vulnerability Microsoft patches Exchange Server zero-day exploited in attacks Microsoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targeting Outlook Web Access users. BleepingComputer · Jun 10, 2026 Critical CVE-2026-42897
ransomware Why schools remain one of cybercriminals’ favourite targets Schools continue to be a prime target for cyberattacks, particularly ransomware, as evidenced by recent incidents at Evanston Township High School and Powys County Council. These attacks disrupt operations and compromise… Graham Cluley · Jun 10, 2026 High USGBschoolsransomwarecyberattack
vulnerability Microsoft ships largest Patch Tuesday on record, with one bug under active attack Microsoft released its largest Patch Tuesday update to date, containing 206 CVEs, driven by the increasing use of AI in vulnerability discovery. A particularly concerning vulnerability, CVE-2026-45657, is described as ‘w… The Record · Jun 10, 2026 Critical CVE-2026-45657CVE-2026-41091CVE-2026-50507UKpatch tuesdayvulnerabilityai
Aryon Security Raises $29 Million in Series A Funding In the post-Mythos era, the company’s platform helps organizations enforce security controls across environments. The post Aryon Security Raises $29 Million in Series A Funding appeared first on SecurityWeek . SecurityWeek · Jun 10, 2026 High
vulnerability Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers Claroty researchers have analyzed the security of Vertiv UPS network cards and the Trane Tracer SC+ HVAC controller. The post Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers appeared first on… SecurityWeek · Jun 10, 2026
CISO Forum Webinar Today: 2026 Mid-Year Review Learn more about protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks. The post CISO Forum Webinar Today: 2026 Mid-Year Review appeared fir… SecurityWeek · Jun 10, 2026
vulnerability New Windows Zero-Day Exploit ‘RoguePlanet’ Released A new Windows zero-day exploit, dubbed RoguePlanet, has been released by the threat actor Nightmare Eclipse, targeting Microsoft Defender and potentially leading to local privilege escalation and BitLocker bypass. This f… SecurityWeek · Jun 10, 2026 High CVE-2026-45586CVE-2026-50507CVE-2026-41091USzero-daylocal privilege escalationbitlocker
threat-intel Microsoft: Some Windows PCs fail to install latest monthly updates Microsoft has identified an issue causing some Windows 11 devices upgraded to 24H2 or 25H2 to fail to install the latest monthly updates. The problem manifests as 0x80073712 or 0x800f0993 errors, linked to corrupted XSX… BleepingComputer · Jun 10, 2026 Medium windowsupdateserror
threat-intel NSO Group Hacking WhatsApp Despite Court Order Recent reports indicate that NSO Group, a cybersecurity firm specializing in offensive intelligence, has been found to be utilizing its Pegasus spyware to target WhatsApp users despite a court order restricting its use.… Schneier on Security · Jun 10, 2026 High spywarewhatsappnsogroup
threat-intel After AI Reaches Production: 12 Ways Security Teams Can Take Control This article discusses 12 practices for security teams to effectively incorporate AI applications into their operational security workflows. It emphasizes the importance of visibility, risk understanding, and trust-build… SecurityWeek · Jun 10, 2026 Medium aisecurityvisibility
Your Automated Pentest Looks Clean. See What It Missed in This Expert Webinar Your pentest report looks clean. That might be the problem. Run automated pentesting long enough, and the new findings start to dry up. By the third or fourth run, fewer issues appear. The report looks stable. Leadership… The Hacker News · Jun 10, 2026
vulnerability Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days On Tuesday, Microsoft patched two zero-day vulnerabilities that let attackers gain SYSTEM privileges on fully patched Windows systems, and a third one that grants access to BitLocker-protected drives. BleepingComputer · Jun 10, 2026 Critical CVE-2026-45586CVE-2020-17103CVE-2026-45585
vulnerability ServiceNow Patches Vulnerability Exploited Against Some Customers The company updated hosted customer instances to patch a security issue it reportedly had known about since April 7. The post ServiceNow Patches Vulnerability Exploited Against Some Customers appeared first on SecurityWe… SecurityWeek · Jun 10, 2026 Medium
vulnerability Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs Microsoft released a significant security update addressing 206 vulnerabilities across its software portfolio, including multiple critical Remote Code Execution (RCE) flaws and several zero-days. The update focuses on pa… The Hacker News · Jun 10, 2026 Critical CVE-2025-10263CVE-2026-8863CVE-2026-45657USzero-dayrcebitlocker
threat-intel Unpacking SMB cyber-readiness – and what makes or breaks it A recent ESET report, alongside Verizon's DBIR, highlights a significant disconnect between SMBs' confidence in their cyber resilience and their actual preparedness. Despite a high percentage (75%) believing they can abs… WeLiveSecurity · Jun 10, 2026 High cybersecurityrisk managementincident response
vulnerability Critical Vulnerabilities Patched in Fortinet, Ivanti Products Two OS command injection flaws can be exploited remotely, without authentication, for arbitrary code execution. The post Critical Vulnerabilities Patched in Fortinet, Ivanti Products appeared first on SecurityWeek . SecurityWeek · Jun 10, 2026 CVE-2026-25089CVE-2026-10520CVE-2026-10523
threat-intel How has use of framing protection security headers changed in the past 3 years?, (Wed, Jun 10th) This SANS Internet Storm Center article analyzes the adoption of framing protection security headers (X-Frame-Options and CSP frame-ancestors) across the top million most popular websites over a three-year period. The an… SANS Internet Storm Center · Jun 10, 2026 Medium framingcspx-frame-options
vulnerability ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact In addition, Rockwell Automation announced some enhancements to its SecureOT cybersecurity solution for OT. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact appeared first on Secur… SecurityWeek · Jun 10, 2026 CVE-2025-15467
threat-intel Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards Anthropic has released Claude Fable 5, its most powerful AI model, alongside a specialized version called Claude Mythos 5 designed for cybersecurity professionals. Fable 5 incorporates cyber-focused classifiers to mitiga… The Hacker News · Jun 10, 2026 High CVE-2026-4747UKaicybersecurityjailbreak
vulnerability ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances ServiceNow has disclosed a security incident where an unknown threat actor exploited a vulnerability to gain unauthorized access to customer instances. The flaw, initially discovered and internally tracked by ServiceNow… The Hacker News · Jun 10, 2026 High AUsecurityvulnerabilityaccess