data-breach Third DraftKings Hacker Sentenced to 18 Months in Prison A third individual, Nathan Austad, has been sentenced to 18 months in prison for his involvement in a 2022 hacking attack against DraftKings. The attack, utilizing credential stuffing, compromised over 60,000 DraftKings… SecurityWeek · Jun 24, 2026 High USALUAcredential stuffingonline gamblingcybercrime
vulnerability Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs Critical vulnerabilities were discovered in Ubiquiti UniFi devices, specifically CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, allowing for unauthorized access and command injection. While patches were released in… SecurityWeek · Jun 24, 2026 Critical CVE-2026-34908CVE-2026-34909CVE-2026-34910USvulnerabilitycommand injectionauthentication
threat-intel Agentic AI Security: Wrong Context, Wrong Decisions at Machine Speed This SecurityWeek article highlights the critical importance of accurate context for agentic AI systems, particularly in security applications. The piece explains that agentic AI, relying on speed and automation, can mak… SecurityWeek · Jun 24, 2026 High USGBagentic aillmcontext
ransomware New ‘Mistic’ RAT Opens Door to Several Ransomware Families Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. The post New ‘Mistic’ RAT Opens Door to Several Ransomware Families appeared first on SecurityWe… SecurityWeek · Jun 24, 2026 High
supply-chain Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking A new vulnerability, dubbed ‘Cordyceps,’ has been identified within CI/CD workflows across numerous open-source projects, allowing unauthorized access and control over developer repositories. The flaws, primarily found i… SecurityWeek · Jun 24, 2026 High ci/cdsupply chaingithub actions
BeyondTrust, LastPass Impacted by Klue-Salesforce Incident Over a dozen Klue customers have confirmed that hackers stole data from their Salesforce instances. The post BeyondTrust, LastPass Impacted by Klue-Salesforce Incident appeared first on SecurityWeek . SecurityWeek · Jun 24, 2026 High
Webinar Today: Modern Exposure Validation in the AI Era The exploit timeline collapsed. Make sure your validation didn't. The post Webinar Today: Modern Exposure Validation in the AI Era appeared first on SecurityWeek . SecurityWeek · Jun 24, 2026
vulnerability Hackers Exploiting Cisco Unified CM Vulnerability Cisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June. The post Hackers Exploiting Cisco Unified CM Vulnerability appeared first on SecurityWeek . SecurityWeek · Jun 24, 2026 Medium CVE-2026-20230CVE-2026-20045
threat-intel Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says Anthropic’s Mythos AI model identified vulnerabilities within several U.S. government computer systems during a testing exercise conducted in collaboration with intelligence agencies. While the model quickly detected wea… SecurityWeek · Jun 24, 2026 High UNaivulnerabilitysecurity
Dragos Unveils AI for OT Security Named EmberAI, the new capability is built on Dragos’ massive operational technology cybersecurity dataset. The post Dragos Unveils AI for OT Security appeared first on SecurityWeek . SecurityWeek · Jun 23, 2026
vulnerability Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps A significant vulnerability has been identified in the Dify AI platform, a widely used LLMOps solution powering over one million applications across numerous industries. The flaws, detailed as CVE-2026-41947 through CVE-… SecurityWeek · Jun 23, 2026 Critical CVE-2026-41947CVE-2026-41948CVE-2026-41949aillmopsdata-exposure
vulnerability Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks Researchers discovered a long-standing vulnerability (CVE-2026-20971) in Samsung’s KNOX kernel across numerous Galaxy devices, from S9 to S25. The flaw, a race-condition use-after-free (UAF), allowed for potential kernel… SecurityWeek · Jun 23, 2026 High uafkernelrace condition
threat-intel CISO Conversations: Carl Froggett – Combining CISO and CIO at Deep Instinct This SecurityWeek article details Carl Froggett’s career transition from a technology engineering background at Citi to becoming a CISO, highlighting his combined CISO and CIO role. Froggett emphasizes the interconnected… SecurityWeek · Jun 23, 2026 Medium cisociocybersecurity
Algerian Man Extradited to US for Running Cybercrime Marketplaces 26-year-old Abdellah Belmili faces up to 30 years in prison for allegedly operating the marketplaces Market0Day and Spoxy. The post Algerian Man Extradited to US for Running Cybercrime Marketplaces appeared first on Secu… SecurityWeek · Jun 23, 2026
vulnerability FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances A critical vulnerability, dubbed PixelSmash, has been identified in FFmpeg, a widely used media processing framework. The flaw allows for remote code execution (RCE) via crafted media files, potentially impacting a broad… SecurityWeek · Jun 23, 2026 Critical CVE-2026-8461USUKremote code executionmedia processingheap overflow
threat-intel OpenAI Refocuses Cybersecurity Efforts on Patching Over Discovery OpenAI is shifting its cybersecurity strategy from solely discovering vulnerabilities to accelerating the process of patching them, recognizing the overwhelming volume of findings generated by AI. The company is deployin… SecurityWeek · Jun 23, 2026 Medium USaicybersecuritypatching
threat-intel Russian Initial Access Broker Behind FortiBleed Campaign A Russian initial access broker (IAB) is targeting over 430,000 FortiGate firewalls globally as part of the FortiBleed campaign, harvesting credentials and selling access to other malicious actors. The campaign utilizes… SecurityWeek · Jun 23, 2026 High USGBNLcredential harvestingfirewallsupply chain
data-breach Canadian Electricity Provider London Hydro Discloses Data Breach Hackers stole customers’ names, addresses, email addresses, phone numbers, and account information. The post Canadian Electricity Provider London Hydro Discloses Data Breach appeared first on SecurityWeek . SecurityWeek · Jun 23, 2026 High
Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration Federal agencies are required to transition high-value assets and high-impact systems to use PQC by the end of 2030 and 2031. The post Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration appeared… SecurityWeek · Jun 23, 2026
data-breach Xsolis Data Breach Affects 1.4 Million Individuals Threat actors gained access to personal and protected health information that Xsolis received from its clients. The post Xsolis Data Breach Affects 1.4 Million Individuals appeared first on SecurityWeek . SecurityWeek · Jun 23, 2026 High