threat-intel Vulnerabilities Expose Private Data in Indian Government Systems A security researcher discovered 14 vulnerabilities across multiple Indian government IT systems, including portals for education, civil service, and scholarships. These vulnerabilities exposed sensitive personal data, s… Dark Reading · Jun 29, 2026 High INvulnerabilitydata-breachidentity-access-management
vulnerability ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access A critical vulnerability, dubbed ‘DirtyClone,’ has been identified in the Linux kernel, allowing local users to gain root access. This flaw, similar to previous ‘DirtyFrag’ and ‘Fragnesia’ vulnerabilities, stems from how… SecurityWeek · Jun 29, 2026 Critical CVE-2026-43503CVE-2026-43284CVE-2026-43500linuxkernelroot
threat-intel AI Decline? Confidence in Autonomous Penetration Testing Falls The confidence in fully autonomous AI systems for penetration testing has significantly declined after initial optimism. A report by Cobalt found that only 9% of organizations now rely on AI-powered testing, down from 29… Dark Reading · Jun 26, 2026 Medium aipentestingautomation
data-breach One Million Passports Leaked Online A database containing nearly a million passports from various countries has been exposed online. The breach occurred due to a vulnerability in an ID verification system used by cannabis dispensaries, highlighting the ris… Schneier on Security · Jun 26, 2026 High passportsdata breachidentity theft
threat-intel In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw A critical vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager (CUCM) has been rapidly weaponized by attackers within 24 hours of a proof-of-concept release. The SSRF flaw allows unauthenticated remote… Dark Reading · Jun 25, 2026 Critical CVE-2026-20230USssrfprivilege escalationcisco
threat-intel ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories This article reports on several security vulnerabilities and trends, including a privacy-preserving protocol from Cloudflare, six vulnerabilities in the curl library, a critical security flaw in Hoppscotch allowing unaut… The Hacker News · Jun 25, 2026 High CVE-2026-8932CVE-2026-50160USKRsmart tvproxywareiot
vulnerability Horner Automation Cscape This advisory details a critical vulnerability in Horner Automation’s Cscape software, specifically versions prior to 10.2_SP3. The vulnerability allows for out-of-bounds reads, potentially leading to information disclos… CISA Advisories · Jun 25, 2026 Critical CVE-2026-12897UScscapeout-of-boundsvulnerability
vulnerability Yokogawa FAST/TOOLS and CI Server This advisory details a vulnerability in Yokogawa FAST/TOOLS and CI Server software, specifically versions R9.01 to R10.04, that allows an attacker to potentially retrieve CI Server setting information. The vulnerability… CISA Advisories · Jun 25, 2026 Medium CVE-2026-11833USweb servercwe-319vulnerability
ransomware Europe Evolves Into Ransomware's Favorite Region Ransomware attacks in Europe have dramatically increased, representing a significant shift from previous trends. Black Kite researchers report a 55% rise in ransomware attacks across the continent through the first four… Dark Reading · Jun 25, 2026 High UKGEFRransomwaresupply-chainai
supply-chain Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks A new vulnerability, dubbed 'Cordyceps,' has been discovered in CI/CD workflows, allowing unauthorized access and control over hundreds of GitHub repositories across major tech companies. The flaw stems from overly permi… The Hacker News · Jun 24, 2026 Critical cicdsupply chaingithub
vulnerability Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs Critical vulnerabilities were discovered in Ubiquiti UniFi devices, specifically CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, allowing for unauthorized access and command injection. While patches were released in… SecurityWeek · Jun 24, 2026 Critical CVE-2026-34908CVE-2026-34909CVE-2026-34910USvulnerabilitycommand injectionauthentication
threat-intel Dawn of the Apex Agentic Adversary This article discusses a significant shift in cybersecurity driven by the emergence of "agentic" AI models capable of rapidly discovering and exploiting vulnerabilities at speeds far exceeding human capabilities. The ris… The Hacker News · Jun 24, 2026 Critical aiautomationcybersecurity
supply-chain Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking A new vulnerability, dubbed ‘Cordyceps,’ has been identified within CI/CD workflows across numerous open-source projects, allowing unauthorized access and control over developer repositories. The flaws, primarily found i… SecurityWeek · Jun 24, 2026 High ci/cdsupply chaingithub actions
threat-intel StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader A new malware family, named SharkLoader, has been identified as part of a broader campaign targeting organizations globally, including diplomatic entities, government organizations, and software development companies. Th… Securelist · Jun 24, 2026 Medium CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikeexploitloader
threat-intel Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says Anthropic’s Mythos AI model identified vulnerabilities within several U.S. government computer systems during a testing exercise conducted in collaboration with intelligence agencies. While the model quickly detected wea… SecurityWeek · Jun 24, 2026 High UNaivulnerabilitysecurity
threat-intel Five Eyes agencies sound alarm about AI’s threat to cybersecurity Five Eyes intelligence agencies are issuing a stark warning about the rapidly escalating threat posed by artificial intelligence (AI) to cybersecurity. They believe AI will dramatically accelerate both offensive and defe… The Record · Jun 23, 2026 High USUKCAaicybersecuritythreat intelligence
vulnerability Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps A significant vulnerability has been identified in the Dify AI platform, a widely used LLMOps solution powering over one million applications across numerous industries. The flaws, detailed as CVE-2026-41947 through CVE-… SecurityWeek · Jun 23, 2026 Critical CVE-2026-41947CVE-2026-41948CVE-2026-41949aillmopsdata-exposure
threat-intel The Exploit Doesn't Exist. You Can Still Prove It Works Against You This BleepingComputer article discusses the rapidly decreasing timeframes for vulnerabilities to be exploited, driven by advancements in AI like Anthropic’s Mythos model. Traditional patching strategies are becoming inef… BleepingComputer · Jun 23, 2026 High CVE-2025-29824USaivulnerabilityexploitation
vulnerability Siemens WinCC Certificate Manager A vulnerability has been identified in Siemens WinCC Certificate Manager, specifically versions V16 through V21, that allows an attacker to potentially extract sensitive information due to insufficient protection of key… CISA Advisories · Jun 23, 2026 High CVE-2026-24349GEcertificatekey managementindustrial control systems
threat-intel Siemens SINEC INS This CISA advisory details a critical vulnerability affecting Siemens SINEC INS versions prior to V1.0 SP2 Update 6. The vulnerability stems from improper input sanitization, allowing for command injection, path traversa… CISA Advisories · Jun 23, 2026 Critical CVE-2026-46746CVE-2026-46747CVE-2026-46748DEcommand injectionpath traversalpassword cracking