Critical vulnerabilities, active threats, and security news — curated for professionals.
Improper input validation in UniFi OS enabling remote code execution. Added to CISA KEV June 23 — actively exploited.
SourceCritical Windows Kernel remote code execution vulnerability patched in June 2026 Patch Tuesday.
SourceStack-based buffer overflow RCE in Windows DHCP Client Service.
SourceHeap use-after-free in PKCS7_verify() enabling potential RCE. Patched June 2026.
SourceUnauthenticated RCE actively exploited by ShinyHunters in education sector campaigns.
SourceStack-based buffer overflow allowing unauthenticated RCE on Domain Controllers. Actively exploited.
SourceCritical information disclosure vulnerability in Exchange Online.
SourceCritical severity vulnerability published June 24, 2026. NVD analysis pending.
SourceNew malware loader evading detection via .reloc section abuse and anti-VM checks to deliver CastleStealer infostealer. Uses fake Node.js ads and Storj-hosted payloads.
SourceActive compromise campaign via CVE-2026-35273 (Oracle PeopleSoft zero-day). Mandiant/Google Threat Intelligence identified campaign.
SourceEuropol, Microsoft DCU, Dutch Police disrupted major malware networks. Servers taken offline June 24, 2026.
Source2.2M records stolen. Kodak confirmed breach after ShinyHunters threatened leak.
SourceCISA added Lantronix EDS5000 and Ubiquiti UniFi OS flaws to KEV. Federal agencies must patch by June 26.
Read moreSupplier confirmed cyber incident after World Leaks group claimed theft of Apple factory data and Tesla trade secrets.
Read more206 vulnerabilities patched including 39 Critical and 6 zero-days (1 actively exploited).
Read moreIncludes 22 critical flaws. One zero-day (CVE-2026-11645) exploited in the wild.
Read moreCVE-2026-20230 now actively exploited to drop webshells and gain root access on Cisco Unified Communications Manager.
Read moreBelgian government confirms active exploitation of critical Netlogon RCE. Urgent patching advised.
Read moreUse-after-free vulnerability allowing remote, unauthenticated code execution over network. Patched in June 2026 Patch Tuesday.
SourceUnauthenticated SSRF-to-RCE vulnerability actively exploited by ShinyHunters. Oracle out-of-band security alert released.
SourceAuthentication bypass in Remote Access VPN and Mobile Access. Actively exploited by Qilin ransomware affiliates since May 7.
SourceCross-Site WebSocket Hijacking in Spring for GraphQL applications with WebSocket transport enabled.
SourceUnbounded DEFLATE inflation in SAML 2.0 Service Provider allowing DoS via crafted SAML assertions.
SourceUnfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credentials BLOB database entries.
SourceTLS hostname verification bypass via improper Unicode dot separator handling leading to unauthorized connections.
SourceTLS host identity verification bypass via session reuse with different servername.
SourceAuthorization plugin bypass (AuthZ) affecting container security. Patched in Docker Engine 29.3.1.
SourcePotential out-of-bounds access in ceph_handle_auth_reply() function, could lead to memory corruption or DoS.
SourceElevation of privilege in Microsoft Malware Protection Engine. Zero-day publicly disclosed; turns Defender quarantine into attack vector.
SourceLarge-scale campaign distributing malicious VBScript files via WhatsApp direct messages. Delivers RATs and info-stealers.
SourceOngoing large-scale campaign exploiting CVE-2026-24858 and default credentials. Thousands of device credentials leaked.
Sourcenpm supply chain attack compromising 90+ Red Hat packages. Worm-like self-propagation through CI/CD and Azure repos. Credential-stealing.
SourceGo-based RAT abusing Microsoft Teams TURN relay servers to mask C2 traffic. Used by DragonForce ransomware affiliates.
SourceUS, UK, Canada, Australia, NZ intelligence agencies warn cutting-edge AI could overwhelm defenses of governments and businesses within months.
