Cybersecurity Daily Briefings

Critical vulnerabilities, active threats, and security news — curated for professionals.

Updated every workday at 08:00 CET
10 Jul 2026
Daily Cybersecurity Briefing — July 10, 2026
5 CVEs 4 threats 6 news items
Critical Vulnerabilities 5
CVE-2026-48282 CVSS 10.0 Adobe ColdFusion

Critical path traversal vulnerability (CVSS 10.0) in Adobe ColdFusion's Remote Development Services FILEIO handler affecting versions 2025.9, 2023.20 and earlier. Added to CISA KEV on July 7, 2026. Can lead to arbitrary code execution. Being actively exploited in the wild. Federal agencies required to patch by July 10, 2026.

Source
CVE-2026-45659 CVSS 8.8 Microsoft SharePoint Server

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Added to CISA KEV on July 1, 2026. Being actively exploited by threat actor Storm-2603 to deploy Warlock ransomware against on-premises SharePoint servers. Patch shipped May 2026; CISA gave federal agencies 3 days to patch.

Source
CVE-2026-50751 CVSS 9.3 Check Point Security Gateway VPN

Critical authentication bypass vulnerability (CVSS 9.3) in Check Point Remote Access VPN, Mobile Access, and Spark Firewall products using deprecated IKEv1 protocol. Allows unauthenticated remote attackers to bypass password-based authentication. Under active exploitation since disclosure on June 8, 2026. Added to CISA KEV.

Source
CVE-2026-45648 CVSS 8.8 Microsoft Windows Active Directory Domain Services

Critical remote code execution vulnerability in Windows Active Directory Domain Services due to a stack-based buffer overflow. Patched in June 2026 Patch Tuesday (record 198 CVEs). Considered a top priority for enterprise patching.

Source
CVE-2026-50656 CVSS 7.8 Microsoft Malware Protection Engine (Defender)

Privilege escalation vulnerability in the Microsoft Malware Protection Engine (mpengine.dll), dubbed 'RoguePlanet'. Allows local attackers to gain SYSTEM privileges. Microsoft released a fix on July 9, 2026. Discovered by researchers at Kudelski Security.

Source
Malware & Threats 4
Warlock Ransomware (Storm-2603) ransomware Targets: Global — on-premises Microsoft SharePoint servers

Deployed by China-nexus threat actor Storm-2603, Warlock ransomware exploits unpatched SharePoint vulnerabilities (CVE-2026-45659) to gain initial access, escalate privileges, steal credentials, and deploy ransomware across enterprise networks. Added to CISA KEV on July 1, 2026.

Source
StealC / Amadey (Disrupted) infostealer Targets: Global — over 140,000 infected devices

Infostealer malware-as-a-service operations disrupted on June 24, 2026, by Microsoft DCU, Europol, ESET, and partners as part of Operation Endgame. 326 servers seized, 27 million stolen credentials recovered. StealC and Amadey were widely used to deliver ransomware and other payloads.

Source
BabaDeda / Lorem Ipsum / Potemkin Loaders loader Targets: Global — Windows users via social engineering

Three new malware loaders delivered through ClickFix social-engineering lures (fake CAPTCHAs, fake update prompts). Victims are tricked into copying and running malicious PowerShell commands that deploy stealers, RATs, and ransomware tooling. API-driven infrastructure generates fresh obfuscated payloads on demand.

Source
FortiBleed Credential Leak rat Targets: Global maritime, ports, and energy sectors — 194 countries

Large-scale credential compromise campaign affecting Fortinet FortiGate devices. Over 86,000 administrator credentials leaked due to weak password storage algorithms in legacy Fortinet firmware. Hundreds of maritime, port, and energy companies' network perimeters exposed.

Source
Security News 6
CISA Adds 4 Actively Exploited Flaws to KEV — Three Rated CVSS 10.0

CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on July 7, 2026: Adobe ColdFusion path traversal (CVE-2026-48282, CVSS 10.0), two Joomla page builder flaws (JoomShaper SP Page Builder, CVSS 10.0 each), and a Langflow authorization bypass (CVSS 10.0). All are under active exploitation, with the Langflow chain using IDOR + RCE to steal LLM provider credentials.

Read more
Microsoft Patches 'RoguePlanet' Defender Zero-Day (CVE-2026-50656)

Microsoft released a security update on July 9, 2026, for the Microsoft Malware Protection Engine fixing CVE-2026-50656 ('RoguePlanet'), a privilege escalation vulnerability allowing local attackers to gain SYSTEM privileges via Defender's scanning engine.

Read more
EU Launches AI Cybersecurity Action Plan

The European Commission unveiled an Action Plan on Cybersecurity and Artificial Intelligence on July 7, 2026, establishing a dedicated EU framework to address AI-driven cyber threats. The plan includes an EU Grand Challenge on AI for cybersecurity, mandatory security testing of frontier AI systems, and aims to reduce reliance on non-EU AI models.

Read more
IBM and Red Hat Launch Project Lightwell Commercially with $5B Commitment

IBM and Red Hat commercially launched Project Lightwell on July 8, 2026, backed by a $5 billion commitment and 20,000 engineers. The initiative focuses on securing open-source software supply chains with AI-driven vulnerability discovery and remediation, including two new commercial offerings for enterprises.

Read more
FortiBleed Campaign Exposes Credentials at Hundreds of Maritime and Energy Firms

Security researchers identified an active large-scale campaign affecting Fortinet devices across 194 countries. Over 86,000 administrator credentials from FortiGate firewalls were leaked due to weak legacy password storage, exposing maritime, port, and energy companies to potential network compromise.

Read more
Anthropic's AI Finds Thousands of Zero-Day Vulnerabilities; IBM Bets $5B on Remediation

Anthropic's Claude Mythos AI discovered thousands of high-severity zero-day vulnerabilities across major operating systems and browsers as part of Project Glasswing. In response, IBM and Red Hat committed $5B to Project Lightwell for large-scale vulnerability remediation, signaling a new era of AI-driven offensive and defensive cybersecurity.

