Bitsight says Fuyao-linked Android TV boxes can masquerade as phones for ad fraud and relay stranger traffic through home broadband. Use Play Protect-certified devices, review cheap TV boxes, and unplug suspicious hardware.
Wiz disclosed CosmosEscape, an Azure Cosmos DB Gremlin API vulnerability chain that could expose a platform-wide master key for database access. Microsoft says it has remediated the issue; defenders should verify cloud trust boundaries and monitor logs.
Ruflo CVE-2026-59726 exposed an unauthenticated MCP bridge that could let outsiders run tools, steal provider API keys, and poison AI memory; upgrade to 3.16.3, restrict network access, and audit keys and memory stores.
OpenWrt CVE-2026-53921 is a critical DHCPv6 overflow in odhcpd that could let reachable requests run code as root. Update to 24.10.8 or 25.12.5 and keep router services limited to trusted networks.
Public exploit details for vBulletin CVE-2026-61511 show how unpatched self-hosted forums could face pre-auth code execution. Upgrade to vBulletin 6.2.2 or apply the branch security patches now.
NodeBB patched eight high-severity flaws that could expose admin views, private chats, and hidden forum areas. Admins should update to 4.14.2 and review logs for suspicious access.
Check Point patched CVE-2026-16232, an actively exploited SmartConsole authentication bypass that can grant full admin tokens for security-management servers. Apply hotfixes, restrict Trusted Clients, and review security-policy changes/logs.
Windmill CVE-2026-29059 is being exploited to read server files without authentication; if a superadmin secret is exposed it can become a master key. Update to 1.603.3+ and review exposed instances and logs.
SharePoint CVE-2026-50522 is a critical on-prem server RCE now reported under active exploitation after public PoC release. Defenders should patch affected SharePoint servers, rotate exposed machine keys or credentials, and hunt for persistence.
Attackers are reportedly exploiting ServiceNow AI Platform CVE-2026-6875, a sandbox-escape RCE risk for enterprise workflows; hosted fixes are handled, while self-hosted teams should apply updates and review logs.
CISA added Microsoft SharePoint Server CVE-2026-58644 to KEV after exploitation in the wild; defenders should patch on-prem servers, verify AMSI, review logs and artifacts, and reduce exposed admin surfaces.
CISA says Oracle E-Business Suite Payments CVE-2026-46817 is being actively exploited and ordered rapid patching. Exposed organizations should apply Oracle’s May update and check for compromise.
SonicWall patched two actively exploited SMA 1000 zero-days, CVE-2026-15409 and CVE-2026-15410, affecting remote-access appliances. Admins should apply hotfixes, review IoCs/logs, and reset credentials if compromise is suspected.
SAP's July 2026 updates fix critical NetWeaver, Approuter, and Commerce Cloud flaws that could expose or alter enterprise data. Patch quickly and audit production Commerce Cloud sample credentials.
RabbitMQ patched CVE-2026-57219, a flaw that could expose a broker's OAuth client secret from exposed management pages and let attackers take control in affected setups. Upgrade, rotate secrets, and keep management access off untrusted networks.
Microsoft patched CVE-2026-50656, the RoguePlanet elevation-of-privilege flaw in Microsoft Defender that could raise local access to SYSTEM; verify Malware Protection Engine updates reached endpoints.
Microsoft patched RoguePlanet (CVE-2026-50656), a Defender Malware Protection Engine flaw that could let a local attacker jump to SYSTEM privileges. Confirm Defender engine auto-updates reach version 1.1.26060.3008 or later.
Ubiquiti patched CVE-2026-50746, a critical UniFi Connect flaw that could let a network-access attacker run commands on building-control hosts. Update UniFi Connect Application to 3.4.20 or later.
Threat actors are probing Gitea Docker CVE-2026-20896, a critical reverse-proxy auth trust flaw that can let reachable containers accept spoofed user identity. Upgrade to 1.26.3 and restrict trusted proxies.
Opera patched an Opera GX mods flaw with no CVE that could let a malicious site silently install a GX Mod and use CSS to leak page data such as an email address. Update Opera GX to 130.0.5847.89 or later.
North Korea-linked malicious npm packages mimicked Rollup polyfill tooling to steal developer secrets and enable remote access. Remove suspect packages, rotate exposed keys, and review dependency changes.
