Cybersecurity
265 articles RSS
CISA Adds the First-Ever Splunk Flaw to Its KEV Catalog, an Unauthenticated File-Write Bug in a PostgreSQL Sidecar Now Exploited in the Wild
CVE-2026-20253, a CVSS 9.8 missing-authentication flaw in Splunk Enterprise's PostgreSQL sidecar, became the first Splunk bug on CISA's KEV list, with federal agencies ordered to patch by June 21.
Salesforce Disables Klue Battlecards Integration After OAuth Token Theft Drains CRM Data From Customers Including Huntress
Attackers abused a compromised legacy Klue credential to mint Salesforce OAuth tokens and pull CRM records over roughly 24 hours. Salesforce disabled the Battlecards app on June 17.
F5 Ships Out-of-Band NGINX Patches for Two Critical Flaws, Including a 9.2 HTTP/3 Use-After-Free Reachable by Unauthenticated Attackers
F5 patched CVE-2026-42530, a CVSS 9.2 use-after-free in NGINX's HTTP/3 module, alongside a second 9.2 buffer overflow. Neither is known to be exploited.
Fifteen Malicious JetBrains Marketplace Plugins Stole AI API Keys From Nearly 70,000 Developer Installs Before JetBrains Purged Them
A coordinated campaign published 15 fake AI coding assistants on the JetBrains Marketplace that harvested developer API keys; JetBrains removed them and terminated 7 publisher accounts.
Jenkins Patches High-Severity Deserialization Flaw CVE-2026-53435 That Turns a config.xml Submission Into Controller-Side Code Execution
Jenkins fixed CVE-2026-53435, an 8.8-rated deserialization flaw letting an attacker-controlled config.xml impersonate users and reach the Script Console for code execution on the controller.
CISA Flags Exploited SolarWinds Serv-U Crash Flaw CVE-2026-28318 in KEV as a Single Deflate Header Downs File-Transfer Servers
CVE-2026-28318 lets an unauthenticated attacker crash SolarWinds Serv-U with a crafted POST request using a Content-Encoding: deflate header. CISA added it to the KEV catalog on June 5, 2026 amid active exploitation; SolarWinds shipped a hotfix on June 6.
IronWorm, a Rust-Based npm Infostealer, Hides Behind an eBPF Rootkit and Tor C2 While Self-Propagating Through Stolen Credentials
JFrog disclosed IronWorm, a self-propagating npm worm written in Rust that uses an eBPF rootkit, Tor command-and-control, and stolen credentials to spread.
ShinyHunters Exploited an Oracle PeopleSoft Zero-Day for Two Weeks Before Disclosure as CVE-2026-35273 Lands on CISA's KEV Catalog
CVE-2026-35273, a CVSS 9.8 missing-authentication flaw in Oracle PeopleSoft PeopleTools, was exploited as a zero-day by UNC6240 before Oracle shipped mitigations and CISA set a June 15 federal deadline.
ServiceNow Patches an Unauthenticated API Endpoint That Let Customer Instance Tables Be Queried Without Credentials
ServiceNow fixed a REST API endpoint that shipped without authentication, after confirming a subset of customer instances were queried. It has not assigned a CVE.
CISA's BOD 26-04 Orders Federal Agencies to Patch the Most Dangerous Vulnerabilities in Three Days, Replacing the CVSS-Score Model
The risk-tiered directive harmonizes BOD 19-02 and BOD 22-01, ranking flaws by exposure, KEV status, automation, and impact.
Microsoft Ships Its Largest Patch Tuesday on Record, Led by a Wormable CVSS 9.8 Windows Kernel Flaw
June 2026's update tops the previous record of 177 CVEs and includes CVE-2026-45657, a wormable 9.8 kernel use-after-free.
Check Point Patches Critical VPN Zero-Day CVE-2026-50751 After a Month of Exploitation Tied to a Qilin Ransomware Affiliate
A logic flaw in Check Point's deprecated IKEv1 certificate validation let attackers bypass VPN authentication. CISA added it to KEV with a June 11 deadline.