Read more
9 Jul 2026
Daily Cybersecurity Briefing — July 9, 2026
5 CVEs 4 threats 5 news items
Critical Vulnerabilities 5
CVE-2026-50746 CVSS 10.0 Ubiquiti UniFi Connect Application

Critical improper access control vulnerability in UniFi Connect Application (part of UniFi OS). A network-adjacent attacker can exploit this to execute arbitrary OS commands on the host without authentication. Part of Ubiquiti Security Advisory Bulletin 066, affecting 25 vulnerabilities across the UniFi ecosystem. Over 100,000 endpoints are potentially exposed.

Source
CVE-2026-48282 CVSS 10.0 Adobe ColdFusion

Path traversal vulnerability in Adobe ColdFusion (versions 2025.9, 2023.20 and earlier) affecting the Remote Development Services (RDS) component. A remote, unauthenticated attacker can exploit this to achieve arbitrary code execution. Added to CISA KEV on July 7, 2026 after active exploitation was detected in the wild.

Source
CVE-2026-35273 CVSS 9.8 Oracle PeopleSoft Enterprise PeopleTools

Critical unauthenticated vulnerability in Oracle PeopleSoft Enterprise PeopleTools Updates Environment Management component. Successful exploitation allows remote takeover of PeopleSoft Enterprise PeopleTools without authentication. Added to CISA KEV catalog; actively exploited by ShinyHunters ransomware group.

Source
CVE-2026-14536 CVSS 7.5 Devolutions Server 2026.2.9.0

Improper enforcement of mandatory multi-factor authentication (MFA) policy in Devolutions Server. An attacker with valid user credentials can bypass the MFA Required policy and authenticate without completing multi-factor authentication.

Source
CVE-2026-54403 CVSS 8.6 Ubiquiti UniFi OS

Path traversal vulnerability in UniFi OS that can be chained with other bugs to escalate privileges within UniFi OS devices. Part of Ubiquiti Bulletin 066, enabling chain attacks from low-privilege to full system compromise.

Source
Malware & Threats 4
JadePuffer ransomware Targets: Cloud infrastructure, database servers globally

First documented agentic (LLM-driven) ransomware operation. Using an LLM to autonomously exploit Langflow and Nacos vulnerabilities, JadePuffer steals data from production databases and encrypts systems. Discovered by Sysdig TRT.

Source
Vect / TeamPCP Partnership ransomware Targets: CI/CD pipelines, supply chain, cloud credentials

The Vect ransomware group formalized a partnership with TeamPCP, a supply chain credential-theft gang. TeamPCP harvested 500,000+ cloud credentials from CI/CD pipelines. The alliance industrializes ransomware delivery by combining credential theft with encryption extortion.

Source
PolinRider apt Targets: Software developers, open-source ecosystems (npm, PyPI, Packagist, Go, Chrome Web Store)

North Korea-linked supply chain campaign that published 108 malicious packages and extensions across multiple registries. Uses blockchain-hosted payloads to evade detection. Compromised 1,951 GitHub repositories targeting developers through fake job interviews (Contagious Interview).

Source
FortiBleed infostealer Targets: Fortinet FortiGate firewalls across 194 countries (~75,000 devices)

Massive credential compromise campaign exploiting default/weak credentials on internet-facing Fortinet FortiGate firewalls. Exposed verified admin and SSL VPN credentials. Traced to INC and Lynx ransomware groups for initial access.

Source
Security News 5
Accenture Confirms Data Breach After Hacker Claims 35GB Data Theft

Accenture confirmed a security breach after threat actor '888' claimed to have stolen 35 GB of internal data, including source code, encryption keys, and credentials. The incident could have cascading impacts on Accenture's global client base.

Read more
CISA Adds 4 Actively Exploited Flaws to KEV — Adobe ColdFusion, Joomla, Langflow

CISA added four newly exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: Adobe ColdFusion (CVE-2026-48282, CVSS 10.0), two Joomla page builder flaws, and a Langflow authorization bypass (CVE-2026-55255). Federal agencies must patch by July 10.

Read more
Ubiquiti Patches 25 Critical UniFi Vulnerabilities — CVE-2026-50746 at CVSS 10.0

Ubiquiti released Security Advisory Bulletin 066 addressing 25 vulnerabilities across the UniFi ecosystem. The most severe (CVE-2026-50746, CVSS 10.0) allows unauthenticated command injection on UniFi Connect. Over 100,000 devices are potentially at risk.

Read more
Opera GX Zero-Click Flaw Allowed Silent Malicious Mod Installation

A critical zero-click flaw in Opera GX browser allowed malicious websites to silently install GX Mods and exfiltrate signed-in user data (including Gmail addresses) via CSS. Patched in version LVL5.

Read more
ShinyHunters Targeting Oracle PeopleSoft — Over 100 Organizations at Risk

The ShinyHunters cybercrime group, linked to the Instructure Canvas breach (275M records), is now actively targeting Oracle PeopleSoft instances using CVE-2026-35273. Google researchers report more than 100 organizations may be compromised.

Read more
8 Jul 2026
Cybersecurity Briefing — Woensdag 8 juli 2026
6 CVEs 3 threats 5 news items
Critical Vulnerabilities 6
CVE-2026-48282 CVSS 10.0 Adobe ColdFusion

Maximale-kritische path traversal kwetsbaarheid in Adobe ColdFusion RDS-component die leidt tot unauthorised remote code execution (RCE). Wordt actief misbruikt in het wild sinds de patch van 30 juni 2026. Canadian Centre for Cyber Security (CCCS) waarschuwt voor actieve exploitatie. Getroffen versies: ColdFusion 2025.9, 2023.20 en eerder.

Source
CVE-2026-20896 CVSS 9.8 Gitea Docker

Kritieke authenticatie bypass kwetsbaarheid in Gitea Docker images ≤ 1.26.2. Door vertrouwen op de X-WEBAUTH-USER HTTP-header van willekeurige IP-adressen kan een unauthorised aanvaller elke gebruiker (inclusief admins) imiteren wanneer reverse proxy authenticatie is ingeschakeld. Eerste exploits in het wild gezien 13 dagen na disclosure.

