vulnerability Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk A critical vulnerability was discovered in six Microsoft 365 Android apps – Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote – due to a debug flag left enabled in production code. This allowed… SecurityWeek · Jun 2, 2026 Critical CVE-2026-41100USdebugaccess tokensupply chain
vulnerability Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks. The post Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 2, 2026 Critical CVE-2025-48595CVE-2026-0059
vulnerability Anthropic Expanding Mythos Access to 150 New Organizations Only approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products. The post Anthropic Expanding Mythos Access to 150 New Organizations appeared first o… SecurityWeek · Jun 2, 2026
threat-intel The Zero-Knowledge Threat Actor and the End of Responsible Disclosure This article discusses the rise of ‘zero-knowledge’ threat actors, empowered by AI, who pose a significant new challenge to cybersecurity. These actors, lacking deep technical expertise, can rapidly discover and exploit… SecurityWeek · Jun 2, 2026 High aivulnerabilityphishing
vulnerability Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches A critical vulnerability (CVE-2026-0826) has been identified in HP Poly Voice VoIP phone models, allowing for remote code execution with root privileges. The flaw, triggered by a stack-based buffer overflow when processi… SecurityWeek · Jun 2, 2026 Critical CVE-2026-0826USvoipbuffer overflowremote code execution
vulnerability Oracle WebLogic Vulnerability Exploited in the Wild The vulnerability is CVE-2024-21182 and it can be exploited without authentication to hack affected WebLogic servers. The post Oracle WebLogic Vulnerability Exploited in the Wild appeared first on SecurityWeek . SecurityWeek · Jun 2, 2026 Critical CVE-2024-21182
Meta AI Hands Over High-Profile Instagram Accounts to Hackers Exploiting a confused deputy weakness, the hackers simply asked the chatbot to link the account to a new email address. The post Meta AI Hands Over High-Profile Instagram Accounts to Hackers appeared first on SecurityWee… SecurityWeek · Jun 2, 2026
supply-chain Supply Chain Attack Hits 32 Red Hat NPM Packages Hackers published 96 malicious package versions, injected with a credential-stealing worm similar to Mini Shai-Hulud. The post Supply Chain Attack Hits 32 Red Hat NPM Packages appeared first on SecurityWeek . SecurityWeek · Jun 2, 2026
Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads Dashlane’s security systems automatically locked accounts to protect them against the hacking attempts. The post Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads appeared first on SecurityWeek . SecurityWeek · Jun 2, 2026 High
vulnerability Oracle’s First Monthly Patches Resolve 77 Vulnerabilities Oracle’s monthly Critical Security Patch Update (CSPU) rollouts are meant to deliver critical fixes faster. The post Oracle’s First Monthly Patches Resolve 77 Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 2, 2026 Medium
vulnerability WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites The security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations. The post WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites appeared fir… SecurityWeek · Jun 1, 2026 Medium CVE-2026-8732
malware Dutch Police Dismantle Massive 17-Million-Device Botnet Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime. The post Dutch… SecurityWeek · Jun 1, 2026
vulnerability Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs Organizations are advised to patch CVE-2026-41089 as soon as possible, given its severity, the potential ongoing exploitation. The post Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs appeared first on S… SecurityWeek · Jun 1, 2026 Medium CVE-2026-41089
Dragos Acquires xIoT Security Firm Phosphorus Dragos said customers will soon gain expanded asset visibility and integrated device intelligence, with automated remediation workflows and a unified platform experience to follow. The post Dragos Acquires xIoT Security… SecurityWeek · Jun 1, 2026
threat-intel As the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge Caution This article reports on the U.S. Department of Defense's push to integrate artificial intelligence into military operations, particularly within the Special Operations Command, while facing concerns from tech companies a… SecurityWeek · Jun 1, 2026 Medium UNartificial intelligenceaimilitary
vulnerability 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access proof-of-concept (PoC) exploit code has been released for the CIFSwitch flaw, which allows low-privileged users to escalate to root on vulnerable Linux systems. The post 19-Year-Old Linux Kernel Vulnerability Exposes Sys… SecurityWeek · Jun 1, 2026 Medium
vulnerability Recent Palo Alto Networks Vulnerability Exploited for Weeks Hackers began exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS, four days after public disclosure. The post Recent Palo Alto Networks Vulnerability Exploited for Weeks appeared first on Sec… SecurityWeek · Jun 1, 2026 Medium CVE-2026-0257
threat-intel Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say As a result of sanctions and the ongoing war in Ukraine, Russian intelligence agencies are intensifying their efforts to steal Western technology and defense secrets. This includes targeting advanced machine tools, resea… SecurityWeek · May 30, 2026 High RUSEFIsanctionsespionagecyberattack
vulnerability Exploit Code Published for Critical Flowise RCE Vulnerability A critical remote code execution (RCE) vulnerability, CVE-2026-40933, has been discovered in Flowise, a popular open-source AI agent platform. The flaw, stemming from a command injection issue within the Anthropic MCP pr… SecurityWeek · May 30, 2026 Critical CVE-2026-40933rcecommand injectionai
threat-intel In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks This week’s cybersecurity news highlights a range of incidents, including a data breach affecting Trump Mobile customers, ongoing Russian government intrusion into US Treasury systems, and vulnerabilities in popular soft… SecurityWeek · May 29, 2026 High UNCHdata breachsupply chainphishing