// 3 CRITICAL · 6 ZERO-DAY · 11 CVE · 7 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSECCRITICAL

Splunk Enterprise PostgreSQL Sidecar Bug (CVSS 9.8) Enables Unauthenticated RCE

CVE-2026-20253 allows unauthenticated remote code execution on Splunk Enterprise. The web proxy on port 8000 exposes an internal Postg…

Jun 18, 2026views - 971

ransomwareZERO-DAY

INC Ransomware: 800 Victims, Not a Single Zero-Day

INC ranks among the world's most active ransomware groups despite relying exclusively on known techniques. The Acronis report reveals…

Jun 17, 2026views - 775

malware

Rust Crypto Clipper Campaign Weaponizes Fake Reputation on VirusTotal and GitHub

A threat actor distributed a Rust-based crypto clipper for Windows and macOS by fabricating trust signals across GitHub, SourceForge,…

Jun 17, 2026views - 674

ai

AI Agents Used to Breach 14 Companies: Over 1,000 Sessions Recovered

A low-skill attacker leveraged local Claude and Codex agents to compromise at least 14 organizations, bypassing guardrails through nar…

Jun 17, 2026views - 855

CYBERSEC

MySQL Exposed at 26%: The 2026 Top 10 Attack Surface Exposures

Intruder's 2026 ASM Index reveals exposed databases and admin panels as primary vectors. Time-to-exploit has collapsed to a single day…

Jun 17, 2026views - 1.2k

VULNCRITICAL

CISA Adds Joomla JCE to KEV: Pre-Auth RCE, CVSS 10.0

CISA added CVE-2026-48907 to the Known Exploited Vulnerabilities catalog on June 16, 2026, confirming active exploitation of a pre-aut…

Jun 17, 2026views - 1.2k

newsZERO-DAY

RoguePlanet: Unpatched Zero-Day in Microsoft Defender Enables SYSTEM Escalation

RoguePlanet is a zero-day vulnerability in Microsoft Defender with no CVE assigned and no patch available as of June 17, 2026. It allo…

Jun 17, 2026views - 859

news

The Gentlemen: How LLMs and Automation Are Reshaping Ransomware

CERT-AGID maps The Gentlemen's use of LLMs: 500 victims in under a year, negotiation platform built in three days, self-replicating wo…

Jun 17, 2026views - 1.1k

CYBERSEC

Malicious JetBrains Plugins Steal AI API Keys: 70,000 Downloads

A coordinated campaign of 15 malicious plugins on the JetBrains Marketplace exfiltrates AI API keys from developers' IDEs. Roughly 70,…

Jun 17, 2026views - 872

CYBERSECCRITICAL

FortiSandbox: Three Critical Vulnerabilities Under Active Exploitation, Defused Cyber Says

Threat intelligence firm Defused Cyber observed active exploitation of three critical pre-authentication flaws in Fortinet FortiSandbo…

Jun 16, 2026views - 1k

malware

Rokarolla: The Android Trojan That Turns Your Phone Into a Digital Prison

Discovered by Zimperium zLabs, the Rokarolla trojan deploys 137 commands and fake overlays to isolate victims, steal banking credentia…

Jun 16, 2026views - 1.3k

malware

Lorem Ipsum Pivots to ClickFix After Fox Tempest Takedown

BlueVoyant reports the Lorem Ipsum malware abandoned signed Microsoft Teams installers for ClickFix tactics on compromised WordPress s…

Jun 16, 2026views - 800

CYBERSEC

GhostTree: The NTFS Attack That Freezes EDR

Varonis Threat Labs disclosed GhostTree, an evasion technique that neutralizes Windows Defender using recursive NTFS junctions — no el…

Jun 16, 2026views - 968

VULNCRITICAL

Vertex AI SDK: Cross-Tenant Bucket Squatting Enabled RCE

Google Cloud Vertex AI SDK versions 1.139.0 through 1.140.0 were vulnerable to cross-tenant bucket squatting leading to remote code ex…

Jun 16, 2026views - 924

malware

DragonForce Weaponizes Microsoft Teams TURN Relays for Stealth C2

The DragonForce ransomware group deployed Backdoor.Turn, the first documented in-the-wild malware to abuse Microsoft Teams' legitimate…

Jun 16, 2026views - 838

CYBERSECCVE

Cisco SD-WAN, CVE-2026-20262: Internal Discovery, External Exploitation

Cisco disclosed CVE-2026-20262, a path traversal vulnerability in Catalyst SD-WAN Manager actively exploited in the wild. It requires…

Jun 16, 2026views - 771

malware

SprySOCKS Returns to Windows: Kernel Rootkit and Government Targeting

ESET discovered Windows variants of the SprySOCKS backdoor—previously Linux-only—equipped with a kernel rootkit and used against gover…

Jun 16, 2026views - 955

news

Malware on Steam Workshop: Animated Wallpapers Steal Credentials

Dozens of malicious wallpapers on Steam Workshop have infected thousands of users, delivering backdoors, Steam account theft, and hidd…

Jun 16, 2026views - 1.2k

CYBERSEC

iRhythm: Patient Health Data Stolen via Social Engineering

iRhythm Holdings disclosed a data breach in which attackers exfiltrated PHI and PII from third-party business applications through soc…

Jun 16, 2026views - 883

VULNEXPLOIT

LiteSpeed cPanel: Two CVEs Added to KEV Catalog, Shared Hosting at Risk

CISA adds two distinct LiteSpeed cPanel plugin flaws to its Known Exploited Vulnerabilities catalog: root privilege escalation on shar…

Jun 16, 2026views - 884

news

North Korea Targets Developers: When the IDE Becomes the Attack Surface

North Korean state actors abused VS Code, npm, GitHub, and Hugging Face to distribute malware to developers. The UNK_DeadDrop campaign…

Jun 15, 2026views - 1.2k

ransomware

Conti Developer Sentenced: Why Loaders Are the RaaS Achilles' Heel

Ukrainian Conti ransomware developer Oleksii Lytvynenko pleaded guilty in U.S. federal court after extradition from Ireland. The case…

Jun 15, 2026views - 925

CYBERSEC

Chinese APT UNC6508: A Year of Espionage on REDCap Servers

Google exposes UNC6508: over a year of REDCap server compromise at U.S. and Canadian medical and military institutions using InfiniteR…

Jun 15, 2026views - 769

ai

Anthropic Disables Fable 5 and Mythos 5 on US Directive Restricting Foreign Access

On June 12, 2026, at 5:21 p.m. ET, Anthropic received a US government directive ordering the immediate suspension of all access to Fab…

Jun 15, 2026views - 1.7k