Source
CVE-2026-41089 CVSS 9.8 Microsoft Windows Netlogon

Stack-based buffer overflow in Windows Netlogon waarmee een unauthorised remote attacker code kan uitvoeren op domeincontrollers. Actief misbruikt in het wild. CERT-EU en CISA adviseren direct patchen gezien de ernst en de geschiedenis van Netlogon-aanvallen (denk aan Zerologon/CVE-2020-1472).

Source
CVE-2026-45659 CVSS 8.8 Microsoft SharePoint Server

Deserialization remote code execution kwetsbaarheid in on-prem Microsoft SharePoint Server. Toegevoegd aan CISA KEV catalogus op 1 juli 2026 na actieve exploitatie door Storm-2603. Een laaggeprivilegieerde Site Member kan de kwetsbaarheid misbruiken. Patch beschikbaar sinds mei 2026.

Source
CVE-2026-48908 CVSS 9.8 JoomShaper SP Page Builder (Joomla)

Unrestricted upload of file with dangerous type kwetsbaarheid in JoomShaper SP Page Builder voor Joomla. Toegevoegd aan CISA KEV op 7 juli 2026 wegens actieve exploitatie. Maakt volledige server overname mogelijk.

Source
CVE-2026-55255 CVSS 9.1 Langflow

Authorization bypass via user-controlled key kwetsbaarheid in Langflow, een open-source AI workflow tool. Toegevoegd aan CISA KEV op 7 juli 2026. Maakt unauthorised toegang tot AI/ML-pipelines mogelijk.

Source
Malware & Threats 3
Avalon / CrownX ransomware Targets: Wereldwijd - organisaties via spoofed legal document emails

Nieuw ontdekt multi-stage malware framework 'Avalon' dat eindigt met CrownX ransomware. Aanvalsketen: spoofed legal document email → Proton Drive (password protected archive) → ISO image → LNK file → MSBuild → ETW/EventLog uitschakeling → credential harvesting → CrownX ransomware/extortion. Ontdekt door Blackpoint Cyber APG.

Source
Anubis Ransomware ransomware Targets: Enterprise netwerken wereldwijd

Anubis ransomware operatie maakt gebruik van Citrix Bleed 2 (CVE-2025-5777) voor initial access, in combinatie met BYOVD (Bring Your Own Vulnerable Driver) en supply chain credential harvesting. Gebruikt legitieme RMM-tools voor laterale beweging.

Source
SocGholish / Amadey / StealC loader Targets: Wereldwijd - infrastructuren en critical infrastructure

Internationale politie-operatie (Europol, Politie Nederland) heeft malware netwerken rond SocGholish, Amadey en StealC verstoord in juni 2026. SocGholish was sinds 2017 actief als loader voor ransomware op kritieke infrastructuren. Verdachten worden internationaal opgespoord.

Source
Security News 5
Nederland: Cyberbeveiligingswet goedgekeurd door Eerste Kamer, ingang 15 augustus 2026

De Eerste Kamer heeft op 7 juli 2026 ingestemd met de Cyberbeveiligingswet. Vanaf 15 augustus 2026 geldt onder andere een registratieplicht bij het NCSC, een wettelijke zorgplicht voor cybersecurity, en een meldplicht voor significante incidenten. Ook de Wet weerbaarheid kritieke entiteiten treedt dan in werking.

Read more
CISA voegt 3 nieuwe KEV-kwetsbaarheden toe op 7 juli 2026

CISA heeft drie nieuwe kwetsbaarheden toegevoegd aan de Known Exploited Vulnerabilities (KEV) catalogus: CVE-2026-48908 (JoomShaper SP Page Builder), CVE-2026-55255 (Langflow authorization bypass), en CVE-2026-56290 (Joomlack Page Builder). Federale instanties krijgen bindende deadline voor patching.

Read more
Golf van cyberaanvallen treft Japanse bedrijven — miljoenen getroffen

Meerdere grote Japanse bedrijven zijn getroffen door cyberaanvallen in een tijdsbestek van twee weken. Aflac Japan meldt een datalek met 4,38 miljoen verzekerdengegevens en betaalgegevens van 230.000 klanten. Ook zijn onder andere Nissan, Kubota en Foxconn getroffen via een Oracle PeopleSoft zero-day (CVE-2026-35273) campagne van ShinyHunters.

Read more
Adobe patcht 7 kritische CVSS 10.0 kwetsbaarheden in ColdFusion en Campaign Classic

Adobe heeft op 30 juni 2026 zeven maximale-kritische (CVSS 10.0) kwetsbaarheden gepatched in ColdFusion en Adobe Campaign Classic. CVE-2026-48282 (ColdFusion path traversal → RCE) wordt nu al actief misbruikt. Organisaties worden dringend geadviseerd de patches direct te installeren.

Read more
Ransomware groepen gebruiken Citrix Bleed 2, BYOVD en supply chain credentials

Nieuw onderzoek toont aan dat ransomware-operaties zoals Anubis steeds vaker gebruik maken van Citrix Bleed 2 (CVE-2025-5777), BYOVD (Bring Your Own Vulnerable Driver) aanvallen, en gestolen supply chain credentials voor initial access. Dit markeert een verschuiving naar meer geavanceerde en moeilijker te detecteren aanvalsvectoren.

Read more
6 Jul 2026
Daily Cybersecurity Briefing
13 CVEs 3 threats 5 news items
Critical Vulnerabilities 13
CVE-2026-48276 CVSS 10.0 Adobe ColdFusion 2025/2023

Unrestricted File Upload with Dangerous Type — arbitrary code execution. One of 7 CVSS 10.0 flaws patched by Adobe on July 1.

Source
CVE-2026-48558 CVSS 10.0 SimpleHelp RMM

Critical authentication bypass in OIDC flow. Added to CISA KEV. Actively exploited for TaskWeaver/Djinn Stealer deployment.

Source
CVE-2026-58289 CVSS 9.0 Microsoft Edge (Chromium)

Type confusion vulnerability allowing unauthorized remote code execution.

