Critical vulnerabilities, active threats, and security news — curated for professionals.
Critical path traversal vulnerability (CVSS 10.0) in Adobe ColdFusion's Remote Development Services FILEIO handler affecting versions 2025.9, 2023.20 and earlier. Added to CISA KEV on July 7, 2026. Can lead to arbitrary code execution. Being actively exploited in the wild. Federal agencies required to patch by July 10, 2026.
SourceDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Added to CISA KEV on July 1, 2026. Being actively exploited by threat actor Storm-2603 to deploy Warlock ransomware against on-premises SharePoint servers. Patch shipped May 2026; CISA gave federal agencies 3 days to patch.
SourceCritical authentication bypass vulnerability (CVSS 9.3) in Check Point Remote Access VPN, Mobile Access, and Spark Firewall products using deprecated IKEv1 protocol. Allows unauthenticated remote attackers to bypass password-based authentication. Under active exploitation since disclosure on June 8, 2026. Added to CISA KEV.
SourceCritical remote code execution vulnerability in Windows Active Directory Domain Services due to a stack-based buffer overflow. Patched in June 2026 Patch Tuesday (record 198 CVEs). Considered a top priority for enterprise patching.
SourcePrivilege escalation vulnerability in the Microsoft Malware Protection Engine (mpengine.dll), dubbed 'RoguePlanet'. Allows local attackers to gain SYSTEM privileges. Microsoft released a fix on July 9, 2026. Discovered by researchers at Kudelski Security.
SourceDeployed by China-nexus threat actor Storm-2603, Warlock ransomware exploits unpatched SharePoint vulnerabilities (CVE-2026-45659) to gain initial access, escalate privileges, steal credentials, and deploy ransomware across enterprise networks. Added to CISA KEV on July 1, 2026.
SourceInfostealer malware-as-a-service operations disrupted on June 24, 2026, by Microsoft DCU, Europol, ESET, and partners as part of Operation Endgame. 326 servers seized, 27 million stolen credentials recovered. StealC and Amadey were widely used to deliver ransomware and other payloads.
SourceThree new malware loaders delivered through ClickFix social-engineering lures (fake CAPTCHAs, fake update prompts). Victims are tricked into copying and running malicious PowerShell commands that deploy stealers, RATs, and ransomware tooling. API-driven infrastructure generates fresh obfuscated payloads on demand.
SourceLarge-scale credential compromise campaign affecting Fortinet FortiGate devices. Over 86,000 administrator credentials leaked due to weak password storage algorithms in legacy Fortinet firmware. Hundreds of maritime, port, and energy companies' network perimeters exposed.
SourceCISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on July 7, 2026: Adobe ColdFusion path traversal (CVE-2026-48282, CVSS 10.0), two Joomla page builder flaws (JoomShaper SP Page Builder, CVSS 10.0 each), and a Langflow authorization bypass (CVSS 10.0). All are under active exploitation, with the Langflow chain using IDOR + RCE to steal LLM provider credentials.
Read moreMicrosoft released a security update on July 9, 2026, for the Microsoft Malware Protection Engine fixing CVE-2026-50656 ('RoguePlanet'), a privilege escalation vulnerability allowing local attackers to gain SYSTEM privileges via Defender's scanning engine.
Read moreThe European Commission unveiled an Action Plan on Cybersecurity and Artificial Intelligence on July 7, 2026, establishing a dedicated EU framework to address AI-driven cyber threats. The plan includes an EU Grand Challenge on AI for cybersecurity, mandatory security testing of frontier AI systems, and aims to reduce reliance on non-EU AI models.
Read moreIBM and Red Hat commercially launched Project Lightwell on July 8, 2026, backed by a $5 billion commitment and 20,000 engineers. The initiative focuses on securing open-source software supply chains with AI-driven vulnerability discovery and remediation, including two new commercial offerings for enterprises.
