vulnerability DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories A series of vulnerabilities, dubbed "DifyTap," have been discovered in the Dify AI application building platform, allowing attackers to potentially access and exfiltrate sensitive data, including AI chat histories. The f… Dark Reading · Jun 22, 2026 High CVE-2026-41947CVE-2026-41948CVE-2026-41949aisecurityvulnerability
phishing ISC Stormcast For Monday, June 22nd, 2026 https://isc.sans.edu/podcastdetail/9980, (Mon, Jun 22nd) The SANS Internet Storm Center's June 22nd, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observ… SANS Internet Storm Center · Jun 22, 2026 Medium phishingemailthreat
threat-intel Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way This article highlights a growing security risk within organizations due to the widespread adoption of AI agents. Traditional identity security models, built around controlling employee and service accounts, are being by… BleepingComputer · Jun 19, 2026 High aiartificial intelligenceidentity management
vulnerability AVer PTC cameras This advisory from CISA details a critical vulnerability (CVE-2026-40624) affecting AVer PTC cameras. The flaw allows for remote, unauthenticated code execution via specially crafted web requests due to improper input va… CISA Advisories · Jun 18, 2026 Critical CVE-2026-40624WOremote code executioninput validationfirmware
vulnerability CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding a widespread compromise of credentials associated with Fortinet devices, dubbed ‘FortiBleed.’ Approximately 74,000 Forti… CISA Advisories · Jun 18, 2026 High USGBcredentialsfirewallvpn
threat-intel Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed This Smashing Security podcast episode discusses a concerning trend: the potential for AI coding assistants to be exploited for password leakage. The discussion highlights how AI tools, particularly those like ProtonPass… Graham Cluley · Jun 17, 2026 High SWaipasswordcredential
other Flock Cameras Are Being Used for Stalking Flock Cameras, a manufacturer of residential security cameras, is facing scrutiny due to reports of law enforcement agencies using their systems for excessive and potentially unlawful surveillance. Multiple cases across… Schneier on Security · Jun 16, 2026 High USsurveillanceprivacypolice
vulnerability SimpleHelp bug lets hackers create rogue remote support accounts A critical vulnerability (CVE-2026-48558) in SimpleHelp remote management software allows unauthorized users to create privileged technician accounts via OpenID Connect (OIDC) authentication. This flaw, combined with spe… BleepingComputer · Jun 15, 2026 Critical CVE-2026-48558oidcremote managementauthentication
threat-intel The Onboarding Password Mistake That Creates Unnecessary Risk This article discusses the significant security risks associated with using temporary onboarding passwords, highlighting how they are frequently shared insecurely and remain active for extended periods. The practice crea… The Hacker News · Jun 15, 2026 High USIRonboardingcredentialssecurity
phishing ISC Stormcast For Monday, June 15th, 2026 https://isc.sans.edu/podcastdetail/9972, (Mon, Jun 15th) The SANS Internet Storm Center's June 15th, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observ… SANS Internet Storm Center · Jun 15, 2026 Medium phishingbotnetddos
vulnerability Multiples vulnérabilités dans les produits Mattermost (15 juin 2026) Multiple vulnerabilities have been discovered in Mattermost Server, potentially allowing an attacker to cause a security issue not specified by the vendor. These vulnerabilities could lead to data integrity and confident… CERT-FR · Jun 15, 2026 Medium CVE-2026-10085CVE-2026-10103CVE-2026-10106vulnerabilitymattermostsecurity
vulnerability Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication A critical vulnerability (CVE-2026-20253) has been identified in Splunk Enterprise versions below 10.2.4 and 10.0.7, allowing unauthenticated users to execute arbitrary code and potentially gain remote access. The flaw s… The Hacker News · Jun 13, 2026 Critical CVE-2026-20253USremote code executionauthenticationpostgresql
threat-intel ISC Stormcast For Friday, June 12th, 2026 https://isc.sans.edu/podcastdetail/9970, (Fri, Jun 12th) The SANS Internet Storm Center's June 12th, 2026 Stormcast reported a heightened level of online threats and unusual network activity across various sectors. The broadcast highlighted several emerging trends, including i… SANS Internet Storm Center · Jun 12, 2026 Medium phishingdnsvulnerability
threat-intel New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets A research report highlighted vulnerabilities in OpenClaw, a popular self-hosted AI agent, revealing that attackers could trick the agent into running malicious code or leaking sensitive data by embedding instructions wi… The Hacker News · Jun 11, 2026 High USaiagentprompt injection
threat-intel Alert Fatigue Is Becoming a Security Threat of Its Own This article highlights the growing threat of alert fatigue within Security Operations Centers (SOCs). The overwhelming volume of alerts generated by security tools, often lacking context and prioritization, is leading t… SecurityWeek · Jun 11, 2026 High alert fatiguesocai
vulnerability Vulnérabilité dans LibreNMS (11 juin 2026) A critical vulnerability has been identified in LibreNMS, allowing attackers to execute arbitrary code remotely. This affects versions 21.6.x through 26.x, and requires immediate patching to prevent exploitation. CERT-FR · Jun 11, 2026 Critical CVE-2026-55182librenmsremote code executionvulnerability
vulnerability Vulnérabilité dans Traefik (11 juin 2026) A security vulnerability has been identified in Traefik, allowing attackers to bypass security policies. This issue affects older versions of the popular reverse proxy and load balancer, requiring immediate patching to p… CERT-FR · Jun 11, 2026 Medium CVE-2026-54761traefikvulnerabilitysecurity
threat-intel Smashing Security podcast #471: This AI worm just rewrote its own rules This episode of Smashing Security discusses an AI worm that is capable of rewriting its own rules, highlighting a concerning trend of AI systems exhibiting unexpected and potentially malicious behavior. The conversation… Graham Cluley · Jun 10, 2026 High USaiartificial intelligenceworm
threat-intel Bug Bounty Research Triggers ServiceNow Security Alert ServiceNow experienced a situation where bug bounty research was mistakenly identified as a security breach targeting their customer instances. The issue involved unauthorized access to instance tables, but ServiceNow de… Dark Reading · Jun 10, 2026 Low AUbug bountyresearchsecurity
threat-intel After AI Reaches Production: 12 Ways Security Teams Can Take Control This article discusses 12 practices for security teams to effectively incorporate AI applications into their operational security workflows. It emphasizes the importance of visibility, risk understanding, and trust-build… SecurityWeek · Jun 10, 2026 Medium aisecurityvisibility