Source
CVE-2026-45447 CVSS 9.8 OpenSSL

Use-after-free in PKCS#7 signature verification (PKCS7_verify). Can lead to RCE or DoS.

Source
CVE-2026-45659 CVSS 8.8 Microsoft SharePoint Server

Deserialization RCE vulnerability added to CISA KEV. Actively exploited in the wild.

Source
CVE-2026-46242 CVSS 7.8 Linux Kernel 6.4+

'Bad Epoll' — use-after-free race condition in eventpoll. Allows local privilege escalation to root on Linux and Android.

Source
CVE-2026-42945 CVSS 8.1 NGINX (ngx_http_rewrite_module)

'NGINX Rift' — critical heap buffer overflow, 18-year-old bug. Exploit published; actively exploited.

Source
CVE-2026-41720 CVSS 7.4 Spring LDAP

Authentication bypass: non-empty username + empty/null password accepted.

Source
CVE-2026-46519 CVSS 8.8 mcp-server-kubernetes

Access control bypass lets any client invoke restricted Kubernetes tools. Fixed in v3.6.0.

Source
CVE-2026-34040 CVSS 8.8 Docker

Authorization bypass allowing attackers to bypass AuthZ plugins. Incomplete fix of CVE-2024-41110.

Source
CVE-2026-41843 CVSS 5.9 Spring Framework

Path traversal in versioned static resource resolution (Spring MVC/WebFlux).

Source
CVE-2026-41841 CVSS 5.9 Spring Framework

Information disclosure via static resource cache key omission.

Source
CVE-2026-34480 CVSS 5.5 Apache Log4j 2

XmlLayout fails to properly escape XML-invalid characters, causing log parsing issues.

Source
Malware & Threats 3
Avalon / CrownX Ransomware Modular Malware Framework + Ransomware Targets: Windows enterprise networks

Multi-stage phishing chain. Credential harvesting from browsers, wallets, VPNs, SSH, RDP. Fileless execution via LOLBins. AI-assisted development. CrownX ransomware payload.

Source
Prinz Eugen Ransomware Go-based Ransomware Targets: Organizations across multiple sectors

Prioritizes encrypting recently modified files. Operates without ransom notes, uses out-of-band extortion, self-destructs after execution.

Source
TaskWeaver / Djinn Stealer Loader + Infostealer Targets: MSP supply chain via SimpleHelp RMM

Deployed through CVE-2026-48558 exploitation. Steals credentials from cloud services, code repos, and AI development platforms.

Source
Security News 5
DHS HSIN Breach Under Investigation

The U.S. Department of Homeland Security is investigating a breach of its Homeland Security Information Network (HSIN), a critical intelligence-sharing platform for law enforcement.

Read more
EU Debates Cybersecurity Act 2 and NIS2 Amendments

European Parliament debates EU strategy on cybersecurity and AI, including Cybersecurity Act 2 and targeted amendments to NIS2. Scheduled for vote in July 2026.

Read more
KDDI Data Breach — 14.2 Million Credentials Exposed

Japanese telecom KDDI disclosed breach affecting email systems used by six ISPs. Up to 14.22 million email login credentials potentially compromised.

Read more
SharePoint RCE (CVE-2026-45659) Added to CISA KEV

Active exploitation of SharePoint Server deserialization RCE confirmed. Federal agencies required to patch by July 4.

Read more
Adobe Patches 7 CVSS 10.0 Flaws, Moves to Bi-Monthly Releases

Adobe disclosed 7 maximum-severity flaws in ColdFusion and Campaign Classic. Moving to twice-monthly security releases starting July 14 citing AI-accelerated vulnerability discovery.

Read more
3 Jul 2026
Daily Cybersecurity Briefing
11 CVEs 3 threats 4 news items
Critical Vulnerabilities 11
CVE-2026-48276 CVSS 10.0 Adobe ColdFusion 2023/2025

Unrestricted file upload allowing unauthenticated remote code execution. Part of 7 CVSS 10.0 flaws patched July 1, 2026.

Source
CVE-2026-48286 CVSS 10.0 Adobe Campaign Classic v7

Incorrect authorization allowing attackers to execute arbitrary code on on-premise Campaign Classic v7 instances.

Source
CVE-2026-27944 CVSS 9.8 Nginx UI

Missing authentication on /api/backup endpoint allows unauthenticated download of full server backups with credentials, session tokens, and SSL keys.

Source
CVE-2026-41089 CVSS 9.8 Microsoft Windows Netlogon

Stack-based buffer overflow in Windows Netlogon allows unauthenticated remote code execution on domain controllers.

Source
CVE-2026-12569 CVSS 9.8 PTC Windchill / FlexPLM

Improper input validation leading to RCE via deserialization. ACTIVELY EXPLOITED — CISA KEV, webshells deployed in the wild.

Source
CVE-2026-21858 CVSS 10.0 n8n Workflow Automation Platform

Improper input validation in webhook/file-handling logic enabling unauthenticated remote code execution.

Source
CVE-2026-10520 CVSS 10.0 Ivanti Sentry

OS Command Injection allowing remote unauthenticated RCE as root on Ivanti Sentry appliances.

Source
CVE-2026-10523 CVSS 10.0 Ivanti Sentry

Authentication bypass on Ivanti Sentry allowing unauthenticated access.

Source
CVE-2026-28221 CVSS 10.0 Wazuh SIEM Platform

Critical vulnerability (v4.8.0 to v4.14.4) allowing authenticated endpoints to manipulate central log storage and execute arbitrary code.

Source
CVE-2026-7839 CVSS 9.1 UltraVNC Repeater

Hardcoded default password in HTTP administration server (through v1.8.2.2).

Source
CVE-2026-7840 CVSS 9.8 UltraVNC Repeater

Pre-authentication RCE via global buffer overflow in embedded HTTP administration server.

Source
Malware & Threats 3
AsyncRAT Campaign RAT Targets: Windows users worldwide

Active multi-stage campaign using 90+ spoofed domains, SEO poisoning, and fake software installers. Delivers AsyncRAT via ScreenConnect with DLL sideloading to bypass AV.

