Featured

Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters

Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters 2026-06-12 at 09:44 By Eduard Kovacs Oracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation. The post Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters Read More »

Microsoft Patches Exploited Exchange Server Vulnerability

Microsoft Patches Exploited Exchange Server Vulnerability 2026-06-11 at 11:18 By Eduard Kovacs The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14.  The post Microsoft Patches Exploited Exchange Server Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches Exploited Exchange Server Vulnerability Read More »

ServiceNow Patches Vulnerability Exploited Against Some Customers

ServiceNow Patches Vulnerability Exploited Against Some Customers 2026-06-10 at 14:22 By Eduard Kovacs The company updated hosted customer instances to patch a security issue it reportedly had known about since April 7. The post ServiceNow Patches Vulnerability Exploited Against Some Customers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

ServiceNow Patches Vulnerability Exploited Against Some Customers Read More »

Will AI Kill the Bug Bounty Industry?

Will AI Kill the Bug Bounty Industry? 2026-06-09 at 14:00 By Kevin Townsend Anthropic’s Mythos is accelerating vulnerability discovery to machine speed, forcing the bug bounty industry and offensive security teams to adapt to a future where finding flaws is no longer the hard part. The post Will AI Kill the Bug Bounty Industry? appeared

Will AI Kill the Bug Bounty Industry? Read More »

Google Patches 5th Chrome Zero-Day Exploited in 2026

Google Patches 5th Chrome Zero-Day Exploited in 2026 2026-06-09 at 09:42 By Eduard Kovacs The vulnerability is tracked as CVE-2026-11645 and it was reported in late April by an anonymous researcher. The post Google Patches 5th Chrome Zero-Day Exploited in 2026 appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Google Patches 5th Chrome Zero-Day Exploited in 2026 Read More »

WhatsApp Catches Spyware Firm NSO Defying No-Hacking Court Order

WhatsApp Catches Spyware Firm NSO Defying No-Hacking Court Order 2026-06-08 at 17:58 By Eduard Kovacs The Meta-owned communications app is filing a federal court contempt order against NSO. The post WhatsApp Catches Spyware Firm NSO Defying No-Hacking Court Order appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WhatsApp Catches Spyware Firm NSO Defying No-Hacking Court Order Read More »

Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026

Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 2026-06-05 at 09:23 By Eduard Kovacs The vulnerability is tracked as CVE-2026-20245 and it can allow arbitrary command execution as root, but no patch yet. The post Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 appeared first on SecurityWeek. This article is an excerpt from

Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 Read More »

Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash

Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash 2026-06-03 at 12:57 By Eduard Kovacs Microsoft responds to backlash over its threats of legal action against researchers who publicly disclose zero-day vulnerabilities. The post Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash appeared first on SecurityWeek. This article is an

Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash Read More »

Trump Signs Executive Order That Invites Vetting of Top AI Models for National Security Risks

Trump Signs Executive Order That Invites Vetting of Top AI Models for National Security Risks 2026-06-02 at 23:10 By Associated Press The order establishes a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release. The post Trump Signs

Trump Signs Executive Order That Invites Vetting of Top AI Models for National Security Risks Read More »

Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk

Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk 2026-06-02 at 18:01 By Kevin Townsend A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations. The post Exclusive: How One Line of Code Put Billions of Microsoft Android

Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk Read More »

Supply Chain Attack Hits 32 Red Hat NPM Packages

Supply Chain Attack Hits 32 Red Hat NPM Packages 2026-06-02 at 15:46 By Ionut Arghire Hackers published 96 malicious package versions, injected with a credential-stealing worm similar to Mini Shai-Hulud. The post Supply Chain Attack Hits 32 Red Hat NPM Packages appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Supply Chain Attack Hits 32 Red Hat NPM Packages Read More »

Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads 2026-06-02 at 11:12 By Eduard Kovacs Dashlane’s security systems automatically locked accounts to protect them against the hacking attempts. The post Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads Read More »

19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access

19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access 2026-06-01 at 17:37 By Ionut Arghire Proof-of-concept (PoC) exploit code has been released for the CIFSwitch flaw, which allows low-privileged users to escalate to root on vulnerable Linux systems. The post 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access appeared first on SecurityWeek. This article

19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access Read More »

Exploit Code Published for Critical Flowise RCE Vulnerability

Exploit Code Published for Critical Flowise RCE Vulnerability 2026-05-30 at 18:55 By Ionut Arghire The one-click vulnerability allows attackers to execute arbitrary code on self-hosted Flowise servers by tricking users into importing a malicious chatflow. The post Exploit Code Published for Critical Flowise RCE Vulnerability appeared first on SecurityWeek. This article is an excerpt from

Exploit Code Published for Critical Flowise RCE Vulnerability Read More »

Charter Communications Data Breach Could Impact Nearly 5 Million

Charter Communications Data Breach Could Impact Nearly 5 Million 2026-05-29 at 17:49 By Ionut Arghire The notorious ShinyHunters extortion group leaked over 42 million records allegedly stolen from Charter in April. The post Charter Communications Data Breach Could Impact Nearly 5 Million appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Charter Communications Data Breach Could Impact Nearly 5 Million Read More »

Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects

Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects 2026-05-25 at 13:58 By Eduard Kovacs Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase.  The post Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects appeared first on SecurityWeek. This article is an excerpt

Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects Read More »

Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack

Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack 2026-05-25 at 10:56 By Ionut Arghire Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens. The post Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack appeared first on SecurityWeek. This article is an excerpt from

Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack Read More »

‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains

‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains 2026-05-23 at 14:04 By Ionut Arghire The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic. The post ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains appeared first on SecurityWeek. This article is

‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains Read More »

Scroll to Top