Read moreSecurity researchers identified an active large-scale campaign affecting Fortinet devices across 194 countries. Over 86,000 administrator credentials from FortiGate firewalls were leaked due to weak legacy password storage, exposing maritime, port, and energy companies to potential network compromise.
Read moreAnthropic's Claude Mythos AI discovered thousands of high-severity zero-day vulnerabilities across major operating systems and browsers as part of Project Glasswing. In response, IBM and Red Hat committed $5B to Project Lightwell for large-scale vulnerability remediation, signaling a new era of AI-driven offensive and defensive cybersecurity.
Read moreCritical improper access control vulnerability in UniFi Connect Application (part of UniFi OS). A network-adjacent attacker can exploit this to execute arbitrary OS commands on the host without authentication. Part of Ubiquiti Security Advisory Bulletin 066, affecting 25 vulnerabilities across the UniFi ecosystem. Over 100,000 endpoints are potentially exposed.
SourcePath traversal vulnerability in Adobe ColdFusion (versions 2025.9, 2023.20 and earlier) affecting the Remote Development Services (RDS) component. A remote, unauthenticated attacker can exploit this to achieve arbitrary code execution. Added to CISA KEV on July 7, 2026 after active exploitation was detected in the wild.
SourceCritical unauthenticated vulnerability in Oracle PeopleSoft Enterprise PeopleTools Updates Environment Management component. Successful exploitation allows remote takeover of PeopleSoft Enterprise PeopleTools without authentication. Added to CISA KEV catalog; actively exploited by ShinyHunters ransomware group.
SourceImproper enforcement of mandatory multi-factor authentication (MFA) policy in Devolutions Server. An attacker with valid user credentials can bypass the MFA Required policy and authenticate without completing multi-factor authentication.
SourcePath traversal vulnerability in UniFi OS that can be chained with other bugs to escalate privileges within UniFi OS devices. Part of Ubiquiti Bulletin 066, enabling chain attacks from low-privilege to full system compromise.
SourceFirst documented agentic (LLM-driven) ransomware operation. Using an LLM to autonomously exploit Langflow and Nacos vulnerabilities, JadePuffer steals data from production databases and encrypts systems. Discovered by Sysdig TRT.
SourceThe Vect ransomware group formalized a partnership with TeamPCP, a supply chain credential-theft gang. TeamPCP harvested 500,000+ cloud credentials from CI/CD pipelines. The alliance industrializes ransomware delivery by combining credential theft with encryption extortion.
SourceNorth Korea-linked supply chain campaign that published 108 malicious packages and extensions across multiple registries. Uses blockchain-hosted payloads to evade detection. Compromised 1,951 GitHub repositories targeting developers through fake job interviews (Contagious Interview).
SourceMassive credential compromise campaign exploiting default/weak credentials on internet-facing Fortinet FortiGate firewalls. Exposed verified admin and SSL VPN credentials. Traced to INC and Lynx ransomware groups for initial access.
SourceAccenture confirmed a security breach after threat actor '888' claimed to have stolen 35 GB of internal data, including source code, encryption keys, and credentials. The incident could have cascading impacts on Accenture's global client base.
Read moreCISA added four newly exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: Adobe ColdFusion (CVE-2026-48282, CVSS 10.0), two Joomla page builder flaws, and a Langflow authorization bypass (CVE-2026-55255). Federal agencies must patch by July 10.
Read moreUbiquiti released Security Advisory Bulletin 066 addressing 25 vulnerabilities across the UniFi ecosystem. The most severe (CVE-2026-50746, CVSS 10.0) allows unauthenticated command injection on UniFi Connect. Over 100,000 devices are potentially at risk.
Read moreA critical zero-click flaw in Opera GX browser allowed malicious websites to silently install GX Mods and exfiltrate signed-in user data (including Gmail addresses) via CSS. Patched in version LVL5.
Read moreThe ShinyHunters cybercrime group, linked to the Instructure Canvas breach (275M records), is now actively targeting Oracle PeopleSoft instances using CVE-2026-35273. Google researchers report more than 100 organizations may be compromised.