Source
BlueHammer / RedSun / UnDefend Zero-day exploit tooling Targets: Enterprise Windows environments

Windows Defender exploit chain (CVE-2026-33825). BlueHammer confirmed exploited in ransomware attacks per CISA. Combined with RedSun and UnDefend in 'Nightmare-Eclipse' tooling observed in real-world intrusions.

Source
Operation Endgame Disruption Cybercrime infrastructure takedown Targets: Global (SocGholish, Amadey, StealC malware networks)

Europol-led operation actioned 326 servers and 142 domains. StealC C2 panels reverse-engineered for takedown. These malware-as-a-service platforms enable ransomware, fraud, and attacks on critical infrastructure.

Source
Security News 4
Adobe Patches 7 Maximum-Severity (CVSS 10.0) Flaws in ColdFusion and Campaign Classic

Emergency patches released July 1 for six ColdFusion CVSS 10.0 flaws (unauthenticated RCE, privilege escalation, arbitrary file upload) and one Campaign Classic flaw. Two additional path traversal flaws rated CVSS 9.3.

Read more
24 Billion Credential Records Found Exposed Online

One of the largest data leaks in history: 24 billion records (usernames, passwords, URLs in plaintext) from 36 sources including Telegram channels, infostealer logs, and breach collections. Massive credential-stuffing risk.

Read more
PTC Windchill CVE-2026-12569 Under Active Exploitation with JSP Webshells

Critical RCE vulnerability actively exploited. CISA KEV, JSP webshells deployed on unpatched instances. PTC, CISA, and BSI have issued urgent patching alerts.

Read more
Critical Netlogon Vulnerability (CVE-2026-41089) in Attackers' Crosshairs

Microsoft May 2026 Patch Tuesday fixed CVSS 9.8 unauthenticated RCE in Windows Netlogon. Active scanning and PoC code available. Domain controllers are primary targets.

Read more
2 Jul 2026
Daily Cybersecurity Briefing
6 CVEs 5 threats 5 news items
Critical Vulnerabilities 6
CVE-2026-48276, CVE-2026-48283, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316 CVSS 10.0 Adobe ColdFusion

Multiple unrestricted file upload and deserialization flaws enabling unauthenticated arbitrary code execution. 7 maximum-severity vulnerabilities patched in emergency update.

Source
CVE-2026-48286 CVSS 10.0 Adobe Campaign Classic

Incorrect authorization vulnerability allowing code execution. Patched in the same July 2026 Adobe emergency update.

Source
CVE-2026-8037 CVSS 9.6 Progress Kemp LoadMaster

OS command injection enabling unauthenticated RCE. Active exploitation attempts detected since June 29. CISA warned organizations to patch immediately.

Source
CVE-2026-46817 CVSS 9.8 Oracle E-Business Suite (Oracle Payments)

Unauthenticated RCE in File Transmission component. Actively exploited. Over 900 exposed instances identified online.

Source
CVE-2026-35273 CVSS 9.8 Oracle PeopleSoft Enterprise PeopleTools

Missing authentication for critical function — unauthenticated attacker can achieve RCE. Added to CISA KEV catalog. Actively exploited.

Source
Argo CD repo-server (no CVE yet) CVSS Unpatched Argo CD / Kubernetes

Unauthenticated RCE flaw in repo-server component allowing Kubernetes cluster takeover. No fix available yet. Published by Synacktiv.

Source
Malware & Threats 5
AI-Generated Browser Ransomware Browser Ransomware Targets: Windows & Android users

AI-generated ransomware abusing Chromium File System Access API to encrypt files without native payload after user grants browser-level permissions.

Source
Prinz Eugen Ransomware Ransomware Targets: General

New Go-based ransomware discovered on underground forums. Targets recent files for encryption and operates without ransom notes.

Source
GoldenGh0stLoader Malware Loader Targets: General

New malware loader identified in threat intelligence reports. Deployed in multiple intrusion campaigns.

Source
Screening Serpens (Iranian APT) APT / RAT Targets: Technology & Defense sectors

Iranian APT using AppDomainManager hijacking and new RAT variants for espionage campaigns. Tracked by Palo Alto Networks Unit 42.

Source
Phantom Squatting Campaign Phishing / Brand Abuse Targets: General public & enterprises

Attackers using AI-hallucinated domain names (domains that don't exist but AI models hallucinate) for phishing and malware delivery.

Source
Security News 5
Four Japanese Giants Breached in Two Weeks

Aflac Japan (insurer), Sapporo Brewery, Nidec (manufacturer), and KDDI (telecom) all disclosed cyber intrusions inside a two-week window in late June 2026.

Read more
19-Year-Old Scattered Spider Suspect Extradited from Finland to US

Teenager extradited to face US charges for conspiracy, wire fraud, and computer intrusion as part of the notorious Scattered Spider cybercrime group.

Read more
US Lifts Export Controls on Anthropic's Claude Fable 5 & Mythos 5

Department of Commerce lifted export control directive, allowing Anthropic to restore global access to its most advanced AI models.

Read more
Microsoft Accelerates Post-Quantum Cryptography Timeline to 2029

Microsoft announced accelerated migration to post-quantum cryptographic standards, citing harvest-now-decrypt-later threats.

Read more
Citrix Patches Six NetScaler Flaws Including CitrixBleed-style Memory Overread

CVE-2026-8451 (CVSS 8.8) and 5 other vulnerabilities patched. The memory overread flaw in SAML IDP configuration can leak restricted memory.

Read more
1 Jul 2026
Daily Cybersecurity Briefing
7 CVEs 3 threats 6 news items
Critical Vulnerabilities 7
CVE-2026-8037 CVSS 9.8 Progress Kemp LoadMaster

Pre-authentication OS command injection allowing unauthenticated root-level RCE via crafted API requests. Public PoC available and active exploitation detected since June 29.

Source
CVE-2026-10520 CVSS 10.0 Ivanti Sentry

OS command injection allowing remote unauthenticated attackers to achieve root-level remote code execution.

