vulnerability Hubbell Aclara Metrum Cellular Web Interface This CISA advisory details a vulnerability in Hubbell Aclara Metrum Cellular Web Interface software, specifically versions prior to 2.1.0.105. The flaw allows unauthorized access to critical device settings, potentially… CISA Advisories · Jun 23, 2026 High CVE-2026-1840USfirmwareauthenticationcritical infrastructure
threat-intel Anthropic’s Fable 5 Model Jailbroken Within Days Anthropic’s Fable 5 model, designed as a safer alternative to their Mythos Preview, was quickly compromised by researchers. The model’s built-in safeguards against generating malicious code were bypassed within a short t… Schneier on Security · Jun 23, 2026 High aijailbreakmodel
threat-intel OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws OpenAI is expanding its Daybreak initiative with GPT-5.5-Cyber, an AI model designed to accelerate vulnerability discovery and patching within software. This expansion includes a new plugin for streamlining the vulnerabi… The Hacker News · Jun 23, 2026 High CVE-2026-47729CVE-2026-4890CVE-2026-4891CAaivulnerabilitypatching
threat-intel ISC Stormcast For Tuesday, June 23rd, 2026 https://isc.sans.edu/podcastdetail/9982, (Tue, Jun 23rd) The SANS Internet Storm Center's Stormcast for June 23rd, 2026, reported a heightened level of online threats and potential disruptions. The broadcast highlighted several ongoing campaigns and emerging vulnerabilities th… SANS Internet Storm Center · Jun 23, 2026 Medium stormcastthreat intelligencephishing
vulnerability DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories A series of vulnerabilities, dubbed "DifyTap," have been discovered in the Dify AI application building platform, allowing attackers to potentially access and exfiltrate sensitive data, including AI chat histories. The f… Dark Reading · Jun 22, 2026 High CVE-2026-41947CVE-2026-41948CVE-2026-41949aisecurityvulnerability
threat-intel Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants Researchers have identified four critical vulnerabilities in the open-source Dify agentic workflow platform, dubbed DifyTap, allowing unauthorized access to AI conversations and data across tenants. These flaws include a… The Hacker News · Jun 22, 2026 Critical CVE-2024-5846CVE-2026-41947CVE-2026-41948aivulnerabilitytenant
threat-intel Stop Your Legacy Infrastructure from Hijacking Your AI Agents This article highlights a significant security risk: attackers leveraging legacy infrastructure to compromise AI agent environments. Despite organizations investing heavily in securing AI workloads against direct attacks… The Hacker News · Jun 22, 2026 High CVE-2025-24813USailegacypermissions
malware AryStinger botnet infected thousands of D-Link routers worldwide A new botnet, named AryStinger, has been discovered compromising over 4,000 outdated D-Link routers worldwide, turning them into proxies for malicious traffic. The malware utilizes multiple vulnerabilities to perform sca… BleepingComputer · Jun 21, 2026 High CVE-2013-3307CVE-2016-5681CVE-2025-11837KRCNSErouterbotnetdns
vulnerability Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin Hackers are actively exploiting a vulnerability in the Gravity SMTP WordPress plugin, allowing them to access sensitive information such as API keys and email service credentials. This flaw, tracked as CVE-2026-4020, has… BleepingComputer · Jun 19, 2026 Medium CVE-2026-4020CVE-2026-8713wordpressapicredentials
threat-intel Anthropic’s Fable and the State of AI Anthropic’s Fable AI model, designed to identify vulnerabilities in code, has sparked concern due to its capabilities and the potential for misuse. The US government classified it as a dangerous munition and restricted a… Schneier on Security · Jun 19, 2026 High UKUSCZaivulnerabilitycybersecurity
threat-intel FIFA Bug Exposed World Cup Streams to Remote Takeover A vulnerability in FIFA's Microsoft Entra environment allowed an ethical hacker, "BobDaHacker," to gain unauthorized access to global World Cup streams, match management systems, and related data platforms. The issue ste… Dark Reading · Jun 18, 2026 High USFRCOaccess-controlvulnerabilityauthentication
data-breach [Virtual Event] Anatomy of a Data Breach: What to Do if it Happens to You This article discusses the preparation needed for organizations to respond effectively to data breaches. It highlights the vulnerabilities and exploits commonly used in attacks, alongside the latest incident response too… Dark Reading · Jun 18, 2026 Medium data breachincident responsesecops
vulnerability AzeoTech DAQFactory This advisory details a Type Confusion vulnerability (CVE-2026-12390) in AzeoTech DAQFactory versions up to 21.1, allowing for potential arbitrary code execution via specially crafted .ctl files. The vulnerability affect… CISA Advisories · Jun 18, 2026 High CVE-2026-12390UStype confusioncwe843code execution
vulnerability Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT This CISA advisory details a vulnerability in the Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT, specifically version 0x0110_v1.1.0. The device is susceptible to unauthorized interception of sensitive health… CISA Advisories · Jun 18, 2026 High CVE-2026-50034CVE-2026-52866INbluetoothbleglucose
vulnerability Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products Schneider Electric has identified a vulnerability (CVE-2026-4827) in several of its industrial automation products, including Easergy, EcoStruxture, PowerLogic, and Saitel systems. The vulnerability, a CWE-331 Insufficie… CISA Advisories · Jun 18, 2026 High CVE-2026-4827upsindustrial controlsession management
threat-intel ISC Stormcast For Thursday, June 18th, 2026 https://isc.sans.edu/podcastdetail/9978, (Thu, Jun 18th) The SANS Internet Storm Center's June 18th, 2026 Stormcast reported a heightened level of online threats and unusual network activity across various sectors. The broadcast highlighted several emerging trends, including i… SANS Internet Storm Center · Jun 18, 2026 Medium phishingdnsthreat-monitoring
vulnerability Multiples vulnérabilités dans Mattermost Desktop App (18 juin 2026) Multiple vulnerabilities have been discovered in the Mattermost Desktop App, potentially allowing for remote denial-of-service attacks and an unspecified security issue. These vulnerabilities affect older versions of the… CERT-FR · Jun 18, 2026 Medium CVE-2026-8075CVE-2026-9602vulnerabilitymattermostdesktop app
threat-intel The Top 10 Attack Surface Exposures in 2026 This article from The Hacker News details a study by Intruder analyzing 3,000 attack surfaces, revealing widespread vulnerabilities in organizations’ internet-facing services. A significant 60% of organizations had expos… The Hacker News · Jun 17, 2026 High attack-surfacevulnerabilitydatabase
vulnerability 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs Recent analysis reveals that three previously patched Fortinet FortiSandbox vulnerabilities – CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089 – are actively being exploited in the wild. A significant number of comprom… SecurityWeek · Jun 17, 2026 High CVE-2026-39808CVE-2026-39813CVE-2026-25089USINALvulnerabilitypatchingexploitation
vulnerability CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution CISA has added a critical vulnerability, CVE-2026-48907, to its Known Exploited Vulnerabilities catalog affecting the Widget Factory Joomla Content Editor (JCE) due to improper access control. This flaw allows for PHP co… The Hacker News · Jun 17, 2026 Critical CVE-2026-48907TUjoomlaphpcode execution