Read moreMaximale-kritische path traversal kwetsbaarheid in Adobe ColdFusion RDS-component die leidt tot unauthorised remote code execution (RCE). Wordt actief misbruikt in het wild sinds de patch van 30 juni 2026. Canadian Centre for Cyber Security (CCCS) waarschuwt voor actieve exploitatie. Getroffen versies: ColdFusion 2025.9, 2023.20 en eerder.
SourceKritieke authenticatie bypass kwetsbaarheid in Gitea Docker images ≤ 1.26.2. Door vertrouwen op de X-WEBAUTH-USER HTTP-header van willekeurige IP-adressen kan een unauthorised aanvaller elke gebruiker (inclusief admins) imiteren wanneer reverse proxy authenticatie is ingeschakeld. Eerste exploits in het wild gezien 13 dagen na disclosure.
SourceStack-based buffer overflow in Windows Netlogon waarmee een unauthorised remote attacker code kan uitvoeren op domeincontrollers. Actief misbruikt in het wild. CERT-EU en CISA adviseren direct patchen gezien de ernst en de geschiedenis van Netlogon-aanvallen (denk aan Zerologon/CVE-2020-1472).
SourceDeserialization remote code execution kwetsbaarheid in on-prem Microsoft SharePoint Server. Toegevoegd aan CISA KEV catalogus op 1 juli 2026 na actieve exploitatie door Storm-2603. Een laaggeprivilegieerde Site Member kan de kwetsbaarheid misbruiken. Patch beschikbaar sinds mei 2026.
SourceUnrestricted upload of file with dangerous type kwetsbaarheid in JoomShaper SP Page Builder voor Joomla. Toegevoegd aan CISA KEV op 7 juli 2026 wegens actieve exploitatie. Maakt volledige server overname mogelijk.
SourceAuthorization bypass via user-controlled key kwetsbaarheid in Langflow, een open-source AI workflow tool. Toegevoegd aan CISA KEV op 7 juli 2026. Maakt unauthorised toegang tot AI/ML-pipelines mogelijk.
SourceNieuw ontdekt multi-stage malware framework 'Avalon' dat eindigt met CrownX ransomware. Aanvalsketen: spoofed legal document email → Proton Drive (password protected archive) → ISO image → LNK file → MSBuild → ETW/EventLog uitschakeling → credential harvesting → CrownX ransomware/extortion. Ontdekt door Blackpoint Cyber APG.
SourceAnubis ransomware operatie maakt gebruik van Citrix Bleed 2 (CVE-2025-5777) voor initial access, in combinatie met BYOVD (Bring Your Own Vulnerable Driver) en supply chain credential harvesting. Gebruikt legitieme RMM-tools voor laterale beweging.
SourceInternationale politie-operatie (Europol, Politie Nederland) heeft malware netwerken rond SocGholish, Amadey en StealC verstoord in juni 2026. SocGholish was sinds 2017 actief als loader voor ransomware op kritieke infrastructuren. Verdachten worden internationaal opgespoord.
SourceDe Eerste Kamer heeft op 7 juli 2026 ingestemd met de Cyberbeveiligingswet. Vanaf 15 augustus 2026 geldt onder andere een registratieplicht bij het NCSC, een wettelijke zorgplicht voor cybersecurity, en een meldplicht voor significante incidenten. Ook de Wet weerbaarheid kritieke entiteiten treedt dan in werking.
Read moreCISA heeft drie nieuwe kwetsbaarheden toegevoegd aan de Known Exploited Vulnerabilities (KEV) catalogus: CVE-2026-48908 (JoomShaper SP Page Builder), CVE-2026-55255 (Langflow authorization bypass), en CVE-2026-56290 (Joomlack Page Builder). Federale instanties krijgen bindende deadline voor patching.