Source
CVE-2026-10523 CVSS 9.8 Ivanti Sentry

Authentication bypass allowing remote unauthenticated attacker to create arbitrary admin accounts and obtain full administrative access.

Source
CVE-2026-44815 CVSS 9.8 Windows DHCP Client Service

Stack-based buffer overflow allowing remote unauthenticated code execution over the network.

Source
CVE-2026-35273 CVSS 9.8 Oracle PeopleSoft PeopleTools

Unauthenticated SSRF-to-RCE zero-day exploited in the wild by ShinyHunters, leading to data breaches at Nissan and other organizations.

Source
CVE-2026-41089 CVSS 9.8 Windows Netlogon

Critical RCE vulnerability in Windows Domain Controllers, now actively exploited in the wild.

Source
CVE-2026-48579 CVSS 9.1 Microsoft Exchange Online

Critical information disclosure vulnerability affecting Exchange Online.

Source
Malware & Threats 3
Prinz Eugen Ransomware Ransomware Targets: General / enterprise environments

New Go-based ransomware family that encrypts recently modified files, leaves no ransom note, and self-destructs after execution.

Source
Screening Serpens (Iranian APT) APT / RAT Targets: US, Israel, UAE high-value sectors

Iranian state-sponsored APT deployed six new RAT variants in parallel espionage campaigns using spear-phishing and fake job postings.

Source
BlueHammer ransomware exploitation Ransomware Targets: Windows systems

CVE-2026-33825 (Microsoft Defender privilege escalation) now being actively exploited by ransomware gangs to gain SYSTEM-level access.

Source
Security News 6
Aflac Japan Data Breach - 4+ Million Customers Affected

Insurance giant Aflac disclosed a data breach at its Japan subsidiary after unauthorized access from June 15-25, 2026. Customer names, policy details, and bank account information exposed.

Read more
Nissan Employee Data Breached via Oracle PeopleSoft Zero-Day

Nissan confirmed employee data breach after attackers exploited CVE-2026-35273 (Oracle PeopleSoft zero-day) to access payroll and HR systems. Part of a broader campaign targeting 100+ organizations.

Read more
Progress Kemp LoadMaster Under Active Attack

CVE-2026-8037 in Progress Kemp LoadMaster is being actively exploited since June 29 with public PoC code available. eSentire TRU identified widespread exploitation attempts.

Read more
FIFA World Cup 2026 Fraud Infrastructure Pre-Built Before Kickoff

Check Point Research found a 60x spike in fake sportsbook apps and extensive phishing/scam infrastructure targeting World Cup 2026 fans, built before the June 11 tournament start.

Read more
BlueHammer (CVE-2026-33825) Added to CISA KEV

CISA confirmed ransomware gangs are exploiting the Microsoft Defender privilege escalation flaw. Added to Known Exploited Vulnerabilities catalog on June 29.

Read more
June 2026 Patch Tuesday Smashes Records

Microsoft patched 204 vulnerabilities including 38 critical. Sophos reported 500+ CVEs across the June patch cycle.

Read more
30 Jun 2026
Daily Cybersecurity Briefing
10 CVEs 5 threats 5 news items
Critical Vulnerabilities 10
CVE-2026-10520 CVSS 10.0 Ivanti Sentry

OS Command Injection allowing remote unauthenticated root-level RCE. Actively exploited.

Source
CVE-2026-20131 CVSS 10.0 Cisco Secure FMC

Unauthenticated RCE as root via web management interface. Exploited by Interlock ransomware as zero-day.

Source
CVE-2026-45657 CVSS 9.8 Windows Kernel

Use-after-free allowing remote unauthenticated SYSTEM-level code execution. Wormable.

Source
CVE-2026-50751 CVSS 9.3 Check Point VPN

Authentication bypass in IKEv1 VPN protocol. Exploited by Qilin ransomware since May 7.

Source
CVE-2026-40976 CVSS 9.1 Spring Boot

Default web security bypass allowing unauthorized access to all endpoints in vulnerable configurations.

Source
CVE-2026-34040 CVSS 8.8 Docker Engine / Moby

AuthZ plugin bypass when provided oversized request bodies (1MB+), allowing security policy bypass.

Source
CVE-2026-41700 CVSS 8.1 Spring for GraphQL

Cross-Site WebSocket Hijacking in Spring GraphQL applications with WebSocket transport enabled.

Source
CVE-2026-46300 CVSS 7.8 Linux Kernel (Fragnesia)

LPE via XFRM ESP-in-TCP page cache corruption — Dirty Frag variant giving root access to local attackers.

Source
CVE-2026-41850 CVSS 7.5 Spring Framework

Algorithmic DoS via crafted SpEL expressions causing resource exhaustion.

Source
CVE-2026-41845 CVSS 7.1 Spring Framework

XSS via JavaScriptUtils.javaScriptEscape() not escaping backtick/dollar sign characters.

Source
Malware & Threats 5
Malicious Perplexity Chrome Extension Spyware/Info-stealer Targets: Chrome users searching for AI tools

Fake Perplexity AI extension intercepted searches, address bar input, IPs, and browser headers via MV3 APIs.

Source
Qilin Ransomware — Transcore Attack Ransomware Targets: US transportation/logistics sector

Qilin claimed attack on Transcore on June 28-29. Qilin remains the most active ransomware group in 2026.

Source
Prinz Eugen Ransomware Ransomware (Go-based) Targets: Enterprise businesses

New Go-based ransomware encrypts recent files first with ChaCha20-Poly1305, leaves no ransom note, self-destructs.

Source
Interlock Ransomware Ransomware Targets: Enterprise firewall infrastructure

Exploited CVE-2026-20131 in Cisco FMC as zero-day for 36 days pre-patch. Campaign identified by Amazon threat intel.

Source
Iran-Linked APT (Chaos Ransomware Front) APT Targets: International organizations

Iranian APT group posed as Chaos ransomware affiliate to provide plausible deniability for cyberattacks.

Source
Security News 5
Apple Releases iOS 26.5.2 Early After Anthropic's Mythos AI Found Vulnerabilities

Apple fast-tracked security updates after Anthropic's Mythos AI discovered macOS vulnerabilities in 5 days. Signals accelerated patch cycles against AI-powered attacks.

