vulnerability Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data Squidbleed, discovered with the aid of Claude Mythos Preview, has been described as a Heartbleed-style vulnerability. The post Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data appeared first on SecurityWeek… SecurityWeek · Jun 22, 2026 Medium CVE-2026-47729
Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data. The post Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data appeared first on Security… SecurityWeek · Jun 22, 2026 CVE-2026-4020
supply-chain North Korean Hackers Blamed for Mastra NPM Supply Chain Attack A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions. The post North Korean Hackers Blamed for Mastra NPM Supply Chain Attack appeared first on Secu… SecurityWeek · Jun 22, 2026
threat-intel What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks Recent breaches attributed to the ShinyHunters cybercrime collective, including attacks on organizations like University of Nottingham and Medtronic, highlight a shift in cyberattack tactics. Attackers are increasingly t… SecurityWeek · Jun 22, 2026 High UKidentity-theftcredential-theftmfa
vulnerability New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones The vulnerability exploited by the Usbliter8 exploit cannot be patched and a PoC exploit has been released by researchers. The post New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones appeared first o… SecurityWeek · Jun 22, 2026 Medium
Fortinet Responds to FortiBleed Campaign A database of over 86,000 confirmed working credentials was created during the credential-harvesting campaign. The post Fortinet Responds to FortiBleed Campaign appeared first on SecurityWeek . SecurityWeek · Jun 22, 2026 CVE-2026-24858CVE-2025-59718CVE-2025-59719
More Cybersecurity Firms Disclose Impact From Klue Hack HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium are among the affected Klue customers. The post More Cybersecurity Firms Disclose Impact From Klue Hack appeared first on SecurityWeek . SecurityWeek · Jun 22, 2026
data-breach Texas Parks & Wildlife Data Breach Affects 3 Million Individuals Hackers stole personal information after breaching the systems of a third-party license vendor serving TPWD. The post Texas Parks & Wildlife Data Breach Affects 3 Million Individuals appeared first on SecurityWeek . SecurityWeek · Jun 22, 2026 High
threat-intel French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation This article reports on a discussion at the G7 summit regarding the regulation of advanced artificial intelligence (AI) systems, particularly focusing on the U.S. government’s restriction on access to Anthropic’s latest… SecurityWeek · Jun 20, 2026 Medium FRUNCAaiartificial intelligenceregulation
vulnerability In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum This week’s cybersecurity news highlights several significant vulnerabilities and attacks across various platforms and industries. A critical phpBB flaw enabled session hijacking, while vulnerabilities in Chrome extensio… SecurityWeek · Jun 19, 2026 High CVE-2025-20701CHISsession hijackingchrome extensionssupply chain attack
vulnerability CryptoBandits Malware Doubles as a Backdoor, Abuses Tor CryptoBandits uses a local SOCKS5 proxy for traffic routing, blending data theft with remote code execution. The post CryptoBandits Malware Doubles as a Backdoor, Abuses Tor appeared first on SecurityWeek . SecurityWeek · Jun 19, 2026 High
phishing FortiBleed: 86,000 Fortinet Device Credentials Compromised The large-scale credential theft campaign hit roughly half of the internet-accessible Fortinet firewalls and VPNs. The post FortiBleed: 86,000 Fortinet Device Credentials Compromised appeared first on SecurityWeek . SecurityWeek · Jun 19, 2026
supply-chain Cybersecurity Firms Impacted by Klue Supply Chain Attack A supply chain attack targeting the Klue market intelligence platform resulted in the unauthorized harvesting of customer data from various integrations, including Salesforce and HubSpot. The attack, attributed to a new… SecurityWeek · Jun 19, 2026 High supply-chainoauthcrm
Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC WideField will accelerate Agentic SOC capabilities by expanding the lens on threat investigation to include identity, credentials, sessions, and blast radius. The post Cisco to Acquire WideField Security to Boost Splunk’… SecurityWeek · Jun 19, 2026
malware 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame. The post 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown appeared first on SecurityWe… SecurityWeek · Jun 19, 2026 High
vulnerability Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution. The post Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosu… SecurityWeek · Jun 19, 2026 High CVE-2026-20253
malware Majority of Internet-Accessible REDCap Servers Outdated These servers are regularly targeted by China-linked UNC6508 for initial access and backdoor deployment. The post Majority of Internet-Accessible REDCap Servers Outdated appeared first on SecurityWeek . SecurityWeek · Jun 18, 2026
supply-chain Accenture to Acquire Majority Stake in Dragos, All of runZero, NetRise in $4.1 Billion OT Cybersecurity Push Accenture is undertaking a significant investment in operational technology (OT) cybersecurity through a series of acquisitions, totaling approximately $4.1 billion. This includes a majority stake in Dragos, along with t… SecurityWeek · Jun 18, 2026 High USot securityindustrial control systemsasset discovery
threat-intel No Exploits Required This article discusses the limitations of relying solely on exploiting vulnerabilities in cybersecurity, arguing that defenders often struggle due to the inherent complexity and interconnectedness of modern networks. The… SecurityWeek · Jun 18, 2026 Medium network securitycybersecurityzero-trust
Dream Raises $260 Million at $3 Billion Valuation The Israeli startup provides sovereign AI and cyber defenses for governments and critical infrastructure. The post Dream Raises $260 Million at $3 Billion Valuation appeared first on SecurityWeek . SecurityWeek · Jun 18, 2026