Read moreIndian Apple/Tesla supplier hit by cyberattack. Threat actors claim theft of factory data, supplier documents, and trade secrets.
Read moreReport finds 48% of ransomware victims had data exfiltrated before ransomware was detected. Emphasizes need for faster detection.
Read moreMicrosoft patched 200+ vulnerabilities including 33 critical. Highlights: CVE-2026-45657 (Windows Kernel RCE CVSS 9.8), Graphics Component RCEs.
Read moreJune 18 security releases addressed 12 CVEs across Node.js 22.x, 24.x, 26.x. Includes TLS auth bypass and session reuse flaws.
Read moreHorizon Eye Care (US ophthalmology provider) fell victim to INC Ransom group. Discovered June 24, 2026.
Read moreOS Command Injection allowing remote unauthenticated attacker to execute arbitrary commands. Actively exploited.
SourceAuthentication Bypass (CWE-288) allowing remote unauthenticated attacker to create arbitrary admin accounts.
SourceStack-based buffer overflow allowing remote code execution over the network with low attack complexity.
SourceMissing Authentication for Critical Function in PostgreSQL sidecar. Unauthenticated RCE. Added to CISA KEV June 18.
SourceZero-day spoofing vulnerability in Exchange OWA, actively exploited in attacks. Patched in June 2026 Patch Tuesday.
Source830+ victims since 2023. Rewritten in Rust. Exploits Citrix NetScaler and Veeam backup vulnerabilities. Credential dumping against backup deployments.
SourceDisrupted via Operation Endgame (FBI, Dutch Police, Europol). ~15,000 infected websites cleaned. Hunt ongoing for group members.
SourceUses ClickFix and fake browser update redirects. Hijacked thousands of legitimate websites. Delivers Windows and macOS malware.
SourceEmerging underground market that searches stolen credential databases for specific companies/domains. Midpoint in infostealer-to-account-takeover chain.
SourceIcarus threat actor exploited dormant OAuth tokens from a defunct Klue integration to access Salesforce CRM data at hundreds of clients including multiple security vendors.
Read moreHealthcare device maker iRhythm disclosed data breach after hackers accessed third-party-hosted applications. Patient health information stolen, ransom demanded.
Read moreCISA added Cisco Catalyst SD-WAN Manager (CVE-2026-20245), Chrome V8, Arista EOS, and Splunk Enterprise (CVE-2026-20253) to Known Exploited Vulnerabilities catalog. Federal agencies required to patch by June 23, 2026.
Read moreRecord-breaking Patch Tuesday: 204-209 vulnerabilities patched including 6 zero-days (3 publicly disclosed), 38+ critical flaws across Windows, Office, Exchange, Azure, Hyper-V.
Read moreResearcher disclosed Microsoft Defender zero-day granting SYSTEM privileges via race condition in quarantine feature. Permanent patch in progress.
Read moreSAP released 15 security patches including 4 critical for NetWeaver AS ABAP, SAP Kernel, NetWeaver AS Java, and Commerce Cloud.
Read moreGoogle patched 124 Android vulnerabilities including actively exploited zero-day CVE-2025-48595. 18 critical flaws in framework, system, and Qualcomm components.
Read moreCritical buffer overflow vulnerability in Perl DBI error message handling. Error messages written to a 200-byte buffer without length limit, allowing attackers who can influence error text to trigger a buffer overflow.
SourceCritical out-of-bounds read/information disclosure vulnerability in Microsoft Office. An unauthorized attacker can disclose information locally via a buffer over-read.
SourceCritical improper input validation in Adobe ColdFusion. Internet-facing servers should be patched as emergency.
SourceNew ransomware that prioritizes recent files, leaves no ransom note, extorts out-of-band.
SourceINC evolved into one of the most active ransomware groups with 830+ victims.
SourceFirst known malware to abuse Microsoft Teams TURN relay for C2 traffic blending.
SourceCampaign exposes credentials for 73,000+ FortiGate firewalls across 194 countries. Includes IPs, admin passwords, SSL VPN creds.
