threat-intel Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them. This article reports on a significant investment by IBM and Red Hat into Project Lightwell, a new service designed to address the growing challenge of securing open-source software supply chains. Driven by Anthropic's My… Dark Reading · Jul 2, 2026 High USaivulnerabilityopen source
threat-intel Gardyn IoT Hub This advisory details a vulnerability within the Gardyn IoT Hub, specifically versions prior to 2.12.2026, that allows unauthenticated users to potentially gain control of connected devices. The vulnerability stems from… CISA Advisories · Jul 2, 2026 Critical CVE-2026-13768CVE-2026-55726CVE-2026-54477USiotvulnerabilitycommand execution
threat-intel ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials Researchers at LayerX discovered a vulnerability dubbed ‘BioShocking’ that exploits the tendency of AI browsers to prioritize game-like objectives over security protocols. The attack leverages a puzzle-solving scenario t… SecurityWeek · Jul 2, 2026 High aibrowsercredentials
ransomware AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack A security firm, Sysdig, has identified what appears to be the first fully automated ransomware attack orchestrated by an AI agent, dubbed JADEPUFFER. The agent exploited a vulnerability in Langflow, an open-source AI ap… The Hacker News · Jul 2, 2026 High CVE-2025-3248CVE-2021-29441CHairansomwareautomation
ransomware SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation A high-severity remote code execution (RCE) vulnerability (CVE-2026-45659) in Microsoft SharePoint Server has been added to the CISA KEV catalog due to active exploitation. This vulnerability, stemming from deserializing… The Hacker News · Jul 2, 2026 High CVE-2026-45659CVE-2025-11371USremote code executionsharepointvulnerability
vulnerability Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack? This article discusses a security vulnerability discovered in Fortinet’s FortiBleed, a tool designed to securely dispose of sensitive data. A researcher identified a flaw allowing unauthorized access to sensitive data, h… Graham Cluley · Jul 1, 2026 High vulnerabilityfortinetsecurity
vulnerability Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic Adobe has released critical security patches for vulnerabilities in both ColdFusion and Adobe Campaign Classic, addressing flaws with CVSS scores of up to 10.0. These vulnerabilities could allow for remote code execution… The Hacker News · Jul 1, 2026 Critical CVE-2026-48276CVE-2026-48283CVE-2026-48277adobevulnerabilitycode execution
threat-intel Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands A critical vulnerability, dubbed DuneSlide, has been discovered in Cursor, an AI code editor used by over half of the Fortune 500, allowing attackers to bypass the editor's sandbox and execute arbitrary commands on a dev… The Hacker News · Jul 1, 2026 Critical CVE-2026-50548CVE-2026-50549CVE-2025-54135prompt-injectionsandboxai-code-editor
vulnerability Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts A critical remote code execution (RCE) vulnerability, CVE-2026-8037, in Progress Kemp LoadMaster is currently being actively exploited. The flaw allows unauthenticated attackers to execute arbitrary commands on vulnerabl… The Hacker News · Jul 1, 2026 Critical CVE-2026-8037CVE-2024-1212rcecommand injectionload balancer
data-breach Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches Multiple Japanese companies, including an insurer, brewer, manufacturer, and telecom provider, have recently disclosed significant cyber breaches impacting customer data and operational systems. The attacks range from a… The Record · Jul 1, 2026 High JASICAdata breachransomwarecyberattack
threat-intel Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls Anthropic has restored access to Claude Fable 5 following the U.S. Commerce Department’s lifting of export controls triggered by a jailbreak vulnerability discovered in the model. The controls, implemented in June, restr… The Hacker News · Jul 1, 2026 High USjailbreakaisecurity
malware RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS A new botnet, RustDuck, is leveraging Rust programming to hijack routers, IP cameras, and servers for DDoS attacks. Developed by QiAnXin's XLab, the botnet utilizes a two-stage approach, exploiting vulnerabilities in dev… The Hacker News · Jun 30, 2026 High CVE-2017-17215CVE-2025-29635CVE-2024-1781CNddosbotnetrust
threat-intel This month in security with Tony Anscombe – June 2026 edition This month’s security roundup highlights a critical CISA policy demanding rapid patching of vulnerabilities for federal agencies, a targeted cyberattack campaign against US-based Automatic Tank Gauges (ATGs), a surge in… WeLiveSecurity · Jun 30, 2026 Medium USUKCAvulnerabilitycyberattacksocial media
threat-intel GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks A research report by Adversa AI has revealed a significant security vulnerability in ten popular open-source AI coding agents, including GuardFall, which allows attackers to bypass safety checks and execute shell command… The Hacker News · Jun 30, 2026 High aishellsecurity
vulnerability Schneider Electric EcoStruxure IT Data Center Expert This report details a vulnerability discovered in Schneider Electric’s EcoStruxure IT Data Center Expert software, specifically versions up to 9.1.1. The vulnerability, classified as CWE-611, is an Improper Restriction o… CISA Advisories · Jun 30, 2026 Medium CVE-2026-8045FRxmlcwe-611data center
vulnerability StoneFly Storage Concentrator This report details a critical vulnerability affecting StoneFly Storage Concentrator versions prior to 8.0.4.29, exposing the system to significant risks including unauthorized access, command execution, and data theft.… CISA Advisories · Jun 30, 2026 Critical CVE-2026-56415CVE-2026-55721CVE-2026-50040UScredentialcommand injectionsql injection
vulnerability Delta Electronics DVP12SE PLC This advisory details a critical vulnerability in Delta Electronics’ DVP12SE PLC, exposing it to unauthorized remote access and control. The PLC’s Modbus TCP service lacks authentication, allowing attackers to potentiall… CISA Advisories · Jun 30, 2026 Critical CVE-2026-12819CVE-2026-12818TWplcmodbusiot
vulnerability Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth A critical vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster allows unauthenticated attackers to execute arbitrary commands as root by manipulating API requests. The flaw stems from a lack of proper sanitization… The Hacker News · Jun 30, 2026 Critical CVE-2026-8037CVE-2026-33691CVE-2024-1212CAcommand-injectionrootapi
threat-intel Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs Apple released a significant security update addressing over 30 vulnerabilities across its iOS, macOS, and Safari platforms. Notably, several WebKit vulnerabilities were identified using AI tools, highlighting a new tren… The Hacker News · Jun 30, 2026 Medium CVE-2026-43707CVE-2026-43716CVE-2026-43745webkitaivulnerability
threat-intel NIST Enrichment Reductions Impact CVE Coverage, Accuracy This article reports on a reduction in in-depth analysis of vulnerabilities by the National Institute of Standards and Technology (NIST), impacting the National Vulnerability Database (NVD). Research by Volerion revealed… Dark Reading · Jun 29, 2026 Medium CVE-2026-8856vulnerabilitynistcvss