Read moreMeerdere grote Japanse bedrijven zijn getroffen door cyberaanvallen in een tijdsbestek van twee weken. Aflac Japan meldt een datalek met 4,38 miljoen verzekerdengegevens en betaalgegevens van 230.000 klanten. Ook zijn onder andere Nissan, Kubota en Foxconn getroffen via een Oracle PeopleSoft zero-day (CVE-2026-35273) campagne van ShinyHunters.
Read moreAdobe heeft op 30 juni 2026 zeven maximale-kritische (CVSS 10.0) kwetsbaarheden gepatched in ColdFusion en Adobe Campaign Classic. CVE-2026-48282 (ColdFusion path traversal → RCE) wordt nu al actief misbruikt. Organisaties worden dringend geadviseerd de patches direct te installeren.
Read moreNieuw onderzoek toont aan dat ransomware-operaties zoals Anubis steeds vaker gebruik maken van Citrix Bleed 2 (CVE-2025-5777), BYOVD (Bring Your Own Vulnerable Driver) aanvallen, en gestolen supply chain credentials voor initial access. Dit markeert een verschuiving naar meer geavanceerde en moeilijker te detecteren aanvalsvectoren.
Read moreUnrestricted File Upload with Dangerous Type — arbitrary code execution. One of 7 CVSS 10.0 flaws patched by Adobe on July 1.
SourceCritical authentication bypass in OIDC flow. Added to CISA KEV. Actively exploited for TaskWeaver/Djinn Stealer deployment.
SourceType confusion vulnerability allowing unauthorized remote code execution.
SourceUse-after-free in PKCS#7 signature verification (PKCS7_verify). Can lead to RCE or DoS.
SourceDeserialization RCE vulnerability added to CISA KEV. Actively exploited in the wild.
Source'Bad Epoll' — use-after-free race condition in eventpoll. Allows local privilege escalation to root on Linux and Android.
Source'NGINX Rift' — critical heap buffer overflow, 18-year-old bug. Exploit published; actively exploited.
SourceAuthentication bypass: non-empty username + empty/null password accepted.
SourceAccess control bypass lets any client invoke restricted Kubernetes tools. Fixed in v3.6.0.
SourceAuthorization bypass allowing attackers to bypass AuthZ plugins. Incomplete fix of CVE-2024-41110.
SourcePath traversal in versioned static resource resolution (Spring MVC/WebFlux).
SourceInformation disclosure via static resource cache key omission.
SourceXmlLayout fails to properly escape XML-invalid characters, causing log parsing issues.
SourceMulti-stage phishing chain. Credential harvesting from browsers, wallets, VPNs, SSH, RDP. Fileless execution via LOLBins. AI-assisted development. CrownX ransomware payload.
SourcePrioritizes encrypting recently modified files. Operates without ransom notes, uses out-of-band extortion, self-destructs after execution.
SourceDeployed through CVE-2026-48558 exploitation. Steals credentials from cloud services, code repos, and AI development platforms.
SourceThe U.S. Department of Homeland Security is investigating a breach of its Homeland Security Information Network (HSIN), a critical intelligence-sharing platform for law enforcement.
Read moreEuropean Parliament debates EU strategy on cybersecurity and AI, including Cybersecurity Act 2 and targeted amendments to NIS2. Scheduled for vote in July 2026.
Read moreJapanese telecom KDDI disclosed breach affecting email systems used by six ISPs. Up to 14.22 million email login credentials potentially compromised.
Read moreActive exploitation of SharePoint Server deserialization RCE confirmed. Federal agencies required to patch by July 4.
Read moreAdobe disclosed 7 maximum-severity flaws in ColdFusion and Campaign Classic. Moving to twice-monthly security releases starting July 14 citing AI-accelerated vulnerability discovery.
Read moreUnrestricted file upload allowing unauthenticated remote code execution. Part of 7 CVSS 10.0 flaws patched July 1, 2026.
SourceIncorrect authorization allowing attackers to execute arbitrary code on on-premise Campaign Classic v7 instances.
