Cybersecurity
204 articles RSS
Salesforce Disables Klue Battlecards Integration After OAuth Token Theft Drains CRM Data From Customers Including Huntress
Attackers abused a compromised legacy Klue credential to mint Salesforce OAuth tokens and pull CRM records over roughly 24 hours. Salesforce disabled the Battlecards app on June 17.
F5 Ships Out-of-Band NGINX Patches for Two Critical Flaws, Including a 9.2 HTTP/3 Use-After-Free Reachable by Unauthenticated Attackers
F5 patched CVE-2026-42530, a CVSS 9.2 use-after-free in NGINX's HTTP/3 module, alongside a second 9.2 buffer overflow. Neither is known to be exploited.
Fifteen Malicious JetBrains Marketplace Plugins Stole AI API Keys From Nearly 70,000 Developer Installs Before JetBrains Purged Them
A coordinated campaign published 15 fake AI coding assistants on the JetBrains Marketplace that harvested developer API keys; JetBrains removed them and terminated 7 publisher accounts.
Jenkins Patches High-Severity Deserialization Flaw CVE-2026-53435 That Turns a config.xml Submission Into Controller-Side Code Execution
Jenkins fixed CVE-2026-53435, an 8.8-rated deserialization flaw letting an attacker-controlled config.xml impersonate users and reach the Script Console for code execution on the controller.
CISA Flags Exploited SolarWinds Serv-U Crash Flaw CVE-2026-28318 in KEV as a Single Deflate Header Downs File-Transfer Servers
CVE-2026-28318 lets an unauthenticated attacker crash SolarWinds Serv-U with a crafted POST request using a Content-Encoding: deflate header. CISA added it to the KEV catalog on June 5, 2026 amid active exploitation; SolarWinds shipped a hotfix on June 6.
IronWorm, a Rust-Based npm Infostealer, Hides Behind an eBPF Rootkit and Tor C2 While Self-Propagating Through Stolen Credentials
JFrog disclosed IronWorm, a self-propagating npm worm written in Rust that uses an eBPF rootkit, Tor command-and-control, and stolen credentials to spread.
ShinyHunters Exploited an Oracle PeopleSoft Zero-Day for Two Weeks Before Disclosure as CVE-2026-35273 Lands on CISA's KEV Catalog
CVE-2026-35273, a CVSS 9.8 missing-authentication flaw in Oracle PeopleSoft PeopleTools, was exploited as a zero-day by UNC6240 before Oracle shipped mitigations and CISA set a June 15 federal deadline.
ServiceNow Patches an Unauthenticated API Endpoint That Let Customer Instance Tables Be Queried Without Credentials
ServiceNow fixed a REST API endpoint that shipped without authentication, after confirming a subset of customer instances were queried. It has not assigned a CVE.
CISA's BOD 26-04 Orders Federal Agencies to Patch the Most Dangerous Vulnerabilities in Three Days, Replacing the CVSS-Score Model
The risk-tiered directive harmonizes BOD 19-02 and BOD 22-01, ranking flaws by exposure, KEV status, automation, and impact.
Microsoft Ships Its Largest Patch Tuesday on Record, Led by a Wormable CVSS 9.8 Windows Kernel Flaw
June 2026's update tops the previous record of 177 CVEs and includes CVE-2026-45657, a wormable 9.8 kernel use-after-free.
Check Point Patches Critical VPN Zero-Day CVE-2026-50751 After a Month of Exploitation Tied to a Qilin Ransomware Affiliate
A logic flaw in Check Point's deprecated IKEv1 certificate validation let attackers bypass VPN authentication. CISA added it to KEV with a June 11 deadline.
Critical Everest Forms Pro WordPress Flaw CVE-2026-3300 Exploited for Two Months as Wordfence Blocks 29,300 Attacks
An unauthenticated PHP code-injection bug in the Everest Forms Pro plugin, patched in March, has been exploited since April 13 to plant rogue administrator accounts on WordPress sites.