Read more429,000+ documents stolen including 15 years of payroll data for 10,000+ staff across 46 member states.
Read moreStudent data leaked via third-party breach. Linked to ShinyHunters. 8.8M records exposed.
Read more200+ flaws including 3 zero-days. Critical: Office info disclosure (CVE-2026-45460), AKS RCE (CVE-2026-32193).
Read morePHI and proprietary data stolen from third-party apps. Ransom demanded. Patient safety unaffected.
Read more12 vulnerabilities patched including TLS auth bypass and AES DoS. Upgrades to OpenSSL 3.5.7, llhttp 9.4.2.
Read moreEmergency patch for ColdFusion 2025/2023. CVE-2026-47928 critical input validation flaw.
Read moreAuthentication bypass by spoofing allowing unauthorized elevation of privileges over network.
SourceUnauthenticated remote code execution via HTTP.
SourceBuffer overflow in error message handling — attackers influencing error text can trigger overflow. Versions < 1.648 affected.
SourceRemote Code Execution vulnerability, patched in June 2026 Patch Tuesday.
SourceDHCP Client Service Remote Code Execution Vulnerability.
SourceRemote Code Execution via unsafe deserialization in Jackson JMS message converters. Affects Spring Framework 5.3.0-7.0.7.
SourceContainer breakout via XFRM ESP-in-TCP privilege escalation affecting Docker, GKE, EKS.
SourceAuthZ bypass via padded requests enabling dangerous container creation. Fixed in Docker 29.3.1.
SourceInformation disclosure via improper authorization.
SourceAuthentication bypass via CRLF injection. Actively exploited — 44,000+ servers compromised globally.
Source243 CVEs across 245 security updates including JD Edwards EnterpriseOne, Solaris, and more.
SourceNorth Korean APT37/ScarCruft spreads Python RAT via phishing emails with fake Microsoft alerts. Capable of keystroke logging, screenshot capture, data exfiltration.
SourceOperation FlutterBridge — malvertising campaign delivering Flutter-based backdoor that passed Apple notarization.
SourceBYOVD attacks disabling 300+ EDR drivers before deploying ransomware. Multi-stage attack chains.
SourceSelf-propagating npm worm abusing native-addon build hooks via binding.gyp to steal CI/CD secrets and persist in GitHub.
SourceRussian-speaking cybercriminal group harvested credentials from ~74,000 Fortinet FortiGate devices across 194 countries. Admin credentials being sold on criminal forums. Fortinet confirmed the credential harvesting campaign.
Read moreKodak confirmed data breach after ShinyHunters claimed theft of 2.2M records of customer PII and internal corporate data.
Read moreShinyHunters published 45 GB of MSG Sports data including VIP profiles, customer emails, and internal risk assessments.
Read moreCISA added SolarWinds Serv-U DoS vulnerability to KEV with mandatory federal remediation deadline of June 19, 2026.
Read moreRecord-setting Patch Tuesday with 206+ CVEs including 38 Critical. CVSS 10.0 Azure HorizonDB vulnerability.
Read moreLargest Oracle CPU of 2026 with 245 security updates across Oracle product families.
Read moreEmergency security releases across all active release lines addressing vulnerabilities in llhttp and nghttp2 dependencies.
Read moreOS Command Injection allowing unauthenticated remote code execution. Actively exploited.
SourceAuthentication Bypass allowing remote creation of arbitrary admin accounts.
SourceAuthentication Bypass exploited by Qilin ransomware to compromise VPN deployments.
SourceImproper Input Validation allowing arbitrary code execution with no user interaction.
SourceRemote Code Execution on Backup Server by authenticated domain user.
SourceUnauthenticated remote code execution allowing full server compromise.
SourcePrivilege escalation via symlink following. Added to CISA KEV.
SourceImproper access control allowing PHP code execution by unauthenticated users.
SourceOn June 17, @mastra npm org was compromised via typosquatted 'easy-day-js' dependency, delivering cross-platform RAT to 140+ packages.