SourceMissing authentication on /api/backup endpoint allows unauthenticated download of full server backups with credentials, session tokens, and SSL keys.
SourceStack-based buffer overflow in Windows Netlogon allows unauthenticated remote code execution on domain controllers.
SourceImproper input validation leading to RCE via deserialization. ACTIVELY EXPLOITED — CISA KEV, webshells deployed in the wild.
SourceImproper input validation in webhook/file-handling logic enabling unauthenticated remote code execution.
SourceOS Command Injection allowing remote unauthenticated RCE as root on Ivanti Sentry appliances.
SourceAuthentication bypass on Ivanti Sentry allowing unauthenticated access.
SourceCritical vulnerability (v4.8.0 to v4.14.4) allowing authenticated endpoints to manipulate central log storage and execute arbitrary code.
SourceHardcoded default password in HTTP administration server (through v1.8.2.2).
SourcePre-authentication RCE via global buffer overflow in embedded HTTP administration server.
SourceActive multi-stage campaign using 90+ spoofed domains, SEO poisoning, and fake software installers. Delivers AsyncRAT via ScreenConnect with DLL sideloading to bypass AV.
SourceWindows Defender exploit chain (CVE-2026-33825). BlueHammer confirmed exploited in ransomware attacks per CISA. Combined with RedSun and UnDefend in 'Nightmare-Eclipse' tooling observed in real-world intrusions.
SourceEuropol-led operation actioned 326 servers and 142 domains. StealC C2 panels reverse-engineered for takedown. These malware-as-a-service platforms enable ransomware, fraud, and attacks on critical infrastructure.
SourceEmergency patches released July 1 for six ColdFusion CVSS 10.0 flaws (unauthenticated RCE, privilege escalation, arbitrary file upload) and one Campaign Classic flaw. Two additional path traversal flaws rated CVSS 9.3.
Read moreOne of the largest data leaks in history: 24 billion records (usernames, passwords, URLs in plaintext) from 36 sources including Telegram channels, infostealer logs, and breach collections. Massive credential-stuffing risk.
Read moreCritical RCE vulnerability actively exploited. CISA KEV, JSP webshells deployed on unpatched instances. PTC, CISA, and BSI have issued urgent patching alerts.
Read moreMicrosoft May 2026 Patch Tuesday fixed CVSS 9.8 unauthenticated RCE in Windows Netlogon. Active scanning and PoC code available. Domain controllers are primary targets.
Read moreMultiple unrestricted file upload and deserialization flaws enabling unauthenticated arbitrary code execution. 7 maximum-severity vulnerabilities patched in emergency update.
SourceIncorrect authorization vulnerability allowing code execution. Patched in the same July 2026 Adobe emergency update.
SourceOS command injection enabling unauthenticated RCE. Active exploitation attempts detected since June 29. CISA warned organizations to patch immediately.
SourceUnauthenticated RCE in File Transmission component. Actively exploited. Over 900 exposed instances identified online.
SourceMissing authentication for critical function — unauthenticated attacker can achieve RCE. Added to CISA KEV catalog. Actively exploited.
SourceUnauthenticated RCE flaw in repo-server component allowing Kubernetes cluster takeover. No fix available yet. Published by Synacktiv.
SourceAI-generated ransomware abusing Chromium File System Access API to encrypt files without native payload after user grants browser-level permissions.
SourceNew Go-based ransomware discovered on underground forums. Targets recent files for encryption and operates without ransom notes.
SourceNew malware loader identified in threat intelligence reports. Deployed in multiple intrusion campaigns.
SourceIranian APT using AppDomainManager hijacking and new RAT variants for espionage campaigns. Tracked by Palo Alto Networks Unit 42.
SourceAttackers using AI-hallucinated domain names (domains that don't exist but AI models hallucinate) for phishing and malware delivery.
SourceAflac Japan (insurer), Sapporo Brewery, Nidec (manufacturer), and KDDI (telecom) all disclosed cyber intrusions inside a two-week window in late June 2026.
