Cybersecurity
204 articles RSS
CISA Adds Actively Exploited SharePoint RCE CVE-2026-45659 to KEV, Giving Federal Agencies Three Days to Patch
A deserialization flaw in on-premises SharePoint, patched in May, is now confirmed under active exploitation, with a July 4 federal deadline.
Microsoft Ties Mastra npm Supply-Chain Attack to North Korea's Sapphire Sleet as 'easy-day-js' Typosquat Poisons 140-Plus AI Packages
Microsoft attributes the June 17 compromise of 140-plus Mastra npm packages to North Korean state actor Sapphire Sleet, which used a hijacked maintainer account to inject a malicious dayjs typosquat called easy-day-js.
Miasma Worm Forges SLSA Provenance and Hides in binding.gyp as It Hits Red Hat, Vapi, and Leo Platform npm Packages
A self-spreading npm worm called Miasma published Trojanized packages carrying valid-looking SLSA provenance, beginning with 32 @redhat-cloud-services releases on June 1.
DifyTap: Four Authorization Flaws Let Attackers Silently Wiretap AI Chats Across Tenants on a Platform Powering Over 1 Million Apps
Zafran Security disclosed four authorization flaws in the open-source LLMOps platform Dify, including two critical bugs that let an attacker redirect another tenant's AI conversations to an attacker-controlled endpoint.
World Food Programme Breach Exposes Data of 600,000 Gaza Households in What Researchers Call the Largest Known Hack of Humanitarian Beneficiary Records
A cyberattack on the UN World Food Programme's Palestine registration app exposed personal data of about 600,000 Gaza households, drawing criticism over a 17-day notification delay.
24 Billion Stolen Credentials Found Exposed in an 8.3 TB Elasticsearch Cluster Dominated by Infostealer Logs
Cybernews researchers found an unsecured Elasticsearch cluster holding 24 billion records compiled from 36 sources, mostly infostealer logs with plaintext passwords.
Symantec Links a Self-Destructing 'Mistic' Backdoor to the KongTuke Access Broker Feeding Six Ransomware Crews
Symantec ties the in-memory Mistic backdoor to access broker KongTuke, whose footholds have fed Qilin, Akira, Black Basta and other ransomware groups since April 2026.
Operation Endgame Disrupts StealC and Amadey Malware as Microsoft Uses AI and a RICO Suit to Treat Them as One Conspiracy
Law enforcement seized 326 servers and froze 47 million dollars in crypto, while Microsoft filed RICO claims against five defendants after AI tools tied the two malware suites to shared infrastructure.
CISA Adds Max-Severity Joomla Content Editor Flaw CVE-2026-48907 to KEV as Attackers Drop Web Shells via Rogue Editor Profiles
An unauthenticated RCE in the JCE extension, scored CVSS 4.0 10.0, is being exploited to plant web shells. CISA set a June 19 federal deadline.
FortiBleed Campaign Exposes Credentials for Roughly 86,000 FortiGate Devices Across 194 Countries as CISA Urges Immediate Password Resets
A credential-harvesting campaign dubbed FortiBleed reached 86,644 compromised FortiGate devices across 194 countries by June 19, prompting a CISA hardening advisory.
Node.js Patches 12 CVEs in June Security Release, Two Rated High, as End-of-Life Node 20 Is Left Without a Fix
Node.js shipped v22.23.0, v24.17.0 and v26.3.1 on June 18, fixing 12 CVEs including two high-severity WebCrypto and TLS flaws. Node 20, EOL since April, gets no patch.
CISA Adds the First-Ever Splunk Flaw to Its KEV Catalog, an Unauthenticated File-Write Bug in a PostgreSQL Sidecar Now Exploited in the Wild
CVE-2026-20253, a CVSS 9.8 missing-authentication flaw in Splunk Enterprise's PostgreSQL sidecar, became the first Splunk bug on CISA's KEV list, with federal agencies ordered to patch by June 21.