vulnerability Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs Microsoft released a significant security update addressing 206 vulnerabilities across its software portfolio, including multiple critical Remote Code Execution (RCE) flaws and several zero-days. The update focuses on pa… The Hacker News · Jun 10, 2026 Critical CVE-2025-10263CVE-2026-8863CVE-2026-45657USzero-dayrcebitlocker
vulnerability ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances ServiceNow has disclosed a security incident where an unknown threat actor exploited a vulnerability to gain unauthorized access to customer instances. The flaw, initially discovered and internally tracked by ServiceNow… The Hacker News · Jun 10, 2026 High AUsecurityvulnerabilityaccess
vulnerability Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws Microsoft released its June 2026 Patch Tuesday updates, addressing a significant number of vulnerabilities across its product suite. The updates include five publicly disclosed zero-day vulnerabilities, one of which is c… BleepingComputer · Jun 9, 2026 High zero-daypatchvulnerability
vulnerability Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws Microsoft released its June 2026 Patch Tuesday updates, addressing a significant number of vulnerabilities across its product suite. The updates included three previously unknown zero-day exploits and a total of 200 othe… BleepingComputer · Jun 9, 2026 High zero-daypatchmicrosoft
threat-intel Windows 11 KB5094126 & KB5093998 cumulative updates released This article reports on the release of Windows 11 cumulative updates KB5094126 and KB5093998, part of the June 2026 Patch Tuesday security releases. These updates address several vulnerabilities discovered in previous mo… BleepingComputer · Jun 9, 2026 Medium securityupdatespatches
vulnerability Schneider Electric EcoStruxure Panel Server Schneider Electric has identified a vulnerability in its EcoStruxure Panel Server product line, specifically versions prior to 002.006.000. This vulnerability, classified as CWE-1188, allows for potential unauthorized au… CISA Advisories · Jun 9, 2026 High CVE-2026-6866FRcwe-1188firmwareauthentication
vulnerability Schneider Electric Modicon Network Managed Switches Schneider Electric has identified a vulnerability (CVE-2024-3596) in its Modicon Network Managed Switches due to a misconfigured RADIUS protocol. Specifically, disabling the RADIUS Server Message Authenticator option mak… CISA Advisories · Jun 9, 2026 High CVE-2024-3596WOradiuscvesecurity
vulnerability Gogs patches critical zero-day enabling remote code execution A critical zero-day vulnerability in Gogs, a remote collaboration platform, has been identified, allowing authenticated attackers to execute remote code and access private repositories. The flaw, present in versions up t… BleepingComputer · Jun 8, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPremote-code-executionzero-dayauthentication
threat-intel Everybody Is Vibe Coding But Nobody Told the Security Team This article discusses the emerging security challenges posed by "vibe coding," a new approach to software development heavily reliant on AI-assisted tools. Rapid, AI-driven application development, particularly using pl… SecurityWeek · Jun 8, 2026 High UKaivibe-codingshadow-ai
phishing ISC Stormcast For Monday, June 8th, 2026 https://isc.sans.edu/podcastdetail/9962, (Mon, Jun 8th) The SANS Internet Storm Center's June 8th, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing campaigns and malicious email activity. The report highlighted an increase in observe… SANS Internet Storm Center · Jun 8, 2026 Medium phishingemailthreat-intelligence
phishing ISC Stormcast For Friday, June 5th, 2026 https://isc.sans.edu/podcastdetail/9960, (Fri, Jun 5th) The SANS Internet Storm Center's June 5th, 2026 Stormcast reported a heightened level of online threats, primarily focused on phishing and malicious email campaigns. The report highlighted several emerging trends in cybe… SANS Internet Storm Center · Jun 5, 2026 Medium phishingbotnetddos
threat-intel Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It The article highlights the increasing use of agentic AI in defense and intelligence networks, emphasizing the potential risks associated with its deployment. A recent incident involving Anthropic's Claude Mythos model de… The Hacker News · Jun 4, 2026 High aiagentic aidefense
vulnerability Hitachi Energy ITT600 Explorer Hitachi Energy has identified vulnerabilities in its ITT600 Explorer product, specifically versions prior to 2.1 SP6, which could lead to Denial of Service (DoS) attacks. The vulnerabilities stem from a stack overflow in… CISA Advisories · Jun 4, 2026 High CVE-2024-8176CVE-2025-59375SWiec61850denial of servicelibexpat
phishing Hacking Meta’s AI Chatbot Meta's AI chatbot, the Meta AI Support Assistant, was exploited by hackers to gain unauthorized access to Instagram accounts. The attackers leveraged the chatbot's ability to generate verification codes and reset passwor… Schneier on Security · Jun 4, 2026 High aichatbotphishing
threat-intel WhatsApp, Slack Notifications Could Hijack Google Gemini on Android This article details a vulnerability in Google Gemini on Android that allows malicious notifications from apps like WhatsApp, Slack, or SMS to hijack the voice assistant and perform actions such as opening windows, launc… The Hacker News · Jun 3, 2026 High voice assistantprompt injectionandroid
ddos New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute A new denial-of-service (DoS) attack, dubbed ‘HTTP/2 Bomb,’ has been identified that can cripple web servers within seconds by exploiting vulnerabilities in default HTTP/2 configurations of popular web servers like Nginx… BleepingComputer · Jun 3, 2026 High CVE-2026-49975doshttp2compression
threat-intel Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover A coding error in several Microsoft 365 Android applications, specifically Excel, Word, PowerPoint, OneNote, Loop, and Microsoft 365 Copilot, exposed user accounts to potential compromise. The issue stemmed from a disabl… Dark Reading · Jun 3, 2026 High CVE-2026-41100CVE-2026-41101CVE-2026-41102authenticationtokensandroid
vulnerability Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479) A 2-year-old remote code execution (RCE) vulnerability, CVE-2026-23479, was discovered in Redis 7.2.0 by an autonomous AI security tool, Team Xint Code. The flaw, stemming from a use-after-free issue in the `unblockClien… The Hacker News · Jun 3, 2026 High CVE-2026-23479UKuse-after-freerceredis
threat-intel Security of 100 AI Agents Tested and Ranked – What You Need to Know A recent analysis by Adversa AI tested and ranked 100 AI agents, revealing a concerning trend: nearly all agents possess a dangerous combination of excessive power, trust, and a lack of control – what they term the ‘leth… SecurityWeek · Jun 3, 2026 High aiagentsecurity
vulnerability Acer working to patch max severity zero-days in Wave 7 routers Acer has confirmed the existence of two critical zero-day vulnerabilities in its Wave 7 mesh routers, reported by security researcher Gergo Pap. These flaws, CVE-2026-49200 and CVE-2026-49201, allow unauthorized access t… BleepingComputer · Jun 3, 2026 Critical CVE-2026-49200CVE-2026-49201zero-daymesh routercredentials