threat-intel FFmpeg fixes PixelSmash flaw in widely used video decoder A vulnerability, dubbed ‘PixelSmash’ (CVE-2026-8461), has been identified in FFmpeg’s MagicYUV decoder, allowing for remote code execution (RCE) on vulnerable systems. The flaw stems from an out-of-bounds write in the de… BleepingComputer · Jun 22, 2026 High CVE-2026-8461USsupply-chainremote-code-executionheap-overflow
threat-intel Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants Researchers have identified four critical vulnerabilities in the open-source Dify agentic workflow platform, dubbed DifyTap, allowing unauthorized access to AI conversations and data across tenants. These flaws include a… The Hacker News · Jun 22, 2026 Critical CVE-2024-5846CVE-2026-41947CVE-2026-41948aivulnerabilitytenant
threat-intel Google Sets Sept. 30 Deadline for Android Developer Verification in Four Countries Google is implementing a new Android developer verification system, starting September 30, 2026, in Brazil, Indonesia, Singapore, and Thailand, to combat app scams and malware. This will block installations of apps from… The Hacker News · Jun 22, 2026 Medium BRIDSGapp scamsdeveloper verificationopen source
threat-intel Get Out of Security Debt by Tackling the Exposure Problem This Dark Reading article discusses the growing problem of ‘security debt’ – vulnerabilities that remain open in systems for extended periods. It argues that organizations need to shift their focus from simply tracking a… Dark Reading · Jun 18, 2026 High risk managementvulnerability managementsecurity debt
threat-intel Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model This article details a technique developed by Cisco Talos for automating reverse engineering of VB6 binaries using AI agents. The approach leverages the COM object model of VBdec, allowing external scripting tools like C… Cisco Talos · Jun 18, 2026 Medium reverse-engineeringaicom
threat-intel The Top 10 Attack Surface Exposures in 2026 This article from The Hacker News details a study by Intruder analyzing 3,000 attack surfaces, revealing widespread vulnerabilities in organizations’ internet-facing services. A significant 60% of organizations had expos… The Hacker News · Jun 17, 2026 High attack-surfacevulnerabilitydatabase
threat-intel GhostTree Attack Abused Recursive Windows Junctions to Hide Malware Security researchers have discovered a novel technique, dubbed "GhostTree," used by attackers to evade detection by security tools. This method leverages recursive loops created using NTFS junctions to hide malicious fil… BleepingComputer · Jun 16, 2026 High USjunctionsntfsrecursion
vulnerability Oracle mitigates PeopleSoft zero-day exploited in data theft attacks A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools has been exploited by the ShinyHunters ransomware gang to steal data from numerous organizations. Oracle has released mitigations, but t… BleepingComputer · Jun 11, 2026 Critical CVE-2026-35273zero-daydata theftpeoplesoft
threat-intel AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS. The rapid advancement of AI, particularly through tools like Anthropic's Claude Mythos Preview, has dramatically reduced the time it takes to discover and exploit vulnerabilities in software. This has collapsed the tradi… The Hacker News · Jun 11, 2026 High USGBaivulnerabilityexploitation
threat-intel Bug Bounty Research Triggers ServiceNow Security Alert ServiceNow experienced a situation where bug bounty research was mistakenly identified as a security breach targeting their customer instances. The issue involved unauthorized access to instance tables, but ServiceNow de… Dark Reading · Jun 10, 2026 Low AUbug bountyresearchsecurity
vulnerability Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities This article reports on critical security vulnerabilities recently patched by Fortinet, Ivanti, and SAP. These vulnerabilities, including command injection and authentication bypass flaws, could allow unauthorized code e… The Hacker News · Jun 10, 2026 Critical CVE-2026-25089CVE-2026-10520CVE-2026-10523command injectionremote code executionauthentication bypass
threat-intel Microsoft: Some Windows PCs fail to install latest monthly updates Microsoft has identified an issue causing some Windows 11 devices upgraded to 24H2 or 25H2 to fail to install the latest monthly updates. The problem manifests as 0x80073712 or 0x800f0993 errors, linked to corrupted XSX… BleepingComputer · Jun 10, 2026 Medium windowsupdateserror
threat-intel After AI Reaches Production: 12 Ways Security Teams Can Take Control This article discusses 12 practices for security teams to effectively incorporate AI applications into their operational security workflows. It emphasizes the importance of visibility, risk understanding, and trust-build… SecurityWeek · Jun 10, 2026 Medium aisecurityvisibility
vulnerability ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances ServiceNow has disclosed a security incident where an unknown threat actor exploited a vulnerability to gain unauthorized access to customer instances. The flaw, initially discovered and internally tracked by ServiceNow… The Hacker News · Jun 10, 2026 High AUsecurityvulnerabilityaccess
vulnerability Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows A security researcher, Chaotic Eclipse (MSNightmare), has released a proof-of-concept exploit, RoguePlanet, targeting a zero-day vulnerability in Microsoft Defender, granting SYSTEM-level access on updated Windows 11 and… The Hacker News · Jun 10, 2026 High CVE-2026-33825CVE-2026-45498CVE-2026-41091USzero-dayexploitmicrosoft defender
threat-intel A Record-Breaking Patch Tuesday for June 2026 Microsoft released a record-breaking 200 security patches on June 2026, addressing numerous vulnerabilities across its operating systems and software. Several critical flaws, including those identified by the security re… Krebs on Security · Jun 9, 2026 High CVE-2026-49160CVE-2026-45586CVE-2026-50507USzero-daypatch tuesdayai
threat-intel Blame AI: Patch Tuesday Hits Record 206 CVEs Microsoft’s June 2026 Patch Tuesday update released a record-breaking 206 CVEs, signaling a potential shift towards larger and more frequent security updates driven by the accelerating pace of vulnerability discovery fac… Dark Reading · Jun 9, 2026 High CVE-2026-45586CVE-2026-49160CVE-2026-50507USvulnerabilityzero-dayai
threat-intel XBOW tests Anthropic's Mythos Preview for offensive security BleepingComputer reports on XBOW’s testing of Anthropic’s Mythos Preview, a new AI model designed for offensive security. The testing revealed that Mythos Preview demonstrates significant advancements in vulnerability de… BleepingComputer · Jun 9, 2026 Medium aivulnerabilitysource code
threat-intel Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation Anthropic’s Claude Mythos AI model has demonstrated the ability to rapidly generate working exploits for known vulnerabilities in software like Firefox and Windows, significantly accelerating the attack process. The mode… SecurityWeek · Jun 9, 2026 High USaiexploitationn-day
threat-intel Will AI Kill the Bug Bounty Industry? This article discusses the potential disruption of the bug bounty industry by advancements in artificial intelligence, specifically Anthropic’s Claude Mythos model. The rise of AI-powered tools like Claude is enabling bo… SecurityWeek · Jun 9, 2026 Medium aiartificial intelligencebug bounty