vulnerability Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps A significant vulnerability has been identified in the Dify AI platform, a widely used LLMOps solution powering over one million applications across numerous industries. The flaws, detailed as CVE-2026-41947 through CVE-… SecurityWeek · Jun 23, 2026 Critical CVE-2026-41947CVE-2026-41948CVE-2026-41949aillmopsdata-exposure
vulnerability ABB Freelance Security Lock This report details a critical vulnerability in ABB’s Freelance Security Lock software, allowing attackers to bypass security measures and potentially gain access to underlying operating system functions. The vulnerabili… CISA Advisories · Jun 23, 2026 Critical CVE-2025-7064WOkeyboardsecuritybypass
threat-intel Siemens SINEC INS This CISA advisory details a critical vulnerability affecting Siemens SINEC INS versions prior to V1.0 SP2 Update 6. The vulnerability stems from improper input sanitization, allowing for command injection, path traversa… CISA Advisories · Jun 23, 2026 Critical CVE-2026-46746CVE-2026-46747CVE-2026-46748DEcommand injectionpath traversalpassword cracking
vulnerability FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances A critical vulnerability, dubbed PixelSmash, has been identified in FFmpeg, a widely used media processing framework. The flaw allows for remote code execution (RCE) via crafted media files, potentially impacting a broad… SecurityWeek · Jun 23, 2026 Critical CVE-2026-8461USUKremote code executionmedia processingheap overflow
threat-intel CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd) This report details a significant ongoing cyber threat targeting SonicWall firewalls exploiting CVE-2024-40766, a critical access control vulnerability. Ransomware groups, notably Akira and Fog, have been actively levera… SANS Internet Storm Center · Jun 23, 2026 Critical CVE-2024-40766CVE-2024-12802USGBvpncredential theftransomware
threat-intel FortiBleed campaign used custom FortiGate sniffer to steal credentials The FortiBleed campaign, targeting Fortinet FortiGate devices, utilized a custom Golang tool called "FortigateSniffer" to steal credentials from compromised firewalls. This campaign, active since at least February 2026,… BleepingComputer · Jun 22, 2026 Critical UScredential theftfirewallgpu cracking
supply-chain ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack A supply chain attack compromised multiple WordPress plugins from ShapedPlugin, injecting backdoor code into Pro plugin releases distributed through official update channels. The malicious plugins, affecting versions of… The Hacker News · Jun 22, 2026 Critical CVE-2026-49777CVE-2026-10735wordpresssupply chainbackdoor
threat-intel Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants Researchers have identified four critical vulnerabilities in the open-source Dify agentic workflow platform, dubbed DifyTap, allowing unauthorized access to AI conversations and data across tenants. These flaws include a… The Hacker News · Jun 22, 2026 Critical CVE-2024-5846CVE-2026-41947CVE-2026-41948aivulnerabilitytenant
threat-intel ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More This week’s cybersecurity news highlights a significant Fortinet vulnerability dubbed ‘FortiBleed,’ where over 80,000 FortiGate devices have been compromised by suspected Russian-speaking threat actors. Simultaneously, t… The Hacker News · Jun 22, 2026 Critical CVE-2026-24858CVE-2025-59718CVE-2025-59719RUcredential_reuseedrransomware
vulnerability CISA: Splunk Enterprise flaw actively exploited, patch by Sunday CISA has urged U.S. federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks. BleepingComputer · Jun 19, 2026 Critical CVE-2026-20253
threat-intel Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone A vulnerability in Apple’s Beats Studio Buds firmware allowed nearby attackers to potentially eavesdrop on users via the device’s microphone. The flaw, tracked as CVE-2025-20701, stemmed from incorrect authorization with… The Hacker News · Jun 19, 2026 Critical CVE-2025-20701CVE-2025-20700CVE-2025-20702GEbluetoothmicrophonesecurerom
vulnerability F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution F5 has released security patches to address two critical vulnerabilities (CVE-2026-42530 and CVE-2026-42055) in its NGINX Open Source and NGINX Plus products. These vulnerabilities, which allow for remote code execution,… The Hacker News · Jun 18, 2026 Critical CVE-2026-42530CVE-2026-42055CVE-2026-42945nginxcode executionremote vulnerability
vulnerability AVer PTC cameras This advisory from CISA details a critical vulnerability (CVE-2026-40624) affecting AVer PTC cameras. The flaw allows for remote, unauthenticated code execution via specially crafted web requests due to improper input va… CISA Advisories · Jun 18, 2026 Critical CVE-2026-40624WOremote code executioninput validationfirmware
vulnerability F5 Patches Critical, High-Severity NGINX Vulnerabilities Critical flaws in NGINX could allow remote, unauthenticated attackers to cause a restart and potentially execute arbitrary code. The post F5 Patches Critical, High-Severity NGINX Vulnerabilities appeared first on Securit… SecurityWeek · Jun 18, 2026 Critical CVE-2026-42530CVE-2026-42055CVE-2026-11311
vulnerability Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability has now been assigned the CVE identifier CVE-2026-50656 (CVSS score: 7.8), wit… The Hacker News · Jun 17, 2026 Critical CVE-2026-50656CVE-2026-33825CVE-2026-45498
threat-intel Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices A large-scale cyber espionage campaign has compromised over 30,000 Fortinet firewalls and VPN gateways globally, harvesting credentials for devices across nearly 200 countries. The operation, believed to be conducted by… Dark Reading · Jun 17, 2026 Critical USINGBcredential-harvestingpassword-compromiseautomation
CISA orders feds to patch max severity Joomla plugin flaw by Friday The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity flaw in the Widget Factory Joomla Content Editor (JCE) plugin that is being actively exploited in… BleepingComputer · Jun 17, 2026 Critical CVE-2026-48907
vulnerability Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day The public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges. The post Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day appeared first on SecurityWeek . SecurityWeek · Jun 17, 2026 Critical CVE-2026-50656CVE-2026-33825CVE-2026-41091
vulnerability Microsoft working on Defender patch for RoguePlanet zero-day Microsoft confirmed that it's working on a security patch for a Defender zero-day vulnerability named "RoguePlanet," disclosed one week ago. BleepingComputer · Jun 17, 2026 Critical CVE-2026-50656
vulnerability CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution CISA has added a critical vulnerability, CVE-2026-48907, to its Known Exploited Vulnerabilities catalog affecting the Widget Factory Joomla Content Editor (JCE) due to improper access control. This flaw allows for PHP co… The Hacker News · Jun 17, 2026 Critical CVE-2026-48907TUjoomlaphpcode execution