vulnerability AVer PTC cameras This advisory from CISA details a critical vulnerability (CVE-2026-40624) affecting AVer PTC cameras. The flaw allows for remote, unauthenticated code execution via specially crafted web requests due to improper input va… CISA Advisories · Jun 18, 2026 Critical CVE-2026-40624WOremote code executioninput validationfirmware
vulnerability Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT This CISA advisory details a vulnerability in the Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT, specifically version 0x0110_v1.1.0. The device is susceptible to unauthorized interception of sensitive health… CISA Advisories · Jun 18, 2026 High CVE-2026-50034CVE-2026-52866INbluetoothbleglucose
vulnerability Mitsubishi Electric MELSEC iQ-F Series This advisory from CISA details a vulnerability (CVE-2026-8805) in the Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module. The vulnerability, stemming from an integer overflow, allows a remote attacker to… CISA Advisories · Jun 18, 2026 High CVE-2026-8805JPethernet/ipdenial of serviceinteger overflow
vulnerability AzeoTech DAQFactory This advisory details a Type Confusion vulnerability (CVE-2026-12390) in AzeoTech DAQFactory versions up to 21.1, allowing for potential arbitrary code execution via specially crafted .ctl files. The vulnerability affect… CISA Advisories · Jun 18, 2026 High CVE-2026-12390UStype confusioncwe843code execution
vulnerability Rockwell Automation FactoryTalk Historian Site Edition This advisory from CISA details vulnerabilities in Rockwell Automation’s FactoryTalk Historian Site Edition software, specifically versions through 11.00. Exploitation could lead to denial-of-service attacks or authentic… CISA Advisories · Jun 18, 2026 Medium CVE-2025-13036CVE-2025-44019CVE-2025-36539USfactorytalkhistorianrockwellautomation
vulnerability Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module This advisory from CISA details a denial-of-service (DoS) vulnerability in Mitsubishi Electric's MELSEC iQ-F Series FX5-ENET/IP Ethernet Module. The vulnerability, CVE-2026-8806, allows a remote attacker to overwhelm the… CISA Advisories · Jun 18, 2026 High CVE-2026-8806JPdenial-of-serviceethernetcve-2026-8806
vulnerability Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products Schneider Electric has identified a vulnerability (CVE-2026-4827) in several of its industrial automation products, including Easergy, EcoStruxture, PowerLogic, and Saitel systems. The vulnerability, a CWE-331 Insufficie… CISA Advisories · Jun 18, 2026 High CVE-2026-4827upsindustrial controlsession management
vulnerability CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding a widespread compromise of credentials associated with Fortinet devices, dubbed ‘FortiBleed.’ Approximately 74,000 Forti… CISA Advisories · Jun 18, 2026 High USGBcredentialsfirewallvpn
Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network If an autonomous AI agent interacts with your company's core intellectual property today, can your security team instantly name the person who authorized it? For most enterprises, the answer is a simple no. The rush to a… The Hacker News · Jun 18, 2026
Dream Raises $260 Million at $3 Billion Valuation The Israeli startup provides sovereign AI and cyber defenses for governments and critical infrastructure. The post Dream Raises $260 Million at $3 Billion Valuation appeared first on SecurityWeek . SecurityWeek · Jun 18, 2026
vulnerability F5 issues out-of-band patches for critical NGINX vulnerabilities Cybersecurity company F5 has released out-of-band security updates to address multiple NGINX web server vulnerabilities, including two critical-severity flaws that could allow attackers to execute code on vulnerable syst… BleepingComputer · Jun 18, 2026 CVE-2026-42530CVE-2026-42055CVE-2026-11311
malware Embedding Forbidden Text in Spyware to Discourage AI Analysis At least one malware developer is adding text about nuclear and biological weapons to their spyware, in an effort to stop automatic AI analysis. Details : The _index.js payload begins with a large JavaScript block commen… Schneier on Security · Jun 18, 2026 Medium
The Scripts on Your Checkout Page Are Now a PCI DSS Problem An independent PCI assessor tested Reflectiz against the new PCI DSS rules. Here is the verdict: See the full QSA assessment here → When a customer types their card number into your checkout, their browser is running far… The Hacker News · Jun 18, 2026
vulnerability Atlassian, Splunk Patch Critical Vulnerabilities Splunk patched an OS command injection in AI Toolkit, while Atlassian fixed dozens of flaws in third-party dependencies. The post Atlassian, Splunk Patch Critical Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 18, 2026 CVE-2026-20266CVE-2026-20265CVE-2026-42043
malware Rokarolla Banking Trojan Targets 200 Applications The Android malware allows its operators to take control of infected devices and harvest sensitive information. The post Rokarolla Banking Trojan Targets 200 Applications appeared first on SecurityWeek . SecurityWeek · Jun 18, 2026 Medium
vulnerability Critical Command Execution Vulnerability Patched in Cisco ISE Insufficient validation of user input allows an attacker to gain access to the underlying OS and elevate their privileges to root. The post Critical Command Execution Vulnerability Patched in Cisco ISE appeared first on… SecurityWeek · Jun 18, 2026 Medium CVE-2026-20181CVE-2026-20190
Microsoft fixes Windows Server 2016 security update failures Microsoft has fixed a known issue causing the June 2026 security updates to fail on Windows Server 2016 systems that weren't up to date. BleepingComputer · Jun 18, 2026
threat-intel Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model This article details a technique developed by Cisco Talos for automating reverse engineering of VB6 binaries using AI agents. The approach leverages the COM object model of VBdec, allowing external scripting tools like C… Cisco Talos · Jun 18, 2026 Medium reverse-engineeringaicom
ransomware Killing me gently: Inside Gentlemen’s EDR killer framework The Gentlemen ransomware-as-a-service (RaaS) gang has emerged as a significant and technically agile threat, distinguished by its proactive development and maintenance of a comprehensive suite of Endpoint Detection and R… WeLiveSecurity · Jun 18, 2026 High THBRFRransomwareedrrd
vulnerability F5 Patches Critical, High-Severity NGINX Vulnerabilities Critical flaws in NGINX could allow remote, unauthenticated attackers to cause a restart and potentially execute arbitrary code. The post F5 Patches Critical, High-Severity NGINX Vulnerabilities appeared first on Securit… SecurityWeek · Jun 18, 2026 Critical CVE-2026-42530CVE-2026-42055CVE-2026-11311