vulnerability No Patch Planned for Exploited Arista EOS Vulnerability Organizations are advised to apply vendor-supplied mitigations or discontinue the vulnerable devices. The post No Patch Planned for Exploited Arista EOS Vulnerability appeared first on SecurityWeek . SecurityWeek · Jun 10, 2026 Medium CVE-2026-7473CVE-2026-11645CVE-2026-20245
vulnerability Ivanti: Max severity Sentry flaw allows code execution as root Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway solution, including a maximum-severity flaw that enables remote attackers to execute code with root privileges. BleepingComputer · Jun 10, 2026 CVE-2026-10520CVE-2026-10523
vulnerability Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows A security researcher, Chaotic Eclipse (MSNightmare), has released a proof-of-concept exploit, RoguePlanet, targeting a zero-day vulnerability in Microsoft Defender, granting SYSTEM-level access on updated Windows 11 and… The Hacker News · Jun 10, 2026 High CVE-2026-33825CVE-2026-45498CVE-2026-41091USzero-dayexploitmicrosoft defender
vulnerability Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS Six vulnerabilities, dubbed Proto6, have been identified in protobuf.js, a JavaScript implementation of Protocol Buffers. These flaws could lead to remote code execution (RCE) and denial-of-service (DoS) attacks, primari… The Hacker News · Jun 10, 2026 High CVE-2026-44289CVE-2026-44290CVE-2026-44291node.jsprotobufrce
threat-intel Anthropic rolls out Claude Fable 5, but it's available for a limited time Anthropic has released a new AI model, Claude Fable 5, built on the Mythos model, but with enhanced safeguards to mitigate potential misuse by malicious actors. Initially limited to cybersecurity experts and trusted part… BleepingComputer · Jun 10, 2026 High aicybersecuritymodel
threat-intel ISC Stormcast For Wednesday, June 10th, 2026 https://isc.sans.edu/podcastdetail/9966, (Wed, Jun 10th) The SANS Internet Storm Center's Stormcast for June 10th, 2026 highlighted several emerging threats and ongoing activity across the internet landscape. The broadcast detailed observed trends in malicious campaigns, vulne… SANS Internet Storm Center · Jun 10, 2026 Medium stormcastthreat-intelligencephishing
vulnerability Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges A new Microsoft Defender zero-day vulnerability, dubbed "RoguePlanet," has emerged, allowing attackers to gain SYSTEM privileges on fully patched Windows 10 and 11 systems via a race condition. The vulnerability was disc… BleepingComputer · Jun 9, 2026 High zero-dayrace conditionremote code execution
threat-intel UK weakens proposed telecoms defenses against Chinese hackers after industry pushback The UK government has weakened proposed cybersecurity protections for its telecoms networks in response to pushback from telecom companies regarding the cost and practicality of implementing measures designed to counter… The Record · Jun 9, 2026 High UKCHespionagetelecomscybersecurity
threat-intel A Record-Breaking Patch Tuesday for June 2026 Microsoft released a record-breaking 200 security patches on June 2026, addressing numerous vulnerabilities across its operating systems and software. Several critical flaws, including those identified by the security re… Krebs on Security · Jun 9, 2026 High CVE-2026-49160CVE-2026-45586CVE-2026-50507USzero-daypatch tuesdayai
threat-intel Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility This article from Palo Alto Unit 42 details how attackers are exploiting cloud logging services, specifically AWS CloudTrail and Google Cloud Logging, to evade detection and gain continuous visibility into target environ… Palo Alto Unit 42 · Jun 9, 2026 High cloud securityloggingevasion
threat-intel The Invisible Battlefield: How Cyber War Is Reshaping Everyday Life This article, authored by former National Cyber Director Chris Inglis, highlights the evolving nature of cyber warfare, arguing that it’s no longer a technical issue confined to IT departments but a central arena for nat… Dark Reading · Jun 9, 2026 High UScybersecuritycyberwarfarecritical infrastructure
threat-intel Blame AI: Patch Tuesday Hits Record 206 CVEs Microsoft’s June 2026 Patch Tuesday update released a record-breaking 206 CVEs, signaling a potential shift towards larger and more frequent security updates driven by the accelerating pace of vulnerability discovery fac… Dark Reading · Jun 9, 2026 High CVE-2026-45586CVE-2026-49160CVE-2026-50507USvulnerabilityzero-dayai
ServiceNow discloses security incident exposing customer data ServiceNow is warning about a security incident after attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from customer instances. BleepingComputer · Jun 9, 2026
vulnerability Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities Microsoft released its June 2026 security patch update, addressing 206 vulnerabilities across its product suite. A significant portion, 32 critical vulnerabilities, focus on remote code execution (RCE) issues within prod… Cisco Talos · Jun 9, 2026 High CVE-2026-42985CVE-2026-47291CVE-2026-44803remote code executionbuffer overflowinteger overflow
threat-intel OpenClaw AI agent found falling for phishing attacks, spills user data An OpenClaw AI agent, designed to monitor email and perform automated tasks, was successfully tricked by phishing attacks, highlighting vulnerabilities in AI systems’ ability to discern malicious intent. Researchers at V… BleepingComputer · Jun 9, 2026 High aiphishingcredentials
threat-intel Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address This article details a vulnerability in Microsoft Exchange, dubbed "Ghost-Sender," that allows attackers to spoof any email address by exploiting misconfigurations in Exchange Online and on-premises hybrid environments u… Dark Reading · Jun 9, 2026 High email spoofingexchangephishing
vulnerability SAP fixes critical flaws in NetWeaver and Commerce Cloud SAP has released a security patch addressing 15 vulnerabilities across its NetWeaver and Commerce Cloud platforms. The patch includes four critical flaws, primarily focused on authentication bypass and memory corruption,… BleepingComputer · Jun 9, 2026 Critical CVE-2026-44748CVE-2026-27671CVE-2026-22732samsauthenticationmemory corruption
supply-chain Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories A sophisticated supply chain attack, orchestrated by the Miasma worm (a variant of Shai-Hulud), targeted 73 Microsoft GitHub repositories, primarily within the Azure organization. The attack, initially discovered through… Dark Reading · Jun 9, 2026 High supply chaingithubazure
vulnerability Microsoft Patches 200 Vulnerabilities Three of the vulnerabilities fixed with the latest Patch Tuesday updates were publicly disclosed before Microsoft addressed them. The post Microsoft Patches 200 Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 9, 2026 CVE-2026-49160CVE-2026-50507CVE-2026-45586
threat-intel CISA to transform how it assesses cyber vulnerabilities and risks, Andersen says CISA is undergoing a significant transformation in its approach to cybersecurity vulnerability assessment, shifting from a blanket patching strategy to a risk-based prioritization model. This change, driven by increasing… The Record · Jun 9, 2026 Medium risk-basedvulnerability managementcybersecurity