vulnerability Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479) A 2-year-old remote code execution (RCE) vulnerability, CVE-2026-23479, was discovered in Redis 7.2.0 by an autonomous AI security tool, Team Xint Code. The flaw, stemming from a use-after-free issue in the `unblockClien… The Hacker News · Jun 3, 2026 High CVE-2026-23479UKuse-after-freerceredis
Continuing Scans for swagger.json, (Wed, Jun 3rd) Enterprise applications often still use complex standards like SOAP for web services. The big advantage of SOAP is its tight and extensive standards, which enable interoperability across an enterprise governed by web ser… SANS Internet Storm Center · Jun 3, 2026
Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites. The post Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs appeared first… SecurityWeek · Jun 3, 2026 CVE-2026-8206
threat-intel Security of 100 AI Agents Tested and Ranked – What You Need to Know A recent analysis by Adversa AI tested and ranked 100 AI agents, revealing a concerning trend: nearly all agents possess a dangerous combination of excessive power, trust, and a lack of control – what they term the ‘leth… SecurityWeek · Jun 3, 2026 High aiagentsecurity
One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user's GitHub token. "Just by clicking a link, it's possible for an attacker to ste… The Hacker News · Jun 3, 2026
data-breach Hackers Target Global Stock Exchange in Espionage Operation The attackers had access to a senior executive’s email account for 150 days and exfiltrated data for months. The post Hackers Target Global Stock Exchange in Espionage Operation appeared first on SecurityWeek . SecurityWeek · Jun 3, 2026
data-breach IMA Diligence Services Data Breach Impacts 525,000 People The affected individuals’ personal information was stolen from a legacy server managed by a third party. The post IMA Diligence Services Data Breach Impacts 525,000 People appeared first on SecurityWeek . SecurityWeek · Jun 3, 2026 High
threat-intel Malicious Notifications Could Trick Google Gemini Users A SafeBreach research report, "Gemini's Secret Affair," details a prompt injection flaw in Google Gemini's voice assistant that allows attackers to trick users into executing malicious commands through seemingly harmless… Dark Reading · Jun 3, 2026 High prompt-injectionllmvoice-assistant
threat-intel Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP) This article discusses the growing problem of ‘identity dark matter’ – unseen identity activity within enterprise systems due to fragmented IAM and a lack of visibility. Gartner has introduced the Identity Visibility and… The Hacker News · Jun 3, 2026 Medium identity managementvisibilityanalytics
vulnerability Organizations Warned of Exploited Linux Kernel Vulnerability An improper authentication bug allows attackers to escalate their privileges and escape containers. The post Organizations Warned of Exploited Linux Kernel Vulnerability appeared first on SecurityWeek . SecurityWeek · Jun 3, 2026 Medium CVE-2022-0492CVE-2025-48595
vulnerability Acer working to patch max severity zero-days in Wave 7 routers Acer has confirmed the existence of two critical zero-day vulnerabilities in its Wave 7 mesh routers, reported by security researcher Gergo Pap. These flaws, CVE-2026-49200 and CVE-2026-49201, allow unauthorized access t… BleepingComputer · Jun 3, 2026 Critical CVE-2026-49200CVE-2026-49201zero-daymesh routercredentials
vulnerability Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore Assume the breach. Zero-days keep shipping, AI is writing exploits faster than anyone patches, and "patch everything in time" stopped working years ago. Stop betting the org on winning that race. You don't control which… The Hacker News · Jun 3, 2026 Critical
AI Used to Decrypt Medieval Ciphers Researchers are using machine learning algorithms to decrypt historical pencil-and-paper ciphers. Schneier on Security · Jun 3, 2026
threat-intel ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds A new ‘HTTP/2 Bomb’ exploit has been discovered that leverages existing vulnerabilities in HTTP/2 implementations to cause widespread denial-of-service attacks against web servers. The exploit combines compression and fl… SecurityWeek · Jun 3, 2026 High CVE-2016-6581CVE-2025-53020CVE-2016-8740USdoshttp2compression
vulnerability Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the attacker. Like in the case of CVE-2026-33829, which impacted the Windows Snipping Too… The Hacker News · Jun 3, 2026 Medium CVE-2026-33829CVE-2023-35636
Police dismantles 9 crime groups in illegal streaming crackdown European and international law enforcement agencies have dismantled nine organized crime groups and arrested 29 suspects in a major crackdown on illegal streaming operations. BleepingComputer · Jun 3, 2026 High
threat-intel New cyber force would cost up to $11 billion to start, commission says This article reports on a commission’s recommendation for the U.S. to establish a dedicated cyber warfare force, estimated to cost up to $11 billion and staffed by approximately 30,000 personnel. The proposal stems from… The Record · Jun 3, 2026 High UNRUCHcybersecuritymilitarydefense
threat-intel Global Stock Exchange Hit by Monthslong Email Campaign A global stock exchange was targeted by a sophisticated threat actor who gained near-continuous access to a senior executive’s Microsoft Outlook mailbox over a five-month period. The attacker utilized legitimate Windows… Dark Reading · Jun 3, 2026 High UKemail espionagelateral movementdata exfiltration
threat-intel Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash This article reports on a controversy between Microsoft and a security researcher, known as Nightmare Eclipse, regarding the disclosure of several zero-day vulnerabilities affecting Microsoft products. Microsoft initiall… SecurityWeek · Jun 3, 2026 High CVE-2026-41091CVE-2026-45498CVE-2026-33825USzero-dayvulnerability disclosurelegal action
threat-intel Google adds Android protection against AI deepfake scam calls Google is launching a new Android security feature, "fake call detection," to combat increasingly sophisticated scams utilizing AI-generated deepfake calls. The system works by verifying call authenticity in real-time, a… BleepingComputer · Jun 3, 2026 High USdeepfakeaiscam