vulnerability Hackers Exploit Langflow Vulnerability for Remote Code Execution Disclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system. The post Hackers Exploit Langflow Vulnerability for Remote Code Execution appeared first on S… SecurityWeek · Jun 11, 2026 High CVE-2026-5027
malware Siemens Says Desigo CC Files Flagged as Malware by Security Engines A PowerShell script included in patch files appears to be triggering false positives by multiple security engines. The post Siemens Says Desigo CC Files Flagged as Malware by Security Engines appeared first on SecurityWe… SecurityWeek · Jun 11, 2026 Medium
threat-intel AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS. The rapid advancement of AI, particularly through tools like Anthropic's Claude Mythos Preview, has dramatically reduced the time it takes to discover and exploit vulnerabilities in software. This has collapsed the tradi… The Hacker News · Jun 11, 2026 High USGBaivulnerabilityexploitation
threat-intel FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers The FBI has taken down thirteen websites used by Chinese intelligence operatives to target and recruit U.S. government employees with access to sensitive information. These websites impersonated consulting firms offering… SecurityWeek · Jun 11, 2026 High USCNespionagerecruitmentcybersecurity
Enhanced License Plate Tracking The surveillance company Leonardo wants more data : A surveillance company plans to add sensors to automatic license plate readers (ALPRs) that would mean the devices, as well as capture the license plate of passing vehi… Schneier on Security · Jun 11, 2026 High
vulnerability Splunk, Palo Alto Networks Patch Severe Vulnerabilities The security defects could allow attackers to create or modify arbitrary files and access and modify protected resources. The post Splunk, Palo Alto Networks Patch Severe Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 11, 2026 High CVE-2026-0274CVE-2026-20253
threat-intel Trust No Skill: Integrity Verification for AI Agent Supply Chains This report from Palo Alto Unit 42 highlights a critical security vulnerability in the rapidly growing ecosystem of AI agent-skill supply chains. The analysis reveals that a significant number of skills, readily availabl… Palo Alto Unit 42 · Jun 11, 2026 High aiagentsupply chain
vulnerability ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker The PoC exploits Microsoft Defender’s offline scan to spawn a SYSTEM shell when rebooting in Recovery Mode. The post ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker appeared first on SecurityWeek . SecurityWeek · Jun 11, 2026 Critical
threat-intel OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack OceanLotus, a 15-year-old APT group with a history of targeting China and human rights activists, has been conducting a prolonged cyber espionage operation against Vietnamese entities, including a transport construction… The Hacker News · Jun 11, 2026 High VNsupply chainbackdoorespionage
threat-intel OceanLotus: From external espionage to domestic targeting OceanLotus, a Vietnamese-aligned cyberespionage group (formerly APT32), has shifted its focus from external espionage to domestic targeting, particularly in relation to corruption investigations in Vietnam. Since 2020, f… WeLiveSecurity · Jun 11, 2026 High VNsupply-chainespionagebackdoor
vulnerability Microsoft fixes BitLocker recovery bug on Windows Server 2025 Microsoft released updates (KB5094125 and KB5093998) to address a bug in Windows Server 2025 and Windows 11 that caused BitLocker recovery prompts after installing security updates. The issue stemmed from specific Group… BleepingComputer · Jun 11, 2026 Medium bitlockertpmgroup policy
University of Nottingham Confirms Breach After Hackers Leak Data The ShinyHunters hacker group has taken credit for the attack, leaking more than 450,000 email addresses and other information. The post University of Nottingham Confirms Breach After Hackers Leak Data appeared first on… SecurityWeek · Jun 11, 2026
data-breach Nottingham University data breach affects over 450,000 students The University of Nottingham experienced a significant data breach affecting over 450,000 current and former students due to a cyberattack by the ShinyHunters extortion group. The attackers gained access to student recor… BleepingComputer · Jun 11, 2026 High UKCHMAstudent datapeoplesoftextortion
vulnerability Microsoft Patches Exploited Exchange Server Vulnerability The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14. The post Microsoft Patches Exploited Exchange Server Vulnerability appeared first on SecurityWeek . SecurityWeek · Jun 11, 2026 Critical CVE-2026-42897
supply-chain GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks GitHub has announced what it said are "breaking changes" coming to npm version 12, one of which turns off install scripts by default to combat software supply chain threats. The changes aim to combat attack techniques th… The Hacker News · Jun 11, 2026
vulnerability Max severity Ivanti Sentry vulnerability now exploited in attacks Attackers are now targeting a recently patched maximum-severity flaw in Ivanti Sentry, enabling them to execute code with root privileges on Internet-exposed secure mobile gateways. BleepingComputer · Jun 11, 2026 Medium CVE-2026-10520
threat-intel ISC Stormcast For Thursday, June 11th, 2026 https://isc.sans.edu/podcastdetail/9968, (Thu, Jun 11th) The SANS Internet Storm Center's June 11th, 2026 Stormcast reported a heightened level of online threats and unusual network activity. The broadcast highlighted several emerging risks, including increased phishing campai… SANS Internet Storm Center · Jun 11, 2026 Medium phishingvulnerabilitynetwork
threat-intel Chinese, N. Korean Threat Groups Build on Asia-Pacific Success This article reports on the ongoing cybercrime activities of North Korean and Chinese threat groups targeting financial firms and cryptocurrency assets within the Asia-Pacific region. Despite increased international coll… Dark Reading · Jun 11, 2026 High CHNOSOcybercrimecryptocurrencynorth korea
vulnerability Vulnérabilité dans LibreNMS (11 juin 2026) A critical vulnerability has been identified in LibreNMS, allowing attackers to execute arbitrary code remotely. This affects versions 21.6.x through 26.x, and requires immediate patching to prevent exploitation. CERT-FR · Jun 11, 2026 Critical CVE-2026-55182librenmsremote code executionvulnerability
vulnerability Vulnérabilité dans Traefik (11 juin 2026) A security vulnerability has been identified in Traefik, allowing attackers to bypass security policies. This issue affects older versions of the popular reverse proxy and load balancer, requiring immediate patching to p… CERT-FR · Jun 11, 2026 Medium CVE-2026-54761traefikvulnerabilitysecurity