Read more
Dutch Travel Firm BCD Hacked — 700,000 Customers Affected by ShinyHunters

ShinyHunters breached BCD Travel, stealing 700,000 customer records. Data offered for sale on dark web.

Read more
85% of Defense Contractors Expect AI Attacks, Yet Half Build Security Around Compliance

2026 federal cybersecurity report finds compliance-focused security still dominates despite widespread expectation of AI-powered attacks.

Read more
Check Point VPN Zero-Day (CVE-2026-50751) Actively Exploited by Qilin Ransomware

Qilin affiliates exploited IKEv1 auth bypass since May 7. CISA issued emergency patch mandate for federal agencies.

Read more
White House Executive Order on AI Innovation and Security

New executive order promotes advanced AI innovation while establishing national security frameworks for AI safety testing.

Read more
29 Jun 2026
Daily Cybersecurity Briefing
22 CVEs 5 threats 8 news items
Critical Vulnerabilities 22
CVE-2026-45657 CVSS 9.8 Microsoft Windows Kernel

Use-after-free and heap-based buffer overflow allows unauthenticated remote code execution. Part of June 2026 Patch Tuesday.

Source
CVE-2026-47291 CVSS 9.8 Microsoft Windows HTTP.sys

Integer overflow in HTTP.sys allows unauthenticated remote code execution over the network.

Source
CVE-2026-41089 CVSS 9.8 Microsoft Windows Netlogon

Stack-based buffer overflow in Windows Netlogon allows unauthenticated RCE. Actively exploited against domain controllers.

Source
CVE-2026-10520 CVSS 10.0 Ivanti Sentry

OS Command Injection in Ivanti Sentry allows remote, unauthenticated root-level command execution.

Source
CVE-2026-10523 CVSS 9.9 Ivanti Sentry

Authentication bypass vulnerability in Ivanti Sentry, disclosed alongside CVE-2026-10520.

Source
CVE-2026-34040 CVSS Critical Docker/Moby

Authorization bypass in Docker/Moby container framework. Attackers can bypass security plugins via oversized requests. Affects 92% of enterprise deployments.

Source
CVE-2026-34909 CVSS High Ubiquiti UniFi OS

Path Traversal vulnerability in UniFi OS devices allows network-based file access on the underlying system.

Source
CVE-2026-41855 CVSS 8.1 Spring Framework

Unsafe Jackson deserialization in Spring Framework JMS message converters. Could lead to remote code execution.

Source
CVE-2026-41842 CVSS 7.5 Spring Framework

Denial of Service via versioned static resources in Spring MVC and WebFlux.

Source
CVE-2026-41853 CVSS 5.3 Spring Framework

Multipart request smuggling in Spring MVC and WebFlux applications.

Source
CVE-2026-41841 CVSS 5.3 Spring Framework

Information disclosure via static resource resolution in Spring MVC and WebFlux.

Source
CVE-2026-20230 CVSS 8.6 Cisco Unified Communications Manager

SSRF vulnerability actively exploited. CISA set June 28 deadline for federal agencies. Allows unauthenticated root access.

Source
CVE-2026-20245 CVSS 7.8 Cisco Catalyst SD-WAN

Command injection zero-day exploited in attacks to create rogue root accounts. Reported by Mandiant.

Source
CVE-2026-20262 CVSS High Cisco Catalyst SD-WAN Manager

Path traversal vulnerability added to CISA KEV catalog. Active exploitation reported.

Source
CVE-2026-31431 CVSS 7.8 Linux Kernel / Kubernetes

"Copy Fail" — local privilege escalation in Linux kernel algif_aead module. Enables Kubernetes container escape to node-level root.

Source
CVE-2026-43503 CVSS High Linux Kernel (DirtyClone)

New DirtyClone flaw allows local users to gain root by corrupting file-backed memory through cloned network packets. PoC released.

Source
CVE-2026-46331 CVSS High Linux Kernel (pedit COW)

Linux tc subsystem flaw enables root by corrupting page-cache memory.

Source
CVE-2026-0093 CVSS Critical Kubernetes

Container escape vulnerability targeting clusters running CRI-O or containerd via host-socket mount.

Source
CVE-2026-5843 CVSS High Docker Desktop

Container-to-host code execution in Docker Model Runner MLX backend. Fixed in Docker Desktop 4.71.0.

Source
CVE-2026-42902 CVSS High Microsoft PowerToys

Local privilege escalation to SYSTEM via improper authorization. Fixed in v0.99.1.

Source
CVE-2026-0229 CVSS Medium Palo Alto Networks PAN-OS

DoS vulnerability in Advanced DNS Security feature. Attacker can force firewall into maintenance mode.

Source
CVE-2026-34480 CVSS Medium Apache Log4j

Invalid XML character handling in XmlLayout output can cause log parsing failures. Log4j 2 <= 2.25.3.

Source
Malware & Threats 5
Edgecution Malicious Browser Extension / Ransomware Targets: Microsoft Edge users

Malicious Edge extension escapes browser sandbox via Native Messaging to deploy Python-based backdoor in ransomware attacks. Discovered by Zscaler.

Source
OXLOADER + CastleStealer Malware Loader / Infostealer Targets: Victims of malvertising

New OXLOADER loader spreads via malicious Google Ads (fake Node.js ads), using Storj-hosted payloads with anti-VM checks. Delivers CastleStealer.

Source
VBV Stealer Information Stealer Targets: General users

New VBV Stealer campaign quietly collecting user data. Detection added by Hatching Triage.

Source
Operation Endgame Phase 2 Law Enforcement Takedown Targets: SocGholish, Amadey, StealC infrastructure

Europol coordinated global takedown of cybercrime-as-a-service infrastructure. Over EUR 41M in criminal crypto seized.

Source
Seedworm (MuddyWater) Iranian APT Targets: US banks, airports, defense contractors

Iranian APT group spotted on networks of multiple US companies since February 2026.