Sysdig says JADEPUFFER used Langflow CVE-2025-3248 to drive an AI-agent ransomware chain against database infrastructure. Patch exposed Langflow servers, remove unnecessary internet exposure, and rotate credentials stored in workflows.
Two critical Cursor flaws, CVE-2026-50548 and CVE-2026-50549, could let hidden prompt injections escape the AI editor sandbox and run commands. Update to Cursor 3.0+ and audit MCP inputs.
Researchers found 282 iOS AI apps exposing paid LLM access through plaintext keys, replayable tokens, or open relays. Developers should keep provider secrets server-side, rotate exposed keys, and monitor usage for abuse.
A public PoC for CVE-2026-55200 highlights a critical libssh2 client-side flaw where a malicious SSH server could corrupt a connecting client. Inventory bundled or statically linked libssh2 copies and apply upstream or backported patches.
CISA added exploited PTC Windchill and FlexPLM CVE-2026-12569 to KEV after reports of JSP web shells on vulnerable systems. Patch or mitigate quickly, assess exposed PLM servers, and inspect logs and files for signs of compromise.
Researchers found the Chrome extension Adblock for YouTube, with 10M+ installs, had dormant script-injection capability but no reported malicious payload use. Remove untrusted extensions and review browser permissions.
Researchers reported Cordyceps, a CI/CD workflow weakness that could let untrusted GitHub pull requests hijack privileged workflows in 300+ repositories, enabling credential theft or supply-chain compromise. Audit Actions permissions, secrets, and approval gates.
GitHub actions/checkout v7 now blocks common pwn-request checkouts that could let unreviewed fork PR code run with repository secrets. Update pinned workflows and audit any manual fetches or custom scripts.
Squidbleed (CVE-2026-47729) is a 29-year-old Squid Proxy heap over-read that can leak cleartext HTTP requests in shared proxy setups. Patch verified builds and disable FTP support if it is not needed.
Salesforce disabled Klue’s app integration after stolen access tokens were used to reach connected CRM data. Revoke risky integrations, rotate credentials, and review API logs for bulk access.
Microsoft detailed a Windows malware campaign that spreads through USB LNK shortcuts, swaps copied crypto wallet addresses, steals screenshots, and uses Tor-based command-and-control. Defenders should disable AutoRun and block removable-drive shortcuts.
More than 140 Mastra npm packages were compromised through a hijacked contributor account and a malicious easy-day-js dependency. Teams should audit recent installs, remove affected versions, and rotate developer API keys or wallet secrets.
Attackers are exploiting three Fortinet FortiSandbox flaws, including command-injection and path-traversal issues. Patch FortiSandbox appliances quickly and review logs for suspicious uploads or commands.
CVE-2026-42824 in M365 Copilot could have exposed emails, files, calendars, and MFA codes through a trusted link. Microsoft mitigated it server-side; defenders should audit Copilot data access and overshared content.
Attackers exploited Oracle PeopleSoft CVE-2026-35273, a remotely exploitable flaw that can expose reachable Environment Management Hubs to takeover. Restrict PSEMHUB access and apply Oracle’s mitigations or updates immediately.
GitHub says npm v12 will stop dependency install scripts from running by default, reducing a major supply-chain code-execution path. Teams should review npm warnings now and approve only package scripts they truly trust.
Microsoft’s June 2026 Patch Tuesday fixes 206 flaws, including three publicly disclosed zero-days and critical RCE bugs. Defenders should prioritize high-risk Windows and server updates, especially exposed services and fleet-wide endpoints.
Google patched CVE-2026-11645, an actively exploited Chrome V8 out-of-bounds read/write flaw. Update Chrome now and verify managed devices received the fix.
Check Point warns CVE-2026-50751 is being exploited against legacy IKEv1 Remote Access VPN setups, letting attackers start VPN sessions without a valid password. Patch immediately, retire IKEv1, and require stronger certificate-based access.
Cisco says CVE-2026-20245 in Catalyst SD-WAN Manager is being exploited to turn netadmin access into root and push risky configuration changes. With no patch yet, teams should review Cisco IOCs, audit privileged accounts, and patch related SD-WAN flaws.
Google’s June 2026 Android update fixes 124 flaws, including CVE-2025-48595, a Framework privilege-escalation issue under limited targeted exploitation. Install the 2026-06-05 security patch level or later and keep Play Protect enabled.
