
Loading summary
A
From the CISO series It's Cybersecurity Headlines
B
these are the cybersecurity headlines for Monday, June 8, 2026. I'm Steve Prentiss, Palantir Executive considered for CISA leadership, following up on a story we covered last week regarding DHS Secretary Mark Wayne Mullen's comment about a possible director for cisa. Two anonymous sources quoted by the suggest that Shyam Sankar, chief technology officer at Palantir Technologies, has emerged as a lead contender for the long vacant director role at cisa. A White House official has disputed this announcement, saying there were no personnel announcements to make at this time, and CISA has not had a Senate confirmed chief since the departure of Jen easterly back in January 2025. The EU unveils tech sovereignty package to cut reliance on US and Chinese suppliers as posted in the record, the European Commission proposed a sweeping set of laws and strategies this week aimed at reducing the European Union's reliance on foreign technology amid concerns that its long standing tech dependencies are becoming a security vulnerability. Describing this as a major shift in how Europe approaches technological sovereignty, the Commission's tech lead henna Verkonen described two draft a Chips Act 2.0 and a Cloud and AI Development Act. Currently, the EU relies on foreign countries for more than 80% of its key digital products services, infrastructure and intellectual property. Hackers now exploiting SolarWinds Serv U flaw A warning from CISA on Friday that hackers are now actively exploiting a recently patched high severity SolarWinds Serv U flaw to crash servers. End quote this is the Windows and Linux file transfer software that offers management, file transfer and FTP server capabilities for the secure exchange of files via HTTP, HTTPs, FTP and others. SolarWinds released Serv UH 5.1.15 hotfix1 on Thursday. The CVE numbered flaw allows remote attackers to exploit it without privileges in low complexity attacks that do not require user interaction. Critical Everest Forms Pro flaw exploited to take over WordPress sites this is a CVE numbered vulnerability in the Everest Forms Pro plugin which allows attackers to take complete control of a WordPress website without authentication. The issue affects versions January12 and earlier. Everest Forms Pro is a WordPress add on used to create contact registration, payment and other custom application forms. Telemetry data from wordfence shows that the vulnerability is being exploited in the wild to create rogue administrator accounts. Huge thanks to our sponsor Doppel. Cybercriminals don't respect your security silos. They use one connected attack chain to hit your brand externally, infiltrate your inbox and manipulate your team. Stop playing whack a mole with fragmented tools. Doppel unifies digital risk protection, human risk management and email security into one platform one attack chain three pillars of defense zero blind spots secure your enterprise relentlessly at doppel.com that is d o p p e l com miasma worm attacks 73 Microsoft GitHub repositories the ongoing self replicating supply chain attack campaign hit the repositories across four of its GitHub organizations, including Azure, Azure Samples, Microsoft and Microsoft Docs. According to open source malware, the development has forced GitHub to disable access to those repositories as opposed to being a standalone attack. This particular campaign involves the recompromise of the durable Task PI PI package, which was infected by Team PCP last month to deliver an information stealer on Linux systems Reports claim Anthropic engineers are helping the NSA use Mythos the Financial Times is reporting that Anthropic has placed six forward deployed engineers inside the National Security Agency, end quote, to help the agency use Mythos for offensive operations. It is believed that its function is to assist in infiltrating networks in countries like China or Iran, although it is currently unclear if the anthropic engineers are involved in live operations or just customization and setup. This comes during a period of tension between Anthropic and the US Government, including a presidential order to the Pentagon to drop Claude from its systems by August. New ChatGPT lockdown mode limits Data Exfiltration Tools this new mode being rolled out by OpenAI is intended for personal accounts to reduce the risk of data exfiltration arising from prompt injection attacks. It has been specifically designed for people and organizations that handle sensitive data and require stricter protection guarantees, and is available to logged in users across free Go plus and Pro and self serve ChatGPT business plans. Lockdown mode works by reducing the risk of data exfiltration from prompt injection attacks, by limiting outbound network requests thwarted Hackers now making house calls Google's Mandiant Incident Response Team has released a warning about hackers appearing in person at businesses masquerading as IT technicians. A data theft and extortion gang named UNC3753 has targeted dozens of banks, law firms and other professional services companies in the US From January through to May, using fake help desk calls and other social engineering techniques to gain access to corporate IT environments. When the remote deception methods don't work, they show up at the victim's physical offices posing as IT technicians and attempting to steal sensitive files using thumb drives. The FBI even posted a warning last month about this new tactic. The actors claim to be IT support staff needing to image a device or create local backups for security reasons. If that line works, they plug in a USB thumb drive into the victim's computer and steal data the old fashioned way. Remember to join us this Friday for our Department of no Livestream. Each and every Friday at 4pm Eastern, we bring you the biggest cybersecurity news of the week and our expert CISO guests will tell you how it applies to your security team. You can get involved in the livestream, ask some questions, give your thoughts on the news of the week, and have a good time. It all takes place on the CISO Series YouTube channel, so head over there, subscribe and join us this Friday at 4pm and if you have some thoughts on the news from today or about this show in general, please be sure to reach out to us@feedbackisoseries.com we would love to hear from you. I'm Steve Prentiss reporting for the CISO Series.
A
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
C
Sam.
Cybersecurity Headlines – June 8, 2026 | CISO Series
This episode of “Cybersecurity Headlines” delivers the top infosec news of the day, focusing on leadership changes at CISA, new regulatory technology moves within the EU, and major vulnerabilities being exploited in real time. Hosted by Steve Prentiss, the episode touches on hot topics including Palantir’s potential influence over U.S. cyber policy, supply chain threats, zero-day exploits, offensive AI at the NSA, and evolving threat actor tactics.
Today’s episode highlighted major shifts and threats in the cybersecurity landscape, with leadership decisions at CISA, Europe’s strategy for digital independence, live exploitation of critical software flaws, and evolving threat actor techniques combining remote and physical approaches. Listeners came away updated on pivotal vulnerabilities and the need for heightened vigilance both remotely and in-person as attackers adapt to bypass modern controls.
For the full stories and even deeper analysis, visit CISOseries.com.