SourceShinyHunters claimed 2.2M+ records from Kodak. Deadline expired June 18. Kodak confirmed breach.
SourceQilin affiliates exploiting CVE-2026-50751 Check Point VPN auth bypass to gain initial access.
SourceEastman Kodak confirmed data breach involving 2.2M+ records as ShinyHunters extortion deadline expired.
Read more37 critical, 3 zero-days patched across Windows, Office, Defender, and Edge.
Read moreLiteSpeed cPanel and Joomla JCE vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog.
Read moreA single hijacked maintainer account backdoored the entire @mastra npm scope with cross-platform RAT malware.
Read moreTwo pre-auth CVEs (CVE-2026-10520, CVE-2026-10523) in Ivanti Sentry under active exploitation with CISA KEV addition.
Read more16 new security patches for Oracle Enterprise Manager, 6 remotely exploitable.
Read moreJune 2026 Android security update includes patch for actively exploited zero-day alongside 123 other fixes.
Read moreAuthentication bypass vulnerability in deprecated IKEv1 VPN protocol, actively exploited by Qilin ransomware affiliates. Check Point released urgent hotfix.
SourceOS Command Injection vulnerability allows remote unauthenticated attackers to execute arbitrary commands. Affects versions before R10.5.2, R10.6.2, R10.7.1.
SourceAuthentication bypass vulnerability in Ivanti Sentry allowing remote attackers to bypass security controls.
SourceUnauthenticated SSRF-to-RCE zero-day vulnerability exploited by ShinyHunters to breach 100+ universities and the Council of Europe. Oracle out-of-band alert on June 10.
SourceUse-after-free vulnerability allowing unauthenticated remote code execution over a network. Wormable class flaw, part of June 2026 Patch Tuesday.
SourceAuthorization plugin (AuthZ) bypass via oversized API request bodies allowing attackers to silently disable security policies. Patched in Moby 29.3.1.
SourceNorth Korean APT37 (ScarCruft) delivers Python RAT via fake Microsoft Account alert spear-phishing emails with ZIP attachments. Multi-stage infection chain targets data theft.
SourceQilin affiliates actively exploiting CVE-2026-50751 authentication bypass in Check Point VPN deployments for initial access. Post-compromise lateral movement confirmed.
SourceAbuses NTFS junctions to create recursive directory loops, causing Windows Defender and EDR scanners to hang indefinitely, leaving malware undetected.
SourceExploiting CVE-2026-35273 (PeopleSoft zero-day) at scale. Breached 100+ universities (450K+ student records) and Council of Europe (297 GB data including payroll).
SourceMicrosoft released 206 patches including 39 Critical, 3 zero-days, and a wormable Windows Kernel RCE (CVE-2026-45657, CVSS 9.8). Combined with Adobe (123 CVEs) and Chrome, over 500 CVEs for the month.
Read morePharmaceutical giant (Ozempic maker) disclosed cyberattack on June 11. Hackers breached internal IT systems and stole pseudonymized clinical trial patient data.
Read moreCardiac monitoring device maker hit on June 9. Threat actors obtained patient data and proprietary information, issued ransom demand. No impact on device safety.
Read moreShinyHunters claims 297 GB data theft including payroll and employee personal information via CVE-2026-35273. Council investigating.
Read moreNode.js released HIGH severity security updates for 26.x, 24.x, and 22.x release lines. Specific CVEs pending publication. Immediate upgrade recommended.
Read moreDutch authorities dismantled massive botnet of 17 million infected devices, seizing 200+ servers at a local hosting provider.
Read moreOS Command Injection allowing remote unauthenticated root-level RCE. Affects Ivanti Sentry before R10.5.2, R10.6.2, R10.7.1.
SourceUse-after-free RCE vulnerability. Part of Microsoft June 2026 Patch Tuesday. Actively exploited as zero-day.
