threat-intel Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers The CISA, NSA, and international partners have jointly released guidance to help software companies and online services establish effective Coordinated Vulnerability Disclosure (CVD) programs. This program focuses on col… CISA Advisories · Jul 15, 2026 Info vulnerabilitycvdsecurity
threat-intel White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative The White House has launched Gold Eagle, a new initiative designed to streamline vulnerability detection and remediation across government and industry. This program leverages AI, specifically Anthropic's Mythos, to proa… SecurityWeek · Jul 15, 2026 Medium vulnerabilityaicybersecurity
threat-intel Lessons Learned from CISA’s Recent GitHub Leak A CISA contractor inadvertently published a massive trove of sensitive credentials, including AWS GovCloud keys and plaintext passwords, in a public GitHub repository for nearly six months before CISA was notified. The a… Krebs on Security · Jul 13, 2026 High secretsgithubaws
threat-intel Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting Russian state-sponsored actors are exploiting poorly configured and vulnerable networking devices, primarily routers, across critical infrastructure sectors worldwide. This joint cybersecurity advisory, released by numer… CISA Advisories · Jul 13, 2026 High CVE-2018-0171CVE-2008-4128RUsnmpcverouter
threat-intel New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware Microsoft has uncovered a sophisticated Windows backdoor, dubbed GigaWiper, that combines destructive capabilities with remote control functionality. GigaWiper operates by bundling three separate tools – a disk wiper, a… The Hacker News · Jul 9, 2026 High IRISUKransomwarebackdoordata destruction
vulnerability 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google A 15-year-old Linux kernel vulnerability, dubbed ‘GhostLock,’ has been exploited to earn a security researcher $92,000. The flaw allows for local privilege escalation and container escapes, highlighting the long-term ris… SecurityWeek · Jul 9, 2026 High CVE-2026-43499linuxkernelvulnerability
vulnerability Microsoft Patches Defender ‘RoguePlanet’ Vulnerability Microsoft has released a patch to address a Defender vulnerability, dubbed RoguePlanet, which could allow an attacker to escalate privileges. The vulnerability was initially identified by Nightmare Eclipse (Chaotic Eclip… SecurityWeek · Jul 9, 2026 High CVE-2026-50656CVE-2026-41091CVE-2026-45498vulnerabilitypatchdefender
threat-intel 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros Researchers at Nebula Security discovered GhostLock (CVE-2026-43499), a 15-year-old Linux kernel vulnerability that allows an unprivileged user to gain root access on a machine. The flaw, discovered by their AI-driven bu… The Hacker News · Jul 8, 2026 High CVE-2026-43499CVE-2026-53166CVE-2026-46242linuxkernelprivilege-escalation
threat-intel CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws The US Cybersecurity and Infrastructure Security Agency (CISA) is leveraging Anthropic’s AI model, Mythos, to proactively scan federal government software for security vulnerabilities. This initiative is part of a broade… SecurityWeek · Jul 7, 2026 Medium USaiintelligencevulnerability
ransomware SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation A high-severity remote code execution (RCE) vulnerability (CVE-2026-45659) in Microsoft SharePoint Server has been added to the CISA KEV catalog due to active exploitation. This vulnerability, stemming from deserializing… The Hacker News · Jul 2, 2026 High CVE-2026-45659CVE-2025-11371USremote code executionsharepointvulnerability
malware RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS A new botnet, RustDuck, is leveraging Rust programming to hijack routers, IP cameras, and servers for DDoS attacks. Developed by QiAnXin's XLab, the botnet utilizes a two-stage approach, exploiting vulnerabilities in dev… The Hacker News · Jun 30, 2026 High CVE-2017-17215CVE-2025-29635CVE-2024-1781CNddosbotnetrust
threat-intel This month in security with Tony Anscombe – June 2026 edition This month’s security roundup highlights a critical CISA policy demanding rapid patching of vulnerabilities for federal agencies, a targeted cyberattack campaign against US-based Automatic Tank Gauges (ATGs), a surge in… WeLiveSecurity · Jun 30, 2026 Medium USUKCAvulnerabilitycyberattacksocial media
vulnerability Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth A critical vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster allows unauthenticated attackers to execute arbitrary commands as root by manipulating API requests. The flaw stems from a lack of proper sanitization… The Hacker News · Jun 30, 2026 Critical CVE-2026-8037CVE-2026-33691CVE-2024-1212CAcommand-injectionrootapi
threat-intel Iran, Russia, China Target Water Systems for Sabotage A DomainTools report details ongoing nation-state targeting of water systems by Iran, Russia, and China, primarily through exploiting weak passwords, exposed PLCs, and HMI vulnerabilities. The motivations behind these at… Dark Reading · Jun 29, 2026 High IRRUCHcritical infrastructurenation-statewater systems
threat-intel FBI: Russian hackers now target Signal backup recovery keys The FBI and CISA are warning about a phishing campaign orchestrated by Russian Intelligence Services (RIS) targeting Signal users. Attackers are now specifically seeking Signal Backup Recovery Keys to gain access to vict… BleepingComputer · Jun 26, 2026 High USRUUKphishingsignalrecovery key
phishing Russian Intelligence Services Continue to Target Commercial Messaging Applications The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have issued a new PSA highlighting ongoing cyberattacks by Russian Intelligence Services (RIS) targeting commercial messaging applications. These at… CISA Advisories · Jun 26, 2026 Medium RUphishingcredential theftrussian intelligence
vulnerability Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure Attackers exploited a critical vulnerability in Cisco Catalyst SD-WAN Controller (CVE-2026-20245) approximately two months before Cisco publicly disclosed it. The vulnerability, stemming from insufficient input validatio… Dark Reading · Jun 24, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127USsd-wanprivilege escalationzero-day
threat-intel Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration This article reports on a new executive order issued by President Trump setting deadlines for federal agencies to migrate to post-quantum cryptography. The order prioritizes protecting U.S. data from future decryption by… The Hacker News · Jun 23, 2026 High USpost-quantumcryptographyquantum computing
threat-intel FortiBleed Attackers Turn Firewalls Into Credentials Stealers as Heist Persists The FortiBleed campaign, spearheaded by threat actors likely originating from Russia, has compromised over 430,000 FortiGate firewalls globally, resulting in the theft of more than 110 million credentials. Attackers util… Dark Reading · Jun 23, 2026 High USRUINcredential theftfirewallauthentication
threat-intel Stop Your Legacy Infrastructure from Hijacking Your AI Agents This article highlights a significant security risk: attackers leveraging legacy infrastructure to compromise AI agent environments. Despite organizations investing heavily in securing AI workloads against direct attacks… The Hacker News · Jun 22, 2026 High CVE-2025-24813USailegacypermissions