Source
Security News 8
CISA Sets Urgent Deadline for Cisco Flaw Exploited in Attacks

CISA gave federal agencies until June 28 to patch CVE-2026-20230 (Cisco Unified CM SSRF) and CVE-2026-12569 under BOD 26-04.

Read more
Microsoft June 2026 Patch Tuesday Fixes 200 Flaws, 6 Zero-Days

Microsoft addressed 200 vulnerabilities including 6 zero-days. Critical fixes include Windows Kernel RCE, HTTP.sys RCE, and Netlogon RCE.

Read more
Google June 2026 Android Update Patches 124 Flaws Including Exploited Zero-Day

June Android patches include fix for CVE-2025-48595, actively exploited in targeted attacks.

Read more
Ransomware Surges 48% — AI Accelerating Cybercrime

Check Point Research reports ransomware up 48% in May 2026. Education sector most targeted. AI tools accelerating flaw discovery.

Read more
FBI Declares Major Cyber Incident After Surveillance System Breach

The FBI declared a major cyber incident after its surveillance system was breached.

Read more
Canvas Data Breach — 275 Million Users Affected

ShinyHunters stole 3.65 TB of data from approximately 275 million Canvas LMS users.

Read more
Linux Kernel: Third Major LPE in Six Weeks (DirtyClone + pedit COW)

CVE-2026-43503 (DirtyClone) and CVE-2026-46331 (pedit COW) — third and fourth Linux kernel LPE flaws in six weeks. Both bypass file integrity tools.

Read more
One-Click GitHub Dev Attack Exposes OAuth Tokens

VS Code flaw on GitHub.dev allowed one-click attack to steal GitHub OAuth tokens, enabling private repo access.

Read more
26 Jun 2026
Daily Cybersecurity Briefing
9 CVEs 4 threats 5 news items
Critical Vulnerabilities 9
CVE-2026-20253 CVSS 9.8 Splunk Enterprise

Missing authentication in PostgreSQL sidecar service endpoint allows unauthenticated remote attackers to create/truncate files. Actively exploited in the wild. CISA added to KEV catalog.

Source
CVE-2026-50751 CVSS 9.3 Check Point VPN Remote Access / Mobile Access

Authentication bypass vulnerability in deprecated IKEv1 VPN protocol. Exploited by Qilin ransomware affiliates since May 7, 2026.

Source
CVE-2026-41855 CVSS 8.8 Spring Framework (JMS module)

Unsafe deserialization via Jackson-based message converters in spring-jms module. RCE in untrusted JMS environments. Affects Spring Framework 5.3.x through 7.0.x.

Source
CVE-2026-34040 CVSS 8.8 Docker Engine (< 29.3.1)

Authorization bypass allowing attackers to bypass AuthZ plugins and gain host access. Incomplete fix for CVE-2024-41110. Affects ~92% of enterprise deployments.

Source
CVE-2026-31431 CVSS 7.8 Linux Kernel ('Copy Fail')

Privilege escalation via AF_ALG splice race in page-cache CoW path. Enables container escape on Kubernetes. Affects all Linux distributions since 2017.

Source
CVE-2026-28318 CVSS 7.5 SolarWinds Serv-U

Uncontrolled resource consumption (DoS) via crafted HTTP POST requests. Actively exploited, CISA added to KEV catalog.

Source
Node.js June 2026 (12 CVEs incl. CVE-2026-48934) CVSS Various Node.js (all active release lines)

TLS host identity verification bypass via session reuse (CVE-2026-48934), plus multiple DoS and memory safety issues patched across Node.js 22.x, 24.x, and 26.x lines.

Source
CVE-2026-34480 CVSS 5.5 Apache Log4j 2 (<= 2.25.3)

Invalid XML characters in XmlLayout output can cause log parsing failures or injection. Fixed in Log4j 2.25.4.

Source
CVE-2026-46519 CVSS TBD Kubernetes MCP Server

Access control bypass allowing unauthorized operations on Kubernetes clusters via Model Context Protocol servers.

Source
Malware & Threats 4
Gaslight macOS Malware Rust-based Backdoor Targets: macOS users

Newly discovered Rust-based implant attributed to North Korea-aligned actors. Uses prompt injection (38 fabricated system error messages) to disrupt AI-assisted malware analysis tools.

Source
SafePay Ransomware Ransomware (Double Extortion) Targets: Global organizations

Rapidly emerging centralized ransomware operation with 300+ victims. Uses double extortion, spam email campaigns, and Microsoft Teams to pressure victims.

Source
The Gentlemen RaaS Ransomware-as-a-Service Targets: Organizations across 66+ countries

Fastest-growing ransomware group, claims 478+ victims since mid-2025. Targets Windows, Linux, NAS, BSD, and VMware ESXi platforms.

Source
Nitrogen Ransomware Ransomware Targets: Manufacturing sector

Stole 8 TB of data from Foxconn in May 2026 attack. Also hit West Pharmaceutical and other manufacturers. Uses malvertising for initial access.

Source
Security News 5
Microsoft June 2026 Patch Tuesday — Record 200+ flaws, 6 zero-days

Microsoft's largest Patch Tuesday ever fixed 200+ vulnerabilities across Windows, Office, Edge, and Azure, including 6 zero-days (one actively exploited).

Read more
CISA: Splunk Enterprise CVE-2026-20253 Under Active Attack

CISA added the critical Splunk flaw to KEV catalog. Public exploits available. Federal agencies given until June 21 to patch.

Read more
London Hydro Data Breach Exposes Customer Information

Canadian electricity provider disclosed breach exposing customer names, addresses, phone numbers, and account information.

Read more
Check Point VPN Zero-Day (CVE-2026-50751) Exploited by Qilin Ransomware

Critical authentication bypass in IKEv1 VPN under active exploitation since early May. Urgent hotfix released by Check Point.

Read more
Foxconn Confirms Nitrogen Ransomware Attack

Electronics manufacturing giant Foxconn confirmed ransomware attack affecting North American operations. 8 TB of data allegedly stolen by Nitrogen group.

Read more
Featured Project

Zero Day Clock

Track Time-to-Exploit across 83,000+ CVEs in real time

Explore live exploit intelligence →