vulnerability Check Point VPN Flaw Exploited Since Early May A critical zero-day vulnerability (CVE-2026-50751) in Check Point's Security Gateways and Spark Firewalls has been exploited since early May by a Qilin ransomware affiliate. The flaw, involving a logic flaw in certificat… Dark Reading · Jun 8, 2026 Critical CVE-2026-50751CVE-2026-50752zero-dayikev1vpn
vulnerability Gogs patches critical zero-day enabling remote code execution A critical zero-day vulnerability in Gogs, a remote collaboration platform, has been identified, allowing authenticated attackers to execute remote code and access private repositories. The flaw, present in versions up t… BleepingComputer · Jun 8, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPremote-code-executionzero-dayauthentication
vulnerability Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups Check Point has identified and warned of a critical vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access products, allowing unauthenticated attackers to bypass password authentication when using the… The Hacker News · Jun 8, 2026 Critical CVE-2026-50751CVE-2026-50752GLikev1vpncertificate
vulnerability Check Point links VPN zero-day attacks to Qilin ransomware gang Check Point identified a zero-day vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access deployments, exploited by the Qilin ransomware gang. The flaw allowed unauthenticated attackers to bypass authen… BleepingComputer · Jun 8, 2026 High CVE-2026-50751CVE-2026-50752ISJAAUzero-dayvpnauthentication
data-breach Over 20,000 Instagram accounts stolen in Meta AI support hack Over 20,000 Instagram accounts were compromised due to a vulnerability in Meta’s AI-powered support system, High Touch Support (HTS). Attackers exploited the system to reset passwords, gaining unauthorized access to user… BleepingComputer · Jun 8, 2026 High IEaipasswordaccount takeover
threat-intel Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 Palo Alto Networks Unit 42 has identified active exploitation of CVE-2026-0257, a PAN-OS vulnerability related to GlobalProtect authentication, by an unidentified threat actor. The vulnerability allows unauthorized VPN c… Palo Alto Unit 42 · Jun 5, 2026 High CVE-2026-0257vpnauthenticationvulnerability
threat-intel 4 Critical Threats Where Attackers Have the Advantage This Dark Reading article highlights four critical cybersecurity threats identified by Gartner: deepfakes, software supply chain risks, prompt injections, and AI application compromises. Gartner analysts contend that cur… Dark Reading · Jun 4, 2026 High deepfakesai securitysupply chain
threat-intel Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover A coding error in several Microsoft 365 Android applications, specifically Excel, Word, PowerPoint, OneNote, Loop, and Microsoft 365 Copilot, exposed user accounts to potential compromise. The issue stemmed from a disabl… Dark Reading · Jun 3, 2026 High CVE-2026-41100CVE-2026-41101CVE-2026-41102authenticationtokensandroid
threat-intel Google adds Android protection against AI deepfake scam calls Google is launching a new Android security feature, "fake call detection," to combat increasingly sophisticated scams utilizing AI-generated deepfake calls. The system works by verifying call authenticity in real-time, a… BleepingComputer · Jun 3, 2026 High USdeepfakeaiscam
phishing Instagram users locked out after Meta AI abused to steal accounts Instagram accounts were compromised due to attackers exploiting Meta’s AI-powered support tools to impersonate legitimate owners. Users were tricked into verifying their identities via AI-generated selfies, bypassing tra… BleepingComputer · Jun 2, 2026 High USaisocial mediaaccount takeover
threat-intel CISA and Partners Urge Hardening Automatic Tank Gauge Systems CISA, alongside several US government agencies, has issued an alert regarding malicious cyber activity targeting Automatic Tank Gauge (ATG) systems used across sectors like energy, chemicals, and transportation. Cyber ac… CISA Advisories · Jun 2, 2026 High oticstank gauges
vulnerability Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit A vulnerability in Palo Alto Networks' PAN-OS GlobalProtect VPN technology, tracked as CVE-2026-0257, is currently being actively exploited. Attackers are leveraging a configuration flaw to bypass authentication and gain… Dark Reading · Jun 1, 2026 Critical CVE-2026-0257CVE-2025-0108USvpnauthenticationcookie
threat-intel ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More This Hacker News recap details several ongoing cyber threats, including an active exploitation of a PAN-OS GlobalProtect authentication bypass vulnerability, a critical zero-day vulnerability in the Gogs Git service, and… The Hacker News · Jun 1, 2026 High CVE-2026-0257CVE-2026-8732CVE-2026-27771RUvulnerabilityauthenticationc2
supply-chain OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack A supply chain attack targeting OpenAI Codex developers has been discovered through a malicious npm package named ‘codexui-android’. The package, developed by ‘friuns’ (Igor Levochkin) and promoted by ‘BrutalStrike’, sil… The Hacker News · Jun 1, 2026 High USsupply chainauthenticationtokens
vulnerability Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks Palo Alto Networks is warning of an actively exploited vulnerability (CVE-2026-0257) in its GlobalProtect VPN software, allowing attackers to bypass authentication and establish unauthorized VPN connections. The flaw, in… BleepingComputer · May 30, 2026 High CVE-2026-0257USvpnauthenticationcookie
vulnerability ABB Busch-Welcome 2 Wire Door Opener Actuator A vulnerability has been identified in ABB Busch-Welcome 2 Wire Door Opener Actuators, specifically due to a default compatibility mode that allows for authentication bypass. This could enable an attacker to gain unautho… CISA Advisories · May 28, 2026 High CVE-2025-7705WOdoor lockphysical accessauthentication
threat-intel XCharge C6 This CISA advisory details a critical vulnerability series affecting XCharge C6 charging controllers worldwide. The vulnerabilities include a firmware validation flaw, a stack-based buffer overflow, and a misconfigured r… CISA Advisories · May 28, 2026 Critical CVE-2026-9037CVE-2026-9038CVE-2026-9039USfirmwarebuffer overflowremote management
vulnerability Fourth Frontier Frontier X Mobile Application, Frontier X2 A vulnerability has been identified in the Fourth Frontier Frontier X Mobile Application and Frontier X2 devices, allowing unauthorized access and control. Attackers could potentially read and modify patient data, trigge… CISA Advisories · May 28, 2026 High CVE-2026-5768USbleauthenticationdevice control
threat-intel MacGregor Voyage Data Recorder (VDR) G4e A vulnerability has been identified in MacGregor Voyage Data Recorder (VDR) G4e devices, specifically versions prior to V5.250, due to the use of default credentials, weak password hashing, and hard-coded credentials. Th… CISA Advisories · May 28, 2026 High CVE-2026-42941CVE-2026-42951CVE-2026-44611DKdefault credentialsvdrfirmware
threat-intel Can you enforce strong Active Directory password rules without frustrating users? This article discusses the challenges of enforcing strong Active Directory (AD) password policies without frustrating users. It highlights the importance of using passphrases over complex passwords, blocking weak or comp… BleepingComputer · May 27, 2026 Medium active directorypassword policypassphrases