threat-intel The Exploit Doesn't Exist. You Can Still Prove It Works Against You This BleepingComputer article discusses the rapidly decreasing timeframes for vulnerabilities to be exploited, driven by advancements in AI like Anthropic’s Mythos model. Traditional patching strategies are becoming inef… BleepingComputer · Jun 23, 2026 High CVE-2025-29824USaivulnerabilityexploitation
data-breach LastPass confirms data breach in Klue supply chain attack LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month. BleepingComputer · Jun 23, 2026 High
threat-intel SocGholish Takedown Highlights Malicious TDS Threats A coordinated international law enforcement operation, part of Operation Endgame, successfully disrupted SocGholish, a decade-old malware framework used as an initial-access broker by cybercriminal groups like Evil Corp.… Dark Reading · Jun 23, 2026 High NLtdssmalwareaffiliate
vulnerability Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks Researchers discovered a long-standing vulnerability (CVE-2026-20971) in Samsung’s KNOX kernel across numerous Galaxy devices, from S9 to S25. The flaw, a race-condition use-after-free (UAF), allowed for potential kernel… SecurityWeek · Jun 23, 2026 High uafkernelrace condition
threat-intel Two Scattered Spider members plead guilty over cyberattack that crippled London transit Two members of the Scattered Spider cybercrime gang have pleaded guilty to a prolonged cyberattack against London's transport authority, resulting in significant disruption and data exposure. The attack, which occurred i… The Record · Jun 23, 2026 High UKUScyberattacklondondata breach
threat-intel FortiBleed Attackers Turn Firewalls Into Credentials Stealers as Heist Persists The FortiBleed campaign, spearheaded by threat actors likely originating from Russia, has compromised over 430,000 FortiGate firewalls globally, resulting in the theft of more than 110 million credentials. Attackers util… Dark Reading · Jun 23, 2026 High USRUINcredential theftfirewallauthentication
vulnerability Siemens Products using OpenSSL A stack-based buffer overflow vulnerability (CVE-2025-15467) has been identified in various Siemens products utilizing OpenSSL. This vulnerability allows a remote attacker to potentially cause a denial-of-service or exec… CISA Advisories · Jun 23, 2026 High CVE-2025-15467DEUSCNopensslbuffer overflowdenial of service
vulnerability Impact of Linux Kernel vulnerabilities on B&R products View CSAF Summary B&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory. Successful local exploitation of these vulnerabilities… CISA Advisories · Jun 23, 2026 High CVE-2026-31431CVE-2026-43284CVE-2026-46333
vulnerability Siemens WinCC Certificate Manager A vulnerability has been identified in Siemens WinCC Certificate Manager, specifically versions V16 through V21, that allows an attacker to potentially extract sensitive information due to insufficient protection of key… CISA Advisories · Jun 23, 2026 High CVE-2026-24349GEcertificatekey managementindustrial control systems
vulnerability CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-67038 Lantronix EDS5000 Code Injection Vulnerability CVE-2026-34908 Ubiqui… CISA Advisories · Jun 23, 2026 High CVE-2025-67038CVE-2026-34908CVE-2026-34909
vulnerability Siemens SIPROTEC 5 Using DIGSI5 Protocol This CISA advisory details a vulnerability in Siemens SIPROTEC 5 devices, specifically utilizing the DIGSI5 protocol, that allows authenticated users to upload arbitrary files. This could lead to denial-of-service condit… CISA Advisories · Jun 23, 2026 High CVE-2025-40808relayprotocoldenial of service
vulnerability Hubbell Aclara Metrum Cellular Web Interface This CISA advisory details a vulnerability in Hubbell Aclara Metrum Cellular Web Interface software, specifically versions prior to 2.1.0.105. The flaw allows unauthorized access to critical device settings, potentially… CISA Advisories · Jun 23, 2026 High CVE-2026-1840USfirmwareauthenticationcritical infrastructure
threat-intel Agentic AI: The Weapon That No Longer Needs a Warrior This article discusses the rise of "Agentic AI" in offensive cyber operations, where AI systems autonomously execute attacks without direct human control. Previously, AI acted as a tool assisting humans in crafting attac… The Hacker News · Jun 23, 2026 High USaiautomationphishing
threat-intel Anthropic’s Fable 5 Model Jailbroken Within Days Anthropic’s Fable 5 model, designed as a safer alternative to their Mythos Preview, was quickly compromised by researchers. The model’s built-in safeguards against generating malicious code were bypassed within a short t… Schneier on Security · Jun 23, 2026 High aijailbreakmodel
threat-intel Russian Initial Access Broker Behind FortiBleed Campaign A Russian initial access broker (IAB) is targeting over 430,000 FortiGate firewalls globally as part of the FortiBleed campaign, harvesting credentials and selling access to other malicious actors. The campaign utilizes… SecurityWeek · Jun 23, 2026 High USGBNLcredential harvestingfirewallsupply chain
data-breach Canadian Electricity Provider London Hydro Discloses Data Breach Hackers stole customers’ names, addresses, email addresses, phone numbers, and account information. The post Canadian Electricity Provider London Hydro Discloses Data Breach appeared first on SecurityWeek . SecurityWeek · Jun 23, 2026 High
malware Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT A series of malicious npm packages, disguised as PostCSS tools, have been discovered delivering a Windows-based remote access trojan (RAT). These packages, published by 'abdrizak', leveraged legitimate build tooling to d… The Hacker News · Jun 23, 2026 High USnpmsupply-chainrat
data-breach Xsolis Data Breach Affects 1.4 Million Individuals Threat actors gained access to personal and protected health information that Xsolis received from its clients. The post Xsolis Data Breach Affects 1.4 Million Individuals appeared first on SecurityWeek . SecurityWeek · Jun 23, 2026 High
threat-intel OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws OpenAI is expanding its Daybreak initiative with GPT-5.5-Cyber, an AI model designed to accelerate vulnerability discovery and patching within software. This expansion includes a new plugin for streamlining the vulnerabi… The Hacker News · Jun 23, 2026 High CVE-2026-47729CVE-2026-4890CVE-2026-4891CAaivulnerabilitypatching
threat-intel The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration This report details a newly discovered bucket hijacking technique impacting major cloud service providers (CSPs) like Google Cloud, AWS, and Microsoft Azure. The vulnerability exploits a shared namespace design where glo… Palo Alto Unit 42 · Jun 22, 2026 High cloud securitydata exfiltrationbucket hijacking