Vulnerabilities
Curated coverage and analysis in this editorial area.

Citrix Patches Six NetScaler Flaws: The Trap Is Manual
Citrix released patches on June 30, 2026 for six vulnerabilities in NetScaler ADC and NetScaler Gateway, including a new CitrixBleed i…

Agentjacking: Fake Bug Report Hijacks AI Coding Agents, 85% Success Rate
Tenet Security researchers demonstrated on June 12, 2026 that a poisoned Sentry error report can hijack Claude Code, Cursor, and Codex…

BioShocking: How a Game Tricks Agentic AI into Stealing Credentials
LayerX researchers demonstrated BioShocking, a prompt injection attack that manipulates agentic AI browsers into exfiltrating sensitiv…

Langflow RCE Exploited for Miner Worm: 19-Day Campaign
CVE-2026-33017: Commodity operators exploit exposed AI endpoints to deploy Lambsys, an SSH worm that compromises entire enterprise inf…

Aflac Japan Confirms 4.38 Million Records Breached; U.S. Systems Unaffected
Aflac Life Insurance Japan Ltd. disclosed a ten-day intrusion from June 15–25, 2026, affecting 4.38 million customers and agents and e…

Nissan Payroll Breach via Oracle PeopleSoft Zero-Day CVE-2026-35273
Nissan Americas confirmed a breach exposing employee payroll data and Social Security numbers across four countries through CVE-2026-3…

CVE-2026-48558: Djinn Stealer Exploited In-the-Wild on SimpleHelp
Threat actors exploit CVE-2026-48558 to deploy Djinn Stealer and TaskWeaver. The new infostealer targets AI and cloud credentials. Rou…

Public PoC for CVE-2026-55200: libssh2 at Risk of RCE
A working proof-of-concept for CVE-2026-55200, a critical CVSS 9.2 vulnerability in libssh2, was released on June 23, 2026. The pre-au…

Claude Code Tricked: Clean Repo Opens Reverse Shell
Mozilla 0DIN demonstrates that Claude Code executes malware from clean GitHub repositories by exploiting its own proactivity: a fabric…

KDDI Breach Exposes 14.2 Million Credentials Across Six Japanese ISPs
KDDI Corporation disclosed unauthorized access to a shared email platform serving six Japanese telecom operators on June 17, 2026. The…

ATEN Unizon: Authenticated Bug Deletes Files, CVSS 5.5 Understates Risk
Directory traversal in ATEN Unizon's uploadSSL lets an authenticated attacker delete arbitrary files. The CVSS 5.5 rating masks real o…

ZDI-26-397: Use-After-Free in X.Org Server Opens Door to Local Privilege Escalation
A Use-After-Free flaw in X.Org Server's CreateSaverWindow function (CVE-2026-50263) lets a local low-privilege attacker leak sensitive…