Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

Citrix Patches Six NetScaler Flaws: The Trap Is Manual
Citrix released patches on June 30, 2026 for six vulnerabilities in NetScaler ADC and NetScaler Gateway, including a new CitrixBleed i…

Phantom Squatting: When AI Generates Your Next Supply-Chain Threat
Unit 42 documents a novel attack vector: adversaries proactively register domains hallucinated by LLMs to intercept traffic from AI-in…

Langflow RCE Exploited for Miner Worm: 19-Day Campaign
CVE-2026-33017: Commodity operators exploit exposed AI endpoints to deploy Lambsys, an SSH worm that compromises entire enterprise inf…

Aflac Japan Confirms 4.38 Million Records Breached; U.S. Systems Unaffected
Aflac Life Insurance Japan Ltd. disclosed a ten-day intrusion from June 15–25, 2026, affecting 4.38 million customers and agents and e…

CISA Confirms: BlueHammer Now Exploited by Ransomware
CISA has elevated CVE-2026-33825 to a confirmed ransomware vector. Microsoft has not updated its advisory, creating an intelligence ga…

Mustang Panda Turns Zoho WorkDrive Into Covert C2 Channel Against Indian Government
The Mustang Panda APT group ran two espionage campaigns in June 2026 targeting the Indian government and hydroelectric infrastructure,…

CVE-2026-46817: Oracle EBS Under Attack, 450+ Servers Exposed
Defused detects active exploitation of CVE-2026-46817 on Oracle EBS honeypots. CVSS 9.8, patch available since May, over 450 instances…

Gamaredon 2025: 35 Spear-Phishing Campaigns and 6 PowerShell Tools Target Ukraine
The Gamaredon APT group, attributed by Ukraine's SSU to the FSB's 18th Center for Information Security, launched 35 distinct spear-phi…

Microsoft Removes 119 Edge Extensions Hiding Malware in Images and Fonts
Microsoft purged 119 Edge extensions that concealed StegoAd malware inside PNG, WebP, and WOFF2 font files, reaching a combined instal…

Public PoC for CVE-2026-55200: libssh2 at Risk of RCE
A working proof-of-concept for CVE-2026-55200, a critical CVSS 9.2 vulnerability in libssh2, was released on June 23, 2026. The pre-au…

DarkMoon: Open-Source AI Pentesting at $10 a Scan — and the Hard Limit of Vendor LLM Classifiers
DarkMoon separates LLM reasoning from execution via MCP to bypass Anthropic's safety classifiers. At roughly $10 per web-app scan, the…

OpenClaw: 5 Malicious Skills Evade AI Scanners for Months
Unit 42 reveals evasive skills on ClawHub exploiting semantic instruction hijacking. 80% of 49,943 skills analyzed show behavioral dev…