vulnerability SAP Patches Critical NetWeaver, Commerce Vulnerabilities The flaws could lead to the disclosure of sensitive information, memory corruption, and disruption of normal system usage. The post SAP Patches Critical NetWeaver, Commerce Vulnerabilities appeared first on SecurityWeek… SecurityWeek · Jun 9, 2026 High CVE-2026-44748CVE-2026-27671CVE-2026-22732
vulnerability Siemens KACO Blueplanet Inverters This advisory from CISA details vulnerabilities within Siemens KACO Blueplanet Inverters, a series of industrial inverters used in energy systems. The vulnerabilities, specifically a CRC16-based algorithm for generating… CISA Advisories · Jun 9, 2026 High CVE-2025-40946CVE-2026-41125WOindustrial control systemsvulnerabilityauthentication
vulnerability Schneider Electric EcoStruxure Panel Server Schneider Electric has identified a vulnerability in its EcoStruxure Panel Server product line, specifically versions prior to 002.006.000. This vulnerability, classified as CWE-1188, allows for potential unauthorized au… CISA Advisories · Jun 9, 2026 High CVE-2026-6866FRcwe-1188firmwareauthentication
vulnerability Schneider Electric Modicon Network Managed Switches Schneider Electric has identified a vulnerability (CVE-2024-3596) in its Modicon Network Managed Switches due to a misconfigured RADIUS protocol. Specifically, disabling the RADIUS Server Message Authenticator option mak… CISA Advisories · Jun 9, 2026 High CVE-2024-3596WOradiuscvesecurity
malware Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models Researchers at the University of Toronto have developed a novel AI-driven computer worm that operates autonomously by leveraging locally hosted, open-weight large language models. The worm dynamically generates attack st… The Hacker News · Jun 9, 2026 Critical CVE-2026-39987CVE-2026-31431CVE-2026-43284GBaiwormllm
vulnerability Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS score: 8.8), has bee… The Hacker News · Jun 9, 2026 Critical CVE-2026-11645CVE-2026-2441CVE-2026-3909
supply-chain Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks A new wave of Shai-Hulud supply chain attacks has impacted over 471 NPM and PyPI packages, utilizing variants named Miasma and Hades. The attacks, originating from TeamPCP, involve credential harvesting and self-replicat… SecurityWeek · Jun 9, 2026 High supply chainnpmpypi
threat-intel The Hidden Security Risk in Modern Networks: The Work Between Tools This article highlights a critical operational challenge facing modern network security teams: the ‘work between tools.’ Despite advancements in technology and AI, organizations struggle with fragmented workflows when re… The Hacker News · Jun 9, 2026 Medium workflowautomationalerting
threat-intel Will AI Kill the Bug Bounty Industry? This article discusses the potential disruption of the bug bounty industry by advancements in artificial intelligence, specifically Anthropic’s Claude Mythos model. The rise of AI-powered tools like Claude is enabling bo… SecurityWeek · Jun 9, 2026 Medium aiartificial intelligencebug bounty
data-breach French govt messaging service breached in account hijacking attack The French government’s Tchap messaging service was breached after a compromised user account was used to gain access, leading to the theft of sensitive data including user information and over 13.5GB of files. The attac… BleepingComputer · Jun 9, 2026 High FRsocial engineeringdata theftmessaging
threat-intel New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing A new attack method, dubbed FROST, allows websites to track which sites and apps a user opens by analyzing the timing of SSD reads. Developed by researchers at Graz University of Technology, FROST leverages the Origin Pr… The Hacker News · Jun 9, 2026 High DEopfsssdtiming attack
ransomware Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks The authentication bypass vulnerability allows attackers to establish VPN connections without a valid password. The post Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks appeared first on SecurityWeek . SecurityWeek · Jun 9, 2026 Critical CVE-2026-50751CVE-2026-50752
supply-chain Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer A new supply chain attack, dubbed Hades, is leveraging the Miasma campaign to compromise 37 PyPI packages, including those used in bioinformatics and computational biology. The attack utilizes a malicious setup.pth file… The Hacker News · Jun 9, 2026 High RUsupply-chainpythoncredential-stealing
threat-intel Cybercriminals: the 'auditors' you never hired This article explores the psychological phenomenon of ‘normalcy bias’ – our tendency to underestimate risk and assume things will always go as they have in the past – and how it contributes to a persistent rise in cybera… WeLiveSecurity · Jun 9, 2026 High UKIRcognitive biasnormalcy biascybersecurity
vulnerability CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day The Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive (BOD) 22-01, requiring U.S. federal agencies to patch a critical zero-day vulnerability in Check Point’s Remote Acces… BleepingComputer · Jun 9, 2026 High CVE-2026-50751CVE-2024-24919zero-dayvpnikev1
vulnerability Google patches new Chrome zero-day flaw exploited in the wild Google has released a security update to address a newly discovered and actively exploited zero-day vulnerability (CVE-2026-11645) within the Chrome browser. This flaw, originating in the V8 JavaScript engine, allows att… BleepingComputer · Jun 9, 2026 High CVE-2026-11645CVE-2024-0519CVE-2026-2441zero-daychromev8
ransomware LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE A critical command injection vulnerability (CVE-2026-42271) in BerriAI’s LiteLLM has been actively exploited in the wild. The flaw, combined with a separate Starlette vulnerability (CVE-2026-48710), allows for unauthenti… The Hacker News · Jun 9, 2026 Critical CVE-2026-42271CVE-2026-48710CVE-2026-42208command injectionremote code executionunauthenticated
vulnerability Google Patches 5th Chrome Zero-Day Exploited in 2026 The vulnerability is tracked as CVE-2026-11645 and it was reported in late April by an anonymous researcher. The post Google Patches 5th Chrome Zero-Day Exploited in 2026 appeared first on SecurityWeek . SecurityWeek · Jun 9, 2026 Critical CVE-2026-11645CVE-2026-2441CVE-2026-3909
phishing ISC Stormcast For Tuesday, June 9th, 2026 https://isc.sans.edu/podcastdetail/9964, (Tue, Jun 9th) The SANS Internet Storm Center's June 9th, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The broadcast highlighted several emerging tr… SANS Internet Storm Center · Jun 9, 2026 Medium phishingbotnetemail
threat-intel When “Hi, This Is IT” Comes Through Microsoft Teams This report details a tactic employed by threat actors, primarily Cloaked Ursa (APT29), to compromise organizations by impersonating IT departments within Microsoft Teams. The attackers leverage trusted communication cha… Palo Alto Unit 42 · Jun 8, 2026 High microsoft teamssocial engineeringmfa