Read moreTeenager extradited to face US charges for conspiracy, wire fraud, and computer intrusion as part of the notorious Scattered Spider cybercrime group.
Read moreDepartment of Commerce lifted export control directive, allowing Anthropic to restore global access to its most advanced AI models.
Read moreMicrosoft announced accelerated migration to post-quantum cryptographic standards, citing harvest-now-decrypt-later threats.
Read moreCVE-2026-8451 (CVSS 8.8) and 5 other vulnerabilities patched. The memory overread flaw in SAML IDP configuration can leak restricted memory.
Read morePre-authentication OS command injection allowing unauthenticated root-level RCE via crafted API requests. Public PoC available and active exploitation detected since June 29.
SourceOS command injection allowing remote unauthenticated attackers to achieve root-level remote code execution.
SourceAuthentication bypass allowing remote unauthenticated attacker to create arbitrary admin accounts and obtain full administrative access.
SourceStack-based buffer overflow allowing remote unauthenticated code execution over the network.
SourceUnauthenticated SSRF-to-RCE zero-day exploited in the wild by ShinyHunters, leading to data breaches at Nissan and other organizations.
SourceCritical RCE vulnerability in Windows Domain Controllers, now actively exploited in the wild.
SourceCritical information disclosure vulnerability affecting Exchange Online.
SourceNew Go-based ransomware family that encrypts recently modified files, leaves no ransom note, and self-destructs after execution.
SourceIranian state-sponsored APT deployed six new RAT variants in parallel espionage campaigns using spear-phishing and fake job postings.
SourceCVE-2026-33825 (Microsoft Defender privilege escalation) now being actively exploited by ransomware gangs to gain SYSTEM-level access.
SourceInsurance giant Aflac disclosed a data breach at its Japan subsidiary after unauthorized access from June 15-25, 2026. Customer names, policy details, and bank account information exposed.
Read moreNissan confirmed employee data breach after attackers exploited CVE-2026-35273 (Oracle PeopleSoft zero-day) to access payroll and HR systems. Part of a broader campaign targeting 100+ organizations.
Read moreCVE-2026-8037 in Progress Kemp LoadMaster is being actively exploited since June 29 with public PoC code available. eSentire TRU identified widespread exploitation attempts.
Read moreCheck Point Research found a 60x spike in fake sportsbook apps and extensive phishing/scam infrastructure targeting World Cup 2026 fans, built before the June 11 tournament start.
Read moreCISA confirmed ransomware gangs are exploiting the Microsoft Defender privilege escalation flaw. Added to Known Exploited Vulnerabilities catalog on June 29.
Read moreMicrosoft patched 204 vulnerabilities including 38 critical. Sophos reported 500+ CVEs across the June patch cycle.
Read moreOS Command Injection allowing remote unauthenticated root-level RCE. Actively exploited.
SourceUnauthenticated RCE as root via web management interface. Exploited by Interlock ransomware as zero-day.
SourceUse-after-free allowing remote unauthenticated SYSTEM-level code execution. Wormable.
SourceAuthentication bypass in IKEv1 VPN protocol. Exploited by Qilin ransomware since May 7.
SourceDefault web security bypass allowing unauthorized access to all endpoints in vulnerable configurations.
SourceAuthZ plugin bypass when provided oversized request bodies (1MB+), allowing security policy bypass.
SourceCross-Site WebSocket Hijacking in Spring GraphQL applications with WebSocket transport enabled.
SourceLPE via XFRM ESP-in-TCP page cache corruption — Dirty Frag variant giving root access to local attackers.
SourceAlgorithmic DoS via crafted SpEL expressions causing resource exhaustion.
SourceXSS via JavaScriptUtils.javaScriptEscape() not escaping backtick/dollar sign characters.
SourceFake Perplexity AI extension intercepted searches, address bar input, IPs, and browser headers via MV3 APIs.
