// 1 CRITICAL · 11 ZERO-DAY · 9 CVE · 10 EXPLOIT IN THE LAST 24H
CYBERSEC

Klue Breach: Dormant OAuth Credential Opens Multi-Victim Door to Salesforce

The Icarus extortion group exfiltrated CRM data from Klue customers by abusing stolen OAuth tokens. Cybersecurity vendor Huntress conf…

Jun 18, 2026views - 1.1k

CYBERSEC

Apple Beats: Bluetooth Flaw Turns Headphones Into Spy Microphones

Apple patched CVE-2025-20701 in Beats Studio Buds: attackers within Bluetooth range could eavesdrop on conversations by exploiting a f…

Jun 18, 2026views - 933

CYBERSEC

Kodak Confirms Breach: ShinyHunters Threatens 2.2 Million Records

Kodak confirms a data breach after the ShinyHunters extortion group claimed theft of over 2.2 million records and threatened publicati…

Jun 18, 2026views - 834

CYBERSECCRITICAL

Splunk Enterprise PostgreSQL Sidecar Bug (CVSS 9.8) Enables Unauthenticated RCE

CVE-2026-20253 allows unauthenticated remote code execution on Splunk Enterprise. The web proxy on port 8000 exposes an internal Postg…

Jun 18, 2026views - 995

CYBERSEC

MySQL Exposed at 26%: The 2026 Top 10 Attack Surface Exposures

Intruder's 2026 ASM Index reveals exposed databases and admin panels as primary vectors. Time-to-exploit has collapsed to a single day…

Jun 17, 2026views - 1.3k

CYBERSEC

Malicious JetBrains Plugins Steal AI API Keys: 70,000 Downloads

A coordinated campaign of 15 malicious plugins on the JetBrains Marketplace exfiltrates AI API keys from developers' IDEs. Roughly 70,…

Jun 17, 2026views - 906

CYBERSECCRITICAL

FortiSandbox: Three Critical Vulnerabilities Under Active Exploitation, Defused Cyber Says

Threat intelligence firm Defused Cyber observed active exploitation of three critical pre-authentication flaws in Fortinet FortiSandbo…

Jun 16, 2026views - 1.1k

CYBERSEC

GhostTree: The NTFS Attack That Freezes EDR

Varonis Threat Labs disclosed GhostTree, an evasion technique that neutralizes Windows Defender using recursive NTFS junctions — no el…

Jun 16, 2026views - 991

CYBERSECCVE

Cisco SD-WAN, CVE-2026-20262: Internal Discovery, External Exploitation

Cisco disclosed CVE-2026-20262, a path traversal vulnerability in Catalyst SD-WAN Manager actively exploited in the wild. It requires…

Jun 16, 2026views - 797

CYBERSEC

iRhythm: Patient Health Data Stolen via Social Engineering

iRhythm Holdings disclosed a data breach in which attackers exfiltrated PHI and PII from third-party business applications through soc…

Jun 16, 2026views - 912

CYBERSEC

Chinese APT UNC6508: A Year of Espionage on REDCap Servers

Google exposes UNC6508: over a year of REDCap server compromise at U.S. and Canadian medical and military institutions using InfiniteR…

Jun 15, 2026views - 794

CYBERSEC

Infinite Campus: 137,123 Staff Emails Exposed in Salesforce Breach

ShinyHunters compromised an Infinite Campus employee's Salesforce account on March 18, 2026. After a failed extortion attempt, 137,123…

Jun 15, 2026views - 1.5k