SourceStack-based buffer overflow allowing remote code execution. Part of Microsoft June 2026 Patch Tuesday.
SourceBuffer overflow in error message handling. Attackers who can influence error text can trigger overflow. Affects all Perl DB applications.
SourceUnauthenticated RCE over HTTP. Actively exploited by ShinyHunters as zero-day before Oracle's June 10 patch.
SourceUnauthenticated arbitrary file creation and truncation leading to RCE. Affects versions below 10.2.4 and 10.0.7.
SourceImproper input validation allowing arbitrary code execution with no user interaction. Part of APSB26-64.
SourceAuthentication bypass vulnerability under active exploitation by Qilin ransomware affiliates since early May 2026.
SourceCompromised 32+ @redhat-cloud-services npm packages. Preinstall hook steals cloud credentials, persists in dev tooling, spreads via dependency confusion.
SourceExploiting Oracle PeopleSoft zero-day (CVE-2026-35273) to breach university systems, exfiltrate data, and demand extortion payments.
SourceExploiting CVE-2026-50751 (Check Point VPN auth bypass) for initial access to corporate networks.
SourceNew ransomware strain discovered by CYFIRMA on underground forums.
SourceRansomware attack on logistics company with data leak threats.
SourceDeploying BSD variant of BRICKSTORM backdoor plus PLENET/GRIMBOLT and AGENTPSD malware.
SourceMicrosoft patched a record 206 vulnerabilities across Windows, Office, and other products, including 3 actively exploited zero-days (CVE-2026-45657 Windows Kernel RCE, 2 Microsoft Defender flaws).
Read moreCVE-2026-35273 (CVSS 9.8) actively exploited before Oracle's June 10, 2026 advisory. Multiple universities breached and extorted.
Read moreCVE-2026-50751 (IKEv1 auth bypass) exploited since early May. Qilin ransomware affiliates linked to attacks against corporate VPNs.
Read moreCredential-stealing worm compromised official @redhat-cloud-services npm packages. Affects CI/CD pipelines and cloud credential security.
Read moreUnauthenticated arbitrary file operations enabling RCE. Patched in Splunk Enterprise versions 10.2.4 and 10.0.7.
Read moreIncludes 6 critical severity flaws in Android 14, 15, and 16 covering system components, Framework, and kernel.
Read moreAPSB26-64 (ColdFusion) and APSB26-66 (Campaign Classic) address multiple critical RCE vulnerabilities. CVE-2026-47928 (CVSS 9.6) tops the list.
Read moreCVE-2026-10520 allows remote unauthenticated attackers to execute OS commands as root on Ivanti Sentry appliances.
Read moreUse-after-free vulnerability enabling remote code execution over the network. Zero-day patched in June 2026 Patch Tuesday.
SourceInteger overflow/wraparound in HTTP.sys kernel-mode driver. Unauthenticated RCE via crafted HTTP requests.
SourceStack-based buffer overflow in DHCP Client. Attacker on same network triggers code execution via malicious DHCP response.
SourceHeap-based buffer overflow in TCP/IP stack. Adjacent network attacker elevates privileges via crafted packets.
SourceOS command injection vulnerability allowing remote unauthenticated attackers to achieve root-level RCE. Added to CISA KEV June 11.
SourceAuthentication bypass vulnerability in deprecated IKEv1 VPN protocol. Under active exploitation. CISA KEV June 8.
SourceTampering vulnerability in Windows DHCP Server enabling man-in-the-middle attacks.
SourceAuthorization plugin (AuthZ) bypass. Single oversized HTTP request disables all authorization plugins. Affects 92% of enterprise deployments. Fixed in 29.3.1.
SourceHeap-based buffer overflow RCE in Remote Desktop Client. Unauthenticated attacker executes code over network.
SourceNew file-encrypting ransomware appending .lalia extension. Deletes Volume Shadow Copies to prevent recovery. Includes anti-analysis checks for sandbox/VMs.
SourceMulti-stage malware employing batch/PowerShell scripts, living-off-the-land techniques, obfuscation, and anti-analysis.