SourceQilin claimed attack on Transcore on June 28-29. Qilin remains the most active ransomware group in 2026.
SourceNew Go-based ransomware encrypts recent files first with ChaCha20-Poly1305, leaves no ransom note, self-destructs.
SourceExploited CVE-2026-20131 in Cisco FMC as zero-day for 36 days pre-patch. Campaign identified by Amazon threat intel.
SourceIranian APT group posed as Chaos ransomware affiliate to provide plausible deniability for cyberattacks.
SourceApple fast-tracked security updates after Anthropic's Mythos AI discovered macOS vulnerabilities in 5 days. Signals accelerated patch cycles against AI-powered attacks.
Read moreShinyHunters breached BCD Travel, stealing 700,000 customer records. Data offered for sale on dark web.
Read more2026 federal cybersecurity report finds compliance-focused security still dominates despite widespread expectation of AI-powered attacks.
Read moreQilin affiliates exploited IKEv1 auth bypass since May 7. CISA issued emergency patch mandate for federal agencies.
Read moreNew executive order promotes advanced AI innovation while establishing national security frameworks for AI safety testing.
Read moreUse-after-free and heap-based buffer overflow allows unauthenticated remote code execution. Part of June 2026 Patch Tuesday.
SourceInteger overflow in HTTP.sys allows unauthenticated remote code execution over the network.
SourceStack-based buffer overflow in Windows Netlogon allows unauthenticated RCE. Actively exploited against domain controllers.
SourceOS Command Injection in Ivanti Sentry allows remote, unauthenticated root-level command execution.
SourceAuthentication bypass vulnerability in Ivanti Sentry, disclosed alongside CVE-2026-10520.
SourceAuthorization bypass in Docker/Moby container framework. Attackers can bypass security plugins via oversized requests. Affects 92% of enterprise deployments.
SourcePath Traversal vulnerability in UniFi OS devices allows network-based file access on the underlying system.
SourceUnsafe Jackson deserialization in Spring Framework JMS message converters. Could lead to remote code execution.
SourceDenial of Service via versioned static resources in Spring MVC and WebFlux.
SourceMultipart request smuggling in Spring MVC and WebFlux applications.
SourceInformation disclosure via static resource resolution in Spring MVC and WebFlux.
SourceSSRF vulnerability actively exploited. CISA set June 28 deadline for federal agencies. Allows unauthenticated root access.
SourceCommand injection zero-day exploited in attacks to create rogue root accounts. Reported by Mandiant.
SourcePath traversal vulnerability added to CISA KEV catalog. Active exploitation reported.
Source"Copy Fail" — local privilege escalation in Linux kernel algif_aead module. Enables Kubernetes container escape to node-level root.
SourceNew DirtyClone flaw allows local users to gain root by corrupting file-backed memory through cloned network packets. PoC released.
SourceLinux tc subsystem flaw enables root by corrupting page-cache memory.
SourceContainer escape vulnerability targeting clusters running CRI-O or containerd via host-socket mount.
SourceContainer-to-host code execution in Docker Model Runner MLX backend. Fixed in Docker Desktop 4.71.0.
SourceLocal privilege escalation to SYSTEM via improper authorization. Fixed in v0.99.1.
SourceDoS vulnerability in Advanced DNS Security feature. Attacker can force firewall into maintenance mode.
SourceInvalid XML character handling in XmlLayout output can cause log parsing failures. Log4j 2 <= 2.25.3.
SourceMalicious Edge extension escapes browser sandbox via Native Messaging to deploy Python-based backdoor in ransomware attacks. Discovered by Zscaler.
SourceNew OXLOADER loader spreads via malicious Google Ads (fake Node.js ads), using Storj-hosted payloads with anti-VM checks. Delivers CastleStealer.
SourceNew VBV Stealer campaign quietly collecting user data. Detection added by Hatching Triage.
