A critical pre-authentication remote code execution vulnerability in vBulletin forum software has been patched following the public release of an exploit, enabling unauthenticated attackers to execute arbitrary PHP code.
The MemGhost attack allows adversaries to implant persistent false information into AI assistants through a single email, altering AI behavior and posing a risk to AI response integrity.
Datadog Security Labs warns of campaigns using dormant GitHub accounts and compromised OAuth tokens to scrape corporate GitHub organizations and user data through the GitHub API. Attackers automate scraping with custom or legitimate-sounding user agents to blend in and avoid detection.
OpenPLC v3 contains a critical authenticated arbitrary file write vulnerability that can lead to native code execution through compiling malicious files. This affects critical infrastructure sectors worldwide and requires urgent mitigation.
A threat actor known as O-UNC-066 is using a phishing kit to exploit Microsoft 365 users via fake Entra passkey enrollment requests, aiming at data extortion. This tactic spans multiple industry sectors and involves voice-based social engineering.
Hackers compromised the Injective Labs SDK GitHub repository to publish a malicious npm package that steals cryptocurrency wallet private keys and seed phrases. This malware poses a direct threat to developers and users managing crypto assets.
Microsoft has analyzed a new Windows backdoor called GigaWiper that merges three destructive tools: full disk wiping, Windows drive overwriting, and fake ransomware that scrambles files without saving keys. This modular malware gives operators multiple ways to disrupt or destroy infected machines.
GitHub released npm version 12 with install scripts disabled by default and deprecated granular access tokens used to bypass 2FA. These changes reduce the risk of supply chain attacks for developers and security teams.
Researchers tested 281 popular free Android VPN apps and discovered many leak user traffic, transmit unencrypted data, and include tracking. These apps, collectively installed over 2.4 billion times, fail to meet basic privacy and security standards.
A China-linked threat actor is exploiting a vulnerability in Roundcube webmail servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. This campaign specifically targets academic researchers to gather intelligence.
The Chinese APT actor UAT-7810 is enhancing its ORB network via a new LONGLEASH malware targeting internet-facing networking devices, according to Cisco Talos. This campaign builds on the previously identified LapDogs ORB infrastructure active since mid-2025.
Japanese telecom giant KDDI suffered a data breach affecting over 12 million people, with attackers accessing email addresses and passwords through a compromised platform used by multiple ISPs. The breach highlights significant risks in telecom infrastructure security.
A new EvilTokens campaign uses ghost phishing to bypass traditional email security by hiding malicious pages until decrypted inside a victim’s browser. This poses high risk to businesses using Microsoft 365 and handling sensitive data.
Ubiquiti released updates to fix critical vulnerabilities in UniFi Connect, Talk, Access, Protect, and OS. These flaws could allow privilege escalation and arbitrary command execution.
A critical use-after-free flaw in Linux's KVM hypervisor allows guest VMs on Intel and AMD systems to corrupt host kernel memory, potentially escaping the virtual environment. The vulnerability, known as Januscape (CVE-2026-53359), includes a public PoC that crashes hosts with a more impactful exploit reportedly in development.
A China-nexus threat group is targeting Indian taxpayers and finance teams with spear-phishing emails impersonating the Income Tax Department to deploy DcRAT, a remote access trojan. This multi-stage campaign aims to steal sensitive data from compromised systems.
Threat actors are impersonating IT support via Microsoft Teams voice calls to trick employees into installing EtherRAT malware, compromising corporate networks. This tactic enables attackers to gain initial access and conduct further intrusion.
An Iran-linked hacker group associated with MOIS has started using a new modular command-and-control framework called Cavern to target Israeli IT providers and government organizations. This activity has been tracked by Check Point Research and highlights evolving state-sponsored cyber threats.
Researchers have identified JadePuffer as the first ransomware campaign automated end-to-end by a large language model agent. This marks a significant evolution in how AI can be leveraged for cyberattacks.
A critical Adobe ColdFusion vulnerability, CVE-2026-48282, is now being actively exploited in cyberattacks, according to KEVIntel. This flaw demands immediate attention due to its maximum severity rating.
North Korean hackers linked to the Contagious Interview campaign have published 108 malicious packages and browser extensions across multiple platforms as part of their ongoing PolinRider operation. These malicious artifacts are being actively distributed via compromised maintainer accounts on npm, Packagist, Go, and Chrome Web Store.
Security firm runZero disclosed seven vulnerabilities in FatFs, a widely used filesystem library in embedded devices including security cameras and drones. These flaws pose a risk due to FatFs's ubiquity in consumer and industrial firmware.
Attackers have started exploiting a critical CVE-2026-46817 vulnerability in the Oracle E-Business Suite financial application, as reported by Defused. This flaw poses significant risk to enterprises using Oracle EBS.
Hackers are actively exploiting a critical vulnerability in SimpleHelp (CVE-2026-48558) to distribute Djinn Stealer, a new cross-platform information stealer targeting Windows, macOS, and Linux. This campaign represents a novel threat leveraging an undocumented malware strain.
Japanese ISP KDDI Corporation disclosed a data breach compromising up to 14.2 million email logins from one of its systems shared with five other ISPs. Threat actors gained unauthorized access, impacting multiple large providers.
The FBI and CISA warn of a phishing campaign by Russian intelligence targeting Signal users to steal backup recovery keys, giving attackers access to historical messages. This represents a significant escalation in targeting secure communications.
Ukraine and the FBI uncovered a Russian intelligence campaign targeting messaging accounts of officials and activists across Ukraine, Europe, and the U.S. The operation involved fake support texts aimed at stealing sensitive credentials.
CISA has issued a warning about an actively exploited critical code injection vulnerability, CVE-2025-67038, affecting Lantronix EDS5000 Series devices. Federal agencies are urged to apply patches by June 26, 2026, to prevent potential remote code execution.
CISA has issued a warning about hackers actively exploiting severe vulnerabilities in Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers. These flaws carry a maximum severity rating and pose significant risk to affected organizations.
Mandiant has exposed how attackers exploited a zero-day CVE-2026-20245 in Cisco Catalyst SD-WAN to create rogue root accounts on devices, raising serious security concerns. This vulnerability enables full control of targeted network appliances, potentially impacting enterprise operations.
A high-severity Server-Side Request Forgery vulnerability in Cisco Unified Communications Manager Server, tracked as CVE-2026-20230, is actively being exploited in the wild. Security teams should prioritize detection and mitigation to prevent potential compromise.
Tata Electronics has confirmed a cyberattack impacting parts of its IT infrastructure, with hackers leaking some data. The incident highlights the ongoing risks to enterprise security from targeted attacks.
Microsoft Security Blog discusses the implications when threat actors attempt to manipulate what AI systems remember and the emerging defenses against these attacks. Understanding these risks is crucial for securing AI-driven technologies.
Microsoft has attributed the recent Mastra AI supply chain attack, compromising over 140 npm packages, to the North Korean group Sapphire Sleet, aka BlueNoroff. This highlights ongoing state-sponsored supply chain risks affecting open source ecosystems.
Attackers compromised ShapedPlugin's build pipeline to inject backdoor code into Pro plugins via official update channels. This supply chain attack puts thousands of WordPress sites at risk of remote exploitation.