Redis patched CVE-2026-23479, a use-after-free that could let authenticated users run code on self-managed servers. Upgrade fixed releases and restrict Redis access to trusted networks and accounts.
Cisco patched CVE-2026-20182, an actively exploited Catalyst SD-WAN authentication bypass that could let remote attackers gain administrator control. Patch affected controllers and managers, then audit SSH keys, NETCONF changes, and admin/root activity.
Attackers are actively exploiting WP Maps Pro CVE-2026-8732 to create WordPress administrator accounts on vulnerable sites. Update the plugin to 6.1.1 or later and review unexpected admins.
Attackers exploited Marimo CVE-2026-39987 on an exposed notebook, then used an LLM agent to chase cloud credentials, an SSH key, and database access. Patch Marimo, remove public exposure, and rotate cloud, API, and SSH keys.
Attackers are exploiting FortiClient EMS CVE-2026-35616 to abuse trusted endpoint management and push credential-stealing malware. Patch to 7.4.7 or later and review endpoint policy changes for tampering.
Gitea CVE-2026-27771 let unauthenticated outsiders pull private container images from affected self-hosted registries. Upgrade to Gitea 1.26.2 and restrict registry access until patched.
Microsoft patched SharePoint CVE-2026-45659, an Important RCE flaw that could let a low-privilege site member run code on vulnerable servers. Apply the update and review site-member access.
Attackers exploited Ghost CMS CVE-2026-26980 to steal admin API keys and inject ClickFix scripts into 700+ sites. Ghost operators should update, rotate credentials, clean pages, and audit logs.
Megalodon pushed malicious GitHub Actions workflow commits into 5,561 repositories, risking exposed CI secrets, cloud keys, SSH keys, and tokens. Review workflow changes, rotate exposed credentials, and tighten CI/CD permissions.
Microsoft says Defender flaws CVE-2026-41091 and CVE-2026-45498 are being exploited, risking SYSTEM privilege escalation or disrupted protection. Keep Defender platform updates enabled and confirm patched versions are applied.
GitHub says a poisoned VS Code extension on an employee device exposed about 3,800 internal repositories. The practical takeaway: review developer extensions, rotate secrets after suspected compromise, and monitor for follow-on activity.
A compromised Nx Console 18.95.0 VS Code extension ran a credential stealer when developers opened workspaces, putting tokens, keys, and secrets at risk. Update to 18.100.0 or later and rotate exposed credentials.
MiniPlasma reportedly revives CVE-2020-17103 in Windows cldflt.sys, letting local attackers gain SYSTEM privileges on fully patched Windows 11; limit local exposure, monitor privilege jumps, and patch when Microsoft fixes it.
Four OpenClaw “Claw Chain” flaws (CVE-2026-44112/44113/44115/44118) could expose files, bypass command checks, and seize gateway controls. Patch quickly and restrict agent/gateway access.
NGINX CVE-2026-42945 is a rewrite-module heap overflow that can let crafted HTTP requests crash worker processes and, on weaker setups, possibly run code. Update NGINX Open Source/Plus and related F5 components promptly.
Exim CVE-2026-45185, aka Dead.Letter, can corrupt memory in GnuTLS-based mail server builds and may allow code execution. Admins should update Exim and verify whether their configurations use the affected GnuTLS path.
Ollama CVE-2026-7482 can let exposed AI servers leak process memory, including API keys, prompts, and chats. Update to 0.17.1 or later, firewall instances, and put an auth proxy/API gateway in front.
A fake OpenAI Privacy Filter repo on Hugging Face reportedly hit #1 trending and drew about 244K downloads before being disabled, while HiddenLayer says it shipped infostealer malware. Defensive takeaway: verify AI model sources, and if the fake repo was run, isolate or wipe the host and rotate saved passwords, cookies, tokens, and keys.
CVE-2026-41940 is a critical cPanel/WHM authentication bypass that can let unauthenticated attackers into hosting control panels, putting websites, mail, databases, and configurations at risk. Update to fixed builds, restart services, and check for signs of compromise.
Palo Alto Networks CVE-2026-0300 is an actively exploited PAN-OS User-ID Authentication Portal flaw that can let unauthenticated attackers run code as root on exposed firewalls. Restrict the portal to trusted IPs, apply workarounds, monitor, and patch as fixes arrive.
9000 Schools and 231M emails exposed. A for effort..
One panel a day. No spam, unsubscribe with one click.