products and services.

Apple released a firmware update for Beats Studio Buds, patching a critical vulnerability that allowed nearby attackers to listen via the microphone on unpaired devices. The update, 1B211, fixes CVE-2025-20701, one of three Bluetooth security issues disclosed last year, which have been found to impact devices from several major vendors.

phpBB Flaw Enables Session Hijacking

Researchers uncovered a critical authentication bypass in phpBB versions up to 3.3.16 and 4.0.0-a2. A single unauthenticated HTTP request can impersonate any user, including admins, exposing private messages and forum content, and providing full administrative control. phpBB users should upgrade immediately to 3.3.17 or the latest master branch.

Velvet Ant Maintained Decade-Long Stealth in Air-Gapped Critical Infrastructure

China-nexus actor Velvet Ant compromised an organization’s segregated network starting around 2016. It chained internet-facing footholds, Nginx/FastCGI proxies, and backdoored PAM/OpenSSH components for credential theft and persistent access.

New Cybersecurity Tools and Services

AWS has announced a new AI-powered tool designed to help organizations discover, prioritize, validate, and resolve vulnerabilities. Available in gated preview, Continuum takes findings from existing tools and its own scanning, prioritizing them based on exploitability in the user’s own environment.

MaXSS and Spyder Flaws Expose 10 Million Chrome Users to Hacking

Critical vulnerabilities in SiderAI (Spyder) and MaxAI (MaXSS) agentic side-panel Chrome extensions can allow malicious websites to trigger arbitrary extension actions, including hidden tab screenshots, AI memory dumps, and potential file access. With over 10 million combined installs and no vendor response, the issues enable full browser session compromise and account takeovers without user interaction.

Cybersecurity Incidents and Breaches

1.2 million WordPress sites were compromised in an OptinMonster supply chain attack. Attackers injected malicious JavaScript into Awesome Motive’s OptinMonster, TrustPulse, and PushEngage WordPress plugin CDN scripts. The payload activates for logged-in admins, creating rogue administrator accounts and a hidden backdoor plugin.

FTC Says Imposter Scams Cost Americans $3.5 Billion in 2025

The FTC reported imposter scams as the most common fraud category, with losses nearly tripling since 2020. Bank and government impersonation schemes drove the bulk of the damage, often via fake security alerts urging money transfers.

Regulatory Updates and Investigations

The US Department of Transportation ended its probe into Delta’s prolonged recovery from the global CrowdStrike incident without penalties. Investigators found the airline provided adequate refunds, baggage help, and support for passengers with disabilities.

JetBrains Marketplace Plugins Steal Developer AI Keys

At least 15 malicious AI coding assistant plugins, published in the JetBrains Marketplace under various vendor accounts, exfiltrate OpenAI, DeepSeek, and similar API keys. The plugins have racked up nearly 70,000 installs while functioning as advertised.

Other Noteworthy Events

Researchers linked the large Popa Android TV box botnet — used for residential proxy traffic in ad fraud and scraping — to NetNut, operated by publicly traded Israeli company Alarum Technologies. The operation involves millions of IPs daily and raises concerns about local network exposure and ties to data scraping.

GCP Config Connector enables org-wide IAM owner takeover. A confused deputy vulnerability in Config Connector lets any Kubernetes namespace user escalate to GCP Organization Owner by submitting a malicious IAMPolicyMember.


Source: SecurityWeek

Source: SecurityWeek

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free