SourceIranian state-sponsored APT group active on networks of multiple US companies since February 2026.
SourcePakistan-aligned cyber espionage group deploying customized XenoRAT variant targeting Afghan government entities.
SourceVoice phishing (vishing) campaigns compromising DentaQuest (2.6M), Instructure/Canvas (30M+), Charter (40M), and Carnival.
SourceNew macOS malvertising campaign discovered by Unit 42 spreading malware via fake browser updates.
SourceFake open-source project sites (Ghidra, dnSpy) used as lure in click-hijacking scheme delivering multiple malware families.
Source32 critical vulnerabilities including 28 RCE flaws, three zero-days. Critical kernel RCE (CVE-2026-45657), HTTP.sys, DHCP Client, and TCP/IP flaws all network-exploitable.
Read moreNew national security memorandum rescinds Biden-era instruction, focuses on cloud-based environment security requirements.
Read moreNew directive requires federal agencies to prioritize vulnerabilities based on risk rather than severity alone.
Read moreFY2027 DHS budget bill reduces CISA funding to $2.35B. Also seeks guidance on agentic AI security and SBOM opportunities.
Read moreExploit Prediction Scoring System version 5 launches June 15, 2026 with significant improvements in predicting vulnerability exploitation likelihood.
Read moreNew guidance helps organizations prepare for, respond to, and recover from ransomware attacks under the Cybersecurity Framework.
Read moreShinyHunters leaked exfiltrated data including names, emails, government IDs, and health insurance information from the dental benefits provider.
Read moreAttackers brute-forced two-factor authentication codes to register unauthorized devices and download encrypted password vaults.
Read moreUnauthorized access to Gaza self-registration app exposed names, ID numbers, mobile numbers, and location data.
Read moreIncludes DOGE Social Security data exposure (potentially largest in US history), Iranian attacks on Stryker, FBI surveillance system breach, and European critical infrastructure attacks.
Read moreIncludes one actively exploited zero-day (CVE-2025-48595) affecting Android 14+. Framework vulnerability enables local code execution and privilege escalation.
Read moreUnauthenticated file write vulnerability leading to root compromise. Requires WebDialer enabled. Public PoC published.
Read moreDenial of Service (DoS) via VersionedResourceResolver. Spring MVC and WebFlux applications vulnerable to DoS when resolving static resources with crafted versioned resource requests. Affects Spring Framework 5.3.0-5.3.48, 6.1.0-6.1.27, 6.2.0-6.2.18, 7.0.0-7.0.7.
SourcePath Traversal via VersionedResourceResolver. Spring MVC and WebFlux applications vulnerable to path traversal attacks when resolving static resources. Same affected versions as CVE-2026-41842.
SourceInformation Disclosure via Static Resource Cache. Spring MVC and WebFlux applications vulnerable to information disclosure when resolving static resources. Same affected versions.
SourceInformation Disclosure via Java scripting engine (JRuby, Jython) template views in Spring MVC and Spring WebFlux applications.
SourceThree Spring Framework vulnerabilities were disclosed on June 8 (CVE-2026-41841, CVE-2026-41842, CVE-2026-41843) affecting static resource handling in Spring MVC and WebFlux. Combined with CVE-2026-22737 (March 2026, Java scripting engine info disclosure), this is a significant batch for one of the most widely used Java frameworks. Spring Boot applications using embedded Tomcat, Jetty, or Undertow are affected. Upgrade to Spring Framework 5.3.49+, 6.1.28+, 6.2.19+, or 7.0.8+.
Read moreHigh severity DoS vulnerability. An attacker can send crafted requests to trigger expensive resource resolution, potentially exhausting server resources. No authentication required. Affects all Spring MVC and WebFlux applications using VersionResourceResolver with static resources.
Read moreMedium severity path traversal. An attacker can read arbitrary files from the server by crafting versioned resource requests. Requires some knowledge of the application structure.
Read more