Cybersecurity
204 articles RSS
Microsoft Discloses CVE-2026-45497, a Command-Injection RCE in 365 Copilot Already Fixed Server-Side With No Customer Action
Microsoft rated the Copilot command-injection flaw Critical, with a 7.7 CVSS base score. It was already mitigated in the cloud and not exploited.
Cisco Discloses Another Exploited SD-WAN Manager Zero-Day, CVE-2026-20245, With No Patch Yet and a Crafted File Path to Root
Cisco says CVE-2026-20245, a 7.8-rated command-injection flaw in Catalyst SD-WAN Manager, is being exploited to gain root. No patch or workaround is available; Mandiant reported it.
Carnival Confirms Data Breach Affecting Nearly 6 Million People After Social-Engineering Attack as ShinyHunters Claims the Records
Carnival told Maine's attorney general that 5,995,277 people were affected by an April breach traced to a compromised employee account; ShinyHunters claims the data.
CISA Adds Four-Year-Old Linux Kernel cgroups Container-Escape Flaw CVE-2022-0492 to KEV Catalog Citing Active Exploitation
CISA added the 2022 Linux kernel cgroups release_agent flaw CVE-2022-0492 to its KEV catalog on June 2, 2026, with a June 5 federal patch deadline.
Google Confirms Limited Exploitation of an Android Framework Integer-Overflow Flaw, CVE-2025-48595, in June Security Bulletin
Google's June 2026 Android update patches a Framework privilege-escalation zero-day under limited, targeted exploitation. CISA added it to the KEV catalog with a June 5 federal deadline.
Belgium's Cyber Agency Says Critical Windows Netlogon Flaw CVE-2026-41089 Is Now Being Exploited — Microsoft Disputes It
Belgium's CCB warns the 9.8-rated Netlogon RCE is exploited in the wild, threatening domain controllers. Microsoft says it has no evidence.
Attackers Exploit CVE-2026-35616 in FortiClient EMS to Deploy EKZ Infostealer Disguised as a Fortinet Patch
Arctic Wolf found attackers abusing a critical 9.8-CVSS FortiClient EMS authentication bypass to silently push EKZ Infostealer to every managed endpoint via legitimate VPN scripting workflows.
Trend Micro Patches Apex One Zero-Day CVE-2026-34926 Exploited in the Wild, CISA Orders Federal Agencies to Patch by June 4
A directory traversal flaw in Trend Micro Apex One lets an attacker with admin server access inject malicious code into managed endpoints. CISA added it to KEV on May 21 with a June 4 federal deadline.
DAEMON Tools Lite Backdoored for 27 Days: Supply Chain Attack Targeted Government and Scientific Organizations in Russia, Belarus, and Thailand
Kaspersky found official DAEMON Tools Lite installers trojanized from April 8 to May 5, 2026, deploying a multi-stage backdoor to over a dozen targeted machines. CISA added CVE-2026-8398 to its KEV catalog on May 27.
Ghost CMS SQL Injection CVE-2026-26980 Exploited to Hijack 700 Sites in Large-Scale ClickFix Campaign
A patched SQL injection in Ghost CMS (versions 3.24.0–6.19.0) has been exploited at scale to compromise 700+ websites, including Harvard and Oxford, turning them into ClickFix malware distribution points.
TrapDoor Campaign Deploys 34 Malicious Packages Across npm, PyPI, and Crates.io, Weaponizing AI Coding Assistants to Steal Crypto Wallets
Socket researchers discovered TrapDoor, a supply chain attack spanning 34 packages and 384+ versions across three registries, with a novel technique that embeds hidden instructions in AI coding assistant config files to trigger credential exfiltration.
Veeam Previews Data Platform v13.1 at VeeamON 2026, Launching DataAI Command Platform and Post-Quantum Cryptography Support
Veeam used its VeeamON 2026 conference in New York City to preview v13.1 of its Data Platform with 70+ new features, a new DataAI Command Platform, and post-quantum cryptography support.