Vulnerabilities

Hackers Exploiting Cisco Unified CM Vulnerability

Hackers Exploiting Cisco Unified CM Vulnerability 2026-06-24 at 08:44 By Eduard Kovacs Cisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June. The post Hackers Exploiting Cisco Unified CM Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Exploiting Cisco Unified CM Vulnerability Read More »

Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says

Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says 2026-06-24 at 06:29 By Associated Press Come vulnerabilities were found within hours, but that does not mean the model was able to exploit them within that time, the official said. The post Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official

Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says Read More »

Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps 2026-06-23 at 18:36 By Ionut Arghire Attackers could abuse Dify’s multi-tenant cloud service to read private chats, preview other tenants’ documents, and reach internal APIs. The post Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps appeared first on SecurityWeek.

Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps Read More »

Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks

Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks 2026-06-23 at 16:00 By Kevin Townsend The high-severity use-after-free vulnerability in Samsung’s KNOX security framework affected Android-powered Galaxy devices from the S9 through S25. The post Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks appeared first on SecurityWeek. This

Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks Read More »

FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances

FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances 2026-06-23 at 14:48 By Ionut Arghire Attackers can send crafted media files to execute code in any application that uses FFmpeg’s libavcodec library. The post FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances appeared first on SecurityWeek. This article

FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances Read More »

Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data 2026-06-22 at 16:22 By Eduard Kovacs Squidbleed, discovered with the aid of Claude Mythos Preview, has been described as a Heartbleed-style vulnerability.  The post Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data Read More »

Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data

Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data 2026-06-22 at 14:45 By Ionut Arghire Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data. The post Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data Read More »

In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum

In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum 2026-06-19 at 18:23 By SecurityWeek News Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Connector flaw enables takeover. The post In Other

In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum Read More »

Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure

Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure 2026-06-19 at 07:10 By Eduard Kovacs CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution. The post Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure appeared first on SecurityWeek. This article is an excerpt

Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure Read More »

Majority of Internet-Accessible REDCap Servers Outdated

Majority of Internet-Accessible REDCap Servers Outdated 2026-06-18 at 20:07 By Ionut Arghire These servers are regularly targeted by China-linked UNC6508 for initial access and backdoor deployment. The post Majority of Internet-Accessible REDCap Servers Outdated appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Majority of Internet-Accessible REDCap Servers Outdated Read More »

Operation FlutterBridge: The FlutterShell macOS Backdoor

Operation FlutterBridge: The FlutterShell macOS Backdoor 2026-06-18 at 17:00 By Maor Gabay Identified through macOS endpoint monitoring, the CL-CRI-1089 cluster, delivered under the publicly reported Operation FlutterBridge campaign, demonstrates a deliberate misuse of the Flutter framework for macOS malware delivery. Rather than re-documenting the campaign itself, this report treats the recovered FlutterShell artifacts as a

Operation FlutterBridge: The FlutterShell macOS Backdoor Read More »

Atlassian, Splunk Patch Critical Vulnerabilities

Atlassian, Splunk Patch Critical Vulnerabilities 2026-06-18 at 13:59 By Ionut Arghire Splunk patched an OS command injection in AI Toolkit, while Atlassian fixed dozens of flaws in third-party dependencies. The post Atlassian, Splunk Patch Critical Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Atlassian, Splunk Patch Critical Vulnerabilities Read More »

Critical Command Execution Vulnerability Patched in Cisco ISE

Critical Command Execution Vulnerability Patched in Cisco ISE 2026-06-18 at 13:27 By Ionut Arghire Insufficient validation of user input allows an attacker to gain access to the underlying OS and elevate their privileges to root. The post Critical Command Execution Vulnerability Patched in Cisco ISE appeared first on SecurityWeek. This article is an excerpt from

Critical Command Execution Vulnerability Patched in Cisco ISE Read More »

F5 Patches Critical, High-Severity NGINX Vulnerabilities

F5 Patches Critical, High-Severity NGINX Vulnerabilities 2026-06-18 at 12:39 By Ionut Arghire Critical flaws in NGINX could allow remote, unauthenticated attackers to cause a restart and potentially execute arbitrary code. The post F5 Patches Critical, High-Severity NGINX Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

F5 Patches Critical, High-Severity NGINX Vulnerabilities Read More »

Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software

Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software 2026-06-17 at 14:32 By Eduard Kovacs The industrial automation giant has fixed security holes in Logix, CompactLogix, Flex, RSLinx, and FactoryTalk products. The post Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software Read More »

Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day

Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day 2026-06-17 at 12:41 By Ionut Arghire The public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges. The post Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day Read More »

Oracle’s Second Monthly Security Updates Deliver 245 Patches 

Oracle’s Second Monthly Security Updates Deliver 245 Patches  2026-06-17 at 12:04 By Eduard Kovacs Oracle has released its June 2026 Critical Security Patch Update to fix vulnerabilities in Communications, EBS, Enterprise Manager and other products. The post Oracle’s Second Monthly Security Updates Deliver 245 Patches  appeared first on SecurityWeek. This article is an excerpt from

Oracle’s Second Monthly Security Updates Deliver 245 Patches  Read More »

Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities

Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities 2026-06-17 at 11:21 By Ionut Arghire The browser updates address multiple memory safety bugs that could potentially lead to remote code execution. The post Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities Read More »

Joomla, LiteSpeed Vulnerabilities Exploited in Attacks

Joomla, LiteSpeed Vulnerabilities Exploited in Attacks 2026-06-17 at 10:28 By Ionut Arghire The flaws allow attackers to execute arbitrary PHP code and gain root privileges on shared hosting servers. The post Joomla, LiteSpeed Vulnerabilities Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Joomla, LiteSpeed Vulnerabilities Exploited in Attacks Read More »

Scroll to Top