SecurityTicks

LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271)

LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271) 2026-06-09 at 15:21 By Zeljka Zorz A command injection vulnerability (CVE-2026-42271) in BerryAI’s LiteLLM open-source AI gateway is being exploited by attackers, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed by adding the flaw to its Known Exploited Vulnerabilities catalog on Monday. About CVE-2026-42271 LiteLLM is […]

LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271) Read More »

Apple Intelligence can now replace weak passwords without user intervention

Apple Intelligence can now replace weak passwords without user intervention 2026-06-09 at 15:21 By Anamarija Pogorelec Apple’s next generation of Apple Intelligence, the company’s personal intelligence system, expands its capabilities and introduces new security features in Passwords. Automatically Fix Passwords (Source: Apple) Introduced as a standalone app in 2024, Passwords gives users a central place […]

Apple Intelligence can now replace weak passwords without user intervention Read More »

Google patches Chrome zero-day exploited in the wild (CVE-2026-11645)

Google patches Chrome zero-day exploited in the wild (CVE-2026-11645) 2026-06-09 at 15:21 By Sinisa Markovic Google has fixed 74 vulnerabilities in Chrome, including a high-severity zero-day (CVE-2026-11645) that has been exploited in the wild. “Google is aware that an exploit for CVE-2026-11645 exists in the wild,” the company said in a Monday security advisory. The […]

Google patches Chrome zero-day exploited in the wild (CVE-2026-11645) Read More »

Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks

Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks 2026-06-09 at 15:21 By Ionut Arghire The most recent variants of the self-propagating attacks are named Miasma and Hades. The post Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks appeared first on SecurityWeek. This article is an excerpt from […]

Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks Read More »

SAP Patches Critical NetWeaver, Commerce Vulnerabilities

SAP Patches Critical NetWeaver, Commerce Vulnerabilities 2026-06-09 at 15:21 By Ionut Arghire The flaws could lead to the disclosure of sensitive information, memory corruption, and disruption of normal system usage. The post SAP Patches Critical NetWeaver, Commerce Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SAP Patches Critical NetWeaver, Commerce Vulnerabilities Read More »

The Hidden Security Risk in Modern Networks: The Work Between Tools

The Hidden Security Risk in Modern Networks: The Work Between Tools 2026-06-09 at 15:21 By Organizations have more visibility than ever. Growing tech stacks provide greater coverage, and network security teams are increasingly adopting AI and automation to help with routine tasks and reduce manual effort. But the same challenges persist. Outages still last hours, […]

The Hidden Security Risk in Modern Networks: The Work Between Tools Read More »

Will AI Kill the Bug Bounty Industry?

Will AI Kill the Bug Bounty Industry? 2026-06-09 at 14:00 By Kevin Townsend Anthropic’s Mythos is accelerating vulnerability discovery to machine speed, forcing the bug bounty industry and offensive security teams to adapt to a future where finding flaws is no longer the hard part. The post Will AI Kill the Bug Bounty Industry? appeared […]

Will AI Kill the Bug Bounty Industry? Read More »

New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing

New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing 2026-06-09 at 14:00 By A malicious website can work out which sites you visit and which apps you open, using nothing but JavaScript and the timing of your SSD. The attack, called FROST, needs no native code, no extension, and […]

New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing Read More »

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer 2026-06-09 at 14:00 By The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the Python Package Index (PyPI) registry, as the Mini Shai-Hulud-style attacks continue to be refined and […]

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer Read More »

Mythos Preview can weaponize N-day vulnerabilities in hours

Mythos Preview can weaponize N-day vulnerabilities in hours 2026-06-09 at 13:39 By Sinisa Markovic Mythos Preview can develop working exploits from newly disclosed software vulnerabilities in hours, cutting down a process that has historically taken days or weeks, according to Anthropic. Anthropic’s recent cybersecurity research has largely focused on zero-days, vulnerabilities unknown to software vendors. […]

Mythos Preview can weaponize N-day vulnerabilities in hours Read More »

Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks

Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks 2026-06-09 at 13:39 By Ionut Arghire The authentication bypass vulnerability allows attackers to establish VPN connections without a valid password. The post Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks Read More »

Bitcoin rebound highlights discount but $162M bid liquidity points to downside risk

Bitcoin rebound highlights discount but $162M bid liquidity points to downside risk 2026-06-09 at 10:28 By Cointelegraph by Biraajmaan Tamuly Bitcoin’s recovery highlights investors’ belief that BTC is discounted, but weak futures market activity could slow the rebound. This article is an excerpt from Cointelegraph.com News View Original Source

Bitcoin rebound highlights discount but $162M bid liquidity points to downside risk Read More »

AI agents with crypto could escape and become ‘unstoppable,’ experts warn

AI agents with crypto could escape and become ‘unstoppable,’ experts warn 2026-06-09 at 10:28 By Cointelegraph by Martin Young Autonomous AI and crypto could have “far-reaching consequences for users and the financial system,” IC3 researchers said. This article is an excerpt from Cointelegraph.com News View Original Source

AI agents with crypto could escape and become ‘unstoppable,’ experts warn Read More »

The architecture of subtraction: Why it’s time to erase the roads, not just map the traffic

The architecture of subtraction: Why it’s time to erase the roads, not just map the traffic 2026-06-09 at 09:42 By Help Net Security The advent of AI-assisted vulnerability discovery and autonomous exploit development has brought about a new age in cybersecurity—one in which we can no longer rely on patching as a primary defense mechanism. […]

The architecture of subtraction: Why it’s time to erase the roads, not just map the traffic Read More »

Google Patches 5th Chrome Zero-Day Exploited in 2026

Google Patches 5th Chrome Zero-Day Exploited in 2026 2026-06-09 at 09:42 By Eduard Kovacs The vulnerability is tracked as CVE-2026-11645 and it was reported in late April by an anonymous researcher. The post Google Patches 5th Chrome Zero-Day Exploited in 2026 appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Google Patches 5th Chrome Zero-Day Exploited in 2026 Read More »

LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE 2026-06-09 at 09:42 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-42271 (CVSS score: 8.7), is a command […]

LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE Read More »

Humanity Protocol token falls 85% amid $30M private key exploit

Humanity Protocol token falls 85% amid $30M private key exploit 2026-06-09 at 08:46 By Cointelegraph by Martin Young The compromise of private keys belonging to a member of the Humanity Foundation has reportedly resulted in the theft of at least $30 million worth of its native token. This article is an excerpt from Cointelegraph.com News […]

Humanity Protocol token falls 85% amid $30M private key exploit Read More »

UK financial regulator floats allowing 10% crypto allocations for retail funds

UK financial regulator floats allowing 10% crypto allocations for retail funds 2026-06-09 at 08:46 By Cointelegraph by Jesse Coghlan The Financial Conduct Authority floated the idea of allowing limited exposure to crypto for retail-focused funds if it aligns with “disclosed investment objectives.” This article is an excerpt from Cointelegraph.com News View Original Source

UK financial regulator floats allowing 10% crypto allocations for retail funds Read More »

Scroll to Top