SourceEuropol coordinated global takedown of cybercrime-as-a-service infrastructure. Over EUR 41M in criminal crypto seized.
SourceIranian APT group spotted on networks of multiple US companies since February 2026.
SourceCISA gave federal agencies until June 28 to patch CVE-2026-20230 (Cisco Unified CM SSRF) and CVE-2026-12569 under BOD 26-04.
Read moreMicrosoft addressed 200 vulnerabilities including 6 zero-days. Critical fixes include Windows Kernel RCE, HTTP.sys RCE, and Netlogon RCE.
Read moreJune Android patches include fix for CVE-2025-48595, actively exploited in targeted attacks.
Read moreCheck Point Research reports ransomware up 48% in May 2026. Education sector most targeted. AI tools accelerating flaw discovery.
Read moreThe FBI declared a major cyber incident after its surveillance system was breached.
Read moreShinyHunters stole 3.65 TB of data from approximately 275 million Canvas LMS users.
Read moreCVE-2026-43503 (DirtyClone) and CVE-2026-46331 (pedit COW) — third and fourth Linux kernel LPE flaws in six weeks. Both bypass file integrity tools.
Read moreVS Code flaw on GitHub.dev allowed one-click attack to steal GitHub OAuth tokens, enabling private repo access.
Read moreMissing authentication in PostgreSQL sidecar service endpoint allows unauthenticated remote attackers to create/truncate files. Actively exploited in the wild. CISA added to KEV catalog.
SourceAuthentication bypass vulnerability in deprecated IKEv1 VPN protocol. Exploited by Qilin ransomware affiliates since May 7, 2026.
SourceUnsafe deserialization via Jackson-based message converters in spring-jms module. RCE in untrusted JMS environments. Affects Spring Framework 5.3.x through 7.0.x.
SourceAuthorization bypass allowing attackers to bypass AuthZ plugins and gain host access. Incomplete fix for CVE-2024-41110. Affects ~92% of enterprise deployments.
SourcePrivilege escalation via AF_ALG splice race in page-cache CoW path. Enables container escape on Kubernetes. Affects all Linux distributions since 2017.
SourceUncontrolled resource consumption (DoS) via crafted HTTP POST requests. Actively exploited, CISA added to KEV catalog.
SourceTLS host identity verification bypass via session reuse (CVE-2026-48934), plus multiple DoS and memory safety issues patched across Node.js 22.x, 24.x, and 26.x lines.
SourceInvalid XML characters in XmlLayout output can cause log parsing failures or injection. Fixed in Log4j 2.25.4.
SourceAccess control bypass allowing unauthorized operations on Kubernetes clusters via Model Context Protocol servers.
SourceNewly discovered Rust-based implant attributed to North Korea-aligned actors. Uses prompt injection (38 fabricated system error messages) to disrupt AI-assisted malware analysis tools.
SourceRapidly emerging centralized ransomware operation with 300+ victims. Uses double extortion, spam email campaigns, and Microsoft Teams to pressure victims.
SourceFastest-growing ransomware group, claims 478+ victims since mid-2025. Targets Windows, Linux, NAS, BSD, and VMware ESXi platforms.
SourceStole 8 TB of data from Foxconn in May 2026 attack. Also hit West Pharmaceutical and other manufacturers. Uses malvertising for initial access.
SourceMicrosoft's largest Patch Tuesday ever fixed 200+ vulnerabilities across Windows, Office, Edge, and Azure, including 6 zero-days (one actively exploited).
Read moreCISA added the critical Splunk flaw to KEV catalog. Public exploits available. Federal agencies given until June 21 to patch.
Read moreCanadian electricity provider disclosed breach exposing customer names, addresses, phone numbers, and account information.
Read moreCritical authentication bypass in IKEv1 VPN under active exploitation since early May. Urgent hotfix released by Check Point.
Read moreElectronics manufacturing giant Foxconn confirmed ransomware attack affecting North American operations. 8 TB of data allegedly stolen by Nitrogen group.
Read more