vulnerability Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 Cisco has issued a security advisory regarding a newly discovered zero-day vulnerability (CVE-2026-20245) within its SD-WAN Manager product. This vulnerability, exploitable via command injection, has been actively used b… SecurityWeek · Jun 5, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127zero-daycommand injectionsd-wan
threat-intel Offroad Emerges From Stealth With $7 Million to Tackle Enterprise Identity Risk Offroad, a new cybersecurity firm, has launched with $7 million in funding to address the growing risk of identity-related vulnerabilities in enterprise environments. The company utilizes AI-powered agents to proactively… SecurityWeek · Jun 4, 2026 Medium USILISoauthidentity riskai
Webinar Today: Third-Party Risk in Practice – Where Programs Break Down and How to Respond Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. The post Webinar Today: Third-Party Risk in Practice… SecurityWeek · Jun 4, 2026
Willow Raises $7 Million for Securing Autonomous AI Agents Willow (formerly Webrix) emerged from stealth mode with an access platform designed to secure enterprise AI agents. The post Willow Raises $7 Million for Securing Autonomous AI Agents appeared first on SecurityWeek . SecurityWeek · Jun 4, 2026
Gemini Voice Assistant Hijacked via Messaging Notifications Attackers could have triggered dangerous actions, including controlling smart home devices via Google Home and starting Zoom video calls. The post Gemini Voice Assistant Hijacked via Messaging Notifications appeared firs… SecurityWeek · Jun 4, 2026
vulnerability Mirasvit Vulnerability Exploited to Execute Code on Magento Servers A flaw in the Full Page Cache Warmer extension can be exploited without authentication via serialized PHP object payloads. The post Mirasvit Vulnerability Exploited to Execute Code on Magento Servers appeared first on Se… SecurityWeek · Jun 4, 2026 Medium CVE-2026-45247
threat-intel Chinese Cybercrime Group in Spotlight for Record Campaign Pace A Chinese cybercrime group, TA4922, is experiencing a record surge in campaign activity, utilizing sophisticated social engineering tactics to target organizations globally. The group’s primary objectives involve data th… SecurityWeek · Jun 4, 2026 High GBDEITsocial engineeringcredential phishingremote access
Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown Law enforcement and tech companies disrupted infrastructure linked to scammers operating across Southeast Asia. The post Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown appeared first on SecurityWeek . SecurityWeek · Jun 4, 2026 High
vulnerability Cisco Warns of Available PoC for Critical Unified CM Vulnerability The high-severity flaw can be exploited remotely, without authentication, in server-side request forgery (SSRF) attacks. The post Cisco Warns of Available PoC for Critical Unified CM Vulnerability appeared first on Secur… SecurityWeek · Jun 4, 2026 High CVE-2026-20230
vulnerability VS Code Vulnerability Allows One-Click GitHub Token Theft A researcher has disclosed the full details of the vulnerability and released a PoC without notifying Microsoft in advance. The post VS Code Vulnerability Allows One-Click GitHub Token Theft appeared first on SecurityWee… SecurityWeek · Jun 4, 2026 Medium
Coralogix Raises $200M at $1.6B Valuation to Scale AI Observability Platform Coralogix offers a full-stack observability platform that unifies logs, metrics, traces, security, and AI observability. The post Coralogix Raises $200M at $1.6B Valuation to Scale AI Observability Platform appeared firs… SecurityWeek · Jun 3, 2026
Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites. The post Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs appeared first… SecurityWeek · Jun 3, 2026 CVE-2026-8206
threat-intel Security of 100 AI Agents Tested and Ranked – What You Need to Know A recent analysis by Adversa AI tested and ranked 100 AI agents, revealing a concerning trend: nearly all agents possess a dangerous combination of excessive power, trust, and a lack of control – what they term the ‘leth… SecurityWeek · Jun 3, 2026 High aiagentsecurity
data-breach Hackers Target Global Stock Exchange in Espionage Operation The attackers had access to a senior executive’s email account for 150 days and exfiltrated data for months. The post Hackers Target Global Stock Exchange in Espionage Operation appeared first on SecurityWeek . SecurityWeek · Jun 3, 2026
data-breach IMA Diligence Services Data Breach Impacts 525,000 People The affected individuals’ personal information was stolen from a legacy server managed by a third party. The post IMA Diligence Services Data Breach Impacts 525,000 People appeared first on SecurityWeek . SecurityWeek · Jun 3, 2026 High
vulnerability Organizations Warned of Exploited Linux Kernel Vulnerability An improper authentication bug allows attackers to escalate their privileges and escape containers. The post Organizations Warned of Exploited Linux Kernel Vulnerability appeared first on SecurityWeek . SecurityWeek · Jun 3, 2026 Medium CVE-2022-0492CVE-2025-48595
threat-intel ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds A new ‘HTTP/2 Bomb’ exploit has been discovered that leverages existing vulnerabilities in HTTP/2 implementations to cause widespread denial-of-service attacks against web servers. The exploit combines compression and fl… SecurityWeek · Jun 3, 2026 High CVE-2016-6581CVE-2025-53020CVE-2016-8740USdoshttp2compression
threat-intel Microsoft Tries to Calm Legal Threat Fears After Zero-Day Disclosure Backlash This article reports on a controversy between Microsoft and a security researcher, known as Nightmare Eclipse, regarding the disclosure of several zero-day vulnerabilities affecting Microsoft products. Microsoft initiall… SecurityWeek · Jun 3, 2026 High CVE-2026-41091CVE-2026-45498CVE-2026-33825USzero-dayvulnerability disclosurelegal action
threat-intel Trump Signs Executive Order That Invites Vetting of Top AI Models for National Security Risks President Trump signed an executive order establishing a framework for the federal government to vet the national security risks of advanced AI systems, primarily focusing on models developed by companies like Anthropic… SecurityWeek · Jun 2, 2026 Medium artificial intelligenceai securitynational security
threat-intel Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis This SecurityWeek article examines the evolving cybersecurity crisis, highlighting a shift in focus from traditional vulnerability management to the challenges of rapid exploit development and runtime visibility. The rep… SecurityWeek · Jun 2, 2026 High airuntimepatching